ASan: Unauthorized Access in htable_foreach_lle

0 views
Skip to first unread message

syzbot

unread,
Jun 15, 2024, 8:02:20 PM (11 days ago) Jun 15
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: e9cd92281172 Ignore unit attention caused EIO errors when ..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=155911de980000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=ea87a9be2c566dcef510
compiler: g++ (Debian 12.2.0-14) 12.2.0

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/7031dddde2e2/disk-e9cd9228.raw.xz
netbsd.gdb: https://storage.googleapis.com/syzbot-assets/d2bcb5e76758/netbsd-e9cd9228.gdb.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+ea87a9...@syzkaller.appspotmail.com

[ 100.1404394] .: failed to start extattr, error = 0panic: ASan: Unauthorized Access In 0xffffffff81dd23c3: Addr 0xffff9d80129f3c50 [8 bytes, read, PoolUseAfterFree]

[ 101.2064366] cpu0: Begin traceback...
[ 101.2204233] vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:288
[ 101.2704176] panic() at netbsd:panic+0x9e sys/kern/subr_prf.c:1084
[ 101.3204187] kasan_report() at netbsd:kasan_report+0x8f kasan_code_name sys/kern/subr_asan.c:169 [inline]
[ 101.3204187] kasan_report() at netbsd:kasan_report+0x8f sys/kern/subr_asan.c:201
[ 101.3604164] __asan_load8() at netbsd:__asan_load8+0xac kasan_shadow_8byte_isvalid sys/kern/subr_asan.c:371 [inline]
[ 101.3604164] __asan_load8() at netbsd:__asan_load8+0xac kasan_shadow_check sys/kern/subr_asan.c:421 [inline]
[ 101.3604164] __asan_load8() at netbsd:__asan_load8+0xac sys/kern/subr_asan.c:1208
[ 101.4004230] htable_foreach_lle() at netbsd:htable_foreach_lle+0x73 sys/net/if_llatbl.c:198
[ 101.4504186] htable_prefix_free() at netbsd:htable_prefix_free+0x103 llentries_unlink sys/net/if_llatbl.c:307 [inline]
[ 101.4504186] htable_prefix_free() at netbsd:htable_prefix_free+0x103 sys/net/if_llatbl.c:287
[ 101.4904167] lltable_prefix_free() at netbsd:lltable_prefix_free+0x81 sys/net/if_llatbl.c:513
[ 101.5304197] rtrequest1() at netbsd:rtrequest1+0xb85 sys/net/route.c:1204
[ 101.5704214] rtinit() at netbsd:rtinit+0x412 sys/net/route.c:1656
[ 101.6104182] in_scrubprefix.part.0.isra.0() at netbsd:in_scrubprefix.part.0.isra.0+0x2dd
[ 101.6604190] in_scrubaddr() at netbsd:in_scrubaddr+0xe0 in_ifremlocal sys/netinet/in.c:816 [inline]
[ 101.6604190] in_scrubaddr() at netbsd:in_scrubaddr+0xe0 sys/netinet/in.c:861
[ 101.7004208] in_purgeaddr() at netbsd:in_purgeaddr+0x44 sys/netinet/in.c:889
[ 101.7404189] if_purgeaddrs() at netbsd:if_purgeaddrs+0x1a2 sys/net/if.c:1245
[ 101.7804176] in_purgeif() at netbsd:in_purgeif+0x3e sys/netinet/in.c:952
[ 101.8204217] rip_purgeif_wrapper() at netbsd:rip_purgeif_wrapper+0x56 rip_purgeif sys/netinet/raw_ip.c:830 [inline]
[ 101.8204217] rip_purgeif_wrapper() at netbsd:rip_purgeif_wrapper+0x56 sys/netinet/raw_ip.c:837
[ 101.8604198] if_detach() at netbsd:if_detach+0x768 sys/net/if.c:1459
[ 101.9104187] tap_detach() at netbsd:tap_detach+0xe8 sys/net/if_tap.c:402
[ 101.9504188] config_detach_release() at netbsd:config_detach_release+0x3d7 sys/kern/subr_autoconf.c:2177
[ 102.0004246] tap_clone_destroyer() at netbsd:tap_clone_destroyer+0x2d sys/net/if_tap.c:644
[ 102.0404181] tap_clone_destroy() at netbsd:tap_clone_destroy+0x2c sys/net/if_tap.c:634
[ 102.0904222] doifioctl() at netbsd:doifioctl+0x14b7 if_clone_destroy sys/net/if.c:1631 [inline]
[ 102.0904222] doifioctl() at netbsd:doifioctl+0x14b7 sys/net/if.c:3512
[ 102.1304211] soo_ioctl() at netbsd:soo_ioctl+0x3cc sys/kern/sys_socket.c:215
[ 102.1704233] sys_ioctl() at netbsd:sys_ioctl+0x8f6 sys/kern/sys_generic.c:675
[ 102.2104190] syscall() at netbsd:syscall+0x246 sy_call sys/sys/syscallvar.h:65 [inline]
[ 102.2104190] syscall() at netbsd:syscall+0x246 sy_invoke sys/sys/syscallvar.h:94 [inline]
[ 102.2104190] syscall() at netbsd:syscall+0x246 sys/arch/x86/x86/syscall.c:137
[ 102.2204199] --- syscall (number 54) ---
[ 102.2404310] netbsd:syscall+0x246:
[ 102.2404310] cpu0: End traceback...
[ 102.2404310] fatal breakpoint trap in supervisor mode
[ 102.2531958] trap type 1 code 0 rip 0xffffffff8023240d cs 0x8 rflags 0x282 cr2 0x1b3162f000 ilevel 0x6 rsp 0xffff9d8248619720
[ 102.2661796] curlwp 0xffff9d801408d500 pid 3031.3031 lowest kstack 0xffff9d82486132c0
Stopped in pid 3031.3031 (ifconfig) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0x105 sys/ddb/db_panic.c:71
vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:288
panic() at netbsd:panic+0x9e sys/kern/subr_prf.c:1084
kasan_report() at netbsd:kasan_report+0x8f kasan_code_name sys/kern/subr_asan.c:169 [inline]
kasan_report() at netbsd:kasan_report+0x8f sys/kern/subr_asan.c:201
__asan_load8() at netbsd:__asan_load8+0xac kasan_shadow_8byte_isvalid sys/kern/subr_asan.c:371 [inline]
__asan_load8() at netbsd:__asan_load8+0xac kasan_shadow_check sys/kern/subr_asan.c:421 [inline]
__asan_load8() at netbsd:__asan_load8+0xac sys/kern/subr_asan.c:1208
htable_foreach_lle() at netbsd:htable_foreach_lle+0x73 sys/net/if_llatbl.c:198
htable_prefix_free() at netbsd:htable_prefix_free+0x103 llentries_unlink sys/net/if_llatbl.c:307 [inline]
htable_prefix_free() at netbsd:htable_prefix_free+0x103 sys/net/if_llatbl.c:287
lltable_prefix_free() at netbsd:lltable_prefix_free+0x81 sys/net/if_llatbl.c:513
rtrequest1() at netbsd:rtrequest1+0xb85 sys/net/route.c:1204
rtinit() at netbsd:rtinit+0x412 sys/net/route.c:1656
in_scrubprefix.part.0.isra.0() at netbsd:in_scrubprefix.part.0.isra.0+0x2dd
in_scrubaddr() at netbsd:in_scrubaddr+0xe0 in_ifremlocal sys/netinet/in.c:816 [inline]
in_scrubaddr() at netbsd:in_scrubaddr+0xe0 sys/netinet/in.c:861
in_purgeaddr() at netbsd:in_purgeaddr+0x44 sys/netinet/in.c:889
if_purgeaddrs() at netbsd:if_purgeaddrs+0x1a2 sys/net/if.c:1245
in_purgeif() at netbsd:in_purgeif+0x3e sys/netinet/in.c:952
rip_purgeif_wrapper() at netbsd:rip_purgeif_wrapper+0x56 rip_purgeif sys/netinet/raw_ip.c:830 [inline]
rip_purgeif_wrapper() at netbsd:rip_purgeif_wrapper+0x56 sys/netinet/raw_ip.c:837
if_detach() at netbsd:if_detach+0x768 sys/net/if.c:1459
tap_detach() at netbsd:tap_detach+0xe8 sys/net/if_tap.c:402
config_detach_release() at netbsd:config_detach_release+0x3d7 sys/kern/subr_autoconf.c:2177
tap_clone_destroyer() at netbsd:tap_clone_destroyer+0x2d sys/net/if_tap.c:644
tap_clone_destroy() at netbsd:tap_clone_destroy+0x2c sys/net/if_tap.c:634
doifioctl() at netbsd:doifioctl+0x14b7 if_clone_destroy sys/net/if.c:1631 [inline]
doifioctl() at netbsd:doifioctl+0x14b7 sys/net/if.c:3512
soo_ioctl() at netbsd:soo_ioctl+0x3cc sys/kern/sys_socket.c:215
sys_ioctl() at netbsd:sys_ioctl+0x8f6 sys/kern/sys_generic.c:675
syscall() at netbsd:syscall+0x246 sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x246 sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x246 sys/arch/x86/x86/syscall.c:137
--- syscall (number 54) ---
netbsd:syscall+0x246:
Panic string: ASan: Unauthorized Access In 0xffffffff81dd23c3: Addr 0xffff9d80129f3c50 [8 bytes, read, PoolUseAfterFree]

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
3031 > 3031 7 0 0 ffff9d801408d500 ifconfig
2381 3285 3 0 0 ffff9d8012bb45c0 syz-executor.1 biolock
2381 2381 2 0 10040000 ffff9d8013df5a80 syz-executor.1
1477 2082 3 0 0 ffff9d801408d0c0 syz-executor.3 rwlock
1477 3126 3 0 0 ffff9d8012bf6640 syz-executor.3 rwlock
1477 3124 3 0 0 ffff9d80126d7740 syz-executor.3 rwlock
1477 2855 3 0 0 ffff9d8012a6c480 syz-executor.3 biowait
1477 1477 2 0 10040000 ffff9d8012bda600 syz-executor.3
2364 2364 2 0 10000000 ffff9d8013dc0a40 syz-executor.4
3294 3294 2 1 0 ffff9d8012b90580 syz-executor.2
1488 1488 3 1 40180 ffff9d8013fbd480 syz-executor.5 wait
3032 3032 2 0 0 ffff9d80134504c0 syz-executor.3
2783 2783 3 1 180 ffff9d801333e980 syz-executor.4 nanoslp
2778 2778 2 0 0 ffff9d801333e100 syz-executor.1
2231 2231 2 1 0 ffff9d8013fda080 syz-executor.0
1081 1472 3 1 180 ffff9d8012d126c0 syz-fuzzer wait
1081 1638 3 0 180 ffff9d8012c1bb00 syz-fuzzer wait
1081 449 3 0 180 ffff9d8013e11b00 syz-fuzzer parked
1081 331 3 0 180 ffff9d8012bdaa40 syz-fuzzer wait
1081 1234 3 0 180 ffff9d8012b909c0 syz-fuzzer wait
1081 1202 3 1 180 ffff9d8013e09680 syz-fuzzer parked
1081 1073 3 1 180 ffff9d8013e09240 syz-fuzzer kqueue
1081 829 3 1 180 ffff9d8013dc0600 syz-fuzzer parked
1081 943 3 1 180 ffff9d8012d2fb80 syz-fuzzer parked
1081 1095 3 0 180 ffff9d8012d2f740 syz-fuzzer wait
1081 1235 3 0 180 ffff9d80133eeb40 syz-fuzzer parked
1081 801 3 0 180 ffff9d80133ee700 syz-fuzzer parked
1081 1233 3 1 180 ffff9d801343cbc0 syz-fuzzer parked
1081 1081 3 1 180 ffff9d8012abf940 syz-fuzzer wait
1238 1238 3 0 180 ffff9d8012abf500 sshd select
1086 1086 3 0 180 ffff9d80126db480 getty nanoslp
1225 1225 3 0 180 ffff9d8013499180 getty nanoslp
1224 1224 3 1 180 ffff9d80126d9780 getty nanoslp
1195 1195 3 0 180 ffff9d8012a1bb80 getty ttyraw
1094 1094 3 0 180 ffff9d80133a5a80 sshd select
985 985 3 1 180 ffff9d8012d62780 powerd kqueue
767 767 3 1 180 ffff9d80133ee2c0 syslogd kqueue
747 747 3 0 180 ffff9d8012c61740 dhcpcd poll
748 748 3 1 180 ffff9d8012cbd100 dhcpcd poll
745 745 2 1 0 ffff9d8012c79780 dhcpcd
604 604 3 0 180 ffff9d8012c79bc0 dhcpcd poll
487 487 3 0 180 ffff9d8012db30c0 dhcpcd poll
292 292 3 0 180 ffff9d8012d98900 dhcpcd poll
485 > 485 7 1 0 ffff9d8012d984c0 dhcpcd
1 1 3 1 180 ffff9d8012874180 init wait
0 1000 3 0 200 ffff9d80129bf6c0 physiod physiod
0 196 3 1 200 ffff9d80129c1700 pooldrain pooldrain
0 195 3 0 200 ffff9d80129c12c0 ioflush syncer
0 194 3 0 200 ffff9d80129bfb00 pgdaemon pgdaemon
0 169 3 1 200 ffff9d8012976ac0 usb7 usbevt
0 172 3 1 200 ffff9d8012976680 usb6 usbevt
0 170 3 0 200 ffff9d8012976240 usb5 usbevt
0 168 3 1 200 ffff9d801291ea80 usb4 usbevt
0 166 3 0 200 ffff9d801291e640 usb3 usbevt
0 165 3 0 200 ffff9d801291e200 usb2 usbevt
0 31 3 0 200 ffff9d80128caa40 usb1 usbevt
0 63 3 0 200 ffff9d80128ca600 usb0 usbevt
0 126 3 0 200 ffff9d80128ca1c0 usbtask-dr usbtsk
0 125 3 1 200 ffff9d8012874a00 usbtask-hc usbtsk
0 124 3 0 200 ffff9d8010d66b00 swwreboot swwreboot
0 123 3 1 200 ffff9d80128745c0 npfgc0 npfgcw
0 122 3 0 200 ffff9d80128699c0 rt_free rt_free
0 121 3 0 200 ffff9d8012869580 unpgc unpgc
0 120 3 0 200 ffff9d8012869140 key_timehandler key_timehandler
0 119 3 1 200 ffff9d8012707980 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 ffff9d8012707540 icmp6_wqinput/0 icmp6_wqinput
0 117 3 0 200 ffff9d8012707100 nd6_timer nd6_timer
0 116 3 1 200 ffff9d80126ff940 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 ffff9d80126ff500 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 ffff9d80126ff0c0 carp_wqinput/1 carp_wqinput
0 113 3 0 200 ffff9d80126f1900 carp_wqinput/0 carp_wqinput
0 112 3 1 200 ffff9d80126f14c0 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 ffff9d80126f1080 icmp_wqinput/0 icmp_wqinput
0 110 3 0 200 ffff9d80126db8c0 rt_timer rt_timer
0 109 3 0 200 ffff9d80126d7b80 vmem_rehash vmem_rehash
0 100 3 0 200 ffff9d80126d7300 entbutler entropy
0 99 3 0 200 ffff9d80120bdb40 viomb balloon
0 98 3 1 200 ffff9d80120bd700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 ffff9d80120bd2c0 vioif0_txrx/0 vioif0_txrx
0 30 3 0 200 ffff9d8010d666c0 scsibus0 sccomp
0 29 3 0 200 ffff9d8010d66280 pms0 pmsreset
0 28 3 1 200 ffff9d8010cacac0 xcall/1 xcall
0 27 1 1 200 ffff9d8010cac680 softser/1
0 26 1 1 200 ffff9d8010cac240 softclk/1
0 25 1 1 200 ffff9d8010ca9a80 softbio/1
0 24 1 1 200 ffff9d8010ca9640 softnet/1
0 23 1 1 201 ffff9d8010ca9200 idle/1
0 22 3 1 200 ffff9d800fb55a40 lnxsyswq lnxsyswq
0 21 3 1 200 ffff9d800fb55600 lnxubdwq lnxubdwq
0 20 3 1 200 ffff9d800fb551c0 lnxpwrwq lnxpwrwq
0 19 3 1 200 ffff9d800fb54a00 lnxlngwq lnxlngwq
0 18 3 1 200 ffff9d800fb545c0 lnxhipwq lnxhipwq
0 17 3 1 200 ffff9d800fb54180 lnxrcugc lnxrcugc
0 16 3 0 200 ffff9d800fb4d9c0 sysmon smtaskq
0 15 3 0 200 ffff9d800fb4d580 pmfsuspend pmfsuspend
0 14 3 0 200 ffff9d800fb4d140 pmfevent pmfevent
0 13 3 0 200 ffff9d800fb4a980 sopendfree sopendfr
0 12 3 0 200 ffff9d800fb4a540 ifwdog ifwdog
0 11 3 0 200 ffff9d800fb4a100 iflnkst iflnkst
0 10 3 0 200 ffff9d800fb3b940 nfssilly nfssilly
0 9 3 0 200 ffff9d800fb3b500 pooldisp pooldisp
0 8 3 1 200 ffff9d800fb3b0c0 modunload mod_unld
0 7 3 0 200 ffff9d800fb32900 xcall/0 xcall
0 6 1 0 200 ffff9d800fb324c0 softser/0
0 5 1 0 200 ffff9d800fb32080 softclk/0
0 4 1 0 200 ffff9d800fb308c0 softbio/0
0 3 1 0 200 ffff9d800fb30480 softnet/0
0 2 1 0 201 ffff9d800fb30040 idle/0
0 0 3 0 200 ffffffff83350200 swapper uvm
[Locks tracked through LWPs]

****** LWP 3031.3031 (ifconfig) @ 0xffff9d801408d500, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:ifinit1+0x23 sys/net/if.c:334)
lock address : netbsd:if_clone_mtx
type : sleep/adaptive
initialized : netbsd:ifinit1+0x23
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 0xffff9d801408d500
last locked* : netbsd:doifioctl+0x137a
unlocked : netbsd:doifioctl+0x1500
owner field : 0xffff9d801408d500 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:soinit+0x1f9 sys/kern/uipc_socket.c:460)
lock address : ffff9d800f68a880
type : sleep/adaptive
initialized : netbsd:soinit+0x1f9
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 0xffff9d801408d500
last locked* : netbsd:rip_purgeif_wrapper+0x3f
unlocked : netbsd:sopoll+0x1a0
owner field : 0xffff9d801408d500 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 2 (initialized at netbsd:if_initialize+0x284 sys/net/if.c:762)
lock address : ffff9d8013e49dc0
type : sleep/adaptive
initialized : netbsd:if_initialize+0x284
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 0xffff9d801408d500
last locked* : netbsd:in_purgeif+0x2a
unlocked : netbsd:if_detach+0x280
owner field : 0xffff9d801408d500 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 3 (initialized at netbsd:if_initialize+0x1fe sys/net/if.c:757)
lock address : ffff9d8013e354c0
type : sleep/adaptive
initialized : netbsd:if_initialize+0x1fe
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 0xffff9d801408d500
last locked* : netbsd:htable_prefix_free+0xe1
unlocked : netbsd:lla_rt_output+0x7bb
owner/count : 0xffff9d801408d500 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 2381.3285 (syz-executor.1) @ 0xffff9d8012bb45c0, l_stat=3

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014043f40
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d8012bb45c0 last held: 0xffff9d8012bb45c0
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8012bb45c0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1477.2082 (syz-executor.3) @ 0xffff9d801408d0c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014057200
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 1 exclusive: 2
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d0c0 last held: 0xffff9d8012a6c480
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8012a6c480 flags : 0x0000000000000007
Turnstile:
=> 1 waiting readers: 0xffff9d8012bf6640
=> 2 waiting writers: 0xffff9d80126d7740 0xffff9d801408d0c0

****** LWP 1477.3126 (syz-executor.3) @ 0xffff9d8012bf6640, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014057200
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 1 exclusive: 2
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d8012bf6640 last held: 0xffff9d8012a6c480
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8012a6c480 flags : 0x0000000000000007
Turnstile:
=> 1 waiting readers: 0xffff9d8012bf6640
=> 2 waiting writers: 0xffff9d80126d7740 0xffff9d801408d0c0

****** LWP 1477.3124 (syz-executor.3) @ 0xffff9d80126d7740, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014057200
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 1 exclusive: 2
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d80126d7740 last held: 0xffff9d8012a6c480
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8012a6c480 flags : 0x0000000000000007
Turnstile:
=> 1 waiting readers: 0xffff9d8012bf6640
=> 2 waiting writers: 0xffff9d80126d7740 0xffff9d801408d0c0

****** LWP 1477.2855 (syz-executor.3) @ 0xffff9d8012a6c480, l_stat=3

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014057200
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 1 exclusive: 2
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d8012a6c480 last held: 0xffff9d8012a6c480
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8012a6c480 flags : 0x0000000000000007
Turnstile:
=> 1 waiting readers: 0xffff9d8012bf6640
=> 2 waiting writers: 0xffff9d80126d7740 0xffff9d801408d0c0

* Lock 1 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014052a40
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d8012a6c480 last held: 0xffff9d8012a6c480
last locked* : netbsd:genfs_lock+0x160
unlocked : 0
owner/count : 0xffff9d8012a6c480 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 2364.2364 (syz-executor.4) @ 0xffff9d8013dc0a40, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:uvm_km_bootstrap+0x13e sys/uvm/uvm_km.c:294)
lock address : netbsd:kernel_map_store+0x18
type : sleep/adaptive
initialized : netbsd:uvm_km_bootstrap+0x13e
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 0 last held: 1
relevant lwp : 0xffff9d8013dc0a40 last held: 000000000000000000
last locked : netbsd:uvm_map_pageable+0xb1f
unlocked* : netbsd:uvm_map_pageable+0xb40
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 3294.3294 (syz-executor.2) @ 0xffff9d8012b90580, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:kcov_open+0x40 sys/kern/subr_kcov.c:461)
lock address : ffff9d8013f8c940
type : sleep/adaptive
initialized : netbsd:kcov_open+0x40
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8012b90580 last held: 0xffff9d8012b90580
last locked* : netbsd:kcov_fops_ioctl+0x28
unlocked : 0
owner field : 0xffff9d8012b90580 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:uvm_obj_init+0x9a sys/uvm/uvm_object.c:70)
lock address : ffff9d8013f8cc40
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0x9a
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8012b90580 last held: 0xffff9d8012b90580
last locked* : netbsd:uvm_fault_internal+0x1e72
unlocked : netbsd:uvm_fault_lower_enter+0x579
owner/count : 0xffff9d8012b90580 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 2231.2231 (syz-executor.0) @ 0xffff9d8013fda080, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8012c58540
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8013fda080 last held: 0xffff9d8013fda080
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8013fda080 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1438)
lock address : ffff9d8014045200
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8013fda080 last held: 0xffff9d8013fda080
last locked* : netbsd:genfs_lock+0x160
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffff9d8013fda080 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 748.748 (dhcpcd) @ 0xffff9d8012cbd100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8012cbd100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 745.745 (dhcpcd) @ 0xffff9d8012c79780, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8012c79780 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 292.292 (dhcpcd) @ 0xffff9d8012d98900, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d8012d98900 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 485.485 (dhcpcd) @ 0xffff9d8012d984c0, l_stat=7

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8012d984c0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.26 (softclk/1) @ 0xffff9d8010cac240, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8010cac240 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffff9d800fb4a100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d800fb4a100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffff9d800fb32080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d800fb32080 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff83350200, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff83350200 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu0:

* Lock 0 (initialized at netbsd:main+0x11e sys/kern/init_main.c:304)
lock address : netbsd:kernel_lock
type : spin
initialized : netbsd:main+0x11e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 0xffff9d801408d500
last locked* : netbsd:sleepq_block+0x5d7
unlocked : netbsd:route_intr+0x158
curcpu holds : 3 wanted by: 000000000000000000

* Lock 1 (initialized at netbsd:kprintf_init+0x61 sys/kern/subr_prf.c:156)
lock address : netbsd:kprintf_mtx
type : spin
initialized : netbsd:kprintf_init+0x61
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801408d500 last held: 0xffff9d801408d500
last locked* : netbsd:kprintf_lock+0x33
unlocked : netbsd:kprintf_unlock+0x53
owner field : 0x0000000000000800 wait/spin: 0/1

PAGE FLAG PQ UOBJECT UANON
0xffff9d8000017180 0041 00000000 0x0 0x0
0xffff9d8000017200 0041 00000000 0x0 0x0
0xffff9d8000017280 0041 00000000 0x0 0x0
0xffff9d8000017300 0041 00000000 0x0 0x0
0xffff9d8000017380 0041 00000000 0x0 0x0
0xffff9d8000017400 0041 00000000 0x0 0x0
0xffff9d8000017480 0041 00000000 0x0 0x0
0xffff9d8000017500 0041 00000000 0x0 0x0
0xffff9d8000017580 0041 00000000 0x0 0x0
0xffff9d8000017600 0041 00000000 0x0 0x0
0xffff9d8000017680 0041 00000000 0x0 0x0
0xffff9d8000017700 0041 00000000 0x0 0x0
0xffff9d8000017780 0041 00000000 0x0 0x0
0xffff9d8000017800 0041 00000000 0x0 0x0
0xffff9d8000017880 0041 00000000 0x0 0x0
0xffff9d8000017900 0041 00000000 0x0 0x0
0xffff9d8000017980 0041 00000000 0x0 0x0
0xffff9d8000017a00 0041 00000000 0x0 0x0
0xffff9d8000017a80 0041 00000000 0x0 0x0
0xffff9d8000017b00 0041 00000000 0x0 0x0
0xffff9d8000017b80 0041 00000000 0x0 0x0
0xffff9d8000017c00 0041 00000000 0x0 0x0
0xffff9d8000017c80 0041 00000000 0x0 0x0
0xffff9d8000017d00 0041 00000000 0x0 0x0
0xffff9d8000017d80 0041 00000000 0x0 0x0
0xffff9d8000017e00 0041 00000000 0x0 0x0
0xffff9d8000017e80 0041 00000000 0x0 0x0
0xffff9d8000017f00 0041 00000000 0x0 0x0
0xffff9d8000017f80 0041 00000000 0x0 0x0
0xffff9d8000018000 0041 00000000 0x0 0x0
0xffff9d8000018080 0041 00000000 0x0 0x0
0xffff9d8000018100 0041 00000000 0x0 0x0
0xffff9d8000018180 0041 00000000 0x0 0x0
0xffff9d8000018200 0041 00000000 0x0 0x0
0xffff9d8000018280 0041 00000000 0x0 0x0
0xffff9d8000018300 0041 00000000 0x0 0x0
0xffff9d8000018380 0041 00000000 0x0 0x0
0xffff9d8000018400 0041 00000000 0x0 0x0
0xffff9d8000018480 0041 00000000 0x0 0x0
0xffff9d8000018500 0041 00000000 0x0 0x0
0xffff9d8000018580 0041 00000000 0x0 0x0
0xffff9d8000018600 0041 00000000 0x0 0x0
0xffff9d8000018680 0041 00000000 0x0 0x0
0xffff9d8000018700 0041 00000000 0x0 0x0
0xffff9d8000018780 0041 00000000 0x0 0x0
0xffff9d8000018800 0041 00000000 0x0 0x0
0xffff9d8000018880 0041 00000000 0x0 0x0
0xffff9d8000018900 0041 00000000 0x0 0x0
0xffff9d8000018980 0041 00000000 0x0 0x0
0xffff9d8000018a00 0041 00000000 0x0 0x0
0xffff9d8000018a80 0041 00000000 0x0 0x0
0xffff9d8000018b00 0041 00000000 0x0 0x0
0xffff9d8000018b80 0041 00000000 0x0 0x0
0xffff9d8000018c00 0041 00000000 0x0 0x0
0xffff9d8000018c80 0041 00000000 0x0 0x0
0xffff9d8000018d00 0041 00000000 0x0 0x0
0xffff9d8000018d80 0041 00000000 0x0 0x0
0xffff9d8000018e00 0041 00000000 0x0 0x0
0xffff9d8000018e80 0041 00000000 0x0 0x0
0xffff9d8000018f00 0041 00000000 0x0 0x0
0xffff9d8000018f80 0041 00000000 0x0 0x0
0xffff9d8000019000 0041 00000000 0x0 0x0
0xffff9d8000019080 0041 00000000 0x0 0x0
0xffff9d8000019100 0041 00000000 0x0 0x0
0xffff9d8000019180 0041 00000000 0x0 0x0
0xffff9d8000019200 0041 00000000 0x0 0x0
0xffff9d8000019280 0041 00000000 0x0 0x0
0xffff9d8000019300 0041 00000000 0x0 0x0
0xffff9d8000019380 0041 00000000 0x0 0x0
0xffff9d8000019400 0041 00000000 0x0 0x0
0xffff9d8000019480 0041 00000000 0x0 0x0
0xffff9d8000019500 0041 00000000 0x0 0x0
0xffff9d8000019580 0041 00000000 0x0 0x0
0xffff9d8000019600 0041 00000000 0x0 0x0
0xffff9d8000019680 0041 00000000 0x0 0x0
0xffff9d8000019700 0041 00000000 0x0 0x0
0xffff9d8000019780 0041 00000000 0x0 0x0
0xffff9d8000019800 0041 00000000 0x0 0x0
0xffff9d8000019880 0041 00000000 0x0 0x0
0xffff9d8000019900 0041 00000000 0x0 0x0
0xffff9d8000019980 0041 00000000 0x0 0x0
0xffff9d8000019a00 0041 00000000 0x0 0x0
0xffff9d8000019a80 0041 00000000 0x0 0x0
0xffff9d8000019b00 0041 00000000 0x0 0x0
0xffff9d8000019b80 0041 00000000 0x0 0x0
0xffff9d8000019c00 0041 00000000 0x0 0x0
0xffff9d8000019c80 0041 00000000 0x0 0x0
0xffff9d8000019d00 0041 00000000 0x0 0x0
0xffff9d8000019d80 0041 00000000 0x0 0x0
0xffff9d8000019e00 0041 00000000 0x0 0x0
0xffff9d8000019e80 0041 00000000 0x0 0x0
0xffff9d8000019f00 0041 00000000 0x0 0x0
0xffff9d8000019f80 0041 00000000 0x0 0x0
0xffff9d800001a000 0041 00000000 0x0 0x0
0xffff9d800001a080 0041 00000000 0x0 0x0
0xffff9d800001a100 0041 00000000 0x0 0x0
0xffff9d800001a180 0041 00000000 0x0 0x0
0xffff9d800001a200 0041 00000000 0x0 0x0
0xffff9d800001a280 0041 00000000 0x0 0x0
0xffff9d800001a300 0041 00000000 0x0 0x0
0xffff9d800001a380 0041 00000000 0x0 0x0
0xffff9d800001a400 0041 00000000 0x0 0x0
0xffff9d800001a480 0041 00000000 0x0 0x0
0xffff9d800001a500 0041 00000000 0x0 0x0
0xffff9d800001a580 0041 00000000 0x0 0x0
0xffff9d800001a600 0041 00000000 0x0 0x0
0xffff9d800001a680 0041 00000000 0x0 0x0
0xffff9d800001a700 0041 00000000 0x0 0x0
0xffff9d800001a780 0041 00000000 0x0 0x0
0xffff9d800001a800 0041 00000000 0x0 0x0
0xffff9d800001a880 0041 00000000 0x0 0x0
0xffff9d800001a900 0041 00000000 0x0 0x0
0xffff9d800001a980 0041 00000000 0x0 0x0
0xffff9d800001aa00 0041 00000000 0x0 0x0
0xffff9d800001aa80 0041 00000000 0x0 0x0
0xffff9d800001ab00 0041 00000000 0x0 0x0
0xffff9d800001ab80 0041 00000000 0x0 0x0
0xffff9d800001ac00 0041 00000000 0x0 0x0
0xffff9d800001ac80 0041 00000000 0x0 0x0
0xffff9d800001ad00 0041 00000000 0x0 0x0
0xffff9d800001ad80 0041 00000000 0x0 0x0
0xffff9d800001ae00 0041 00000000 0x0 0x0
0xffff9d800001ae80 0041 00000000 0x0 0x0
0xffff9d800001af00 0041 00000000 0x0 0x0
0xffff9d800001af80 0041 00000000 0x0 0x0
0xffff9d800001b000 0041 00000000 0x0 0x0
0xffff9d800001b080 0041 00000000 0x0 0x0
0xffff9d800001b100 0041 00000000 0x0 0x0
0xffff9d800001b180 0041 00000000 0x0 0x0
0xffff9d800001b200 0041 00000000 0x0 0x0
0xffff9d800001b280 0041 00000000 0x0 0x0
0xffff9d800001b300 0041 00000000 0x0 0x0
0xffff9d800001b380 0041 00000000 0x0 0x0
0xffff9d800001b400 0041 00000000 0x0 0x0
0xffff9d800001b480 0041 00000000 0x0 0x0
0xffff9d800001b500 0041 00000000 0x0 0x0
0xffff9d800001b580 0041 00000000 0x0 0x0
0xffff9d800001b600 0041 00000000 0x0 0x0
0xffff9d800001b680 0041 00000000 0x0 0x0
0xffff9d800001b700 0041 00000000 0x0 0x0
0xffff9d800001b780 0041 00000000 0x0 0x0
0xffff9d800001b800 0041 00000000 0x0 0x0
0xffff9d800001b880 0041 00000000 0x0 0x0
0xffff9d800001b900 0041 00000000 0x0 0x0
0xffff9d800001b980 0041 00000000 0x0 0x0
0xffff9d800001ba00 0041 00000000 0x0 0x0
0xffff9d800001ba80 0041 00000000 0x0 0x0
0xffff9d800001bb00 0001 00000000 0x0 0x0
0xffff9d800001bb80 0001 00000000 0x0 0x0
0xffff9d800001bc00 0001 00000000 0x0 0x0
0xffff9d800001bc80 0001 00000000 0x0 0x0
0xffff9d800001bd00 0001 00000000 0x0 0x0
0xffff9d800001bd80 0001 00000000 0x0 0x0
0xffff9d800001be00 0001 00000000 0x0 0x0
0xffff9d800001be80 0001 00000000 0x0 0x0
0xffff9d800001bf00 0001 00000000 0x0 0x0
0xffff9d800001bf80 0001 00000000 0x0 0x0
0xffff9d800001c000 0001 00000000 0x0 0x0
0xffff9d800001c080 0001 00000000 0x0 0x0
0xffff9d800001c100 0001 00000000 0x0 0x0
0xffff9d800001c180 0001 00000000 0x0 0x0
0xffff9d800001c200 0001 00000000 0x0 0x0
0xffff9d800001c280 0001 00000000 0x0 0x0
0xffff9d800001c300 0001 00000000 0x0 0x0
0xffff9d800001c380 0001 00000000 0x0 0x0
0xffff9d800001c400 0001 00000000 0x0 0x0
0xffff9d800001c480 0001 00000000 0x0 0x0
0xffff9d800001c500 0001 00000000 0x0 0x0
0xffff9d800001c580 0001 00000000 0x0 0x0
0xffff9d800001c600 0001 00000000 0x0 0x0
0xffff9d800001c680 0001 00000000 0x0 0x0
0xffff9d800001c700 0001 00000000 0x0 0x0
0xffff9d800001c780 0001 00000000 0x0 0x0
0xffff9d800001c800 0001 00000000 0x0 0x0
0xffff9d800001c880 0001 00000000 0x0 0x0
0xffff9d800001c900 0001 00000000 0x0 0x0
0xffff9d800001c980 0001 00000000 0x0 0x0
0xffff9d800001ca00 0001 00000000 0x0 0x0
0xffff9d800001ca80 0001 00000000 0x0 0x0
0xffff9d800001cb00 0001 00000000 0x0 0x0
0xffff9d800001cb80 0001 00000000 0x0 0x0
0xffff9d800001cc00 0001 00000000 0x0 0x0
0xffff9d800001cc80 0001 00000000 0x0 0x0
0xffff9d800001cd00 0001 00000000 0x0 0x0
0xffff9d800001cd80 0001 00000000 0x0 0x0
0xffff9d800001ce00 0001 00000000 0x0 0x0
0xffff9d800001ce80 0001 00000000 0x0 0x0
0xffff9d800001cf00 0001 00000000 0x0 0x0
0xffff9d800001cf80 0001 00000000 0x0 0x0
0xffff9d800001d000 0001 00000000 0x0 0x0
0xffff9d800001d080 0001 00000000 0x0 0x0
0xffff9d800001d100 0001 00000000 0x0 0x0
0xffff9d800001d180 0001 00000000 0x0 0x0
0xffff9d800001d200 0001 00000000 0x0 0x0
0xffff9d800001d280 0001 00000000 0x0 0x0
0xffff9d800001d300 0001 00000000 0x0 0x0
0xffff9d800001d380 0001 00000000 0x0 0x0
0xffff9d800001d400 0001 00000000 0x0 0x0
0xffff9d800001d480 0001 00000000 0x0 0x0
0xffff9d800001d500 0001 00000000 0x0 0x0
0xffff9d800001d580 0001 00000000 0x0 0x0
0xffff9d800001d600 0001 00000000 0x0 0x0
0xffff9d800001d680 0001 00000000 0x0 0x0
0xffff9d800001d700 0001 00000000 0x0 0x0
0xffff9d800001d780 0001 00000000 0x0 0x0
0xffff9d800001d800 0001 00000000 0x0 0x0
0xffff9d800001d880 0001 00000000 0x0 0x0
0xffff9d800001d900 0001 00000000 0x0 0x0
0xffff9d800001d980 0001 00000000 0x0 0x0
0xffff9d800001da00 0001 00000000 0x0 0x0
0xffff9d800001da80 0001 00000000 0x0 0x0
0xffff9d800001db00 0001 00000000 0x0 0x0
0xffff9d800001db80 0001 00000000 0x0 0x0
0xffff9d800001dc00 0001 00000000 0x0 0x0
0xffff9d800001dc80 0001 00000000 0x0 0x0
0xffff9d800001dd00 0001 00000000 0x0 0x0
0xffff9d800001dd80 0001 00000000 0x0 0x0
0xffff9d800001de00 0001 00000000 0x0 0x0
0xffff9d800001de80 0001 00000000 0x0 0x0
0xffff9d800001df00 0001 00000000 0x0 0x0
0xffff9d800001df80 0001 00000000 0x0 0x0
0xffff9d800001e000 0001 00000000 0x0 0x0
0xffff9d800001e080 0001 00000000 0x0 0x0
0xffff9d800001e100 0001 00000000 0x0 0x0
0xffff9d800001e180 0001 00000000 0x0 0x0
0xffff9d800001e200 0001 00000000 0x0 0x0
0xffff9d800001e280 0001 00000000 0x0 0x0
0xffff9d800001e300 0001 00000000 0x0 0x0
0xffff9d800001e380 0001 00000000 0x0 0x0
0xffff9d800001e400 0001 00000000 0x0 0x0
0xffff9d800001e480 0001 00000000 0x0 0x0
0xffff9d800001e500 0001 00000000 0x0 0x0
0xffff9d800001e580 0001 00000000 0x0 0x0
0xffff9d800001e600 0001 00000000 0x0 0x0
0xffff9d800001e680 0001 00000000 0x0 0x0
0xffff9d800001e700 0001 00000000 0x0 0x0
0xffff9d800001e780 0001 00000000 0x0 0x0
0xffff9d800001e800 0001 00000000 0x0 0x0
0xffff9d800001e880 0001 00000000 0x0 0x0
0xffff9d800001e900 0001 00000000 0x0 0x0
0xffff9d800001e980 0001 00000000 0x0 0x0
0xffff9d800001ea00 0001 00000000 0x0 0x0
0xffff9d800001ea80 0001 00000000 0x0 0x0
0xffff9d800001eb00 0001 00000000 0x0 0x0
0xffff9d800001eb80 0001 00000000 0x0 0x0
0xffff9d800001ec00 0001 00000000 0x0 0x0
0xffff9d800001ec80 0001 00000000 0x0 0x0
0xffff9d800001ed00 0001 00000000 0x0 0x0
0xffff9d800001ed80 0001 00000000 0x0 0x0
0xffff9d800001ee00 0001 00000000 0x0 0x0
0xffff9d800001ee80 0001 00000000 0x0 0x0
0xffff9d800001ef00 0001 00000000 0x0 0x0
0xffff9d800001ef80 0001 00000000 0x0 0x0
0xffff9d800001f000 0001 00000000 0x0 0x0
0xffff9d800001f080 0001 00000000 0x0 0x0
0xffff9d800001f100 0001 00000000 0x0 0x0
0xffff9d800001f180 0001 00000000 0x0 0x0
0xffff9d800001f200 0001 00000000 0x0 0x0
0xffff9d800001f280 0001 00000000 0x0 0x0
0xffff9d800001f300 0001 00000000 0x0 0x0
0xffff9d800001f380 0001 00000000 0x0 0x0
0xffff9d800001f400 0001 00000000 0x0 0x0
0xffff9d800001f480 0001 00000000 0x0 0x0
0xffff9d800001f500 0001 00000000 0x0 0x0
0xffff9d800001f580 0001 00000000 0x0 0x0
0xffff9d800001f600 0001 00000000 0x0 0x0
0xffff9d800001f680 0001 00000000 0x0 0x0
0xffff9d800001f700 0001 00000000 0x0 0x0
0xffff9d800001f780 0001 00000000 0x0 0x0
0xffff9d800001f800 0001 00000000 0x0 0x0
0xffff9d800001f880 0001 00000000 0x0 0x0
0xffff9d800001f900 0001 00000000 0x0 0x0
0xffff9d800001f980 0001 00000000 0x0 0x0
0xffff9d800001fa00 0001 00000000 0x0 0x0
0xffff9d800001fa80 0001 00000000 0x0 0x0
0xffff9d800001fb00 0001 00000000 0x0 0x0
0xffff9d800001fb80 0001 00000000 0x0 0x0
0xffff9d800001fc00 0001 00000000 0x0 0x0
0xffff9d800001fc80 0001 00000000 0x0 0x0
0xffff9d800001fd00 0001 00000000 0x0 0x0
0xffff9d800001fd80 0001 00000000 0x0 0x0
0xffff9d800001fe00 0001 00000000 0x0 0x0
0xffff9d800001fe80 0001 00000000 0x0 0x0
0xffff9d800001ff00 0001 00000000 0x0 0x0
0xffff9d800001ff80 0001 00000000 0x0 0x0
0xffff9d8000020000 0001 00000000 0x0 0x0
0xffff9d8000020080 0001 00000000 0x0 0x0
0xffff9d8000020100 0001 00000000 0x0 0x0
0xffff9d8000020180 0001 00000000 0x0 0x0
0xffff9d8000020200 0001 00000000 0x0 0x0
0xffff9d8000020280 0001 00000000 0x0 0x0
0xffff9d8000020300 0001 00000000 0x0 0x0
0xffff9d8000020380 0001 00000000 0x0 0x0
0xffff9d8000020400 0001 00000000 0x0 0x0
0xffff9d8000020480 0001 00000000 0x0 0x0
0xffff9d8000020500 0001 00000000 0x0 0x0
0xffff9d8000020580 0001 00000000 0x0 0x0
0xffff9d8000020600 0001 00000000 0x0 0x0
0xffff9d8000020680 0001 00000000 0x0 0x0
0xffff9d8000020700 0001 00000000 0x0 0x0
0xffff9d8000020780 0001 00000000 0x0 0x0
0xffff9d8000020800 0001 00000000 0x0 0x0
0xffff9d8000020880 0001 00000000 0x0 0x0
0xffff9d8000020900 0001 00000000 0x0 0x0
0xffff9d8000020980 0001 00000000 0x0 0x0
0xffff9d8000020a00 0001 00000000 0x0 0x0
0xffff9d8000020a80 0001 00000000 0x0 0x0
0xffff9d8000020b00 0001 00000000 0x0 0x0
0xffff9d8000020b80 0001 00000000 0x0 0x0
0xffff9d8000020c00 0001 00000000 0x0 0x0
0xffff9d8000020c80 0001 00000000 0x0 0x0
0xffff9d8000020d00 0001 00000000 0x0 0x0
0xffff9d8000020d80 0001 00000000 0x0 0x0
0xffff9d8000020e00 0001 00000000 0x0 0x0
0xffff9d8000020e80 0001 00000000 0x0 0x0
0xffff9d8000020f00 0001 00000000 0x0 0x0
0xffff9d8000020f80 0001 00000000 0x0 0x0
0xffff9d8000021000 0001 00000000 0x0 0x0
0xffff9d8000021080 0001 00000000 0x0 0x0
0xffff9d8000021100 0001 00000000 0x0 0x0
0xffff9d8000021180 0001 00000000 0x0 0x0
0xffff9d8000021200 0001 00000000 0x0 0x0
0xffff9d8000021280 0001 00000000 0x0 0x0
0xffff9d8000021300 0001 00000000 0x0 0x0
0xffff9d8000021380 0001 00000000 0x0 0x0
0xffff9d8000021400 0001 00000000 0x0 0x0
0xffff9d8000021480 0001 00000000 0x0 0x0
0xffff9d8000021500 0001 00000000 0x0 0x0
0xffff9d8000021580 0001 00000000 0x0 0x0
0xffff9d8000021600 0001 00000000 0x0 0x0
0xffff9d8000021680 0001 00000000 0x0 0x0
0xffff9d8000021700 0001 00000000 0x0 0x0
0xffff9d8000021780 0001 00000000 0x0 0x0
0xffff9d8000021800 0001 00000000 0x0 0x0
0xffff9d8000021880 0001 00000000 0x0 0x0
0xffff9d8000021900 0001 00000000 0x0 0x0
0xffff9d8000021980 0001 00000000 0x0 0x0
0xffff9d8000021a00 0001 00000000 0x0 0x0
0xffff9d8000021a80 0001 00000000 0x0 0x0
0xffff9d8000021b00 0001 00000000 0x0 0x0
0xffff9d8000021b80 0001 00000000 0x0 0x0
0xffff9d8000021c00 0001 00000000 0x0 0x0
0xffff9d8000021c80 0001 00000000 0x0 0x0
0xffff9d8000021d00 0001 00000000 0x0 0x0
0xffff9d8000021d80 0001 00000000 0x0 0x0
0xffff9d8000021e00 0001 00000000 0x0 0x0
0xffff9d8000021e80 0001 00000000 0x0 0x0
0xffff9d8000021f00 0001 00000000 0x0 0x0
0xffff9d8000021f80 0001 00000000 0x0 0x0
0xffff9d8000022000 0001 00000000 0x0 0x0
0xffff9d8000022080 0001 00000000 0x0 0x0
0xffff9d8000022100 0001 00000000 0x0 0x0
0xffff9d8000022180 0001 00000000 0x0 0x0
0xffff9d8000022200 0001 00000000 0x0 0x0
0xffff9d8000022280 0001 00000000 0x0 0x0
0xffff9d8000022300 0001 00000000 0x0 0x0
0xffff9d8000022380 0001 00000000 0x0 0x0
0xffff9d8000022400 0001 00000000 0x0 0x0
0xffff9d8000022480 0001 00000000 0x0 0x0
0xffff9d8000022500 0001 00000000 0x0 0x0
0xffff9d8000022580 0001 00000000 0x0 0x0
0xffff9d8000022600 0001 00000000 0x0 0x0
0xffff9d8000022680 0001 00000000 0x0 0x0
0xffff9d8000022700 0001 00000000 0x0 0x0
0xffff9d8000022780 0001 00000000 0x0 0x0
0xffff9d8000022800 0001 00000000 0x0 0x0
0xffff9d8000022880 0001 00000000 0x0 0x0
0xffff9d8000022900 0001 00000000 0x0 0x0
0xffff9d8000022980 0001 00000000 0x0 0x0
0xffff9d8000022a00 0001 00000000 0x0 0x0
0xffff9d8000022a80 0001 00000000 0x0 0x0
0xffff9d8000022b00 0001 00000000 0x0 0x0
0xffff9d8000022b80 0001 00000000 0x0 0x0
0xffff9d8000022c00 0001 00000000 0x0 0x0
0xffff9d8000022c80 0001 00000000 0x0 0x0
0xffff9d8000022d00 0001 00000000 0x0 0x0
0xffff9d8000022d80 0001 00000000 0x0 0x0
0xffff9d8000022e00 0001 00000000 0x0 0x0
0xffff9d8000022e80 0001 00000000 0x0 0x0
0xffff9d8000022f00 0001 00000000 0x0 0x0
0xffff9d8000022f80 0001 00000000 0x0 0x0
0xffff9d8000023000 0001 00000000 0x0 0x0
0xffff9d8000023080 0001 00000000 0x0 0x0
0xffff9d8000023100 0001 00000000 0x0 0x0
0xffff9d8000023180 0001 00000000 0x0 0x0
0xffff9d8000023200 0001 00000000 0x0 0x0
0xffff9d8000023280 0001 00000000 0x0 0x0
0xffff9d8000023300 0001 00000000 0x0 0x0
0xffff9d8000023380 0001 00000000 0x0 0x0
0xffff9d8000023400 0001 00000000 0x0 0x0
0xffff9d8000023480 0001 00000000 0x0 0x0
0xffff9d8000023500 0001 00000000 0x0 0x0
0xffff9d8000023580 0001 00000000 0x0 0x0
0xffff9d8000023600 0001 00000000 0x0 0x0
0xffff9d8000023680 0001 00000000 0x0 0x0
0xffff9d8000023700 0001 00000000 0x0 0x0
0xffff9d8000023780 0001 00000000 0x0 0x0
0xffff9d8000023800 0001 00000000 0x0 0x0
0xffff9d8000023880 0001 00000000 0x0 0x0
0xffff9d8000023900 0001 00000000 0x0 0x0
0xffff9d8000023980 0001 00000000 0x0 0x0
0xffff9d8000023a00 0001 00000000 0x0 0x0
0xffff9d8000023a80 0001 00000000 0x0 0x0
0xffff9d8000023b00 0001 00000000 0x0 0x0
0xffff9d8000023b80 0001 00000000 0x0 0x0
0xffff9d8000023c00 0001 00000000 0x0 0x0
0xffff9d8000023c80 0001 00000000 0x0 0x0
0xffff9d8000023d00 0001 00000000 0x0 0x0
0xffff9d8000023d80 0001 00000000 0x0 0x0
0xffff9d8000023e00 0001 00000000 0x0 0x0
0xffff9d8000023e80 0001 00000000 0x0 0x0
0xffff9d8000023f00 0001 00000000 0x0 0x0
0xffff9d8000023f80 0001 00000000 0x0 0x0
0xffff9d8000024000 0001 00000000 0x0 0x0
0xffff9d8000024080 0001 00000000 0x0 0x0
0xffff9d8000024100 0001 00000000 0x0 0x0
0xffff9d8000024180 0001 00000000 0x0 0x0
0xffff9d8000024200 0001 00000000 0x0 0x0
0xffff9d8000024280 0001 00000000 0x0 0x0
0xffff9d8000024300 0001 00000000 0x0 0x0
0xffff9d8000024380 0001 00000000 0x0 0x0
0xffff9d8000024400 0001 00000000 0x0 0x0
0xffff9d8000024480 0001 00000000 0x0 0x0
0xffff9d8000024500 0001 00000000 0x0 0x0
0xffff9d8000024580 0001 00000000 0x0 0x0
0xffff9d8000024600 0001 00000000 0x0 0x0
0xffff9d8000024680 0001 00000000 0x0 0x0
0xffff9d8000024700 0001 00000000 0x0 0x0
0xffff9d8000024780 0001 00000000 0x0 0x0
0xffff9d8000024800 0001 00000000 0x0 0x0
0xffff9d8000024880 0001 00000000 0x0 0x0
0xffff9d8000024900 0001 00000000 0x0 0x0
0xffff9d8000024980 0001 00000000 0x0 0x0
0xffff9d8000024a00 0001 00000000 0x0 0x0
0xffff9d8000024a80 0001 00000000 0x0 0x0
0xffff9d8000024b00 0001 00000000 0x0 0x0
0xffff9d8000024b80 0001 00000000 0x0 0x0
0xffff9d8000024c00 0001 00000000 0x0 0x0
0xffff9d8000024c80 0001 00000000 0x0 0x0
0xffff9d8000024d00 0001 00000000 0x0 0x0
0xffff9d8000024d80 0001 00000000 0x0 0x0
0xffff9d8000024e00 0001 00000000 0x0 0x0
0xffff9d8000024e80 0001 00000000 0x0 0x0
0xffff9d8000024f00 0001 00000000 0x0 0x0
0xffff9d8000024f80 0001 00000000 0x0 0x0
0xffff9d8000025000 0001 00000000 0x0 0x0
0xffff9d8000025080 0001 00000000 0x0 0x0
0xffff9d8000025100 0001 00000000 0x0 0x0
0xffff9d8000025180 0001 00000000 0x0 0x0
0xffff9d8000025200 0001 00000000 0x0 0x0
0xffff9d8000025280 0001 00000000 0x0 0x0
0xffff9d8000025300 0001 00000000 0x0 0x0
0xffff9d8000025380 0001 00000000 0x0 0x0
0xffff9d8000025400 0001 00000000 0x0 0x0
0xffff9d8000025480 0001 00000000 0x0 0x0
0xffff9d8000025500 0001 00000000 0x0 0x0
0xffff9d8000025580 0001 00000000 0x0 0x0
0xffff9d8000025600 0001 00000000 0x0 0x0
0xffff9d8000025680 0001 00000000 0x0 0x0
0xffff9d8000025700 0001 00000000 0x0 0x0
0xffff9d8000025780 0001 00000000 0x0 0x0
0xffff9d8000025800 0001 00000000 0x0 0x0
0xffff9d8000025880 0001 00000000 0x0 0x0
0xffff9d8000025900 0001 00000000 0x0 0x0
0xffff9d8000025980 0001 00000000 0x0 0x0
0xffff9d8000025a00 0001 00000000 0x0 0x0
0xffff9d8000025a80 0001 00000000 0x0 0x0
0xffff9d8000025b00 0001

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title

If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)

If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report

If you want to undo deduplication, reply with:
#syz undup
Reply all
Reply to author
Forward
0 new messages