panic: port NUM configuration NUM interface 0kernel diagnostic assertion "ret == NUM" failed: file "/syzkaller/managers

0 views
Skip to first unread message

syzbot

unread,
Jan 8, 2022, 2:55:21 PM1/8/22
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: faadc77dc789 place additional parens around multiline stri..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=12c88f53b00000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=95d4852ea931f775cf35
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=10130507b00000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+95d485...@syzkaller.appspotmail.com

[ 55.5887835] uhidev1 at uhub4panic: port 1 configuration 1 interface 0kernel diagnostic assertion "ret == 0" failed: file "/syzkaller/managers/ci2-netbsd/kernel/sys/dev/usb/vhci.c", line 1054

[ 55.6073282] uhidev1: syz (0x0000) syz (0x0000), rev 0.00/0.40, addr 2, iclass 3/1
[ 55.6073282] cpu0: Begin traceback...
[ 55.6287677] vpanic() at netbsd:vpanic+0x258 sys/kern/subr_prf.c:290
[ 55.6587679] _sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x202c
[ 55.6887670] vhci_fd_close() at netbsd:vhci_fd_close+0xd1 sys/dev/usb/vhci.c:1054
[ 55.7187664] closef() at netbsd:closef+0x152 sys/kern/kern_descrip.c:832
[ 55.7487672] fd_close() at netbsd:fd_close+0x340 sys/kern/kern_descrip.c:715
[ 55.7787662] sys_close() at netbsd:sys_close+0x3e sys/kern/sys_descrip.c:516
[ 55.8087661] syscall() at netbsd:syscall+0x25a sy_call sys/sys/syscallvar.h:65 [inline]
[ 55.8087661] syscall() at netbsd:syscall+0x25a sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 55.8087661] syscall() at netbsd:syscall+0x25a sys/arch/x86/x86/syscall.c:138
[ 55.8187674] --- syscall (number 6) ---
[ 55.8287685] netbsd:syscall+0x25a:
[ 55.8287685] cpu0: End traceback...
[ 55.8416745] fatal breakpoint trap in supervisor mode
[ 55.8416745] trap type 1 code 0 rip 0xffffffff80220a2d cs 0x8 rflags 0x282 cr2 0xa41000 ilevel 0 rsp 0xffffc7019dc42b20
[ 55.8572924] curlwp 0xffffc70013307940 pid 1469.1468 lowest kstack 0xffffc7019dc3b2c0
Stopped in pid 1469.1468 (syz-executor.2) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0x105 sys/ddb/db_panic.c:69
vpanic() at netbsd:vpanic+0x258 sys/kern/subr_prf.c:290
_sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x202c
vhci_fd_close() at netbsd:vhci_fd_close+0xd1 sys/dev/usb/vhci.c:1054
closef() at netbsd:closef+0x152 sys/kern/kern_descrip.c:832
fd_close() at netbsd:fd_close+0x340 sys/kern/kern_descrip.c:715
sys_close() at netbsd:sys_close+0x3e sys/kern/sys_descrip.c:516
syscall() at netbsd:syscall+0x25a sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x25a sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x25a sys/arch/x86/x86/syscall.c:138
--- syscall (number 6) ---
netbsd:syscall+0x25a:
Panic string: kernel diagnostic assertion "ret == 0" failed: file "/syzkaller/managers/ci2-netbsd/kernel/sys/dev/usb/vhci.c", line 1054
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
1604 1765 2 1 0 ffffc70013352580 syz-executor.0
1604 1463 2 0 0 ffffc7001267c340 syz-executor.0
1604 1604 2 1 10000000 ffffc70012ce46c0 syz-executor.0
1384 1466 3 1 180 ffffc7001332f540 syz-executor.1 parked
1384 1639 2 0 140 ffffc70013352140 syz-executor.1
1384 1384 2 0 10000140 ffffc70013307500 syz-executor.1
1469 >1468 7 0 0 ffffc70013307940 syz-executor.2
1469 1485 2 0 0 ffffc700133070c0 syz-executor.2
1469 1469 2 1 10000000 ffffc70012d7b900 syz-executor.2
1460 1462 2 0 0 ffffc70012d27740 syz-executor.5
1460 1497 2 1 40000 ffffc70012d27300 syz-executor.5
1460 1460 2 1 10040000 ffffc70012d61040 syz-executor.5
1461 1203 3 0 40180 ffffc70012cf2b40 syz-executor.4 parked
1461 579 2 0 40140 ffffc70012d7b4c0 syz-executor.4
1461 1461 2 0 10040140 ffffc70012d34340 syz-executor.4
1490 590 3 1 180 ffffc70012cf22c0 syz-executor.3 parked
1490 585 2 1 40140 ffffc70012cb91c0 syz-executor.3
1490 1490 2 0 10000140 ffffc70012ce4280 syz-executor.3
1186 1186 2 0 140 ffffc70013cfe6c0 syz-executor.1
1237 1237 2 0 140 ffffc70013cfe280 syz-executor.5
982 982 2 0 140 ffffc70013ccba80 syz-executor.4
1193 1193 2 0 140 ffffc70013ccb200 syz-executor.3
972 972 2 1 140 ffffc70013cb8a40 syz-executor.2
1151 1151 2 1 140 ffffc70013cb8600 syz-executor.0
1105 989 3 0 180 ffffc70013ccb640 syz-execprog kqueue
1105 1001 3 1 180 ffffc70013cb81c0 syz-execprog parked
1105 1194 3 0 180 ffffc700133a2ac0 syz-execprog parked
1105 983 3 0 180 ffffc700133a2680 syz-execprog parked
1105 421 3 0 180 ffffc700133a2240 syz-execprog parked
1105 1130 3 1 180 ffffc70012a8e080 syz-execprog parked
1105 1191 3 1 180 ffffc70013c225c0 syz-execprog parked
1105 1223 3 0 180 ffffc70013441980 syz-execprog parked
1105 1222 3 1 180 ffffc700120b7b40 syz-execprog parked
1105 1105 3 1 180 ffffc70012b310c0 syz-execprog parked
1086 1086 3 0 180 ffffc70012a8e900 sshd select
1070 1070 3 0 180 ffffc70013435500 getty nanoslp
1069 1069 3 1 180 ffffc7001267cbc0 getty nanoslp
1126 1126 3 1 180 ffffc700134649c0 getty nanoslp
1115 1115 3 1 1c0 ffffc70013464140 getty ttyraw
1093 1093 3 1 180 ffffc7001337d1c0 sshd select
953 953 3 1 180 ffffc70012cf2700 powerd kqueue
689 689 3 1 180 ffffc700133b6b00 syslogd kqueue
602 602 3 0 180 ffffc70012be3ac0 dhcpcd poll
739 739 3 0 180 ffffc70012c70900 dhcpcd poll
464 464 3 0 180 ffffc70012be3680 dhcpcd poll
587 587 3 1 180 ffffc70012c37300 dhcpcd poll
289 289 3 0 180 ffffc70012d7b080 dhcpcd poll
288 288 3 0 180 ffffc70012d618c0 dhcpcd poll
351 351 3 0 180 ffffc70012d61480 dhcpcd poll
1 1 3 1 180 ffffc700127f49c0 init wait
0 968 3 0 200 ffffc7001295fac0 physiod physiod
0 194 3 1 200 ffffc70012979b00 pooldrain pooldrain
0 > 193 7 1 240 ffffc700129796c0 ioflush
0 192 3 0 200 ffffc70012979280 pgdaemon pgdaemon
0 168 3 1 200 ffffc7001295f240 usb7 usbevt
0 166 3 1 200 ffffc70012916a80 usb6 usbevt
0 164 2 0 240 ffffc70012916640 usb5
0 163 3 1 240 ffffc70012916200 usb4 usbxfer
0 31 2 0 240 ffffc700128c8a40 usb3
0 63 3 1 200 ffffc700128c8600 usb2 usbevt
0 126 3 0 240 ffffc700128c81c0 usb1 usbxfer
0 125 3 1 240 ffffc70012859a00 usb0 usbxfer
0 124 3 1 200 ffffc700128595c0 usbtask-dr usbtsk
0 123 3 0 200 ffffc700120b36c0 usbtask-hc usbtsk
0 122 3 1 200 ffffc70012859180 npfgc0 npfgcw
0 121 3 1 200 ffffc700127f4580 rt_free rt_free
0 120 3 1 200 ffffc700127f4140 unpgc unpgc
0 119 3 0 200 ffffc700127eb980 key_timehandler key_timehandler
0 118 3 1 200 ffffc700127eb540 icmp6_wqinput/1 icmp6_wqinput
0 117 3 0 200 ffffc700127eb100 icmp6_wqinput/0 icmp6_wqinput
0 116 3 0 200 ffffc700127e2940 nd6_timer nd6_timer
0 115 3 1 200 ffffc700127e2500 carp6_wqinput/1 carp6_wqinput
0 114 3 0 200 ffffc700127e20c0 carp6_wqinput/0 carp6_wqinput
0 113 3 1 200 ffffc700127d4900 carp_wqinput/1 carp_wqinput
0 112 3 0 200 ffffc700127d44c0 carp_wqinput/0 carp_wqinput
0 111 3 1 200 ffffc700127d4080 icmp_wqinput/1 icmp_wqinput
0 110 3 0 200 ffffc700127c48c0 icmp_wqinput/0 icmp_wqinput
0 109 3 0 200 ffffc700127c4480 rt_timer rt_timer
0 108 3 0 200 ffffc700127c4040 vmem_rehash vmem_rehash
0 107 3 0 200 ffffc7001267c780 entbutler entropy
0 98 3 1 200 ffffc700120b7700 viomb balloon
0 97 3 1 200 ffffc700120b72c0 vioif0_txrx/1 vioif0_txrx
0 96 3 0 200 ffffc700120b3b00 vioif0_txrx/0 vioif0_txrx
0 29 3 0 200 ffffc700120b3280 scsibus0 sccomp
0 28 3 0 200 ffffc70010cb9ac0 pms0 pmsreset
0 27 3 1 200 ffffc70010cb9680 xcall/1 xcall
0 26 1 1 200 ffffc70010cb9240 softser/1
0 25 1 1 200 ffffc70010cb8a80 softclk/1
0 24 1 1 200 ffffc70010cb8640 softbio/1
0 23 1 1 200 ffffc70010cb8200 softnet/1
0 22 1 1 201 ffffc7000fb55a40 idle/1
0 21 3 0 200 ffffc7000fb55600 lnxsyswq lnxsyswq
0 20 3 0 200 ffffc7000fb551c0 lnxubdwq lnxubdwq
0 19 3 0 200 ffffc7000fb53a00 lnxpwrwq lnxpwrwq
0 18 3 0 200 ffffc7000fb535c0 lnxlngwq lnxlngwq
0 17 3 0 200 ffffc7000fb53180 lnxhipwq lnxhipwq
0 16 3 0 200 ffffc7000fb4b9c0 lnxrcugc lnxrcugc
0 15 3 0 200 ffffc7000fb4b580 sysmon smtaskq
0 14 3 0 200 ffffc7000fb4b140 pmfsuspend pmfsuspend
0 13 3 0 200 ffffc7000fb47980 pmfevent pmfevent
0 12 3 0 200 ffffc7000fb47540 sopendfree sopendfr
0 11 3 0 200 ffffc7000fb47100 iflnkst iflnkst
0 10 3 0 200 ffffc7000fb3c940 nfssilly nfssilly
0 9 3 0 200 ffffc7000fb3c500 vdrain vdrain
0 8 3 1 200 ffffc7000fb3c0c0 modunload mod_unld
0 7 3 0 200 ffffc7000fb32900 xcall/0 xcall
0 6 1 0 200 ffffc7000fb324c0 softser/0
0 5 1 0 200 ffffc7000fb32080 softclk/0
0 4 1 0 200 ffffc7000fb308c0 softbio/0
0 3 1 0 200 ffffc7000fb30480 softnet/0
0 2 1 0 201 ffffc7000fb30040 idle/0
0 0 2 0 240 ffffffff8334fd80 swapper
[Locks tracked through LWPs]

****** LWP 1604.1765 (syz-executor.0) @ 0xffffc70013352580, l_stat=2

*** Locks held:

* Lock 0 (initialized at vhci_attach)
lock address : 0xffffc700126866d8 type : sleep/adaptive
initialized : 0xffffffff80bf5077
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc70013352580 last held: 0xffffc70013352580
last locked* : 0xffffffff80bf6d3d unlocked : 0xffffffff80bf7062
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1469.1485 (syz-executor.2) @ 0xffffc700133070c0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at uhub_attach)
lock address : 0xffffc700128cfa20 type : sleep/adaptive
initialized : 0xffffffff80728726
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 1
relevant lwp : 0xffffc700133070c0 last held: 000000000000000000
last locked : 0xffffffff8072718d unlocked*: 0xffffffff8072729c
owner field : 0xffffc700133070c0 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 1460.1462 (syz-executor.5) @ 0xffffc70012d27740, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at vhci_attach)
lock address : 0xffffc700126966d8 type : sleep/adaptive
initialized : 0xffffffff80bf5077
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 2
relevant cpu : 0 last held: 1
relevant lwp : 0xffffc70012d27740 last held: 000000000000000000
last locked : 0xffffffff80bf6d3d unlocked*: 0xffffffff80bf7062
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 1460.1497 (syz-executor.5) @ 0xffffc70012d27300, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at vhci_attach)
lock address : 0xffffc700126966d8 type : sleep/adaptive
initialized : 0xffffffff80bf5077
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 2
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc70012d27300 last held: 000000000000000000
last locked : 0xffffffff80bf6d3d unlocked*: 0xffffffff80bf7062
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 739.739 (dhcpcd) @ 0xffffc70012c70900, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc70012c70900 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 464.464 (dhcpcd) @ 0xffffc70012be3680, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc70012be3680 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 288.288 (dhcpcd) @ 0xffffc70012d618c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc70012d618c0 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 351.351 (dhcpcd) @ 0xffffc70012d61480, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc70012d61480 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.163 (usb4) @ 0xffffc70012916200, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at kprintf_init)
lock address : 0xffffffff83571d60 type : spin
initialized : 0xffffffff81be0cc5
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 0
relevant lwp : 0xffffc70012916200 last held: 000000000000000000
last locked : 0xffffffff81be579d unlocked*: 0xffffffff81be0d94
owner field : 0x0000000000000800 wait/spin: 0/1

****** LWP 0.11 (iflnkst) @ 0xffffc7000fb47100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc7000fb47100 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffffc7000fb32080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffc7000fb32080 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff8334fd80, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff83464440 type : sleep/adaptive
initialized : 0xffffffff81b35e61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff8334fd80 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu1:

* Lock 0 (initialized at main)
lock address : 0xffffffff83464340 type : spin
initialized : 0xffffffff81f26ed4
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffc700129796c0 last held: 0xffffc70012916200
last locked* : 0xffffffff81b6a8c0 unlocked : 0xffffffff81aebc2e
curcpu holds : 0 wanted by: 000000000000000000

PAGE FLAG PQ UOBJECT UANON
0xffffc70000017180 0041 00000000 0x0 0x0
0xffffc70000017200 0041 00000000 0x0 0x0
0xffffc70000017280 0041 00000000 0x0 0x0
0xffffc70000017300 0041 00000000 0x0 0x0
0xffffc70000017380 0041 00000000 0x0 0x0
0xffffc70000017400 0041 00000000 0x0 0x0
0xffffc70000017480 0041 00000000 0x0 0x0
0xffffc70000017500 0041 00000000 0x0 0x0
0xffffc70000017580 0041 00000000 0x0 0x0
0xffffc70000017600 0041 00000000 0x0 0x0
0xffffc70000017680 0041 00000000 0x0 0x0
0xffffc70000017700 0041 00000000 0x0 0x0
0xffffc70000017780 0041 00000000 0x0 0x0
0xffffc70000017800 0041 00000000 0x0 0x0
0xffffc70000017880 0041 00000000 0x0 0x0
0xffffc70000017900 0041 00000000 0x0 0x0
0xffffc70000017980 0041 00000000 0x0 0x0
0xffffc70000017a00 0041 00000000 0x0 0x0
0xffffc70000017a80 0041 00000000 0x0 0x0
0xffffc70000017b00 0041 00000000 0x0 0x0
0xffffc70000017b80 0041 00000000 0x0 0x0
0xffffc70000017c00 0041 00000000 0x0 0x0
0xffffc70000017c80 0041 00000000 0x0 0x0
0xffffc70000017d00 0041 00000000 0x0 0x0
0xffffc70000017d80 0041 00000000 0x0 0x0
0xffffc70000017e00 0041 00000000 0x0 0x0
0xffffc70000017e80 0041 00000000 0x0 0x0
0xffffc70000017f00 0041 00000000 0x0 0x0
0xffffc70000017f80 0041 00000000 0x0 0x0
0xffffc70000018000 0041 00000000 0x0 0x0
0xffffc70000018080 0041 00000000 0x0 0x0
0xffffc70000018100 0041 00000000 0x0 0x0
0xffffc70000018180 0041 00000000 0x0 0x0
0xffffc70000018200 0041 00000000 0x0 0x0
0xffffc70000018280 0041 00000000 0x0 0x0
0xffffc70000018300 0041 00000000 0x0 0x0
0xffffc70000018380 0041 00000000 0x0 0x0
0xffffc70000018400 0041 00000000 0x0 0x0
0xffffc70000018480 0041 00000000 0x0 0x0
0xffffc70000018500 0041 00000000 0x0 0x0
0xffffc70000018580 0041 00000000 0x0 0x0
0xffffc70000018600 0041 00000000 0x0 0x0
0xffffc70000018680 0041 00000000 0x0 0x0
0xffffc70000018700 0041 00000000 0x0 0x0
0xffffc70000018780 0041 00000000 0x0 0x0
0xffffc70000018800 0041 00000000 0x0 0x0
0xffffc70000018880 0041 00000000 0x0 0x0
0xffffc70000018900 0041 00000000 0x0 0x0
0xffffc70000018980 0041 00000000 0x0 0x0
0xffffc70000018a00 0041 00000000 0x0 0x0
0xffffc70000018a80 0041 00000000 0x0 0x0
0xffffc70000018b00 0041 00000000 0x0 0x0
0xffffc70000018b80 0041 00000000 0x0 0x0
0xffffc70000018c00 0041 00000000 0x0 0x0
0xffffc70000018c80 0041 00000000 0x0 0x0
0xffffc70000018d00 0041 00000000 0x0 0x0
0xffffc70000018d80 0041 00000000 0x0 0x0
0xffffc70000018e00 0041 00000000 0x0 0x0
0xffffc70000018e80 0041 00000000 0x0 0x0
0xffffc70000018f00 0041 00000000 0x0 0x0
0xffffc70000018f80 0041 00000000 0x0 0x0
0xffffc70000019000 0041 00000000 0x0 0x0
0xffffc70000019080 0041 00000000 0x0 0x0
0xffffc70000019100 0041 00000000 0x0 0x0
0xffffc70000019180 0041 00000000 0x0 0x0
0xffffc70000019200 0041 00000000 0x0 0x0
0xffffc70000019280 0041 00000000 0x0 0x0
0xffffc70000019300 0041 00000000 0x0 0x0
0xffffc70000019380 0041 00000000 0x0 0x0
0xffffc70000019400 0041 00000000 0x0 0x0
0xffffc70000019480 0041 00000000 0x0 0x0
0xffffc70000019500 0041 00000000 0x0 0x0
0xffffc70000019580 0041 00000000 0x0 0x0
0xffffc70000019600 0041 00000000 0x0 0x0
0xffffc70000019680 0041 00000000 0x0 0x0
0xffffc70000019700 0041 00000000 0x0 0x0
0xffffc70000019780 0041 00000000 0x0 0x0
0xffffc70000019800 0041 00000000 0x0 0x0
0xffffc70000019880 0041 00000000 0x0 0x0
0xffffc70000019900 0041 00000000 0x0 0x0
0xffffc70000019980 0041 00000000 0x0 0x0
0xffffc70000019a00 0041 00000000 0x0 0x0
0xffffc70000019a80 0041 00000000 0x0 0x0
0xffffc70000019b00 0041 00000000 0x0 0x0
0xffffc70000019b80 0041 00000000 0x0 0x0
0xffffc70000019c00 0041 00000000 0x0 0x0
0xffffc70000019c80 0041 00000000 0x0 0x0
0xffffc70000019d00 0041 00000000 0x0 0x0
0xffffc70000019d80 0041 00000000 0x0 0x0
0xffffc70000019e00 0041 00000000 0x0 0x0
0xffffc70000019e80 0041 00000000 0x0 0x0
0xffffc70000019f00 0041 00000000 0x0 0x0
0xffffc70000019f80 0041 00000000 0x0 0x0
0xffffc7000001a000 0041 00000000 0x0 0x0
0xffffc7000001a080 0041 00000000 0x0 0x0
0xffffc7000001a100 0041 00000000 0x0 0x0
0xffffc7000001a180 0041 00000000 0x0 0x0
0xffffc7000001a200 0041 00000000 0x0 0x0
0xffffc7000001a280 0041 00000000 0x0 0x0
0xffffc7000001a300 0041 00000000 0x0 0x0
0xffffc7000001a380 0041 00000000 0x0 0x0
0xffffc7000001a400 0041 00000000 0x0 0x0
0xffffc7000001a480 0041 00000000 0x0 0x0
0xffffc7000001a500 0041 00000000 0x0 0x0
0xffffc7000001a580 0041 00000000 0x0 0x0
0xffffc7000001a600 0041 00000000 0x0 0x0
0xffffc7000001a680 0041 00000000 0x0 0x0
0xffffc7000001a700 0041 00000000 0x0 0x0
0xffffc7000001a780 0041 00000000 0x0 0x0
0xffffc7000001a800 0041 00000000 0x0 0x0
0xffffc7000001a880 0041 00000000 0x0 0x0
0xffffc7000001a900 0041 00000000 0x0 0x0
0xffffc7000001a980 0041 00000000 0x0 0x0
0xffffc7000001aa00 0041 00000000 0x0 0x0
0xffffc7000001aa80 0041 00000000 0x0 0x0
0xffffc7000001ab00 0041 00000000 0x0 0x0
0xffffc7000001ab80 0041 00000000 0x0 0x0
0xffffc7000001ac00 0041 00000000 0x0 0x0
0xffffc7000001ac80 0041 00000000 0x0 0x0
0xffffc7000001ad00 0041 00000000 0x0 0x0
0xffffc7000001ad80 0041 00000000 0x0 0x0
0xffffc7000001ae00 0041 00000000 0x0 0x0
0xffffc7000001ae80 0041 00000000 0x0 0x0
0xffffc7000001af00 0041 00000000 0x0 0x0
0xffffc7000001af80 0041 00000000 0x0 0x0
0xffffc7000001b000 0041 00000000 0x0 0x0
0xffffc7000001b080 0041 00000000 0x0 0x0
0xffffc7000001b100 0041 00000000 0x0 0x0
0xffffc7000001b180 0041 00000000 0x0 0x0
0xffffc7000001b200 0041 00000000 0x0 0x0
0xffffc7000001b280 0041 00000000 0x0 0x0
0xffffc7000001b300 0041 00000000 0x0 0x0
0xffffc7000001b380 0041 00000000 0x0 0x0
0xffffc7000001b400 0041 00000000 0x0 0x0
0xffffc7000001b480 0041 00000000 0x0 0x0
0xffffc7000001b500 0041 00000000 0x0 0x0
0xffffc7000001b580 0041 00000000 0x0 0x0
0xffffc7000001b600 0041 00000000 0x0 0x0
0xffffc7000001b680 0041 00000000 0x0 0x0
0xffffc7000001b700 0041 00000000 0x0 0x0
0xffffc7000001b780 0041 00000000 0x0 0x0
0xffffc7000001b800 0041 00000000 0x0 0x0
0xffffc7000001b880 0041 00000000 0x0 0x0
0xffffc7000001b900 0041 00000000 0x0 0x0
0xffffc7000001b980 0041 00000000 0x0 0x0
0xffffc7000001ba00 0041 00000000 0x0 0x0
0xffffc7000001ba80 0041 00000000 0x0 0x0
0xffffc7000001bb00 0001 00000000 0x0 0x0
0xffffc7000001bb80 0001 00000000 0x0 0x0
0xffffc7000001bc00 0001 00000000 0x0 0x0
0xffffc7000001bc80 0001 00000000 0x0 0x0
0xffffc7000001bd00 0001 00000000 0x0 0x0
0xffffc7000001bd80 0001 00000000 0x0 0x0
0xffffc7000001be00 0001 00000000 0x0 0x0
0xffffc7000001be80 0001 00000000 0x0 0x0
0xffffc7000001bf00 0001 00000000 0x0 0x0
0xffffc7000001bf80 0001 00000000 0x0 0x0
0xffffc7000001c000 0001 00000000 0x0 0x0
0xffffc7000001c080 0001 00000000 0x0 0x0
0xffffc7000001c100 0001 00000000 0x0 0x0
0xffffc7000001c180 0001 00000000 0x0 0x0
0xffffc7000001c200 0001 00000000 0x0 0x0
0xffffc7000001c280 0001 00000000 0x0 0x0
0xffffc7000001c300 0001 00000000 0x0 0x0
0xffffc7000001c380 0001 00000000 0x0 0x0
0xffffc7000001c400 0001 00000000 0x0 0x0
0xffffc7000001c480 0001 00000000 0x0 0x0
0xffffc7000001c500 0001 00000000 0x0 0x0
0xffffc7000001c580 0001 00000000 0x0 0x0
0xffffc7000001c600 0001 00000000 0x0 0x0
0xffffc7000001c680 0001 00000000 0x0 0x0
0xffffc7000001c700 0001 00000000 0x0 0x0
0xffffc7000001c780 0001 00000000 0x0 0x0
0xffffc7000001c800 0001 00000000 0x0 0x0
0xffffc7000001c880 0001 00000000 0x0 0x0
0xffffc7000001c900 0001 00000000 0x0 0x0
0xffffc7000001c980 0001 00000000 0x0 0x0
0xffffc7000001ca00 0001 00000000 0x0 0x0
0xffffc7000001ca80 0001 00000000 0x0 0x0
0xffffc7000001cb00 0001 00000000 0x0 0x0
0xffffc7000001cb80 0001 00000000 0x0 0x0
0xffffc7000001cc00 0001 00000000 0x0 0x0
0xffffc7000001cc80 0001 00000000 0x0 0x0
0xffffc7000001cd00 0001 00000000 0x0 0x0
0xffffc7000001cd80 0001 00000000 0x0 0x0
0xffffc7000001ce00 0001 00000000 0x0 0x0
0xffffc7000001ce80 0001 00000000 0x0 0x0
0xffffc7000001cf00 0001 00000000 0x0 0x0
0xffffc7000001cf80 0001 00000000 0x0 0x0
0xffffc7000001d000 0001 00000000 0x0 0x0
0xffffc7000001d080 0001 00000000 0x0 0x0
0xffffc7000001d100 0001 00000000 0x0 0x0
0xffffc7000001d180 0001 00000000 0x0 0x0
0xffffc7000001d200 0001 00000000 0x0 0x0
0xffffc7000001d280 0001 00000000 0x0 0x0
0xffffc7000001d300 0001 00000000 0x0 0x0
0xffffc7000001d380 0001 00000000 0x0 0x0
0xffffc7000001d400 0001 00000000 0x0 0x0
0xffffc7000001d480 0001 00000000 0x0 0x0
0xffffc7000001d500 0001 00000000 0x0 0x0
0xffffc7000001d580 0001 00000000 0x0 0x0
0xffffc7000001d600 0001 00000000 0x0 0x0
0xffffc7000001d680 0001 00000000 0x0 0x0
0xffffc7000001d700 0001 00000000 0x0 0x0
0xffffc7000001d780 0001 00000000 0x0 0x0
0xffffc7000001d800 0001 00000000 0x0 0x0
0xffffc7000001d880 0001 00000000 0x0 0x0
0xffffc7000001d900 0001 00000000 0x0 0x0
0xffffc7000001d980 0001 00000000 0x0 0x0
0xffffc7000001da00 0001 00000000 0x0 0x0
0xffffc7000001da80 0001 00000000 0x0 0x0
0xffffc7000001db00 0001 00000000 0x0 0x0
0xffffc7000001db80 0001 00000000 0x0 0x0
0xffffc7000001dc00 0001 00000000 0x0 0x0
0xffffc7000001dc80 0001 00000000 0x0 0x0
0xffffc7000001dd00 0001 00000000 0x0 0x0
0xffffc7000001dd80 0001 00000000 0x0 0x0
0xffffc7000001de00 0001 00000000 0x0 0x0
0xffffc7000001de80 0001 00000000 0x0 0x0
0xffffc7000001df00 0001 00000000 0x0 0x0
0xffffc7000001df80 0001 00000000 0x0 0x0
0xffffc7000001e000 0001 00000000 0x0 0x0
0xffffc7000001e080 0001 00000000 0x0 0x0
0xffffc7000001e100 0001 00000000 0x0 0x0
0xffffc7000001e180 0001 00000000 0x0 0x0
0xffffc7000001e200 0001 00000000 0x0 0x0
0xffffc7000001e280 0001 00000000 0x0 0x0
0xffffc7000001e300 0001 00000000 0x0 0x0
0xffffc7000001e380 0001 00000000 0x0 0x0
0xffffc7000001e400 0001 00000000 0x0 0x0
0xffffc7000001e480 0001 00000000 0x0 0x0
0xffffc7000001e500 0001 00000000 0x0 0x0
0xffffc7000001e580 0001 00000000 0x0 0x0
0xffffc7000001e600 0001 00000000 0x0 0x0
0xffffc7000001e680 0001 00000000 0x0 0x0
0xffffc7000001e700 0001 00000000 0x0 0x0
0xffffc7000001e780 0001 00000000 0x0 0x0
0xffffc7000001e800 0001 00000000 0x0 0x0
0xffffc7000001e880 0001 00000000 0x0 0x0
0xffffc7000001e900 0001 00000000 0x0 0x0
0xffffc7000001e980 0001 00000000 0x0 0x0
0xffffc7000001ea00 0001 00000000 0x0 0x0
0xffffc7000001ea80 0001 00000000 0x0 0x0
0xffffc7000001eb00 0001 00000000 0x0 0x0
0xffffc7000001eb80 0001 00000000 0x0 0x0
0xffffc7000001ec00 0001 00000000 0x0 0x0
0xffffc7000001ec80 0001 00000000 0x0 0x0
0xffffc7000001ed00 0001 00000000 0x0 0x0
0xffffc7000001ed80 0001 00000000 0x0 0x0
0xffffc7000001ee00 0001 00000000 0x0 0x0
0xffffc7000001ee80 0001 00000000 0x0 0x0
0xffffc7000001ef00 0001 00000000 0x0 0x0
0xffffc7000001ef80 0001 00000000 0x0 0x0
0xffffc7000001f000 0001 00000000 0x0 0x0
0xffffc7000001f080 0001 00000000 0x0 0x0
0xffffc7000001f100 0001 00000000 0x0 0x0
0xffffc7000001f180 0001 00000000 0x0 0x0
0xffffc7000001f200 0001 00000000 0x0 0x0
0xffffc7000001f280 0001 00000000 0x0 0x0
0xffffc7000001f300 0001 00000000 0x0 0x0
0xffffc7000001f380 0001 00000000 0x0 0x0
0xffffc7000001f400 0001 00000000 0x0 0x0
0xffffc7000001f480 0001 00000000 0x0 0x0
0xffffc7000001f500 0001 00000000 0x0 0x0
0xffffc7000001f580 0001 00000000 0x0 0x0
0xffffc7000001f600 0001 00000000 0x0 0x0
0xffffc7000001f680 0001 00000000 0x0 0x0
0xffffc7000001f700 0001 00000000 0x0 0x0
0xffffc7000001f780 0001 00000000 0x0 0x0
0xffffc7000001f800 0001 00000000 0x0 0x0
0xffffc7000001f880 0001 00000000 0x0 0x0
0xffffc7000001f900 0001 00000000 0x0 0x0
0xffffc7000001f980 0001 00000000 0x0 0x0
0xffffc7000001fa00 0001 00000000 0x0 0x0
0xffffc7000001fa80 0001 00000000 0x0 0x0
0xffffc7000001fb00 0001 00000000 0x0 0x0
0xffffc7000001fb80 0001 00000000 0x0 0x0
0xffffc7000001fc00 0001 00000000 0x0 0x0
0xffffc7000001fc80 0001 00000000 0x0 0x0
0xffffc7000001fd00 0001 00000000 0x0 0x0
0xffffc7000001fd80 0001 00000000 0x0 0x0
0xffffc7000001fe00 0001 00000000 0x0 0x0
0xffffc7000001fe80 0001 00000000 0x0 0x0
0xffffc7000001ff00 0001 00000000 0x0 0x0
0xffffc7000001ff80 0001 00000000 0x0 0x0
0xffffc70000020000 0001 00000000 0x0 0x0
0xffffc70000020080 0001 00000000 0x0 0x0
0xffffc70000020100 0001 00000000 0x0 0x0
0xffffc70000020180 0001 00000000 0x0 0x0
0xffffc70000020200 0001 00000000 0x0 0x0
0xffffc70000020280 0001 00000000 0x0 0x0
0xffffc70000020300 0001 00000000 0x0 0x0
0xffffc70000020380 0001 00000000 0x0 0x0
0xffffc70000020400 0001 00000000 0x0 0x0
0xffffc70000020480 0001 00000000 0x0 0x0
0xffffc70000020500 0001 00000000 0x0 0x0
0xffffc70000020580 0001 00000000 0x0 0x0
0xffffc70000020600 0001 00000000 0x0 0x0
0xffffc70000020680 0001 00000000 0x0 0x0
0xffffc70000020700 0001 00000000 0x0 0x0
0xffffc70000020780 0001 00000000 0x0 0x0
0xffffc70000020800 0001 00000000 0x0 0x0
0xffffc70000020880 0001 00000000 0x0 0x0
0xffffc70000020900 0001 00000000 0x0 0x0
0xffffc70000020980 0001 00000000 0x0 0x0
0xffffc70000020a00 0001 00000000 0x0 0x0
0xffffc70000020a80 0001 00000000 0x0 0x0
0xffffc70000020b00 0001 00000000 0x0 0x0
0xffffc70000020b80 0001 00000000 0x0 0x0
0xffffc70000020c00 0001 00000000 0x0 0x0
0xffffc70000020c80 0001 00000000 0x0 0x0
0xffffc70000020d00 0001 00000000 0x0 0x0
0xffffc70000020d80 0001 00000000 0x0 0x0
0xffffc70000020e00 0001 00000000 0x0 0x0
0xffffc70000020e80 0001 00000000 0x0 0x0
0xffffc70000020f00 0001 00000000 0x0 0x0
0xffffc70000020f80 0001 00000000 0x0 0x0
0xffffc70000021000 0001 00000000 0x0 0x0
0xffffc70000021080 0001 00000000 0x0 0x0
0xffffc70000021100 0001 00000000 0x0 0x0
0xffffc70000021180 0001 00000000 0x0 0x0
0xffffc70000021200 0001 00000000 0x0 0x0
0xffffc70000021280 0001 00000000 0x0 0x0
0xffffc70000021300 0001 00000000 0x0 0x0
0xffffc70000021380 0001 00000000 0x0 0x0
0xffffc70000021400 0001 00000000 0x0 0x0
0xffffc70000021480 0001 00000000 0x0 0x0
0xffffc70000021500 0001 00000000 0x0 0x0
0xffffc70000021580 0001 00000000 0x0 0x0
0xffffc70000021600 0001 00000000 0x0 0x0
0xffffc70000021680 0001 00000000 0x0 0x0
0xffffc70000021700 0001 00000000 0x0 0x0
0xffffc70000021780 0001 00000000 0x0 0x0
0xffffc70000021800 0001 00000000 0x0 0x0
0xffffc70000021880 0001 00000000 0x0 0x0
0xffffc70000021900 0001 00000000 0x0 0x0
0xffffc70000021980 0001 00000000 0x0 0x0
0xffffc70000021a00 0001 00000000 0x0 0x0
0xffffc70000021a80 0001 00000000 0x0 0x0
0xffffc70000021b00 0001 00000000 0x0 0x0
0xffffc70000021b80 0001 00000000 0x0 0x0
0xffffc70000021c00 0001 00000000 0x0 0x0
0xffffc70000021c80 0001 00000000 0x0 0x0
0xffffc70000021d00 0001 00000000 0x0 0x0
0xffffc70000021d80 0001 00000000 0x0 0x0
0xffffc70000021e00 0001 00000000 0x0 0x0
0xffffc70000021e80 0001 00000000 0x0 0x0
0xffffc70000021f00 0001 00000000 0x0 0x0
0xffffc70000021f80 0001 00000000 0x0 0x0
0xffffc70000022000 0001 00000000 0x0 0x0
0xffffc70000022080 0001 00000000 0x0 0x0
0xffffc70000022100 0001 00000000 0x0 0x0
0xffffc70000022180 0001 00000000 0x0 0x0
0xffffc70000022200 0001 00000000 0x0 0x0
0xffffc70000022280 0001 00000000 0x0 0x0
0xffffc70000022300 0001 00000000 0x0 0x0
0xffffc70000022380 0001 00000000 0x0 0x0
0xffffc70000022400 0001 00000000 0x0 0x0
0xffffc70000022480 0001 00000000 0x0 0x0
0xffffc70000022500 0001 00000000 0x0 0x0
0xffffc70000022580 0001 00000000 0x0 0x0
0xffffc70000022600 0001 00000000 0x0 0x0
0xffffc70000022680 0001 00000000 0x0 0x0
0xffffc70000022700 0001 00000000 0x0 0x0


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
syzbot can test patches for this issue, for details see:
https://goo.gl/tpsmEJ#testing-patches
Reply all
Reply to author
Forward
0 new messages