panic: tcp_output: no tempWlARatNIe[

0 views
Skip to first unread message

syzbot

unread,
Nov 12, 2019, 2:37:11 PM11/12/19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: b99a164f Fix SA can be expaired wrongly when there are man..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=130950e2e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=6e4d6bd2b8e377a2
dashboard link: https://syzkaller.appspot.com/bug?extid=6ce8bd46ef2e1bdcf34c

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+6ce8bd...@syzkaller.appspotmail.com

[ 90.5072783] panic: tcp_output: no tempWlARatNIe[

[ 90 .950.057207728738]3 N] Gc: pdu1e:f auBletgiedn tmmraapc(eb)
acskha.r.e.
[ 90.5072783] type to MAP_PRIVATE (pid 740 command syz-executor.3)
[ 90.5072783] vpanic() at netbsd:vpanic+0x241 sys/kern/subr_prf.c:336
[ 90.5072783] snprintf() at netbsd:snprintf
[ 90.5072783] tcp_output() at netbsd:tcp_output+0x5480
sys/netinet/tcp_output.c:1343
[ 90.5072783] tcp_sendoob_wrapper() at netbsd:tcp_sendoob_wrapper+0x249
tcp_sendoob sys/netinet/tcp_usrreq.c:1178 [inline]
[ 90.5072783] tcp_sendoob_wrapper() at netbsd:tcp_sendoob_wrapper+0x249
sys/netinet/tcp_usrreq.c:2450
[ 90.5072783] sosend() at netbsd:sosend+0x8d3 sys/kern/uipc_socket.c:1056
[ 90.5072783] do_sys_sendmsg_so() at netbsd:do_sys_sendmsg_so+0x540
sys/kern/uipc_syscalls.c:629
[ 90.5072783] do_sys_sendmsg() at netbsd:do_sys_sendmsg+0x15a
sys/kern/uipc_syscalls.c:679
[ 90.5072783] sys_sendmsg() at netbsd:sys_sendmsg+0x117
sys/kern/uipc_syscalls.c:533
[ 90.5072783] sys___syscall() at netbsd:sys___syscall+0xf5 sy_call
sys/sys/syscallvar.h:65 [inline]
[ 90.5072783] sys___syscall() at netbsd:sys___syscall+0xf5
sys/kern/sys_syscall.c:77
[ 90.5072783] syscall() at netbsd:syscall+0x431 sy_call
sys/sys/syscallvar.h:65 [inline]
[ 90.5072783] syscall() at netbsd:syscall+0x431 sy_invoke
sys/sys/syscallvar.h:94 [inline]
[ 90.5072783] syscall() at netbsd:syscall+0x431
sys/arch/x86/x86/syscall.c:138
[ 90.5072783] --- syscall (number 198) ---
[ 90.5072783] 70c20b243b9a:
[ 90.5072783] cpu1: End traceback...
[ 90.5072783] fatal breakpoint trap in supervisor mode
[ 90.5072783] trap type 1 code 0 rip 0xffffffff8021ccd5 cs 0x8 rflags
0x246 cr2 0x20001800 ilevel 0x8 rsp 0xffffcb817bd27270
[ 90.5072783] curlwp 0xffffcb8012d63bc0 pid 644.3 lowest kstack
0xffffcb817bd202c0
Stopped in pid 644.3 (syz-executor.0) at netbsd:breakpoint+0x5:
leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xf9 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x241 sys/kern/subr_prf.c:336
snprintf() at netbsd:snprintf
tcp_output() at netbsd:tcp_output+0x5480 sys/netinet/tcp_output.c:1343
tcp_sendoob_wrapper() at netbsd:tcp_sendoob_wrapper+0x249 tcp_sendoob
sys/netinet/tcp_usrreq.c:1178 [inline]
tcp_sendoob_wrapper() at netbsd:tcp_sendoob_wrapper+0x249
sys/netinet/tcp_usrreq.c:2450
sosend() at netbsd:sosend+0x8d3 sys/kern/uipc_socket.c:1056
do_sys_sendmsg_so() at netbsd:do_sys_sendmsg_so+0x540
sys/kern/uipc_syscalls.c:629
do_sys_sendmsg() at netbsd:do_sys_sendmsg+0x15a sys/kern/uipc_syscalls.c:679
sys_sendmsg() at netbsd:sys_sendmsg+0x117 sys/kern/uipc_syscalls.c:533
sys___syscall() at netbsd:sys___syscall+0xf5 sy_call
sys/sys/syscallvar.h:65 [inline]
sys___syscall() at netbsd:sys___syscall+0xf5 sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x431 sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x431 sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x431 sys/arch/x86/x86/syscall.c:138
--- syscall (number 198) ---
70c20b243b9a:
ds 2
es 20c0
fs 7250
gs 72a0
rdi ffffcb800d92d458
rsi ffffcb8012d63ea8
rbp ffffcb817bd27270
rbx ffffcb816d892000
rdx 3ffff
rcx ffffcb816efdc000
rax ffffcb800f746088
r8 4
r9 1ffffffff055356c
r10 ffffffff82a9ab63 db_onpanic+0x3
r11 8000000000
r12 ffffcb816d8a4000
r13 ffffffff82040160 __func__.15559+0x720
r14 ffffcb817bd27300
r15 ffffcb816d892058
rip ffffffff8021ccd5 breakpoint+0x5
cs 8
rflags 246
rsp ffffcb817bd27270
ss 10
netbsd:breakpoint+0x5: leave
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
477 3 4 0 1000000 ffffcb80121c6780 syz-executor.0
818 3 3 0 80 ffffcb80122879a0 syz-executor.4 parked
767 3 3 0 80 ffffcb8013cfa2e0 syz-executor.4 parked
767 1 2 0 10040000 ffffcb8012dee9e0 syz-executor.4
623 4 3 1 80 ffffcb8013e0e060 syz-executor.5 parked
623 3 3 0 80 ffffcb8013cb2b00 syz-executor.5 parked
623 1 2 1 40000 ffffcb8012dee5a0 syz-executor.5
794 3 4 0 1000000 ffffcb80122f1200 syz-executor.0
264 3 3 1 80 ffffcb8012d804a0 syz-executor.2 parked
644 7 3 1 80 ffffcb8012d44320 syz-executor.0 parked
644 6 3 0 80 ffffcb8012124b40 syz-executor.0 parked
644 5 3 0 80 ffffcb80123aa720 syz-executor.0 parked
644 4 3 1 80 ffffcb8012db30a0 syz-executor.0 parked
644 > 3 7 1 0 ffffcb8012d63bc0 syz-executor.0
644 1 2 1 10040000 ffffcb8013d85bc0 syz-executor.0
740 7 3 1 80 ffffcb8012db34e0 syz-executor.3 parked
740 6 3 0 80 ffffcb8012d924c0 syz-executor.3 parked
740 5 3 0 80 ffffcb8012d70480 syz-executor.3 parked
740 4 3 1 80 ffffcb80122b35c0 syz-executor.3 parked
740 > 3 7 0 0 ffffcb8012d80060 syz-executor.3
740 1 2 0 10040000 ffffcb8013d85340 syz-executor.3
601 3 3 1 80 ffffcb80122c1a20 syz-executor.1 parked
728 3 3 1 80 ffffcb80122d2600 syz-executor.1 parked
790 3 3 1 80 ffffcb8013e7f960 syz-executor.4 parked
659 3 3 1 80 ffffcb8013e6f940 syz-executor.4 parked
599 3 3 1 80 ffffcb8013e6f500 syz-executor.4 parked
628 4 3 1 80 ffffcb8013e6f0c0 syz-executor.5 parked
758 4 3 0 80 ffffcb8012d25b80 syz-executor.2 parked
747 3 3 1 80 ffffcb801232db00 syz-executor.1 parked
582 3 3 0 80 ffffcb801233f6e0 syz-executor.1 parked
632 3 3 0 80 ffffcb8012242980 syz-executor.0 parked
66 3 3 1 80 ffffcb80121d2040 syz-executor.0 parked
651 4 3 1 80 ffffcb8012287120 syz-executor.0 parked
638 3 3 0 80 ffffcb801216db80 syz-executor.0 parked
487 1 3 0 80 ffffcb8013c6aae0 syz-executor.4 nanoslp
503 1 3 0 80 ffffcb8013c6a6a0 syz-executor.5 nanoslp
603 1 3 1 80 ffffcb8013c6a260 syz-executor.3 nanoslp
45 1 3 0 80 ffffcb8013adbac0 syz-executor.2 pipe_rd
399 1 3 0 80 ffffcb8013adb680 syz-executor.1 pipe_rd
41 1 3 1 80 ffffcb8011ea61a0 syz-executor.0 nanoslp
543 11 3 0 80 ffffcb8013adb240 syz-fuzzer parked
543 10 3 1 80 ffffcb8013abdaa0 syz-fuzzer parked
543 9 3 1 80 ffffcb8011ea5a00 syz-fuzzer parked
543 8 3 0 80 ffffcb8013abd660 syz-fuzzer kqueue
543 7 3 1 80 ffffcb8013ab6a80 syz-fuzzer parked
543 6 3 0 80 ffffcb8013ab6640 syz-fuzzer parked
543 5 3 0 80 ffffcb8013ab6200 syz-fuzzer parked
543 4 3 0 80 ffffcb8013582a60 syz-fuzzer parked
543 3 3 0 80 ffffcb8012d708c0 syz-fuzzer parked
543 2 3 1 80 ffffcb8012e075e0 syz-fuzzer parked
543 1 3 1 80 ffffcb8011ea5180 syz-fuzzer parked
594 1 3 0 80 ffffcb8012d44760 sshd select
505 1 3 0 80 ffffcb8012ddb9a0 getty nanoslp
581 1 3 0 80 ffffcb8012ddb120 getty nanoslp
468 1 3 0 80 ffffcb8012dee160 getty nanoslp
419 1 3 0 80 ffffcb8012de69c0 getty ttyraw
528 1 3 0 80 ffffcb801233f2a0 cron nanoslp
550 1 3 0 80 ffffcb8012d92900 inetd kqueue
317 1 3 1 80 ffffcb801233fb20 sshd select
476 1 3 0 80 ffffcb80122e01e0 powerd kqueue
202 1 3 0 80 ffffcb8012d63780 syslogd kqueue
245 1 3 1 80 ffffcb80122e0620 dhcpcd kqueue
236 1 3 1 80 ffffcb80122120a0 dhcpcd kqueue
1 1 3 1 80 ffffcb8012011240 init wait
0 58 3 0 204 ffffcb8012011ac0 physiod physiod
0 57 3 1 204 ffffcb80120596a0 pooldrain pooldrain
0 56 3 0 204 ffffcb801205a280 aiodoned aiodoned
0 55 3 1 200 ffffcb8012059ae0 ioflush syncer
0 54 3 1 200 ffffcb8012059260 pgdaemon pgdaemon
0 51 3 0 200 ffffcb8012011680 npfgc-0 npfgccv
0 50 3 1 204 ffffcb8011ffeaa0 rt_free rt_free
0 49 3 1 204 ffffcb8011ffe660 unpgc unpgc
0 48 3 0 204 ffffcb8011ffe220 key_timehandler
key_timehandler
0 47 3 1 204 ffffcb8011ed4a80 icmp6_wqinput/1
icmp6_wqinput
0 46 3 0 204 ffffcb8011ed4640 icmp6_wqinput/0
icmp6_wqinput
0 45 3 1 204 ffffcb8011ed4200 nd6_timer nd6_timer
0 44 3 1 204 ffffcb8011ecba60 carp6_wqinput/1
carp6_wqinput
0 43 3 0 204 ffffcb8011ecb620 carp6_wqinput/0
carp6_wqinput
0 42 3 1 204 ffffcb8011ecb1e0 carp_wqinput/1
carp_wqinput
0 41 3 0 204 ffffcb8011eb7a40 carp_wqinput/0
carp_wqinput
0 40 3 1 204 ffffcb8011eb7600 icmp_wqinput/1
icmp_wqinput
0 39 3 0 204 ffffcb8011eb71c0 icmp_wqinput/0
icmp_wqinput
0 38 3 1 204 ffffcb8011ea6a20 rt_timer rt_timer
0 37 3 0 204 ffffcb8011ea45a0 vmem_rehash vmem_rehash
0 27 3 0 204 ffffcb800f7ca580 scsibus0 sccomp
0 26 3 0 200 ffffcb800f7ca140 pms0 pmsreset
0 25 3 1 204 ffffcb800f73c9a0 xcall/1 xcall
0 24 1 1 200 ffffcb800f73c560 softser/1
0 23 1 1 200 ffffcb800f73c120 softclk/1
0 22 1 1 200 ffffcb800f738980 softbio/1
0 21 1 1 200 ffffcb800f738540 softnet/1
0 20 1 1 201 ffffcb800f738100 idle/1
0 19 3 0 204 ffffcb800f66e960 lnxpwrwq lnxpwrwq
0 18 3 0 204 ffffcb800f66e520 lnxlngwq lnxlngwq
0 17 3 0 204 ffffcb800f66e0e0 lnxsyswq lnxsyswq
0 16 3 0 204 ffffcb800de53940 lnxrcugc lnxrcugc
0 15 3 0 204 ffffcb800de53500 sysmon smtaskq
0 14 3 1 204 ffffcb800de530c0 pmfsuspend pmfsuspend
0 13 3 0 204 ffffcb800de43920 pmfevent pmfevent
0 12 3 0 204 ffffcb800de434e0 sopendfree sopendfr
0 11 3 0 204 ffffcb800de430a0 nfssilly nfssilly
0 10 3 0 200 ffffcb800de39900 cachegc cachegc
0 9 3 1 204 ffffcb800de394c0 vdrain vdrain
0 8 3 0 200 ffffcb800de39080 modunload mod_unld
0 7 3 0 204 ffffcb800de2b8e0 xcall/0 xcall
0 6 1 0 200 ffffcb800de2b4a0 softser/0
0 5 1 0 200 ffffcb800de2b060 softclk/0
0 4 1 0 200 ffffcb800de268c0 softbio/0
0 3 1 0 200 ffffcb800de26480 softnet/0
0 2 1 0 201 ffffcb800de26040 idle/0
0 1 3 1 200 ffffffff82b633a0 swapper uvm
[Locks tracked through LWPs]
Locks held by an LWP (syz-executor.4):
Lock 0 (initialized at uvm_obj_init)
lock address : 0xffffcb8013c945c0 type : sleep/adaptive
initialized : 0xffffffff810df8b3
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 0
current lwp : 0xffffcb8012d63bc0 last held: 0xffffcb8012dee9e0
last locked* : 0xffffffff810c3f1e unlocked : 0xffffffff810c10dc
owner field : 0xffffcb8012dee9e0 wait/spin: 0/0

Turnstile chain at 0xffffffff82d7ee00.
=> No active turnstile for this lock.

Locks held by an LWP (syz-executor.0):
Lock 0 (initialized at soinit)
lock address : 0xffffcb800d92c080 type : sleep/adaptive
initialized : 0xffffffff8124ab34
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xffffcb8012d63bc0 last held: 0xffffcb8012d63bc0
last locked* : 0xffffffff81249d31 unlocked : 0xffffffff81249db1
owner field : 0xffffcb8012d63bc0 wait/spin: 0/0

Turnstile chain at 0xffffffff82d7eb80.
=> No active turnstile for this lock.


[Locks tracked through CPUs]
Locks held on CPU 1:
Lock 0 (initialized at main)
lock address : 0xffffffff82d7d400 type : spin
initialized : 0xffffffff81a0e916
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xffffcb8012d63bc0 last held: 0xffffcb8012d63bc0
last locked* : 0xffffffff80bffd9d unlocked : 0xffffffff80c36de3
curcpu holds : 1 wanted by: 000000000000000000


PAGE FLAG PQ UOBJECT UANON
0xffffcb8000014180 0048 0000 0x0 0x0
0xffffcb80000141f8 0048 0000 0x0 0x0
0xffffcb8000014270 0048 0000 0x0 0x0
0xffffcb80000142e8 0048 0000 0x0 0x0
0xffffcb8000014360 0048 0000 0x0 0x0
0xffffcb80000143d8 0040 0000 0x0 0x0
0xffffcb8000014450 0048 0000 0x0 0x0
0xffffcb80000144c8 0048 0000 0x0 0x0
0xffffcb8000014540 0048 0000 0x0 0x0
0xffffcb80000145b8 0048 0000 0x0 0x0
0xffffcb8000014630 0048 0000 0x0 0x0
0xffffcb80000146a8 0048 0000 0x0 0x0
0xffffcb8000014720 0048 0000 0x0 0x0
0xffffcb8000014798 0048 0000 0x0 0x0
0xffffcb8000014810 0040 0000 0x0 0x0
0xffffcb8000014888 0040 0000 0x0 0x0
0xffffcb8000014900 0040 0000 0x0 0x0
0xffffcb8000014978 0040 0000 0x0 0x0
0xffffcb80000149f0 0040 0000 0x0 0x0
0xffffcb8000014a68 0040 0000 0x0 0x0
0xffffcb8000014ae0 0040 0000 0x0 0x0
0xffffcb8000014b58 0040 0000 0x0 0x0
0xffffcb8000014bd0 0048 0000 0x0 0x0
0xffffcb8000014c48 0048 0000 0x0 0x0
0xffffcb8000014cc0 0048 0000 0x0 0x0
0xffffcb8000014d38 0048 0000 0x0 0x0
0xffffcb8000014db0 0048 0000 0x0 0x0
0xffffcb8000014e28 0048 0000 0x0 0x0
0xffffcb8000014ea0 0048 0000 0x0 0x0
0xffffcb8000014f18 0048 0000 0x0 0x0
0xffffcb8000014f90 0048 0000 0x0 0x0
0xffffcb8000015008 0048 0000 0x0 0x0
0xffffcb8000015080 0048 0000 0x0 0x0
0xffffcb80000150f8 0048 0000 0x0 0x0
0xffffcb8000015170 0048 0000 0x0 0x0
0xffffcb80000151e8 0048 0000 0x0 0x0
0xffffcb8000015260 0048 0000 0x0 0x0
0xffffcb80000152d8 0048 0000 0x0 0x0
0xffffcb8000015350 0048 0000 0x0 0x0
0xffffcb80000153c8 0048 0000 0x0 0x0
0xffffcb8000015440 0048 0000 0x0 0x0
0xffffcb80000154b8 0048 0000 0x0 0x0
0xffffcb8000015530 0048 0000 0x0 0x0
0xffffcb80000155a8 0048 0000 0x0 0x0
0xffffcb8000015620 0048 0000 0x0 0x0
0xffffcb8000015698 0048 0000 0x0 0x0
0xffffcb8000015710 0048 0000 0x0 0x0
0xffffcb8000015788 0048 0000 0x0 0x0
0xffffcb8000015800 0048 0000 0x0 0x0
0xffffcb8000015878 0048 0000 0x0 0x0
0xffffcb80000158f0 0048 0000 0x0 0x0
0xffffcb8000015968 0048 0000 0x0 0x0
0xffffcb80000159e0 0048 0000 0x0 0x0
0xffffcb8000015a58 0048 0000 0x0 0x0
0xffffcb8000015ad0 0048 0000 0x0 0x0
0xffffcb8000015b48 0048 0000 0x0 0x0
0xffffcb8000015bc0 0048 0000 0x0 0x0
0xffffcb8000015c38 0048 0000 0x0 0x0
0xffffcb8000015cb0 0048 0000 0x0 0x0
0xffffcb8000015d28 0048 0000 0x0 0x0
0xffffcb8000015da0 0048 0000 0x0 0x0
0xffffcb8000015e18 0048 0000 0x0 0x0
0xffffcb8000015e90 0048 0000 0x0 0x0
0xffffcb8000015f08 0048 0000 0x0 0x0
0xffffcb8000015f80 0048 0000 0x0 0x0
0xffffcb8000015ff8 0048 0000 0x0 0x0
0xffffcb8000016070 0040 0000 0x0 0x0
0xffffcb80000160e8 0041 0000 0x0 0x0
0xffffcb8000016160 0041 0000 0x0 0x0
0xffffcb80000161d8 0048 0000 0x0 0x0
0xffffcb8000016250 0048 0000 0x0 0x0
0xffffcb80000162c8 0048 0000 0x0 0x0
0xffffcb8000016340 0048 0000 0x0 0x0
0xffffcb80000163b8 0040 0000 0x0 0x0
0xffffcb8000016430 0041 0000 0x0 0x0
0xffffcb80000164a8 0041 0000 0x0 0x0
0xffffcb8000016520 0041 0000 0x0 0x0
0xffffcb8000016598 0048 0000 0x0 0x0
0xffffcb8000016610 0040 0000 0x0 0x0
0xffffcb8000016688 0048 0000 0x0 0x0
0xffffcb8000016700 0048 0000 0x0 0x0
0xffffcb8000016778 0041 0000 0x0 0x0
0xffffcb80000167f0 0041 0000 0x0 0x0
0xffffcb8000016868 0048 0000 0x0 0x0
0xffffcb80000168e0 0048 0000 0x0 0x0
0xffffcb8000016958 0041 0000 0x0 0x0
0xffffcb80000169d0 0041 0000 0x0 0x0
0xffffcb8000016a48 0040 0000 0x0 0x0
0xffffcb8000016ac0 0040 0000 0x0 0x0
0xffffcb8000016b38 0041 0000 0x0 0x0
0xffffcb8000016bb0 0048 0000 0x0 0x0
0xffffcb8000016c28 0048 0000 0x0 0x0
0xffffcb8000016ca0 0048 0000 0x0 0x0
0xffffcb8000016d18 0041 0000 0x0 0x0
0xffffcb8000016d90 0041 0000 0x0 0x0
0xffffcb8000016e08 0041 0000 0x0 0x0
0xffffcb8000016e80 0041 0000 0x0 0x0
0xffffcb8000016ef8 0048 0000 0x0 0x0
0xffffcb8000016f70 0048 0000 0x0 0x0
0xffffcb8000016fe8 0048 0000 0x0 0x0
0xffffcb8000017060 0048 0000 0x0 0x0
0xffffcb80000170d8 0048 0000 0x0 0x0
0xffffcb8000017150 0048 0000 0x0 0x0
0xffffcb80000171c8 0041 0000 0x0 0x0
0xffffcb8000017240 0041 0000 0x0 0x0
0xffffcb80000172b8 0048 0000 0x0 0x0
0xffffcb8000017330 0048 0000 0x0 0x0
0xffffcb80000173a8 0048 0000 0x0 0x0
0xffffcb8000017420 0048 0000 0x0 0x0
0xffffcb8000017498 0048 0000 0x0 0x0
0xffffcb8000017510 0048 0000 0x0 0x0
0xffffcb8000017588 0048 0000 0x0 0x0
0xffffcb8000017600 0048 0000 0x0 0x0
0xffffcb8000017678 0048 0000 0x0 0x0
0xffffcb80000176f0 0048 0000 0x0 0x0
0xffffcb8000017768 0048 0000 0x0 0x0
0xffffcb80000177e0 0048 0000 0x0 0x0
0xffffcb8000017858 0048 0000 0x0 0x0
0xffffcb80000178d0 0048 0000 0x0 0x0
0xffffcb8000017948 0048 0000 0x0 0x0
0xffffcb80000179c0 0048 0000 0x0 0x0
0xffffcb8000017a38 0048 0000 0x0 0x0
0xffffcb8000017ab0 0048 0000 0x0 0x0
0xffffcb8000017b28 0048 0000 0x0 0x0
0xffffcb8000017ba0 0048 0000 0x0 0x0
0xffffcb8000017c18 0048 0000 0x0 0x0
0xffffcb8000017c90 0048 0000 0x0 0x0
0xffffcb8000017d08 0048 0000 0x0 0x0
0xffffcb8000017d80 0048 0000 0x0 0x0
0xffffcb8000017df8 0048 0000 0x0 0x0
0xffffcb8000017e70 0048 0000 0x0 0x0
0xffffcb8000017ee8 0048 0000 0x0 0x0
0xffffcb8000017f60 0048 0000 0x0 0x0
0xffffcb8000017fd8 0048 0000 0x0 0x0
0xffffcb8000018050 0048 0000 0x0 0x0
0xffffcb80000180c8 0048 0000 0x0 0x0
0xffffcb8000018140 0048 0000 0x0 0x0
0xffffcb80000181b8 0048 0000 0x0 0x0
0xffffcb8000018230 0048 0000 0x0 0x0
0xffffcb80000182a8 0048 0000 0x0 0x0
0xffffcb8000018320 0048 0000 0x0 0x0
0xffffcb8000018398 0048 0000 0x0 0x0
0xffffcb8000018410 0048 0000 0x0 0x0
0xffffcb8000018488 0048 0000 0x0 0x0
0xffffcb8000018500 0048 0000 0x0 0x0
0xffffcb8000018578 0048 0000 0x0 0x0
0xffffcb80000185f0 0048 0000 0x0 0x0
0xffffcb8000018668 0048 0000 0x0 0x0
0xffffcb80000186e0 0048 0000 0x0 0x0
0xffffcb8000018758 0048 0000 0x0 0x0
0xffffcb80000187d0 0048 0000 0x0 0x0
0xffffcb8000018848 0048 0000 0x0 0x0
0xffffcb80000188c0 0048 0000 0x0 0x0
0xffffcb8000018938 0048 0000 0x0 0x0
0xffffcb80000189b0 0048 0000 0x0 0x0
0xffffcb8000018a28 0048 0000 0x0 0x0
0xffffcb8000018aa0 0048 0000 0x0 0x0
0xffffcb8000018b18 0048 0000 0x0 0x0
0xffffcb8000018b90 0048 0000 0x0 0x0
0xffffcb8000018c08 0048 0000 0x0 0x0
0xffffcb8000018c80 0048 0000 0x0 0x0
0xffffcb8000018cf8 0048 0000 0x0 0x0
0xffffcb8000018d70 0048 0000 0x0 0x0
0xffffcb8000018de8 0048 0000 0x0 0x0
0xffffcb8000018e60 0048 0000 0x0 0x0
0xffffcb8000018ed8 0048 0000 0x0 0x0
0xffffcb8000018f50 0048 0000 0x0 0x0
0xffffcb8000018fc8 0048 0000 0x0 0x0
0xffffcb8000019040 0048 0000 0x0 0x0
0xffffcb80000190b8 0048 0000 0x0 0x0
0xffffcb8000019130 0048 0000 0x0 0x0
0xffffcb80000191a8 0048 0000 0x0 0x0
0xffffcb8000019220 0048 0000 0x0 0x0
0xffffcb8000019298 0048 0000 0x0 0x0
0xffffcb8000019310 0048 0000 0x0 0x0
0xffffcb8000019388 0048 0000 0x0 0x0
0xffffcb8000019400 0048 0000 0x0 0x0
0xffffcb8000019478 0048 0000 0x0 0x0
0xffffcb80000194f0 0048 0000 0x0 0x0
0xffffcb8000019568 0048 0000 0x0 0x0
0xffffcb80000195e0 0048 0000 0x0 0x0
0xffffcb8000019658 0048 0000 0x0 0x0
0xffffcb80000196d0 0048 0000 0x0 0x0
0xffffcb8000019748 0048 0000 0x0 0x0
0xffffcb80000197c0 0048 0000 0x0 0x0
0xffffcb8000019838 0048 0000 0x0 0x0
0xffffcb80000198b0 0048 0000 0x0 0x0
0xffffcb8000019928 0048 0000 0x0 0x0
0xffffcb80000199a0 0048 0000 0x0 0x0
0xffffcb8000019a18 0048 0000 0x0 0x0
0xffffcb8000019a90 0048 0000 0x0 0x0
0xffffcb8000019b08 0048 0000 0x0 0x0
0xffffcb8000019b80 0048 0000 0x0 0x0
0xffffcb8000019bf8 0048 0000 0x0 0x0
0xffffcb8000019c70 0048 0000 0x0 0x0
0xffffcb8000019ce8 0048 0000 0x0 0x0
0xffffcb8000019d60 0048 0000 0x0 0x0
0xffffcb8000019dd8 0048 0000 0x0 0x0
0xffffcb8000019e50 0048 0000 0x0 0x0
0xffffcb8000019ec8 0048 0000 0x0 0x0
0xffffcb8000019f40 0048 0000 0x0 0x0
0xffffcb8000019fb8 0048 0000 0x0 0x0
0xffffcb800001a030 0048 0000 0x0 0x0
0xffffcb800001a0a8 0048 0000 0x0 0x0
0xffffcb800001a120 0048 0000 0x0 0x0
0xffffcb800001a198 0048 0000 0x0 0x0
0xffffcb800001a210 0048 0000 0x0 0x0
0xffffcb800001a288 0048 0000 0x0 0x0
0xffffcb800001a300 0048 0000 0x0 0x0
0xffffcb800001a378 0048 0000 0x0 0x0
0xffffcb800001a3f0 0048 0000 0x0 0x0
0xffffcb800001a468 0048 0000 0x0 0x0
0xffffcb800001a4e0 0048 0000 0x0 0x0
0xffffcb800001a558 0048 0000 0x0 0x0
0xffffcb800001a5d0 0048 0000 0x0 0x0
0xffffcb800001a648 0048 0000 0x0 0x0
0xffffcb800001a6c0 0048 0000 0x0 0x0
0xffffcb800001a738 0008 0000 0x0 0x0
0xffffcb800001a7b0 0008 0000 0x0 0x0
0xffffcb800001a828 0008 0000 0x0 0x0
0xffffcb800001a8a0 0008 0000 0x0 0x0
0xffffcb800001a918 0008 0000 0x0 0x0
0xffffcb800001a990 0008 0000 0x0 0x0
0xffffcb800001aa08 0008 0000 0x0 0x0
0xffffcb800001aa80 0008 0000 0x0 0x0
0xffffcb800001aaf8 0008 0000 0x0 0x0
0xffffcb800001ab70 0008 0000 0x0 0x0
0xffffcb800001abe8 0008 0000 0x0 0x0
0xffffcb800001ac60 0008 0000 0x0 0x0
0xffffcb800001acd8 0008 0000 0x0 0x0
0xffffcb800001ad50 0008 0000 0x0 0x0
0xffffcb800001adc8 0008 0000 0x0 0x0
0xffffcb800001ae40 0008 0000 0x0 0x0
0xffffcb800001aeb8 0008 0000 0x0 0x0
0xffffcb800001af30 0008 0000 0x0 0x0
0xffffcb800001afa8 0008 0000 0x0 0x0
0xffffcb800001b020 0008 0000 0x0 0x0
0xffffcb800001b098 0008 0000 0x0 0x0
0xffffcb800001b110 0008 0000 0x0 0x0
0xffffcb800001b188 0008 0000 0x0 0x0
0xffffcb800001b200 0008 0000 0x0 0x0
0xffffcb800001b278 0008 0000 0x0 0x0
0xffffcb800001b2f0 0008 0000 0x0 0x0
0xffffcb800001b368 0008 0000 0x0 0x0
0xffffcb800001b3e0 0008 0000 0x0 0x0
0xffffcb800001b458 0008 0000 0x0 0x0
0xffffcb800001b4d0 0008 0000 0x0 0x0
0xffffcb800001b548 0008 0000 0x0 0x0
0xffffcb800001b5c0 0008 0000 0x0 0x0
0xffffcb800001b638 0008 0000 0x0 0x0
0xffffcb800001b6b0 0008 0000 0x0 0x0
0xffffcb800001b728 0008 0000 0x0 0x0
0xffffcb800001b7a0 0008 0000 0x0 0x0
0xffffcb800001b818 0008 0000 0x0 0x0
0xffffcb800001b890 0008 0000 0x0 0x0
0xffffcb800001b908 0008 0000 0x0 0x0
0xffffcb800001b980 0008 0000 0x0 0x0
0xffffcb800001b9f8 0008 0000 0x0 0x0
0xffffcb800001ba70 0008 0000 0x0 0x0
0xffffcb800001bae8 0008 0000 0x0 0x0
0xffffcb800001bb60 0008 0000 0x0 0x0
0xffffcb800001bbd8 0008 0000 0x0 0x0
0xffffcb800001bc50 0008 0000 0x0 0x0
0xffffcb800001bcc8 0008 0000 0x0 0x0
0xffffcb800001bd40 0008 0000 0x0 0x0
0xffffcb800001bdb8 0008 0000 0x0 0x0
0xffffcb800001be30 0008 0000 0x0 0x0
0xffffcb800001bea8 0008 0000 0x0 0x0
0xffffcb800001bf20 0008 0000 0x0 0x0
0xffffcb800001bf98 0008 0000 0x0 0x0
0xffffcb800001c010 0008 0000 0x0 0x0
0xffffcb800001c088 0048 0000 0x0 0x0
0xffffcb800001c100 0048 0000 0x0 0x0
0xffffcb800001c178 0048 0000 0x0 0x0
0xffffcb800001c1f0 0048 0000 0x0 0x0
0xffffcb800001c268 0048 0000 0x0 0x0
0xffffcb800001c2e0 0048 0000 0x0 0x0
0xffffcb800001c358 0048 0000 0x0 0x0
0xffffcb800001c3d0 0048 0000 0x0 0x0
0xffffcb800001c448 0048 0000 0x0 0x0
0xffffcb800001c4c0 0048 0000 0x0 0x0
0xffffcb800001c538 0048 0000 0x0 0x0
0xffffcb800001c5b0 0048 0000 0x0 0x0
0xffffcb800001c628 0048 0000 0x0 0x0
0xffffcb800001c6a0 0048 0000 0x0 0x0
0xffffcb800001c718 0048 0000 0x0 0x0
0xffffcb800001c790 0048 0000 0x0 0x0
0xffffcb800001c808 0048 0000 0x0 0x0
0xffffcb800001c880 0048 0000 0x0 0x0
0xffffcb800001c8f8 0048 0000 0x0 0x0
0xffffcb800001c970 0048 0000 0x0 0x0
0xffffcb800001c9e8 0048 0000 0x0 0x0
0xffffcb800001ca60 0048 0000 0x0 0x0
0xffffcb800001cad8 0048 0000 0x0 0x0
0xffffcb800001cb50 0048 0000 0x0 0x0
0xffffcb800001cbc8 0048 0000 0x0 0x0
0xffffcb800001cc40 0048 0000 0x0 0x0
0xffffcb800001ccb8 0048 0000 0x0 0x0
0xffffcb800001cd30 0048 0000 0x0 0x0
0xffffcb800001cda8 0048 0000 0x0 0x0
0xffffcb800001ce20 0048 0000 0x0 0x0
0xffffcb800001ce98 0048 0000 0x0 0x0
0xffffcb800001cf10 0048 0000 0x0 0x0
0xffffcb800001cf88 0048 0000 0x0 0x0
0xffffcb800001d000 0048 0000 0x0 0x0
0xffffcb800001d078 0048 0000 0x0 0x0
0xffffcb800001d0f0 0048 0000 0x0 0x0
0xffffcb800001d168 0048 0000 0x0 0x0
0xffffcb800001d1e0 0048 0000 0x0 0x0
0xffffcb800001d258 0048 0000 0x0 0x0
0xffffcb800001d2d0 0048 0000 0x0 0x0
0xffffcb800001d348 0048 0000 0x0 0x0
0xffffcb800001d3c0 0048 0000 0x0 0x0
0xffffcb800001d438 0008 0000 0x0 0x0
0xffffcb800001d4b0 0008 0000 0x0 0x0
0xffffcb800001d528 0008 0000 0x0 0x0
0xffffcb800001d5a0 0008 0000 0x0 0x0
0xffffcb800001d618 0008 0000 0x0 0x0
0xffffcb800001d690 0008 0000 0x0 0x0
0xffffcb800001d708 0008 0000 0x0 0x0
0xffffcb800001d780 0008 0000 0x0 0x0
0xffffcb800001d7f8 0008 0000 0x0 0x0
0xffffcb800001d870 0008 0000 0x0 0x0
0xffffcb800001d8e8 0008 0000 0x0 0x0
0xffffcb800001d960 0008 0000 0x0 0x0
0xffffcb800001d9d8 0008 0000 0x0 0x0
0xffffcb800001da50 0008 0000 0x0 0x0
0xffffcb800001dac8 0008 0000 0x0 0x0
0xffffcb800001db40 0008 0000 0x0 0x0
0xffffcb800001dbb8 0008 0000 0x0 0x0
0xffffcb800001dc30 0008 0000 0x0 0x0
0xffffcb800001dca8 0008 0000 0x0 0x0
0xffffcb800001dd20 0008 0000 0x0 0x0
0xffffcb800001dd98 0008 0000 0x0 0x0
0xffffcb800001de10 0008 0000 0x0 0x0
0xffffcb800001de88 0008 0000 0x0 0x0
0xffffcb800001df00 0008 0000 0x0 0x0
0xffffcb800001df78 0008 0000 0x0 0x0
0xffffcb800001dff0 0008 0000 0x0 0x0
0xffffcb800001e068 0008 0000 0x0 0x0
0xffffcb800001e0e0 0008 0000 0x0 0x0
0xffffcb800001e158 0008 0000 0x0 0x0
0xffffcb800001e1d0 0008 0000 0x0 0x0
0xffffcb800001e248 0008 0000 0x0 0x0
0xffffcb800001e2c0 0008 0000 0x0 0x0
0xffffcb800001e338 0008 0000 0x0 0x0
0xffffcb800001e3b0 0008 0000 0x0 0x0
0xffffcb800001e428 0008 0000 0x0 0x0
0xffffcb800001e4a0 0008 0000 0x0 0x0
0xffffcb800001e518 0008 0000 0x0 0x0
0xffffcb800001e590 0008 0000 0x0 0x0
0xffffcb800001e608 0008 0000 0x0 0x0
0xffffcb800001e680 0008 0000 0x0 0x0
0xffffcb800001e6f8 0008 0000 0x0 0x0
0xffffcb800001e770 0008 0000 0x0 0x0
0xffffcb800001e7e8 0008 0000 0x0 0x0
0xffffcb800001e860 0008 0000 0x0 0x0
0xffffcb800001e8d8 0008 0000 0x0 0x0
0xffffcb800001e950 0008 0000 0x0 0x0
0xffffcb800001e9c8 0008 0000 0x0 0x0
0xffffcb800001ea40 0008 0000 0x0 0x0
0xffffcb800001eab8 0008 0000 0x0 0x0
0xffffcb800001eb30 0008 0000 0x0 0x0
0xffffcb800001eba8 0008 0000 0x0 0x0
0xffffcb800001ec20 0008 0000 0x0 0x0
0xffffcb800001ec98 0008 0000 0x0 0x0
0xffffcb800001ed10 0008 0000 0x0 0x0
0xffffcb800001ed88 0048 0000 0x0 0x0
0xffffcb800001ee00 0048 0000 0x0 0x0
0xffffcb800001ee78 0048 0000 0x0 0x0
0xffffcb800001eef0 0048 0000 0x0 0x0
0xffffcb800001ef68 0048 0000 0x0 0x0
0xffffcb800001efe0 0048 0000 0x0 0x0
0xffffcb800001f058 0048 0000 0x0 0x0
0xffffcb800001f0d0 0048 0000 0x0 0x0
0xffffcb800001f148 0048 0000 0x0 0x0
0xffffcb800001f1c0 0048 0000 0x0 0x0
0xffffcb800001f238 0048 0000 0x0 0x0
0xffffcb800001f2b0 0048 0000 0x0 0x0
0xffffcb800001f328 0048 0000 0x0 0x0
0xffffcb800001f3a0 0048 0000 0x0 0x0
0xffffcb800001f418 0048 0000 0x0 0x0
0xffffcb800001f490 0048 0000 0x0 0x0
0xffffcb800001f508 0048 0000 0x0 0x0
0xffffcb800001f580 0048 0000 0x0 0x0
0xffffcb800001f5f8 0048 0000 0x0 0x0
0xffffcb800001f670 0048 0000 0x0 0x0
0xffffcb800001f6e8 0048 0000 0x0 0x0
0xffffcb800001f760 0048 0000 0x0 0x0
0xffffcb800001f7d8 0048 0000 0x0 0x0
0xffffcb800001f850 0048 0000 0x0 0x0
0xffffcb800001f8c8 0048 0000 0x0 0x0
0xffffcb800001f940 0048 0000 0x0 0x0
0xffffcb800001f9b8 0048 0000 0x0 0x0
0xffffcb800001fa30 0048 0000 0x0 0x0
0xffffcb800001faa8 0040 0000 0x0 0x0
0xffffcb800001fb20 0040 0000 0x0 0x0
0xffffcb800001fb98 0048 0000 0x0 0x0
0xffffcb800001fc10 0040 0000 0x0 0x0
0xffffcb800001fc88 0048 0000 0x0 0x0
0xffffcb800001fd00 0048 0000 0x0 0x0
0xffffcb800001fd78 0048 0000 0x0 0x0
0xffffcb800001fdf0 0048 0000 0x0 0x0
0xffffcb800001fe68 0040 0000 0x0 0x0
0xffffcb800001fee0 0040 0000 0x0 0x0
0xffffcb800001ff58 0040 0000 0x0 0x0
0xffffcb800001ffd0 0040 0000 0x0 0x0
0xffffcb8000020048 0040 0000 0x0 0x0
0xffffcb80000200c0 0048 0000 0x0 0x0
0xffffcb8000020138 0048 0000 0x0 0x0
0xffffcb80000201b0 0008 0000 0x0 0x0
0xffffcb8000020228 0008 0000 0x0 0x0
0xffffcb80000202a0 0008 0000 0x0 0x0
0xffffcb8000020318 0008 0000 0x0 0x0
0xffffcb8000020390 0008 0000 0x0 0x0
0xffffcb8000020408 0008 0000 0x0 0x0
0xffffcb8000020480 0008 0000 0x0 0x0
0xffffcb80000204f8 0008 0000 0x0 0x0
0xffffcb8000020570 0008 0000 0x0 0x0
0xffffcb80000205e8 0008 0000 0x0 0x0
0xffffcb8000020660 0008 0000 0x0 0x0
0xffffcb80000206d8 0008 0000 0x0 0x0
0xffffcb8000020750 0008 0000 0x0 0x0
0xffffcb80000207c8 0008 0000 0x0 0x0
0xffffcb8000020840 0008 0000 0x0 0x0
0xffffcb80000208b8 0008 0000 0x0 0x0
0xffffcb8000020930 0008 0000 0x0 0x0
0xffffcb80000209a8 0008 0000 0x0 0x0
0xffffcb8000020a20 0008 0000 0x0 0x0
0xffffcb8000020a98 0008 0000 0x0 0x0
0xffffcb8000020b10 0008 0000 0x0 0x0
0xffffcb8000020b88 0008 0000 0x0 0x0
0xffffcb8000020c00 0008 0000 0x0 0x0
0xffffcb8000020c78 0008 0000 0x0 0x0
0xffffcb8000020cf0 0008 0000 0x0 0x0
0xffffcb8000020d68 0008 0000 0x0 0x0
0xffffcb8000020de0 0008 0000 0x0 0x0
0xffffcb8000020e58 0008 0000 0x0 0x0
0xffffcb8000020ed0 0008 0000 0x0 0x0
0xffffcb8000020f48 0008 0000 0x0 0x0
0xffffcb8000020fc0 0008 0000 0x0 0x0
0xffffcb8000021038 0008 0000 0x0 0x0
0xffffcb80000210b0 0008 0000 0x0 0x0
0xffffcb8000021128 0008 0000 0x0 0x0
0xffffcb80000211a0 0008 0000 0x0 0x0
0xffffcb8000021218 0008 0000 0x0 0x0
0xffffcb8000021290 0008 0000 0x0 0x0
0xffffcb8000021308 0008 0000 0x0 0x0
0xffffcb8000021380 0008 0000 0x0 0x0
0xffffcb80000213f8 0008 0000 0x0 0x0
0xffffcb8000021470 0008 0000 0x0 0x0
0xffffcb80000214e8 0008 0000 0x0 0x0
0xffffcb8000021560 0008 0000 0x0 0x0
0xffffcb80000215d8 0008 0000 0x0 0x0
0xffffcb8000021650 0008 0000 0x0 0x0
0xffffcb80000216c8 0008 0000 0x0 0x0
0xffffcb8000021740 0008 0000 0x0 0x0
0xffffcb80000217b8 0008 0000 0x0 0x0
0xffffcb8000021830 0008 0000 0x0 0x0
0xffffcb80000218a8 0008 0000 0x0 0x0
0xffffcb8000021920 0008 0000 0x0 0x0
0xffffcb8000021998 0008 0000 0x0 0x0
0xffffcb8000021a10 0008 0000 0x0 0x0
0xffffcb8000021a88 0008 0000 0x0 0x0
0xffffcb8000021b00 0040 0000 0x0 0x0
0xffffcb8000021b78 0040 0000 0x0 0x0
0xffffcb8000021bf0 0040 0000 0x0 0x0
0xffffcb8000021c68 0040 0000 0x0 0x0
0xffffcb8000021ce0 0040 0000 0x0 0x0
0xffffcb8000021d58 0040 0000 0x0 0x0
0xffffcb8000021dd0 0040 0000 0x0 0x0
0xffffcb8000021e48 0040 0000 0x0 0x0
0xffffcb8000021ec0 0040 0000 0x0 0x0
0xffffcb8000021f38 0040 0000 0x0 0x0
0xffffcb8000021fb0 0040 0000 0x0 0x0
0xffffcb8000022028 0040 0000 0x0 0x0
0xffffcb80000220a0 0040 0000 0x0 0x0
0xffffcb8000022118 0040 0000 0x0 0x0
0xffffcb8000022190 0040 0000 0x0 0x0
0xffffcb8000022208 0040 0000 0x0 0x0
0xffffcb8000022280 0040 0000 0x0 0x0
0xffffcb80000222f8 0040 0000 0x0 0x0
0xffffcb8000022370 0040 0000 0x0 0x0
0xffffcb80000223e8 0040 0000 0x0 0x0
0xffffcb8000022460 0040 0000 0x0 0x0
0xffffcb80000224d8 0040 0000 0x0 0x0
0xffffcb8000022550 0040 0000 0x0 0x0
0xffffcb80000225c8 0040 0000 0x0 0x0
0xffffcb8000022640 0040 0000 0x0 0x0
0xffffcb80000226b8 0040 0000 0x0 0x0
0xffffcb8000022730 0040 0000 0x0 0x0
0xffffcb80000227a8 0040 0000 0x0 0x0
0xffffcb8000022820 0040 0000 0x0 0x0
0xffffcb8000022898 0040 0000 0x0 0x0
0xffffcb8000022910 0040 0000 0x0 0x0
0xffffcb8000022988 0040 0000 0x0 0x0
0xffffcb8000022a00 0040 0000 0x0 0x0
0xffffcb8000022a78 0040 0000 0x0 0x0
0xffffcb8000022af0 0040 0000 0x0 0x0
0xffffcb8000022b68 0040 0000 0x0 0x0
0xffffcb8000022be0 0040 0000 0x0 0x0
0xffffcb8000022c58 0040 0000 0x0 0x0
0xffffcb8000022cd0 0040 0000 0x0 0x0
0xffffcb8000022d48 0040 0000 0x0 0x0
0xffffcb8000022dc0 0040 0000 0x0 0x0
0xffffcb8000022e38 0040 0000 0x0 0x0
0xffffcb8000022eb0 0040 0000 0x0 0x0
0xffffcb8000022f28 0040 0000 0x0 0x0
0xffffcb8000022fa0 0040 0000 0x0 0x0
0xffffcb8000023018 0040 0000 0x0 0x0
0xffffcb8000023090 0040 0000 0x0 0x0
0xffffcb8000023108 0040 0000 0x0 0x0
0xffffcb8000023180 0040 0000 0x0 0x0
0xffffcb80000231f8 0040 0000 0x0 0x0
0xffffcb8000023270 0040 0000 0x0 0x0
0xffffcb80000232e8 0048 0000 0x0 0x0
0xffffcb8000023360 0048 0000 0x0 0x0
0xffffcb80000233d8 0040 0000 0x0 0x0
0xffffcb8000023450 0048 0000 0x0 0x0
0xffffcb80000234c8 0040 0000 0x0 0x0
0xffffcb8000023540 0040 0000 0x0 0x0
0xffffcb80000235b8 0040 0000 0x0 0x0
0xffffcb8000023630 0040 0000 0x0 0x0
0xffffcb80000236a8 0048 0000 0x0 0x0
0xffffcb8000023720 0048 0000 0x0 0x0
0xffffcb8000023798 0040 0000 0x0 0x0
0xffffcb8000023810 0048 0000 0x0 0x0
0xffffcb8000023888 0048 0000 0x0 0x0
0xffffcb8000023900 0048 0000 0x0 0x0
0xffffcb8000023978 0048 0000 0x0 0x0
0xffffcb80000239f0 0048 0000 0x0 0x0
0xffffcb8000023a68 0048 0000 0x0 0x0
0xffffcb8000023ae0 0048 0000 0x0 0x0
0xffffcb8000023b58 0048 0000 0x0 0x0
0xffffcb8000023bd0 0048 0000 0x0 0x0
0xffffcb8000023c48 0048 0000 0x0 0x0
0xffffcb8000023cc0 0048 0000 0x0 0x0
0xffffcb8000023d38 0048 0000 0x0 0x0
0xffffcb8000023db0 0048 0000 0x0 0x0
0xffffcb8000023e28 0048 0000 0x0 0x0
0xffffcb8000023ea0 0048 0000 0x0 0x0
0xffffcb8000023f18 0048 0000 0x0 0x0
0xffffcb8000023f90 0048 0000 0x0 0x0
0xffffcb8000024008 0048 0000 0x0 0x0
0xffffcb8000024080 0048 0000 0x0 0x0
0xffffcb80000240f8 0048 0000 0x0 0x0
0xffffcb8000024170 0048 0000 0x0 0x0
0xffffcb80000241e8 0048 0000 0x0 0x0
0xffffcb8000024260 0048 0000 0x0 0x0
0xffffcb80000242d8 0048 0000 0x0 0x0
0xffffcb8000024350 0048 0000 0x0 0x0
0xffffcb80000243c8 0048 0000 0x0 0x0
0xffffcb8000024440 0048 0000 0x0 0x0
0xffffcb80000244b8 0048 0000 0x0 0x0
0xffffcb8000024530 0048 0000 0x0 0x0
0xffffcb80000245a8 0048 0000 0x0 0x0
0xffffcb8000024620 0048 0000 0x0 0x0
0xffffcb8000024698 0048 0000 0x0 0x0
0xffffcb8000024710 0048 0000 0x0 0x0
0xffffcb8000024788 0048 0000 0x0 0x0
0xffffcb8000024800 0048 0000 0x0 0x0
0xffffcb8000024878 0048 0000 0x0 0x0
0xffffcb80000248f0 0048 0000 0x0 0x0
0xffffcb8000024968 0048 0000 0x0 0x0
0xffffcb80000249e0 0048 0000 0x0 0x0
0xffffcb8000024a58 0048 0000 0x0 0x0
0xffffcb8000024ad0 0048 0000 0x0 0x0
0xffffcb8000024b48 0048 0000 0x0 0x0
0xffffcb8000024bc0 0048 0000 0x0 0x0
0xffffcb8000024c38 0048 0000 0x0 0x0
0xffffcb8000024cb0 0048 0000 0x0 0x0
0xffffcb8000024d28 0048 0000 0x0 0x0
0xffffcb8000024da0 0048 0000 0x0 0x0
0xffffcb8000024e18 0048 0000 0x0 0x0
0xffffcb8000024e90 0048 0000 0x0 0x0
0xffffcb8000024f08 0048 0000 0x0 0x0
0xffffcb8000024f80 0048 0000 0x0 0x0
0xffffcb8000024ff8 0048 0000 0x0 0x0
0xffffcb8000025070 0048 0000 0x0 0x0
0xffffcb80000250e8 0048 0000 0x0 0x0
0xffffcb8000025160 0048 0000 0x0 0x0
0xffffcb80000251d8 0048 0000 0x0 0x0
0xffffcb8000025250 0008 0000 0x0 0x0
0xffffcb80000252c8 0008 0000 0x0 0x0
0xffffcb8000025340 0008 0000 0x0 0x0
0xffffcb80000253b8 0008 0000 0x0 0x0
0xffffcb8000025430 0008 0000 0x0 0x0
0xffffcb80000254a8 0008 0000 0x0 0x0
0xffffcb8000025520 0008 0000 0x0 0x0
0xffffcb8000025598 0008 0000 0x0 0x0
0xffffcb8000025610 0008 0000 0x0 0x0
0xffffcb8000025688 0008 0000 0x0 0x0
0xffffcb8000025700 0008 0000 0x0 0x0
0xffffcb8000025778 0008 0000 0x0 0x0
0xffffcb80000257f0 0008 0000 0x0 0x0
0xffffcb8000025868 0008 0000 0x0 0x0
0xffffcb80000258e0 0008 0000 0x0 0x0
0xffffcb8000025958 0008 0000 0x0 0x0
0xffffcb80000259d0 0008 0000 0x0 0x0
0xffffcb8000025a48 0008 0000 0x0 0x0
0xffffcb8000025ac0 0008 0000 0x0 0x0
0xffffcb8000025b38 0008 0000 0x0 0x0
0xffffcb8000025bb0 0008 0000 0x0 0x0
0xffffcb8000025c28 0008 0000 0x0 0x0
0xffffcb8000025ca0 0008 0000 0x0 0x0
0xffffcb8000025d18 0008 0000 0x0 0x0
0xffffcb8000025d90 0008 0000 0x0 0x0
0xffffcb8000025e08 0008 0000 0x0 0x0
0xffffcb8000025e80 0008 0000 0x0 0x0
0xffffcb8000025ef8 0008 0000 0x0 0x0
0xffffcb8000025f70 0008 0000 0x0 0x0
0xffffcb8000025fe8 0008 0000 0x0 0x0
0xffffcb8000026060 0008 0000 0x0 0x0
0xffffcb80000260d8 0008 0000 0x0 0x0
0xffffcb8000026150 0008 0000 0x0 0x0
0xffffcb80000261c8 0008 0000 0x0 0x0
0xffffcb8000026240 0008 0000 0x0 0x0
0xffffcb80000262b8 0008 0000 0x0 0x0
0xffffcb8000026330 0008 0000 0x0 0x0
0xffffcb80000263a8 0008 0000 0x0 0x0
0xffffcb8000026420 0008 0000 0x0 0x0
0xffffcb8000026498 0008 0000 0x0 0x0
0xffffcb8000026510 0008 0000 0x0 0x0
0xffffcb8000026588 0008 0000 0x0 0x0
0xffffcb8000026600 0008 0000 0x0 0x0
0xffffcb8000026678 0008 0000 0x0 0x0
0xffffcb80000266f0 0008 0000 0x0 0x0
0xffffcb8000026768 0008 0000 0x0 0x0
0xffffcb80000267e0 0008 0000 0x0 0x0
0xffffcb8000026858 0008 0000 0x0 0x0
0xffffcb80000268d0 0008 0000 0x0 0x0
0xffffcb8000026948 0008 0000 0x0 0x0
0xffffcb80000269c0 0008 0000 0x0 0x0
0xffffcb8000026a38 0008 0000 0x0 0x0
0xffffcb8000026ab0 0008 0000 0x0 0x0
0xffffcb8000026b28 0008 0000 0x0 0x0
0xffffcb8000026ba0 0008 0000 0x0 0x0
0xffffcb8000026c18 0008 0000 0x0 0x0
0xffffcb8000026c90 0008 0000 0x0 0x0
0xffffcb8000026d08 0008 0000 0x0 0x0
0xffffcb8000026d80 0008 0000 0x0 0x0
0xffffcb8000026df8 0008 0000 0x0 0x0
0xffffcb8000026e70 0008 0000 0x0 0x0
0xffffcb8000026ee8 0008 0000 0x0 0x0
0xffffcb8000026f60 0008 0000 0x0 0x0
0xffffcb8000026fd8 0008 0000 0x0 0x0
0xffffcb8000027050 0008 0000 0x0 0x0
0xffffcb80000270c8 0008 0000 0x0 0x0
0xffffcb8000027140 0008 0000 0x0 0x0
0xffffcb80000271b8 0008 0000 0x0 0x0
0xffffcb8000027230 0008 0000 0x0 0x0
0xffffcb80000272a8 0008 0000 0x0 0x0
0xffffcb8000027320 0008 0000 0x0 0x0
0xffffcb8000027398 0008 0000 0x0 0x0
0xffffcb8000027410 0008 0000 0x0 0x0
0xffffcb8000027488 0008 0000 0x0 0x0
0xffffcb8000027500 0008 0000 0x0 0x0
0xffffcb8000027578 0008 0000 0x0 0x0
0xffffcb80000275f0 0008 0000 0x0 0x0
0xffffcb8000027668 0008 0000 0x0 0x0
0xffffcb80000276e0 0008 0000 0x0 0x0
0xffffcb8000027758 0008 0000 0x0 0x0
0xffffcb80000277d0 0008 0000 0x0 0x0
0xffffcb8000027848 0008 0000 0x0 0x0
0xffffcb80000278c0 0008 0000 0x0 0x0
0xffffcb8000027938 0008 0000 0x0 0x0
0xffffcb80000279b0 0008 0000 0x0 0x0
0xffffcb8000027a28 0008 0000 0x0 0x0
0xffffcb8000027aa0 0008 0000 0x0 0x0
0xffffcb8000027b18 0008 0000 0x0 0x0
0xffffcb8000027b90 0008 0000 0x0 0x0
0xffffcb8000027c08 0008 0000 0x0 0x0
0xffffcb8000027c80 0008 0000 0x0 0x0
0xffffcb8000027cf8 0008 0000 0x0 0x0
0xffffcb8000027d70 0008 0000 0x0 0x0
0xffffcb8000027de8 0008 0000 0x0 0x0
0xffffcb8000027e60 0008 0000 0x0 0x0
0xffffcb8000027ed8 0008 0000 0x0 0x0
0xffffcb8000027f50 0008 0000 0x0 0x0
0xffffcb8000027fc8 0008 0000 0x0 0x0
0xffffcb8000028040 0008 0000 0x0 0x0
0xffffcb80000280b8 0008 0000 0x0 0x0
0xffffcb8000028130 0008 0000 0x0 0x0
0xffffcb80000281a8 0008 0000 0x0 0x0
0xffffcb8000028220 0008 0000 0x0 0x0
0xffffcb8000028298 0008 0000 0x0 0x0
0xffffcb8000028310 0008 0000 0x0 0x0
0xffffcb8000028388 0008 0000 0x0 0x0
0xffffcb8000028400 0008 0000 0x0 0x0
0xffffcb8000028478 0008 0000 0x0 0x0
0xffffcb80000284f0 0008 0000 0x0 0x0
0xffffcb8000028568 0008 0000 0x0 0x0
0xffffcb80000285e0 0008 0000 0x0 0x0
0xffffcb8000028658 0008 0000 0x0 0x0
0xffffcb80000286d0 0008 0000 0x0 0x0
0xffffcb8000028748 0008 0000 0x0 0x0
0xffffcb80000287c0 0008 0000 0x0 0x0
0xffffcb8000028838 0008 0000 0x0 0x0
0xffffcb80000288b0 0008 0000 0x0 0x0
0xffffcb8000028928 0008 0000 0x0 0x0
0xffffcb80000289a0 0008 0000 0x0 0x0
0xffffcb8000028a18 0008 0000 0x0 0x0
0xffffcb8000028a90 0008 0000 0x0 0x0
0xffffcb8000028b08 0008 0000 0x0 0x0
0xffffcb8000028b80 0008 0000 0x0 0x0
0xffffcb8000028bf8 0008 0000 0x0 0x0
0xffffcb8000028c70 0008 0000 0x0 0x0
0xffffcb8000028ce8 0008 0000 0x0 0x0
0xffffcb8000028d60 0008 0000 0x0 0x0
0xffffcb8000028dd8 0008 0000 0x0 0x0
0xffffcb8000028e50 0008 0000 0x0 0x0
0xffffcb8000028ec8 0008 0000 0x0 0x0
0xffffcb8000028f40 0008 0000 0x0 0x0
0xffffcb8000028fb8 0008 0000 0x0 0x0
0xffffcb8000029030 0008 0000 0x0 0x0
0xffffcb80000290a8 0008 0000 0x0 0x0
0xffffcb8000029120 0008 0000 0x0 0x0
0xffffcb8000029198 0008 0000 0x0 0x0
0xffffcb8000029210 0008 0000 0x0 0x0
0xffffcb8000029288 0008 0000 0x0 0x0
0xffffcb8000029300 0008 0000 0x0 0x0
0xffffcb8000029378 0008 0000 0x0 0x0
0xffffcb80000293f0 0008 0000 0x0 0x0
0xffffcb8000029468 0008 0000 0x0 0x0
0xffffcb80000294e0 0008 0000 0x0 0x0
0xffffcb8000029558 0008 0000 0x0 0x0
0xffffcb80000295d0 0008 0000 0x0 0x0
0xffffcb8000029648 0008 0000 0x0 0x0
0xffffcb80000296c0 0008 0000 0x0 0x0
0xffffcb8000029738 0008 0000 0x0 0x0
0xffffcb80000297b0 0008 0000 0x0 0x0
0xffffcb8000029828 0008 0000 0x0 0x0
0xffffcb80000298a0 0008 0000 0x0 0x0
0xffffcb8000029918 0008 0000 0x0 0x0
0xffffcb8000029990 0008 0000 0x0 0x0
0xffffcb8000029a08 0008 0000 0x0 0x0
0xffffcb8000029a80 0008 0000 0x0 0x0
0xffffcb8000029af8 0008 0000 0x0 0x0
0xffffcb8000029b70 0008 0000 0x0 0x0
0xffffcb8000029be8 0008 0000 0x0 0x0
0xffffcb8000029c60 0008 0000 0x0 0x0
0xffffcb8000029cd8 0008 0000 0x0 0x0
0xffffcb8000029d50 0008 0000 0x0 0x0
0xffffcb8000029dc8 0008 0000 0x0 0x0
0xffffcb8000029e40 0008 0000 0x0 0x0
0xffffcb8000029eb8 0008 0000 0x0 0x0
0xffffcb8000029f30 0008 0000 0x0 0x0
0xffffcb8000029fa8 0008 0000 0x0 0x0
0xffffcb800002a020 0008 0000 0x0 0x0
0xffffcb800002a098 0008 0000 0x0 0x0
0xffffcb800002a110 0008 0000 0x0 0x0
0xffffcb800002a188 0008 0000 0x0 0x0
0xffffcb800002a200 0008 0000 0x0 0x0
0xffffcb800002a278 0008 0000 0x0 0x0
0xffffcb800002a2f0 0008 0000 0x0 0x0
0xffffcb800002a368 0008 0000 0x0 0x0
0xffffcb800002a3e0 0008 0000 0x0 0x0
0xffffcb800002a458 0008 0000 0x0 0x0
0xffffcb800002a4d0 0008 0000 0x0 0x0
0xffffcb800002a548 0008 0000 0x0 0x0
0xffffcb800002a5c0 0008 0000 0x0 0x0
0xffffcb800002a638 0008 0000 0x0 0x0
0xffffcb800002a6b0 0008 0000 0x0 0x0
0xffffcb800002a728 0008 0000 0x0 0x0
0xffffcb800002a7a0 0008 0000 0x0 0x0
0xffffcb800002a818 0008 0000 0x0 0x0
0xffffcb800002a890 0008 0000 0x0 0x0
0xffffcb800002a908 0008 0000 0x0 0x0
0xffffcb800002a980 0008 0000 0x0 0x0
0xffffcb800002a9f8 0008 0000 0x0 0x0
0xffffcb800002aa70 0008 0000 0x0 0x0
0xffffcb800002aae8 0008 0000 0x0 0x0
0xffffcb800002ab60 0008 0000 0x0 0x0
0xffffcb800002abd8 0008 0000 0x0 0x0
0

---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Maxime Villard

unread,
Nov 14, 2019, 9:40:33 AM11/14/19
to syzbot, syzkaller-...@googlegroups.com
dup but garbage, close

#syz invalid
Reply all
Reply to author
Forward
0 new messages