ASan: Unauthorized Access in ttioctl

4 views
Skip to first unread message

syzbot

unread,
Mar 26, 2021, 7:45:15 AM3/26/21
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: 59ee1e30 make(1): replace global preserveUndefined with VA..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=17bf4d9ed00000
kernel config: https://syzkaller.appspot.com/x/.config?x=fab579639ba4bf0a
dashboard link: https://syzkaller.appspot.com/bug?extid=91bf701f674ecf0b0670
compiler: g++ (Ubuntu 5.4.0-6ubuntu1~16.04.12) 5.4.0 20160609

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+91bf70...@syzkaller.appspotmail.com

[ 135.5823862] panic: ASan: Unauthorized Access In 0xffffffff819df37a: Addr 0xffff9d0015080b10 [4 bytes, read, PoolUseAfterFree]

[ 135.5923606] cpu1: Begin traceback...
[ 135.6123644] vpanic() at netbsd:vpanic+0x265 syzkaller/managers/netbsd/kernel/sys/kern/subr_prf.c:290
[ 135.6523633] snprintf() at netbsd:snprintf
[ 135.6923636] kasan_report() at netbsd:kasan_report+0x8c kasan_code_name syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:168 [inline]
[ 135.6923636] kasan_report() at netbsd:kasan_report+0x8c syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:200
[ 135.7423616] __asan_load4() at netbsd:__asan_load4+0x9a kasan_shadow_4byte_isvalid syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:350 [inline]
[ 135.7423616] __asan_load4() at netbsd:__asan_load4+0x9a kasan_shadow_check syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:417 [inline]
[ 135.7423616] __asan_load4() at netbsd:__asan_load4+0x9a syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:1206
[ 135.7823678] ttioctl() at netbsd:ttioctl+0xdbd syzkaller/managers/netbsd/kernel/sys/kern/tty.c:1087
[ 135.8223699] ptyioctl() at netbsd:ptyioctl+0x526 syzkaller/managers/netbsd/kernel/sys/kern/tty_pty.c:1182
[ 135.8623623] cdev_ioctl() at netbsd:cdev_ioctl+0x147 syzkaller/managers/netbsd/kernel/sys/kern/subr_devsw.c:935
[ 135.9123656] spec_ioctl() at netbsd:spec_ioctl+0x20f syzkaller/managers/netbsd/kernel/sys/miscfs/specfs/spec_vnops.c:933
[ 135.9523618] VOP_IOCTL() at netbsd:VOP_IOCTL+0x12c syzkaller/managers/netbsd/kernel/sys/kern/vnode_if.c:646
[ 135.9923627] vn_ioctl() at netbsd:vn_ioctl+0x1b9 syzkaller/managers/netbsd/kernel/sys/kern/vfs_vnops.c:783
[ 136.0423646] sys_fcntl() at netbsd:sys_fcntl+0xa0e syzkaller/managers/netbsd/kernel/sys/kern/sys_descrip.c:476
[ 136.0823619] sys___syscall() at netbsd:sys___syscall+0xff sy_call syzkaller/managers/netbsd/kernel/sys/sys/syscallvar.h:65 [inline]
[ 136.0823619] sys___syscall() at netbsd:sys___syscall+0xff syzkaller/managers/netbsd/kernel/sys/kern/sys_syscall.c:77
[ 136.1323628] syscall() at netbsd:syscall+0x259 sy_call syzkaller/managers/netbsd/kernel/sys/sys/syscallvar.h:65 [inline]
[ 136.1323628] syscall() at netbsd:syscall+0x259 sy_invoke syzkaller/managers/netbsd/kernel/sys/sys/syscallvar.h:94 [inline]
[ 136.1323628] syscall() at netbsd:syscall+0x259 syzkaller/managers/netbsd/kernel/sys/arch/x86/x86/syscall.c:138
[ 136.1423628] --- syscall (number 198) ---
[ 136.1523603] netbsd:syscall+0x259:
[ 136.1623615] cpu1: End traceback...
[ 136.1623615] fatal breakpoint trap in supervisor mode
[ 136.1623615] trap type 1 code 0 rip 0xffffffff80220a2d cs 0x8 rflags 0x282 cr2 0x7421275eb0d8 ilevel 0 rsp 0xffff9d019e5b7480
[ 136.1723587] curlwp 0xffff9d0013bcea00 pid 5825.6973 lowest kstack 0xffff9d019e5b02c0
Stopped in pid 5825.6973 (syz-executor.1) at netbsd:breakpoint+0x5: leave
?
breakpoint() at netbsd:breakpoint+0x5
db_panic() at netbsd:db_panic+0x105 syzkaller/managers/netbsd/kernel/sys/ddb/db_panic.c:67
vpanic() at netbsd:vpanic+0x265 syzkaller/managers/netbsd/kernel/sys/kern/subr_prf.c:290
snprintf() at netbsd:snprintf
kasan_report() at netbsd:kasan_report+0x8c kasan_code_name syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:168 [inline]
kasan_report() at netbsd:kasan_report+0x8c syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:200
__asan_load4() at netbsd:__asan_load4+0x9a kasan_shadow_4byte_isvalid syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:350 [inline]
__asan_load4() at netbsd:__asan_load4+0x9a kasan_shadow_check syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:417 [inline]
__asan_load4() at netbsd:__asan_load4+0x9a syzkaller/managers/netbsd/kernel/sys/kern/subr_asan.c:1206
ttioctl() at netbsd:ttioctl+0xdbd syzkaller/managers/netbsd/kernel/sys/kern/tty.c:1087
ptyioctl() at netbsd:ptyioctl+0x526 syzkaller/managers/netbsd/kernel/sys/kern/tty_pty.c:1182
cdev_ioctl() at netbsd:cdev_ioctl+0x147 syzkaller/managers/netbsd/kernel/sys/kern/subr_devsw.c:935
spec_ioctl() at netbsd:spec_ioctl+0x20f syzkaller/managers/netbsd/kernel/sys/miscfs/specfs/spec_vnops.c:933
VOP_IOCTL() at netbsd:VOP_IOCTL+0x12c syzkaller/managers/netbsd/kernel/sys/kern/vnode_if.c:646
vn_ioctl() at netbsd:vn_ioctl+0x1b9 syzkaller/managers/netbsd/kernel/sys/kern/vfs_vnops.c:783
sys_fcntl() at netbsd:sys_fcntl+0xa0e syzkaller/managers/netbsd/kernel/sys/kern/sys_descrip.c:476
sys___syscall() at netbsd:sys___syscall+0xff sy_call syzkaller/managers/netbsd/kernel/sys/sys/syscallvar.h:65 [inline]
sys___syscall() at netbsd:sys___syscall+0xff syzkaller/managers/netbsd/kernel/sys/kern/sys_syscall.c:77
syscall() at netbsd:syscall+0x259 sy_call syzkaller/managers/netbsd/kernel/sys/sys/syscallvar.h:65 [inline]
syscall() at netbsd:syscall+0x259 sy_invoke syzkaller/managers/netbsd/kernel/sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x259 syzkaller/managers/netbsd/kernel/sys/arch/x86/x86/syscall.c:138
--- syscall (number 198) ---
netbsd:syscall+0x259:
Panic string: ASan: Unauthorized Access In 0xffffffff819df37a: Addr 0xffff9d0015080b10 [4 bytes, read, PoolUseAfterFree]

PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
5825 >6973 7 1 100 ffff9d0013bcea00 syz-executor.1
5825 5825 2 1 10000140 ffff9d0013a9d8c0 syz-executor.1
6444 6444 2 0 0 ffff9d00153a7240 syz-executor.4
6457 >6457 7 0 40140 ffff9d0013c4e700 syz-executor.1
5960 5960 3 1 180 ffff9d0013bb1580 syz-executor.3 parked
1342 1342 3 0 180 ffff9d0013cf3240 syz-executor.3 parked
460 460 3 0 180 ffff9d0013c63b80 syz-executor.2 parked
1347 1347 3 0 180 ffff9d0013c63740 syz-executor.2 parked
1191 1191 3 0 1c0 ffff9d00152d9640 syz-executor.5 pipe_rd
1189 1189 3 0 1c0 ffff9d00152d9200 syz-executor.3 pipe_rd
1073 1073 3 0 1c0 ffff9d001529a1c0 syz-executor.2 pipe_rd
422 422 3 0 1c0 ffff9d0013b66500 syz-executor.0 pipe_rd
1079 1151 3 1 1c0 ffff9d0015150a00 syz-fuzzer parked
1079 1078 3 1 1c0 ffff9d00151505c0 syz-fuzzer parked
1079 1101 3 1 180 ffff9d0013be9a40 syz-fuzzer parked
1079 1076 3 1 180 ffff9d0014841b00 syz-fuzzer parked
1079 1074 3 1 180 ffff9d00148416c0 syz-fuzzer kqueue
1079 1083 3 0 180 ffff9d0014855700 syz-fuzzer parked
1079 1125 3 1 180 ffff9d0014881080 syz-fuzzer parked
1079 1077 3 1 180 ffff9d001398eb00 syz-fuzzer parked
1079 1079 3 0 180 ffff9d0013a9d480 syz-fuzzer parked
1072 1072 3 1 180 ffff9d0013aba4c0 sshd select
1249 1249 3 0 180 ffff9d00148c1140 getty nanoslp
1250 1250 3 0 180 ffff9d00136e9700 getty nanoslp
947 947 3 1 180 ffff9d0013959a80 getty nanoslp
979 979 3 0 1c0 ffff9d00139fc700 getty ttyraw
952 952 3 0 180 ffff9d00147d7a40 sshd select
991 991 3 1 180 ffff9d0013d00b00 powerd kqueue
555 555 3 1 180 ffff9d0014855b40 syslogd kqueue
599 599 3 0 180 ffff9d0013c2cb00 dhcpcd poll
598 598 3 0 180 ffff9d0013c934c0 dhcpcd poll
597 597 3 1 180 ffff9d0013c0e240 dhcpcd poll
578 578 3 1 180 ffff9d0013c63300 dhcpcd poll
350 350 3 0 180 ffff9d0013d7f8c0 dhcpcd poll
349 349 3 0 180 ffff9d0013d7f480 dhcpcd poll
348 348 3 0 180 ffff9d0013d7f040 dhcpcd poll
1 1 3 0 180 ffff9d001385b140 init wait
0 796 3 0 200 ffff9d001398c240 physiod physiod
0 192 3 0 200 ffff9d001398e280 pooldrain pooldrain
0 163 2 1 240 ffff9d001398cac0 ioflush
0 168 3 1 200 ffff9d001398c680 pgdaemon pgdaemon
0 162 3 1 200 ffff9d0013959640 usb7 usbevt
0 161 3 1 200 ffff9d0013959200 usb6 usbevt
0 31 3 1 200 ffff9d001390ba40 usb5 usbevt
0 63 3 0 200 ffff9d001390b600 usb4 usbevt
0 126 3 1 200 ffff9d001390b1c0 usb3 usbevt
0 125 3 0 200 ffff9d00138b9a00 usb2 usbevt
0 124 3 1 200 ffff9d00138b95c0 usb1 usbevt
0 123 3 0 200 ffff9d00138b9180 usb0 usbevt
0 122 3 1 200 ffff9d001385b9c0 usbtask-dr usbtsk
0 121 3 1 200 ffff9d0010dbbac0 usbtask-hc usbtsk
0 120 3 0 200 ffff9d001385b580 npfgc0 npfgcw
0 119 3 1 200 ffff9d001384c980 rt_free rt_free
0 118 3 1 200 ffff9d001384c540 unpgc unpgc
0 117 3 0 200 ffff9d001384c100 key_timehandler key_timehandler
0 116 3 1 200 ffff9d001371b940 icmp6_wqinput/1 icmp6_wqinput
0 115 3 0 200 ffff9d001371b500 icmp6_wqinput/0 icmp6_wqinput
0 114 3 1 200 ffff9d001371b0c0 nd6_timer nd6_timer
0 113 3 1 200 ffff9d0013711900 carp6_wqinput/1 carp6_wqinput
0 112 3 0 200 ffff9d00137114c0 carp6_wqinput/0 carp6_wqinput
0 111 3 1 200 ffff9d0013711080 carp_wqinput/1 carp_wqinput
0 110 3 0 200 ffff9d00137008c0 carp_wqinput/0 carp_wqinput
0 109 3 1 200 ffff9d0013700480 icmp_wqinput/1 icmp_wqinput
0 108 3 0 200 ffff9d0013700040 icmp_wqinput/0 icmp_wqinput
0 107 3 0 200 ffff9d00136edbc0 rt_timer rt_timer
0 106 3 0 200 ffff9d00136ed780 vmem_rehash vmem_rehash
0 105 3 0 200 ffff9d00136ecb80 entbutler entropy
0 96 3 1 200 ffff9d00130c0b00 viomb balloon
0 30 3 1 200 ffff9d00130c06c0 vioif0_txrx/1 vioif0_txrx
0 29 3 0 200 ffff9d00130c0280 vioif0_txrx/0 vioif0_txrx
0 27 3 0 200 ffff9d0010dbb680 scsibus0 sccomp
0 26 3 0 200 ffff9d0010dbb240 pms0 pmsreset
0 25 3 1 200 ffff9d0010d0ea80 xcall/1 xcall
0 24 1 1 200 ffff9d0010d0e640 softser/1
0 23 1 1 200 ffff9d0010d0e200 softclk/1
0 22 1 1 200 ffff9d0010d0ca40 softbio/1
0 21 1 1 200 ffff9d0010d0c600 softnet/1
0 20 1 1 201 ffff9d0010d0c1c0 idle/1
0 19 3 0 200 ffff9d000f77da00 lnxpwrwq lnxpwrwq
0 18 3 0 200 ffff9d000f77d5c0 lnxlngwq lnxlngwq
0 17 3 0 200 ffff9d000f77d180 lnxsyswq lnxsyswq
0 16 3 0 200 ffff9d000f7759c0 lnxrcugc lnxrcugc
0 15 3 0 200 ffff9d000f775580 sysmon smtaskq
0 14 3 0 200 ffff9d000f775140 pmfsuspend pmfsuspend
0 13 3 0 200 ffff9d000f771980 pmfevent pmfevent
0 12 3 0 200 ffff9d000f771540 sopendfree sopendfr
0 11 3 0 200 ffff9d000f771100 iflnkst iflnkst
0 10 3 0 200 ffff9d000f766940 nfssilly nfssilly
0 9 3 0 200 ffff9d000f766500 vdrain vdrain
0 8 3 0 200 ffff9d000f7660c0 modunload mod_unld
0 7 3 0 200 ffff9d000f758900 xcall/0 xcall
0 6 1 0 200 ffff9d000f7584c0 softser/0
0 > 5 7 0 200 ffff9d000f758080 softclk/0
0 4 1 0 200 ffff9d000f7568c0 softbio/0
0 3 1 0 200 ffff9d000f756480 softnet/0
0 2 1 0 201 ffff9d000f756040 idle/0
0 0 3 0 240 ffffffff82eee940 swapper tstile
[Locks tracked through LWPs]

****** LWP 5825.6973 (syz-executor.1) @ 0xffff9d0013bcea00, l_stat=7

*** Locks held:

* Lock 0 (initialized at procinit)
lock address : 0xffffffff82ff69c0 type : sleep/adaptive
initialized : 0xffffffff818ef8d5
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d0013bcea00 last held: 0xffff9d0013bcea00
last locked* : 0xffffffff819df2d8 unlocked : 0xffffffff818c61f0
owner field : 0xffff9d0013bcea00 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 1 waiting writers: 0xffffffff82eee940

*** Locks wanted: none

****** LWP 6444.6444 (syz-executor.4) @ 0xffff9d00153a7240, l_stat=2

*** Locks held:

* Lock 0 (initialized at kcov_open)
lock address : 0xffff9d00153f91c0 type : sleep/adaptive
initialized : 0xffffffff81973564
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d00153a7240 last held: 0xffff9d00153a7240
last locked* : 0xffffffff8197393e unlocked : 000000000000000000
owner field : 0xffff9d00153a7240 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at uvm_obj_init)
lock address : 0xffff9d0015570ac0 type : sleep/adaptive
initialized : 0xffffffff8185d75a
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d00153a7240 last held: 0xffff9d00153a7240
last locked* : 0xffffffff8183d77e unlocked : 0xffffffff8183aa0c
owner/count : 0xffff9d00153a7240 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 598.598 (dhcpcd) @ 0xffff9d0013c934c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff82ff68c0 type : sleep/adaptive
initialized : 0xffffffff818e1d61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d0013c934c0 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 597.597 (dhcpcd) @ 0xffff9d0013c0e240, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff82ff68c0 type : sleep/adaptive
initialized : 0xffffffff818e1d61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d0013c0e240 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 349.349 (dhcpcd) @ 0xffff9d0013d7f480, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff82ff68c0 type : sleep/adaptive
initialized : 0xffffffff818e1d61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d0013d7f480 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 348.348 (dhcpcd) @ 0xffff9d0013d7f040, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff82ff68c0 type : sleep/adaptive
initialized : 0xffffffff818e1d61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d0013d7f040 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.23 (softclk/1) @ 0xffff9d0010d0e200, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff82ff68c0 type : sleep/adaptive
initialized : 0xffffffff818e1d61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d0010d0e200 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffff9d000f771100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at module_hook_init)
lock address : 0xffffffff82ff68c0 type : sleep/adaptive
initialized : 0xffffffff818e1d61
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d000f771100 last held: 000000000000000000
last locked : 000000000000000000 unlocked*: 000000000000000000
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

******* Locks held on cpu1:

* Lock 0 (initialized at main)
lock address : 0xffffffff82ff67c0 type : spin
initialized : 0xffffffff81c8af44
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d0013bcea00 last held: 0xffff9d0013bcea00
last locked* : 0xffffffff8196428e unlocked : 0xffffffff81963d64
curcpu holds : 1 wanted by: 000000000000000000

PAGE FLAG PQ UOBJECT UANON
0xffff9d0000017180 0041 00000000 0x0 0x0
0xffff9d0000017200 0041 00000000 0x0 0x0
0xffff9d0000017280 0041 00000000 0x0 0x0
0xffff9d0000017300 0041 00000000 0x0 0x0
0xffff9d0000017380 0041 00000000 0x0 0x0
0xffff9d0000017400 0041 00000000 0x0 0x0
0xffff9d0000017480 0041 00000000 0x0 0x0
0xffff9d0000017500 0041 00000000 0x0 0x0
0xffff9d0000017580 0041 00000000 0x0 0x0
0xffff9d0000017600 0041 00000000 0x0 0x0
0xffff9d0000017680 0041 00000000 0x0 0x0
0xffff9d0000017700 0041 00000000 0x0 0x0
0xffff9d0000017780 0041 00000000 0x0 0x0
0xffff9d0000017800 0041 00000000 0x0 0x0
0xffff9d0000017880 0041 00000000 0x0 0x0
0xffff9d0000017900 0041 00000000 0x0 0x0
0xffff9d0000017980 0041 00000000 0x0 0x0
0xffff9d0000017a00 0041 00000000 0x0 0x0
0xffff9d0000017a80 0041 00000000 0x0 0x0
0xffff9d0000017b00 0041 00000000 0x0 0x0
0xffff9d0000017b80 0041 00000000 0x0 0x0
0xffff9d0000017c00 0041 00000000 0x0 0x0
0xffff9d0000017c80 0041 00000000 0x0 0x0
0xffff9d0000017d00 0041 00000000 0x0 0x0
0xffff9d0000017d80 0041 00000000 0x0 0x0
0xffff9d0000017e00 0041 00000000 0x0 0x0
0xffff9d0000017e80 0041 00000000 0x0 0x0
0xffff9d0000017f00 0041 00000000 0x0 0x0
0xffff9d0000017f80 0041 00000000 0x0 0x0
0xffff9d0000018000 0041 00000000 0x0 0x0
0xffff9d0000018080 0041 00000000 0x0 0x0
0xffff9d0000018100 0041 00000000 0x0 0x0
0xffff9d0000018180 0041 00000000 0x0 0x0
0xffff9d0000018200 0041 00000000 0x0 0x0
0xffff9d0000018280 0041 00000000 0x0 0x0
0xffff9d0000018300 0041 00000000 0x0 0x0
0xffff9d0000018380 0041 00000000 0x0 0x0
0xffff9d0000018400 0041 00000000 0x0 0x0
0xffff9d0000018480 0041 00000000 0x0 0x0
0xffff9d0000018500 0041 00000000 0x0 0x0
0xffff9d0000018580 0041 00000000 0x0 0x0
0xffff9d0000018600 0041 00000000 0x0 0x0
0xffff9d0000018680 0041 00000000 0x0 0x0
0xffff9d0000018700 0041 00000000 0x0 0x0
0xffff9d0000018780 0041 00000000 0x0 0x0
0xffff9d0000018800 0041 00000000 0x0 0x0
0xffff9d0000018880 0041 00000000 0x0 0x0
0xffff9d0000018900 0041 00000000 0x0 0x0
0xffff9d0000018980 0041 00000000 0x0 0x0
0xffff9d0000018a00 0041 00000000 0x0 0x0
0xffff9d0000018a80 0041 00000000 0x0 0x0
0xffff9d0000018b00 0041 00000000 0x0 0x0
0xffff9d0000018b80 0041 00000000 0x0 0x0
0xffff9d0000018c00 0041 00000000 0x0 0x0
0xffff9d0000018c80 0041 00000000 0x0 0x0
0xffff9d0000018d00 0041 00000000 0x0 0x0
0xffff9d0000018d80 0041 00000000 0x0 0x0
0xffff9d0000018e00 0041 00000000 0x0 0x0
0xffff9d0000018e80 0041 00000000 0x0 0x0
0xffff9d0000018f00 0041 00000000 0x0 0x0
0xffff9d0000018f80 0041 00000000 0x0 0x0
0xffff9d0000019000 0041 00000000 0x0 0x0
0xffff9d0000019080 0041 00000000 0x0 0x0
0xffff9d0000019100 0041 00000000 0x0 0x0
0xffff9d0000019180 0041 00000000 0x0 0x0
0xffff9d0000019200 0041 00000000 0x0 0x0
0xffff9d0000019280 0041 00000000 0x0 0x0
0xffff9d0000019300 0041 00000000 0x0 0x0
0xffff9d0000019380 0041 00000000 0x0 0x0
0xffff9d0000019400 0041 00000000 0x0 0x0
0xffff9d0000019480 0041 00000000 0x0 0x0
0xffff9d0000019500 0041 00000000 0x0 0x0
0xffff9d0000019580 0041 00000000 0x0 0x0
0xffff9d0000019600 0041 00000000 0x0 0x0
0xffff9d0000019680 0041 00000000 0x0 0x0
0xffff9d0000019700 0041 00000000 0x0 0x0
0xffff9d0000019780 0041 00000000 0x0 0x0
0xffff9d0000019800 0041 00000000 0x0 0x0
0xffff9d0000019880 0041 00000000 0x0 0x0
0xffff9d0000019900 0041 00000000 0x0 0x0
0xffff9d0000019980 0041 00000000 0x0 0x0
0xffff9d0000019a00 0041 00000000 0x0 0x0
0xffff9d0000019a80 0041 00000000 0x0 0x0
0xffff9d0000019b00 0041 00000000 0x0 0x0
0xffff9d0000019b80 0041 00000000 0x0 0x0
0xffff9d0000019c00 0041 00000000 0x0 0x0
0xffff9d0000019c80 0041 00000000 0x0 0x0
0xffff9d0000019d00 0041 00000000 0x0 0x0
0xffff9d0000019d80 0041 00000000 0x0 0x0
0xffff9d0000019e00 0041 00000000 0x0 0x0
0xffff9d0000019e80 0041 00000000 0x0 0x0
0xffff9d0000019f00 0041 00000000 0x0 0x0
0xffff9d0000019f80 0041 00000000 0x0 0x0
0xffff9d000001a000 0041 00000000 0x0 0x0
0xffff9d000001a080 0041 00000000 0x0 0x0
0xffff9d000001a100 0041 00000000 0x0 0x0
0xffff9d000001a180 0041 00000000 0x0 0x0
0xffff9d000001a200 0041 00000000 0x0 0x0
0xffff9d000001a280 0041 00000000 0x0 0x0
0xffff9d000001a300 0041 00000000 0x0 0x0
0xffff9d000001a380 0041 00000000 0x0 0x0
0xffff9d000001a400 0041 00000000 0x0 0x0
0xffff9d000001a480 0041 00000000 0x0 0x0
0xffff9d000001a500 0041 00000000 0x0 0x0
0xffff9d000001a580 0041 00000000 0x0 0x0
0xffff9d000001a600 0041 00000000 0x0 0x0
0xffff9d000001a680 0041 00000000 0x0 0x0
0xffff9d000001a700 0041 00000000 0x0 0x0
0xffff9d000001a780 0041 00000000 0x0 0x0
0xffff9d000001a800 0041 00000000 0x0 0x0
0xffff9d000001a880 0041 00000000 0x0 0x0
0xffff9d000001a900 0041 00000000 0x0 0x0
0xffff9d000001a980 0041 00000000 0x0 0x0
0xffff9d000001aa00 0041 00000000 0x0 0x0
0xffff9d000001aa80 0041 00000000 0x0 0x0
0xffff9d000001ab00 0041 00000000 0x0 0x0
0xffff9d000001ab80 0001 00000000 0x0 0x0
0xffff9d000001ac00 0001 00000000 0x0 0x0
0xffff9d000001ac80 0001 00000000 0x0 0x0
0xffff9d000001ad00 0001 00000000 0x0 0x0
0xffff9d000001ad80 0001 00000000 0x0 0x0
0xffff9d000001ae00 0001 00000000 0x0 0x0
0xffff9d000001ae80 0001 00000000 0x0 0x0
0xffff9d000001af00 0001 00000000 0x0 0x0
0xffff9d000001af80 0001 00000000 0x0 0x0
0xffff9d000001b000 0001 00000000 0x0 0x0
0xffff9d000001b080 0001 00000000 0x0 0x0
0xffff9d000001b100 0001 00000000 0x0 0x0
0xffff9d000001b180 0001 00000000 0x0 0x0
0xffff9d000001b200 0001 00000000 0x0 0x0
0xffff9d000001b280 0001 00000000 0x0 0x0
0xffff9d000001b300 0001 00000000 0x0 0x0
0xffff9d000001b380 0001 00000000 0x0 0x0
0xffff9d000001b400 0001 00000000 0x0 0x0
0xffff9d000001b480 0001 00000000 0x0 0x0
0xffff9d000001b500 0001 00000000 0x0 0x0
0xffff9d000001b580 0001 00000000 0x0 0x0
0xffff9d000001b600 0001 00000000 0x0 0x0
0xffff9d000001b680 0001 00000000 0x0 0x0
0xffff9d000001b700 0001 00000000 0x0 0x0
0xffff9d000001b780 0001 00000000 0x0 0x0
0xffff9d000001b800 0001 00000000 0x0 0x0
0xffff9d000001b880 0001 00000000 0x0 0x0
0xffff9d000001b900 0001 00000000 0x0 0x0
0xffff9d000001b980 0001 00000000 0x0 0x0
0xffff9d000001ba00 0001 00000000 0x0 0x0
0xffff9d000001ba80 0001 00000000 0x0 0x0
0xffff9d000001bb00 0001 00000000 0x0 0x0
0xffff9d000001bb80 0001 00000000 0x0 0x0
0xffff9d000001bc00 0001 00000000 0x0 0x0
0xffff9d000001bc80 0001 00000000 0x0 0x0
0xffff9d000001bd00 0001 00000000 0x0 0x0
0xffff9d000001bd80 0001 00000000 0x0 0x0
0xffff9d000001be00 0001 00000000 0x0 0x0
0xffff9d000001be80 0001 00000000 0x0 0x0
0xffff9d000001bf00 0001 00000000 0x0 0x0
0xffff9d000001bf80 0001 00000000 0x0 0x0
0xffff9d000001c000 0001 00000000 0x0 0x0
0xffff9d000001c080 0001 00000000 0x0 0x0
0xffff9d000001c100 0001 00000000 0x0 0x0
0xffff9d000001c180 0001 00000000 0x0 0x0
0xffff9d000001c200 0001 00000000 0x0 0x0
0xffff9d000001c280 0001 00000000 0x0 0x0
0xffff9d000001c300 0001 00000000 0x0 0x0
0xffff9d000001c380 0001 00000000 0x0 0x0
0xffff9d000001c400 0001 00000000 0x0 0x0
0xffff9d000001c480 0001 00000000 0x0 0x0
0xffff9d000001c500 0001 00000000 0x0 0x0
0xffff9d000001c580 0001 00000000 0x0 0x0
0xffff9d000001c600 0001 00000000 0x0 0x0
0xffff9d000001c680 0001 00000000 0x0 0x0
0xffff9d000001c700 0001 00000000 0x0 0x0
0xffff9d000001c780 0001 00000000 0x0 0x0
0xffff9d000001c800 0001 00000000 0x0 0x0
0xffff9d000001c880 0001 00000000 0x0 0x0
0xffff9d000001c900 0001 00000000 0x0 0x0
0xffff9d000001c980 0001 00000000 0x0 0x0
0xffff9d000001ca00 0001 00000000 0x0 0x0
0xffff9d000001ca80 0001 00000000 0x0 0x0
0xffff9d000001cb00 0001 00000000 0x0 0x0
0xffff9d000001cb80 0001 00000000 0x0 0x0
0xffff9d000001cc00 0001 00000000 0x0 0x0
0xffff9d000001cc80 0001 00000000 0x0 0x0
0xffff9d000001cd00 0001 00000000 0x0 0x0
0xffff9d000001cd80 0001 00000000 0x0 0x0
0xffff9d000001ce00 0001 00000000 0x0 0x0
0xffff9d000001ce80 0001 00000000 0x0 0x0
0xffff9d000001cf00 0001 00000000 0x0 0x0
0xffff9d000001cf80 0001 00000000 0x0 0x0
0xffff9d000001d000 0001 00000000 0x0 0x0
0xffff9d000001d080 0001 00000000 0x0 0x0
0xffff9d000001d100 0001 00000000 0x0 0x0
0xffff9d000001d180 0001 00000000 0x0 0x0
0xffff9d000001d200 0001 00000000 0x0 0x0
0xffff9d000001d280 0001 00000000 0x0 0x0
0xffff9d000001d300 0001 00000000 0x0 0x0
0xffff9d000001d380 0001 00000000 0x0 0x0
0xffff9d000001d400 0001 00000000 0x0 0x0
0xffff9d000001d480 0001 00000000 0x0 0x0
0xffff9d000001d500 0001 00000000 0x0 0x0
0xffff9d000001d580 0001 00000000 0x0 0x0
0xffff9d000001d600 0001 00000000 0x0 0x0
0xffff9d000001d680 0001 00000000 0x0 0x0
0xffff9d000001d700 0001 00000000 0x0 0x0
0xffff9d000001d780 0001 00000000 0x0 0x0
0xffff9d000001d800 0001 00000000 0x0 0x0
0xffff9d000001d880 0001 00000000 0x0 0x0
0xffff9d000001d900 0001 00000000 0x0 0x0
0xffff9d000001d980 0001 00000000 0x0 0x0
0xffff9d000001da00 0001 00000000 0x0 0x0
0xffff9d000001da80 0001 00000000 0x0 0x0
0xffff9d000001db00 0001 00000000 0x0 0x0
0xffff9d000001db80 0001 00000000 0x0 0x0
0xffff9d000001dc00 0001 00000000 0x0 0x0
0xffff9d000001dc80 0001 00000000 0x0 0x0
0xffff9d000001dd00 0001 00000000 0x0 0x0
0xffff9d000001dd80 0001 00000000 0x0 0x0
0xffff9d000001de00 0001 00000000 0x0 0x0
0xffff9d000001de80 0001 00000000 0x0 0x0
0xffff9d000001df00 0001 00000000 0x0 0x0
0xffff9d000001df80 0001 00000000 0x0 0x0
0xffff9d000001e000 0001 00000000 0x0 0x0
0xffff9d000001e080 0001 00000000 0x0 0x0
0xffff9d000001e100 0001 00000000 0x0 0x0
0xffff9d000001e180 0001 00000000 0x0 0x0
0xffff9d000001e200 0001 00000000 0x0 0x0
0xffff9d000001e280 0001 00000000 0x0 0x0
0xffff9d000001e300 0001 00000000 0x0 0x0
0xffff9d000001e380 0001 00000000 0x0 0x0
0xffff9d000001e400 0001 00000000 0x0 0x0
0xffff9d000001e480 0001 00000000 0x0 0x0
0xffff9d000001e500 0001 00000000 0x0 0x0
0xffff9d000001e580 0001 00000000 0x0 0x0
0xffff9d000001e600 0001 00000000 0x0 0x0
0xffff9d000001e680 0001 00000000 0x0 0x0
0xffff9d000001e700 0001 00000000 0x0 0x0
0xffff9d000001e780 0001 00000000 0x0 0x0
0xffff9d000001e800 0001 00000000 0x0 0x0
0xffff9d000001e880 0001 00000000 0x0 0x0
0xffff9d000001e900 0001 00000000 0x0 0x0
0xffff9d000001e980 0001 00000000 0x0 0x0
0xffff9d000001ea00 0001 00000000 0x0 0x0
0xffff9d000001ea80 0001 00000000 0x0 0x0
0xffff9d000001eb00 0001 00000000 0x0 0x0
0xffff9d000001eb80 0001 00000000 0x0 0x0
0xffff9d000001ec00 0001 00000000 0x0 0x0
0xffff9d000001ec80 0001 00000000 0x0 0x0
0xffff9d000001ed00 0001 00000000 0x0 0x0
0xffff9d000001ed80 0001 00000000 0x0 0x0
0xffff9d000001ee00 0001 00000000 0x0 0x0
0xffff9d000001ee80 0001 00000000 0x0 0x0
0xffff9d000001ef00 0001 00000000 0x0 0x0
0xffff9d000001ef80 0001 00000000 0x0 0x0
0xffff9d000001f000 0001 00000000 0x0 0x0
0xffff9d000001f080 0001 00000000 0x0 0x0
0xffff9d000001f100 0001 00000000 0x0 0x0
0xffff9d000001f180 0001 00000000 0x0 0x0
0xffff9d000001f200 0001 00000000 0x0 0x0
0xffff9d000001f280 0001 00000000 0x0 0x0
0xffff9d000001f300 0001 00000000 0x0 0x0
0xffff9d000001f380 0001 00000000 0x0 0x0
0xffff9d000001f400 0001 00000000 0x0 0x0
0xffff9d000001f480 0001 00000000 0x0 0x0
0xffff9d000001f500 0001 00000000 0x0 0x0
0xffff9d000001f580 0001 00000000 0x0 0x0
0xffff9d000001f600 0001 00000000 0x0 0x0
0xffff9d000001f680 0001 00000000 0x0 0x0
0xffff9d000001f700 0001 00000000 0x0 0x0
0xffff9d000001f780 0001 00000000 0x0 0x0
0xffff9d000001f800 0001 00000000 0x0 0x0
0xffff9d000001f880 0001 00000000 0x0 0x0
0xffff9d000001f900 0001 00000000 0x0 0x0
0xffff9d000001f980 0001 00000000 0x0 0x0
0xffff9d000001fa00 0001 00000000 0x0 0x0
0xffff9d000001fa80 0001 00000000 0x0 0x0
0xffff9d000001fb00 0001 00000000 0x0 0x0
0xffff9d000001fb80 0001 00000000 0x0 0x0
0xffff9d000001fc00 0001 00000000 0x0 0x0
0xffff9d000001fc80 0001 00000000 0x0 0x0
0xffff9d000001fd00 0001 00000000 0x0 0x0
0xffff9d000001fd80 0001 00000000 0x0 0x0
0xffff9d000001fe00 0001 00000000 0x0 0x0
0xffff9d000001fe80 0001 00000000 0x0 0x0
0xffff9d000001ff00 0001 00000000 0x0 0x0
0xffff9d000001ff80 0001 00000000 0x0 0x0
0xffff9d0000020000 0001 00000000 0x0 0x0
0xffff9d0000020080 0001 00000000 0x0 0x0
0xffff9d0000020100 0001 00000000 0x0 0x0
0xffff9d0000020180 0001 00000000 0x0 0x0
0xffff9d0000020200 0001 00000000 0x0 0x0
0xffff9d0000020280 0001 00000000 0x0 0x0
0xffff9d0000020300 0001 00000000 0x0 0x0
0xffff9d0000020380 0001 00000000 0x0 0x0
0xffff9d0000020400 0001 00000000 0x0 0x0
0xffff9d0000020480 0001 00000000 0x0 0x0
0xffff9d0000020500 0001 00000000 0x0 0x0
0xffff9d0000020580 0001 00000000 0x0 0x0
0xffff9d0000020600 0001 00000000 0x0 0x0
0xffff9d0000020680 0001 00000000 0x0 0x0
0xffff9d0000020700 0001 00000000 0x0 0x0
0xffff9d0000020780 0001 00000000 0x0 0x0
0xffff9d0000020800 0001 00000000 0x0 0x0
0xffff9d0000020880 0001 00000000 0x0 0x0
0xffff9d0000020900 0001 00000000 0x0 0x0
0xffff9d0000020980 0001 00000000 0x0 0x0
0xffff9d0000020a00 0001 00000000 0x0 0x0
0xffff9d0000020a80 0001 00000000 0x0 0x0
0xffff9d0000020b00 0001 00000000 0x0 0x0
0xffff9d0000020b80 0001 00000000 0x0 0x0
0xffff9d0000020c00 0001 00000000 0x0 0x0
0xffff9d0000020c80 0001 00000000 0x0 0x0
0xffff9d0000020d00 0001 00000000 0x0 0x0
0xffff9d0000020d80 0001 00000000 0x0 0x0
0xffff9d0000020e00 0001 00000000 0x0 0x0
0xffff9d0000020e80 0001 00000000 0x0 0x0
0xffff9d0000020f00 0001 00000000 0x0 0x0
0xffff9d0000020f80 0001 00000000 0x0 0x0
0xffff9d0000021000 0001 00000000 0x0 0x0
0xffff9d0000021080 0001 00000000 0x0 0x0
0xffff9d0000021100 0001 00000000 0x0 0x0
0xffff9d0000021180 0001 00000000 0x0 0x0
0xffff9d0000021200 0001 00000000 0x0 0x0
0xffff9d0000021280 0001 00000000 0x0 0x0
0xffff9d0000021300 0001 00000000 0x0 0x0
0xffff9d0000021380 0001 00000000 0x0 0x0
0xffff9d0000021400 0001 00000000 0x0 0x0
0xffff9d0000021480 0001 00000000 0x0 0x0
0xffff9d0000021500 0001 00000000 0x0 0x0
0xffff9d0000021580 0001 00000000 0x0 0x0
0xffff9d0000021600 0001 00000000 0x0 0x0
0xffff9d0000021680 0001 00000000 0x0 0x0
0xffff9d0000021700 0001 00000000 0x0 0x0
0xffff9d0000021780 0001 00000000 0x0 0x0
0xffff9d0000021800 0001 00000000 0x0 0x0
0xffff9d0000021880 0001 00000000 0x0 0x0
0xffff9d0000021900 0001 00000000 0x0 0x0
0xffff9d0000021980 0001 00000000 0x0 0x0
0xffff9d0000021a00 0001 00000000 0x0 0x0
0xffff9d0000021a80 0001 00000000 0x0 0x0
0xffff9d0000021b00 0001 00000000 0x0 0x0
0xffff9d0000021b80 0001 00000000 0x0 0x0
0xffff9d0000021c00 0001 00000000 0x0 0x0
0xffff9d0000021c80 0001 00000000 0x0 0x0
0xffff9d0000021d00 0001 00000000 0x0 0x0
0xffff9d0000021d80 0001 00000000 0x0 0x0
0xffff9d0000021e00 0001 00000000 0x0 0x0
0xffff9d0000021e80 0001 00000000 0x0 0x0
0xffff9d0000021f00 0001 00000000 0x0 0x0
0xffff9d0000021f80 0001 00000000 0x0 0x0
0xffff9d0000022000 0001 00000000 0x0 0x0
0xffff9d0000022080 0001 00000000 0x0 0x0
0xffff9d0000022100 0001 00000000 0x0 0x0
0xffff9d0000022180 0001 00000000 0x0 0x0
0xffff9d0000022200 0001 00000000 0x0 0x0
0xffff9d0000022280 0001 00000000 0x0 0x0
0xffff9d0000022300 0001 00000000 0x0 0x0
0xffff9d0000022380 0001 00000000 0x0 0x0
0xffff9d0000022400 0001 00000000 0x0 0x0
0xffff9d0000022480 0001 00000000 0x0 0x0
0xffff9d0000022500 0001 00000000 0x0 0x0
0xffff9d0000022580 0001 00000000 0x0 0x0
0xffff9d0000022600 0001 00000000 0x0 0x0
0xffff9d0000022680 0001 00000000 0x0 0x0
0xffff9d0000022700 0001 00000000 0x0 0x0
0xffff9d0000022780 0001 00000000 0x0 0x0
0xffff9d0000022800 0001 00000000 0x0 0x0
0xffff9d0000022880 0001 00000000 0x0 0x0
0xffff9d0000022900 0001 00000000 0x0 0x0
0xffff9d0000022980 0001 00000000 0x0 0x0
0xffff9d0000022a00 0001 00000000 0x0 0x0
0xffff9d0000022a80 0001 00000000 0x0 0x0
0xffff9d0000022b00 0001 00000000 0x0 0x0
0xffff9d0000022b80 0001 00000000 0x0 0x0
0xffff9d0000022c00 0001 00000000 0x0 0x0
0xffff9d0000022c80 0001 00000000 0x0 0x0
0xffff9d0000022d00 0001 00000000 0x0 0x0
0xffff9d0000022d80 0001 00000000 0x0 0x0
0xffff9d0000022e00 0001 00000000 0x0 0x0
0xffff9d0000022e80 0001 00000000 0x0 0x0
0xffff9d0000022f00 0001 00000000 0x0 0x0
0xffff9d0000022f80 0001 00000000 0x0 0x0
0xffff9d0000023000 0001 00000000 0x0 0x0
0xffff9d0000023080 0001 00000000 0x0 0x0
0xffff9d0000023100 0001 00000000 0x0 0x0
0xffff9d0000023180 0001 00000000 0x0 0x0
0xffff9d0000023200 0001 00000000 0x0 0x0
0xffff9d0000023280 0001 00000000 0x0 0x0
0xffff9d0000023300 0001 00000000 0x0 0x0
0xffff9d0000023380 0001 00000000 0x0 0x0
0xffff9d0000023400 0001 00000000 0x0 0x0
0xffff9d0000023480 0001 00000000 0x0 0x0
0xffff9d0000023500 0001 00000000 0x0 0x0
0xffff9d0000023580 0001 00000000 0x0 0x0
0xffff9d0000023600 0001 00000000 0x0 0x0
0xffff9d0000023680 0001 00000000 0x0 0x0
0xffff9d0000023700 0001 00000000 0x0 0x0
0xffff9d0000023780 0001 00000000 0x0 0x0
0xffff9d0000023800 0001 00000000 0x0 0x0
0xffff9d0000023880 0001 00000000 0x0 0x0
0xffff9d0000023900 0001 00000000 0x0 0x0
0xffff9d0000023980 0001 00000000 0x0 0x0
0xffff9d0000023a00 0001 00000000 0x0 0x0
0xffff9d0000023a80 0001 00000000 0x0 0x0
0xffff9d0000023b00 0001 00000000 0x0 0x0
0xffff9d0000023b80 0001 00000000 0x0 0x0
0xffff9d0000023c00 0001 00000000 0x0 0x0
0xffff9d0000023c80 0001 00000000 0x0 0x0
0xffff9d0000023d00 0001 00000000 0x0 0x0
0xffff9d0000023d80 0001 00000000 0x0 0x0
0xffff9d0000023e00 0001 00000000 0x0 0x0
0xffff9d0000023e80 0001 00000000 0x0 0x0
0xffff9d0000023f00 0001 00000000 0x0 0x0
0xffff9d0000023f80 0001 00000000 0x0 0x0
0xffff9d0000024000 0001 00000000 0x0 0x0
0xffff9d0000024080 0001 00000000 0x0 0x0
0xffff9d0000024100 0001 00000000 0x0 0x0
0xffff9d0000024180 0001 00000000 0x0 0x0
0xffff9d0000024200 0001 00000000 0x0 0x0
0xffff9d0000024280 0001 00000000 0x0 0x0
0xffff9d0000024300 0001 00000000 0x0 0x0
0xffff9d0000024380 0001 00000000 0x0 0x0
0xffff9d0000024400 0001 00000000 0x0 0x0
0xffff9d0000024480 0001 00000000 0x0 0x0
0xffff9d0000024500 0001 00000000 0x0 0x0
0xffff9d0000024580 0001 00000000 0x0 0x0
0xffff9d0000024600 0001 00000000 0x0 0x0
0xffff9d0000024680 0001 00000000 0x0 0x0
0xffff9d0000024700 0001 00000000 0x0 0x0
0xffff9d0000024780 0001 00000000 0x0 0x0
0xffff9d0000024800 0001 00000000 0x0 0x0
0xffff9d0000024880 0001 00000000 0x0 0x0
0xffff9d0000024900 0001 00000000 0x0 0x0
0xffff9d0000024980 0001 00000000 0x0 0x0
0xffff9d0000024a00 0001 00000000 0x0 0x0
0xffff9d0000024a80 0001 00000000 0x0 0x0
0xffff9d0000024b00 0001 00000000 0x0 0x0
0xffff9d0000024b80 0001 00000000 0x0 0x0
0xffff9d0000024c00 0001 00000000 0x0 0x0
0xffff9d0000024c80 0001 00000000 0x0 0x0
0xffff9d0000024d00 0001 00000000 0x0 0x0
0xffff9d0000024d80 0001 00000000 0x0 0x0
0xffff9d0000024e00 0001 00000000 0x0 0x0
0xffff9d0000024e80 0001 00000000 0x0 0x0
0xffff9d0000024f00 0001 00000000 0x0 0x0
0xffff9d0000024f80 0001 00000000 0x0 0x0
0xffff9d0000025000 0001 00000000 0x0 0x0
0xffff9d0000025080 0001 00000000 0x0 0x0
0xffff9d0000025100 0001 00000000 0x0 0x0
0xffff9d0000025180 0001 00000000 0x0 0x0
0xffff9d0000025200 0001 00000000 0x0 0x0
0xffff9d0000025280 0001 00000000 0x0 0x0
0xffff9d0000025300 0001 00000000 0x0 0x0
0xffff9d0000025380 0001 00000000 0x0 0x0
0xffff9d0000025400 0001 00000000 0x0 0x0
0xffff9d0000025480 0001 00000000 0x0 0x0
0xffff9d0000025500 0001 00000000 0x0 0x0
0xffff9d0000025580 0001 00000000 0x0 0x0
0xffff9d0000025600 0001 00000000 0x0 0x0
0xffff9d0000025680 0001 00000000 0x0 0x0
0xffff9d0000025700 0001 00000000 0x0 0x0
0xffff9d0000025780 0001 00000000 0x0 0x0
0xffff9d0000025800 0001 00000000 0x0 0x0
0xffff9d0000025880 0001 00000000 0x0 0x0
0xffff9d0000025900 0001 00000000 0x0 0x0
0xffff9d0000025980 0001 00000000 0x0 0x0
0xffff9d0000025a00 0001 00000000 0x0 0x0
0xffff9d0000025a80 0001 00000000 0x0 0x0
0xffff9d0000025b00 0001 00000000 0x0 0x0
0xffff9d0000025b80 0001 00000000 0x0 0x0
0xffff9d0000025c00 0001 00000000 0x0 0x0
0xffff9d0000025c80 0001 00000000 0x0 0x0
0xffff9d0000025d00 0001 00000000 0x0 0x0
0xffff9d0000025d80 0001 00000000 0x0 0x0
0xffff9d0000025e00 0001 00000000 0x0 0x0
0xffff9d0000025e80 0001 00000000 0x0 0x0
0xffff9d0000025f00 0001 00000000 0x0 0x0
0xffff9d0000025f80 0001 00000000 0x0 0x0
0xffff9d0000026000 0001 00000000 0x0 0x0
0xffff9d0000026080 0001 00000000 0x0 0x0
0xffff9d0000026100 0001 00000000 0x0 0x0
0xffff9d0000026180 0001 00000000 0x0 0x0
0xffff9d0000026200 0001 00000000 0x0 0x0
0xffff9d0000026280 0001 00000000 0x0 0x0
0xffff9d0000026300 0001 00000000 0x0 0x0
0xffff9d0000026380 0001 00000000 0x0 0x0
0xffff9d0000026400 0001 00000000 0x0 0x0
0xffff9d0000026480 0001 00000000 0x0 0x0
0xffff9d0000026500 0001 00000000 0x0 0x0
0xffff9d0000026580 0001 00000000 0x0 0x0
0xffff9d0000026600 0001 00000000 0x0 0x0
0xffff9d0000026680 0001 00000000 0x0 0x0
0xffff9d0000026700 0001 00000000 0x0 0x0
0xffff9d0000026780 0001 00000000 0x0 0x0
0xffff9d0000026800 0001 00000000 0x0 0x0
0xffff9d0000026880 0001 00000000 0x0 0x0
0xffff9d0000026900 0001 00000000 0x0 0x0
0xffff9d0000026980 0001 00000000 0x0 0x0
0xffff9d0000026a00 0001 00000000 0x0 0x0
0xffff9d0000026a80 0001 00000000 0x0 0x0
0xffff9d0000026b00 0001 00000000 0x0 0x0
0xffff9d0000026b80 0001 00000000 0x0 0x0
0xffff9d0000026c00 0001 00000000 0x0 0x0
0xffff9d0000026c80 0001 00000000 0x0 0x0
0xffff9d0000026d00 0001 00000000 0x0 0x0
0xffff9d0000026d80 0001 00000000 0x0 0x0
0xffff9d0000026e00 0001 00000000 0x0 0x0
0xffff9d0000026e80 0001 00000000 0x0 0x0
0xffff9d0000026f00 0001 00000000 0x0 0x0
0xffff9d0000026f80 0001 00000000 0x0 0x0
0xffff9d0000027000 0001 00000000 0x0 0x0
0xffff9d0000027080 0001 00000000 0x0 0x0
0xffff9d0000027100 0001 00000000 0x0 0x0
0xffff9d0000027180 0001 00000000 0x0 0x0
0xffff9d0000027200 0001 00000000 0x0 0x0
0xffff9d0000027280 0001 00000000 0x0 0x0
0xffff9d0000027300 0001 00000000 0x0 0x0
0xffff9d0000027380 0001 00000000 0x0 0x0
0xffff9d0000027400 0001 00000000 0x0 0x0
0xffff9d0000027480 0001 00000000 0x0 0x0
0xffff9d0000027500 0001 00000000 0x0 0x0
0xffff9d0000027580 0001 00000000 0x0 0x0
0xffff9d0000027600 0001 00000000 0x0 0x0
0xffff9d0000027680 0001 00000000 0x0 0x0
0xffff9d0000027700 0001 00000000 0x0 0x0
0xffff9d0000027780 0001 00000000 0x0 0x0
0xffff9d0000027800 0001 00000000 0x0 0x0
0xffff9d0000027880 0001 00000000 0x0 0x0
0xffff9d0000027900 0001 00000000 0x0 0x0
0xffff9d0000027980 0001 00000000 0x0 0x0
0xffff9d0000027a00 0001 00000000 0x0 0x0
0xffff9d0000027a80 0001 00000000 0x0 0x0
0xffff9d0000027b00 0001 00000000 0x0 0x0
0xffff9d0000027b80 0001 00000000 0x0 0x0
0xffff9d0000027c00 0001 00000000 0x0 0x0
0xffff9d0000027c80 0001 00000000 0x0 0x0
0xffff9d0000027d00 0001 00000000 0x0 0x0
0xffff9d0000027d80 0001 00000000 0x0 0x0
0xffff9d0000027e00 0001 00000000 0x0 0x0
0xffff9d0000027e80 0001 00000000 0x0 0x0
0xffff9d0000027f00 0001 00000000 0x0 0x0
0xffff9d0000027f80 0001 00000000 0x0 0x0
0xffff9d0000028000 0001 00000000 0x0 0x0
0xffff9d0000028080 0001 00000000 0x0 0x0
0xffff9d0000028100 0001 00000000 0x0 0x0
0xffff9d0000028180 0001 00000000 0x0 0x0
0xffff9d0000028200 0001 00000000 0x0 0x0
0xffff9d0000028280 0001 00000000 0x0 0x0
0xffff9d0000028300 0001 00000000 0x0 0x0
0xffff9d0000028380 0001 00000000 0x0 0x0
0xffff9d0000028400 0001 00000000 0x0 0x0
0xffff9d0000028480 0001 00000000 0x0 0x0
0xffff9d0000028500 0001 00000000 0x0 0x0
0xffff9d0000028580 0001 00000000 0x0 0x0
0xffff9d0000028600 0001 00000000 0x0 0x0
0xffff9d0000028680 0001 00000000 0x0 0x0
0xffff9d0000028700 0001 00000000 0x0 0x0
0xffff9d0000028780 0001 00000000 0x0 0x0
0xffff9d0000028800 0001 00000000 0x0 0x0
0xffff9d0000028880 0001 00000000 0x0 0x0
0xffff9d0000028900 0001 00000000 0x0 0x0
0xffff9d0000028980 0001 00000000 0x0 0x0
0xffff9d0000028a00 0001 00000000 0x0 0x0
0xffff9d0000028a80 0001 00000000 0x0 0x0
0xffff9d0000028b00 0001 00000000 0x0 0x0
0xffff9d0000028b80 0001 00000000 0x0 0x0
0xffff9d0000028c00 0001 00000000 0x0 0x0
0xffff9d0000028c80 0001 00000000 0x0 0x0
0xffff9d0000028d00 0001 00000000 0x0 0x0
0xffff9d0000028d80 0001 00000000 0x0 0x0
0xffff9d0000028e00 0001 00000000 0x0 0x0
0xffff9d0000028e80 0001 00000000 0x0 0x0
0xffff9d0000028f00 0001 00000000 0x0 0x0
0xffff9d0000028f80 0001 00000000 0x0 0x0
0xffff9d0000029000 0001 00000000 0x0 0x0
0xffff9d0000029080 0001 00000000 0x0 0x0
0xffff9d0000029100 0001 00000000 0x0 0x0
0xffff9d0000029180 0001 00000000 0x0 0x0
0xffff9d0000029200 0001 00000000 0x0 0x0
0xffff9d0000029280 0001 00000000 0x0 0x0
0xffff9d0000029300 0001 00000000 0x0 0x0
0xffff9d0000029380 0001 00000000 0x0 0x0
0xffff9d0000029400 0001 00000000 0x0 0x0
0xffff9d0000029480 0001 00000000 0x0 0x0
0xffff9d0000029500 0001 00000000 0x0 0x0
0xffff9d0000029580 0001 00000000 0x0 0x0
0xffff9d0000029600 0001 00000000 0x0 0x0
0xffff9d0000029680 0001 00000000 0x0 0x0
0xffff9d0000029700 0001 00000000 0x0 0x0
0xffff9d0000029780 0001 00000000 0x0 0x0
0xffff9d0000029800 0001 00000000 0x0 0x0
0xffff9d0000029880 0001 00000000 0x0 0x0
0xffff9d0000029900 0001 00000000 0x0 0x0
0xffff9d0000029980 0001 00000000 0x0 0x0
0xffff9d0000029a00 0001 00000000 0x0 0x0
0xffff9d0000029a80 0001 00000000 0x0 0x0
0xffff9d0000029b00 0001 00000000 0x0 0x0
0xffff9d0000029b80 0001 00000000 0x0 0x0
0xffff9d0000029c00 0001 00000000 0x0 0x0
0xffff9d0000029c80 0001 00000000 0x0 0x0
0xffff9d0000029d00 0001 00000000 0x0 0x0
0xffff9d0000029d80 0001 00000000 0x0 0x0
0xffff9d0000029e00 0001 00000000 0x0 0x0
0xffff9d0000029e80 0001 00000000 0x0 0x0
0xffff9d0000029f00 0001 00000000 0x0 0x0
0xffff9d0000029f80 0001 00000000 0x0 0x0
0xffff9d000002a000 0001 00000000 0x0 0x0
0xffff9d000002a080 0001 00000000 0x0 0x0
0xffff9d000002a100 0001 00000000 0x0 0x0
0xffff9d000002a180 0001 00000000 0x0 0x0
0xffff9d000002a200 0001 00000000 0x0 0x0
0xffff9d000002a280 0001 00000000 0x0 0x0
0xffff9d000002a300 0001 00000000 0x0 0x0
0xffff9d000002a380 0001 00000000 0x0 0x0
0xffff9d000002a400 0001 00000000 0x0 0x0
0xffff9d000002a480 0001 00000000 0x0 0x0
0xffff9d000002a500 0001 00000000 0x0 0x0
0xffff9d000002a580 0001 00000000 0x0 0x0
0xffff9d000002a600 0001 00000000 0x0 0x0
0xffff9d000002a680 0001 00000000 0x0 0x0
0xffff9d000002a700 0001 00000000 0x0 0x0
0xffff9d000002a780 0001 00000000 0x0 0x0
0xffff9d000002a800 0001 00000000 0x0 0x0
0xffff9d000002a880 0001 00000000 0x0 0x0
0xffff9d000002a900 0001 00000000 0x0 0x0
0xffff9d000002a980 0001 00000000 0x0 0x0
0xffff9d000002aa00 0001 00000000 0x0 0x0
0xffff9d000002aa80 0001 00000000 0x0 0x0
0xffff9d000002ab00 0001 00000000 0x0 0x0
0xffff9d000002ab80 0001 00000000 0x0 0x0
0xffff9d000002ac00 0001 00000000 0x0 0x0
0xffff9d000002ac80 0001 00000000 0x0 0x0
0xffff9d000002ad00 0001 00000000 0x0 0x0
0xffff9d000002ad80 0001 00000000 0x0 0x0
0xffff9d000002ae00 0001 00000000 0x0 0x0
0xffff9d000002ae80 0001 00000000 0x0 0x0
0xffff9d000002af00 0001 00000000 0x0 0x0
0xffff9d000002af80 0001 00000000 0x0 0x0
0xffff9d000002b000 0001 00000000 0x0 0x0
0xffff9d000002b080 0001 00000000 0x0 0x0
0xffff9d000002b100 0001 00000000 0x0 0x0
0xffff9d000002b180 0001 00000000 0x0 0x0
0xffff9d000002b200 0001 00000000 0x0 0x0
0xffff9d000002b280 0001 00000000 0x0 0x0
0xffff9d000002b300 0001 00000000 0x0 0x0
0xffff9d000002b380 0001 00000000 0x0 0x0
0xffff9d000002b400 0001 00000000 0x0 0x0
0xffff9d000002b480 0001 00000000 0x0 0x0
0xffff9d000002b500 0001 00000000 0x0 0x0
0xffff9d000002b580 0001 00000000 0x0 0x0
0xffff9d000002b600 0001 00000000 0x0 0x0
0xffff9d000002b680 0001 00000000 0x0 0x0
0xffff9d000002b700 0001 00000000 0x0 0x0
0xffff9d000002b780 0001 00000000 0x0 0x0
0xffff9d000002b800 0001 00000000 0x0 0x0
0xffff9d000002b880 0001 00000000 0x0 0x0
0xffff9d000002b900 0001 00000000 0x0 0x0
0xffff9d000002b980 0001 00000000 0x0 0x0
0xffff9d000002ba00 0001 00000000 0x0 0x0
0xffff9d000002ba80 0001 00000000

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Jun 24, 2021, 7:45:14 AM6/24/21
to syzkaller-...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages