panic: kernel diagnostic assertion "l->l_cpu == ci" failed: file "/syzkaller/managers/netbsd/kernel/sys/kern/kern_syn

0 views
Skip to first unread message

syzbot

unread,
Dec 9, 2019, 7:00:09 PM12/9/19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 79bebca3 sys/atomic.h for membar_*
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=160d7c82e00000
kernel config: https://syzkaller.appspot.com/x/.config?x=6e4d6bd2b8e377a2
dashboard link: https://syzkaller.appspot.com/bug?extid=f98e035a2b40aac0c548
compiler: g++ (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+f98e03...@syzkaller.appspotmail.com

[
1 69.5724874]
panic: kernel diagnostic assertion "l->l_cpu == ci" failed:
file "/syzkaller/managers /netbsd/kernel/sys/ kern/kern_synch.c", line 768
[ 169.5823481] cpu1: Begin traceback...
[ 169.6424023] vpanic() at netbsd:vpanic+0x241
sys/kern/subr_prf.c:336
[ 169.7926713] _GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
[ 169.9427941] mi_switch() at netbsd:mi_switch+0xbfd
sys/kern/kern_synch.c:768
[ 170.0829744] sleepq_block() at netbsd:sleepq_block+0x2b4
sys/kern/kern_sleepq.c:276
[ 170.2331755] kpause() at netbsd:kpause+0x1da sys/kern/kern_synch.c:235
[ 170.3633410] nanosleep1() at netbsd:nanosleep1+0x289
sys/kern/kern_time.c:355
[ 170.5135363] sys___nanosleep50() at netbsd:sys___nanosleep50+0xe5
sys/kern/kern_time.c:293
[ 170.6637312] syscall() at netbsd:syscall+0x559 sy_call
sys/sys/syscallvar.h:65 [inline]
[ 170.6637312] syscall() at netbsd:syscall+0x559 sy_invoke
sys/sys/syscallvar.h:94 [inline]
[ 170.6637312] syscall() at netbsd:syscall+0x559
sys/arch/x86/x86/syscall.c:138
[ 170.6937706] --- syscall (number 430) ---
[ 170.7538489] 75a3b8e42a1a:
[ 170.7538489] cpu1: End traceback...
[ 170.7538489] fatal breakpoint trap in supervisor mode
[ 170.7638599] trap type 1 code 0 rip 0xffffffff8021ccb5 cs 0x8 rflags
0x246 cr2 0x75a3b8e43b9a ilevel 0 rsp 0xffffdc816efd78c0
[ 170.7738773] curlwp 0xffffdc8013b39ac0 pid 631.1 lowest kstack
0xffffdc816efd02c0
Stopped in pid 631.1 (syz-executor.1) at netbsd:breakpoint+0x5:
leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xe9 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x241 sys/kern/subr_prf.c:336
_GLOBAL__sub_D_65535_0_cpu_configure() at
netbsd:_GLOBAL__sub_D_65535_0_cpu_configure
mi_switch() at netbsd:mi_switch+0xbfd sys/kern/kern_synch.c:768
sleepq_block() at netbsd:sleepq_block+0x2b4 sys/kern/kern_sleepq.c:276
kpause() at netbsd:kpause+0x1da sys/kern/kern_synch.c:235
nanosleep1() at netbsd:nanosleep1+0x289 sys/kern/kern_time.c:355
sys___nanosleep50() at netbsd:sys___nanosleep50+0xe5
sys/kern/kern_time.c:293
syscall() at netbsd:syscall+0x559 sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x559 sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x559 sys/arch/x86/x86/syscall.c:138
--- syscall (number 430) ---
75a3b8e42a1a:
ds 4000
es 2000
fs 78b0
gs 2fa7
rdi ffffdc800d92b458
rsi ffffdc8013b39da8
rbp ffffdc816efd78c0
rbx ffffdc816d892000
rdx 2
rcx ffffffff80282fa7 cpu_intr_p+0x6e
rax 0
r8 0
r9 ffffdc8013b39b87
r10 1ffffb9002767370
r11 10
r12 ffffdc816d8a4000
r13 ffffffff8219fa20 __func__.12445+0xd40
r14 ffffdc816efd7950
r15 ffffdc816d892060
rip ffffffff8021ccb5 breakpoint+0x5
cs 8
rflags 246
rsp ffffdc816efd78c0
ss 10
netbsd:breakpoint+0x5: leave
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
622 4 3 0 80 ffffdc80122d81c0 syz-executor.1 parked
173 1 3 1 10000000 ffffdc801229b580 syz-executor.5 tstile
395 6 2 0 100000 ffffdc80122e3620 syz-executor.1
395 5 2 1 100000 ffffdc801229b9c0 syz-executor.1
395 4 2 1 100000 ffffdc80122ac5a0 syz-executor.1
395 3 2 1 100000 ffffdc8012d34ba0 syz-executor.1
395 1 3 0 40004 ffffdc80122baa00 syz-executor.1 lwpwait
72 4 3 1 80 ffffdc8012165740 syz-executor.4 parked
647 5 3 0 80 ffffdc8013dee4e0 syz-executor.3 parked
646 4 3 1 80 ffffdc80121f04a0 syz-executor.3 parked
516 3 3 1 80 ffffdc8013dca8e0 syz-executor.4 parked
515 3 3 1 80 ffffdc8013dc48c0 syz-executor.3 parked
97 4 3 1 1100004 ffffdc80121f0060 syz-executor.4 vfork
97 3 3 1 1100004 ffffdc801213bb60 syz-executor.4 vfork
97 1 3 1 1000004 ffffdc80121c7bc0 syz-executor.4 lwpwait
623 3 3 0 80 ffffdc8013d91340 syz-executor.0 parked
601 5 3 0 80 ffffdc8013d69b60 syz-executor.2 parked
526 3 3 1 80 ffffdc8013d692e0 syz-executor.2 parked
363 5 3 0 1100004 ffffdc8013d83320 syz-executor.3 vfork
363 4 3 1 1100004 ffffdc8013d69720 syz-executor.3 vfork
363 3 3 0 1100004 ffffdc8011ee85e0 syz-executor.3 vfork
363 1 3 0 11000004 ffffdc8013d5b2c0 syz-executor.3 lwpwait
484 4 3 0 1000004 ffffdc8013d81300 syz-executor.0 lwpwait
484 3 3 0 11100004 ffffdc80121c7340 syz-executor.0 vfork
615 5 3 0 11100004 ffffdc8013d5bb40 syz-executor.2 vfork
615 3 3 1 11100004 ffffdc8013d426e0 syz-executor.2 vfork
615 1 3 0 11000004 ffffdc8013ca6b00 syz-executor.2 lwpwait
492 > 1 7 0 0 ffffdc8013ca6280 syz-executor.5
468 1 3 1 80 ffffdc8013c71ae0 syz-executor.3 wait
40 1 3 1 80 ffffdc8013c716a0 syz-executor.4 wait
41 1 3 1 80 ffffdc8013c71260 syz-executor.2 wait
631 > 1 7 1 0 ffffdc8013b39ac0 syz-executor.1
539 1 3 0 80 ffffdc8013b39680 syz-executor.0 wait
606 11 3 1 80 ffffdc8013b39240 syz-fuzzer parked
606 10 3 0 80 ffffdc8013b19aa0 syz-fuzzer parked
606 9 2 1 0 ffffdc80120b2b20 syz-fuzzer
606 8 3 0 80 ffffdc8013b19220 syz-fuzzer parked
606 7 3 0 80 ffffdc8012ddb980 syz-fuzzer parked
606 6 3 1 80 ffffdc8012ddb540 syz-fuzzer parked
606 5 3 1 80 ffffdc8012e055c0 syz-fuzzer parked
606 4 3 1 80 ffffdc801213b720 syz-fuzzer parked
606 3 3 1 80 ffffdc801213b2e0 syz-fuzzer parked
606 2 3 0 80 ffffdc8012e0f5e0 syz-fuzzer parked
606 1 3 0 80 ffffdc801217eba0 syz-fuzzer kqueue
541 1 3 0 80 ffffdc8011ee5a00 sshd select
415 1 3 1 80 ffffdc801200b680 getty nanoslp
614 1 3 0 80 ffffdc8012d50780 getty nanoslp
563 1 3 1 80 ffffdc80120b26e0 getty nanoslp
593 1 3 1 80 ffffdc80120b22a0 getty ttyraw
581 1 3 1 80 ffffdc8012e1d600 cron nanoslp
506 1 3 1 80 ffffdc801360aa80 inetd kqueue
476 1 3 1 80 ffffdc8012d7d4a0 sshd select
406 1 3 0 80 ffffdc8012304aa0 powerd kqueue
483 1 2 1 40000 ffffdc80122889a0 makemandb
344 1 3 0 80 ffffdc8012d8e900 syslogd kqueue
274 1 3 1 80 ffffdc8012304660 dhcpcd kqueue
234 1 3 1 80 ffffdc801220b920 dhcpcd kqueue
1 1 3 1 80 ffffdc801200b240 init wait
0 58 3 0 204 ffffdc801200bac0 physiod physiod
0 57 3 0 204 ffffdc8012054280 aiodoned aiodoned
0 56 2 1 200 ffffdc8012053ae0 ioflush
0 55 3 0 204 ffffdc80120536a0 pooldrain pooldrain
0 54 3 0 200 ffffdc8012053260 pgdaemon pgdaemon
0 51 2 1 200 ffffdc800f7ca9c0 npfgc-0
0 50 3 0 204 ffffdc8011ffdaa0 rt_free rt_free
0 49 3 0 204 ffffdc8011ffd660 unpgc unpgc
0 48 3 0 204 ffffdc8011ffd220 key_timehandler
key_timehandler
0 47 3 1 204 ffffdc8011ff5a80 icmp6_wqinput/1
icmp6_wqinput
0 46 3 0 204 ffffdc8011ff5640 icmp6_wqinput/0
icmp6_wqinput
0 45 3 0 204 ffffdc8011ff5200 nd6_timer nd6_timer
0 44 3 1 204 ffffdc8011f0ca60 carp6_wqinput/1
carp6_wqinput
0 43 3 0 204 ffffdc8011f0c620 carp6_wqinput/0
carp6_wqinput
0 42 3 1 204 ffffdc8011f0c1e0 carp_wqinput/1
carp_wqinput
0 41 3 0 204 ffffdc8011ef9a40 carp_wqinput/0
carp_wqinput
0 40 3 1 204 ffffdc8011ef9600 icmp_wqinput/1
icmp_wqinput
0 39 3 0 204 ffffdc8011ef91c0 icmp_wqinput/0
icmp_wqinput
0 38 2 1 200 ffffdc8011ee8a20 rt_timer
0 37 3 1 204 ffffdc8011ee81a0 vmem_rehash vmem_rehash
0 27 3 0 204 ffffdc800f7ca580 scsibus0 sccomp
0 26 3 0 200 ffffdc800f7ca140 pms0 pmsreset
0 25 3 1 204 ffffdc800f73c9a0 xcall/1 xcall
0 24 1 1 200 ffffdc800f73c560 softser/1
0 23 1 1 200 ffffdc800f73c120 softclk/1
0 22 1 1 200 ffffdc800f738980 softbio/1
0 21 1 1 200 ffffdc800f738540 softnet/1
0 20 1 1 201 ffffdc800f738100 idle/1
0 19 3 1 204 ffffdc800f66e960 lnxpwrwq lnxpwrwq
0 18 3 1 204 ffffdc800f66e520 lnxlngwq lnxlngwq
0 17 3 0 204 ffffdc800f66e0e0 lnxsyswq lnxsyswq
0 16 3 0 204 ffffdc800de53940 lnxrcugc lnxrcugc
0 15 3 0 204 ffffdc800de53500 sysmon smtaskq
0 14 3 1 204 ffffdc800de530c0 pmfsuspend pmfsuspend
0 13 3 0 204 ffffdc800de44920 pmfevent pmfevent
0 12 3 0 204 ffffdc800de444e0 sopendfree sopendfr
0 11 3 1 204 ffffdc800de440a0 nfssilly nfssilly
0 10 2 1 200 ffffdc800de38900 cachegc
0 9 3 1 204 ffffdc800de384c0 vdrain vdrain
0 8 3 0 200 ffffdc800de38080 modunload mod_unld
0 7 3 0 204 ffffdc800de298e0 xcall/0 xcall
0 6 1 0 200 ffffdc800de294a0 softser/0
0 5 1 0 200 ffffdc800de29060 softclk/0
0 4 1 0 200 ffffdc800de258c0 softbio/0
0 3 1 0 200 ffffdc800de25480 softnet/0
0 2 1 0 201 ffffdc800de25040 idle/0
0 1 2 1 200 ffffffff82b63620 swapper
[Locks tracked through LWPs]
Locks held by an LWP (syz-executor.1):
Lock 0 (initialized at uvm_obj_init)
lock address : 0xffffdc8013afd140 type : sleep/adaptive
initialized : 0xffffffff810ea7f3
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
current cpu : 1 last held: 0
current lwp : 0xffffdc8013b39ac0 last held: 0xffffdc80122d81c0
last locked* : 0xffffffff810cecc4 unlocked : 0xffffffff810df0bf
owner field : 000000000000000000 wait/spin: 0/0

Turnstile chain at 0xffffffff82d83e68 with mutex 0xffffdc800de1c340.
=> Turnstile at 0xffffdc8012243180 (wrq=0xffffdc80122431a0,
rdq=0xffffdc80122431b0).
=> 0 waiting readers:
=> 1 waiting writers: 0xffffdc801229b580

Locks held by an LWP (syz-executor.5):
Lock 0 (initialized at fork1)
lock address : 0xffffdc8012141380 type : sleep/adaptive
initialized : 0xffffffff8113fa3c
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xffffdc8013b39ac0 last held: 0xffffdc801229b580
last locked* : 0xffffffff8113c12d unlocked : 0xffffffff811339a1
owner/count : 0xffffdc801229b580 flags : 0x0000000000000004

Turnstile chain at 0xffffffff82d83eb0 with mutex 0xffffdc800de1c580.
=> No active turnstile for this lock.

Locks held by an LWP (syz-executor.1):
Lock 0 (initialized at uvm_obj_init)
lock address : 0xffffdc8013c6cf00 type : sleep/adaptive
initialized : 0xffffffff810ea7f3
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xffffdc8013b39ac0 last held: 0xffffdc80122baa00
last locked* : 0xffffffff810cecc4 unlocked : 0xffffffff810cbb5c
owner field : 000000000000000000 wait/spin: 0/0

Turnstile chain at 0xffffffff82d83e20 with mutex 0xffffdc800de1c100.
=> No active turnstile for this lock.


[Locks tracked through CPUs]
Locks held on CPU 0:
Lock 0 (initialized at main)
lock address : 0xffffffff82d7e840 type : spin
initialized : 0xffffffff81a242e6
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 1
current cpu : 1 last held: 0
current lwp : 0xffffdc8013b39ac0 last held: 0xffffdc800de294a0
last locked* : 0xffffffff8026764c unlocked : 0xffffffff802a133c
curcpu holds : 0 wanted by: 000000000000000000

Lock 1 (initialized at dk_attach)
lock address : 0xffffdc8011eeb120 type : spin
initialized : 0xffffffff812e63f6
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 0
current lwp : 0xffffdc8013b39ac0 last held: 0xffffdc800de294a0
last locked* : 0xffffffff812e616b unlocked : 0xffffffff812e68db
owner field : 0x0000000000000600 wait/spin: 0/1

Lock 2 (initialized at com_attach_subr)
lock address : 0xffffdc8011e92888 type : spin
initialized : 0xffffffff80a07b8d
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 0
current lwp : 0xffffdc8013b39ac0 last held: 0xffffdc800de294a0
last locked* : 0xffffffff80a05c87 unlocked : 0xffffffff80a06102
owner field : 0x0000000000000800 wait/spin: 0/1


PAGE FLAG PQ UOBJECT UANON
0xffffdc8000014180 0048 0000 0x0 0x0
0xffffdc80000141f8 0048 0000 0x0 0x0
0xffffdc8000014270 0048 0000 0x0 0x0
0xffffdc80000142e8 0048 0000 0x0 0x0
0xffffdc8000014360 0048 0000 0x0 0x0
0xffffdc80000143d8 0048 0000 0x0 0x0
0xffffdc8000014450 0040 0000 0x0 0x0
0xffffdc80000144c8 0048 0000 0x0 0x0
0xffffdc8000014540 0040 0000 0x0 0x0
0xffffdc80000145b8 0048 0000 0x0 0x0
0xffffdc8000014630 0048 0000 0x0 0x0
0xffffdc80000146a8 0048 0000 0x0 0x0
0xffffdc8000014720 0048 0000 0x0 0x0
0xffffdc8000014798 0048 0000 0x0 0x0
0xffffdc8000014810 0048 0000 0x0 0x0
0xffffdc8000014888 0040 0000 0x0 0x0
0xffffdc8000014900 0048 0000 0x0 0x0
0xffffdc8000014978 0040 0000 0x0 0x0
0xffffdc80000149f0 0040 0000 0x0 0x0
0xffffdc8000014a68 0040 0000 0x0 0x0
0xffffdc8000014ae0 0040 0000 0x0 0x0
0xffffdc8000014b58 0040 0000 0x0 0x0
0xffffdc8000014bd0 0040 0000 0x0 0x0
0xffffdc8000014c48 0048 0000 0x0 0x0
0xffffdc8000014cc0 0048 0000 0x0 0x0
0xffffdc8000014d38 0048 0000 0x0 0x0
0xffffdc8000014db0 0048 0000 0x0 0x0
0xffffdc8000014e28 0048 0000 0x0 0x0
0xffffdc8000014ea0 0048 0000 0x0 0x0
0xffffdc8000014f18 0048 0000 0x0 0x0
0xffffdc8000014f90 0048 0000 0x0 0x0
0xffffdc8000015008 0048 0000 0x0 0x0
0xffffdc8000015080 0048 0000 0x0 0x0
0xffffdc80000150f8 0048 0000 0x0 0x0
0xffffdc8000015170 0048 0000 0x0 0x0
0xffffdc80000151e8 0048 0000 0x0 0x0
0xffffdc8000015260 0048 0000 0x0 0x0
0xffffdc80000152d8 0048 0000 0x0 0x0
0xffffdc8000015350 0048 0000 0x0 0x0
0xffffdc80000153c8 0048 0000 0x0 0x0
0xffffdc8000015440 0048 0000 0x0 0x0
0xffffdc80000154b8 0048 0000 0x0 0x0
0xffffdc8000015530 0048 0000 0x0 0x0
0xffffdc80000155a8 0048 0000 0x0 0x0
0xffffdc8000015620 0048 0000 0x0 0x0
0xffffdc8000015698 0048 0000 0x0 0x0
0xffffdc8000015710 0048 0000 0x0 0x0
0xffffdc8000015788 0048 0000 0x0 0x0
0xffffdc8000015800 0048 0000 0x0 0x0
0xffffdc8000015878 0048 0000 0x0 0x0
0xffffdc80000158f0 0048 0000 0x0 0x0
0xffffdc8000015968 0048 0000 0x0 0x0
0xffffdc80000159e0 0048 0000 0x0 0x0
0xffffdc8000015a58 0048 0000 0x0 0x0
0xffffdc8000015ad0 0048 0000 0x0 0x0
0xffffdc8000015b48 0048 0000 0x0 0x0
0xffffdc8000015bc0 0048 0000 0x0 0x0
0xffffdc8000015c38 0048 0000 0x0 0x0
0xffffdc8000015cb0 0048 0000 0x0 0x0
0xffffdc8000015d28 0048 0000 0x0 0x0
0xffffdc8000015da0 0048 0000 0x0 0x0
0xffffdc8000015e18 0048 0000 0x0 0x0
0xffffdc8000015e90 0048 0000 0x0 0x0
0xffffdc8000015f08 0048 0000 0x0 0x0
0xffffdc8000015f80 0048 0000 0x0 0x0
0xffffdc8000015ff8 0048 0000 0x0 0x0
0xffffdc8000016070 0048 0000 0x0 0x0
0xffffdc80000160e8 0040 0000 0x0 0x0
0xffffdc8000016160 0041 0000 0x0 0x0
0xffffdc80000161d8 0041 0000 0x0 0x0
0xffffdc8000016250 0048 0000 0x0 0x0
0xffffdc80000162c8 0048 0000 0x0 0x0
0xffffdc8000016340 0048 0000 0x0 0x0
0xffffdc80000163b8 0048 0000 0x0 0x0
0xffffdc8000016430 0040 0000 0x0 0x0
0xffffdc80000164a8 0041 0000 0x0 0x0
0xffffdc8000016520 0041 0000 0x0 0x0
0xffffdc8000016598 0041 0000 0x0 0x0
0xffffdc8000016610 0048 0000 0x0 0x0
0xffffdc8000016688 0040 0000 0x0 0x0
0xffffdc8000016700 0040 0000 0x0 0x0
0xffffdc8000016778 0048 0000 0x0 0x0
0xffffdc80000167f0 0041 0000 0x0 0x0
0xffffdc8000016868 0041 0000 0x0 0x0
0xffffdc80000168e0 0048 0000 0x0 0x0
0xffffdc8000016958 0048 0000 0x0 0x0
0xffffdc80000169d0 0041 0000 0x0 0x0
0xffffdc8000016a48 0041 0000 0x0 0x0
0xffffdc8000016ac0 0041 0000 0x0 0x0
0xffffdc8000016b38 0040 0000 0x0 0x0
0xffffdc8000016bb0 0041 0000 0x0 0x0
0xffffdc8000016c28 0048 0000 0x0 0x0
0xffffdc8000016ca0 0048 0000 0x0 0x0
0xffffdc8000016d18 0048 0000 0x0 0x0
0xffffdc8000016d90 0041 0000 0x0 0x0
0xffffdc8000016e08 0041 0000 0x0 0x0
0xffffdc8000016e80 0041 0000 0x0 0x0
0xffffdc8000016ef8 0041 0000 0x0 0x0
0xffffdc8000016f70 0048 0000 0x0 0x0
0xffffdc8000016fe8 0048 0000 0x0 0x0
0xffffdc8000017060 0048 0000 0x0 0x0
0xffffdc80000170d8 0048 0000 0x0 0x0
0xffffdc8000017150 0048 0000 0x0 0x0
0xffffdc80000171c8 0048 0000 0x0 0x0
0xffffdc8000017240 0048 0000 0x0 0x0
0xffffdc80000172b8 0041 0000 0x0 0x0
0xffffdc8000017330 0048 0000 0x0 0x0
0xffffdc80000173a8 0048 0000 0x0 0x0
0xffffdc8000017420 0048 0000 0x0 0x0
0xffffdc8000017498 0048 0000 0x0 0x0
0xffffdc8000017510 0048 0000 0x0 0x0
0xffffdc8000017588 0048 0000 0x0 0x0
0xffffdc8000017600 0048 0000 0x0 0x0
0xffffdc8000017678 0048 0000 0x0 0x0
0xffffdc80000176f0 0048 0000 0x0 0x0
0xffffdc8000017768 0048 0000 0x0 0x0
0xffffdc80000177e0 0048 0000 0x0 0x0
0xffffdc8000017858 0048 0000 0x0 0x0
0xffffdc80000178d0 0048 0000 0x0 0x0
0xffffdc8000017948 0048 0000 0x0 0x0
0xffffdc80000179c0 0048 0000 0x0 0x0
0xffffdc8000017a38 0048 0000 0x0 0x0
0xffffdc8000017ab0 0048 0000 0x0 0x0
0xffffdc8000017b28 0048 0000 0x0 0x0
0xffffdc8000017ba0 0048 0000 0x0 0x0
0xffffdc8000017c18 0048 0000 0x0 0x0
0xffffdc8000017c90 0048 0000 0x0 0x0
0xffffdc8000017d08 0048 0000 0x0 0x0
0xffffdc8000017d80 0048 0000 0x0 0x0
0xffffdc8000017df8 0048 0000 0x0 0x0
0xffffdc8000017e70 0048 0000 0x0 0x0
0xffffdc8000017ee8 0048 0000 0x0 0x0
0xffffdc8000017f60 0048 0000 0x0 0x0
0xffffdc8000017fd8 0048 0000 0x0 0x0
0xffffdc8000018050 0048 0000 0x0 0x0
0xffffdc80000180c8 0048 0000 0x0 0x0
0xffffdc8000018140 0048 0000 0x0 0x0
0xffffdc80000181b8 0048 0000 0x0 0x0
0xffffdc8000018230 0048 0000 0x0 0x0
0xffffdc80000182a8 0048 0000 0x0 0x0
0xffffdc8000018320 0048 0000 0x0 0x0
0xffffdc8000018398 0048 0000 0x0 0x0
0xffffdc8000018410 0048 0000 0x0 0x0
0xffffdc8000018488 0048 0000 0x0 0x0
0xffffdc8000018500 0048 0000 0x0 0x0
0xffffdc8000018578 0048 0000 0x0 0x0
0xffffdc80000185f0 0048 0000 0x0 0x0
0xffffdc8000018668 0048 0000 0x0 0x0
0xffffdc80000186e0 0048 0000 0x0 0x0
0xffffdc8000018758 0048 0000 0x0 0x0
0xffffdc80000187d0 0048 0000 0x0 0x0
0xffffdc8000018848 0048 0000 0x0 0x0
0xffffdc80000188c0 0048 0000 0x0 0x0
0xffffdc8000018938 0048 0000 0x0 0x0
0xffffdc80000189b0 0048 0000 0x0 0x0
0xffffdc8000018a28 0048 0000 0x0 0x0
0xffffdc8000018aa0 0048 0000 0x0 0x0
0xffffdc8000018b18 0048 0000 0x0 0x0
0xffffdc8000018b90 0048 0000 0x0 0x0
0xffffdc8000018c08 0048 0000 0x0 0x0
0xffffdc8000018c80 0048 0000 0x0 0x0
0xffffdc8000018cf8 0048 0000 0x0 0x0
0xffffdc8000018d70 0048 0000 0x0 0x0
0xffffdc8000018de8 0048 0000 0x0 0x0
0xffffdc8000018e60 0048 0000 0x0 0x0
0xffffdc8000018ed8 0048 0000 0x0 0x0
0xffffdc8000018f50 0048 0000 0x0 0x0
0xffffdc8000018fc8 0048 0000 0x0 0x0
0xffffdc8000019040 0048 0000 0x0 0x0
0xffffdc80000190b8 0048 0000 0x0 0x0
0xffffdc8000019130 0048 0000 0x0 0x0
0xffffdc80000191a8 0048 0000 0x0 0x0
0xffffdc8000019220 0048 0000 0x0 0x0
0xffffdc8000019298 0048 0000 0x0 0x0
0xffffdc8000019310 0048 0000 0x0 0x0
0xffffdc8000019388 0048 0000 0x0 0x0
0xffffdc8000019400 0048 0000 0x0 0x0
0xffffdc8000019478 0048 0000 0x0 0x0
0xffffdc80000194f0 0048 0000 0x0 0x0
0xffffdc8000019568 0048 0000 0x0 0x0
0xffffdc80000195e0 0048 0000 0x0 0x0
0xffffdc8000019658 0048 0000 0x0 0x0
0xffffdc80000196d0 0048 0000 0x0 0x0
0xffffdc8000019748 0048 0000 0x0 0x0
0xffffdc80000197c0 0048 0000 0x0 0x0
0xffffdc8000019838 0048 0000 0x0 0x0
0xffffdc80000198b0 0048 0000 0x0 0x0
0xffffdc8000019928 0048 0000 0x0 0x0
0xffffdc80000199a0 0048 0000 0x0 0x0
0xffffdc8000019a18 0048 0000 0x0 0x0
0xffffdc8000019a90 0048 0000 0x0 0x0
0xffffdc8000019b08 0048 0000 0x0 0x0
0xffffdc8000019b80 0048 0000 0x0 0x0
0xffffdc8000019bf8 0048 0000 0x0 0x0
0xffffdc8000019c70 0048 0000 0x0 0x0
0xffffdc8000019ce8 0048 0000 0x0 0x0
0xffffdc8000019d60 0048 0000 0x0 0x0
0xffffdc8000019dd8 0048 0000 0x0 0x0
0xffffdc8000019e50 0048 0000 0x0 0x0
0xffffdc8000019ec8 0048 0000 0x0 0x0
0xffffdc8000019f40 0048 0000 0x0 0x0
0xffffdc8000019fb8 0048 0000 0x0 0x0
0xffffdc800001a030 0048 0000 0x0 0x0
0xffffdc800001a0a8 0048 0000 0x0 0x0
0xffffdc800001a120 0048 0000 0x0 0x0
0xffffdc800001a198 0048 0000 0x0 0x0
0xffffdc800001a210 0048 0000 0x0 0x0
0xffffdc800001a288 0048 0000 0x0 0x0
0xffffdc800001a300 0048 0000 0x0 0x0
0xffffdc800001a378 0048 0000 0x0 0x0
0xffffdc800001a3f0 0048 0000 0x0 0x0
0xffffdc800001a468 0048 0000 0x0 0x0
0xffffdc800001a4e0 0048 0000 0x0 0x0
0xffffdc800001a558 0048 0000 0x0 0x0
0xffffdc800001a5d0 0048 0000 0x0 0x0
0xffffdc800001a648 0048 0000 0x0 0x0
0xffffdc800001a6c0 0048 0000 0x0 0x0
0xffffdc800001a738 0048 0000 0x0 0x0
0xffffdc800001a7b0 0048 0000 0x0 0x0
0xffffdc800001a828 0048 0000 0x0 0x0
0xffffdc800001a8a0 0048 0000 0x0 0x0
0xffffdc800001a918 0048 0000 0x0 0x0
0xffffdc800001a990 0048 0000 0x0 0x0
0xffffdc800001aa08 0048 0000 0x0 0x0
0xffffdc800001aa80 0048 0000 0x0 0x0
0xffffdc800001aaf8 0048 0000 0x0 0x0
0xffffdc800001ab70 0048 0000 0x0 0x0
0xffffdc800001abe8 0048 0000 0x0 0x0
0xffffdc800001ac60 0048 0000 0x0 0x0
0xffffdc800001acd8 0048 0000 0x0 0x0
0xffffdc800001ad50 0048 0000 0x0 0x0
0xffffdc800001adc8 0048 0000 0x0 0x0
0xffffdc800001ae40 0048 0000 0x0 0x0
0xffffdc800001aeb8 0048 0000 0x0 0x0
0xffffdc800001af30 0008 0000 0x0 0x0
0xffffdc800001afa8 0008 0000 0x0 0x0
0xffffdc800001b020 0008 0000 0x0 0x0
0xffffdc800001b098 0008 0000 0x0 0x0
0xffffdc800001b110 0008 0000 0x0 0x0
0xffffdc800001b188 0008 0000 0x0 0x0
0xffffdc800001b200 0008 0000 0x0 0x0
0xffffdc800001b278 0008 0000 0x0 0x0
0xffffdc800001b2f0 0008 0000 0x0 0x0
0xffffdc800001b368 0008 0000 0x0 0x0
0xffffdc800001b3e0 0008 0000 0x0 0x0
0xffffdc800001b458 0008 0000 0x0 0x0
0xffffdc800001b4d0 0008 0000 0x0 0x0
0xffffdc800001b548 0008 0000 0x0 0x0
0xffffdc800001b5c0 0008 0000 0x0 0x0
0xffffdc800001b638 0008 0000 0x0 0x0
0xffffdc800001b6b0 0008 0000 0x0 0x0
0xffffdc800001b728 0008 0000 0x0 0x0
0xffffdc800001b7a0 0008 0000 0x0 0x0
0xffffdc800001b818 0008 0000 0x0 0x0
0xffffdc800001b890 0008 0000 0x0 0x0
0xffffdc800001b908 0008 0000 0x0 0x0
0xffffdc800001b980 0008 0000 0x0 0x0
0xffffdc800001b9f8 0008 0000 0x0 0x0
0xffffdc800001ba70 0008 0000 0x0 0x0
0xffffdc800001bae8 0008 0000 0x0 0x0
0xffffdc800001bb60 0008 0000 0x0 0x0
0xffffdc800001bbd8 0008 0000 0x0 0x0
0xffffdc800001bc50 0008 0000 0x0 0x0
0xffffdc800001bcc8 0008 0000 0x0 0x0
0xffffdc800001bd40 0008 0000 0x0 0x0
0xffffdc800001bdb8 0008 0000 0x0 0x0
0xffffdc800001be30 0008 0000 0x0 0x0
0xffffdc800001bea8 0008 0000 0x0 0x0
0xffffdc800001bf20 0008 0000 0x0 0x0
0xffffdc800001bf98 0008 0000 0x0 0x0
0xffffdc800001c010 0008 0000 0x0 0x0
0xffffdc800001c088 0008 0000 0x0 0x0
0xffffdc800001c100 0008 0000 0x0 0x0
0xffffdc800001c178 0008 0000 0x0 0x0
0xffffdc800001c1f0 0008 0000 0x0 0x0
0xffffdc800001c268 0008 0000 0x0 0x0
0xffffdc800001c2e0 0008 0000 0x0 0x0
0xffffdc800001c358 0008 0000 0x0 0x0
0xffffdc800001c3d0 0008 0000 0x0 0x0
0xffffdc800001c448 0008 0000 0x0 0x0
0xffffdc800001c4c0 0008 0000 0x0 0x0
0xffffdc800001c538 0008 0000 0x0 0x0
0xffffdc800001c5b0 0008 0000 0x0 0x0
0xffffdc800001c628 0008 0000 0x0 0x0
0xffffdc800001c6a0 0008 0000 0x0 0x0
0xffffdc800001c718 0008 0000 0x0 0x0
0xffffdc800001c790 0008 0000 0x0 0x0
0xffffdc800001c808 0008 0000 0x0 0x0
0xffffdc800001c880 0048 0000 0x0 0x0
0xffffdc800001c8f8 0048 0000 0x0 0x0
0xffffdc800001c970 0048 0000 0x0 0x0
0xffffdc800001c9e8 0048 0000 0x0 0x0
0xffffdc800001ca60 0048 0000 0x0 0x0
0xffffdc800001cad8 0048 0000 0x0 0x0
0xffffdc800001cb50 0048 0000 0x0 0x0
0xffffdc800001cbc8 0048 0000 0x0 0x0
0xffffdc800001cc40 0048 0000 0x0 0x0
0xffffdc800001ccb8 0048 0000 0x0 0x0
0xffffdc800001cd30 0048 0000 0x0 0x0
0xffffdc800001cda8 0048 0000 0x0 0x0
0xffffdc800001ce20 0048 0000 0x0 0x0
0xffffdc800001ce98 0048 0000 0x0 0x0
0xffffdc800001cf10 0048 0000 0x0 0x0
0xffffdc800001cf88 0048 0000 0x0 0x0
0xffffdc800001d000 0048 0000 0x0 0x0
0xffffdc800001d078 0048 0000 0x0 0x0
0xffffdc800001d0f0 0048 0000 0x0 0x0
0xffffdc800001d168 0048 0000 0x0 0x0
0xffffdc800001d1e0 0048 0000 0x0 0x0
0xffffdc800001d258 0048 0000 0x0 0x0
0xffffdc800001d2d0 0048 0000 0x0 0x0
0xffffdc800001d348 0048 0000 0x0 0x0
0xffffdc800001d3c0 0048 0000 0x0 0x0
0xffffdc800001d438 0048 0000 0x0 0x0
0xffffdc800001d4b0 0048 0000 0x0 0x0
0xffffdc800001d528 0048 0000 0x0 0x0
0xffffdc800001d5a0 0048 0000 0x0 0x0
0xffffdc800001d618 0048 0000 0x0 0x0
0xffffdc800001d690 0048 0000 0x0 0x0
0xffffdc800001d708 0048 0000 0x0 0x0
0xffffdc800001d780 0048 0000 0x0 0x0
0xffffdc800001d7f8 0048 0000 0x0 0x0
0xffffdc800001d870 0048 0000 0x0 0x0
0xffffdc800001d8e8 0048 0000 0x0 0x0
0xffffdc800001d960 0048 0000 0x0 0x0
0xffffdc800001d9d8 0048 0000 0x0 0x0
0xffffdc800001da50 0048 0000 0x0 0x0
0xffffdc800001dac8 0048 0000 0x0 0x0
0xffffdc800001db40 0048 0000 0x0 0x0
0xffffdc800001dbb8 0048 0000 0x0 0x0
0xffffdc800001dc30 0008 0000 0x0 0x0
0xffffdc800001dca8 0008 0000 0x0 0x0
0xffffdc800001dd20 0008 0000 0x0 0x0
0xffffdc800001dd98 0008 0000 0x0 0x0
0xffffdc800001de10 0008 0000 0x0 0x0
0xffffdc800001de88 0008 0000 0x0 0x0
0xffffdc800001df00 0008 0000 0x0 0x0
0xffffdc800001df78 0008 0000 0x0 0x0
0xffffdc800001dff0 0008 0000 0x0 0x0
0xffffdc800001e068 0008 0000 0x0 0x0
0xffffdc800001e0e0 0008 0000 0x0 0x0
0xffffdc800001e158 0008 0000 0x0 0x0
0xffffdc800001e1d0 0008 0000 0x0 0x0
0xffffdc800001e248 0008 0000 0x0 0x0
0xffffdc800001e2c0 0008 0000 0x0 0x0
0xffffdc800001e338 0008 0000 0x0 0x0
0xffffdc800001e3b0 0008 0000 0x0 0x0
0xffffdc800001e428 0008 0000 0x0 0x0
0xffffdc800001e4a0 0008 0000 0x0 0x0
0xffffdc800001e518 0008 0000 0x0 0x0
0xffffdc800001e590 0008 0000 0x0 0x0
0xffffdc800001e608 0008 0000 0x0 0x0
0xffffdc800001e680 0008 0000 0x0 0x0
0xffffdc800001e6f8 0008 0000 0x0 0x0
0xffffdc800001e770 0008 0000 0x0 0x0
0xffffdc800001e7e8 0008 0000 0x0 0x0
0xffffdc800001e860 0008 0000 0x0 0x0
0xffffdc800001e8d8 0008 0000 0x0 0x0
0xffffdc800001e950 0008 0000 0x0 0x0
0xffffdc800001e9c8 0008 0000 0x0 0x0
0xffffdc800001ea40 0008 0000 0x0 0x0
0xffffdc800001eab8 0008 0000 0x0 0x0
0xffffdc800001eb30 0008 0000 0x0 0x0
0xffffdc800001eba8 0008 0000 0x0 0x0
0xffffdc800001ec20 0008 0000 0x0 0x0
0xffffdc800001ec98 0008 0000 0x0 0x0
0xffffdc800001ed10 0008 0000 0x0 0x0
0xffffdc800001ed88 0008 0000 0x0 0x0
0xffffdc800001ee00 0008 0000 0x0 0x0
0xffffdc800001ee78 0008 0000 0x0 0x0
0xffffdc800001eef0 0008 0000 0x0 0x0
0xffffdc800001ef68 0008 0000 0x0 0x0
0xffffdc800001efe0 0008 0000 0x0 0x0
0xffffdc800001f058 0008 0000 0x0 0x0
0xffffdc800001f0d0 0008 0000 0x0 0x0
0xffffdc800001f148 0008 0000 0x0 0x0
0xffffdc800001f1c0 0008 0000 0x0 0x0
0xffffdc800001f238 0008 0000 0x0 0x0
0xffffdc800001f2b0 0008 0000 0x0 0x0
0xffffdc800001f328 0008 0000 0x0 0x0
0xffffdc800001f3a0 0008 0000 0x0 0x0
0xffffdc800001f418 0008 0000 0x0 0x0
0xffffdc800001f490 0008 0000 0x0 0x0
0xffffdc800001f508 0008 0000 0x0 0x0
0xffffdc800001f580 0048 0000 0x0 0x0
0xffffdc800001f5f8 0048 0000 0x0 0x0
0xffffdc800001f670 0048 0000 0x0 0x0
0xffffdc800001f6e8 0048 0000 0x0 0x0
0xffffdc800001f760 0048 0000 0x0 0x0
0xffffdc800001f7d8 0048 0000 0x0 0x0
0xffffdc800001f850 0048 0000 0x0 0x0
0xffffdc800001f8c8 0048 0000 0x0 0x0
0xffffdc800001f940 0048 0000 0x0 0x0
0xffffdc800001f9b8 0048 0000 0x0 0x0
0xffffdc800001fa30 0048 0000 0x0 0x0
0xffffdc800001faa8 0048 0000 0x0 0x0
0xffffdc800001fb20 0048 0000 0x0 0x0
0xffffdc800001fb98 0048 0000 0x0 0x0
0xffffdc800001fc10 0048 0000 0x0 0x0
0xffffdc800001fc88 0048 0000 0x0 0x0
0xffffdc800001fd00 0048 0000 0x0 0x0
0xffffdc800001fd78 0048 0000 0x0 0x0
0xffffdc800001fdf0 0048 0000 0x0 0x0
0xffffdc800001fe68 0048 0000 0x0 0x0
0xffffdc800001fee0 0048 0000 0x0 0x0
0xffffdc800001ff58 0048 0000 0x0 0x0
0xffffdc800001ffd0 0048 0000 0x0 0x0
0xffffdc8000020048 0048 0000 0x0 0x0
0xffffdc80000200c0 0048 0000 0x0 0x0
0xffffdc8000020138 0048 0000 0x0 0x0
0xffffdc80000201b0 0048 0000 0x0 0x0
0xffffdc8000020228 0048 0000 0x0 0x0
0xffffdc80000202a0 0040 0000 0x0 0x0
0xffffdc8000020318 0040 0000 0x0 0x0
0xffffdc8000020390 0048 0000 0x0 0x0
0xffffdc8000020408 0040 0000 0x0 0x0
0xffffdc8000020480 0040 0000 0x0 0x0
0xffffdc80000204f8 0048 0000 0x0 0x0
0xffffdc8000020570 0048 0000 0x0 0x0
0xffffdc80000205e8 0048 0000 0x0 0x0
0xffffdc8000020660 0040 0000 0x0 0x0
0xffffdc80000206d8 0040 0000 0x0 0x0
0xffffdc8000020750 0040 0000 0x0 0x0
0xffffdc80000207c8 0040 0000 0x0 0x0
0xffffdc8000020840 0040 0000 0x0 0x0
0xffffdc80000208b8 0048 0000 0x0 0x0
0xffffdc8000020930 0048 0000 0x0 0x0
0xffffdc80000209a8 0008 0000 0x0 0x0
0xffffdc8000020a20 0008 0000 0x0 0x0
0xffffdc8000020a98 0008 0000 0x0 0x0
0xffffdc8000020b10 0008 0000 0x0 0x0
0xffffdc8000020b88 0008 0000 0x0 0x0
0xffffdc8000020c00 0008 0000 0x0 0x0
0xffffdc8000020c78 0008 0000 0x0 0x0
0xffffdc8000020cf0 0008 0000 0x0 0x0
0xffffdc8000020d68 0008 0000 0x0 0x0
0xffffdc8000020de0 0008 0000 0x0 0x0
0xffffdc8000020e58 0008 0000 0x0 0x0
0xffffdc8000020ed0 0008 0000 0x0 0x0
0xffffdc8000020f48 0008 0000 0x0 0x0
0xffffdc8000020fc0 0008 0000 0x0 0x0
0xffffdc8000021038 0008 0000 0x0 0x0
0xffffdc80000210b0 0008 0000 0x0 0x0
0xffffdc8000021128 0008 0000 0x0 0x0
0xffffdc80000211a0 0008 0000 0x0 0x0
0xffffdc8000021218 0008 0000 0x0 0x0
0xffffdc8000021290 0008 0000 0x0 0x0
0xffffdc8000021308 0008 0000 0x0 0x0
0xffffdc8000021380 0008 0000 0x0 0x0
0xffffdc80000213f8 0008 0000 0x0 0x0
0xffffdc8000021470 0008 0000 0x0 0x0
0xffffdc80000214e8 0008 0000 0x0 0x0
0xffffdc8000021560 0008 0000 0x0 0x0
0xffffdc80000215d8 0008 0000 0x0 0x0
0xffffdc8000021650 0008 0000 0x0 0x0
0xffffdc80000216c8 0008 0000 0x0 0x0
0xffffdc8000021740 0008 0000 0x0 0x0
0xffffdc80000217b8 0008 0000 0x0 0x0
0xffffdc8000021830 0008 0000 0x0 0x0
0xffffdc80000218a8 0008 0000 0x0 0x0
0xffffdc8000021920 0008 0000 0x0 0x0
0xffffdc8000021998 0008 0000 0x0 0x0
0xffffdc8000021a10 0008 0000 0x0 0x0
0xffffdc8000021a88 0008 0000 0x0 0x0
0xffffdc8000021b00 0008 0000 0x0 0x0
0xffffdc8000021b78 0008 0000 0x0 0x0
0xffffdc8000021bf0 0008 0000 0x0 0x0
0xffffdc8000021c68 0008 0000 0x0 0x0
0xffffdc8000021ce0 0008 0000 0x0 0x0
0xffffdc8000021d58 0008 0000 0x0 0x0
0xffffdc8000021dd0 0008 0000 0x0 0x0
0xffffdc8000021e48 0008 0000 0x0 0x0
0xffffdc8000021ec0 0008 0000 0x0 0x0
0xffffdc8000021f38 0008 0000 0x0 0x0
0xffffdc8000021fb0 0008 0000 0x0 0x0
0xffffdc8000022028 0008 0000 0x0 0x0
0xffffdc80000220a0 0008 0000 0x0 0x0
0xffffdc8000022118 0008 0000 0x0 0x0
0xffffdc8000022190 0008 0000 0x0 0x0
0xffffdc8000022208 0008 0000 0x0 0x0
0xffffdc8000022280 0008 0000 0x0 0x0
0xffffdc80000222f8 0040 0000 0x0 0x0
0xffffdc8000022370 0040 0000 0x0 0x0
0xffffdc80000223e8 0040 0000 0x0 0x0
0xffffdc8000022460 0040 0000 0x0 0x0
0xffffdc80000224d8 0040 0000 0x0 0x0
0xffffdc8000022550 0040 0000 0x0 0x0
0xffffdc80000225c8 0040 0000 0x0 0x0
0xffffdc8000022640 0040 0000 0x0 0x0
0xffffdc80000226b8 0040 0000 0x0 0x0
0xffffdc8000022730 0040 0000 0x0 0x0
0xffffdc80000227a8 0040 0000 0x0 0x0
0xffffdc8000022820 0040 0000 0x0 0x0
0xffffdc8000022898 0040 0000 0x0 0x0
0xffffdc8000022910 0040 0000 0x0 0x0
0xffffdc8000022988 0040 0000 0x0 0x0
0xffffdc8000022a00 0040 0000 0x0 0x0
0xffffdc8000022a78 0040 0000 0x0 0x0
0xffffdc8000022af0 0040 0000 0x0 0x0
0xffffdc8000022b68 0040 0000

---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Maxime Villard

unread,
Dec 12, 2019, 3:59:00 AM12/12/19
to syzbot, syzkaller-...@googlegroups.com
dismiss

#syz invalid
Reply all
Reply to author
Forward
0 new messages