ASan: Unauthorized Access in uiomove

0 views
Skip to first unread message

Taylor R Campbell

unread,
May 9, 2023, 11:56:27 AM5/9/23
to syzbot+e0f561...@syzkaller.appspotmail.com, syzkaller-...@googlegroups.com
ktrdebug.patch

syzbot

unread,
May 9, 2023, 12:36:33 PM5/9/23
to rias...@netbsd.org, syzkaller-...@googlegroups.com
Hello,

syzbot has tested the proposed patch but the reproducer is still triggering an issue:
panic: keOrnel diHsyz-agnexecprogo5vZdQstic%

� syz-execprog 4vZd �� , ( � syz-execprog 4vZd �� + ����� ܺ G I syz-executor.5 5vZd �4 � � @ I syz-executor.5 5vZd �A � . � .. � file0 � syz-execprog 5vZd �E " � I syz-executor.5 5vZd �L ( P syz-executor.0 5vZd �L � ����� ܺ G P syz-exec[ utor.0 6 5vZd1.8439892] panic: ke �O rnel d � � iH � syz-agnexecprog o5vZd �Q sti c % as����� ܺ G sertion " r e2 � s id == 0 " � syz- failed: fexecprog ile "/s5vZd �W yzkall er� H � /jobs-2/netsbyz-execprog sd/kerne l 5vZd d /sy s/ kern/kern_ktrace.c" ����� ܺ G , 2 � l i H P snyz-executor.0 e 1347 io 5vZd vcnt=1 resid=76; total=88 loopcount=0 zzzcount=1
[ 61.8638227] cpu1: Begin traceback...
[ 61.8738411] vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:292
[ 61.8938452] _sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x6bd2
[ 61.9138456] ktrwrite() at netbsd:ktrwrite+0x6db sys/kern/kern_ktrace.c:1347
[ 61.9338522] ktrace_thread() at netbsd:ktrace_thread+0xfe sys/kern/kern_ktrace.c:1426
[ 61.9438405] cpu1: End traceback...
[ 61.9438405] fatal breakpoint trap in supervisor mode
[ 61.9438405] trap type 1 code 0 rip 0xffffffff8023241d cs 0x8 rflags 0x282 cr2 0x20001640 ilevel 0 rsp 0xffffcd82482007b0
[ 61.9638077] curlwp 0xffffcd8013dc5300 pid 0.1367 lowest kstack 0xffffcd82481f92c0
Stopped in pid 0.1367 (system) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0x105 sys/ddb/db_panic.c:69
vpanic() at netbsd:vpanic+0x282 sys/kern/subr_prf.c:292
_sub_D_65535_0() at netbsd:_sub_D_65535_0+-0x6bd2
ktrwrite() at netbsd:ktrwrite+0x6db sys/kern/kern_ktrace.c:1347
ktrace_thread() at netbsd:ktrace_thread+0xfe sys/kern/kern_ktrace.c:1426
Panic string: kernel diagnostic assertion "resid == 0" failed: file "/syzkaller/jobs-2/netbsd/kernel/sys/kern/kern_ktrace.c", line 1347 iovcnt=1 resid=76; total=88 loopcount=0 zzzcount=1
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
1118 1118 2 1 0 ffffcd8013dd3bc0 syz-executor.0
1357 1357 3 0 40180 ffffcd8013d79b00 syz-executor.4 pipe_rd
1115 1369 2 1 100 ffffcd8013dd3340 syz-executor.1
1115 1115 2 1 10040000 ffffcd8013d796c0 syz-executor.1
1247 577 5 0 100100 ffffcd8013dc5b80 syz-executor.3
1247 1247 3 0 10040000 ffffcd8013d79280 syz-executor.3 xclocv
325 325 2 1 40000 ffffcd8013d54ac0 syz-executor.2
336 336 2 1 40000 ffffcd8013d54680 syz-executor.0
1353 1353 2 1 40 ffffcd8013d54240 syz-executor.5
1211 1211 2 1 140 ffffcd8012b99580 syz-executor.3
1354 1354 2 1 140 ffffcd8012b99140 syz-executor.1
1206 1372 3 1 180 ffffcd8012bf8600 syz-execprog parked
1206 1238 2 1 100 ffffcd8013dc5740 syz-execprog
1206 1208 3 0 180 ffffcd8013d972c0 syz-execprog parked
1206 1204 3 1 180 ffffcd8012b999c0 syz-execprog wait
1206 1312 3 0 180 ffffcd8012bcba00 syz-execprog wait
1206 332 3 1 180 ffffcd8012bcb5c0 syz-execprog wait
1206 331 3 0 180 ffffcd8012bcb180 syz-execprog wait
1206 1210 3 1 180 ffffcd8012c38280 syz-execprog parked
1206 1207 3 0 180 ffffcd8012acf940 syz-execprog parked
1206 1073 3 0 180 ffffcd8012acf500 syz-execprog parked
1206 1214 3 1 180 ffffcd8012b7a980 syz-execprog wait
1206 1323 3 1 180 ffffcd8012b7a540 syz-execprog parked
1206 1206 3 0 40180 ffffcd8012c5a2c0 syz-execprog wait
1209 1209 3 0 180 ffffcd80126eabc0 sshd select
1257 1257 3 1 180 ffffcd80126eb480 getty nanoslp
1223 1223 3 1 180 ffffcd80134929c0 getty nanoslp
1151 1151 3 1 180 ffffcd80134ac5c0 getty nanoslp
1222 1222 3 1 1c0 ffffcd80134ac180 getty ttyraw
1107 1107 3 0 180 ffffcd80133b0600 sshd select
1088 1088 3 0 180 ffffcd8012d48b80 powerd kqueue
700 700 3 1 180 ffffcd801342bb40 syslogd kqueue
746 746 3 0 180 ffffcd8012c38b00 dhcpcd poll
747 747 3 0 180 ffffcd8012cc4500 dhcpcd poll
742 742 3 0 180 ffffcd8012c94bc0 dhcpcd poll
602 602 3 1 180 ffffcd8012c386c0 dhcpcd poll
292 292 3 0 180 ffffcd8012dad900 dhcpcd poll
485 485 3 0 180 ffffcd8012dad4c0 dhcpcd poll
291 291 3 0 180 ffffcd8012dad080 dhcpcd poll
1 1 3 0 180 ffffcd8012878180 init wait
0 1070 3 1 200 ffffcd8013dd3780 ktrace ktrwait
0 >1367 7 1 240 ffffcd8013dc5300 ktrace
0 557 3 0 200 ffffcd80129a16c0 physiod physiod
0 196 3 1 200 ffffcd80129a3700 pooldrain pooldrain
0 > 195 7 0 240 ffffcd80129a32c0 ioflush
0 194 3 1 200 ffffcd80129a1b00 pgdaemon pgdaemon
0 167 3 1 200 ffffcd8012961ac0 usb7 usbevt
0 172 3 1 200 ffffcd8012961680 usb6 usbevt
0 170 3 1 200 ffffcd8012961240 usb5 usbevt
0 168 3 1 200 ffffcd8012915a80 usb4 usbevt
0 166 3 1 200 ffffcd8012915640 usb3 usbevt
0 165 3 0 200 ffffcd8012915200 usb2 usbevt
0 31 3 0 200 ffffcd80128d9a40 usb1 usbevt
0 63 3 1 200 ffffcd80128d9600 usb0 usbevt
0 126 3 0 200 ffffcd80128d91c0 usbtask-dr usbtsk
0 125 3 1 200 ffffcd8012878a00 usbtask-hc usbtsk
0 124 3 0 200 ffffcd8010d76b00 swwreboot swwreboot
0 123 3 0 200 ffffcd80128785c0 npfgc0 npfgcw
0 122 3 0 200 ffffcd801286a9c0 rt_free rt_free
0 121 3 0 200 ffffcd801286a580 unpgc unpgc
0 120 3 1 200 ffffcd801286a140 key_timehandler key_timehandler
0 119 3 1 200 ffffcd801271b980 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 ffffcd801271b540 icmp6_wqinput/0 icmp6_wqinput
0 117 3 0 200 ffffcd801271b100 nd6_timer nd6_timer
0 116 3 1 200 ffffcd8012713940 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 ffffcd8012713500 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 ffffcd80127130c0 carp_wqinput/1 carp_wqinput
0 113 3 0 200 ffffcd8012703900 carp_wqinput/0 carp_wqinput
0 112 3 1 200 ffffcd80127034c0 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 ffffcd8012703080 icmp_wqinput/0 icmp_wqinput
0 110 3 0 200 ffffcd80126eb8c0 rt_timer rt_timer
0 109 3 0 200 ffffcd80126eb040 vmem_rehash vmem_rehash
0 100 3 0 200 ffffcd80126e7300 entbutler entropy
0 99 3 1 200 ffffcd80120bcb40 viomb balloon
0 98 3 1 200 ffffcd80120bc700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 ffffcd80120bc2c0 vioif0_txrx/0 vioif0_txrx
0 30 3 0 200 ffffcd8010d766c0 scsibus0 sccomp
0 29 3 0 200 ffffcd8010d76280 pms0 pmsreset
0 28 2 1 200 ffffcd8010cbcac0 xcall/1
0 27 1 1 200 ffffcd8010cbc680 softser/1
0 26 1 1 200 ffffcd8010cbc240 softclk/1
0 25 1 1 200 ffffcd8010cb9a80 softbio/1
0 24 1 1 200 ffffcd8010cb9640 softnet/1
0 23 1 1 201 ffffcd8010cb9200 idle/1
0 22 3 0 200 ffffcd800fb56a40 lnxsyswq lnxsyswq
0 21 3 0 200 ffffcd800fb56600 lnxubdwq lnxubdwq
0 20 3 0 200 ffffcd800fb561c0 lnxpwrwq lnxpwrwq
0 19 3 0 200 ffffcd800fb55a00 lnxlngwq lnxlngwq
0 18 3 0 200 ffffcd800fb555c0 lnxhipwq lnxhipwq
0 17 3 0 200 ffffcd800fb55180 lnxrcugc lnxrcugc
0 16 3 0 200 ffffcd800fb4e9c0 sysmon smtaskq
0 15 3 0 200 ffffcd800fb4e580 pmfsuspend pmfsuspend
0 14 3 0 200 ffffcd800fb4e140 pmfevent pmfevent
0 13 3 0 200 ffffcd800fb49980 sopendfree sopendfr
0 12 3 0 200 ffffcd800fb49540 ifwdog ifwdog
0 11 3 0 200 ffffcd800fb49100 iflnkst iflnkst
0 10 3 0 200 ffffcd800fb3c940 nfssilly nfssilly
0 9 3 0 200 ffffcd800fb3c500 vdrain vdrain
0 8 3 1 200 ffffcd800fb3c0c0 modunload mod_unld
0 7 3 0 200 ffffcd800fb33900 xcall/0 xcall
0 6 1 0 200 ffffcd800fb334c0 softser/0
0 5 1 0 200 ffffcd800fb33080 softclk/0
0 4 1 0 200 ffffcd800fb318c0 softbio/0
0 3 1 0 200 ffffcd800fb31480 softnet/0
0 2 1 0 201 ffffcd800fb31040 idle/0
0 0 3 0 200 ffffffff8334b340 swapper uvm
[Locks tracked through LWPs]

****** LWP 1357.1357 (syz-executor.4) @ 0xffffcd8013d79b00, l_stat=3

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1376)
lock address : ffffcd8013d4fc40
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd8013d79b00 last held: 0xffffcd8013d79b00
last locked* : netbsd:genfs_lock+0x15d
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1376)
lock address : ffffcd8013dde7c0
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd8013d79b00 last held: 0xffffcd8013d79b00
last locked* : netbsd:genfs_lock+0x15d
unlocked : 0
owner/count : 000000000000000000 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1115.1369 (syz-executor.1) @ 0xffffcd8013dd3340, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:proc0_init+0x47 sys/kern/kern_proc.c:493)
lock address : ffffcd800f67d0c0
type : sleep/adaptive
initialized : netbsd:proc0_init+0x47
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 1
relevant cpu : 1 last held: 0
relevant lwp : 0xffffcd8013dd3340 last held: 000000000000000000
last locked : netbsd:ktrops+0x3b
unlocked* : netbsd:ktrops+0xc6
owner field : 0xffffcd8013dd3340 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 325.325 (syz-executor.2) @ 0xffffcd8013d54ac0, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1376)
lock address : ffffcd8013d4f4c0
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffcd8013d54ac0 last held: 0xffffcd8013d54ac0
last locked* : netbsd:genfs_lock+0x15d
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffffcd8013d54ac0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1376)
lock address : ffffcd8013dde2c0
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffcd8013d54ac0 last held: 0xffffcd8013d54ac0
last locked* : netbsd:genfs_lock+0x15d
unlocked : 0
owner/count : 0xffffcd8013d54ac0 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 336.336 (syz-executor.0) @ 0xffffcd8013d54680, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:amap_ctor+0x39 sys/uvm/uvm_amap.c:265)
lock address : ffffcd8013d65100
type : sleep/adaptive
initialized : netbsd:amap_ctor+0x39
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffcd8013d54680 last held: 0xffffcd8013d54680
last locked* : netbsd:uvm_fault_internal+0x88a
unlocked : netbsd:amap_copy+0x4dc
owner/count : 0xffffcd8013d54680 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 1353.1353 (syz-executor.5) @ 0xffffcd8013d54240, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1376)
lock address : ffffcd8013d4fec0
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffcd8013d54240 last held: 0xffffcd8013d54240
last locked* : netbsd:genfs_lock+0x15d
unlocked : netbsd:genfs_unlock+0x2a
owner/count : 0xffffcd8013d54240 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:vcache_alloc+0x3e sys/kern/vfs_vnode.c:1376)
lock address : ffffcd8013dde540
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0x3e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffcd8013d54240 last held: 0xffffcd8013d54240
last locked* : netbsd:genfs_lock+0x15d
unlocked : 0
owner/count : 0xffffcd8013d54240 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 747.747 (dhcpcd) @ 0xffffcd8012cc4500, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd8012cc4500 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 742.742 (dhcpcd) @ 0xffffcd8012c94bc0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd8012c94bc0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 485.485 (dhcpcd) @ 0xffffcd8012dad4c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd8012dad4c0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 291.291 (dhcpcd) @ 0xffffcd8012dad080, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd8012dad080 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffffcd800fb49100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd800fb49100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.5 (softclk/0) @ 0xffffcd800fb33080, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd800fb33080 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff8334b340, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x1c sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x1c
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffffff8334b340 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu0:

* Lock 0 (initialized at netbsd:com_attach_subr+0x12e sys/dev/ic/com.c:565)
lock address : ffffcd8010c14d20
type : spin
initialized : netbsd:com_attach_subr+0x12e
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffffcd80129a32c0 last held: 0xffffcd8013d79b00
last locked* : netbsd:comintr+0xa3
unlocked : netbsd:comintr+0xe91
owner field : 0x0000000000000800 wait/spin: 0/1

******* Locks held on cpu1:

* Lock 0 (initialized at netbsd:kprintf_init+0x61 sys/kern/subr_prf.c:156)
lock address : netbsd:kprintf_mtx
type : spin
initialized : netbsd:kprintf_init+0x61
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffffcd8013dc5300 last held: 0xffffcd8013dc5300
last locked* : netbsd:kprintf_lock+0x33
unlocked : netbsd:kprintf_unlock+0x53
owner field : 0x0000000000000800 wait/spin: 0/1

PAGE FLAG PQ UOBJECT UANON
0xffffcd8000017180 0041 00000000 0x0 0x0
0xffffcd8000017200 0041 00000000 0x0 0x0
0xffffcd8000017280 0041 00000000 0x0 0x0
0xffffcd8000017300 0041 00000000 0x0 0x0
0xffffcd8000017380 0041 00000000 0x0 0x0
0xffffcd8000017400 0041 00000000 0x0 0x0
0xffffcd8000017480 0041 00000000 0x0 0x0
0xffffcd8000017500 0041 00000000 0x0 0x0
0xffffcd8000017580 0041 00000000 0x0 0x0
0xffffcd8000017600 0041 00000000 0x0 0x0
0xffffcd8000017680 0041 00000000 0x0 0x0
0xffffcd8000017700 0041 00000000 0x0 0x0
0xffffcd8000017780 0041 00000000 0x0 0x0
0xffffcd8000017800 0041 00000000 0x0 0x0
0xffffcd8000017880 0041 00000000 0x0 0x0
0xffffcd8000017900 0041 00000000 0x0 0x0
0xffffcd8000017980 0041 00000000 0x0 0x0
0xffffcd8000017a00 0041 00000000 0x0 0x0
0xffffcd8000017a80 0041 00000000 0x0 0x0
0xffffcd8000017b00 0041 00000000 0x0 0x0
0xffffcd8000017b80 0041 00000000 0x0 0x0
0xffffcd8000017c00 0041 00000000 0x0 0x0
0xffffcd8000017c80 0041 00000000 0x0 0x0
0xffffcd8000017d00 0041 00000000 0x0 0x0
0xffffcd8000017d80 0041 00000000 0x0 0x0
0xffffcd8000017e00 0041 00000000 0x0 0x0
0xffffcd8000017e80 0041 00000000 0x0 0x0
0xffffcd8000017f00 0041 00000000 0x0 0x0
0xffffcd8000017f80 0041 00000000 0x0 0x0
0xffffcd8000018000 0041 00000000 0x0 0x0
0xffffcd8000018080 0041 00000000 0x0 0x0
0xffffcd8000018100 0041 00000000 0x0 0x0
0xffffcd8000018180 0041 00000000 0x0 0x0
0xffffcd8000018200 0041 00000000 0x0 0x0
0xffffcd8000018280 0041 00000000 0x0 0x0
0xffffcd8000018300 0041 00000000 0x0 0x0
0xffffcd8000018380 0041 00000000 0x0 0x0
0xffffcd8000018400 0041 00000000 0x0 0x0
0xffffcd8000018480 0041 00000000 0x0 0x0
0xffffcd8000018500 0041 00000000 0x0 0x0
0xffffcd8000018580 0041 00000000 0x0 0x0
0xffffcd8000018600 0041 00000000 0x0 0x0
0xffffcd8000018680 0041 00000000 0x0 0x0
0xffffcd8000018700 0041 00000000 0x0 0x0
0xffffcd8000018780 0041 00000000 0x0 0x0
0xffffcd8000018800 0041 00000000 0x0 0x0
0xffffcd8000018880 0041 00000000 0x0 0x0
0xffffcd8000018900 0041 00000000 0x0 0x0
0xffffcd8000018980 0041 00000000 0x0 0x0
0xffffcd8000018a00 0041 00000000 0x0 0x0
0xffffcd8000018a80 0041 00000000 0x0 0x0
0xffffcd8000018b00 0041 00000000 0x0 0x0
0xffffcd8000018b80 0041 00000000 0x0 0x0
0xffffcd8000018c00 0041 00000000 0x0 0x0
0xffffcd8000018c80 0041 00000000 0x0 0x0
0xffffcd8000018d00 0041 00000000 0x0 0x0
0xffffcd8000018d80 0041 00000000 0x0 0x0
0xffffcd8000018e00 0041 00000000 0x0 0x0
0xffffcd8000018e80 0041 00000000 0x0 0x0
0xffffcd8000018f00 0041 00000000 0x0 0x0
0xffffcd8000018f80 0041 00000000 0x0 0x0
0xffffcd8000019000 0041 00000000 0x0 0x0
0xffffcd8000019080 0041 00000000 0x0 0x0
0xffffcd8000019100 0041 00000000 0x0 0x0
0xffffcd8000019180 0041 00000000 0x0 0x0
0xffffcd8000019200 0041 00000000 0x0 0x0
0xffffcd8000019280 0041 00000000 0x0 0x0
0xffffcd8000019300 0041 00000000 0x0 0x0
0xffffcd8000019380 0041 00000000 0x0 0x0
0xffffcd8000019400 0041 00000000 0x0 0x0
0xffffcd8000019480 0041 00000000 0x0 0x0
0xffffcd8000019500 0041 00000000 0x0 0x0
0xffffcd8000019580 0041 00000000 0x0 0x0
0xffffcd8000019600 0041 00000000 0x0 0x0
0xffffcd8000019680 0041 00000000 0x0 0x0
0xffffcd8000019700 0041 00000000 0x0 0x0
0xffffcd8000019780 0041 00000000 0x0 0x0
0xffffcd8000019800 0041 00000000 0x0 0x0
0xffffcd8000019880 0041 00000000 0x0 0x0
0xffffcd8000019900 0041 00000000 0x0 0x0
0xffffcd8000019980 0041 00000000 0x0 0x0
0xffffcd8000019a00 0041 00000000 0x0 0x0
0xffffcd8000019a80 0041 00000000 0x0 0x0
0xffffcd8000019b00 0041 00000000 0x0 0x0
0xffffcd8000019b80 0041 00000000 0x0 0x0
0xffffcd8000019c00 0041 00000000 0x0 0x0
0xffffcd8000019c80 0041 00000000 0x0 0x0
0xffffcd8000019d00 0041 00000000 0x0 0x0
0xffffcd8000019d80 0041 00000000 0x0 0x0
0xffffcd8000019e00 0041 00000000 0x0 0x0
0xffffcd8000019e80 0041 00000000 0x0 0x0
0xffffcd8000019f00 0041 00000000 0x0 0x0
0xffffcd8000019f80 0041 00000000 0x0 0x0
0xffffcd800001a000 0041 00000000 0x0 0x0
0xffffcd800001a080 0041 00000000 0x0 0x0
0xffffcd800001a100 0041 00000000 0x0 0x0
0xffffcd800001a180 0041 00000000 0x0 0x0
0xffffcd800001a200 0041 00000000 0x0 0x0
0xffffcd800001a280 0041 00000000 0x0 0x0
0xffffcd800001a300 0041 00000000 0x0 0x0
0xffffcd800001a380 0041 00000000 0x0 0x0
0xffffcd800001a400 0041 00000000 0x0 0x0
0xffffcd800001a480 0041 00000000 0x0 0x0
0xffffcd800001a500 0041 00000000 0x0 0x0
0xffffcd800001a580 0041 00000000 0x0 0x0
0xffffcd800001a600 0041 00000000 0x0 0x0
0xffffcd800001a680 0041 00000000 0x0 0x0
0xffffcd800001a700 0041 00000000 0x0 0x0
0xffffcd800001a780 0041 00000000 0x0 0x0
0xffffcd800001a800 0041 00000000 0x0 0x0
0xffffcd800001a880 0041 00000000 0x0 0x0
0xffffcd800001a900 0041 00000000 0x0 0x0
0xffffcd800001a980 0041 00000000 0x0 0x0
0xffffcd800001aa00 0041 00000000 0x0 0x0
0xffffcd800001aa80 0041 00000000 0x0 0x0
0xffffcd800001ab00 0041 00000000 0x0 0x0
0xffffcd800001ab80 0041 00000000 0x0 0x0
0xffffcd800001ac00 0041 00000000 0x0 0x0
0xffffcd800001ac80 0041 00000000 0x0 0x0
0xffffcd800001ad00 0041 00000000 0x0 0x0
0xffffcd800001ad80 0041 00000000 0x0 0x0
0xffffcd800001ae00 0041 00000000 0x0 0x0
0xffffcd800001ae80 0041 00000000 0x0 0x0
0xffffcd800001af00 0041 00000000 0x0 0x0
0xffffcd800001af80 0041 00000000 0x0 0x0
0xffffcd800001b000 0041 00000000 0x0 0x0
0xffffcd800001b080 0041 00000000 0x0 0x0
0xffffcd800001b100 0041 00000000 0x0 0x0
0xffffcd800001b180 0041 00000000 0x0 0x0
0xffffcd800001b200 0041 00000000 0x0 0x0
0xffffcd800001b280 0041 00000000 0x0 0x0
0xffffcd800001b300 0041 00000000 0x0 0x0
0xffffcd800001b380 0041 00000000 0x0 0x0
0xffffcd800001b400 0041 00000000 0x0 0x0
0xffffcd800001b480 0041 00000000 0x0 0x0
0xffffcd800001b500 0041 00000000 0x0 0x0
0xffffcd800001b580 0041 00000000 0x0 0x0
0xffffcd800001b600 0041 00000000 0x0 0x0
0xffffcd800001b680 0041 00000000 0x0 0x0
0xffffcd800001b700 0041 00000000 0x0 0x0
0xffffcd800001b780 0041 00000000 0x0 0x0
0xffffcd800001b800 0041 00000000 0x0 0x0
0xffffcd800001b880 0041 00000000 0x0 0x0
0xffffcd800001b900 0041 00000000 0x0 0x0
0xffffcd800001b980 0041 00000000 0x0 0x0
0xffffcd800001ba00 0041 00000000 0x0 0x0
0xffffcd800001ba80 0041 00000000 0x0 0x0
0xffffcd800001bb00 0041 00000000 0x0 0x0
0xffffcd800001bb80 0001 00000000 0x0 0x0
0xffffcd800001bc00 0001 00000000 0x0 0x0
0xffffcd800001bc80 0001 00000000 0x0 0x0
0xffffcd800001bd00 0001 00000000 0x0 0x0
0xffffcd800001bd80 0001 00000000 0x0 0x0
0xffffcd800001be00 0001 00000000 0x0 0x0
0xffffcd800001be80 0001 00000000 0x0 0x0
0xffffcd800001bf00 0001 00000000 0x0 0x0
0xffffcd800001bf80 0001 00000000 0x0 0x0
0xffffcd800001c000 0001 00000000 0x0 0x0
0xffffcd800001c080 0001 00000000 0x0 0x0
0xffffcd800001c100 0001 00000000 0x0 0x0
0xffffcd800001c180 0001 00000000 0x0 0x0
0xffffcd800001c200 0001 00000000 0x0 0x0
0xffffcd800001c280 0001 00000000 0x0 0x0
0xffffcd800001c300 0001 00000000 0x0 0x0
0xffffcd800001c380 0001 00000000 0x0 0x0
0xffffcd800001c400 0001 00000000 0x0 0x0
0xffffcd800001c480 0001 00000000 0x0 0x0
0xffffcd800001c500 0001 00000000 0x0 0x0
0xffffcd800001c580 0001 00000000 0x0 0x0
0xffffcd800001c600 0001 00000000 0x0 0x0
0xffffcd800001c680 0001 00000000 0x0 0x0
0xffffcd800001c700 0001 00000000 0x0 0x0
0xffffcd800001c780 0001 00000000 0x0 0x0
0xffffcd800001c800 0001 00000000 0x0 0x0
0xffffcd800001c880 0001 00000000 0x0 0x0
0xffffcd800001c900 0001 00000000 0x0 0x0
0xffffcd800001c980 0001 00000000 0x0 0x0
0xffffcd800001ca00 0001 00000000 0x0 0x0
0xffffcd800001ca80 0001 00000000 0x0 0x0
0xffffcd800001cb00 0001 00000000 0x0 0x0
0xffffcd800001cb80 0001 00000000 0x0 0x0
0xffffcd800001cc00 0001 00000000 0x0 0x0
0xffffcd800001cc80 0001 00000000 0x0 0x0
0xffffcd800001cd00 0001 00000000 0x0 0x0
0xffffcd800001cd80 0001 00000000 0x0 0x0
0xffffcd800001ce00 0001 00000000 0x0 0x0
0xffffcd800001ce80 0001 00000000 0x0 0x0
0xffffcd800001cf00 0001 00000000 0x0 0x0
0xffffcd800001cf80 0001 00000000 0x0 0x0
0xffffcd800001d000 0001 00000000 0x0 0x0
0xffffcd800001d080 0001 00000000 0x0 0x0
0xffffcd800001d100 0001 00000000 0x0 0x0
0xffffcd800001d180 0001 00000000 0x0 0x0
0xffffcd800001d200 0001 00000000 0x0 0x0
0xffffcd800001d280 0001 00000000 0x0 0x0
0xffffcd800001d300 0001 00000000 0x0 0x0
0xffffcd800001d380 0001 00000000 0x0 0x0
0xffffcd800001d400 0001 00000000 0x0 0x0
0xffffcd800001d480 0001 00000000 0x0 0x0
0xffffcd800001d500 0001 00000000 0x0 0x0
0xffffcd800001d580 0001 00000000 0x0 0x0
0xffffcd800001d600 0001 00000000 0x0 0x0
0xffffcd800001d680 0001 00000000 0x0 0x0
0xffffcd800001d700 0001 00000000 0x0 0x0
0xffffcd800001d780 0001 00000000 0x0 0x0
0xffffcd800001d800 0001 00000000 0x0 0x0
0xffffcd800001d880 0001 00000000 0x0 0x0
0xffffcd800001d900 0001 00000000 0x0 0x0
0xffffcd800001d980 0001 00000000 0x0 0x0
0xffffcd800001da00 0001 00000000 0x0 0x0
0xffffcd800001da80 0001 00000000 0x0 0x0
0xffffcd800001db00 0001 00000000 0x0 0x0
0xffffcd800001db80 0001 00000000 0x0 0x0
0xffffcd800001dc00 0001 00000000 0x0 0x0
0xffffcd800001dc80 0001 00000000 0x0 0x0
0xffffcd800001dd00 0001 00000000 0x0 0x0
0xffffcd800001dd80 0001 00000000 0x0 0x0
0xffffcd800001de00 0001 00000000 0x0 0x0
0xffffcd800001de80 0001 00000000 0x0 0x0
0xffffcd800001df00 0001 00000000 0x0 0x0
0xffffcd800001df80 0001 00000000 0x0 0x0
0xffffcd800001e000 0001 00000000 0x0 0x0
0xffffcd800001e080 0001 00000000 0x0 0x0
0xffffcd800001e100 0001 00000000 0x0 0x0
0xffffcd800001e180 0001 00000000 0x0 0x0
0xffffcd800001e200 0001 00000000 0x0 0x0
0xffffcd800001e280 0001 00000000 0x0 0x0
0xffffcd800001e300 0001 00000000 0x0 0x0
0xffffcd800001e380 0001 00000000 0x0 0x0
0xffffcd800001e400 0001 00000000 0x0 0x0
0xffffcd800001e480 0001 00000000 0x0 0x0
0xffffcd800001e500 0001 00000000 0x0 0x0
0xffffcd800001e580 0001 00000000 0x0 0x0
0xffffcd800001e600 0001 00000000 0x0 0x0
0xffffcd800001e680 0001 00000000 0x0 0x0
0xffffcd800001e700 0001 00000000 0x0 0x0
0xffffcd800001e780 0001 00000000 0x0 0x0
0xffffcd800001e800 0001 00000000 0x0 0x0
0xffffcd800001e880 0001 00000000 0x0 0x0
0xffffcd800001e900 0001 00000000 0x0 0x0
0xffffcd800001e980 0001 00000000 0x0 0x0
0xffffcd800001ea00 0001 00000000 0x0 0x0
0xffffcd800001ea80 0001 00000000 0x0 0x0
0xffffcd800001eb00 0001 00000000 0x0 0x0
0xffffcd800001eb80 0001 00000000 0x0 0x0
0xffffcd800001ec00 0001 00000000 0x0 0x0
0xffffcd800001ec80 0001 00000000 0x0 0x0
0xffffcd800001ed00 0001 00000000 0x0 0x0
0xffffcd800001ed80 0001 00000000 0x0 0x0
0xffffcd800001ee00 0001 00000000 0x0 0x0
0xffffcd800001ee80 0001 00000000 0x0 0x0
0xffffcd800001ef00 0001 00000000 0x0 0x0
0xffffcd800001ef80 0001 00000000 0x0 0x0
0xffffcd800001f000 0001 00000000 0x0 0x0
0xffffcd800001f080 0001 00000000 0x0 0x0
0xffffcd800001f100 0001 00000000 0x0 0x0
0xffffcd800001f180 0001 00000000 0x0 0x0
0xffffcd800001f200 0001 00000000 0x0 0x0
0xffffcd800001f280 0001 00000000 0x0 0x0
0xffffcd800001f300 0001 00000000 0x0 0x0
0xffffcd800001f380 0001 00000000 0x0 0x0
0xffffcd800001f400 0001 00000000 0x0 0x0
0xffffcd800001f480 0001 00000000 0x0 0x0
0xffffcd800001f500 0001 00000000 0x0 0x0
0xffffcd800001f580 0001 00000000 0x0 0x0
0xffffcd800001f600 0001 00000000 0x0 0x0
0xffffcd800001f680 0001 00000000 0x0 0x0
0xffffcd800001f700 0001 00000000 0x0 0x0
0xffffcd800001f780 0001 00000000 0x0 0x0
0xffffcd800001f800 0001 00000000 0x0 0x0
0xffffcd800001f880 0001 00000000 0x0 0x0
0xffffcd800001f900 0001 00000000 0x0 0x0
0xffffcd800001f980 0001 00000000 0x0 0x0
0xffffcd800001fa00 0001 00000000 0x0 0x0
0xffffcd800001fa80 0001 00000000 0x0 0x0
0xffffcd800001fb00 0001 00000000 0x0 0x0
0xffffcd800001fb80 0001 00000000 0x0 0x0
0xffffcd800001fc00 0001 00000000 0x0 0x0
0xffffcd800001fc80 0001 00000000 0x0 0x0
0xffffcd800001fd00 0001 00000000 0x0 0x0
0xffffcd800001fd80 0001 00000000 0x0 0x0
0xffffcd800001fe00 0001 00000000 0x0 0x0
0xffffcd800001fe80 0001 00000000 0x0 0x0
0xffffcd800001ff00 0001 00000000 0x0 0x0
0xffffcd800001ff80 0001 00000000 0x0 0x0
0xffffcd8000020000 0001 00000000 0x0 0x0
0xffffcd8000020080 0001 00000000 0x0 0x0
0xffffcd8000020100 0001 00000000 0x0 0x0
0xffffcd8000020180 0001 00000000 0x0 0x0
0xffffcd8000020200 0001 00000000 0x0 0x0
0xffffcd8000020280 0001 00000000 0x0 0x0
0xffffcd8000020300 0001 00000000 0x0 0x0
0xffffcd8000020380 0001 00000000 0x0 0x0
0xffffcd8000020400 0001 00000000 0x0 0x0
0xffffcd8000020480 0001 00000000 0x0 0x0
0xffffcd8000020500 0001 00000000 0x0 0x0
0xffffcd8000020580 0001 00000000 0x0 0x0
0xffffcd8000020600 0001 00000000 0x0 0x0
0xffffcd8000020680 0001 00000000 0x0 0x0
0xffffcd8000020700 0001 00000000 0x0 0x0
0xffffcd8000020780 0001 00000000 0x0 0x0
0xffffcd8000020800 0001 00000000 0x0 0x0
0xffffcd8000020880 0001 00000000 0x0 0x0
0xffffcd8000020900 0001 00000000 0x0 0x0
0xffffcd8000020980 0001 00000000 0x0 0x0
0xffffcd8000020a00 0001 00000000 0x0 0x0
0xffffcd8000020a80 0001 00000000 0x0 0x0
0xffffcd8000020b00 0001 00000000 0x0 0x0
0xffffcd8000020b80 0001 00000000 0x0 0x0
0xffffcd8000020c00 0001 00000000 0x0 0x0
0xffffcd8000020c80 0001 00000000 0x0 0x0
0xffffcd8000020d00 0001 00000000 0x0 0x0
0xffffcd8000020d80 0001 00000000 0x0 0x0
0xffffcd8000020e00 0001 00000000 0x0 0x0
0xffffcd8000020e80 0001 00000000 0x0 0x0
0xffffcd8000020f00 0001 00000000 0x0 0x0
0xffffcd8000020f80 0001 00000000 0x0 0x0
0xffffcd8000021000 0001 00000000 0x0 0x0
0xffffcd8000021080 0001 00000000 0x0 0x0
0xffffcd8000021100 0001 00000000 0x0 0x0
0xffffcd8000021180 0001 00000000 0x0 0x0
0xffffcd8000021200 0001 00000000 0x0 0x0
0xffffcd8000021280 0001 00000000 0x0 0x0
0xffffcd8000021300 0001 00000000 0x0 0x0
0xffffcd8000021380 0001 00000000 0x0 0x0
0xffffcd8000021400 0001 00000000 0x0 0x0
0xffffcd8000021480 0001 00000000 0x0 0x0
0xffffcd8000021500 0001 00000000 0x0 0x0
0xffffcd8000021580 0001 00000000 0x0 0x0
0xffffcd8000021600 0001 00000000 0x0 0x0
0xffffcd8000021680 0001 00000000 0x0 0x0
0xffffcd8000021700 0001 00000000 0x0 0x0
0xffffcd8000021780 0001 00000000 0x0 0x0
0xffffcd8000021800 0001 00000000 0x0 0x0
0xffffcd8000021880 0001 00000000 0x0 0x0
0xffffcd8000021900 0001 00000000 0x0 0x0
0xffffcd8000021980 0001 00000000 0x0 0x0
0xffffcd8000021a00 0001 00000000 0x0 0x0
0xffffcd8000021a80 0001 00000000 0x0 0x0
0xffffcd8000021b00 0001 00000000 0x0 0x0
0xffffcd8000021b80 0001 00000000 0x0 0x0
0xffffcd8000021c00 0001 00000000 0x0 0x0
0xffffcd8000021c80 0001 00000000 0x0 0x0
0xffffcd8000021d00 0001 00000000 0x0 0x0
0xffffcd8000021d80 0001 00000000 0x0 0x0
0xffffcd8000021e00 0001 00000000 0x0 0x0
0xffffcd8000021e80 0001 00000000 0x0 0x0
0xffffcd8000021f00 0001 00000000 0x0 0x0
0xffffcd8000021f80 0001 00000000 0x0 0x0
0xffffcd8000022000 0001 00000000 0x0 0x0
0xffffcd8000022080 0001 00000000 0x0 0x0
0xffffcd8000022100 0001 00000000 0x0 0x0
0xffffcd8000022180 0001 00000000 0x0 0x0
0xffffcd8000022200 0001 00000000 0x0 0x0
0xffffcd8000022280 0001 00000000 0x0 0x0
0xffffcd8000022300 0001 00000000 0x0 0x0
0xffffcd8000022380 0001 00000000 0x0 0x0
0xffffcd8000022400 0001 00000000 0x0 0x0
0xffffcd8000022480 0001 00000000 0x0 0x0
0xffffcd8000022500 0001 00000000 0x0 0x0
0xffffcd8000022580 0001 00000000 0x0 0x0
0xffffcd8000022600 0001 00000000 0x0 0x0
0xffffcd8000022680 0001 00000000 0x0 0x0
0xffffcd8000022700 0001 00000000 0x0 0x0
0xffffcd8000022780 0001 00000000 0x0 0x0
0xffffcd8000022800 0001 00000000 0x0 0x0
0xffffcd8000022880 0001 00000000 0x0 0x0
0xffffcd8000022900 0001 00000000 0x0 0x0
0xffffcd8000022980 0001 00000000 0x0 0x0
0xffffcd8000022a00 0001 00000000 0x0 0x0
0xffffcd8000022a80 0001 00000000 0x0 0x0
0xffffcd8000022b00 0001 00000000 0x0 0x0
0xffffcd8000022b80 0001 00000000 0x0 0x0
0xffffcd8000022c00 0001 00000000 0x0 0x0
0xffffcd8000022c80 0001 00000000 0x0 0x0
0xffffcd8000022d00 0001 00000000 0x0 0x0
0xffffcd8000022d80 0001 00000000 0x0 0x0
0xffffcd8000022e00 0001 00000000 0x0 0x0
0xffffcd8000022e80 0001 00000000 0x0 0x0
0xffffcd8000022f00 0001 00000000 0x0 0x0
0xffffcd8000022f80 0001 00000000 0x0 0x0
0xffffcd8000023000 0001 00000000 0x0 0x0
0xffffcd8000023080 0001 00000000 0x0 0x0
0xffffcd8000023100 0001 00000000 0x0 0x0
0xffffcd8000023180 0001 00000000 0x0 0x0
0xffffcd8000023200 0001 00000000 0x0 0x0
0xffffcd8000023280 0001 00000000 0x0 0x0
0xffffcd8000023300 0001 00000000 0x0 0x0
0xffffcd8000023380 0001 00000000 0x0 0x0
0xffffcd8000023400 0001 00000000 0x0 0x0
0xffffcd8000023480 0001 00000000 0x0 0x0
0xffffcd8000023500 0001 00000000 0x0 0x0
0xffffcd8000023580 0001 00000000 0x0 0x0
0xffffcd8000023600 0001 00000000 0x0 0x0
0xffffcd8000023680 0001 00000000 0x0 0x0
0xffffcd8000023700 0001 00000000 0x0 0x0
0xffffcd8000023780 0001 00000000 0x0 0x0
0xffffcd8000023800 0001 00000000 0x0 0x0
0xffffcd8000023880 0001 00000000 0x0 0x0
0xffffcd8000023900 0001 00000000 0x0 0x0
0xffffcd8000023980 0001 00000000 0x0 0x0
0xffffcd8000023a00 0001 00000000 0x0 0x0
0xffffcd8000023a80 0001 00000000 0x0 0x0
0xffffcd8000023b00 0001 00000000 0x0 0x0
0xffffcd8000023b80 0001 00000000 0x0 0x0
0xffffcd8000023c00 0001 00000000 0x0 0x0
0xffffcd8000023c80 0001 00000000 0x0 0x0
0xffffcd8000023d00 0001 00000000 0x0 0x0
0xffffcd8000023d80 0001 00000000 0x0 0x0
0xffffcd8000023e00 0001 00000000 0x0 0x0
0xffffcd8000023e80 0001 00000000 0x0 0x0
0xffffcd8000023f00 0001 00000000 0x0 0x0
0xffffcd8000023f80 0001 00000000 0x0 0x0
0xffffcd8000024000 0001 00000000 0x0 0x0
0xffffcd8000024080 0001 00000000 0x0 0x0
0xffffcd8000024100 0001 00000000 0x0 0x0
0xffffcd8000024180 0001 00000000 0x0 0x0
0xffffcd8000024200 0001 00000000 0x0 0x0
0xffffcd8000024280 0001 00000000 0x0 0x0
0xffffcd8000024300 0001 00000000 0x0 0x0
0xffffcd8000024380 0001 00000000 0x0 0x0
0xffffcd8000024400 0001 00000000 0x0 0x0
0xffffcd8000024480 0001 00000000 0x0 0x0
0xffffcd8000024500 0001 00000000 0x0 0x0
0xffffcd8000024580 0001 00000000 0x0 0x0
0xffffcd8000024600 0001 00000000 0x0 0x0
0xffffcd8000024680 0001 00000000 0x0 0x0
0xffffcd8000024700 0001 00000000 0x0 0x0
0xffffcd8000024780 0001 00000000 0x0 0x0
0xffffcd8000024800 0001 00000000 0x0 0x0
0xffffcd8000024880 0001 00000000 0x0 0x0
0xffffcd8000024900 0001 00000000 0x0 0x0
0xffffcd8000024980 0001 00000000 0x0 0x0
0xffffcd8000024a00 0001 00000000 0x0 0x0
0xffffcd8000024a80 0001 00000000 0x0 0x0
0xffffcd8000024b00 0001 00000000 0x0 0x0
0xffffcd8000024b80 0001 00000000 0x0 0x0
0xffffcd8000024c00 0001 00000000 0x0 0x0
0xffffcd8000024c80 0001 00000000 0x0 0x0
0xffffcd8000024d00 0001 00000000 0x0 0x0
0xffffcd8000024d80 0001 00000000 0x0 0x0
0xffffcd8000024e00 0001 00000000 0x0 0x0
0xffffcd8000024e80 0001 00000000 0x0 0x0
0xffffcd8000024f00 0001 00000000 0x0 0x0
0xffffcd8000024f80 0001 00000000 0x0 0x0
0xffffcd8000025000 0001 00000000 0x0 0x0
0xffffcd8000025080 0001 00000000 0x0 0x0
0xffffcd8000025100 0001 00000000 0x0 0x0
0xffffcd8000025180 0001 00000000 0x0 0x0
0xffffcd8000025200 0001 00000000 0x0 0x0
0xffffcd8000025280 0001 00000000 0x0 0x0
0xffffcd8000025300 0001 00000000 0x0 0x0
0xffffcd8000025380 0001 00000000 0x0 0x0
0xffffcd8000025400 0001 00000000 0x0 0x0
0xffffcd8000025480 0001 00000000 0x0 0x0
0xffffcd8000025500 0001 00000000 0x0 0x0
0xffffcd8000025580 0001 00000000 0x0 0x0
0xffffcd8000025600 0001 00000000 0x0 0x0
0xffffcd8000025680 0001 00000000 0x0 0x0
0xffffcd8000025700 0001 00000000 0x0 0x0
0xffffcd8000025780 0001 00000000 0x0 0x0
0xffffcd8000025800 0001 00000000 0x0 0x0
0xffffcd8000025880 0001 00000000 0x0 0x0
0xffffcd8000025900 0001 00000000 0x0 0x0
0xffffcd8000025980 0001 00000000 0x0 0x0
0xffffcd8000025a00 0001 00000000 0x0 0x0
0xffffcd8000025a80 0001 00000000 0x0 0x0
0xffffcd8000025b00 0001 00000000 0x0 0x0
0xffffcd8000025b80 0001 00000000 0x0 0x0
0xffffcd8000025c00 0001 00000000 0x0 0x0
0xffffcd8000025c80 0001 00000000 0x0 0x0
0xffffcd8000025d00 0001 00000000 0x0 0x0
0xffffcd8000025d80 0001 00000000 0x0 0x0
0xffffcd8000025e00 0001 00000000 0x0 0x0
0xffffcd8000025e80 0001 00000000 0x0 0x0
0xffffcd8000025f00 0001 00000000 0x0 0x0
0xffffcd8000025f80 0001 00000000 0x0 0x0
0xffffcd8000026000 0001 00000000 0x0 0x0
0xffffcd8000026080 0001 00000000 0x0 0x0
0xffffcd8000026100 0001 00000000 0x0 0x0
0xffffcd8000026180 0001 00000000 0x0 0x0
0xffffcd8000026200 0001 00000000 0x0 0x0
0xffffcd8000026280 0001 00000000 0x0 0x0
0xffffcd8000026300 0001 00000000 0x0 0x0
0xffffcd8000026380 0001 00000000 0x0 0x0
0xffffcd8000026400 0001 00000000 0x0 0x0
0xffffcd8000026480 0001 00000000 0x0 0x0
0xffffcd8000026500 0001 00000000 0x0 0x0
0xffffcd8000026580 0001 00000000 0x0 0x0
0xffffcd8000026600 0001 00000000 0x0 0x0
0xffffcd8000026680 0001 00000000 0x0 0x0
0xffffcd8000026700 0001 00000000 0x0 0x0
0xffffcd8000026780 0001 00000000 0x0 0x0
0xffffcd8000026800 0001 00000000 0x0 0x0
0xffffcd8000026880 0001 00000000 0x0 0x0
0xffffcd8000026900 0001 00000000 0x0 0x0
0xffffcd8000026980 0001 00000000 0x0 0x0
0xffffcd8000026a00 0001 00000000 0x0 0x0
0xffffcd8000026a80 0001 00000000 0x0 0x0
0xffffcd8000026b00 0001 00000000 0x0 0x0
0xffffcd8000026b80 0001 00000000 0x0 0x0
0xffffcd8000026c00 0001 00000000 0x0 0x0
0xffffcd8000026c80 0001 00000000 0x0 0x0
0xffffcd8000026d00 0001 00000000 0x0 0x0
0xffffcd8000026d80 0001 00000000 0x0 0x0
0xffffcd8000026e00 0001 00000000 0x0 0x0
0xffffcd8000026e80 0001 00000000 0x0 0x0
0xffffcd8000026f00 0001 00000000 0x0 0x0
0xffffcd8000026f80 0001 00000000 0x0 0x0
0xffffcd8000027000 0001 00000000 0x0 0x0
0xffffcd8000027080 0001 00000000 0x0 0x0
0xffffcd8000027100 0001 00000000 0x0 0x0
0xffffcd8000027180 0001 00000000 0x0 0x0
0xffffcd8000027200 0001 00000000 0x0 0x0
0xffffcd8000027280 0001 00000000 0x0 0x0
0xffffcd8000027300 0001 00000000 0x0 0x0
0xffffcd8000027380 0001 00000000 0x0 0x0
0xffffcd8000027400 0001 00000000 0x0 0x0
0xffffcd8000027480 0001 00000000 0x0 0x0
0xffffcd8000027500 0001 00000000 0x0 0x0
0xffffcd8000027580 0001 00000000 0x0 0x0
0xffffcd8000027600 0001 00000000 0x0 0x0
0xffffcd8000027680 0001 00000000 0x0 0x0
0xffffcd8000027700 0001 00000000 0x0 0x0
0xffffcd8000027780 0001 00000000 0x0 0x0
0xffffcd8000027800 0001 00000000 0x0 0x0
0xffffcd8000027880 0001 00000000 0x0 0x0
0xffffcd8000027900 0001 00000000 0x0 0x0
0xffffcd8000027980 0001 00000000 0x0 0x0
0xffffcd8000027a00 0001 00000000 0x0 0x0
0xffffcd8000027a80 0001 00000000 0x0 0x0
0xffffcd8000027b00 0001 00000000 0x0 0x0
0xffffcd8000027b80 0001 00000000 0x0 0x0
0xffffcd8000027c00 0001 00000000 0x0 0x0
0xffffcd8000027c80 0001 00000000 0x0 0x0
0xffffcd8000027d00 0001 00000000 0x0 0x0
0xffffcd8000027d80 0001 00000000 0x0 0x0
0xffffcd8000027e00 0001 00000000 0x0 0x0
0xffffcd8000027e80 0001 00000000 0x0 0x0
0xffffcd8000027f00 0001 00000000 0x0 0x0
0xffffcd8000027f80 0001 00000000 0x0 0x0
0xffffcd8000028000 0001 00000000 0x0 0x0
0xffffcd8000028080 0001 00000000 0x0 0x0
0xffffcd8000028100 0001 00000000 0x0 0x0
0xffffcd8000028180 0001 00000000 0x0 0x0
0xffffcd8000028200 0001 00000000 0x0 0x0
0xffffcd8000028280 0001 00000000 0x0 0x0
0xffffcd8000028300 0001 00000000 0x0 0x0
0xffffcd8000028380 0001 00000000 0x0 0x0
0xffffcd8000028400 0001 00000000 0x0 0x0
0xffffcd8000028480 0001 00000000 0x0 0x0
0xffffcd8000028500 0001 00000000 0x0 0x0
0xffffcd8000028580 0001 00000000 0x0 0x0
0xffffcd8000028600 0001 00000000 0x0 0x0
0xffffcd8000028680 0001 00000000 0x0 0x0
0xffffcd8000028700 0001 00000000 0x0 0x0
0xffffcd8000028780 0001 00000000 0x0 0x0
0xffffcd8000028800 0001 00000000 0x0 0x0
0xffffcd8000028880 0001 00000000 0x0 0x0
0xffffcd8000028900 0001 00000000 0x0 0x0
0xffffcd8000028980 0001 00000000 0x0 0x0
0xffffcd8000028a00 0001 00000000 0x0 0x0
0xffffcd8000028a80 0001 00000000 0x0 0x0
0xffffcd8000028b00 0001 00000000 0x0 0x0
0xffffcd8000028b80 0001 00000000 0x0 0x0
0xffffcd8000028c00 0001 00000000 0x0 0x0
0xffffcd8000028c80 0001 00000000 0x0 0x0
0xffffcd8000028d00 0001 00000000 0x0 0x0
0xffffcd8000028d80 0001 00000000 0x0 0x0
0xffffcd8000028e00 0001 00000000 0x0 0x0
0xffffcd8000028e80 0001 00000000 0x0 0x0
0xffffcd8000028f00 0001 00000000 0x0 0x0
0xffffcd8000028f80 0001 00000000 0x0 0x0
0xffffcd8000029000 0001 00000000 0x0 0x0
0xffffcd8000029080 0001 00000000 0x0 0x0
0xffffcd8000029100 0001 00000000 0x0 0x0
0xffffcd8000029180 0001 00000000 0x0 0x0
0xffffcd8000029200 0001 00000000 0x0 0x0
0xffffcd8000029280 0001 00000000 0x0 0x0
0xffffcd8000029300 0001 00000000 0x0 0x0
0xffffcd8000029380 0001 00000000 0x0 0x0
0xffffcd8000029400 0001 00000000 0x0 0x0
0xffffcd8000029480 0001 00000000 0x0 0x0
0xffffcd8000029500 0001 00000000 0x0 0x0
0xffffcd8000029580 0001 00000000 0x0 0x0
0xffffcd8000029600 0001 00000000 0x0 0x0
0xffffcd8000029680 0001 00000000 0x0 0x0
0xffffcd8000029700 0001 00000000 0x0 0x0
0xffffcd8000029780 0001 00000000 0x0 0x0
0xffffcd8000029800 0001 00000000 0x0 0x0
0xffffcd8000029880 0001 00000000 0x0 0x0
0xffffcd8000029900 0001 00000000 0x0 0x0
0xffffcd8000029980 0001 00000000 0x0 0x0
0xffffcd8000029a00 0001 00000000 0x0 0x0
0xffffcd8000029a80 0001 00000000 0x0 0x0
0xffffcd8000029b00 0001 00000000 0x0 0x0
0xffffcd8000029b80 0001 00000000 0x0 0x0
0xffffcd8000029c00 0001 00000000 0x0 0x0
0xffffcd8000029c80 0001 00000000 0x0 0x0
0xffffcd8000029d00 0001 00000000 0x0 0x0
0xffffcd8000029d80 0001 00000000 0x0 0x0
0xffffcd8000029e00 0001 00000000 0x0 0x0
0xffffcd8000029e80 0001 00000000 0x0 0x0
0xffffcd8000029f00 0001 00000000 0x0 0x0
0xffffcd8000029f80 0001 00000000 0x0 0x0
0xffffcd800002a000 0001 00000000 0x0 0x0
0xffffcd800002a080 0001 00000000 0x0 0x0
0xffffcd800002a100 0001 00000000 0x0 0x0
0xffffcd800002a180 0001 00000000 0x0 0x0
0xffffcd800002a200 0001 00000000 0x0 0x0
0xffffcd800002a280 0001 00000000 0x0 0x0
0xffffcd800002a300 0001 00000000 0x0 0x0
0xffffcd800002a380 0001 00000000 0x0 0x0
0xffffcd800002a400 0001 00000000 0x0 0x0
0xffffcd800002a480 0001 00000000 0x0 0x0
0xffffcd800002a500 0001 00000000 0x0 0x0
0xffffcd800002a580 0001 00000000 0x

Tested on:

commit: 37f8bc42 check for proper error value from OF_finddevi..
git tree: https://github.com/NetBSD/src trunk
console output: https://syzkaller.appspot.com/x/log.txt?x=10d95e24280000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=e0f56178d0add0d8be20
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110
patch: https://syzkaller.appspot.com/x/patch.diff?x=13863f6a280000

Taylor R Campbell

unread,
May 9, 2023, 2:21:38 PM5/9/23
to syzbot+e0f561...@syzkaller.appspotmail.com, syzkaller-...@googlegroups.com
ttyuiopeekskip.patch

syzbot

unread,
May 9, 2023, 3:19:43 PM5/9/23
to rias...@netbsd.org, syzkaller-...@googlegroups.com
Hello,

syzbot has tested the proposed patch and the reproducer did not trigger any issue:

Reported-and-tested-by: syzbot+e0f561...@syzkaller.appspotmail.com

Tested on:

commit: c5a256e2 Handle OpenSSL-3.x
console output: https://syzkaller.appspot.com/x/log.txt?x=10fd9c98280000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=e0f56178d0add0d8be20
compiler: g++ (Debian 10.2.1-6) 10.2.1 20210110
patch: https://syzkaller.appspot.com/x/patch.diff?x=148c2a92280000

Note: testing is done by a robot and is best-effort only.
Reply all
Reply to author
Forward
0 new messages