UBSan: Undefined Behavior in psref_release

6 views
Skip to first unread message

syzbot

unread,
Mar 31, 2023, 4:53:41 AM3/31/23
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: a2b32922a129 bump XORG_SERVER_TEENY.
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=1654983ec80000
kernel config: https://syzkaller.appspot.com/x/.config?x=1420f906d33d9f1f
dashboard link: https://syzkaller.appspot.com/bug?extid=2fc5a47b25f0e87e5210
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=14d9f60dc80000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17626f71c80000

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/2099b2585d30/disk-a2b32922.raw.xz
netbsd.gdb: https://storage.googleapis.com/syzbot-assets/f2678d756cd3/netbsd-a2b32922.gdb.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+2fc5a4...@syzkaller.appspotmail.com

[ 40.2379268] panic: UBSan: Undefined Behavior in /syzkaller/managers/ci2-netbsd-kubsan/kernel/sys/kern/subr_psref.c:235:2, member access within misaligned address 0x1 for type 'struct psref' which requires 8 byte alignment

[ 40.2379268] cpu1: Begin traceback...
[ 40.2578954] vpanic() at netbsd:vpanic+0x2f2 sys/kern/subr_prf.c:291
[ 40.3378946] Report() at netbsd:Report+0x3b sys/../common/lib/libc/misc/ubsan.c:1352
[ 40.3978958] HandleTypeMismatch() at netbsd:HandleTypeMismatch+0xfc sys/../common/lib/libc/misc/ubsan.c:432
[ 40.4478953] psref_release() at netbsd:psref_release+0x6bf psref_exist sys/kern/subr_psref.c:235 [inline]
[ 40.4478953] psref_release() at netbsd:psref_release+0x6bf psref_check_existence sys/kern/subr_psref.c:261 [inline]
[ 40.4478953] psref_release() at netbsd:psref_release+0x6bf sys/kern/subr_psref.c:374
[ 40.5078951] doifioctl() at netbsd:doifioctl+0x857 x86_curlwp sys/arch/amd64/compile/obj/GENERIC_SYZKALLER/./machine/cpu.h:68 [inline]
[ 40.5078951] doifioctl() at netbsd:doifioctl+0x857 curlwp_bindx sys/sys/lwp.h:588 [inline]
[ 40.5078951] doifioctl() at netbsd:doifioctl+0x857 sys/net/if.c:3612
[ 40.5578968] soo_ioctl() at netbsd:soo_ioctl+0x29c sys/kern/sys_socket.c:210
[ 40.6078949] sys_ioctl() at netbsd:sys_ioctl+0xd88 sys/kern/sys_generic.c:675
[ 40.6578971] sys_syscall() at netbsd:sys_syscall+0x1e4 sy_call sys/sys/syscallvar.h:65 [inline]
[ 40.6578971] sys_syscall() at netbsd:sys_syscall+0x1e4 sys/kern/sys_syscall.c:90
[ 40.7178978] syscall() at netbsd:syscall+0x2da sy_call sys/sys/syscallvar.h:65 [inline]
[ 40.7178978] syscall() at netbsd:syscall+0x2da sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 40.7178978] syscall() at netbsd:syscall+0x2da sys/arch/x86/x86/syscall.c:138
[ 40.7278950] --- syscall (number 54 via SYS_syscall) ---
[ 40.7478954] netbsd:syscall+0x2da:
[ 40.7478954] cpu1: End traceback...
[ 40.7478954] fatal breakpoint trap in supervisor mode
[ 40.7578960] trap type 1 code 0 rip 0xffffffff80235375 cs 0x8 rflags 0x246 cr2 0x7781c5a3ed30 ilevel 0x4 rsp 0xffffc98248034640
[ 40.7678925] curlwp 0xfffff9845229dac0 pid 1198.1198 lowest kstack 0xffffc982480302c0
Stopped in pid 1198.1198 (syz-executor3541) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xec sys/ddb/db_panic.c:69
vpanic() at netbsd:vpanic+0x2f2 sys/kern/subr_prf.c:291
Report() at netbsd:Report+0x3b sys/../common/lib/libc/misc/ubsan.c:1352
HandleTypeMismatch() at netbsd:HandleTypeMismatch+0xfc sys/../common/lib/libc/misc/ubsan.c:432
psref_release() at netbsd:psref_release+0x6bf psref_exist sys/kern/subr_psref.c:235 [inline]
psref_release() at netbsd:psref_release+0x6bf psref_check_existence sys/kern/subr_psref.c:261 [inline]
psref_release() at netbsd:psref_release+0x6bf sys/kern/subr_psref.c:374
doifioctl() at netbsd:doifioctl+0x857 x86_curlwp sys/arch/amd64/compile/obj/GENERIC_SYZKALLER/./machine/cpu.h:68 [inline]
doifioctl() at netbsd:doifioctl+0x857 curlwp_bindx sys/sys/lwp.h:588 [inline]
doifioctl() at netbsd:doifioctl+0x857 sys/net/if.c:3612
soo_ioctl() at netbsd:soo_ioctl+0x29c sys/kern/sys_socket.c:210
sys_ioctl() at netbsd:sys_ioctl+0xd88 sys/kern/sys_generic.c:675
sys_syscall() at netbsd:sys_syscall+0x1e4 sy_call sys/sys/syscallvar.h:65 [inline]
sys_syscall() at netbsd:sys_syscall+0x1e4 sys/kern/sys_syscall.c:90
syscall() at netbsd:syscall+0x2da sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x2da sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x2da sys/arch/x86/x86/syscall.c:138
--- syscall (number 54 via SYS_syscall) ---
netbsd:syscall+0x2da:
Panic string: UBSan: Undefined Behavior in /syzkaller/managers/ci2-netbsd-kubsan/kernel/sys/kern/subr_psref.c:235:2, member access within misaligned address 0x1 for type 'struct psref' which requires 8 byte alignment

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
1245 1245 2 0 0 fffff98455734180 syz-executor3541
1131 1131 2 0 0 fffff9845363a500 syz-executor3541
1198 >1198 7 1 0 fffff9845229dac0 syz-executor3541
449 > 449 7 0 0 fffff984535c2080 syz-executor3541
829 829 2 0 0 fffff984535c2900 syz-executor3541
1239 1239 2 0 0 fffff98452c3e8c0 syz-executor3541
1004 1004 2 0 0 fffff98453030540 syz-executor3541
986 986 2 1 0 fffff984525c56c0 syz-executor3541
929 929 2 0 140 fffff9845363a0c0 syz-executor3541
1241 1241 3 1 180 fffff984527a7300 syz-executor3541 nanoslp
941 941 3 1 180 fffff98453030100 syz-executor3541 nanoslp
1120 1120 3 0 180 fffff984525c5b00 syz-executor3541 nanoslp
1226 1226 3 0 40180 fffff98452ad7340 sshd select
1222 1222 3 1 180 fffff98453fdb580 getty nanoslp
1184 1184 3 1 180 fffff9845363a940 getty nanoslp
1216 1216 3 0 180 fffff984526de700 getty nanoslp
1195 1195 3 0 1c0 fffff9845226f200 getty ttyraw
1103 1103 3 0 180 fffff98453fdb140 sshd select
955 955 3 0 180 fffff98453030980 powerd kqueue
698 698 3 1 180 fffff984535c24c0 syslogd kqueue
746 746 3 0 180 fffff98452ad7780 dhcpcd poll
742 742 3 0 180 fffff98452c3e480 dhcpcd poll
466 466 3 0 180 fffff98452ad7bc0 dhcpcd poll
603 603 3 0 180 fffff984527a7740 dhcpcd poll
292 292 3 0 180 fffff984526deb40 dhcpcd poll
485 485 3 1 180 fffff984526de2c0 dhcpcd poll
291 291 3 1 180 fffff984527a7b80 dhcpcd poll
1 1 3 0 180 fffff9844a06b980 init wait
0 734 3 0 200 fffff9845226f640 physiod physiod
0 196 3 1 200 fffff9845229d680 pooldrain pooldrain
0 195 3 0 200 fffff9845229d240 ioflush syncer
0 194 3 0 200 fffff9845226fa80 pgdaemon pgdaemon
0 170 3 1 200 fffff984501afa40 usb7 usbevt
0 169 3 1 200 fffff984501af600 usb6 usbevt
0 168 3 1 200 fffff984501af1c0 usb5 usbevt
0 167 3 1 200 fffff9844d15aa00 usb4 usbevt
0 166 3 1 200 fffff9844d15a5c0 usb3 usbevt
0 165 3 1 200 fffff9844d15a180 usb2 usbevt
0 31 3 1 200 fffff9844a0b59c0 usb1 usbevt
0 63 3 1 200 fffff9844a0b5580 usb0 usbevt
0 126 3 1 200 fffff98449ef0740 usbtask-dr usbtsk
0 125 3 1 200 fffff98449ef0b80 usbtask-hc usbtsk
0 124 3 0 200 fffff984484a1b00 swwreboot swwreboot
0 123 3 0 200 fffff9844a0b5140 npfgc0 npfgcw
0 122 3 1 200 fffff9844a06b540 rt_free rt_free
0 121 3 1 200 fffff9844a06b100 unpgc unpgc
0 120 3 0 200 fffff9844a05e940 key_timehandler key_timehandler
0 119 3 1 200 fffff9844a05e500 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 fffff9844a05e0c0 icmp6_wqinput/0 icmp6_wqinput
0 117 3 0 200 fffff9844a041900 nd6_timer nd6_timer
0 116 3 1 200 fffff9844a0414c0 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 fffff9844a041080 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 fffff9844a0248c0 carp_wqinput/1 carp_wqinput
0 113 3 0 200 fffff9844a024480 carp_wqinput/0 carp_wqinput
0 112 3 1 200 fffff9844a024040 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 fffff98449fe7bc0 icmp_wqinput/0 icmp_wqinput
0 110 3 0 200 fffff98449fe7340 rt_timer rt_timer
0 109 3 0 200 fffff98449fe7780 vmem_rehash vmem_rehash
0 100 3 0 200 fffff98449ef0300 entbutler entropy
0 99 3 0 200 fffff98449950b40 viomb balloon
0 98 3 1 200 fffff98449950700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 fffff984499502c0 vioif0_txrx/0 vioif0_txrx
0 30 3 1 200 fffff984484a16c0 scsibus0 sccomp
0 29 3 0 200 fffff984484a1280 pms0 pmsreset
0 28 3 1 200 fffff984483acac0 xcall/1 xcall
0 27 1 1 200 fffff984483ac680 softser/1
0 26 1 1 200 fffff984483ac240 softclk/1
0 25 1 1 200 fffff98448387a80 softbio/1
0 24 1 1 200 fffff98448387640 softnet/1
0 23 1 1 201 fffff98448387200 idle/1
0 22 3 1 200 fffff9857672da40 lnxsyswq lnxsyswq
0 21 3 1 200 fffff9857672d600 lnxubdwq lnxubdwq
0 20 3 1 200 fffff9857672d1c0 lnxpwrwq lnxpwrwq
0 19 3 1 200 fffff98576734a00 lnxlngwq lnxlngwq
0 18 3 1 200 fffff985767345c0 lnxhipwq lnxhipwq
0 17 3 1 200 fffff98576734180 lnxrcugc lnxrcugc
0 16 3 0 200 fffff985767539c0 sysmon smtaskq
0 15 3 1 200 fffff98576753580 pmfsuspend pmfsuspend
0 14 3 0 200 fffff98576753140 pmfevent pmfevent
0 13 3 1 200 fffff9857675e980 sopendfree sopendfr
0 12 3 0 200 fffff9857675e540 ifwdog ifwdog
0 11 3 0 200 fffff9857675e100 iflnkst iflnkst
0 10 3 1 200 fffff98577793940 nfssilly nfssilly
0 9 3 0 200 fffff98577793500 vdrain vdrain
0 8 3 1 200 fffff985777930c0 modunload mod_unld
0 7 3 0 200 fffff985777ba900 xcall/0 xcall
0 6 1 0 200 fffff985777ba4c0 softser/0
0 5 1 0 200 fffff985777ba080 softclk/0
0 4 1 0 200 fffff985777e98c0 softbio/0
0 3 1 0 200 fffff985777e9480 softnet/0
0 2 1 0 201 fffff985777e9040 idle/0
0 0 3 0 200 ffffffff86742d80 swapper uvm
[Locks tracked through LWPs]

****** LWP 1198.1198 (syz-executor3541) @ 0xfffff9845229dac0, l_stat=7

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xfffff9845229dac0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 829.829 (syz-executor3541) @ 0xfffff984535c2900, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:pmap_ctor+0x6d sys/arch/x86/x86/pmap.c:2860)
lock address : fffff9845295ed80
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0x6d
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xfffff984535c2900 last held: 0xfffff984535c2900
last locked* : netbsd:pmap_enter_ma+0x3c0
unlocked : netbsd:pmap_extract+0x2c8
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1239.1239 (syz-executor3541) @ 0xfffff98452c3e8c0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:uvmspace_alloc+0x339 uvm_map_setup sys/uvm/uvm_map.c:4788 [inline])
* Lock 0 (initialized at netbsd:uvmspace_alloc+0x339 uvmspace_init sys/uvm/uvm_map.c:4131 [inline])
* Lock 0 (initialized at netbsd:uvmspace_alloc+0x339 sys/uvm/uvm_map.c:4110)
lock address : fffff984535071b8
type : sleep/adaptive
initialized : netbsd:uvmspace_alloc+0x339
shared holds : 0 exclusive: 0
shares wanted: 1 exclusive: 0
relevant cpu : 0 last held: 65535
relevant lwp : 0xfffff98452c3e8c0 last held: 000000000000000000
last locked : netbsd:uvm_fault_internal+0x20b
unlocked* : netbsd:uvm_fault_lower_enter+0x88c
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

****** LWP 986.986 (syz-executor3541) @ 0xfffff984525c56c0, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:pmap_ctor+0x6d sys/arch/x86/x86/pmap.c:2860)
lock address : fffff9845295e980
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0x6d
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xfffff984525c56c0 last held: 0xfffff984525c56c0
last locked* : netbsd:pmap_enter_ma+0x3c0
unlocked : netbsd:pmap_extract+0x2c8
owner field : 0xfffff984525c56c0 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at netbsd:pmap_ctor+0x9b sys/arch/x86/x86/pmap.c:2861)
lock address : fffff9845295e988
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0x9b
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 1
relevant lwp : 0xfffff984525c56c0 last held: 000000000000000000
last locked : netbsd:pmap_find_ptp+0x266
unlocked* : netbsd:pmap_find_ptp+0x2c6
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

****** LWP 742.742 (dhcpcd) @ 0xfffff98452c3e480, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xfffff98452c3e480 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 466.466 (dhcpcd) @ 0xfffff98452ad7bc0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xfffff98452ad7bc0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 485.485 (dhcpcd) @ 0xfffff984526de2c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xfffff984526de2c0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 291.291 (dhcpcd) @ 0xfffff984527a7b80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xfffff984527a7b80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xfffff9857675e100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xfffff9857675e100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xfffff985777ba080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xfffff985777ba080 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff86742d80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff86742d80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu1:

* Lock 0 (initialized at netbsd:kprintf_init+0x72 sys/kern/subr_prf.c:155)
lock address : netbsd:kprintf_mtx
type : spin
initialized : netbsd:kprintf_init+0x72
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xfffff9845229dac0 last held: 0xfffff9845229dac0
last locked* : netbsd:kprintf_lock+0x50
unlocked : netbsd:kprintf_unlock+0x70
owner field : 0x0000000000000800 wait/spin: 0/1

PAGE FLAG PQ UOBJECT UANON
0xffffc98000007180 0045 00000000 0x0 0x0
0xffffc98000007200 0045 00000000 0x0 0x0
0xffffc98000007280 0045 00000000 0x0 0x0
0xffffc98000007300 0045 00000000 0x0 0x0
0xffffc98000007380 0045 00000000 0x0 0x0
0xffffc98000007400 0045 00000000 0x0 0x0
0xffffc98000007480 0045 00000000 0x0 0x0
0xffffc98000007500 0045 00000000 0x0 0x0
0xffffc98000007580 0045 00000000 0x0 0x0
0xffffc98000007600 0045 00000000 0x0 0x0
0xffffc98000007680 0041 00000000 0x0 0x0
0xffffc98000007700 0041 00000000 0x0 0x0
0xffffc98000007780 0041 00000000 0x0 0x0
0xffffc98000007800 0041 00000000 0x0 0x0
0xffffc98000007880 0045 00000000 0x0 0x0
0xffffc98000007900 0045 00000000 0x0 0x0
0xffffc98000007980 0041 00000000 0x0 0x0
0xffffc98000007a00 0041 00000000 0x0 0x0
0xffffc98000007a80 0041 00000000 0x0 0x0
0xffffc98000007b00 0041 00000000 0x0 0x0
0xffffc98000007b80 0041 00000000 0x0 0x0
0xffffc98000007c00 0041 00000000 0x0 0x0
0xffffc98000007c80 0041 00000000 0x0 0x0
0xffffc98000007d00 0041 00000000 0x0 0x0
0xffffc98000007d80 0041 00000000 0x0 0x0
0xffffc98000007e00 0041 00000000 0x0 0x0
0xffffc98000007e80 0041 00000000 0x0 0x0
0xffffc98000007f00 0041 00000000 0x0 0x0
0xffffc98000007f80 0041 00000000 0x0 0x0
0xffffc98000008000 0041 00000000 0x0 0x0
0xffffc98000008080 0041 00000000 0x0 0x0
0xffffc98000008100 0041 00000000 0x0 0x0
0xffffc98000008180 0041 00000000 0x0 0x0
0xffffc98000008200 0041 00000000 0x0 0x0
0xffffc98000008280 0041 00000000 0x0 0x0
0xffffc98000008300 0041 00000000 0x0 0x0
0xffffc98000008380 0041 00000000 0x0 0x0
0xffffc98000008400 0041 00000000 0x0 0x0
0xffffc98000008480 0041 00000000 0x0 0x0
0xffffc98000008500 0041 00000000 0x0 0x0
0xffffc98000008580 0041 00000000 0x0 0x0
0xffffc98000008600 0045 00000000 0x0 0x0
0xffffc98000008680 0041 00000000 0x0 0x0
0xffffc98000008700 0041 00000000 0x0 0x0
0xffffc98000008780 0041 00000000 0x0 0x0
0xffffc98000008800 0045 00000000 0x0 0x0
0xffffc98000008880 0041 00000000 0x0 0x0
0xffffc98000008900 0041 00000000 0x0 0x0
0xffffc98000008980 0041 00000000 0x0 0x0
0xffffc98000008a00 0041 00000000 0x0 0x0
0xffffc98000008a80 0041 00000000 0x0 0x0
0xffffc98000008b00 0041 00000000 0x0 0x0
0xffffc98000008b80 0041 00000000 0x0 0x0
0xffffc98000008c00 0041 00000000 0x0 0x0
0xffffc98000008c80 0041 00000000 0x0 0x0
0xffffc98000008d00 0041 00000000 0x0 0x0
0xffffc98000008d80 0041 00000000 0x0 0x0
0xffffc98000008e00 0041 00000000 0x0 0x0
0xffffc98000008e80 0041 00000000 0x0 0x0
0xffffc98000008f00 0041 00000000 0x0 0x0
0xffffc98000008f80 0041 00000000 0x0 0x0
0xffffc98000009000 0041 00000000 0x0 0x0
0xffffc98000009080 0041 00000000 0x0 0x0
0xffffc98000009100 0041 00000000 0x0 0x0
0xffffc98000009180 0041 00000000 0x0 0x0
0xffffc98000009200 0041 00000000 0x0 0x0
0xffffc98000009280 0041 00000000 0x0 0x0
0xffffc98000009300 0041 00000000 0x0 0x0
0xffffc98000009380 0041 00000000 0x0 0x0
0xffffc98000009400 0041 00000000 0x0 0x0
0xffffc98000009480 0045 00000000 0x0 0x0
0xffffc98000009500 0041 00000000 0x0 0x0
0xffffc98000009580 0041 00000000 0x0 0x0
0xffffc98000009600 0041 00000000 0x0 0x0
0xffffc98000009680 0041 00000000 0x0 0x0
0xffffc98000009700 0041 00000000 0x0 0x0
0xffffc98000009780 0041 00000000 0x0 0x0
0xffffc98000009800 0041 00000000 0x0 0x0
0xffffc98000009880 0041 00000000 0x0 0x0
0xffffc98000009900 0041 00000000 0x0 0x0
0xffffc98000009980 0041 00000000 0x0 0x0
0xffffc98000009a00 0041 00000000 0x0 0x0
0xffffc98000009a80 0045 00000000 0x0 0x0
0xffffc98000009b00 0041 00000000 0x0 0x0
0xffffc98000009b80 0041 00000000 0x0 0x0
0xffffc98000009c00 0041 00000000 0x0 0x0
0xffffc98000009c80 0041 00000000 0x0 0x0
0xffffc98000009d00 0041 00000000 0x0 0x0
0xffffc98000009d80 0041 00000000 0x0 0x0
0xffffc98000009e00 0041 00000000 0x0 0x0
0xffffc98000009e80 0041 00000000 0x0 0x0
0xffffc98000009f00 0041 00000000 0x0 0x0
0xffffc98000009f80 0041 00000000 0x0 0x0
0xffffc9800000a000 0041 00000000 0x0 0x0
0xffffc9800000a080 0041 00000000 0x0 0x0
0xffffc9800000a100 0041 00000000 0x0 0x0
0xffffc9800000a180 0041 00000000 0x0 0x0
0xffffc9800000a200 0041 00000000 0x0 0x0
0xffffc9800000a280 0041 00000000 0x0 0x0
0xffffc9800000a300 0041 00000000 0x0 0x0
0xffffc9800000a380 0041 00000000 0x0 0x0
0xffffc9800000a400 0041 00000000 0x0 0x0
0xffffc9800000a480 0041 00000000 0x0 0x0
0xffffc9800000a500 0041 00000000 0x0 0x0
0xffffc9800000a580 0041 00000000 0x0 0x0
0xffffc9800000a600 0041 00000000 0x0 0x0
0xffffc9800000a680 0041 00000000 0x0 0x0
0xffffc9800000a700 0041 00000000 0x0 0x0
0xffffc9800000a780 0041 00000000 0x0 0x0
0xffffc9800000a800 0041 00000000 0x0 0x0
0xffffc9800000a880 0041 00000000 0x0 0x0
0xffffc9800000a900 0041 00000000 0x0 0x0
0xffffc9800000a980 0041 00000000 0x0 0x0
0xffffc9800000aa00 0041 00000000 0x0 0x0
0xffffc9800000aa80 0041 00000000 0x0 0x0
0xffffc9800000ab00 0041 00000000 0x0 0x0
0xffffc9800000ab80 0041 00000000 0x0 0x0
0xffffc9800000ac00 0041 00000000 0x0 0x0
0xffffc9800000ac80 0041 00000000 0x0 0x0
0xffffc9800000ad00 0041 00000000 0x0 0x0
0xffffc9800000ad80 0041 00000000 0x0 0x0
0xffffc9800000ae00 0041 00000000 0x0 0x0
0xffffc9800000ae80 0045 00000000 0x0 0x0
0xffffc9800000af00 0045 00000000 0x0 0x0
0xffffc9800000af80 0045 00000000 0x0 0x0
0xffffc9800000b000 0041 00000000 0x0 0x0
0xffffc9800000b080 0041 00000000 0x0 0x0
0xffffc9800000b100 0041 00000000 0x0 0x0
0xffffc9800000b180 0045 00000000 0x0 0x0
0xffffc9800000b200 0041 00000000 0x0 0x0
0xffffc9800000b280 0045 00000000 0x0 0x0
0xffffc9800000b300 0045 00000000 0x0 0x0
0xffffc9800000b380 0045 00000000 0x0 0x0
0xffffc9800000b400 0041 00000000 0x0 0x0
0xffffc9800000b480 0041 00000000 0x0 0x0
0xffffc9800000b500 0045 00000000 0x0 0x0
0xffffc9800000b580 0045 00000000 0x0 0x0
0xffffc9800000b600 0045 00000000 0x0 0x0
0xffffc9800000b680 0045 00000000 0x0 0x0
0xffffc9800000b700 0045 00000000 0x0 0x0
0xffffc9800000b780 0045 00000000 0x0 0x0
0xffffc9800000b800 0045 00000000 0x0 0x0
0xffffc9800000b880 0041 00000000 0x0 0x0
0xffffc9800000b900 0045 00000000 0x0 0x0
0xffffc9800000b980 0045 00000000 0x0 0x0
0xffffc9800000ba00 0045 00000000 0x0 0x0
0xffffc9800000ba80 0045 00000000 0x0 0x0
0xffffc9800000bb00 0045 00000000 0x0 0x0
0xffffc9800000bb80 0045 00000000 0x0 0x0
0xffffc9800000bc00 0045 00000000 0x0 0x0
0xffffc9800000bc80 0041 00000000 0x0 0x0
0xffffc9800000bd00 0045 00000000 0x0 0x0
0xffffc9800000bd80 0045 00000000 0x0 0x0
0xffffc9800000be00 0045 00000000 0x0 0x0
0xffffc9800000be80 0045 00000000 0x0 0x0
0xffffc9800000bf00 0045 00000000 0x0 0x0
0xffffc9800000bf80 0045 00000000 0x0 0x0
0xffffc9800000c000 0045 00000000 0x0 0x0
0xffffc9800000c080 0041 00000000 0x0 0x0
0xffffc9800000c100 0045 00000000 0x0 0x0
0xffffc9800000c180 0045 00000000 0x0 0x0
0xffffc9800000c200 0045 00000000 0x0 0x0
0xffffc9800000c280 0045 00000000 0x0 0x0
0xffffc9800000c300 0045 00000000 0x0 0x0
0xffffc9800000c380 0045 00000000 0x0 0x0
0xffffc9800000c400 0045 00000000 0x0 0x0
0xffffc9800000c480 0045 00000000 0x0 0x0
0xffffc9800000c500 0045 00000000 0x0 0x0
0xffffc9800000c580 0045 00000000 0x0 0x0
0xffffc9800000c600 0045 00000000 0x0 0x0
0xffffc9800000c680 0045 00000000 0x0 0x0
0xffffc9800000c700 0041 00000000 0x0 0x0
0xffffc9800000c780 0041 00000000 0x0 0x0
0xffffc9800000c800 0045 00000000 0x0 0x0
0xffffc9800000c880 0045 00000000 0x0 0x0
0xffffc9800000c900 0045 00000000 0x0 0x0
0xffffc9800000c980 0045 00000000 0x0 0x0
0xffffc9800000ca00 0045 00000000 0x0 0x0
0xffffc9800000ca80 0041 00000000 0x0 0x0
0xffffc9800000cb00 0041 00000000 0x0 0x0
0xffffc9800000cb80 0041 00000000 0x0 0x0
0xffffc9800000cc00 0045 00000000 0x0 0x0
0xffffc9800000cc80 0045 00000000 0x0 0x0
0xffffc9800000cd00 0045 00000000 0x0 0x0
0xffffc9800000cd80 0041 00000000 0x0 0x0
0xffffc9800000ce00 0045 00000000 0x0 0x0
0xffffc9800000ce80 0041 00000000 0x0 0x0
0xffffc9800000cf00 0041 00000000 0x0 0x0
0xffffc9800000cf80 0041 00000000 0x0 0x0
0xffffc9800000d000 0041 00000000 0x0 0x0
0xffffc9800000d080 0045 00000000 0x0 0x0
0xffffc9800000d100 0041 00000000 0x0 0x0
0xffffc9800000d180 0041 00000000 0x0 0x0
0xffffc9800000d200 0041 00000000 0x0 0x0
0xffffc9800000d280 0041 00000000 0x0 0x0
0xffffc9800000d300 0045 00000000 0x0 0x0
0xffffc9800000d380 0041 00000000 0x0 0x0
0xffffc9800000d400 0041 00000000 0x0 0x0
0xffffc9800000d480 0045 00000000 0x0 0x0
0xffffc9800000d500 0041 00000000 0x0 0x0
0xffffc9800000d580 0041 00000000 0x0 0x0
0xffffc9800000d600 0041 00000000 0x0 0x0
0xffffc9800000d680 0045 00000000 0x0 0x0
0xffffc9800000d700 0041 00000000 0x0 0x0
0xffffc9800000d780 0045 00000000 0x0 0x0
0xffffc9800000d800 0041 00000000 0x0 0x0
0xffffc9800000d880 0045 00000000 0x0 0x0
0xffffc9800000d900 0041 00000000 0x0 0x0
0xffffc9800000d980 0041 00000000 0x0 0x0
0xffffc9800000da00 0041 00000000 0x0 0x0
0xffffc9800000da80 0041 00000000 0x0 0x0
0xffffc9800000db00 0045 00000000 0x0 0x0
0xffffc9800000db80 0045 00000000 0x0 0x0
0xffffc9800000dc00 0041 00000000 0x0 0x0
0xffffc9800000dc80 0041 00000000 0x0 0x0
0xffffc9800000dd00 0041 00000000 0x0 0x0
0xffffc9800000dd80 0041 00000000 0x0 0x0
0xffffc9800000de00 0041 00000000 0x0 0x0
0xffffc9800000de80 0041 00000000 0x0 0x0
0xffffc9800000df00 0045 00000000 0x0 0x0
0xffffc9800000df80 0045 00000000 0x0 0x0
0xffffc9800000e000 0045 00000000 0x0 0x0
0xffffc9800000e080 0041 00000000 0x0 0x0
0xffffc9800000e100 0041 00000000 0x0 0x0
0xffffc9800000e180 0045 00000000 0x0 0x0
0xffffc9800000e200 0041 00000000 0x0 0x0
0xffffc9800000e280 0045 00000000 0x0 0x0
0xffffc9800000e300 0045 00000000 0x0 0x0
0xffffc9800000e380 0041 00000000 0x0 0x0
0xffffc9800000e400 0045 00000000 0x0 0x0
0xffffc9800000e480 0041 00000000 0x0 0x0
0xffffc9800000e500 0045 00000000 0x0 0x0
0xffffc9800000e580 0041 00000000 0x0 0x0
0xffffc9800000e600 0045 00000000 0x0 0x0
0xffffc9800000e680 0041 00000000 0x0 0x0
0xffffc9800000e700 0041 00000000 0x0 0x0
0xffffc9800000e780 0041 00000000 0x0 0x0
0xffffc9800000e800 0045 00000000 0x0 0x0
0xffffc9800000e880 0041 00000000 0x0 0x0
0xffffc9800000e900 0041 00000000 0x0 0x0
0xffffc9800000e980 0041 00000000 0x0 0x0
0xffffc9800000ea00 0041 00000000 0x0 0x0
0xffffc9800000ea80 0045 00000000 0x0 0x0
0xffffc9800000eb00 0041 00000000 0x0 0x0
0xffffc9800000eb80 0045 00000000 0x0 0x0
0xffffc9800000ec00 0041 00000000 0x0 0x0
0xffffc9800000ec80 0045 00000000 0x0 0x0
0xffffc9800000ed00 0041 00000000 0x0 0x0
0xffffc9800000ed80 0041 00000000 0x0 0x0
0xffffc9800000ee00 0041 00000000 0x0 0x0
0xffffc9800000ee80 0041 00000000 0x0 0x0
0xffffc9800000ef00 0041 00000000 0x0 0x0
0xffffc9800000ef80 0041 00000000 0x0 0x0
0xffffc9800000f000 0041 00000000 0x0 0x0
0xffffc9800000f080 0045 00000000 0x0 0x0
0xffffc9800000f100 0041 00000000 0x0 0x0
0xffffc9800000f180 0041 00000000 0x0 0x0
0xffffc9800000f200 0041 00000000 0x0 0x0
0xffffc9800000f280 0045 00000000 0x0 0x0
0xffffc9800000f300 0041 00000000 0x0 0x0
0xffffc9800000f380 0041 00000000 0x0 0x0
0xffffc9800000f400 0045 00000000 0x0 0x0
0xffffc9800000f480 0041 00000000 0x0 0x0
0xffffc9800000f500 0041 00000000 0x0 0x0
0xffffc9800000f580 0041 00000000 0x0 0x0
0xffffc9800000f600 0041 00000000 0x0 0x0
0xffffc9800000f680 0041 00000000 0x0 0x0
0xffffc9800000f700 0041 00000000 0x0 0x0
0xffffc9800000f780 0041 00000000 0x0 0x0
0xffffc9800000f800 0041 00000000 0x0 0x0
0xffffc9800000f880 0045 00000000 0x0 0x0
0xffffc9800000f900 0041 00000000 0x0 0x0
0xffffc9800000f980 0045 00000000 0x0 0x0
0xffffc9800000fa00 0041 00000000 0x0 0x0
0xffffc9800000fa80 0041 00000000 0x0 0x0
0xffffc9800000fb00 0041 00000000 0x0 0x0
0xffffc9800000fb80 0041 00000000 0x0 0x0
0xffffc9800000fc00 0045 00000000 0x0 0x0
0xffffc9800000fc80 0041 00000000 0x0 0x0
0xffffc9800000fd00 0045 00000000 0x0 0x0
0xffffc9800000fd80 0041 00000000 0x0 0x0
0xffffc9800000fe00 0041 00000000 0x0 0x0
0xffffc9800000fe80 0041 00000000 0x0 0x0
0xffffc9800000ff00 0041 00000000 0x0 0x0
0xffffc9800000ff80 0041 00000000 0x0 0x0
0xffffc98000010000 0041 00000000 0x0 0x0
0xffffc98000010080 0045 00000000 0x0 0x0
0xffffc98000010100 0041 00000000 0x0 0x0
0xffffc98000010180 0045 00000000 0x0 0x0
0xffffc98000010200 0045 00000000 0x0 0x0
0xffffc98000010280 0041 00000000 0x0 0x0
0xffffc98000010300 0041 00000000 0x0 0x0
0xffffc98000010380 0041 00000000 0x0 0x0
0xffffc98000010400 0041 00000000 0x0 0x0
0xffffc98000010480 0041 00000000 0x0 0x0
0xffffc98000010500 0045 00000000 0x0 0x0
0xffffc98000010580 0041 00000000 0x0 0x0
0xffffc98000010600 0041 00000000 0x0 0x0
0xffffc98000010680 0045 00000000 0x0 0x0
0xffffc98000010700 0041 00000000 0x0 0x0
0xffffc98000010780 0041 00000000 0x0 0x0
0xffffc98000010800 0041 00000000 0x0 0x0
0xffffc98000010880 0041 00000000 0x0 0x0
0xffffc98000010900 0041 00000000 0x0 0x0
0xffffc98000010980 0045 00000000 0x0 0x0
0xffffc98000010a00 0045 00000000 0x0 0x0
0xffffc98000010a80 0041 00000000 0x0 0x0
0xffffc98000010b00 0041 00000000 0x0 0x0
0xffffc98000010b80 0041 00000000 0x0 0x0
0xffffc98000010c00 0041 00000000 0x0 0x0
0xffffc98000010c80 0045 00000000 0x0 0x0
0xffffc98000010d00 0041 00000000 0x0 0x0
0xffffc98000010d80 0041 00000000 0x0 0x0
0xffffc98000010e00 0041 00000000 0x0 0x0
0xffffc98000010e80 0045 00000000 0x0 0x0
0xffffc98000010f00 0041 00000000 0x0 0x0
0xffffc98000010f80 0041 00000000 0x0 0x0
0xffffc98000011000 0041 00000000 0x0 0x0
0xffffc98000011080 0041 00000000 0x0 0x0
0xffffc98000011100 0041 00000000 0x0 0x0
0xffffc98000011180 0041 00000000 0x0 0x0
0xffffc98000011200 0045 00000000 0x0 0x0
0xffffc98000011280 0041 00000000 0x0 0x0
0xffffc98000011300 0041 00000000 0x0 0x0
0xffffc98000011380 0041 00000000 0x0 0x0
0xffffc98000011400 0041 00000000 0x0 0x0
0xffffc98000011480 0045 00000000 0x0 0x0
0xffffc98000011500 0045 00000000 0x0 0x0
0xffffc98000011580 0041 00000000 0x0 0x0
0xffffc98000011600 0041 00000000 0x0 0x0
0xffffc98000011680 0041 00000000 0x0 0x0
0xffffc98000011700 0045 00000000 0x0 0x0
0xffffc98000011780 0045 00000000 0x0 0x0
0xffffc98000011800 0041 00000000 0x0 0x0
0xffffc98000011880 0041 00000000 0x0 0x0
0xffffc98000011900 0041 00000000 0x0 0x0
0xffffc98000011980 0041 00000000 0x0 0x0
0xffffc98000011a00 0041 00000000 0x0 0x0
0xffffc98000011a80 0041 00000000 0x0 0x0
0xffffc98000011b00 0041 00000000 0x0 0x0
0xffffc98000011b80 0041 00000000 0x0 0x0
0xffffc98000011c00 0041 00000000 0x0 0x0
0xffffc98000011c80 0041 00000000 0x0 0x0
0xffffc98000011d00 0041 00000000 0x0 0x0
0xffffc98000011d80 0041 00000000 0x0 0x0
0xffffc98000011e00 0045 00000000 0x0 0x0
0xffffc98000011e80 0041 00000000 0x0 0x0
0xffffc98000011f00 0041 00000000 0x0 0x0
0xffffc98000011f80 0041 00000000 0x0 0x0
0xffffc98000012000 0041 00000000 0x0 0x0
0xffffc98000012080 0041 00000000 0x0 0x0
0xffffc98000012100 0045 00000000 0x0 0x0
0xffffc98000012180 0045 00000000 0x0 0x0
0xffffc98000012200 0041 00000000 0x0 0x0
0xffffc98000012280 0045 00000000 0x0 0x0
0xffffc98000012300 0041 00000000 0x0 0x0
0xffffc98000012380 0041 00000000 0x0 0x0
0xffffc98000012400 0041 00000000 0x0 0x0
0xffffc98000012480 0041 00000000 0x0 0x0
0xffffc98000012500 0041 00000000 0x0 0x0
0xffffc98000012580 0041 00000000 0x0 0x0
0xffffc98000012600 0041 00000000 0x0 0x0
0xffffc98000012680 0041 00000000 0x0 0x0
0xffffc98000012700 0041 00000000 0x0 0x0
0xffffc98000012780 0041 00000000 0x0 0x0
0xffffc98000012800 0041 00000000 0x0 0x0
0xffffc98000012880 0041 00000000 0x0 0x0
0xffffc98000012900 0041 00000000 0x0 0x0
0xffffc98000012980 0041 00000000 0x0 0x0
0xffffc98000012a00 0041 00000000 0x0 0x0
0xffffc98000012a80 0041 00000000 0x0 0x0
0xffffc98000012b00 0041 00000000 0x0 0x0
0xffffc98000012b80 0041 00000000 0x0 0x0
0xffffc98000012c00 0041 00000000 0x0 0x0
0xffffc98000012c80 0041 00000000 0x0 0x0
0xffffc98000012d00 0041 00000000 0x0 0x0
0xffffc98000012d80 0041 00000000 0x0 0x0
0xffffc98000012e00 0041 00000000 0x0 0x0
0xffffc98000012e80 0041 00000000 0x0 0x0
0xffffc98000012f00 0041 00000000 0x0 0x0
0xffffc98000012f80 0041 00000000 0x0 0x0
0xffffc98000013000 0041 00000000 0x0 0x0
0xffffc98000013080 0045 00000000 0x0 0x0
0xffffc98000013100 0001 00000000 0x0 0x0
0xffffc98000013180 0001 00000000 0x0 0x0
0xffffc98000013200 0001 00000000 0x0 0x0
0xffffc98000013280 0001 00000000 0x0 0x0
0xffffc98000013300 0001 00000000 0x0 0x0
0xffffc98000013380 0001 00000000 0x0 0x0
0xffffc98000013400 0001 00000000 0x0 0x0
0xffffc98000013480 0001 00000000 0x0 0x0
0xffffc98000013500 0001 00000000 0x0 0x0
0xffffc98000013580 0001 00000000 0x0 0x0
0xffffc98000013600 0001 00000000 0x0 0x0
0xffffc98000013680 0001 00000000 0x0 0x0
0xffffc98000013700 0001 00000000 0x0 0x0
0xffffc98000013780 0001 00000000 0x0 0x0
0xffffc98000013800 0001 00000000 0x0 0x0
0xffffc98000013880 0001 00000000 0x0 0x0
0xffffc98000013900 0001 00000000 0x0 0x0
0xffffc98000013980 0001 00000000 0x0 0x0
0xffffc98000013a00 0001 00000000 0x0 0x0
0xffffc98000013a80 0001 00000000 0x0 0x0
0xffffc98000013b00 0001 00000000 0x0 0x0
0xffffc98000013b80 0001 00000000 0x0 0x0
0xffffc98000013c00 0001 00000000 0x0 0x0
0xffffc98000013c80 0001 00000000 0x0 0x0
0xffffc98000013d00 0001 00000000 0x0 0x0
0xffffc98000013d80 0001 00000000 0x0 0x0
0xffffc98000013e00 0001 00000000 0x0 0x0
0xffffc98000013e80 0001 00000000 0x0 0x0
0xffffc98000013f00 0001 00000000 0x0 0x0
0xffffc98000013f80 0001 00000000 0x0 0x0
0xffffc98000014000 0001 00000000 0x0 0x0
0xffffc98000014080 0001 00000000 0x0 0x0
0xffffc98000014100 0001 00000000 0x0 0x0
0xffffc98000014180 0001 00000000 0x0 0x0
0xffffc98000014200 0001 00000000 0x0 0x0
0xffffc98000014280 0001 00000000 0x0 0x0
0xffffc98000014300 0001 00000000 0x0 0x0
0xffffc98000014380 0001 00000000 0x0 0x0
0xffffc98000014400 0001 00000000 0x0 0x0
0xffffc98000014480 0001 00000000 0x0 0x0
0xffffc98000014500 0001 00000000 0x0 0x0
0xffffc98000014580 0001 00000000 0x0 0x0
0xffffc98000014600 0001 00000000 0x0 0x0
0xffffc98000014680 0001 00000000 0x0 0x0
0xffffc98000014700 0001 00000000 0x0 0x0
0xffffc98000014780 0001 00000000 0x0 0x0
0xffffc98000014800 0001 00000000 0x0 0x0
0xffffc98000014880 0001 00000000 0x0 0x0
0xffffc98000014900 0001 00000000 0x0 0x0
0xffffc98000014980 0001 00000000 0x0 0x0
0xffffc98000014a00 0001 00000000 0x0 0x0
0xffffc98000014a80 0001 00000000 0x0 0x0
0xffffc98000014b00 0001 00000000 0x0 0x0
0xffffc98000014b80 0001 00000000 0x0 0x0
0xffffc98000014c00 0041 00000000 0x0 0x0
0xffffc98000014c80 0041 00000000 0x0 0x0
0xffffc98000014d00 0041 00000000 0x0 0x0
0xffffc98000014d80 0041 00000000 0x0 0x0
0xffffc98000014e00 0041 00000000 0x0 0x0
0xffffc98000014e80 0041 00000000 0x0 0x0
0xffffc98000014f00 0041 00000000 0x0 0x0
0xffffc98000014f80 0041 00000000 0x0 0x0
0xffffc98000015000 0041 00000000 0x0 0x0
0xffffc98000015080 0041 00000000 0x0 0x0
0xffffc98000015100 0041 00000000 0x0 0x0
0xffffc98000015180 0041 00000000 0x0 0x0
0xffffc98000015200 0041 00000000 0x0 0x0
0xffffc98000015280 0041 00000000 0x0 0x0
0xffffc98000015300 0041 00000000 0x0 0x0
0xffffc98000015380 0041 00000000 0x0 0x0
0xffffc98000015400 0041 00000000 0x0 0x0
0xffffc98000015480 0041 00000000 0x0 0x0
0xffffc98000015500 0041 00000000 0x0 0x0
0xffffc98000015580 0041 00000000 0x0 0x0
0xffffc98000015600 0041 00000000 0x0 0x0
0xffffc98000015680 0041 00000000 0x0 0x0
0xffffc98000015700 0041 00000000 0x0 0x0
0xffffc98000015780 0041 00000000 0x0 0x0
0xffffc98000015800 0041 00000000 0x0 0x0
0xffffc98000015880 0041 00000000 0x0 0x0
0xffffc98000015900 0041 00000000 0x0 0x0
0xffffc98000015980 0041 00000000 0x0 0x0
0xffffc98000015a00 0041 00000000 0x0 0x0
0xffffc98000015a80 0041 00000000 0x0 0x0
0xffffc98000015b00 0041 00000000 0x0 0x0
0xffffc98000015b80 0041 00000000 0x0 0x0
0xffffc98000015c00 0041 00000000 0x0 0x0
0xffffc98000015c80 0041 00000000 0x0 0x0
0xffffc98000015d00 0041 00000000 0x0 0x0
0xffffc98000015d80 0041 00000000 0x0 0x0
0xffffc98000015e00 0041 00000000 0x0 0x0
0xffffc98000015e80 0041 00000000 0x0 0x0
0xffffc98000015f00 0041 00000000 0x0 0x0
0xffffc98000015f80 0041 00000000 0x0 0x0
0xffffc98000016000 0041 00000000 0x0 0x0
0xffffc98000016080 0041 00000000 0x0 0x0
0xffffc98000016100 0001 00000000 0x0 0x0
0xffffc98000016180 0001 00000000 0x0 0x0
0xffffc98000016200 0001 00000000 0x0 0x0
0xffffc98000016280 0001 00000000 0x0 0x0
0xffffc98000016300 0001 00000000 0x0 0x0
0xffffc98000016380 0001 00000000 0x0 0x0
0xffffc98000016400 0001 00000000 0x0 0x0
0xffffc98000016480 0001 00000000 0x0 0x0
0xffffc98000016500 0001 00000000 0x0 0x0
0xffffc98000016580 0001 00000000 0x0 0x0
0xffffc98000016600 0001 00000000 0x0 0x0
0xffffc98000016680 0001 00000000 0x0 0x0
0xffffc98000016700 0001 00000000 0x0 0x0
0xffffc98000016780 0001 00000000 0x0 0x0
0xffffc98000016800 0001 00000000 0x0 0x0
0xffffc98000016880 0001 00000000 0x0 0x0
0xffffc98000016900 0001 00000000 0x0 0x0
0xffffc98000016980 0001 00000000 0x0 0x0
0xffffc98000016a00 0001 00000000 0x0 0x0
0xffffc98000016a80 0001 00000000 0x0 0x0
0xffffc98000016b00 0001 00000000 0x0 0x0
0xffffc98000016b80 0001 00000000 0x0 0x0
0xffffc98000016c00 0001 00000000 0x0 0x0
0xffffc98000016c80 0001 00000000 0x0 0x0
0xffffc98000016d00 0001 00000000 0x0 0x0
0xffffc98000016d80 0001 00000000 0x0 0x0
0xffffc98000016e00 0001 00000000 0x0 0x0
0xffffc98000016e80 0001 00000000 0x0 0x0
0xffffc98000016f00 0001 00000000 0x0 0x0
0xffffc98000016f80 0001 00000000 0x0 0x0
0xffffc98000017000 0001 00000000 0x0 0x0
0xffffc98000017080 0001 00000000 0x0 0x0
0xffffc98000017100 0001 00000000 0x0 0x0
0xffffc98000017180 0001 00000000 0x0 0x0
0xffffc98000017200 0001 00000000 0x0 0x0
0xffffc98000017280 0001 00000000 0x0 0x0
0xffffc98000017300 0001 00000000 0x0 0x0
0xffffc98000017380 0001 00000000 0x0 0x0
0xffffc98000017400 0001 00000000 0x0 0x0
0xffffc98000017480 0001 00000000 0x0 0x0
0xffffc98000017500 0001 00000000 0x0 0x0
0xffffc98000017580 0001 00000000 0x0 0x0
0xffffc98000017600 0001 00000000 0x0 0x0
0xffffc98000017680 0001 00000000 0x0 0x0
0xffffc98000017700 0001 00000000 0x0 0x0
0xffffc98000017780 0001 00000000 0x0 0x0
0xffffc98000017800 0001 00000000 0x0 0x0
0xffffc98000017880 0001 00000000 0x0 0x0
0xffffc98000017900 0001 00000000 0x0 0x0
0xffffc98000017980 0001 00000000 0x0 0x0
0xffffc98000017a00 0001 00000000 0x0 0x0
0xffffc98000017a80 0001 00000000 0x0 0x0
0xffffc98000017b00 0001 00000000 0x0 0x0
0xffffc98000017b80 0001 00000000 0x0 0x0
0xffffc98000017c00 0041 00000000 0x0 0x0
0xffffc98000017c80 0041 00000000 0x0 0x0
0xffffc98000017d00 0041 00000000 0x0 0x0
0xffffc98000017d80 0041 00000000 0x0 0x0
0xffffc98000017e00 0041 00000000 0x0 0x0
0xffffc98000017e80 0041 00000000 0x0 0x0
0xffffc98000017f00 0041 00000000 0x0 0x0
0xffffc98000017f80 0041 00000000 0x0 0x0
0xffffc98000018000 0041 00000000 0x0 0x0
0xffffc98000018080 0041 00000000 0x0 0x0
0xffffc98000018100 0041 00000000 0x0 0x0
0xffffc98000018180 0041 00000000 0x0 0x0
0xffffc98000018200 0041 00000000 0x0 0x0
0xffffc98000018280 0041 00000000 0x0 0x0
0xffffc98000018300 0041 00000000 0x0 0x0
0xffffc98000018380 0041 00000000 0x0 0x0
0xffffc98000018400 0041 00000000 0x0 0x0
0xffffc98000018480 0041 00000000 0x0 0x0
0xffffc98000018500 0041 00000000 0x0 0x0
0xffffc98000018580 0041 00000000 0x0 0x0
0xffffc98000018600 0041 00000000 0x0 0x0
0xffffc98000018680 0041 00000000 0x0 0x0
0xffffc98000018700 0041 00000000 0x0 0x0
0xffffc98000018780 0041 00000000 0x0 0x0
0xffffc98000018800 0041 00000000 0x0 0x0
0xffffc98000018880 0041 00000000 0x0 0x0
0xffffc98000018900 0041 00000000 0x0 0x0
0xffffc98000018980 0041 00000000 0x0 0x0
0xffffc98000018a00 0041 00000000 0x0 0x0
0xffffc98000018a80 0041 00000000 0x0 0x0
0xffffc98000018b00 0041 00000000 0x0 0x0
0xffffc98000018b80 0041 00000000 0x0 0x0
0xffffc98000018c00 0041 00000000 0x0 0x0
0xffffc98000018c80 0041 00000000 0x0 0x0
0xffffc98000018d00 0041 00000000 0x0 0x0
0xffffc98000018d80 0041 00000000 0x0 0x0
0xffffc98000018e00 0041 00000000 0x0 0x0
0xffffc98000018e80 0041 00000000 0x0 0x0
0xffffc98000018f00 0041 00000000 0x0 0x0
0xffffc98000018f80 0041 00000000 0x0 0x0
0xffffc98000019000 0041 00000000 0x0 0x0
0xffffc98000019080 0041 00000000 0x0 0x0
0xffffc98000019100 0001 00000000 0x0 0x0
0xffffc98000019180 0001 00000000 0x0 0x0
0xffffc98000019200 0001 00000000 0x0 0x0
0xffffc98000019280 0001 00000000 0x0 0x0
0xffffc98000019300 0001 00000000 0x0 0x0
0xffffc98000019380 0001 00000000 0x0 0x0
0xffffc98000019400 0001 00000000 0x0 0x0
0xffffc98000019480 0001 00000000 0x0 0x0
0xffffc98000019500 0001 00000000 0x0 0x0
0xffffc98000019580 0001 00000000 0x0 0x0
0xffffc98000019600 0001 00000000 0x0 0x0
0xffffc98000019680 0001 00000000 0x0 0x0
0xffffc98000019700 0001 00000000 0x0 0x0
0xffffc98000019780 0001 00000000 0x0 0x0
0xffffc98000019800 0001 00000000 0x0 0x0
0xffffc98000019880 0001 00000000 0x0 0x0
0xffffc98000019900 0001 00000000 0x0 0x0
0xffffc98000019980 0001 00000000 0x0 0x0
0xffffc98000019a00 0001 00000000 0x0 0x0
0xffffc98000019a80 0001 00000000 0x0 0x0
0xffffc98000019b00 0001 00000000 0x0 0x0
0xffffc98000019b80 0001 00000000 0x0 0x0
0xffffc98000019c00 0001 00000000 0x0 0x0
0xffffc98000019c80 0001 00000000 0x0 0x0
0xffffc98000019d00 0001 00000000 0x0 0x0
0xffffc98000019d80 0001 00000000 0x0 0x0
0xffffc98000019e00 0001 00000000 0x0 0x0
0xffffc98000019e80 0001 00000000 0x0 0x0
0xffffc98000019f00 0001 00000000 0x0 0x0
0xffffc98000019f80 0001 00000000 0x0 0x0
0xffffc9800001a000 0001 00000000 0x0 0x0
0xffffc9800001a080 0001 00000000 0x0 0x0
0xffffc9800001a100 0001 00000000 0x0 0x0
0xffffc9800001a180 0001 00000000 0x0 0x0
0xffffc9800001a200 0001 00000000 0x0 0x0
0xffffc9800001a280 0001 00000000 0x0 0x0
0xffffc9800001a300 0001 00000000 0x0 0x0
0xffffc9800001a380 0001 00000000 0x0 0x0
0xffffc9800001a400 0001 00000000 0x0 0x0
0xffffc9800001a480 0001 00000000 0x0 0x0
0xffffc9800001a500 0001 00000000 0x0 0x0
0xffffc9800001a580 0001 00000000 0x0 0x0
0xffffc9800001a600 0001 00000000 0x0 0x0
0xffffc9800001a680 0001 00000000 0x0 0x0
0xffffc9800001a700 0001 00000000 0x0 0x0
0xffffc9800001a780 0001 00000000 0x0 0x0
0xffffc9800001a800 0001 00000000 0x0 0x0
0xffffc9800001a880 0001 00000000 0x0 0x0
0xffffc9800001a900 0001 00000000 0x0 0x0
0xffffc9800001a980 0001 00000000 0x0 0x0
0xffffc9800001aa00 0001 00000000 0x0 0x0
0xffffc9800001aa80 0001 00000000 0x0 0x0
0xffffc9800001ab00 0001 00000000 0x0 0x0
0xffffc9800001ab80 0001 00000000 0x0 0x0
0xffffc9800001ac00 0041 00000000 0x0 0x0
0xffffc9800001ac80 0041 00000000 0x0 0x0
0xffffc9800001ad00 0041 00000000 0x0 0x0
0xffffc9800001ad80 0041 00000000 0x0 0x0
0xffffc9800001ae00 0041 00000000 0x0 0x0
0xffffc9800001ae80 0041 00000000 0x0 0x0
0xffffc9800001af00 0041 00000000 0x0 0x0
0xffffc9800001af80 0041 00000000 0x0 0x0
0xffffc9800001b000 0041 00000000 0x0 0x0
0xffffc9800001b080 0041 00000000 0x0 0x0
0xffffc9800001b100 0041 00000000 0x0 0x0
0xffffc9800001b180 0041 00000000 0x0 0x0
0xffffc9800001b200 0041 00000000 0x0 0x0
0xffffc9800001b280 0041 00000000 0x0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages