panic: UBSan: Undefined Behavior in /syzkaller/managers/netbsd-kubsan/kernel/sys/kern/sysv_shm.c:LINE, load of value 5 i

0 views
Skip to first unread message

syzbot

unread,
Oct 10, 2019, 4:36:08 AM10/10/19
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following crash on:

HEAD commit: 678da7f9 add +1 to strlcpy's (Patrick Welche)
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=152f6db3600000
kernel config: https://syzkaller.appspot.com/x/.config?x=824b23e1f4b6c76b
dashboard link: https://syzkaller.appspot.com/bug?extid=3265eb89ff20a30d6f45

Unfortunately, I don't have any reproducer for this crash yet.

IMPORTANT: if you fix the bug, please add the following tag to the commit:
Reported-by: syzbot+3265eb...@syzkaller.appspotmail.com

[ 94.6216345] panic: UBSan: Undefined Behavior in
/syzkaller/managers/netbsd-kubsan/kernel/sys/kern/sysv_shm.c:353:15, load
of value 5 is not a valid value for type '_Bool'

[ 94.6416423] cpu1: Begin traceback...
[ 94.6516645] vpanic() at netbsd:vpanic+0x258 sys/kern/subr_prf.c:336
[ 94.7017603] isAlreadyReported() at netbsd:isAlreadyReported
[ 94.7418350] HandleLoadInvalidValue() at
netbsd:HandleLoadInvalidValue+0xff sys/../common/lib/libc/misc/ubsan.c:497
[ 94.7819125] sys_shmdt() at netbsd:sys_shmdt+0x388 sys/kern/sysv_shm.c:353
[ 94.8219891] sys___syscall() at netbsd:sys___syscall+0x132 sy_call
sys/sys/syscallvar.h:65 [inline]
[ 94.8219891] sys___syscall() at netbsd:sys___syscall+0x132
sys/kern/sys_syscall.c:77
[ 94.8620637] syscall() at netbsd:syscall+0x1ce sy_call
sys/sys/syscallvar.h:65 [inline]
[ 94.8620637] syscall() at netbsd:syscall+0x1ce sy_invoke
sys/sys/syscallvar.h:94 [inline]
[ 94.8620637] syscall() at netbsd:syscall+0x1ce
sys/arch/x86/x86/syscall.c:138
[ 94.8821050] --- syscall (number 198) ---
[ 94.9021388] 7ab872643b9a:
[ 94.9021388] cpu1: End traceback...
[ 94.9021388] fatal breakpoint trap in supervisor mode
[ 94.9121662] trap type 1 code 0 rip 0xffffffff8021ddad cs 0x8 rflags
0x282 cr2 0xc ilevel 0 rsp 0xffffcf00b3c40930
[ 94.9221753] curlwp 0xfffff91fb4b44080 pid 1621.2 lowest kstack
0xffffcf00b3c3d2c0
Stopped in pid 1621.2 (syz-executor.2) at netbsd:breakpoint+0x5:
leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0xd9 sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x258 sys/kern/subr_prf.c:336
isAlreadyReported() at netbsd:isAlreadyReported
HandleLoadInvalidValue() at netbsd:HandleLoadInvalidValue+0xff
sys/../common/lib/libc/misc/ubsan.c:497
sys_shmdt() at netbsd:sys_shmdt+0x388 sys/kern/sysv_shm.c:353
sys___syscall() at netbsd:sys___syscall+0x132 sy_call
sys/sys/syscallvar.h:65 [inline]
sys___syscall() at netbsd:sys___syscall+0x132 sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x1ce sy_call sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x1ce sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x1ce sys/arch/x86/x86/syscall.c:138
--- syscall (number 198) ---
7ab872643b9a:
ds 930
es df81
fs 920
gs 2000
rdi fffff91fd46b54e0
rsi fffff91fb4b44368
rbp ffffcf00b3c40930
rbx ffffcf00a57e2000
rdx 2
rcx 0
rax fffff91fd293fcf8
r8 ffffcf00a57e2000
r9 0
r10 ffffcf00b3c40000
r11 10
r12 104
r13 ffffffff83022aa0 ostype+0xee408
r14 ffffcf00b3c409a8
r15 ffffffff84cfd680 pool_head+0x4c0
rip ffffffff8021ddad breakpoint+0x5
cs 8
rflags 282
rsp ffffcf00b3c40930
ss 10
netbsd:breakpoint+0x5: leave
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
1628 1 4 1 1000000 fffff91fbcf234e0 syz-executor.2
1926 2 3 0 80 fffff91fbe64e6a0 syz-executor.5 parked
1926 1 2 0 0 fffff91fb89aa780 syz-executor.5
2118 2 5 1 0 fffff91fb89aa340 syz-executor.4
2118 1 3 1 80 fffff91fb31d0760 syz-executor.4 parked
1621 > 2 7 1 0 fffff91fb4b44080 syz-executor.2
1621 1 3 1 80 fffff91fb87ed2e0 syz-executor.2 parked
1285 2 2 0 0 fffff91fca6a04a0 syz-executor.1
1285 1 3 1 80 fffff91fb61354a0 syz-executor.1 parked
1658 1 3 1 80 fffff91fb828a040 syz-executor.2 parked
1718 1 3 1 80 fffff91fb4b44900 syz-executor.2 parked
2027 1 3 0 80 fffff91fbc728a00 syz-executor.2 parked
1779 1 3 1 80 fffff91fbc9b6700 syz-executor.2 parked
803 1 3 1 80 fffff91fbcd276e0 syz-executor.2 parked
1302 1 3 0 80 fffff91fbe7676c0 syz-executor.4 parked
1111 1 3 0 80 fffff91fcf00d8c0 syz-executor.2 parked
1712 1 3 0 80 fffff91fb31d0320 syz-executor.4 parked
1181 1 3 0 80 fffff91fb31d0ba0 syz-executor.5 parked
970 1 3 0 80 fffff91fb772c740 syz-executor.1 parked
365 1 3 0 80 fffff91fcf1c59c0 syz-executor.4 parked
817 1 3 1 80 fffff91fbf40c200 syz-executor.4 parked
596 1 3 0 80 fffff91fbf0311c0 syz-executor.4 parked
1511 1 3 1 80 fffff91fbf031600 syz-executor.1 parked
665 1 3 1 80 fffff91fca4f84e0 syz-executor.1 parked
1212 1 3 1 80 fffff91fb87edb60 syz-executor.4 parked
930 1 3 0 80 fffff91fbc9b6b40 syz-executor.2 parked
233 1 3 1 80 fffff91fbcd27b20 syz-executor.0 parked
933 1 3 0 80 fffff91fbf40ca80 syz-executor.0 parked
967 1 3 1 80 fffff91fcef94900 syz-executor.0 parked
836 1 3 0 80 fffff91fbe315620 syz-executor.2 parked
1368 1 3 1 80 fffff91fbe3151e0 syz-executor.0 parked
1330 1 3 0 80 fffff91fbf14aa20 syz-executor.5 parked
717 1 3 0 80 fffff91fc0a13aa0 syz-executor.5 parked
861 1 3 0 80 fffff91fc13dc520 syz-executor.4 parked
789 1 3 0 80 fffff91fbe767280 syz-executor.4 parked
649 1 3 0 80 fffff91fc13dc0e0 syz-executor.4 parked
1135 1 3 0 80 fffff91fca4f80a0 syz-executor.4 parked
1002 1 3 1 80 fffff91fc54329a0 syz-executor.1 parked
1191 1 3 1 80 fffff91fca4f8920 syz-executor.3 parked
887 1 3 0 80 fffff91fbc9b62c0 syz-executor.5 parked
654 1 3 0 80 fffff91fbf40c640 syz-executor.1 parked
940 1 3 1 80 fffff91fcf1e5940 syz-executor.1 parked
456 1 3 1 80 fffff91fc2cab980 syz-executor.5 parked
488 1 3 0 80 fffff91fbe64e260 syz-executor.5 parked
869 1 3 0 80 fffff91fbd3eaac0 syz-executor.3 parked
322 1 3 0 80 fffff91fbd3ea680 syz-executor.3 parked
766 1 3 1 80 fffff91fc2cab540 syz-executor.3 parked
644 1 3 1 80 fffff91fcef94080 syz-executor.1 parked
767 1 3 0 80 fffff91fbd3ea240 syz-executor.0 parked
633 1 3 0 80 fffff91fbc728180 syz-executor.1 parked
656 1 3 1 80 fffff91fc2cab100 syz-executor.3 parked
625 1 3 1 80 fffff91fcf06c9e0 syz-executor.3 parked
775 1 3 0 80 fffff91fc5432560 syz-executor.3 parked
796 1 3 1 80 fffff91fbf14a5e0 syz-executor.3 parked
658 1 3 0 80 fffff91fca6a0060 syz-executor.3 parked
97 1 3 0 80 fffff91fcf06c160 syz-executor.2 parked
96 1 3 1 80 fffff91fc5432120 syz-executor.0 parked
696 1 3 1 80 fffff91fc13dc960 syz-executor.2 parked
581 1 3 0 80 fffff91fcf1c5140 syz-executor.0 parked
715 1 3 1 80 fffff91fcf1e50c0 syz-executor.0 parked
550 1 3 1 80 fffff91fcf06c5a0 syz-executor.0 parked
603 1 2 0 0 fffff91fcf00d480 syz-executor.4
607 1 2 0 0 fffff91fcf00d040 syz-executor.5
522 1 3 0 80 fffff91ecb5aabc0 syz-executor.3 pipe_rd
45 1 2 0 0 fffff91fd2804300 syz-executor.2
524 1 2 0 0 fffff91efd43eb60 syz-executor.1
41 1 2 0 0 fffff91f0c338260 syz-executor.0
484 12 2 0 0 fffff91efd43e720 syz-fuzzer
484 11 3 0 80 fffff91f076d6b20 syz-fuzzer parked
484 10 3 0 80 fffff91f05a08ac0 syz-fuzzer parked
484 9 2 0 10000000 fffff91fd2804b80 syz-fuzzer
484 8 3 1 80 fffff91ee1771700 syz-fuzzer parked
484 7 3 1 80 fffff91fd2804740 syz-fuzzer parked
484 6 3 0 80 fffff91ee17712c0 syz-fuzzer parked
484 5 3 1 80 fffff91f05a08680 syz-fuzzer parked
484 4 3 0 80 fffff91f076d66e0 syz-fuzzer parked
484 3 3 1 80 fffff91fd210a320 syz-fuzzer parked
484 2 2 0 0 fffff91f0c338ae0 syz-fuzzer
484 1 3 0 80 fffff91ec5d9c200 syz-fuzzer parked
535 1 3 1 80 fffff91f0c3386a0 sshd select
527 1 3 1 80 fffff91ecb5aa780 getty nanoslp
531 1 3 1 80 fffff91ecb5aa340 getty nanoslp
465 1 3 1 80 fffff91efd43e2e0 getty nanoslp
381 1 3 1 80 fffff91f05a08240 getty ttyraw
542 1 3 0 80 fffff91fd210aba0 cron nanoslp
473 1 3 1 80 fffff91fd210a760 inetd kqueue
355 1 3 1 80 fffff91f0daa8280 sshd select
302 1 3 1 80 fffff91f0daa86c0 powerd kqueue
309 1 3 0 80 fffff91f076d62a0 syslogd kqueue
276 1 3 0 80 fffff91ee1771b40 dhcpcd kqueue
218 1 3 1 80 fffff91f0daa8b00 dhcpcd kqueue
1 1 3 0 80 fffff91ec4e03a60 init wait
0 58 3 0 204 fffff91ec5d9c640 physiod physiod
0 57 3 0 204 fffff91ec5413220 pooldrain pooldrain
0 56 3 0 204 fffff91ec5413aa0 aiodoned aiodoned
0 55 3 0 200 fffff91ec5413660 ioflush syncer
0 54 3 0 200 fffff91ec5d9ca80 pgdaemon pgdaemon
0 51 2 1 200 fffff91ec24fc9c0 npfgc-0
0 50 3 0 204 fffff91ec4e03620 rt_free rt_free
0 49 3 0 204 fffff91ec4e031e0 unpgc unpgc
0 48 3 0 204 fffff91ec4deca40 key_timehandler
key_timehandler
0 47 3 1 204 fffff91ec4dec600 icmp6_wqinput/1
icmp6_wqinput
0 46 3 0 204 fffff91ec4dec1c0 icmp6_wqinput/0
icmp6_wqinput
0 45 2 1 200 fffff91ec4d85a20 nd6_timer
0 44 3 1 204 fffff91ec4d57160 carp6_wqinput/1
carp6_wqinput
0 43 3 0 204 fffff91ec4d575a0 carp6_wqinput/0
carp6_wqinput
0 42 3 1 204 fffff91ec4d579e0 carp_wqinput/1
carp_wqinput
0 41 3 0 204 fffff91ec4d5e180 carp_wqinput/0
carp_wqinput
0 40 3 1 204 fffff91ec4d5e5c0 icmp_wqinput/1
icmp_wqinput
0 39 3 0 204 fffff91ec4d5ea00 icmp_wqinput/0
icmp_wqinput
0 38 3 0 204 fffff91ec4d851a0 rt_timer rt_timer
0 37 3 1 204 fffff91ec4d855e0 vmem_rehash vmem_rehash
0 27 3 0 204 fffff91ec24fc580 scsibus0 sccomp
0 26 3 0 200 fffff91ec24fc140 pms0 pmsreset
0 25 3 1 204 fffff91ec24879a0 xcall/1 xcall
0 24 1 1 200 fffff91ec2487560 softser/1
0 23 1 1 200 fffff91ec2487120 softclk/1
0 22 1 1 200 fffff91ec2478980 softbio/1
0 21 1 1 200 fffff91ec2478540 softnet/1
0 20 1 1 201 fffff91ec2478100 idle/1
0 19 3 0 204 fffff91fd2982960 lnxpwrwq lnxpwrwq
0 18 3 0 204 fffff91fd2982520 lnxlngwq lnxlngwq
0 17 3 0 204 fffff91fd29820e0 lnxsyswq lnxsyswq
0 16 3 0 204 fffff91fd29a1940 lnxrcugc lnxrcugc
0 15 3 0 204 fffff91fd29a1500 sysmon smtaskq
0 14 3 0 204 fffff91fd29a10c0 pmfsuspend pmfsuspend
0 13 3 0 204 fffff91fd2dba920 pmfevent pmfevent
0 12 3 0 204 fffff91fd2dba4e0 sopendfree sopendfr
0 11 3 0 204 fffff91fd2dba0a0 nfssilly nfssilly
0 10 3 0 200 fffff91fd41ef900 cachegc cachegc
0 9 3 0 204 fffff91fd41ef4c0 vdrain vdrain
0 8 3 0 200 fffff91fd41ef080 modunload mod_unld
0 7 3 0 204 fffff91fd420a8e0 xcall/0 xcall
0 6 1 0 200 fffff91fd420a4a0 softser/0
0 5 1 0 200 fffff91fd420a060 softclk/0
0 4 1 0 200 fffff91fd42298c0 softbio/0
0 3 1 0 200 fffff91fd4229480 softnet/0
0 2 1 0 201 fffff91fd4229040 idle/0
0 > 1 7 0 200 ffffffff84c28380 swapper
[Locks tracked through LWPs]
Locks held by an LWP (syz-executor.2):
Lock 0 (initialized at shminit)
lock address : 0xffffffff85a8c1c0 type : sleep/adaptive
initialized : 0xffffffff81cd4660
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xfffff91fb4b44080 last held: 0xfffff91fb4b44080
last locked* : 0xffffffff81cd1a77 unlocked : 0xffffffff81cd2dcf
owner field : 0xfffff91fb4b44080 wait/spin: 0/0

Turnstile chain at 0xffffffff85a8b380.
=> No active turnstile for this lock.

Locks held by an LWP (syz-executor.1):
Lock 0 (initialized at vcache_alloc)
lock address : 0xfffff91fb9ecea08 type : sleep/adaptive
initialized : 0xffffffff81d8a3d6
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 1
current lwp : 0xfffff91fb4b44080 last held: 0xfffff91fca6a04a0
last locked* : 0xffffffff81dce8f0 unlocked : 0xffffffff81dce82f
owner/count : 0xfffff91fca6a04a0 flags : 0x0000000000000004

Turnstile chain at 0xffffffff85a8b010.
=> No active turnstile for this lock.
Lock 1 (initialized at amap_alloc)
lock address : 0xfffff91fb71a7740 type : sleep/adaptive
initialized : 0xffffffff81aa0ea6
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 0
current lwp : 0xfffff91fb4b44080 last held: 0xfffff91fca6a04a0
last locked* : 0xffffffff81abe55a unlocked : 0xffffffff81abbcf7
owner field : 000000000000000000 wait/spin: 0/0

Turnstile chain at 0xffffffff85a8b280.
=> No active turnstile for this lock.

Locks held by an LWP (aiodoned):
Lock 0 (initialized at uvm_obj_init)
lock address : 0xfffff91fb71a7540 type : sleep/adaptive
initialized : 0xffffffff81ae8290
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
current cpu : 1 last held: 0
current lwp : 0xfffff91fb4b44080 last held: 0xfffff91ec5413aa0
last locked* : 0xffffffff81af7829 unlocked : 0xffffffff81d3e61f
owner field : 000000000000000000 wait/spin: 0/0

Turnstile chain at 0xffffffff85a8b280.
=> No active turnstile for this lock.


[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffffcf0000003180 0041 0000 0x0 0x0
0xffffcf00000031f8 0041 0000 0x0 0x0
0xffffcf0000003270 0041 0000 0x0 0x0
0xffffcf00000032e8 0041 0000 0x0 0x0
0xffffcf0000003360 0041 0000 0x0 0x0
0xffffcf00000033d8 0041 0000 0x0 0x0
0xffffcf0000003450 0041 0000 0x0 0x0
0xffffcf00000034c8 0041 0000 0x0 0x0
0xffffcf0000003540 0040 0000 0x0 0x0
0xffffcf00000035b8 0048 0000 0x0 0x0
0xffffcf0000003630 0048 0000 0x0 0x0
0xffffcf00000036a8 0048 0000 0x0 0x0
0xffffcf0000003720 0048 0000 0x0 0x0
0xffffcf0000003798 0048 0000 0x0 0x0
0xffffcf0000003810 0049 0000 0x0 0x0
0xffffcf0000003888 0049 0000 0x0 0x0
0xffffcf0000003900 0040 0000 0x0 0x0
0xffffcf0000003978 0040 0000 0x0 0x0
0xffffcf00000039f0 0040 0000 0x0 0x0
0xffffcf0000003a68 0040 0000 0x0 0x0
0xffffcf0000003ae0 0040 0000 0x0 0x0
0xffffcf0000003b58 0040 0000 0x0 0x0
0xffffcf0000003bd0 0049 0000 0x0 0x0
0xffffcf0000003c48 0040 0000 0x0 0x0
0xffffcf0000003cc0 0048 0000 0x0 0x0
0xffffcf0000003d38 0048 0000 0x0 0x0
0xffffcf0000003db0 0048 0000 0x0 0x0
0xffffcf0000003e28 0049 0000 0x0 0x0
0xffffcf0000003ea0 0048 0000 0x0 0x0
0xffffcf0000003f18 0048 0000 0x0 0x0
0xffffcf0000003f90 0040 0000 0x0 0x0
0xffffcf0000004008 0048 0000 0x0 0x0
0xffffcf0000004080 0049 0000 0x0 0x0
0xffffcf00000040f8 0048 0000 0x0 0x0
0xffffcf0000004170 0048 0000 0x0 0x0
0xffffcf00000041e8 0048 0000 0x0 0x0
0xffffcf0000004260 0048 0000 0x0 0x0
0xffffcf00000042d8 0049 0000 0x0 0x0
0xffffcf0000004350 0048 0000 0x0 0x0
0xffffcf00000043c8 0048 0000 0x0 0x0
0xffffcf0000004440 0048 0000 0x0 0x0
0xffffcf00000044b8 0048 0000 0x0 0x0
0xffffcf0000004530 0048 0000 0x0 0x0
0xffffcf00000045a8 0048 0000 0x0 0x0
0xffffcf0000004620 0048 0000 0x0 0x0
0xffffcf0000004698 0048 0000 0x0 0x0
0xffffcf0000004710 0048 0000 0x0 0x0
0xffffcf0000004788 0048 0000 0x0 0x0
0xffffcf0000004800 0048 0000 0x0 0x0
0xffffcf0000004878 0048 0000 0x0 0x0
0xffffcf00000048f0 0048 0000 0x0 0x0
0xffffcf0000004968 0048 0000 0x0 0x0
0xffffcf00000049e0 0041 0000 0x0 0x0
0xffffcf0000004a58 0048 0000 0x0 0x0
0xffffcf0000004ad0 0040 0000 0x0 0x0
0xffffcf0000004b48 0048 0000 0x0 0x0
0xffffcf0000004bc0 0048 0000 0x0 0x0
0xffffcf0000004c38 0041 0000 0x0 0x0
0xffffcf0000004cb0 0041 0000 0x0 0x0
0xffffcf0000004d28 0041 0000 0x0 0x0
0xffffcf0000004da0 0041 0000 0x0 0x0
0xffffcf0000004e18 0041 0000 0x0 0x0
0xffffcf0000004e90 0048 0000 0x0 0x0
0xffffcf0000004f08 0049 0000 0x0 0x0
0xffffcf0000004f80 0049 0000 0x0 0x0
0xffffcf0000004ff8 0041 0000 0x0 0x0
0xffffcf0000005070 0041 0000 0x0 0x0
0xffffcf00000050e8 0041 0000 0x0 0x0
0xffffcf0000005160 0041 0000 0x0 0x0
0xffffcf00000051d8 0041 0000 0x0 0x0
0xffffcf0000005250 0048 0000 0x0 0x0
0xffffcf00000052c8 0041 0000 0x0 0x0
0xffffcf0000005340 0041 0000 0x0 0x0
0xffffcf00000053b8 0041 0000 0x0 0x0
0xffffcf0000005430 0041 0000 0x0 0x0
0xffffcf00000054a8 0041 0000 0x0 0x0
0xffffcf0000005520 0041 0000 0x0 0x0
0xffffcf0000005598 0041 0000 0x0 0x0
0xffffcf0000005610 0048 0000 0x0 0x0
0xffffcf0000005688 0041 0000 0x0 0x0
0xffffcf0000005700 0041 0000 0x0 0x0
0xffffcf0000005778 0041 0000 0x0 0x0
0xffffcf00000057f0 0041 0000 0x0 0x0
0xffffcf0000005868 0041 0000 0x0 0x0
0xffffcf00000058e0 0041 0000 0x0 0x0
0xffffcf0000005958 0041 0000 0x0 0x0
0xffffcf00000059d0 0041 0000 0x0 0x0
0xffffcf0000005a48 0041 0000 0x0 0x0
0xffffcf0000005ac0 0041 0000 0x0 0x0
0xffffcf0000005b38 0041 0000 0x0 0x0
0xffffcf0000005bb0 0041 0000 0x0 0x0
0xffffcf0000005c28 0041 0000 0x0 0x0
0xffffcf0000005ca0 0041 0000 0x0 0x0
0xffffcf0000005d18 0041 0000 0x0 0x0
0xffffcf0000005d90 0041 0000 0x0 0x0
0xffffcf0000005e08 0041 0000 0x0 0x0
0xffffcf0000005e80 0041 0000 0x0 0x0
0xffffcf0000005ef8 0041 0000 0x0 0x0
0xffffcf0000005f70 0041 0000 0x0 0x0
0xffffcf0000005fe8 0041 0000 0x0 0x0
0xffffcf0000006060 0049 0000 0x0 0x0
0xffffcf00000060d8 0041 0000 0x0 0x0
0xffffcf0000006150 0041 0000 0x0 0x0
0xffffcf00000061c8 0041 0000 0x0 0x0
0xffffcf0000006240 0041 0000 0x0 0x0
0xffffcf00000062b8 0049 0000 0x0 0x0
0xffffcf0000006330 0049 0000 0x0 0x0
0xffffcf00000063a8 0049 0000 0x0 0x0
0xffffcf0000006420 0049 0000 0x0 0x0
0xffffcf0000006498 0049 0000 0x0 0x0
0xffffcf0000006510 0041 0000 0x0 0x0
0xffffcf0000006588 0041 0000 0x0 0x0
0xffffcf0000006600 0049 0000 0x0 0x0
0xffffcf0000006678 0049 0000 0x0 0x0
0xffffcf00000066f0 0049 0000 0x0 0x0
0xffffcf0000006768 0049 0000 0x0 0x0
0xffffcf00000067e0 0049 0000 0x0 0x0
0xffffcf0000006858 0049 0000 0x0 0x0
0xffffcf00000068d0 0041 0000 0x0 0x0
0xffffcf0000006948 0049 0000 0x0 0x0
0xffffcf00000069c0 0049 0000 0x0 0x0
0xffffcf0000006a38 0049 0000 0x0 0x0
0xffffcf0000006ab0 0049 0000 0x0 0x0
0xffffcf0000006b28 0049 0000 0x0 0x0
0xffffcf0000006ba0 0048 0000 0x0 0x0
0xffffcf0000006c18 0049 0000 0x0 0x0
0xffffcf0000006c90 0041 0000 0x0 0x0
0xffffcf0000006d08 0049 0000 0x0 0x0
0xffffcf0000006d80 0049 0000 0x0 0x0
0xffffcf0000006df8 0049 0000 0x0 0x0
0xffffcf0000006e70 0049 0000 0x0 0x0
0xffffcf0000006ee8 0049 0000 0x0 0x0
0xffffcf0000006f60 0048 0000 0x0 0x0
0xffffcf0000006fd8 0048 0000 0x0 0x0
0xffffcf0000007050 0049 0000 0x0 0x0
0xffffcf00000070c8 0049 0000 0x0 0x0
0xffffcf0000007140 0049 0000 0x0 0x0
0xffffcf00000071b8 0049 0000 0x0 0x0
0xffffcf0000007230 0048 0000 0x0 0x0
0xffffcf00000072a8 0048 0000 0x0 0x0
0xffffcf0000007320 0048 0000 0x0 0x0
0xffffcf0000007398 0048 0000 0x0 0x0
0xffffcf0000007410 0049 0000 0x0 0x0
0xffffcf0000007488 0049 0000 0x0 0x0
0xffffcf0000007500 0049 0000 0x0 0x0
0xffffcf0000007578 0048 0000 0x0 0x0
0xffffcf00000075f0 0049 0000 0x0 0x0
0xffffcf0000007668 0049 0000 0x0 0x0
0xffffcf00000076e0 0049 0000 0x0 0x0
0xffffcf0000007758 0048 0000 0x0 0x0
0xffffcf00000077d0 0049 0000 0x0 0x0
0xffffcf0000007848 0049 0000 0x0 0x0
0xffffcf00000078c0 0048 0000 0x0 0x0
0xffffcf0000007938 0048 0000 0x0 0x0
0xffffcf00000079b0 0049 0000 0x0 0x0
0xffffcf0000007a28 0048 0000 0x0 0x0
0xffffcf0000007aa0 0048 0000 0x0 0x0
0xffffcf0000007b18 0048 0000 0x0 0x0
0xffffcf0000007b90 0049 0000 0x0 0x0
0xffffcf0000007c08 0048 0000 0x0 0x0
0xffffcf0000007c80 0048 0000 0x0 0x0
0xffffcf0000007cf8 0048 0000 0x0 0x0
0xffffcf0000007d70 0048 0000 0x0 0x0
0xffffcf0000007de8 0048 0000 0x0 0x0
0xffffcf0000007e60 0048 0000 0x0 0x0
0xffffcf0000007ed8 0049 0000 0x0 0x0
0xffffcf0000007f50 0048 0000 0x0 0x0
0xffffcf0000007fc8 0048 0000 0x0 0x0
0xffffcf0000008040 0048 0000 0x0 0x0
0xffffcf00000080b8 0048 0000 0x0 0x0
0xffffcf0000008130 0048 0000 0x0 0x0
0xffffcf00000081a8 0049 0000 0x0 0x0
0xffffcf0000008220 0048 0000 0x0 0x0
0xffffcf0000008298 0048 0000 0x0 0x0
0xffffcf0000008310 0048 0000 0x0 0x0
0xffffcf0000008388 0048 0000 0x0 0x0
0xffffcf0000008400 0048 0000 0x0 0x0
0xffffcf0000008478 0048 0000 0x0 0x0
0xffffcf00000084f0 0049 0000 0x0 0x0
0xffffcf0000008568 0048 0000 0x0 0x0
0xffffcf00000085e0 0048 0000 0x0 0x0
0xffffcf0000008658 0048 0000 0x0 0x0
0xffffcf00000086d0 0048 0000 0x0 0x0
0xffffcf0000008748 0048 0000 0x0 0x0
0xffffcf00000087c0 0049 0000 0x0 0x0
0xffffcf0000008838 0048 0000 0x0 0x0
0xffffcf00000088b0 0048 0000 0x0 0x0
0xffffcf0000008928 0048 0000 0x0 0x0
0xffffcf00000089a0 0048 0000 0x0 0x0
0xffffcf0000008a18 0048 0000 0x0 0x0
0xffffcf0000008a90 0048 0000 0x0 0x0
0xffffcf0000008b08 0049 0000 0x0 0x0
0xffffcf0000008b80 0048 0000 0x0 0x0
0xffffcf0000008bf8 0048 0000 0x0 0x0
0xffffcf0000008c70 0048 0000 0x0 0x0
0xffffcf0000008ce8 0048 0000 0x0 0x0
0xffffcf0000008d60 0048 0000 0x0 0x0
0xffffcf0000008dd8 0048 0000 0x0 0x0
0xffffcf0000008e50 0049 0000 0x0 0x0
0xffffcf0000008ec8 0008 0000 0x0 0x0
0xffffcf0000008f40 0008 0000 0x0 0x0
0xffffcf0000008fb8 0008 0000 0x0 0x0
0xffffcf0000009030 0008 0000 0x0 0x0
0xffffcf00000090a8 0008 0000 0x0 0x0
0xffffcf0000009120 0008 0000 0x0 0x0
0xffffcf0000009198 0008 0000 0x0 0x0
0xffffcf0000009210 0008 0000 0x0 0x0
0xffffcf0000009288 0008 0000 0x0 0x0
0xffffcf0000009300 0008 0000 0x0 0x0
0xffffcf0000009378 0008 0000 0x0 0x0
0xffffcf00000093f0 0008 0000 0x0 0x0
0xffffcf0000009468 0008 0000 0x0 0x0
0xffffcf00000094e0 0008 0000 0x0 0x0
0xffffcf0000009558 0008 0000 0x0 0x0
0xffffcf00000095d0 0008 0000 0x0 0x0
0xffffcf0000009648 0008 0000 0x0 0x0
0xffffcf00000096c0 0008 0000 0x0 0x0
0xffffcf0000009738 0008 0000 0x0 0x0
0xffffcf00000097b0 0008 0000 0x0 0x0
0xffffcf0000009828 0008 0000 0x0 0x0
0xffffcf00000098a0 0008 0000 0x0 0x0
0xffffcf0000009918 0008 0000 0x0 0x0
0xffffcf0000009990 0008 0000 0x0 0x0
0xffffcf0000009a08 0008 0000 0x0 0x0
0xffffcf0000009a80 0008 0000 0x0 0x0
0xffffcf0000009af8 0008 0000 0x0 0x0
0xffffcf0000009b70 0008 0000 0x0 0x0
0xffffcf0000009be8 0008 0000 0x0 0x0
0xffffcf0000009c60 0008 0000 0x0 0x0
0xffffcf0000009cd8 0008 0000 0x0 0x0
0xffffcf0000009d50 0008 0000 0x0 0x0
0xffffcf0000009dc8 0008 0000 0x0 0x0
0xffffcf0000009e40 0008 0000 0x0 0x0
0xffffcf0000009eb8 0008 0000 0x0 0x0
0xffffcf0000009f30 0008 0000 0x0 0x0
0xffffcf0000009fa8 0008 0000 0x0 0x0
0xffffcf000000a020 0008 0000 0x0 0x0
0xffffcf000000a098 0008 0000 0x0 0x0
0xffffcf000000a110 0008 0000 0x0 0x0
0xffffcf000000a188 0008 0000 0x0 0x0
0xffffcf000000a200 0008 0000 0x0 0x0
0xffffcf000000a278 0008 0000 0x0 0x0
0xffffcf000000a2f0 0008 0000 0x0 0x0
0xffffcf000000a368 0008 0000 0x0 0x0
0xffffcf000000a3e0 0008 0000 0x0 0x0
0xffffcf000000a458 0008 0000 0x0 0x0
0xffffcf000000a4d0 0008 0000 0x0 0x0
0xffffcf000000a548 0008 0000 0x0 0x0
0xffffcf000000a5c0 0008 0000 0x0 0x0
0xffffcf000000a638 0008 0000 0x0 0x0
0xffffcf000000a6b0 0008 0000 0x0 0x0
0xffffcf000000a728 0008 0000 0x0 0x0
0xffffcf000000a7a0 0008 0000 0x0 0x0
0xffffcf000000a818 0048 0000 0x0 0x0
0xffffcf000000a890 0048 0000 0x0 0x0
0xffffcf000000a908 0048 0000 0x0 0x0
0xffffcf000000a980 0048 0000 0x0 0x0
0xffffcf000000a9f8 0048 0000 0x0 0x0
0xffffcf000000aa70 0048 0000 0x0 0x0
0xffffcf000000aae8 0048 0000 0x0 0x0
0xffffcf000000ab60 0048 0000 0x0 0x0
0xffffcf000000abd8 0048 0000 0x0 0x0
0xffffcf000000ac50 0048 0000 0x0 0x0
0xffffcf000000acc8 0048 0000 0x0 0x0
0xffffcf000000ad40 0048 0000 0x0 0x0
0xffffcf000000adb8 0048 0000 0x0 0x0
0xffffcf000000ae30 0048 0000 0x0 0x0
0xffffcf000000aea8 0048 0000 0x0 0x0
0xffffcf000000af20 0048 0000 0x0 0x0
0xffffcf000000af98 0048 0000 0x0 0x0
0xffffcf000000b010 0048 0000 0x0 0x0
0xffffcf000000b088 0048 0000 0x0 0x0
0xffffcf000000b100 0048 0000 0x0 0x0
0xffffcf000000b178 0048 0000 0x0 0x0
0xffffcf000000b1f0 0048 0000 0x0 0x0
0xffffcf000000b268 0048 0000 0x0 0x0
0xffffcf000000b2e0 0048 0000 0x0 0x0
0xffffcf000000b358 0048 0000 0x0 0x0
0xffffcf000000b3d0 0048 0000 0x0 0x0
0xffffcf000000b448 0048 0000 0x0 0x0
0xffffcf000000b4c0 0048 0000 0x0 0x0
0xffffcf000000b538 0048 0000 0x0 0x0
0xffffcf000000b5b0 0048 0000 0x0 0x0
0xffffcf000000b628 0048 0000 0x0 0x0
0xffffcf000000b6a0 0048 0000 0x0 0x0
0xffffcf000000b718 0048 0000 0x0 0x0
0xffffcf000000b790 0048 0000 0x0 0x0
0xffffcf000000b808 0048 0000 0x0 0x0
0xffffcf000000b880 0048 0000 0x0 0x0
0xffffcf000000b8f8 0048 0000 0x0 0x0
0xffffcf000000b970 0048 0000 0x0 0x0
0xffffcf000000b9e8 0048 0000 0x0 0x0
0xffffcf000000ba60 0048 0000 0x0 0x0
0xffffcf000000bad8 0048 0000 0x0 0x0
0xffffcf000000bb50 0048 0000 0x0 0x0
0xffffcf000000bbc8 0048 0000 0x0 0x0
0xffffcf000000bc40 0008 0000 0x0 0x0
0xffffcf000000bcb8 0008 0000 0x0 0x0
0xffffcf000000bd30 0008 0000 0x0 0x0
0xffffcf000000bda8 0008 0000 0x0 0x0
0xffffcf000000be20 0008 0000 0x0 0x0
0xffffcf000000be98 0008 0000 0x0 0x0
0xffffcf000000bf10 0008 0000 0x0 0x0
0xffffcf000000bf88 0008 0000 0x0 0x0
0xffffcf000000c000 0008 0000 0x0 0x0
0xffffcf000000c078 0008 0000 0x0 0x0
0xffffcf000000c0f0 0008 0000 0x0 0x0
0xffffcf000000c168 0008 0000 0x0 0x0
0xffffcf000000c1e0 0008 0000 0x0 0x0
0xffffcf000000c258 0008 0000 0x0 0x0
0xffffcf000000c2d0 0008 0000 0x0 0x0
0xffffcf000000c348 0008 0000 0x0 0x0
0xffffcf000000c3c0 0008 0000 0x0 0x0
0xffffcf000000c438 0008 0000 0x0 0x0
0xffffcf000000c4b0 0008 0000 0x0 0x0
0xffffcf000000c528 0008 0000 0x0 0x0
0xffffcf000000c5a0 0008 0000 0x0 0x0
0xffffcf000000c618 0008 0000 0x0 0x0
0xffffcf000000c690 0008 0000 0x0 0x0
0xffffcf000000c708 0008 0000 0x0 0x0
0xffffcf000000c780 0008 0000 0x0 0x0
0xffffcf000000c7f8 0008 0000 0x0 0x0
0xffffcf000000c870 0008 0000 0x0 0x0
0xffffcf000000c8e8 0008 0000 0x0 0x0
0xffffcf000000c960 0008 0000 0x0 0x0
0xffffcf000000c9d8 0008 0000 0x0 0x0
0xffffcf000000ca50 0008 0000 0x0 0x0
0xffffcf000000cac8 0008 0000 0x0 0x0
0xffffcf000000cb40 0008 0000 0x0 0x0
0xffffcf000000cbb8 0008 0000 0x0 0x0
0xffffcf000000cc30 0008 0000 0x0 0x0
0xffffcf000000cca8 0008 0000 0x0 0x0
0xffffcf000000cd20 0008 0000 0x0 0x0
0xffffcf000000cd98 0008 0000 0x0 0x0
0xffffcf000000ce10 0008 0000 0x0 0x0
0xffffcf000000ce88 0008 0000 0x0 0x0
0xffffcf000000cf00 0008 0000 0x0 0x0
0xffffcf000000cf78 0008 0000 0x0 0x0
0xffffcf000000cff0 0008 0000 0x0 0x0
0xffffcf000000d068 0008 0000 0x0 0x0
0xffffcf000000d0e0 0008 0000 0x0 0x0
0xffffcf000000d158 0008 0000 0x0 0x0
0xffffcf000000d1d0 0008 0000 0x0 0x0
0xffffcf000000d248 0008 0000 0x0 0x0
0xffffcf000000d2c0 0008 0000 0x0 0x0
0xffffcf000000d338 0008 0000 0x0 0x0
0xffffcf000000d3b0 0008 0000 0x0 0x0
0xffffcf000000d428 0008 0000 0x0 0x0
0xffffcf000000d4a0 0008 0000 0x0 0x0
0xffffcf000000d518 0008 0000 0x0 0x0
0xffffcf000000d590 0048 0000 0x0 0x0
0xffffcf000000d608 0048 0000 0x0 0x0
0xffffcf000000d680 0048 0000 0x0 0x0
0xffffcf000000d6f8 0048 0000 0x0 0x0
0xffffcf000000d770 0048 0000 0x0 0x0
0xffffcf000000d7e8 0048 0000 0x0 0x0
0xffffcf000000d860 0048 0000 0x0 0x0
0xffffcf000000d8d8 0048 0000 0x0 0x0
0xffffcf000000d950 0048 0000 0x0 0x0
0xffffcf000000d9c8 0048 0000 0x0 0x0
0xffffcf000000da40 0048 0000 0x0 0x0
0xffffcf000000dab8 0048 0000 0x0 0x0
0xffffcf000000db30 0048 0000 0x0 0x0
0xffffcf000000dba8 0048 0000 0x0 0x0
0xffffcf000000dc20 0048 0000 0x0 0x0
0xffffcf000000dc98 0048 0000 0x0 0x0
0xffffcf000000dd10 0048 0000 0x0 0x0
0xffffcf000000dd88 0048 0000 0x0 0x0
0xffffcf000000de00 0048 0000 0x0 0x0
0xffffcf000000de78 0048 0000 0x0 0x0
0xffffcf000000def0 0048 0000 0x0 0x0
0xffffcf000000df68 0048 0000 0x0 0x0
0xffffcf000000dfe0 0048 0000 0x0 0x0
0xffffcf000000e058 0048 0000 0x0 0x0
0xffffcf000000e0d0 0048 0000 0x0 0x0
0xffffcf000000e148 0048 0000 0x0 0x0
0xffffcf000000e1c0 0048 0000 0x0 0x0
0xffffcf000000e238 0048 0000 0x0 0x0
0xffffcf000000e2b0 0048 0000 0x0 0x0
0xffffcf000000e328 0048 0000 0x0 0x0
0xffffcf000000e3a0 0048 0000 0x0 0x0
0xffffcf000000e418 0048 0000 0x0 0x0
0xffffcf000000e490 0048 0000 0x0 0x0
0xffffcf000000e508 0048 0000 0x0 0x0
0xffffcf000000e580 0048 0000 0x0 0x0
0xffffcf000000e5f8 0048 0000 0x0 0x0
0xffffcf000000e670 0048 0000 0x0 0x0
0xffffcf000000e6e8 0048 0000 0x0 0x0
0xffffcf000000e760 0048 0000 0x0 0x0
0xffffcf000000e7d8 0048 0000 0x0 0x0
0xffffcf000000e850 0048 0000 0x0 0x0
0xffffcf000000e8c8 0048 0000 0x0 0x0
0xffffcf000000e940 0048 0000 0x0 0x0
0xffffcf000000e9b8 0008 0000 0x0 0x0
0xffffcf000000ea30 0008 0000 0x0 0x0
0xffffcf000000eaa8 0008 0000 0x0 0x0
0xffffcf000000eb20 0008 0000 0x0 0x0
0xffffcf000000eb98 0008 0000 0x0 0x0
0xffffcf000000ec10 0008 0000 0x0 0x0
0xffffcf000000ec88 0008 0000 0x0 0x0
0xffffcf000000ed00 0008 0000 0x0 0x0
0xffffcf000000ed78 0008 0000 0x0 0x0
0xffffcf000000edf0 0008 0000 0x0 0x0
0xffffcf000000ee68 0008 0000 0x0 0x0
0xffffcf000000eee0 0008 0000 0x0 0x0
0xffffcf000000ef58 0008 0000 0x0 0x0
0xffffcf000000efd0 0008 0000 0x0 0x0
0xffffcf000000f048 0008 0000 0x0 0x0
0xffffcf000000f0c0 0008 0000 0x0 0x0
0xffffcf000000f138 0008 0000 0x0 0x0
0xffffcf000000f1b0 0008 0000 0x0 0x0
0xffffcf000000f228 0008 0000 0x0 0x0
0xffffcf000000f2a0 0008 0000 0x0 0x0
0xffffcf000000f318 0008 0000 0x0 0x0
0xffffcf000000f390 0008 0000 0x0 0x0
0xffffcf000000f408 0008 0000 0x0 0x0
0xffffcf000000f480 0008 0000 0x0 0x0
0xffffcf000000f4f8 0008 0000 0x0 0x0
0xffffcf000000f570 0008 0000 0x0 0x0
0xffffcf000000f5e8 0008 0000 0x0 0x0
0xffffcf000000f660 0008 0000 0x0 0x0
0xffffcf000000f6d8 0008 0000 0x0 0x0
0xffffcf000000f750 0008 0000 0x0 0x0
0xffffcf000000f7c8 0008 0000 0x0 0x0
0xffffcf000000f840 0008 0000 0x0 0x0
0xffffcf000000f8b8 0008 0000 0x0 0x0
0xffffcf000000f930 0008 0000 0x0 0x0
0xffffcf000000f9a8 0008 0000 0x0 0x0
0xffffcf000000fa20 0008 0000 0x0 0x0
0xffffcf000000fa98 0008 0000 0x0 0x0
0xffffcf000000fb10 0008 0000 0x0 0x0
0xffffcf000000fb88 0008 0000 0x0 0x0
0xffffcf000000fc00 0008 0000 0x0 0x0
0xffffcf000000fc78 0008 0000 0x0 0x0
0xffffcf000000fcf0 0008 0000 0x0 0x0
0xffffcf000000fd68 0008 0000 0x0 0x0
0xffffcf000000fde0 0008 0000 0x0 0x0
0xffffcf000000fe58 0008 0000 0x0 0x0
0xffffcf000000fed0 0008 0000 0x0 0x0
0xffffcf000000ff48 0008 0000 0x0 0x0
0xffffcf000000ffc0 0008 0000 0x0 0x0
0xffffcf0000010038 0008 0000 0x0 0x0
0xffffcf00000100b0 0008 0000 0x0 0x0
0xffffcf0000010128 0008 0000 0x0 0x0
0xffffcf00000101a0 0008 0000 0x0 0x0
0xffffcf0000010218 0008 0000 0x0 0x0
0xffffcf0000010290 0008 0000 0x0 0x0
0xffffcf0000010308 0048 0000 0x0 0x0
0xffffcf0000010380 0048 0000 0x0 0x0
0xffffcf00000103f8 0048 0000 0x0 0x0
0xffffcf0000010470 0048 0000 0x0 0x0
0xffffcf00000104e8 0048 0000 0x0 0x0
0xffffcf0000010560 0048 0000 0x0 0x0
0xffffcf00000105d8 0048 0000 0x0 0x0
0xffffcf0000010650 0048 0000 0x0 0x0
0xffffcf00000106c8 0048 0000 0x0 0x0
0xffffcf0000010740 0048 0000 0x0 0x0
0xffffcf00000107b8 0048 0000 0x0 0x0
0xffffcf0000010830 0048 0000 0x0 0x0
0xffffcf00000108a8 0048 0000 0x0 0x0
0xffffcf0000010920 0048 0000 0x0 0x0
0xffffcf0000010998 0048 0000 0x0 0x0
0xffffcf0000010a10 0048 0000 0x0 0x0
0xffffcf0000010a88 0048 0000 0x0 0x0
0xffffcf0000010b00 0048 0000 0x0 0x0
0xffffcf0000010b78 0048 0000 0x0 0x0
0xffffcf0000010bf0 0048 0000 0x0 0x0
0xffffcf0000010c68 0048 0000 0x0 0x0
0xffffcf0000010ce0 0049 0000 0x0 0x0
0xffffcf0000010d58 0048 0000 0x0 0x0
0xffffcf0000010dd0 0048 0000 0x0 0x0
0xffffcf0000010e48 0048 0000 0x0 0x0
0xffffcf0000010ec0 0048 0000 0x0 0x0
0xffffcf0000010f38 0048 0000 0x0 0x0
0xffffcf0000010fb0 0048 0000 0x0 0x0
0xffffcf0000011028 0048 0000 0x0 0x0
0xffffcf00000110a0 0049 0000 0x0 0x0
0xffffcf0000011118 0049 0000 0x0 0x0
0xffffcf0000011190 0048 0000 0x0 0x0
0xffffcf0000011208 0048 0000 0x0 0x0
0xffffcf0000011280 0048 0000 0x0 0x0
0xffffcf00000112f8 0048 0000 0x0 0x0
0xffffcf0000011370 0048 0000 0x0 0x0
0xffffcf00000113e8 0048 0000 0x0 0x0
0xffffcf0000011460 0049 0000 0x0 0x0
0xffffcf00000114d8 0049 0000 0x0 0x0
0xffffcf0000011550 0048 0000 0x0 0x0
0xffffcf00000115c8 0048 0000 0x0 0x0
0xffffcf0000011640 0048 0000 0x0 0x0
0xffffcf00000116b8 0049 0000 0x0 0x0
0xffffcf0000011730 0048 0000 0x0 0x0
0xffffcf00000117a8 0049 0000 0x0 0x0
0xffffcf0000011820 0049 0000 0x0 0x0
0xffffcf0000011898 0049 0000 0x0 0x0
0xffffcf0000011910 0048 0000 0x0 0x0
0xffffcf0000011988 0008 0000 0x0 0x0
0xffffcf0000011a00 0008 0000 0x0 0x0
0xffffcf0000011a78 0008 0000 0x0 0x0
0xffffcf0000011af0 0008 0000 0x0 0x0
0xffffcf0000011b68 0008 0000 0x0 0x0
0xffffcf0000011be0 0008 0000 0x0 0x0
0xffffcf0000011c58 0008 0000 0x0 0x0
0xffffcf0000011cd0 0008 0000 0x0 0x0
0xffffcf0000011d48 0008 0000 0x0 0x0
0xffffcf0000011dc0 0008 0000 0x0 0x0
0xffffcf0000011e38 0008 0000 0x0 0x0
0xffffcf0000011eb0 0008 0000 0x0 0x0
0xffffcf0000011f28 0008 0000 0x0 0x0
0xffffcf0000011fa0 0008 0000 0x0 0x0
0xffffcf0000012018 0008 0000 0x0 0x0
0xffffcf0000012090 0008 0000 0x0 0x0
0xffffcf0000012108 0008 0000 0x0 0x0
0xffffcf0000012180 0008 0000 0x0 0x0
0xffffcf00000121f8 0008 0000 0x0 0x0
0xffffcf0000012270 0008 0000 0x0 0x0
0xffffcf00000122e8 0008 0000 0x0 0x0
0xffffcf0000012360 0008 0000 0x0 0x0
0xffffcf00000123d8 0008 0000 0x0 0x0
0xffffcf0000012450 0008 0000 0x0 0x0
0xffffcf00000124c8 0008 0000 0x0 0x0
0xffffcf0000012540 0008 0000 0x0 0x0
0xffffcf00000125b8 0008 0000 0x0 0x0
0xffffcf0000012630 0008 0000 0x0 0x0
0xffffcf00000126a8 0008 0000 0x0 0x0
0xffffcf0000012720 0008 0000 0x0 0x0
0xffffcf0000012798 0008 0000 0x0 0x0
0xffffcf0000012810 0008 0000 0x0 0x0
0xffffcf0000012888 0008 0000 0x0 0x0
0xffffcf0000012900 0008 0000 0x0 0x0
0xffffcf0000012978 0008 0000 0x0 0x0
0xffffcf00000129f0 0008 0000 0x0 0x0
0xffffcf0000012a68 0008 0000 0x0 0x0
0xffffcf0000012ae0 0008 0000 0x0 0x0
0xffffcf0000012b58 0008 0000 0x0 0x0
0xffffcf0000012bd0 0008 0000 0x0 0x0
0xffffcf0000012c48 0008 0000 0x0 0x0
0xffffcf0000012cc0 0008 0000 0x0 0x0
0xffffcf0000012d38 0008 0000 0x0 0x0
0xffffcf0000012db0 0008 0000 0x0 0x0
0xffffcf0000012e28 0008 0000 0x0 0x0
0xffffcf0000012ea0 0008 0000 0x0 0x0
0xffffcf0000012f18 0008 0000 0x0 0x0
0xffffcf0000012f90 0008 0000 0x0 0x0
0xffffcf0000013008 0008 0000 0x0 0x0
0xffffcf0000013080 0008 0000 0x0 0x0
0xffffcf00000130f8 0008 0000 0x0 0x0
0xffffcf0000013170 0008 0000 0x0 0x0
0xffffcf00000131e8 0008 0000 0x0 0x0
0xffffcf0000013260 0008 0000 0x0 0x0
0xffffcf00000132d8 0008 0000 0x0 0x0
0xffffcf0000013350 0008 0000 0x0 0x0
0xffffcf00000133c8 0008 0000 0x0 0x0
0xffffcf0000013440 0008 0000 0x0 0x0
0xffffcf00000134b8 0008 0000 0x0 0x0
0xffffcf0000013530 0008 0000 0x0 0x0
0xffffcf00000135a8 0008 0000 0x0 0x0
0xffffcf0000013620 0008 0000 0x0 0x0
0xffffcf0000013698 0008 0000 0x0 0x0
0xffffcf0000013710 0008 0000 0x0 0x0
0xffffcf0000013788 0008 0000 0x0 0x0
0xffffcf0000013800 0008 0000 0x0 0x0
0xffffcf0000013878 0008 0000 0x0 0x0
0xffffcf00000138f0 0008 0000 0x0 0x0
0xffffcf0000013968 0008 0000 0x0 0x0
0xffffcf00000139e0 0008 0000 0x0 0x0
0xffffcf0000013a58 0008 0000 0x0 0x0
0xffffcf0000013ad0 0008 0000 0x0 0x0
0xffffcf0000013b48 0008 0000 0x0 0x0
0xffffcf0000013bc0 0008 0000 0x0 0x0
0xffffcf0000013c38 0008 0000 0x0 0x0
0xffffcf0000013cb0 0008 0000 0x0 0x0
0xffffcf0000013d28 0008 0000 0x0 0x0
0xffffcf0000013da0 0008 0000 0x0 0x0
0xffffcf0000013e18 0008 0000 0x0 0x0
0xffffcf0000013e90 0008 0000 0x0 0x0
0xffffcf0000013f08 0008 0000 0x0 0x0
0xffffcf0000013f80 0008 0000 0x0 0x0
0xffffcf0000013ff8 0008 0000 0x0 0x0
0xffffcf0000014070 0008 0000 0x0 0x0
0xffffcf00000140e8 0008 0000 0x0 0x0
0xffffcf0000014160 0008 0000 0x0 0x0
0xffffcf00000141d8 0008 0000 0x0 0x0
0xffffcf0000014250 0008 0000 0x0 0x0
0xffffcf00000142c8 0008 0000 0x0 0x0
0xffffcf0000014340 0008 0000 0x0 0x0
0xffffcf00000143b8 0008 0000 0x0 0x0
0xffffcf0000014430 0008 0000 0x0 0x0
0xffffcf00000144a8 0008 0000 0x0 0x0
0xffffcf0000014520 0008 0000 0x0 0x0
0xffffcf0000014598 0008 0000 0x0 0x0
0xffffcf0000014610 0008 0000 0x0 0x0
0xffffcf0000014688 0008 0000 0x0 0x0
0xffffcf0000014700 0008 0000 0x0 0x0
0xffffcf0000014778 0008 0000 0x0 0x0
0xffffcf00000147f0 0008 0000 0x0 0x0
0xffffcf0000014868 0008 0000 0x0 0x0
0xffffcf00000148e0 0008 0000 0x0 0x0
0xffffcf0000014958 0008 0000 0x0 0x0
0xffffcf00000149d0 0008 0000 0x0 0x0
0xffffcf0000014a48 0008 0000 0x0 0x0
0xffffcf0000014ac0 0008 0000 0x0 0x0
0xffffcf0000014b38 0008 0000 0x0 0x0
0xffffcf0000014bb0 0008 0000 0x0 0x0
0xffffcf0000014c28 0008 0000 0x0 0x0
0xffffcf0000014ca0 0008 0000 0x0 0x0
0xffffcf0000014d18 0008 0000 0x0 0x0
0xffffcf0000014d90 0008 0000 0x0 0x0
0xffffcf0000014e08 0008 0000 0x0 0x0
0xffffcf0000014e80 0008 0000 0x0 0x0
0xffffcf0000014ef8 0008 0000 0x0 0x0
0xffffcf0000014f70 0008 0000 0x0 0x0
0xffffcf0000014fe8 0008 0000 0x0 0x0
0xffffcf0000015060 0008 0000 0x0 0x0
0xffffcf00000150d8 0008 0000 0x0 0x0
0xffffcf0000015150 0008 0000 0x0 0x0
0xffffcf00000151c8 0008 0000 0x0 0x0
0xffffcf0000015240 0008 0000 0x0 0x0
0xffffcf00000152b8 0008 0000 0x0 0x0
0xffffcf0000015330 0008 0000 0x0 0x0
0xffffcf00000153a8 0008 0000 0x0 0x0
0xffffcf0000015420 0008 0000 0x0 0x0
0xffffcf0000015498 0008 0000 0x0 0x0
0xffffcf0000015510 0008 0000 0x0 0x0
0xffffcf0000015588 0008 0000 0x0 0x0
0xffffcf0000015600 0008 0000 0x0 0x0
0xffffcf0000015678 0008 0000 0x0 0x0
0xffffcf00000156f0 0008 0000 0x0 0x0
0xffffcf0000015768 0008 0000 0x0 0x0
0xffffcf00000157e0 0008 0000 0x0 0x0
0xffffcf0000015858 0008 0000 0x0 0x0
0xffffcf00000158d0 0008 0000 0x0 0x0
0xffffcf0000015948 0008 0000 0x0 0x0
0xffffcf00000159c0 0008 0000 0x0 0x0
0xffffcf0000015a38 0008 0000 0x0 0x0
0xffffcf0000015ab0 0008 0000 0x0 0x0
0xffffcf0000015b28 0008 0000 0x0 0x0
0xffffcf0000015ba0 0008 0000 0x0 0x0
0xffffcf0000015c18 0008 0000 0x0 0x0
0xffffcf0000015c90 0008 0000 0x0 0x0
0xffffcf0000015d08 0008 0000 0x0 0x0
0xffffcf0000015d80 0008 0000 0x0 0x0
0xffffcf0000015df8 0008 0000 0x0 0x0
0xffffcf0000015e70 0008 0000 0x0 0x0
0xffffcf0000015ee8 0008 0000 0x0 0x0
0xffffcf0000015f60 0008 0000 0x0 0x0
0xffffcf0000015fd8 0008 0000 0x0 0x0
0xffffcf0000016050 0008 0000 0x0 0x0
0xffffcf00000160c8 0008 0000 0x0 0x0
0xffffcf0000016140 0008 0000 0x0 0x0
0xffffcf00000161b8 0008 0000 0x0 0x0
0xffffcf0000016230 0008 0000 0x0 0x0
0xffffcf00000162a8 0008 0000 0x0 0x0
0xffffcf0000016320 0008 0000 0x0 0x0
0xffffcf0000016398 0008 0000 0x0 0x0
0xffffcf0000016410 0008 0000 0x0 0x0
0xffffcf0000016488 0008 0000 0x0 0x0
0xffffcf0000016500 0008 0000 0x0 0x0
0xffffcf0000016578 0008 0000 0x0 0x0
0xffffcf00000165f0 0008 0000 0x0 0x0
0xffffcf0000016668 0008 0000 0x0 0x0
0xffffcf00000166e0 0008 0000 0x0 0x0
0xffffcf0000016758 0008 0000 0x0 0x0
0xffffcf00000167d0 0008 0000 0x0 0x0
0xffffcf0000016848 0008 0000 0x0 0x0
0xffffcf00000168c0 0008 0000 0x0 0x0
0xffffcf0000016938 0008 0000 0x0 0x0
0xffffcf00000169b0 0008 0000 0x0 0x0
0xffffcf0000016a28 0008 0000 0x0 0x0
0xffffcf0000016aa0 0008 0000 0x0 0x0
0xffffcf0000016b18 0008 0000 0x0 0x0
0xffffcf0000016b90 0008 0000 0x0 0x0
0xffffcf0000016c08 0008 0000 0x0 0x0
0xffffcf0000016c80 0008 0000 0x0 0x0
0xffffcf0000016cf8 0008 0000 0x0 0x0
0xffffcf0000016d70 0008 0000 0x0 0x0
0xffffcf0000016de8 0008 0000 0x0 0x0
0xffffcf0000016e60 0008 0000 0x0 0x0
0xffffcf0000016ed8 0008 0000 0x0 0x0
0xffffcf0000016f50 0008 0000 0x0 0x0
0xffffcf0000016fc8 0008 0000 0x0 0x0
0xffffcf0000017040 0008 0000 0x0 0x0
0xffffcf00000170b8 0008 0000 0x0 0x0
0xffffcf0000017130 0008 0000 0x0 0x0
0xffffcf00000171a8 0008 0000 0x0 0x0
0xffffcf0000017220 0008 0000 0x0 0x0
0xffffcf0000017298 0008 0000 0x0 0x0
0xffffcf0000017310 0008 0000 0x0 0x0
0xffffcf0000017388 0008 0000 0x0 0x0
0xffffcf0000017400 0008 0000 0x0 0x0
0xffffcf0000017478 0008 0000 0x0 0x0
0xffffcf00000174f0 0008 0000 0x0 0x0
0xffffcf0000017568 0008 0000 0x0 0x0
0xffffcf00000175e0 0008 0000 0x0 0x0
0xffffcf0000017658 0008 0000 0x0 0x0
0xffffcf00000176d0 0008 0000 0x0 0x0
0xffffcf0000017748 0008 0000 0x0 0x0
0xffffcf00000177c0 0008 0000 0x0 0x0
0xffffcf0000017838 0008 0000 0x0 0x0
0xffffcf00000178b0 0008 0000 0x0 0x0
0xffffcf0000017928 0008 0000 0x0 0x0
0xffffcf00000179a0 0008 0000 0x0 0x0
0xffffcf0000017a18 0008 0000 0x0 0x0
0xffffcf0000017a90 0008 0000 0x0 0x0
0xffffcf0000017b08 0008 0000 0x0 0x0
0xffffcf0000017b80 0008 0000 0x0 0x0
0xffffcf0000017bf8 0008 0000 0x0 0x0
0xffffcf0000017c70 0008 0000 0x0 0x0
0xffffcf0000017ce8 0008 0000 0x0 0x0
0xffffcf0000017d60 0008 0000 0x0 0x0
0xffffcf0000017dd8 0008 0000 0x0 0x0
0xffffcf0000017e50 0008 0000 0x0 0x0
0xffffcf0000017ec8 0008 0000 0x0 0x0
0xffffcf0000017f40 0008 0000 0x0 0x0
0xffffcf0000017fb8 0008 0000 0x0 0x0
0xffffcf0000018030 0008 0000 0x0 0x0
0xffffcf00000180a8 0008 0000 0x0 0x0
0xffffcf0000018120 0008 0000 0x0 0x0
0xffffcf0000018198 0008 0000 0x0 0x0
0xffffcf0000018210 0008 0000 0x0 0x0
0xffffcf0000018288 0008 0000 0x0 0x0
0xffffcf0000018300 0008 0000 0x0 0x0
0xffffcf0000018378 0008 0000 0x0 0x0
0xffffcf00000183f0 0008 0000 0x0 0x0
0xffffcf0000018468 0008 0000 0x0 0x0
0xffffcf00000184e0 0008 0000 0x0 0x0
0xffffcf0000018558 0008 0000 0x0 0x0
0xffffcf00000185d0 0008 0000 0x0 0x0
0xffffcf0000018648 0008 0000 0x0 0x0
0xffffcf00000186c0 0008 0000 0x0 0x0
0xffffcf0000018738 0008 0000 0x0 0x0
0xffffcf00000187b0 0008 0000 0x0 0x0
0xffffcf0000018828 0008 0000 0x0 0x0
0xffffcf00000188a0 0008 0000 0x0 0x0
0xffffcf0000018918 0008 0000 0x0 0x0
0xffffcf0000018990 0008 0000 0x0 0x0
0xffffcf0000018a08 0008 0000 0x0 0x0
0xffffcf0000018a80 0008 0000 0x0 0x0
0xffffcf0000018af8 0008 0000 0x0 0x0
0xffffcf0000018b70 0008 0000 0x0 0x0
0xffffcf0000018be8 0008 0000 0x0 0x0
0xffffcf0000018c60 0008 0000 0x0 0x0
0xffffcf0000018cd8 0008 0000 0x0 0x0
0xffffcf0000018d50 0008 0000 0x0 0x0
0xffffcf0000018dc8 0008 0000 0x0 0x0
0xffffcf0000018e40 0008 0000 0x0 0x0
0xffffcf0000018eb8 0008 0000 0x0 0x0
0xffffcf0000018f30 0008 0000 0x0 0x0
0xffffcf0000018fa8 0008

---
This bug is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this bug report. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

Chuck Silvers

unread,
Oct 10, 2019, 1:21:05 PM10/10/19
to syzbot, syzkaller-...@googlegroups.com
#syz fix: simpler fix for the race between shmat() and shmdt():

Maxime Villard

unread,
Oct 10, 2019, 2:11:29 PM10/10/19
to Chuck Silvers, syzbot, syzkaller-...@googlegroups.com
Le 10/10/2019 à 19:21, Chuck Silvers a écrit :
> #syz fix: simpler fix for the race between shmat() and shmdt():

You must unwrap the first line entirely. Besides, this issue was found and
fixed before syzbot reported it, so:

#syz invalid
Reply all
Reply to author
Forward
0 new messages