UBSan: Undefined Behavior in ffs_alloc.cold (3)

0 views
Skip to first unread message

syzbot

unread,
May 30, 2024, 9:47:38 PMMay 30
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 880d6717fef3 make: don't log anything when freeing memory
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=13064dd2980000
kernel config: https://syzkaller.appspot.com/x/.config?x=1420f906d33d9f1f
dashboard link: https://syzkaller.appspot.com/bug?extid=0c31d71cf1b81a161c7e
compiler: g++ (Debian 12.2.0-14) 12.2.0

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/134bd04b75bb/disk-880d6717.raw.xz
netbsd.gdb: https://storage.googleapis.com/syzbot-assets/b5fffb95a1f8/netbsd-880d6717.gdb.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+0c31d7...@syzkaller.appspotmail.com

[ 673.5196055] panic: UBSan: Undefined Behavior in /syzkaller/managers/ci2-netbsd-kubsan/kernel/sys/ufs/ffs/ffs_alloc.c:241:6, left shift of negative value -1

[ 673.5418243] cpu0: Begin traceback...
[ 673.5595986] vpanic() at netbsd:vpanic+0x2f0 sys/kern/subr_prf.c:288
[ 673.6395975] Report() at netbsd:Report+0x3b sys/../common/lib/libc/misc/ubsan.c:1352
[ 673.6995953] HandleShiftOutOfBounds() at netbsd:HandleShiftOutOfBounds+0x1ee sys/../common/lib/libc/misc/ubsan.c:499
[ 673.7495953] ffs_alloc.cold() at netbsd:ffs_alloc.cold+0x59
[ 673.8095969] ffs_balloc() at netbsd:ffs_balloc+0x16c5 ffs_balloc_ufs2 sys/ufs/ffs/ffs_balloc.c:767 [inline]
[ 673.8095969] ffs_balloc() at netbsd:ffs_balloc+0x16c5 sys/ufs/ffs/ffs_balloc.c:99
[ 673.8595965] ufs_mkdir() at netbsd:ufs_mkdir+0xb70 sys/ufs/ufs/ufs_vnops.c:1331
[ 673.9095949] VOP_MKDIR() at netbsd:VOP_MKDIR+0x143 sys/kern/vnode_if.c:1338
[ 673.9695954] do_sys_mkdirat() at netbsd:do_sys_mkdirat+0x245 sys/kern/vfs_syscalls.c:4754
[ 674.0195951] syscall() at netbsd:syscall+0x28b sy_call sys/sys/syscallvar.h:65 [inline]
[ 674.0195951] syscall() at netbsd:syscall+0x28b sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 674.0195951] syscall() at netbsd:syscall+0x28b sys/arch/x86/x86/syscall.c:137
[ 674.0397876] --- syscall (number 136) ---
[ 674.0495981] netbsd:syscall+0x28b:
[ 674.0595964] cpu0: End traceback...
[ 674.0595964] fatal breakpoint trap in supervisor mode
[ 674.0595964] trap type 1 code 0 rip 0xffffffff80235475 cs 0x8 rflags 0x246 cr2 0x7f7f02a10000 ilevel 0 rsp 0xffffc98248e0b420
[ 674.0794134] curlwp 0xffffb6f8ffde1740 pid 25555.25555 lowest kstack 0xffffc98248e072c0
Stopped in pid 25555.25555 (syz-executor.4) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xec sys/ddb/db_panic.c:71
vpanic() at netbsd:vpanic+0x2f0 sys/kern/subr_prf.c:288
Report() at netbsd:Report+0x3b sys/../common/lib/libc/misc/ubsan.c:1352
HandleShiftOutOfBounds() at netbsd:HandleShiftOutOfBounds+0x1ee sys/../common/lib/libc/misc/ubsan.c:499
ffs_alloc.cold() at netbsd:ffs_alloc.cold+0x59
ffs_balloc() at netbsd:ffs_balloc+0x16c5 ffs_balloc_ufs2 sys/ufs/ffs/ffs_balloc.c:767 [inline]
ffs_balloc() at netbsd:ffs_balloc+0x16c5 sys/ufs/ffs/ffs_balloc.c:99
ufs_mkdir() at netbsd:ufs_mkdir+0xb70 sys/ufs/ufs/ufs_vnops.c:1331
VOP_MKDIR() at netbsd:VOP_MKDIR+0x143 sys/kern/vnode_if.c:1338
do_sys_mkdirat() at netbsd:do_sys_mkdirat+0x245 sys/kern/vfs_syscalls.c:4754
syscall() at netbsd:syscall+0x28b sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x28b sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x28b sys/arch/x86/x86/syscall.c:137
--- syscall (number 136) ---
netbsd:syscall+0x28b:
Panic string: UBSan: Undefined Behavior in /syzkaller/managers/ci2-netbsd-kubsan/kernel/sys/ufs/ffs/ffs_alloc.c:241:6, left shift of negative value -1

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
25555>25555 7 0 0 ffffb6f8ffde1740 syz-executor.4
24142 24142 2 0 0 ffffb6f914114b00 syz-executor.5
23444 23444 2 0 0 ffffb6f910a111c0 syz-executor.0
22916 28090 3 0 180 ffffb6f8df6acac0 syz-executor.2 parked
22916 24828 3 0 180 ffffb6f8f1a49b00 syz-executor.2 parked
22916 22916 2 0 10000000 ffffb6f8e414db80 syz-executor.2
23849 23849 3 0 180 ffffb6f90fe18a00 syz-executor.2 parked
23681 23681 2 1 0 ffffb6f8f1a49280 syz-executor.3
24457 24457 3 1 40180 ffffb6f8f18a9780 syz-executor.5 wait
20096 20096 2 1 140 ffffb6f8feb3e640 syz-executor.0
23522 23522 3 1 180 ffffb6f9067b9940 syz-executor.2 parked
23711 23711 2 1 140 ffffb6f8e66874c0 syz-executor.2
21729 21729 2 1 0 ffffb6f90fe185c0 syz-executor.1
26187 26187 3 0 180 ffffb6f9067b90c0 syz-executor.3 parked
25146 25146 3 1 180 ffffb6f914f18ac0 syz-executor.2 parked
20360 20360 3 0 180 ffffb6f8f75bf680 syz-executor.4 parked
23035 23035 3 1 180 ffffb6f9067b9500 init nanoslp
18903 18903 3 0 180 ffffb6f914f18240 syz-executor.3 parked
9206 9206 3 0 180 ffffb6f906185140 syz-executor.2 parked
13145 13145 3 0 180 ffffb6f8ffde1b80 syz-executor.1 parked
12577 12577 3 0 180 ffffb6f906185580 syz-executor.3 parked
13500 13500 3 1 180 ffffb6f8fe3634c0 syz-executor.5 parked
10541 10541 3 1 180 ffffb6f8e851e580 syz-executor.4 parked
11594 11594 3 1 180 ffffb6f8e414d300 syz-executor.2 parked
7236 7236 3 0 180 ffffb6f8e851e9c0 syz-executor.1 parked
7577 7577 3 1 180 ffffb6f8e18111c0 syz-executor.0 parked
12263 8085 3 1 1100000 ffffb6f8e851e140 syz-executor.0 vfork
12263 12263 3 1 11000000 ffffb6f8e10284c0 syz-executor.0 lwpwait
7042 7042 3 0 180 ffffb6f8f75bf240 syz-executor.5 parked
10089 10089 3 0 180 ffffb6f8f78fa640 syz-executor.4 parked
11225 11225 3 1 180 ffffb6f8e1028900 syz-executor.1 parked
6650 6650 3 0 180 ffffb6f8e10d80c0 syz-executor.0 parked
6439 6439 3 0 180 ffffb6f8f18a9bc0 syz-executor.1 parked
9680 9680 3 0 180 ffffb6f8f6caea40 syz-executor.2 parked
9917 9917 3 0 180 ffffb6f8fba502c0 syz-executor.5 parked
5886 5886 3 1 180 ffffb6f8e40908c0 syz-executor.4 parked
4580 4580 3 1 180 ffffb6f8eaaeb540 syz-executor.0 parked
4419 4419 3 1 180 ffffb6f8e0f78540 syz-executor.0 parked
4754 4754 3 1 180 ffffb6f8e3c65340 syz-executor.5 parked
8668 8668 3 1 180 ffffb6f8eaaeb100 syz-executor.2 parked
4921 4921 2 0 0 ffffb6f8f78fa200 ndp
6351 6351 3 0 180 ffffb6f8e15d1a00 syz-executor.0 parked
5317 5317 3 0 180 ffffb6f8e9f9f0c0 syz-executor.2 parked
915 915 3 1 180 ffffb6f8e1d8fb00 syz-executor.0 parked
4297 4297 3 0 180 ffffb6f8e9f9f500 syz-executor.1 parked
3762 3762 3 1 180 ffffb6f8e1028080 syz-executor.2 parked
3257 3257 3 0 180 ffffb6f8e15d15c0 syz-executor.2 parked
4554 4554 3 1 180 ffffb6f8e6687080 syz-executor.0 parked
2753 2753 3 1 180 ffffb6f8e0f78980 syz-executor.5 parked
4151 4151 3 1 180 ffffb6f8e4552b40 syz-executor.2 parked
3126 3126 3 0 180 ffffb6f8e10d8500 syz-executor.0 parked
1238 2622 2 1 0 ffffb6f8e4b7c480 syz-fuzzer
1238 1969 3 1 180 ffffb6f8e06c6040 syz-fuzzer wait
1238 1208 3 1 180 ffffb6f8e4b7c8c0 syz-fuzzer wait
1238 1203 3 0 180 ffffb6f8e4b7c040 syz-fuzzer parked
1238 1279 3 0 180 ffffb6f8e1d8f6c0 syz-fuzzer parked
1238 1384 3 0 180 ffffb6f8e4552700 syz-fuzzer wait
1238 1240 2 0 0 ffffb6f8e45522c0 syz-fuzzer
1238 1004 3 1 180 ffffb6f8e1d8f280 syz-fuzzer wait
1238 990 3 0 180 ffffb6f8e1811600 syz-fuzzer wait
1238 1223 3 0 180 ffffb6f8e1535240 syz-fuzzer parked
1238 987 3 0 180 ffffb6f8e14f2640 syz-fuzzer parked
1238 1229 3 0 180 ffffb6f8e14f2200 syz-fuzzer wait
1238 1233 2 0 0 ffffb6f8df9fc6c0 syz-fuzzer
1238 > 1230 7 1 0 ffffb6f8df9fcb00 syz-fuzzer
1238 1238 3 0 180 ffffb6f8e1811a40 syz-fuzzer parked
1237 1237 3 0 180 ffffb6f8e14f2a80 sshd select
1222 1222 3 0 180 ffffb6f8e0131bc0 getty nanoslp
1224 1224 3 0 180 ffffb6f8df6bf200 getty nanoslp
1184 1184 3 1 180 ffffb6f8df9fc280 getty nanoslp
1107 1107 3 0 180 ffffb6f8e1535ac0 sshd select
1088 1088 3 0 180 ffffb6f8e1535680 powerd kqueue
812 812 3 0 180 ffffb6f8e0e109c0 syslogd kqueue
559 559 3 0 180 ffffb6f8e06c6480 dhcpcd poll
747 747 3 0 180 ffffb6f8e0131340 dhcpcd poll
742 742 2 0 0 ffffb6f8e0131780 dhcpcd
602 602 3 0 180 ffffb6f8dfcdf300 dhcpcd poll
292 292 3 0 180 ffffb6f8dfa7eb40 dhcpcd poll
485 485 3 1 180 ffffb6f8dfcdf740 dhcpcd poll
291 291 3 1 180 ffffb6f8dfcdfb80 dhcpcd poll
1 1 3 1 180 ffffb6f8d7469100 init wait
0 27852 5 1 200 ffffb6f910a11a40 (zombie)
0 21642 3 1 200 ffffb6f914f18680 ktrace ktrwait
0 16867 3 0 200 ffffb6f8f30c1180 ktrace ktrwait
0 20788 3 0 200 ffffb6f8f18a9340 ktrace ktrwait
0 12782 3 1 200 ffffb6f8fe363080 ktrace ktrwait
0 17099 3 0 200 ffffb6f90aa2e540 ktrace ktrwait
0 11675 3 0 200 ffffb6f8eaaeb980 ktrace ktrwait
0 10539 3 0 200 ffffb6f8e6687900 ktrace ktrwait
0 6737 3 0 200 ffffb6f8e10d8940 acctwatch actwat
0 9559 3 0 200 ffffb6f8fba50700 ktrace ktrwait
0 5623 3 0 200 ffffb6f8e3c65780 ktrace ktrwait
0 1694 3 0 200 ffffb6f8dfa7e2c0 ktrace ktrwait
0 2381 3 1 200 ffffb6f8f30c15c0 ktrace ktrwait
0 5471 3 1 200 ffffb6f8e414d740 swapiod swapiod
0 912 3 1 200 ffffb6f8e0f78100 ktrace ktrwait
0 874 3 0 200 ffffb6f8df6bf640 physiod physiod
0 196 3 0 200 ffffb6f8df6ac680 pooldrain pooldrain
0 195 2 0 240 ffffb6f8df6ac240 ioflush
0 194 3 1 200 ffffb6f8df6bfa80 pgdaemon pgdaemon
0 170 3 1 200 ffffb6f8dd5dea40 usb7 usbevt
0 169 3 0 200 ffffb6f8dd5de600 usb6 usbevt
0 168 3 0 200 ffffb6f8dd5de1c0 usb5 usbevt
0 167 3 0 200 ffffb6f8da549a00 usb4 usbevt
0 166 3 1 200 ffffb6f8da5495c0 usb3 usbevt
0 165 3 1 200 ffffb6f8da549180 usb2 usbevt
0 31 3 0 200 ffffb6f8d85049c0 usb1 usbevt
0 63 3 0 200 ffffb6f8d8504580 usb0 usbevt
0 126 3 1 200 ffffb6f8d8504140 usbtask-dr usbtsk
0 125 3 1 200 ffffb6f8d7469980 usbtask-hc usbtsk
0 124 3 0 200 ffffb6f8d5895b00 swwreboot swwreboot
0 123 3 0 200 ffffb6f8d7469540 npfgc0 npfgcw
0 122 3 1 200 ffffb6f8d724d940 rt_free rt_free
0 121 3 1 200 ffffb6f8d724d500 unpgc unpgc
0 120 2 0 200 ffffb6f8d724d0c0 key_timehandler
0 119 3 1 200 ffffb6f8d7447900 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 ffffb6f8d74474c0 icmp6_wqinput/0 icmp6_wqinput
0 117 2 0 200 ffffb6f8d7447080 nd6_timer
0 116 3 1 200 ffffb6f8d74328c0 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 ffffb6f8d7432480 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 ffffb6f8d7432040 carp_wqinput/1 carp_wqinput
0 113 3 0 200 ffffb6f8d73debc0 carp_wqinput/0 carp_wqinput
0 112 3 1 200 ffffb6f8d72ff740 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 ffffb6f8d72ffb80 icmp_wqinput/0 icmp_wqinput
0 110 3 1 200 ffffb6f8d73de340 rt_timer rt_timer
0 109 3 0 200 ffffb6f8d73de780 vmem_rehash vmem_rehash
0 100 3 1 200 ffffb6f8d72ff300 entbutler entropy
0 99 3 1 200 ffffb6f8d6d3eb40 viomb balloon
0 98 3 1 200 ffffb6f8d6d3e700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 ffffb6f8d6d3e2c0 vioif0_txrx/0 vioif0_txrx
0 30 3 1 200 ffffb6f8d58956c0 scsibus0 sccomp
0 29 3 0 200 ffffb6f8d5895280 pms0 pmsreset
0 28 3 1 200 ffffb6f8d57b5ac0 xcall/1 xcall
0 27 1 1 200 ffffb6f8d57b5680 softser/1
0 26 1 1 200 ffffb6f8d57b5240 softclk/1
0 25 1 1 200 ffffb6f8d5798a80 softbio/1
0 24 1 1 200 ffffb6f8d5798640 softnet/1
0 23 1 1 201 ffffb6f8d5798200 idle/1
0 22 3 0 200 ffffb6fa03b33a40 lnxsyswq lnxsyswq
0 21 3 0 200 ffffb6fa03b33600 lnxubdwq lnxubdwq
0 20 3 1 200 ffffb6fa03b331c0 lnxpwrwq lnxpwrwq
0 19 3 1 200 ffffb6fa03b42a00 lnxlngwq lnxlngwq
0 18 3 1 200 ffffb6fa03b425c0 lnxhipwq lnxhipwq
0 17 3 1 200 ffffb6fa03b42180 lnxrcugc lnxrcugc
0 16 3 0 200 ffffb6fa03b599c0 sysmon smtaskq
0 15 3 1 200 ffffb6fa03b59580 pmfsuspend pmfsuspend
0 14 3 0 200 ffffb6fa03b59140 pmfevent pmfevent
0 13 3 0 200 ffffb6fa03b6c980 sopendfree sopendfr
0 12 3 0 200 ffffb6fa03b6c540 ifwdog ifwdog
0 11 3 1 200 ffffb6fa03b6c100 iflnkst iflnkst
0 10 3 1 200 ffffb6fa04b97940 nfssilly nfssilly
0 9 3 0 200 ffffb6fa04b97500 pooldisp pooldisp
0 8 3 1 200 ffffb6fa04b970c0 modunload mod_unld
0 7 3 0 200 ffffb6fa04bc2900 xcall/0 xcall
0 6 1 0 200 ffffb6fa04bc24c0 softser/0
0 5 1 0 200 ffffb6fa04bc2080 softclk/0
0 4 1 0 200 ffffb6fa04bed8c0 softbio/0
0 3 1 0 200 ffffb6fa04bed480 softnet/0
0 2 1 0 201 ffffb6fa04bed040 idle/0
0 0 3 0 200 ffffffff86795c80 swapper uvm
[Locks tracked through LWPs]

****** LWP 25555.25555 (syz-executor.4) @ 0xffffb6f8ffde1740, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0xbf sys/kern/vfs_vnode.c:1438)
lock address : ffffb6f91ddc7f00
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0xbf
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8ffde1740 last held: 0xffffb6f8ffde1740
last locked* : netbsd:genfs_lock+0x220
unlocked : netbsd:genfs_unlock+0x50
owner/count : 0xffffb6f8ffde1740 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:vcache_alloc+0xbf sys/kern/vfs_vnode.c:1438)
lock address : ffffb6f91ddc7500
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0xbf
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8ffde1740 last held: 0xffffb6f8ffde1740
last locked* : netbsd:genfs_lock+0x220
unlocked : 0
owner/count : 0xffffb6f8ffde1740 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 2 (initialized at netbsd:ffs_mountfs+0x1e3 sys/ufs/ffs/ffs_vfsops.c:1199)
lock address : ffffb6f8da563910
type : sleep/adaptive
initialized : netbsd:ffs_mountfs+0x1e3
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8ffde1740 last held: 0xffffb6f8ffde1740
last locked* : netbsd:ffs_balloc+0x1646
unlocked : netbsd:ffs_nodealloccg+0x1763
owner field : 0xffffb6f8ffde1740 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 24142.24142 (syz-executor.5) @ 0xffffb6f914114b00, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:fork1+0x4c5 sys/kern/kern_fork.c:366)
lock address : ffffb6f8fa2bce10
type : sleep/adaptive
initialized : netbsd:fork1+0x4c5
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 1
relevant lwp : 0xffffb6f914114b00 last held: 0xffffb6f914114b00
last locked* : netbsd:execve_loadvm+0x22d
unlocked : 0
owner/count : 0xffffb6f914114b00 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:amap_alloc1+0x30a sys/uvm/uvm_amap.c:167)
lock address : ffffb6f91957df40
type : sleep/adaptive
initialized : netbsd:amap_alloc1+0x30a
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f914114b00 last held: 0xffffb6f914114b00
last locked* : netbsd:uvm_fault_internal+0x75d
unlocked : netbsd:amap_wipeout+0x321
owner/count : 0xffffb6f914114b00 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 2 (initialized at netbsd:pmap_ctor+0x6d sys/arch/x86/x86/pmap.c:2872)
lock address : ffffb6f8eda84d80
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0x6d
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f914114b00 last held: 0xffffb6f914114b00
last locked* : netbsd:pmap_enter_ma+0x3c0
unlocked : netbsd:pmap_write_protect+0x3e3
owner field : 0xffffb6f914114b00 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 23444.23444 (syz-executor.0) @ 0xffffb6f910a111c0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:uvm_obj_init+0xee sys/uvm/uvm_object.c:70)
lock address : ffffb6f8df781100
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0xee
shared holds : 0 exclusive: 0
shares wanted: 1 exclusive: 0
relevant cpu : 0 last held: 65535
relevant lwp : 0xffffb6f910a111c0 last held: 000000000000000000
last locked : netbsd:uvm_fault_internal+0x2453
unlocked* : netbsd:uvm_fault_lower_enter+0x840
owner/count : 0x0000000000000020 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

****** LWP 23681.23681 (syz-executor.3) @ 0xffffb6f8f1a49280, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:amap_alloc1+0x30a sys/uvm/uvm_amap.c:167)
lock address : ffffb6f8e384ed00
type : sleep/adaptive
initialized : netbsd:amap_alloc1+0x30a
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffb6f8f1a49280 last held: 0xffffb6f8f1a49280
last locked* : netbsd:uvm_fault_internal+0x75d
unlocked : netbsd:amap_extend+0x103c
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 21729.21729 (syz-executor.1) @ 0xffffb6f90fe185c0, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:fork1+0x4c5 sys/kern/kern_fork.c:366)
lock address : ffffb6f8e4117e90
type : sleep/adaptive
initialized : netbsd:fork1+0x4c5
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffb6f90fe185c0 last held: 0xffffb6f90fe185c0
last locked* : netbsd:exit1+0x393
unlocked : netbsd:execve_runproc+0x2c3b
owner/count : 0xffffb6f90fe185c0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:uvm_obj_init+0xee sys/uvm/uvm_object.c:70)
lock address : ffffb6f912802340
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0xee
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffb6f90fe185c0 last held: 0xffffb6f90fe185c0
last locked* : netbsd:uao_detach+0x2c5
unlocked : netbsd:uvm_unmap_remove+0xbf3
owner/count : 0xffffb6f90fe185c0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 4921.4921 (ndp) @ 0xffffb6f8f78fa200, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8f78fa200 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 747.747 (dhcpcd) @ 0xffffb6f8e0131340, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8e0131340 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 742.742 (dhcpcd) @ 0xffffb6f8e0131780, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8e0131780 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 485.485 (dhcpcd) @ 0xffffb6f8dfcdf740, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffb6f8dfcdf740 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 291.291 (dhcpcd) @ 0xffffb6f8dfcdfb80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffb6f8dfcdfb80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.26 (softclk/1) @ 0xffffb6f8d57b5240, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffb6f8d57b5240 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffffb6fa03b6c100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffb6fa03b6c100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffffb6fa04bc2080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6fa04bc2080 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff86795c80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff86795c80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu0:

* Lock 0 (initialized at netbsd:kprintf_init+0x72 sys/kern/subr_prf.c:156)
lock address : netbsd:kprintf_mtx
type : spin
initialized : netbsd:kprintf_init+0x72
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffb6f8ffde1740 last held: 0xffffb6f8ffde1740
last locked* : netbsd:kprintf_lock+0x50
unlocked : netbsd:kprintf_unlock+0x70
owner field : 0x0000000000000800 wait/spin: 0/1

PAGE FLAG PQ UOBJECT UANON
0xffffc98000007180 0045 00000000 0x0 0x0
0xffffc98000007200 0045 00000000 0x0 0x0
0xffffc98000007280 0045 00000000 0x0 0x0
0xffffc98000007300 0045 00000000 0x0 0x0
0xffffc98000007380 0045 00000000 0x0 0x0
0xffffc98000007400 0045 00000000 0x0 0x0
0xffffc98000007480 0045 00000000 0x0 0x0
0xffffc98000007500 0045 00000000 0x0 0x0
0xffffc98000007580 0045 00000000 0x0 0x0
0xffffc98000007600 0045 00000000 0x0 0x0
0xffffc98000007680 0041 00000000 0x0 0x0
0xffffc98000007700 0041 00000000 0x0 0x0
0xffffc98000007780 0041 00000000 0x0 0x0
0xffffc98000007800 0041 00000000 0x0 0x0
0xffffc98000007880 0041 00000000 0x0 0x0
0xffffc98000007900 0045 00000000 0x0 0x0
0xffffc98000007980 0041 00000000 0x0 0x0
0xffffc98000007a00 0041 00000000 0x0 0x0
0xffffc98000007a80 0041 00000000 0x0 0x0
0xffffc98000007b00 0041 00000000 0x0 0x0
0xffffc98000007b80 0041 00000000 0x0 0x0
0xffffc98000007c00 0041 00000000 0x0 0x0
0xffffc98000007c80 0041 00000000 0x0 0x0
0xffffc98000007d00 0041 00000000 0x0 0x0
0xffffc98000007d80 0041 00000000 0x0 0x0
0xffffc98000007e00 0041 00000000 0x0 0x0
0xffffc98000007e80 0041 00000000 0x0 0x0
0xffffc98000007f00 0041 00000000 0x0 0x0
0xffffc98000007f80 0041 00000000 0x0 0x0
0xffffc98000008000 0041 00000000 0x0 0x0
0xffffc98000008080 0041 00000000 0x0 0x0
0xffffc98000008100 0041 00000000 0x0 0x0
0xffffc98000008180 0041 00000000 0x0 0x0
0xffffc98000008200 0041 00000000 0x0 0x0
0xffffc98000008280 0041 00000000 0x0 0x0
0xffffc98000008300 0041 00000000 0x0 0x0
0xffffc98000008380 0041 00000000 0x0 0x0
0xffffc98000008400 0041 00000000 0x0 0x0
0xffffc98000008480 0041 00000000 0x0 0x0
0xffffc98000008500 0041 00000000 0x0 0x0
0xffffc98000008580 0041 00000000 0x0 0x0
0xffffc98000008600 0045 00000000 0x0 0x0
0xffffc98000008680 0041 00000000 0x0 0x0
0xffffc98000008700 0041 00000000 0x0 0x0
0xffffc98000008780 0041 00000000 0x0 0x0
0xffffc98000008800 0041 00000000 0x0 0x0
0xffffc98000008880 0041 00000000 0x0 0x0
0xffffc98000008900 0041 00000000 0x0 0x0
0xffffc98000008980 0041 00000000 0x0 0x0
0xffffc98000008a00 0041 00000000 0x0 0x0
0xffffc98000008a80 0041 00000000 0x0 0x0
0xffffc98000008b00 0041 00000000 0x0 0x0
0xffffc98000008b80 0041 00000000 0x0 0x0
0xffffc98000008c00 0041 00000000 0x0 0x0
0xffffc98000008c80 0041 00000000 0x0 0x0
0xffffc98000008d00 0041 00000000 0x0 0x0
0xffffc98000008d80 0041 00000000 0x0 0x0
0xffffc98000008e00 0041 00000000 0x0 0x0
0xffffc98000008e80 0041 00000000 0x0 0x0
0xffffc98000008f00 0041 00000000 0x0 0x0
0xffffc98000008f80 0041 00000000 0x0 0x0
0xffffc98000009000 0041 00000000 0x0 0x0
0xffffc98000009080 0041 00000000 0x0 0x0
0xffffc98000009100 0045 00000000 0x0 0x0
0xffffc98000009180 0045 00000000 0x0 0x0
0xffffc98000009200 0041 00000000 0x0 0x0
0xffffc98000009280 0041 00000000 0x0 0x0
0xffffc98000009300 0041 00000000 0x0 0x0
0xffffc98000009380 0041 00000000 0x0 0x0
0xffffc98000009400 0041 00000000 0x0 0x0
0xffffc98000009480 0041 00000000 0x0 0x0
0xffffc98000009500 0041 00000000 0x0 0x0
0xffffc98000009580 0041 00000000 0x0 0x0
0xffffc98000009600 0041 00000000 0x0 0x0
0xffffc98000009680 0041 00000000 0x0 0x0
0xffffc98000009700 0041 00000000 0x0 0x0
0xffffc98000009780 0041 00000000 0x0 0x0
0xffffc98000009800 0041 00000000 0x0 0x0
0xffffc98000009880 0041 00000000 0x0 0x0
0xffffc98000009900 0041 00000000 0x0 0x0
0xffffc98000009980 0041 00000000 0x0 0x0
0xffffc98000009a00 0041 00000000 0x0 0x0
0xffffc98000009a80 0041 00000000 0x0 0x0
0xffffc98000009b00 0041 00000000 0x0 0x0
0xffffc98000009b80 0041 00000000 0x0 0x0
0xffffc98000009c00 0041 00000000 0x0 0x0
0xffffc98000009c80 0041 00000000 0x0 0x0
0xffffc98000009d00 0041 00000000 0x0 0x0
0xffffc98000009d80 0041 00000000 0x0 0x0
0xffffc98000009e00 0041 00000000 0x0 0x0
0xffffc98000009e80 0041 00000000 0x0 0x0
0xffffc98000009f00 0041 00000000 0x0 0x0
0xffffc98000009f80 0045 00000000 0x0 0x0
0xffffc9800000a000 0041 00000000 0x0 0x0
0xffffc9800000a080 0041 00000000 0x0 0x0
0xffffc9800000a100 0041 00000000 0x0 0x0
0xffffc9800000a180 0041 00000000 0x0 0x0
0xffffc9800000a200 0041 00000000 0x0 0x0
0xffffc9800000a280 0041 00000000 0x0 0x0
0xffffc9800000a300 0041 00000000 0x0 0x0
0xffffc9800000a380 0041 00000000 0x0 0x0
0xffffc9800000a400 0041 00000000 0x0 0x0
0xffffc9800000a480 0041 00000000 0x0 0x0
0xffffc9800000a500 0041 00000000 0x0 0x0
0xffffc9800000a580 0041 00000000 0x0 0x0
0xffffc9800000a600 0041 00000000 0x0 0x0
0xffffc9800000a680 0041 00000000 0x0 0x0
0xffffc9800000a700 0041 00000000 0x0 0x0
0xffffc9800000a780 0041 00000000 0x0 0x0
0xffffc9800000a800 0041 00000000 0x0 0x0
0xffffc9800000a880 0041 00000000 0x0 0x0
0xffffc9800000a900 0041 00000000 0x0 0x0
0xffffc9800000a980 0041 00000000 0x0 0x0
0xffffc9800000aa00 0041 00000000 0x0 0x0
0xffffc9800000aa80 0041 00000000 0x0 0x0
0xffffc9800000ab00 0041 00000000 0x0 0x0
0xffffc9800000ab80 0041 00000000 0x0 0x0
0xffffc9800000ac00 0041 00000000 0x0 0x0
0xffffc9800000ac80 0041 00000000 0x0 0x0
0xffffc9800000ad00 0041 00000000 0x0 0x0
0xffffc9800000ad80 0041 00000000 0x0 0x0
0xffffc9800000ae00 0041 00000000 0x0 0x0
0xffffc9800000ae80 0041 00000000 0x0 0x0
0xffffc9800000af00 0041 00000000 0x0 0x0
0xffffc9800000af80 0041 00000000 0x0 0x0
0xffffc9800000b000 0045 00000000 0x0 0x0
0xffffc9800000b080 0041 00000000 0x0 0x0
0xffffc9800000b100 0041 00000000 0x0 0x0
0xffffc9800000b180 0041 00000000 0x0 0x0
0xffffc9800000b200 0045 00000000 0x0 0x0
0xffffc9800000b280 0045 00000000 0x0 0x0
0xffffc9800000b300 0045 00000000 0x0 0x0
0xffffc9800000b380 0045 00000000 0x0 0x0
0xffffc9800000b400 0045 00000000 0x0 0x0
0xffffc9800000b480 0045 00000000 0x0 0x0
0xffffc9800000b500 0041 00000000 0x0 0x0
0xffffc9800000b580 0041 00000000 0x0 0x0
0xffffc9800000b600 0045 00000000 0x0 0x0
0xffffc9800000b680 0045 00000000 0x0 0x0
0xffffc9800000b700 0045 00000000 0x0 0x0
0xffffc9800000b780 0045 00000000 0x0 0x0
0xffffc9800000b800 0045 00000000 0x0 0x0
0xffffc9800000b880 0045 00000000 0x0 0x0
0xffffc9800000b900 0045 00000000 0x0 0x0
0xffffc9800000b980 0045 00000000 0x0 0x0
0xffffc9800000ba00 0045 00000000 0x0 0x0
0xffffc9800000ba80 0045 00000000 0x0 0x0
0xffffc9800000bb00 0045 00000000 0x0 0x0
0xffffc9800000bb80 0045 00000000 0x0 0x0
0xffffc9800000bc00 0045 00000000 0x0 0x0
0xffffc9800000bc80 0045 00000000 0x0 0x0
0xffffc9800000bd00 0045 00000000 0x0 0x0
0xffffc9800000bd80 0045 00000000 0x0 0x0
0xffffc9800000be00 0045 00000000 0x0 0x0
0xffffc9800000be80 0045 00000000 0x0 0x0
0xffffc9800000bf00 0045 00000000 0x0 0x0
0xffffc9800000bf80 0045 00000000 0x0 0x0
0xffffc9800000c000 0045 00000000 0x0 0x0
0xffffc9800000c080 0045 00000000 0x0 0x0
0xffffc9800000c100 0045 00000000 0x0 0x0
0xffffc9800000c180 0045 00000000 0x0 0x0
0xffffc9800000c200 0045 00000000 0x0 0x0
0xffffc9800000c280 0045 00000000 0x0 0x0
0xffffc9800000c300 0045 00000000 0x0 0x0
0xffffc9800000c380 0045 00000000 0x0 0x0
0xffffc9800000c400 0045 00000000 0x0 0x0
0xffffc9800000c480 0045 00000000 0x0 0x0
0xffffc9800000c500 0045 00000000 0x0 0x0
0xffffc9800000c580 0045 00000000 0x0 0x0
0xffffc9800000c600 0045 00000000 0x0 0x0
0xffffc9800000c680 0045 00000000 0x0 0x0
0xffffc9800000c700 0045 00000000 0x0 0x0
0xffffc9800000c780 0045 00000000 0x0 0x0
0xffffc9800000c800 0041 00000000 0x0 0x0
0xffffc9800000c880 0045 00000000 0x0 0x0
0xffffc9800000c900 0045 00000000 0x0 0x0
0xffffc9800000c980 0045 00000000 0x0 0x0
0xffffc9800000ca00 0041 00000000 0x0 0x0
0xffffc9800000ca80 0045 00000000 0x0 0x0
0xffffc9800000cb00 0045 00000000 0x0 0x0
0xffffc9800000cb80 0045 00000000 0x0 0x0
0xffffc9800000cc00 0041 00000000 0x0 0x0
0xffffc9800000cc80 0041 00000000 0x0 0x0
0xffffc9800000cd00 0045 00000000 0x0 0x0
0xffffc9800000cd80 0045 00000000 0x0 0x0
0xffffc9800000ce00 0041 00000000 0x0 0x0
0xffffc9800000ce80 0041 00000000 0x0 0x0
0xffffc9800000cf00 0041 00000000 0x0 0x0
0xffffc9800000cf80 0041 00000000 0x0 0x0
0xffffc9800000d000 0041 00000000 0x0 0x0
0xffffc9800000d080 0041 00000000 0x0 0x0
0xffffc9800000d100 0041 00000000 0x0 0x0
0xffffc9800000d180 0041 00000000 0x0 0x0
0xffffc9800000d200 0041 00000000 0x0 0x0
0xffffc9800000d280 0041 00000000 0x0 0x0
0xffffc9800000d300 0041 00000000 0x0 0x0
0xffffc9800000d380 0041 00000000 0x0 0x0
0xffffc9800000d400 0041 00000000 0x0 0x0
0xffffc9800000d480 0041 00000000 0x0 0x0
0xffffc9800000d500 0041 00000000 0x0 0x0
0xffffc9800000d580 0041 00000000 0x0 0x0
0xffffc9800000d600 0041 00000000 0x0 0x0
0xffffc9800000d680 0041 00000000 0x0 0x0
0xffffc9800000d700 0041 00000000 0x0 0x0
0xffffc9800000d780 0041 00000000 0x0 0x0
0xffffc9800000d800 0045 00000000 0x0 0x0
0xffffc9800000d880 0041 00000000 0x0 0x0
0xffffc9800000d900 0041 00000000 0x0 0x0
0xffffc9800000d980 0041 00000000 0x0 0x0
0xffffc9800000da00 0041 00000000 0x0 0x0
0xffffc9800000da80 0045 00000000 0x0 0x0
0xffffc9800000db00 0045 00000000 0x0 0x0
0xffffc9800000db80 0041 00000000 0x0 0x0
0xffffc9800000dc00 0045 00000000 0x0 0x0
0xffffc9800000dc80 0045 00000000 0x0 0x0
0xffffc9800000dd00 0041 00000000 0x0 0x0
0xffffc9800000dd80 0041 00000000 0x0 0x0
0xffffc9800000de00 0045 00000000 0x0 0x0
0xffffc9800000de80 0041 00000000 0x0 0x0
0xffffc9800000df00 0041 00000000 0x0 0x0
0xffffc9800000df80 0045 00000000 0x0 0x0
0xffffc9800000e000 0045 00000000 0x0 0x0
0xffffc9800000e080 0045 00000000 0x0 0x0
0xffffc9800000e100 0041 00000000 0x0 0x0
0xffffc9800000e180 0041 00000000 0x0 0x0
0xffffc9800000e200 0041 00000000 0x0 0x0
0xffffc9800000e280 0041 00000000 0x0 0x0
0xffffc9800000e300 0045 00000000 0x0 0x0
0xffffc9800000e380 0045 00000000 0x0 0x0
0xffffc9800000e400 0041 00000000 0x0 0x0
0xffffc9800000e480 0041 00000000 0x0 0x0
0xffffc9800000e500 0045 00000000 0x0 0x0
0xffffc9800000e580 0045 00000000 0x0 0x0
0xffffc9800000e600 0041 00000000 0x0 0x0
0xffffc9800000e680 0045 00000000 0x0 0x0
0xffffc9800000e700 0045 00000000 0x0 0x0
0xffffc9800000e780 0045 00000000 0x0 0x0
0xffffc9800000e800 0041 00000000 0x0 0x0
0xffffc9800000e880 0045 00000000 0x0 0x0
0xffffc9800000e900 0041 00000000 0x0 0x0
0xffffc9800000e980 0041 00000000 0x0 0x0
0xffffc9800000ea00 0041 00000000 0x0 0x0
0xffffc9800000ea80 0041 00000000 0x0 0x0
0xffffc9800000eb00 0045 00000000 0x0 0x0
0xffffc9800000eb80 0041 00000000 0x0 0x0
0xffffc9800000ec00 0045 00000000 0x0 0x0
0xffffc9800000ec80 0041 00000000 0x0 0x0
0xffffc9800000ed00 0041 00000000 0x0 0x0
0xffffc9800000ed80 0041 00000000 0x0 0x0
0xffffc9800000ee00 0041 00000000 0x0 0x0
0xffffc9800000ee80 0045 00000000 0x0 0x0
0xffffc9800000ef00 0041 00000000 0x0 0x0
0xffffc9800000ef80 0041 00000000 0x0 0x0
0xffffc9800000f000 0041 00000000 0x0 0x0
0xffffc9800000f080 0041 00000000 0x0 0x0
0xffffc9800000f100 0041 00000000 0x0 0x0
0xffffc9800000f180 0041 00000000 0x0 0x0
0xffffc9800000f200 0041 00000000 0x0 0x0
0xffffc9800000f280 0041 00000000 0x0 0x0
0xffffc9800000f300 0041 00000000 0x0 0x0
0xffffc9800000f380 0045 00000000 0x0 0x0
0xffffc9800000f400 0045 00000000 0x0 0x0
0xffffc9800000f480 0041 00000000 0x0 0x0
0xffffc9800000f500 0041 00000000 0x0 0x0
0xffffc9800000f580 0041 00000000 0x0 0x0
0xffffc9800000f600 0045 00000000 0x0 0x0
0xffffc9800000f680 0041 00000000 0x0 0x0
0xffffc9800000f700 0041 00000000 0x0 0x0
0xffffc9800000f780 0041 00000000 0x0 0x0
0xffffc9800000f800 0041 00000000 0x0 0x0
0xffffc9800000f880 0045 00000000 0x0 0x0
0xffffc9800000f900 0045 00000000 0x0 0x0
0xffffc9800000f980 0041 00000000 0x0 0x0
0xffffc9800000fa00 0041 00000000 0x0 0x0
0xffffc9800000fa80 0045 00000000 0x0 0x0
0xffffc9800000fb00 0041 00000000 0x0 0x0
0xffffc9800000fb80 0041 00000000 0x0 0x0
0xffffc9800000fc00 0041 00000000 0x0 0x0
0xffffc9800000fc80 0041 00000000 0x0 0x0
0xffffc9800000fd00 0041 00000000 0x0 0x0
0xffffc9800000fd80 0045 00000000 0x0 0x0
0xffffc9800000fe00 0041 00000000 0x0 0x0
0xffffc9800000fe80 0041 00000000 0x0 0x0
0xffffc9800000ff00 0041 00000000 0x0 0x0
0xffffc9800000ff80 0041 00000000 0x0 0x0
0xffffc98000010000 0041 00000000 0x0 0x0
0xffffc98000010080 0045 00000000 0x0 0x0
0xffffc98000010100 0045 00000000 0x0 0x0
0xffffc98000010180 0041 00000000 0x0 0x0
0xffffc98000010200 0045 00000000 0x0 0x0
0xffffc98000010280 0041 00000000 0x0 0x0
0xffffc98000010300 0041 00000000 0x0 0x0
0xffffc98000010380 0041 00000000 0x0 0x0
0xffffc98000010400 0041 00000000 0x0 0x0
0xffffc98000010480 0041 00000000 0x0 0x0
0xffffc98000010500 0041 00000000 0x0 0x0
0xffffc98000010580 0041 00000000 0x0 0x0
0xffffc98000010600 0041 00000000 0x0 0x0
0xffffc98000010680 0041 00000000 0x0 0x0
0xffffc98000010700 0041 00000000 0x0 0x0
0xffffc98000010780 0041 00000000 0x0 0x0
0xffffc98000010800 0041 00000000 0x0 0x0
0xffffc98000010880 0041 00000000 0x0 0x0
0xffffc98000010900 0045 00000000 0x0 0x0
0xffffc98000010980 0045 00000000 0x0 0x0
0xffffc98000010a00 0045 00000000 0x0 0x0
0xffffc98000010a80 0045 00000000 0x0 0x0
0xffffc98000010b00 0045 00000000 0x0 0x0
0xffffc98000010b80 0041 00000000 0x0 0x0
0xffffc98000010c00 0041 00000000 0x0 0x0
0xffffc98000010c80 0041 00000000 0x0 0x0
0xffffc98000010d00 0041 00000000 0x0 0x0
0xffffc98000010d80 0041 00000000 0x0 0x0
0xffffc98000010e00 0041 00000000 0x0 0x0
0xffffc98000010e80 0041 00000000 0x0 0x0
0xffffc98000010f00 0041 00000000 0x0 0x0
0xffffc98000010f80 0045 00000000 0x0 0x0
0xffffc98000011000 0041 00000000 0x0 0x0
0xffffc98000011080 0041 00000000 0x0 0x0
0xffffc98000011100 0041 00000000 0x0 0x0
0xffffc98000011180 0041 00000000 0x0 0x0
0xffffc98000011200 0041 00000000 0x0 0x0
0xffffc98000011280 0045 00000000 0x0 0x0
0xffffc98000011300 0041 00000000 0x0 0x0
0xffffc98000011380 0041 00000000 0x0 0x0
0xffffc98000011400 0041 00000000 0x0 0x0
0xffffc98000011480 0041 00000000 0x0 0x0
0xffffc98000011500 0041 00000000 0x0 0x0
0xffffc98000011580 0041 00000000 0x0 0x0
0xffffc98000011600 0041 00000000 0x0 0x0
0xffffc98000011680 0041 00000000 0x0 0x0
0xffffc98000011700 0041 00000000 0x0 0x0
0xffffc98000011780 0041 00000000 0x0 0x0
0xffffc98000011800 0041 00000000 0x0 0x0
0xffffc98000011880 0041 00000000 0x0 0x0
0xffffc98000011900 0041 00000000 0x0 0x0
0xffffc98000011980 0041 00000000 0x0 0x0
0xffffc98000011a00 0045 00000000 0x0 0x0
0xffffc98000011a80 0041 00000000 0x0 0x0
0xffffc98000011b00 0041 00000000 0x0 0x0
0xffffc98000011b80 0041 00000000 0x0 0x0
0xffffc98000011c00 0045 00000000 0x0 0x0
0xffffc98000011c80 0045 00000000 0x0 0x0
0xffffc98000011d00 0041 00000000 0x0 0x0
0xffffc98000011d80 0041 00000000 0x0 0x0
0xffffc98000011e00 0041 00000000 0x0 0x0
0xffffc98000011e80 0041 00000000 0x0 0x0
0xffffc98000011f00 0045 00000000 0x0 0x0
0xffffc98000011f80 0045 00000000 0x0 0x0
0xffffc98000012000 0041 00000000 0x0 0x0
0xffffc98000012080 0041 00000000 0x0 0x0
0xffffc98000012100 0041 00000000 0x0 0x0
0xffffc98000012180 0045 00000000 0x0 0x0
0xffffc98000012200 0041 00000000 0x0 0x0
0xffffc98000012280 0041 00000000 0x0 0x0
0xffffc98000012300 0041 00000000 0x0 0x0
0xffffc98000012380 0041 00000000 0x0 0x0
0xffffc98000012400 0041 00000000 0x0 0x0
0xffffc98000012480 0041 00000000 0x0 0x0
0xffffc98000012500 0045 00000000 0x0 0x0
0xffffc98000012580 0041 00000000 0x0 0x0
0xffffc98000012600 0041 00000000 0x0 0x0
0xffffc98000012680 0045 00000000 0x0 0x0
0xffffc98000012700 0001 00000000 0x0 0x0
0xffffc98000012780 0001 00000000 0x0 0x0
0xffffc98000012800 0001 00000000 0x0 0x0
0xffffc98000012880 0001 00000000 0x0 0x0
0xffffc98000012900 0001 00000000 0x0 0x0
0xffffc98000012980 0001 00000000 0x0 0x0
0xffffc98000012a00 0001 00000000 0x0 0x0
0xffffc98000012a80 0001 00000000 0x0 0x0
0xffffc98000012b00 0001 00000000 0x0 0x0
0xffffc98000012b80 0001 00000000 0x0 0x0
0xffffc98000012c00 0001 00000000 0x0 0x0
0xffffc98000012c80 0001 00000000 0x0 0x0
0xffffc98000012d00 0001 00000000 0x0 0x0
0xffffc98000012d80 0001 00000000 0x0 0x0
0xffffc98000012e00 0001 00000000 0x0 0x0
0xffffc98000012e80 0001 00000000 0x0 0x0
0xffffc98000012f00 0001 00000000 0x0 0x0
0xffffc98000012f80 0001 00000000 0x0 0x0
0xffffc98000013000 0001 00000000 0x0 0x0
0xffffc98000013080 0001 00000000 0x0 0x0
0xffffc98000013100 0001 00000000 0x0 0x0
0xffffc98000013180 0001 00000000 0x0 0x0
0xffffc98000013200 0001 00000000 0x0 0x0
0xffffc98000013280 0001 00000000 0x0 0x0
0xffffc98000013300 0001 00000000 0x0 0x0
0xffffc98000013380 0001 00000000 0x0 0x0
0xffffc98000013400 0001 00000000 0x0 0x0
0xffffc98000013480 0001 00000000 0x0 0x0
0xffffc98000013500 0001 00000000 0x0 0x0
0xffffc98000013580 0001 00000000 0x0 0x0
0xffffc98000013600 0001 00000000 0x0 0x0
0xffffc98000013680 0001 00000000 0x0 0x0
0xffffc98000013700 0001 00000000 0x0 0x0
0xffffc98000013780 0001 00000000 0x0 0x0
0xffffc98000013800 0001 00000000 0x0 0x0
0xffffc98000013880 0001 00000000 0x0 0x0
0xffffc98000013900 0001 00000000 0x0 0x0
0xffffc98000013980 0001 00000000 0x0 0x0
0xffffc98000013a00 0001 00000000 0x0 0x0
0xffffc98000013a80 0001 00000000 0x0 0x0
0xffffc98000013b00 0001 00000000 0x0 0x0
0xffffc98000013b80 0001 00000000 0x0 0x0
0xffffc98000013c00 0001 00000000 0x0 0x0
0xffffc98000013c80 0001 00000000 0x0 0x0
0xffffc98000013d00 0001 00000000 0x0 0x0
0xffffc98000013d80 0001 00000000 0x0 0x0
0xffffc98000013e00 0001 00000000 0x0 0x0
0xffffc98000013e80 0001 00000000 0x0 0x0
0xffffc98000013f00 0001 00000000 0x0 0x0
0xffffc98000013f80 0001 00000000 0x0 0x0
0xffffc98000014000 0001 00000000 0x0 0x0
0xffffc98000014080 0001 00000000 0x0 0x0
0xffffc98000014100 0001 00000000 0x0 0x0
0xffffc98000014180 0001 00000000 0x0 0x0
0xffffc98000014200 0041 00000000 0x0 0x0
0xffffc98000014280 0041 00000000 0x0 0x0
0xffffc98000014300 0041 00000000 0x0 0x0
0xffffc98000014380 0041 00000000 0x0 0x0
0xffffc98000014400 0041 00000000 0x0 0x0
0xffffc98000014480 0041 00000000 0x0 0x0
0xffffc98000014500 0041 00000000 0x0 0x0
0xffffc98000014580 0041 00000000 0x0 0x0
0xffffc98000014600 0041 00000000 0x0 0x0
0xffffc98000014680 0041 00000000 0x0 0x0
0xffffc98000014700 0041 00000000 0x0 0x0
0xffffc98000014780 0041 00000000 0x0 0x0
0xffffc98000014800 0041 00000000 0x0 0x0
0xffffc98000014880 0041 00000000 0x0 0x0
0xffffc98000014900 0041 00000000 0x0 0x0
0xffffc98000014980 0041 00000000 0x0 0x0
0xffffc98000014a00 0041 00000000 0x0 0x0
0xffffc98000014a80 0041 00000000 0x0 0x0
0xffffc98000014b00 0041 00000000 0x0 0x0
0xffffc98000014b80 0041 00000000 0x0 0x0
0xffffc98000014c00 0041 00000000 0x0 0x0
0xffffc98000014c80 0041 00000000 0x0 0x0
0xffffc98000014d00 0041 00000000 0x0 0x0
0xffffc98000014d80 0041 00000000 0x0 0x0
0xffffc98000014e00 0041 00000000 0x0 0x0
0xffffc98000014e80 0041 00000000 0x0 0x0
0xffffc98000014f00 0041 00000000 0x0 0x0
0xffffc98000014f80 0041 00000000 0x0 0x0
0xffffc98000015000 0041 00000000 0x0 0x0
0xffffc98000015080 0041 00000000 0x0 0x0
0xffffc98000015100 0041 00000000 0x0 0x0
0xffffc98000015180 0041 00000000 0x0 0x0
0xffffc98000015200 0041 00000000 0x0 0x0
0xffffc98000015280 0041 00000000 0x0 0x0
0xffffc98000015300 0041 00000000 0x0 0x0
0xffffc98000015380 0041 00000000 0x0 0x0
0xffffc98000015400 0041 00000000 0x0 0x0
0xffffc98000015480 0041 00000000 0x0 0x0
0xffffc98000015500 0041 00000000 0x0 0x0
0xffffc98000015580 0041 00000000 0x0 0x0
0xffffc98000015600 0041 00000000 0x0 0x0
0xffffc98000015680 0041 00000000 0x0 0x0
0xffffc98000015700 0041 00000000 0x0 0x0
0xffffc98000015780 0041 00000000 0x0 0x0
0xffffc98000015800 0041 00000000 0x0 0x0
0xffffc98000015880 0041 00000000 0x0 0x0
0xffffc98000015900 0041 00000000 0x0 0x0
0xffffc98000015980 0001 00000000 0x0 0x0
0xffffc98000015a00 0001 00000000 0x0 0x0
0xffffc98000015a80 0001 00000000 0x0 0x0
0xffffc98000015b00 0001 00000000 0x0 0x0
0xffffc98000015b80 0001 00000000 0x0 0x0
0xffffc98000015c00 0001 00000000 0x0 0x0
0xffffc98000015c80 0001 00000000 0x0 0x0
0xffffc98000015d00 0001 00000000 0x0 0x0
0xffffc98000015d80 0001 00000000 0x0 0x0
0xffffc98000015e00 0001 00000000 0x0 0x0
0xffffc98000015e80 0001 00000000 0x0 0x0
0xffffc98000015f00 0001 00000000 0x0 0x0
0xffffc98000015f80 0001 00000000 0x0 0x0
0xffffc98000016000 0001 00000000 0x0 0x0
0xffffc98000016080 0001 00000000 0x0 0x0
0xffffc98000016100 0001 00000000 0x0 0x0
0xffffc98000016180 0001 00000000 0x0 0x0
0xffffc98000016200 0001 00000000 0x0 0x0
0xffffc98000016280 0001 00000000 0x0 0x0
0xffffc98000016300 0001 00000000 0x0 0x0
0xffffc98000016380 0001 00000000 0x0 0x0
0xffffc98000016400 0001 00000000 0x0 0x0
0xffffc98000016480 0001 00000000 0x0 0x0
0xffffc98000016500 0001 00000000 0x0 0x0
0xffffc98000016580 0001 00000000 0x0 0x0
0xffffc98000016600 0001 00000000 0x0 0x0
0xffffc98000016680 0001 00000000 0x0 0x0
0xffffc98000016700 0001 00000000 0x0 0x0
0xffffc98000016780 0001 00000000 0x0 0x0
0xffffc98000016800 0001 00000000 0x0 0x0
0xffffc98000016880 0001 00000000 0x0 0x0
0xffffc98000016900 0001 00000000 0x0 0x0
0xffffc98000016980 0001 00000000 0x0 0x0
0xffffc98000016a00 0001 00000000 0x0 0x0
0xffffc98000016a80 0001 00000000 0x0 0x0
0xffffc98000016b00 0001 00000000 0x0 0x0
0xffffc98000016b80 0001 00000000 0x0 0x0
0xffffc98000016c00 0001 00000000 0x0 0x0
0xffffc98000016c80 0001 00000000 0x0 0x0
0xffffc98000016d00 0001 00000000 0x0 0x0
0xffffc98000016d80 0001 00000000 0x0 0x0
0xffffc98000016e00 0001 00000000 0x0 0x0
0xffffc98000016e80 0001 00000000 0x0 0x0
0xffffc98000016f00 0001 00000000 0x0 0x0
0xffffc98000016f80 0001 00000000 0x0 0x0
0xffffc98000017000 0001 00000000 0x0 0x0
0xffffc98000017080 0001 00000000 0x0 0x0
0xffffc98000017100 0001 00000000 0x0 0x0
0xffffc98000017180 0001 00000000 0x0 0x0
0xffffc98000017200 0001 00000000 0x0 0x0
0xffffc98000017280 0001 00000000 0x0 0x0
0xffffc98000017300 0001 00000000 0x0 0x0
0xffffc98000017380 0001 00000000 0x0 0x0
0xffffc98000017400 0001 00000000 0x0 0x0
0xffffc98000017480 0041 00000000 0x0 0x0
0xffffc98000017500 0041 00000000 0x0 0x0
0xffffc98000017580 0041 00000000 0x0 0x0
0xffffc98000017600 0041 00000000 0x0 0x0
0xffffc98000017680 0041 00000000 0x0 0x0
0xffffc98000017700 0041 00000000 0x0 0x0
0xffffc980

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages