ASan: Unauthorized Access in pmap_tlb_shootnow

0 views
Skip to first unread message

syzbot

unread,
May 19, 2024, 2:23:19 AMMay 19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 43bbf82ac46a allow things to compile again
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=147bfdf0980000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=15670fee636fa770b872
compiler: g++ (Debian 12.2.0-14) 12.2.0

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/c6dbb17acfc3/disk-43bbf82a.raw.xz
netbsd.gdb: https://storage.googleapis.com/syzbot-assets/eedf0861d771/netbsd-43bbf82a.gdb.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+15670f...@syzkaller.appspotmail.com

[ 541.5745092] panic: ASan: Unauthorized Access In 0xffffffff81bd1b04: Addr 0xffffdd80128f99f8 [8 bytes, write, PoolUseAfterFree]

[ 541.5745092] cpu0: Begin traceback...
[ 541.5745092] vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:288
[ 541.5745092] panic() at netbsd:panic+0x9e sys/kern/subr_prf.c:1084
[ 541.5745092] kasan_report() at netbsd:kasan_report+0x8f kasan_code_name sys/kern/subr_asan.c:169 [inline]
[ 541.5745092] kasan_report() at netbsd:kasan_report+0x8f sys/kern/subr_asan.c:201
[ 541.5745092] __asan_store8() at netbsd:__asan_store8+0xaf kasan_shadow_8byte_isvalid sys/kern/subr_asan.c:371 [inline]
[ 541.5745092] __asan_store8() at netbsd:__asan_store8+0xaf kasan_shadow_check sys/kern/subr_asan.c:421 [inline]
[ 541.5745092] __asan_store8() at netbsd:__asan_store8+0xaf sys/kern/subr_asan.c:1208
[ 541.5745092] callout_hardclock() at netbsd:callout_hardclock+0xfd sys/kern/kern_timeout.c:797
[ 541.5745092] hardclock() at netbsd:hardclock+0x196 sys/kern/kern_clock.c:304
[ 541.5745092] Xresume_lapic_ltimer() at netbsd:Xresume_lapic_ltimer+0x1e
[ 541.5745092] --- interrupt ---
[ 541.5745092] __asan_store2_noabort() at netbsd:__asan_store2_noabort+0x5 sys/kern/subr_asan.c:1207
[ 541.5745092] pmap_tlb_shootnow() at netbsd:pmap_tlb_shootnow+0xa2 sys/arch/x86/x86/x86_tlb.c:370
[ 541.5745092] pmap_pp_clear_attrs() at netbsd:pmap_pp_clear_attrs+0x296 sys/arch/x86/x86/pmap.c:4737
[ 541.5745092] pmap_clear_attrs() at netbsd:pmap_clear_attrs+0x1f6 sys/arch/x86/x86/pmap.c:4767
[ 541.5745092] uvmpdpol_balancequeue() at netbsd:uvmpdpol_balancequeue+0x399 sys/uvm/uvm_pdpolicy_clock.c:431
[ 541.5745092] uvm_pageout() at netbsd:uvm_pageout+0xb7f uvmpd_scan sys/uvm/uvm_pdaemon.c:941 [inline]
[ 541.5745092] uvm_pageout() at netbsd:uvm_pageout+0xb7f sys/uvm/uvm_pdaemon.c:318
[ 541.5745092] cpu0: End traceback...
[ 541.5745092] fatal breakpoint trap in supervisor mode
[ 541.5745092] trap type 1 code 0 rip 0xffffffff8023240d cs 0x8 rflags 0x246 cr2 0x743d4a600000 ilevel 0x8 rsp 0xffffdd82482094b8
[ 541.5745092] curlwp 0xffffdd80129bfb00 pid 0.194 lowest kstack 0xffffdd82482022c0
Stopped in pid 0.194 (system) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0x105 sys/ddb/db_panic.c:71
vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:288
panic() at netbsd:panic+0x9e sys/kern/subr_prf.c:1084
kasan_report() at netbsd:kasan_report+0x8f kasan_code_name sys/kern/subr_asan.c:169 [inline]
kasan_report() at netbsd:kasan_report+0x8f sys/kern/subr_asan.c:201
__asan_store8() at netbsd:__asan_store8+0xaf kasan_shadow_8byte_isvalid sys/kern/subr_asan.c:371 [inline]
__asan_store8() at netbsd:__asan_store8+0xaf kasan_shadow_check sys/kern/subr_asan.c:421 [inline]
__asan_store8() at netbsd:__asan_store8+0xaf sys/kern/subr_asan.c:1208
callout_hardclock() at netbsd:callout_hardclock+0xfd sys/kern/kern_timeout.c:797
hardclock() at netbsd:hardclock+0x196 sys/kern/kern_clock.c:304
Xresume_lapic_ltimer() at netbsd:Xresume_lapic_ltimer+0x1e
--- interrupt ---
__asan_store2_noabort() at netbsd:__asan_store2_noabort+0x5 sys/kern/subr_asan.c:1207
pmap_tlb_shootnow() at netbsd:pmap_tlb_shootnow+0xa2 sys/arch/x86/x86/x86_tlb.c:370
pmap_pp_clear_attrs() at netbsd:pmap_pp_clear_attrs+0x296 sys/arch/x86/x86/pmap.c:4737
pmap_clear_attrs() at netbsd:pmap_clear_attrs+0x1f6 sys/arch/x86/x86/pmap.c:4767
uvmpdpol_balancequeue() at netbsd:uvmpdpol_balancequeue+0x399 sys/uvm/uvm_pdpolicy_clock.c:431
uvm_pageout() at netbsd:uvm_pageout+0xb7f uvmpd_scan sys/uvm/uvm_pdaemon.c:941 [inline]
uvm_pageout() at netbsd:uvm_pageout+0xb7f sys/uvm/uvm_pdaemon.c:318
Panic string: ASan: Unauthorized Access In 0xffffffff81bd1b04: Addr 0xffffdd80128f99f8 [8 bytes, write, PoolUseAfterFree]

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
12334 12334 2 0 0 ffffdd8012b7d980 syz-executor.1
6016 6016 3 0 0 ffffdd8014608ac0 sh fltamapcopy
10699 10699 2 0 0 ffffdd8014acf040 syz-executor.5
5700 5700 3 0 180 ffffdd8014a37bc0 syz-executor.5 parked
5535 5882 3 1 180 ffffdd8014a37780 syz-executor.2 parked
5535 5628 3 1 180 ffffdd8012d60480 syz-executor.2 parked
5535 5535 2 1 10000000 ffffdd8012cfcac0 syz-executor.2
10956 6031 3 0 180 ffffdd8012d608c0 syz-executor.5 wait
10956 8155 3 0 180 ffffdd8012a72480 syz-executor.5 parked
10956 10956 2 0 10000000 ffffdd80149d9300 syz-executor.5
11085 11085 2 1 10040000 ffffdd8013e0bac0 syz-executor.0
5989 > 5989 7 1 40000 ffffdd8012a20300 syz-executor.3
5103 5103 3 1 180 ffffdd80133c76c0 syz-executor.1 wait
5777 5777 3 1 180 ffffdd801344f080 syz-executor.5 parked
12543 12543 3 0 180 ffffdd80140bf0c0 syz-executor.5 parked
5270 5270 4 1 1000140 ffffdd8013db7600 syz-executor.0
11476 11476 3 1 180 ffffdd8013f4db80 syz-executor.4 wait
11057 11057 2 1 140 ffffdd8012c28b00 syz-executor.5
5157 5157 2 1 140 ffffdd8013459940 syz-executor.2
5703 5703 3 1 180 ffffdd80126d7740 syz-executor.3 parked
11451 11451 3 0 180 ffffdd80146a6b00 syz-executor.3 parked
4593 4593 3 0 180 ffffdd8012d16700 syz-executor.1 parked
4487 4487 3 1 180 ffffdd8012a54780 syz-executor.5 parked
5193 5193 3 1 180 ffffdd8012b9b580 syz-executor.3 parked
4077 4077 3 1 180 ffffdd8013de7a80 syz-executor.1 parked
9836 9836 3 1 180 ffffdd8012ccc580 syz-executor.0 parked
2882 2882 3 1 180 ffffdd8012d24740 syz-executor.3 parked
2788 2788 3 0 180 ffffdd80146e62c0 syz-executor.1 parked
2718 2718 3 1 180 ffffdd8013459500 syz-executor.0 parked
9546 9546 3 0 180 ffffdd8014563a80 syz-executor.5 parked
1068 1068 3 0 180 ffffdd8013337980 syz-executor.0 parked
7404 7404 3 0 180 ffffdd8012a72040 syz-executor.4 parked
1385 1006 3 0 1100000 ffffdd8012c84780 syz-executor.4 vfork
1385 1385 2 1 11000040 ffffdd8013445040 syz-executor.4
7733 7733 3 0 180 ffffdd8012c4a700 syz-executor.1 parked
651 651 3 1 180 ffffdd8012b7d540 syz-executor.5 parked
510 510 3 0 180 ffffdd8013462540 syz-executor.4 parked
7728 7728 3 0 180 ffffdd801337da00 syz-executor.2 parked
6584 6746 3 0 1100000 ffffdd801337d180 syz-executor.2 vfork
6584 6584 2 1 11000040 ffffdd80133a5640 syz-executor.2
4028 4028 3 0 180 ffffdd8012a728c0 syz-executor.2 parked
3141 5408 3 0 1100000 ffffdd8012c84340 syz-executor.2 vfork
3141 3141 2 1 11000040 ffffdd8012da5940 syz-executor.2
2651 2651 3 1 180 ffffdd8012cd5180 ndp netio
1238 4853 3 1 180 ffffdd8013e0b240 syz-fuzzer wait
1238 2750 3 1 180 ffffdd801342d740 syz-fuzzer wait
1238 1209 3 0 180 ffffdd8013ef12c0 syz-fuzzer parked
1238 1235 2 1 140 ffffdd8013e496c0 syz-fuzzer
1238 1202 3 1 180 ffffdd8013de7640 syz-fuzzer wait
1238 930 3 1 180 ffffdd8012b7d100 syz-fuzzer parked
1238 1237 3 1 180 ffffdd8012bc2180 syz-fuzzer wait
1238 991 3 0 180 ffffdd8013de7200 syz-fuzzer parked
1238 829 3 1 180 ffffdd8013db71c0 syz-fuzzer parked
1238 1067 3 1 180 ffffdd8012c69b80 syz-fuzzer wait
1238 449 3 0 180 ffffdd801341e2c0 syz-fuzzer wait
1238 1130 3 1 180 ffffdd8012ccc140 syz-fuzzer parked
1238 1233 3 0 180 ffffdd8013439bc0 syz-fuzzer parked
1238 1239 2 1 140 ffffdd80134458c0 syz-fuzzer
1238 1238 3 0 180 ffffdd8012a99080 syz-fuzzer parked
1222 1222 3 0 180 ffffdd8012ac9500 sshd select
820 820 3 0 180 ffffdd80126db480 getty nanoslp
1223 1223 3 0 180 ffffdd801348f5c0 getty nanoslp
1225 1225 3 1 180 ffffdd80126d7b80 getty nanoslp
1224 1224 3 0 180 ffffdd80129bf280 getty ttyraw
1103 1103 3 0 180 ffffdd80133a5200 sshd select
954 954 3 0 180 ffffdd8012d16b40 powerd kqueue
809 809 3 0 180 ffffdd8012d24b80 syslogd kqueue
606 606 3 0 180 ffffdd8012c286c0 dhcpcd poll
744 744 3 0 180 ffffdd8012cbf100 dhcpcd poll
559 559 3 0 180 ffffdd8012c84bc0 dhcpcd poll
604 604 3 1 180 ffffdd8012c4ab40 dhcpcd poll
487 487 3 0 180 ffffdd8012da50c0 dhcpcd poll
292 292 3 0 180 ffffdd8012d8f900 dhcpcd poll
485 485 3 0 180 ffffdd8012d8f4c0 dhcpcd poll
1 1 3 1 180 ffffdd8012870180 init wait
0 5110 3 1 200 ffffdd8012a99900 ktrace ktrwait
0 5839 3 0 200 ffffdd8012d24300 poolthread pooljob
0 10144 5 1 200 ffffdd80133a5a80 (zombie)
0 8154 3 0 200 ffffdd8012c4a2c0 acctwatch actwat
0 1384 3 1 200 ffffdd8013f7ebc0 ktrace ktrwait
0 8000 3 0 200 ffffdd8012d0b6c0 ktrace ktrwait
0 673 3 0 200 ffffdd80129bf6c0 physiod physiod
0 196 3 1 200 ffffdd80129c1700 pooldrain pooldrain
0 195 3 0 200 ffffdd80129c12c0 ioflush syncer
0 > 194 7 0 200 ffffdd80129bfb00 pgdaemon
0 167 3 0 200 ffffdd8012976ac0 usb7 usbevt
0 172 3 0 200 ffffdd8012976680 usb6 usbevt
0 170 3 1 200 ffffdd8012976240 usb5 usbevt
0 168 3 0 200 ffffdd801291ea80 usb4 usbevt
0 166 3 0 200 ffffdd801291e640 usb3 usbevt
0 165 3 0 200 ffffdd801291e200 usb2 usbevt
0 31 2 1 240 ffffdd80128caa40 usb1
0 63 3 0 200 ffffdd80128ca600 usb0 usbevt
0 126 3 0 200 ffffdd80128ca1c0 usbtask-dr usbtsk
0 125 3 1 200 ffffdd8012870a00 usbtask-hc usbtsk
0 124 3 0 200 ffffdd8010d66b00 swwreboot swwreboot
0 123 2 1 240 ffffdd80128705c0 npfgc0
0 122 3 1 200 ffffdd80128669c0 rt_free rt_free
0 121 3 0 200 ffffdd8012866580 unpgc unpgc
0 120 3 0 200 ffffdd8012866140 key_timehandler key_timehandler
0 119 3 1 200 ffffdd8012707980 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 ffffdd8012707540 icmp6_wqinput/0 icmp6_wqinput
0 117 3 0 200 ffffdd8012707100 nd6_timer nd6_timer
0 116 3 1 200 ffffdd80126fc940 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 ffffdd80126fc500 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 ffffdd80126fc0c0 carp_wqinput/1 carp_wqinput
0 113 3 0 200 ffffdd80126ef900 carp_wqinput/0 carp_wqinput
0 112 3 1 200 ffffdd80126ef4c0 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 ffffdd80126ef080 icmp_wqinput/0 icmp_wqinput
0 110 3 0 200 ffffdd80126db040 rt_timer rt_timer
0 109 3 0 200 ffffdd80126db8c0 vmem_rehash vmem_rehash
0 100 3 1 200 ffffdd80126d7300 entbutler entropy
0 99 3 0 200 ffffdd80120bcb40 viomb balloon
0 98 3 1 200 ffffdd80120bc700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 ffffdd80120bc2c0 vioif0_txrx/0 vioif0_txrx
0 30 3 0 200 ffffdd8010d666c0 scsibus0 sccomp
0 29 3 0 200 ffffdd8010d66280 pms0 pmsreset
0 28 3 1 200 ffffdd8010cacac0 xcall/1 xcall
0 27 1 1 200 ffffdd8010cac680 softser/1
0 26 1 1 200 ffffdd8010cac240 softclk/1
0 25 1 1 200 ffffdd8010ca8a80 softbio/1
0 24 1 1 200 ffffdd8010ca8640 softnet/1
0 23 1 1 201 ffffdd8010ca8200 idle/1
0 22 3 0 200 ffffdd800fb55a40 lnxsyswq lnxsyswq
0 21 3 0 200 ffffdd800fb55600 lnxubdwq lnxubdwq
0 20 3 0 200 ffffdd800fb551c0 lnxpwrwq lnxpwrwq
0 19 3 1 200 ffffdd800fb54a00 lnxlngwq lnxlngwq
0 18 3 0 200 ffffdd800fb545c0 lnxhipwq lnxhipwq
0 17 3 0 200 ffffdd800fb54180 lnxrcugc lnxrcugc
0 16 3 0 200 ffffdd800fb4d9c0 sysmon smtaskq
0 15 3 0 200 ffffdd800fb4d580 pmfsuspend pmfsuspend
0 14 3 0 200 ffffdd800fb4d140 pmfevent pmfevent
0 13 3 0 200 ffffdd800fb4a980 sopendfree sopendfr
0 12 3 1 200 ffffdd800fb4a540 ifwdog ifwdog
0 11 3 1 200 ffffdd800fb4a100 iflnkst iflnkst
0 10 3 0 200 ffffdd800fb3b940 nfssilly nfssilly
0 9 3 0 200 ffffdd800fb3b500 pooldisp pooldisp
0 8 3 1 200 ffffdd800fb3b0c0 modunload mod_unld
0 7 3 0 200 ffffdd800fb32900 xcall/0 xcall
0 6 1 0 200 ffffdd800fb324c0 softser/0
0 5 1 0 200 ffffdd800fb32080 softclk/0
0 4 1 0 200 ffffdd800fb308c0 softbio/0
0 3 1 0 200 ffffdd800fb30480 softnet/0
0 2 1 0 201 ffffdd800fb30040 idle/0
0 0 2 1 240 ffffffff8334fe40 swapper
[Locks tracked through LWPs]

****** LWP 12334.12334 (syz-executor.1) @ 0xffffdd8012b7d980, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:fork1+0x365 sys/kern/kern_fork.c:366)
lock address : ffffdd8012caeb90
type : sleep/adaptive
initialized : netbsd:fork1+0x365
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 1
relevant lwp : 0xffffdd8012b7d980 last held: 0xffffdd8012b7d980
last locked* : netbsd:execve_loadvm+0x308
unlocked : 0
owner/count : 0xffffdd8012b7d980 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:uvmspace_alloc+0x170 uvm_map_setup sys/uvm/uvm_map.c:4786 [inline])
* Lock 1 (initialized at netbsd:uvmspace_alloc+0x170 uvmspace_init sys/uvm/uvm_map.c:4129 [inline])
* Lock 1 (initialized at netbsd:uvmspace_alloc+0x170 sys/uvm/uvm_map.c:4108)
lock address : ffffdd8014937908
type : sleep/adaptive
initialized : netbsd:uvmspace_alloc+0x170
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8012b7d980 last held: 0xffffdd8012b7d980
last locked* : netbsd:uvm_map_prepare+0x198
unlocked : netbsd:uvm_map_enter+0x5ea
owner/count : 0xffffdd8012b7d980 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 10699.10699 (syz-executor.5) @ 0xffffdd8014acf040, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:fork1+0x365 sys/kern/kern_fork.c:366)
lock address : ffffdd8014ac6810
type : sleep/adaptive
initialized : netbsd:fork1+0x365
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8014acf040 last held: 0xffffdd8014acf040
last locked* : netbsd:exit1+0x2f2
unlocked : 0
owner/count : 0xffffdd8014acf040 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8014acf040 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 5535.5628 (syz-executor.2) @ 0xffffdd8012d60480, l_stat=3

*** Locks held:

* Lock 0 (initialized at netbsd:filedesc_ctor+0x37 sys/kern/kern_descrip.c:1355)
lock address : ffffdd8012d029c0
type : sleep/adaptive
initialized : netbsd:filedesc_ctor+0x37
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffdd8012d60480 last held: 0xffffdd8012d60480
last locked* : netbsd:fd_alloc+0xa3
unlocked : netbsd:fd_alloc+0x6d2
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffdd8012d60480 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 11085.11085 (syz-executor.0) @ 0xffffdd8013e0bac0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:xc_init_cpu+0xc3 xc_init sys/kern/subr_xcall.c:152 [inline])
* Lock 0 (initialized at netbsd:xc_init_cpu+0xc3 sys/kern/subr_xcall.c:242)
lock address : netbsd:xc_low_pri
type : sleep/adaptive
initialized : netbsd:xc_init_cpu+0xc3
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 1
relevant lwp : 0xffffdd8013e0bac0 last held: 000000000000000000
last locked : netbsd:xc_wait+0x14b
unlocked* : netbsd:xc_wait+0x1ac
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 5989.5989 (syz-executor.3) @ 0xffffdd8012a20300, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:fork1+0x365 sys/kern/kern_fork.c:366)
lock address : ffffdd80149e1ed0
type : sleep/adaptive
initialized : netbsd:fork1+0x365
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffdd8012a20300 last held: 0xffffdd8012a20300
last locked* : netbsd:exit1+0x2f2
unlocked : netbsd:execve_runproc+0x2211
owner/count : 0xffffdd8012a20300 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:uvm_map_setup+0x11c sys/uvm/uvm_map.c:4786)
lock address : netbsd:kernel_map_store+0x8
type : sleep/adaptive
initialized : netbsd:uvm_map_setup+0x11c
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffdd8012a20300 last held: 0xffffdd8012a20300
last locked* : netbsd:vm_map_lock+0x8f
unlocked : netbsd:uvm_unmap1+0xc3
owner/count : 0xffffdd8012a20300 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 2 (initialized at netbsd:uvm_obj_init+0x9a sys/uvm/uvm_object.c:70)
lock address : ffffdd8014aa41c0
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0x9a
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffdd8012a20300 last held: 0xffffdd8012a20300
last locked* : netbsd:uvm_map_lock_entry+0x9d
unlocked : netbsd:uvm_fault_lower_enter+0x579
owner/count : 0xffffdd8012a20300 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 3 (initialized at netbsd:pmap_bootstrap+0xc3 sys/arch/x86/x86/pmap.c:1237)
lock address : netbsd:kernel_pmap_store+0x180
type : sleep/adaptive
initialized : netbsd:pmap_bootstrap+0xc3
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffdd8012a20300 last held: 0xffffdd8012a20300
last locked* : netbsd:pmap_unwire+0xb8
unlocked : netbsd:pmap_unwire+0x32c
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1385.1006 (syz-executor.4) @ 0xffffdd8012c84780, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8012c84780 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 2651.2651 (ndp) @ 0xffffdd8012cd5180, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffdd8012cd5180 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 744.744 (dhcpcd) @ 0xffffdd8012cbf100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8012cbf100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 559.559 (dhcpcd) @ 0xffffdd8012c84bc0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8012c84bc0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 292.292 (dhcpcd) @ 0xffffdd8012d8f900, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8012d8f900 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 485.485 (dhcpcd) @ 0xffffdd8012d8f4c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd8012d8f4c0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.194 (pgdaemon) @ 0xffffdd80129bfb00, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:uvm_obj_init+0x9a sys/uvm/uvm_object.c:70)
lock address : ffffdd8013d354c0
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0x9a
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd80129bfb00 last held: 0xffffdd80129bfb00
last locked* : netbsd:uvmpd_trylockowner+0x61
unlocked : netbsd:uvmpdpol_balancequeue+0x3d8
owner/count : 0xffffdd80129bfb00 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:uvmpdpol_init+0x1c sys/uvm/uvm_pdpolicy_clock.c:643)
lock address : netbsd:pdpol_state
type : sleep/adaptive
initialized : netbsd:uvmpdpol_init+0x1c
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd80129bfb00 last held: 0xffffdd80129bfb00
last locked* : netbsd:uvmpdpol_balancequeue+0x303
unlocked : netbsd:uvmpdpol_balancequeue+0x2ec
owner field : 0xffffdd80129bfb00 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 0.26 (softclk/1) @ 0xffffdd8010cac240, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffdd8010cac240 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffffdd800fb4a100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffdd800fb4a100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffffdd800fb32080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd800fb32080 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff8334fe40, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffffff8334fe40 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu0:

* Lock 0 (initialized at netbsd:callout_startup+0x43 sys/kern/kern_timeout.c:301)
lock address : ffffdd800f652100
type : spin
initialized : netbsd:callout_startup+0x43
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd80129bfb00 last held: 0xffffdd80129bfb00
last locked* : netbsd:callout_hardclock+0x42
unlocked : netbsd:callout_hardclock+0x297
owner field : 0x0000000000010700 wait/spin: 0/1

* Lock 1 (initialized at netbsd:kprintf_init+0x61 sys/kern/subr_prf.c:156)
lock address : netbsd:kprintf_mtx
type : spin
initialized : netbsd:kprintf_init+0x61
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffdd80129bfb00 last held: 0xffffdd80129bfb00
last locked* : netbsd:kprintf_lock+0x33
unlocked : netbsd:kprintf_unlock+0x53
owner field : 0x0000000000000800 wait/spin: 0/1

PAGE FLAG PQ UOBJECT UANON
0xffffdd8000017180 0041 00000000 0x0 0x0
0xffffdd8000017200 0041 00000000 0x0 0x0
0xffffdd8000017280 0041 00000000 0x0 0x0
0xffffdd8000017300 0041 00000000 0x0 0x0
0xffffdd8000017380 0041 00000000 0x0 0x0
0xffffdd8000017400 0041 00000000 0x0 0x0
0xffffdd8000017480 0041 00000000 0x0 0x0
0xffffdd8000017500 0041 00000000 0x0 0x0
0xffffdd8000017580 0041 00000000 0x0 0x0
0xffffdd8000017600 0041 00000000 0x0 0x0
0xffffdd8000017680 0041 00000000 0x0 0x0
0xffffdd8000017700 0041 00000000 0x0 0x0
0xffffdd8000017780 0041 00000000 0x0 0x0
0xffffdd8000017800 0041 00000000 0x0 0x0
0xffffdd8000017880 0041 00000000 0x0 0x0
0xffffdd8000017900 0041 00000000 0x0 0x0
0xffffdd8000017980 0041 00000000 0x0 0x0
0xffffdd8000017a00 0041 00000000 0x0 0x0
0xffffdd8000017a80 0041 00000000 0x0 0x0
0xffffdd8000017b00 0041 00000000 0x0 0x0
0xffffdd8000017b80 0041 00000000 0x0 0x0
0xffffdd8000017c00 0041 00000000 0x0 0x0
0xffffdd8000017c80 0041 00000000 0x0 0x0
0xffffdd8000017d00 0041 00000000 0x0 0x0
0xffffdd8000017d80 0041 00000000 0x0 0x0
0xffffdd8000017e00 0041 00000000 0x0 0x0
0xffffdd8000017e80 0041 00000000 0x0 0x0
0xffffdd8000017f00 0041 00000000 0x0 0x0
0xffffdd8000017f80 0041 00000000 0x0 0x0
0xffffdd8000018000 0041 00000000 0x0 0x0
0xffffdd8000018080 0041 00000000 0x0 0x0
0xffffdd8000018100 0041 00000000 0x0 0x0
0xffffdd8000018180 0041 00000000 0x0 0x0
0xffffdd8000018200 0041 00000000 0x0 0x0
0xffffdd8000018280 0041 00000000 0x0 0x0
0xffffdd8000018300 0041 00000000 0x0 0x0
0xffffdd8000018380 0041 00000000 0x0 0x0
0xffffdd8000018400 0041 00000000 0x0 0x0
0xffffdd8000018480 0041 00000000 0x0 0x0
0xffffdd8000018500 0041 00000000 0x0 0x0
0xffffdd8000018580 0041 00000000 0x0 0x0
0xffffdd8000018600 0041 00000000 0x0 0x0
0xffffdd8000018680 0041 00000000 0x0 0x0
0xffffdd8000018700 0041 00000000 0x0 0x0
0xffffdd8000018780 0041 00000000 0x0 0x0
0xffffdd8000018800 0041 00000000 0x0 0x0
0xffffdd8000018880 0041 00000000 0x0 0x0
0xffffdd8000018900 0041 00000000 0x0 0x0
0xffffdd8000018980 0041 00000000 0x0 0x0
0xffffdd8000018a00 0041 00000000 0x0 0x0
0xffffdd8000018a80 0041 00000000 0x0 0x0
0xffffdd8000018b00 0041 00000000 0x0 0x0
0xffffdd8000018b80 0041 00000000 0x0 0x0
0xffffdd8000018c00 0041 00000000 0x0 0x0
0xffffdd8000018c80 0041 00000000 0x0 0x0
0xffffdd8000018d00 0041 00000000 0x0 0x0
0xffffdd8000018d80 0041 00000000 0x0 0x0
0xffffdd8000018e00 0041 00000000 0x0 0x0
0xffffdd8000018e80 0041 00000000 0x0 0x0
0xffffdd8000018f00 0041 00000000 0x0 0x0
0xffffdd8000018f80 0041 00000000 0x0 0x0
0xffffdd8000019000 0041 00000000 0x0 0x0
0xffffdd8000019080 0041 00000000 0x0 0x0
0xffffdd8000019100 0041 00000000 0x0 0x0
0xffffdd8000019180 0041 00000000 0x0 0x0
0xffffdd8000019200 0041 00000000 0x0 0x0
0xffffdd8000019280 0041 00000000 0x0 0x0
0xffffdd8000019300 0041 00000000 0x0 0x0
0xffffdd8000019380 0041 00000000 0x0 0x0
0xffffdd8000019400 0041 00000000 0x0 0x0
0xffffdd8000019480 0041 00000000 0x0 0x0
0xffffdd8000019500 0041 00000000 0x0 0x0
0xffffdd8000019580 0041 00000000 0x0 0x0
0xffffdd8000019600 0041 00000000 0x0 0x0
0xffffdd8000019680 0041 00000000 0x0 0x0
0xffffdd8000019700 0041 00000000 0x0 0x0
0xffffdd8000019780 0041 00000000 0x0 0x0
0xffffdd8000019800 0041 00000000 0x0 0x0
0xffffdd8000019880 0041 00000000 0x0 0x0
0xffffdd8000019900 0041 00000000 0x0 0x0
0xffffdd8000019980 0041 00000000 0x0 0x0
0xffffdd8000019a00 0041 00000000 0x0 0x0
0xffffdd8000019a80 0041 00000000 0x0 0x0
0xffffdd8000019b00 0041 00000000 0x0 0x0
0xffffdd8000019b80 0041 00000000 0x0 0x0
0xffffdd8000019c00 0041 00000000 0x0 0x0
0xffffdd8000019c80 0041 00000000 0x0 0x0
0xffffdd8000019d00 0041 00000000 0x0 0x0
0xffffdd8000019d80 0041 00000000 0x0 0x0
0xffffdd8000019e00 0041 00000000 0x0 0x0
0xffffdd8000019e80 0041 00000000 0x0 0x0
0xffffdd8000019f00 0041 00000000 0x0 0x0
0xffffdd8000019f80 0041 00000000 0x0 0x0
0xffffdd800001a000 0041 00000000 0x0 0x0
0xffffdd800001a080 0041 00000000 0x0 0x0
0xffffdd800001a100 0041 00000000 0x0 0x0
0xffffdd800001a180 0041 00000000 0x0 0x0
0xffffdd800001a200 0041 00000000 0x0 0x0
0xffffdd800001a280 0041 00000000 0x0 0x0
0xffffdd800001a300 0041 00000000 0x0 0x0
0xffffdd800001a380 0041 00000000 0x0 0x0
0xffffdd800001a400 0041 00000000 0x0 0x0
0xffffdd800001a480 0041 00000000 0x0 0x0
0xffffdd800001a500 0041 00000000 0x0 0x0
0xffffdd800001a580 0041 00000000 0x0 0x0
0xffffdd800001a600 0041 00000000 0x0 0x0
0xffffdd800001a680 0041 00000000 0x0 0x0
0xffffdd800001a700 0041 00000000 0x0 0x0
0xffffdd800001a780 0041 00000000 0x0 0x0
0xffffdd800001a800 0041 00000000 0x0 0x0
0xffffdd800001a880 0041 00000000 0x0 0x0
0xffffdd800001a900 0041 00000000 0x0 0x0
0xffffdd800001a980 0041 00000000 0x0 0x0
0xffffdd800001aa00 0041 00000000 0x0 0x0
0xffffdd800001aa80 0041 00000000 0x0 0x0
0xffffdd800001ab00 0041 00000000 0x0 0x0
0xffffdd800001ab80 0041 00000000 0x0 0x0
0xffffdd800001ac00 0041 00000000 0x0 0x0
0xffffdd800001ac80 0041 00000000 0x0 0x0
0xffffdd800001ad00 0041 00000000 0x0 0x0
0xffffdd800001ad80 0041 00000000 0x0 0x0
0xffffdd800001ae00 0041 00000000 0x0 0x0
0xffffdd800001ae80 0041 00000000 0x0 0x0
0xffffdd800001af00 0041 00000000 0x0 0x0
0xffffdd800001af80 0041 00000000 0x0 0x0
0xffffdd800001b000 0041 00000000 0x0 0x0
0xffffdd800001b080 0041 00000000 0x0 0x0
0xffffdd800001b100 0041 00000000 0x0 0x0
0xffffdd800001b180 0041 00000000 0x0 0x0
0xffffdd800001b200 0041 00000000 0x0 0x0
0xffffdd800001b280 0041 00000000 0x0 0x0
0xffffdd800001b300 0041 00000000 0x0 0x0
0xffffdd800001b380 0041 00000000 0x0 0x0
0xffffdd800001b400 0041 00000000 0x0 0x0
0xffffdd800001b480 0041 00000000 0x0 0x0
0xffffdd800001b500 0041 00000000 0x0 0x0
0xffffdd800001b580 0041 00000000 0x0 0x0
0xffffdd800001b600 0041 00000000 0x0 0x0
0xffffdd800001b680 0041 00000000 0x0 0x0
0xffffdd800001b700 0041 00000000 0x0 0x0
0xffffdd800001b780 0041 00000000 0x0 0x0
0xffffdd800001b800 0041 00000000 0x0 0x0
0xffffdd800001b880 0041 00000000 0x0 0x0
0xffffdd800001b900 0041 00000000 0x0 0x0
0xffffdd800001b980 0041 00000000 0x0 0x0
0xffffdd800001ba00 0041 00000000 0x0 0x0
0xffffdd800001ba80 0041 00000000 0x0 0x0
0xffffdd800001bb00 0001 00000000 0x0 0x0
0xffffdd800001bb80 0001 00000000 0x0 0x0
0xffffdd800001bc00 0001 00000000 0x0 0x0
0xffffdd800001bc80 0001 00000000 0x0 0x0
0xffffdd800001bd00 0001 00000000 0x0 0x0
0xffffdd800001bd80 0001 00000000 0x0 0x0
0xffffdd800001be00 0001 00000000 0x0 0x0
0xffffdd800001be80 0001 00000000 0x0 0x0
0xffffdd800001bf00 0001 00000000 0x0 0x0
0xffffdd800001bf80 0001 00000000 0x0 0x0
0xffffdd800001c000 0001 00000000 0x0 0x0
0xffffdd800001c080 0001 00000000 0x0 0x0
0xffffdd800001c100 0001 00000000 0x0 0x0
0xffffdd800001c180 0001 00000000 0x0 0x0
0xffffdd800001c200 0001 00000000 0x0 0x0
0xffffdd800001c280 0001 00000000 0x0 0x0
0xffffdd800001c300 0001 00000000 0x0 0x0
0xffffdd800001c380 0001 00000000 0x0 0x0
0xffffdd800001c400 0001 00000000 0x0 0x0
0xffffdd800001c480 0001 00000000 0x0 0x0
0xffffdd800001c500 0001 00000000 0x0 0x0
0xffffdd800001c580 0001 00000000 0x0 0x0
0xffffdd800001c600 0001 00000000 0x0 0x0
0xffffdd800001c680 0001 00000000 0x0 0x0
0xffffdd800001c700 0001 00000000 0x0 0x0
0xffffdd800001c780 0001 00000000 0x0 0x0
0xffffdd800001c800 0001 00000000 0x0 0x0
0xffffdd800001c880 0001 00000000 0x0 0x0
0xffffdd800001c900 0001 00000000 0x0 0x0
0xffffdd800001c980 0001 00000000 0x0 0x0
0xffffdd800001ca00 0001 00000000 0x0 0x0
0xffffdd800001ca80 0001 00000000 0x0 0x0
0xffffdd800001cb00 0001 00000000 0x0 0x0
0xffffdd800001cb80 0001 00000000 0x0 0x0
0xffffdd800001cc00 0001 00000000 0x0 0x0
0xffffdd800001cc80 0001 00000000 0x0 0x0
0xffffdd800001cd00 0001 00000000 0x0 0x0
0xffffdd800001cd80 0001 00000000 0x0 0x0
0xffffdd800001ce00 0001 00000000 0x0 0x0
0xffffdd800001ce80 0001 00000000 0x0 0x0
0xffffdd800001cf00 0001 00000000 0x0 0x0
0xffffdd800001cf80 0001 00000000 0x0 0x0
0xffffdd800001d000 0001 00000000 0x0 0x0
0xffffdd800001d080 0001 00000000 0x0 0x0
0xffffdd800001d100 0001 00000000 0x0 0x0
0xffffdd800001d180 0001 00000000 0x0 0x0
0xffffdd800001d200 0001 00000000 0x0 0x0
0xffffdd800001d280 0001 00000000 0x0 0x0
0xffffdd800001d300 0001 00000000 0x0 0x0
0xffffdd800001d380 0001 00000000 0x0 0x0
0xffffdd800001d400 0001 00000000 0x0 0x0
0xffffdd800001d480 0001 00000000 0x0 0x0
0xffffdd800001d500 0001 00000000 0x0 0x0
0xffffdd800001d580 0001 00000000 0x0 0x0
0xffffdd800001d600 0001 00000000 0x0 0x0
0xffffdd800001d680 0001 00000000 0x0 0x0
0xffffdd800001d700 0001 00000000 0x0 0x0
0xffffdd800001d780 0001 00000000 0x0 0x0
0xffffdd800001d800 0001 00000000 0x0 0x0
0xffffdd800001d880 0001 00000000 0x0 0x0
0xffffdd800001d900 0001 00000000 0x0 0x0
0xffffdd800001d980 0001 00000000 0x0 0x0
0xffffdd800001da00 0001 00000000 0x0 0x0
0xffffdd800001da80 0001 00000000 0x0 0x0
0xffffdd800001db00 0001 00000000 0x0 0x0
0xffffdd800001db80 0001 00000000 0x0 0x0
0xffffdd800001dc00 0001 00000000 0x0 0x0
0xffffdd800001dc80 0001 00000000 0x0 0x0
0xffffdd800001dd00 0001 00000000 0x0 0x0
0xffffdd800001dd80 0001 00000000 0x0 0x0
0xffffdd800001de00 0001 00000000 0x0 0x0
0xffffdd800001de80 0001 00000000 0x0 0x0
0xffffdd800001df00 0001 00000000 0x0 0x0
0xffffdd800001df80 0001 00000000 0x0 0x0
0xffffdd800001e000 0001 00000000 0x0 0x0
0xffffdd800001e080 0001 00000000 0x0 0x0
0xffffdd800001e100 0001 00000000 0x0 0x0
0xffffdd800001e180 0001 00000000 0x0 0x0
0xffffdd800001e200 0001 00000000 0x0 0x0
0xffffdd800001e280 0001 00000000 0x0 0x0
0xffffdd800001e300 0001 00000000 0x0 0x0
0xffffdd800001e380 0001 00000000 0x0 0x0
0xffffdd800001e400 0001 00000000 0x0 0x0
0xffffdd800001e480 0001 00000000 0x0 0x0
0xffffdd800001e500 0001 00000000 0x0 0x0
0xffffdd800001e580 0001 00000000 0x0 0x0
0xffffdd800001e600 0001 00000000 0x0 0x0
0xffffdd800001e680 0001 00000000 0x0 0x0
0xffffdd800001e700 0001 00000000 0x0 0x0
0xffffdd800001e780 0001 00000000 0x0 0x0
0xffffdd800001e800 0001 00000000 0x0 0x0
0xffffdd800001e880 0001 00000000 0x0 0x0
0xffffdd800001e900 0001 00000000 0x0 0x0
0xffffdd800001e980 0001 00000000 0x0 0x0
0xffffdd800001ea00 0001 00000000 0x0 0x0
0xffffdd800001ea80 0001 00000000 0x0 0x0
0xffffdd800001eb00 0001 00000000 0x0 0x0
0xffffdd800001eb80 0001 00000000 0x0 0x0
0xffffdd800001ec00 0001 00000000 0x0 0x0
0xffffdd800001ec80 0001 00000000 0x0 0x0
0xffffdd800001ed00 0001 00000000 0x0 0x0
0xffffdd800001ed80 0001 00000000 0x0 0x0
0xffffdd800001ee00 0001 00000000 0x0 0x0
0xffffdd800001ee80 0001 00000000 0x0 0x0
0xffffdd800001ef00 0001 00000000 0x0 0x0
0xffffdd800001ef80 0001 00000000 0x0 0x0
0xffffdd800001f000 0001 00000000 0x0 0x0
0xffffdd800001f080 0001 00000000 0x0 0x0
0xffffdd800001f100 0001 00000000 0x0 0x0
0xffffdd800001f180 0001 00000000 0x0 0x0
0xffffdd800001f200 0001 00000000 0x0 0x0
0xffffdd800001f280 0001 00000000 0x0 0x0
0xffffdd800001f300 0001 00000000 0x0 0x0
0xffffdd800001f380 0001 00000000 0x0 0x0
0xffffdd800001f400 0001 00000000 0x0 0x0
0xffffdd800001f480 0001 00000000 0x0 0x0
0xffffdd800001f500 0001 00000000 0x0 0x0
0xffffdd800001f580 0001 00000000 0x0 0x0
0xffffdd800001f600 0001 00000000 0x0 0x0
0xffffdd800001f680 0001 00000000 0x0 0x0
0xffffdd800001f700 0001 00000000 0x0 0x0
0xffffdd800001f780 0001 00000000 0x0 0x0
0xffffdd800001f800 0001 00000000 0x0 0x0
0xffffdd800001f880 0001 00000000 0x0 0x0
0xffffdd800001f900 0001 00000000 0x0 0x0
0xffffdd800001f980 0001 00000000 0x0 0x0
0xffffdd800001fa00 0001 00000000 0x0 0x0
0xffffdd800001fa80 0001 00000000 0x0 0x0
0xffffdd800001fb00 0001 00000000 0x0 0x0
0xffffdd800001fb80 0001 00000000 0x0 0x0
0xffffdd800001fc00 0001 00000000 0x0 0x0
0xffffdd800001fc80 0001 00000000 0x0 0x0
0xffffdd800001fd00 0001 00000000 0x0 0x0
0xffffdd800001fd80 0001 00000000 0x0 0x0
0xffffdd800001fe00 0001 00000000 0x0 0x0
0xffffdd800001fe80 0001 00000000 0x0 0x0
0xffffdd800001ff00 0001 00000000 0x0 0x0
0xffffdd800001ff80 0001 00000000 0x0 0x0
0xffffdd8000020000 0001 00000000 0x0 0x0
0xffffdd8000020080 0001 00000000 0x0 0x0
0xffffdd8000020100 0001 00000000 0x0 0x0
0xffffdd8000020180 0001 00000000 0x0 0x0
0xffffdd8000020200 0001 00000000 0x0 0x0
0xffffdd8000020280 0001 00000000 0x0 0x0
0xffffdd8000020300 0001 00000000 0x0 0x0
0xffffdd8000020380 0001 00000000 0x0 0x0
0xffffdd8000020400 0001 00000000 0x0 0x0
0xffffdd8000020480 0001 00000000 0x0 0x0
0xffffdd8000020500 0001 00000000 0x0 0x0
0xffffdd8000020580 0001 00000000 0x0 0x0
0xffffdd8000020600 0001 00000000 0x0 0x0
0xffffdd8000020680 0001 00000000 0x0 0x0
0xffffdd8000020700 0001 00000000 0x0 0x0
0xffffdd8000020780 0001 00000000 0x0 0x0
0xffffdd8000020800 0001 00000000 0x0 0x0
0xffffdd8000020880 0001 00000000 0x0 0x0
0xffffdd8000020900 0001 00000000 0x0 0x0
0xffffdd8000020980 0001 00000000 0x0 0x0
0xffffdd8000020a00 0001 00000000 0x0 0x0
0xffffdd8000020a80 0001 00000000 0x0 0x0
0xffffdd8000020b00 0001 00000000 0x0 0x0
0xffffdd8000020b80 0001 00000000 0x0 0x0
0xffffdd8000020c00 0001 00000000 0x0 0x0
0xffffdd8000020c80 0001 00000000 0x0 0x0
0xffffdd8000020d00 0001 00000000 0x0 0x0
0xffffdd8000020d80 0001 00000000 0x0 0x0
0xffffdd8000020e00 0001 00000000 0x0 0x0
0xffffdd8000020e80 0001 00000000 0x0 0x0
0xffffdd8000020f00 0001 00000000 0x0 0x0
0xffffdd8000020f80 0001 00000000 0x0 0x0
0xffffdd8000021000 0001 00000000 0x0 0x0
0xffffdd8000021080 0001 00000000 0x0 0x0
0xffffdd8000021100 0001 00000000 0x0 0x0
0xffffdd8000021180 0001 00000000 0x0 0x0
0xffffdd8000021200 0001 00000000 0x0 0x0
0xffffdd8000021280 0001 00000000 0x0 0x0
0xffffdd8000021300 0001 00000000 0x0 0x0
0xffffdd8000021380 0001 00000000 0x0 0x0
0xffffdd8000021400 0001 00000000 0x0 0x0
0xffffdd8000021480 0001 00000000 0x0 0x0
0xffffdd8000021500 0001 00000000 0x0 0x0
0xffffdd8000021580 0001 00000000 0x0 0x0
0xffffdd8000021600 0001 00000000 0x0 0x0
0xffffdd8000021680 0001 00000000 0x0 0x0
0xffffdd8000021700 0001 00000000 0x0 0x0
0xffffdd8000021780 0001 00000000 0x0 0x0
0xffffdd8000021800 0001 00000000 0x0 0x0
0xffffdd8000021880 0001 00000000 0x0 0x0
0xffffdd8000021900 0001 00000000 0x0 0x0
0xffffdd8000021980 0001 00000000 0x0 0x0
0xffffdd8000021a00 0001 00000000 0x0 0x0
0xffffdd8000021a80 0001 00000000 0x0 0x0
0xffffdd8000021b00 0001 00000000 0x0 0x0
0xffffdd8000021b80 0001 00000000 0x0 0x0
0xffffdd8000021c00 0001 00000000 0x0 0x0
0xffffdd8000021c80 0001 00000000 0x0 0x0
0xffffdd8000021d00 0001 00000000 0x0 0x0
0xffffdd8000021d80 0001 00000000 0x0 0x0
0xffffdd8000021e00 0001 00000000 0x0 0x0
0xffffdd8000021e80 0001 00000000 0x0 0x0
0xffffdd8000021f00 0001 00000000 0x0 0x0
0xffffdd8000021f80 0001 00000000 0x0 0x0
0xffffdd8000022000 0001 00000000 0x0 0x0
0xffffdd8000022080 0001 00000000 0x0 0x0
0xffffdd8000022100 0001 00000000 0x0 0x0
0xffffdd8000022180 0001 00000000 0x0 0x0
0xffffdd8000022200 0001 00000000 0x0 0x0
0xffffdd8000022280 0001 00000000 0x0 0x0
0xffffdd8000022300 0001 00000000 0x0 0x0
0xffffdd8000022380 0001 00000000 0x0 0x0
0xffffdd8000022400 0001 00000000 0x0 0x0
0xffffdd8000022480 0001 00000000 0x0 0x0
0xffffdd8000022500 0001 00000000 0x0 0x0
0xffffdd8000022580 0001 00000000 0x0 0x0
0xffffdd8000022600 0001 00000000 0x0 0x0
0xffffdd8000022680 0001 00000000 0x0 0x0
0xffffdd8000022700 0001 00000000 0x0 0x0
0xffffdd8000022780 0001 00000000 0x0 0x0
0xffffdd8000022800 0001 00000000 0x0 0x0
0xffffdd8000022880 0001 00000000 0x0 0x0
0xffffdd8000022900 0001 00000000 0x0 0x0
0xffffdd8000022980 0001 00000000 0x0 0x0
0xffffdd8000022a00 0001 00000000 0x0 0x0
0xffffdd8000022a80 0001 00000000 0x0 0x0
0xffffdd8000022b00 0001 00000000 0x0 0x0
0xffffdd8000022b80 0001 00000000 0x0 0x0
0xffffdd8000022c00 0001 00000000 0x0 0x0
0xffffdd8000022c80 0001 00000000 0x0 0x0
0xffffdd8000022d00 0001 00000000 0x0 0x0
0xffffdd8000022d80 0001 00000000 0x0 0x0
0xffffdd8000022e00 0001 00000000 0x0 0x0
0xffffdd8000022e80 0001 00000000 0x0 0x0
0xffffdd8000022f00 0001 00000000 0x0 0x0
0xffffdd8000022f80 0001 00000000 0x0 0x0
0xffffdd8000023000 0001 00000000 0x0 0x0
0xffffdd8000023080 0001 00000000 0x0 0x0
0xffffdd8000023100 0001 00000000 0x0 0x0
0xffffdd8000023180 0001 00000000 0x0 0x0
0xffffdd8000023200 0001 00000000 0x0 0x0
0xffffdd8000023280 0001 00000000 0x0 0x0
0xffffdd8000023300 0001 00000000 0x0 0x0
0xffffdd8000023380 0001 00000000 0x0 0x0
0xffffdd8000023400 0001 00000000 0x0 0x0
0xffffdd8000023480 0001 00000000 0x0 0x0
0xffffdd8000023500 0001 00000000 0x0 0x0
0xffffdd8000023580 0001 00000000 0x0 0x0
0xffffdd8000023600 0001 00000000 0x0 0x0
0xffffdd8000023680 0001 00000000 0x0 0x0
0xffffdd8000023700 0001 00000000 0x0 0x0
0xffffdd8000023780 0001 00000000 0x0 0x0
0xffffdd8000023800 0001 00000000 0x0 0x0
0xffffdd8000023880 0001 00000000 0x0 0x0
0xffffdd8000023900 0001 00000000 0x0 0x0
0xffffdd8000023980 0001 00000000 0x0 0x0
0xffffdd8000023a00 0001 00000000 0x0 0x0
0xffffdd8000023a80 0001 00000000 0x0 0x0
0xffffdd8000023b00 0001 00000000 0x0 0x0
0xffffdd8000023b80 0001 00000000 0x0 0x0
0xffffdd8000023c00 0001 00000000 0x0 0x0
0xffffdd8000023c80 0001 00000000 0x0 0x0
0xffffdd8000023d00 0001 00000000 0x0 0x0
0xffffdd8000023d80 0001 00000000 0x0 0x0
0xffffdd8000023e00 0001 00000000 0x0 0x0
0xffffdd8000023e80 0001 00000000 0x0 0x0
0xffffdd8000023f00 0001 00000000 0x0 0x0
0xffffdd8000023f80 0001 00000000 0x0 0x0
0xffffdd8000024000 0001 00000000 0x0 0x0
0xffffdd8000024080 0001 00000000 0x0 0x0
0xffffdd8000024100 0001 00000000 0x0 0x0
0xffffdd8000024180 0001 00000000 0x0 0x0
0xffffdd8000024200 0001 00000000 0x0 0x0
0xffffdd8000024280 0001 00000000 0x0 0x0
0xffffdd8000024300 0001 00000000 0x0 0x0
0xffffdd8000024380 0001 00000000 0x0 0x0
0xffffdd8000024400 0001 00000000 0x0 0x0
0xffffdd8000024480 0001 00000000 0x0 0x0
0xffffdd8000024500 0001 00000000 0x0 0x0
0xffffdd8000024580 0001 00000000 0x0 0x0
0xffffdd8000024600 0001 00000000 0x0 0x0
0xffffdd8000024680 0001 00000000 0x0 0x0
0xffffdd8000024700 0001 00000000 0x0 0x0
0xffffdd8000024780 0001 00000000 0x0 0x0
0xffffdd8000024800 0001 00000000 0x0 0x0
0xffffdd8000024880 0001 00000000 0x0 0x0
0xffffdd8000024900 0001 00000000 0x0 0x0
0xffffdd8000024980 0001 00000000 0x0 0x0
0xffffdd8000024a00 0001 00000000 0x0 0x0
0xffffdd8000024a80 0001 00000000 0x0 0x0
0xffffdd8000024b00 0001 00000000 0x0 0x0
0xffffdd8000024b80 0001 00000000 0x0 0x0
0xffffdd8000024c00 0001 00000000 0x0 0x0
0xffffdd8000024c80 0001 00000000 0x0 0x0
0xffffdd8000024d00 0001 00000000 0x0 0x0
0xffffdd8000024d80 0001 00000000 0x0 0x0
0xffffdd8000024e00 0001 00000000 0x0 0x0
0xffffdd8000024e80 0001 00000000 0x0 0x0
0xffffdd8000024f00 0001 00000000 0x0 0x0
0xffffdd8000024f80 0001 00000000 0x0 0x0
0xffffdd8000025000 0001 00000000 0x0 0x0
0xffffdd8000025080 0001 00000000 0x0 0x0
0xffffdd8000025100 0001 00000000 0x0 0x0
0xffffdd8000025180 0001 00000000 0x0 0x0
0xffffdd8000025200 0001 00000000 0x0 0x0
0xffffdd8000025280 0001 00000000 0x0 0x0
0xffffdd8000025300 0001 00000000 0x0 0x0
0xffffdd8000025380 0001 00000000 0x0 0x0
0xffffdd8000025400 0001 00000000 0x0 0x0
0xffffdd8000025480 0001 00000000 0x0 0x0
0xffffdd8000025500 0001 00000000 0x0 0x0
0xffffdd8000025580 0001 00000000 0x0 0x0
0xffffdd8000025600 0001 00000000 0x0 0x0
0xffffdd8000025680 0001 00000000 0x0 0x0
0xffffdd8000025700 0001 00000000 0x0 0x0
0xffffdd8000025780 0001 00000000 0x0 0x0
0xffffdd8000025800 0001 00000000 0x0 0x0
0xffffdd8000025880 0001 00000000 0x0 0x0
0xffffdd8000025900 0001 00000000 0x0 0x0
0xffffdd8000025980 0001 00000000 0x0 0x0
0xffffdd8000025a00 0001 00000000 0x0 0x0
0xffffdd8000025a80 0001 00000000 0x0 0x0
0xffffdd8000025b00 0001 00000000 0x0 0x0
0xffffdd8000025b80 0001 00000000 0x0 0x0
0xffffdd8000025c00 0001 00000000 0x0 0x0
0xffffdd8000025c80 0001 00000000 0x0 0x0
0xffffdd8000025d00 0001 00000000 0x0 0x0
0xffffdd8000025d80 0001 00000000 0x0 0x0
0xffffdd8000025e00 0001 00000000 0x0 0x0
0xffffdd8000025e80 0001 00000000 0x0 0x0
0xffffdd8000025f00 0001 00000000 0x0 0x0
0xffffdd8000025f80 0001 00000000 0x0 0x0
0xffffdd8000026000 0001 00000000 0x0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages