protection fault in fork1 (3)

4 views
Skip to first unread message

syzbot

unread,
Jan 16, 2023, 4:03:42 AM1/16/23
to syzkaller-...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: a89c93da70c8 lint: rename local functions to be more reada..
git tree: netbsd
console output: https://syzkaller.appspot.com/x/log.txt?x=14104a36480000
kernel config: https://syzkaller.appspot.com/x/.config?x=739e57438eb9ed9e
dashboard link: https://syzkaller.appspot.com/bug?extid=b9b20fc6eb734045fa5e
compiler: Debian clang version 13.0.1-++20220126092033+75e33f71c2da-1~exp1~20220126212112.63

Unfortunately, I don't have any reproducer for this issue yet.

Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/2f798b5d4c06/disk-a89c93da.raw.xz
netbsd.gdb: https://storage.googleapis.com/syzbot-assets/1dfef253ce52/netbsd-a89c93da.gdb.xz

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+b9b20f...@syzkaller.appspotmail.com

[ 667.1836678] fatal protection fault in supervisor mode
[ 667.2036572] trap type 4 code 0 rip 0xffffffff8516be5b cs 0x8 rflags 0x10246 cr2 0x7d367f7a1cd8 ilevel 0 rsp 0xffff9d80d28e5b50
[ 667.2386722] curlwp 0xffff9d801489b500 pid 4701.4701 lowest kstack 0xffff9d80d28de2c0
kernel: protection fault trap, code=0
Stopped in pid 4701.4701 (syz-executor.1) at netbsd:fork1+0x256b: movq 0(%r14),%rbx
?
fork1() at netbsd:fork1+0x256b sys/kern/kern_fork.c:513
sys_fork() at netbsd:sys_fork+0xa5 sys/kern/kern_fork.c:120
sys___syscall() at netbsd:sys___syscall+0x2c6 sys/kern/sys_syscall.c:90
syscall() at netbsd:syscall+0x60c sy_invoke sys/sys/syscallvar.h:94 [inline]
syscall() at netbsd:syscall+0x60c sys/arch/x86/x86/syscall.c:138
--- syscall (number 2 via SYS_syscall) ---
netbsd:syscall+0x60c:
Panic string: (null)
PID LID S CPU FLAGS STRUCT LWP * NAME WAIT
15548>15548 7 1 0 ffff9d8014918540 syz-executor.1
15688 15688 2 1 0 ffff9d8014918100 syz-executor.1
3884 3884 2 1 0 ffff9d8014610b80 syz-executor.1
3999 3999 2 1 0 ffff9d8014610300 syz-executor.1
4914 4914 2 1 0 ffff9d80146168c0 syz-executor.1
16589 16589 2 1 0 ffff9d8014616480 syz-executor.1
10950 10950 2 1 0 ffff9d8014616040 syz-executor.1
4701 >4701 7 0 0 ffff9d801489b500 syz-executor.1
4654 4654 2 0 0 ffff9d801421c9c0 syz-executor.4
3502 4682 2 1 100 ffff9d801489b0c0 syz-executor.1
3502 3730 2 0 0 ffff9d8014484700 syz-executor.1
3502 3502 3 0 10000000 ffff9d8014614bc0 syz-executor.1 tstile
4013 4086 2 1 0 ffff9d8014918980 syz-executor.5
4013 3908 3 0 0 ffff9d8014610740 syz-executor.5 fstchg
4013 2770 3 1 0 ffff9d801489b940 syz-executor.5 tstile
4013 4013 2 1 10000000 ffff9d801423f640 syz-executor.5
4288 4288 3 0 40180 ffff9d8014614340 syz-executor.1 parked
15802 15802 3 1 40 ffff9d8014484b40 syz-executor.5 tstile
16343 16343 2 0 40 ffff9d80147bd900 syz-executor.3
16341 16362 4 0 1000180 ffff9d8014245680 syz-executor.1 parked
16341 3466 4 0 1000180 ffff9d801371a200 syz-executor.1 parked
16341 16341 4 1 11000000 ffff9d80147bd080 syz-executor.1
14789 14789 3 1 40 ffff9d80147bd4c0 syz-executor.1 tstile
5838 5838 3 1 1c0 ffff9d8013b49080 syz-executor.0 pipe_rd
3411 3411 3 0 180 ffff9d80135575c0 syz-executor.4 parked
3507 3507 3 1 180 ffff9d801423fa80 syz-executor.4 parked
3768 3768 3 0 180 ffff9d80138b6740 syz-executor.4 parked
2625 2625 3 0 180 ffff9d80136401c0 syz-executor.4 parked
810 810 3 1 180 ffff9d80138b6300 syz-executor.4 parked
2978 2978 3 0 180 ffff9d80137d3ac0 syz-executor.4 parked
3361 3361 3 0 180 ffff9d80133fb980 syz-executor.4 parked
2343 2343 3 1 180 ffff9d80133fb100 syz-executor.4 parked
13264 13264 3 1 180 ffff9d8013d4f540 syz-executor.4 parked
15078 15078 3 1 180 ffff9d8013d4f100 syz-executor.4 parked
2017 2017 3 1 40 ffff9d801353f580 syz-executor.4 tstile
806 806 3 0 180 ffff9d80144842c0 syz-executor.3 parked
1969 1969 3 0 0 ffff9d8014479b00 syz-executor.3 vfork
920 920 3 0 0 ffff9d80144796c0 syz-executor.3 vfork
12975 12975 3 0 0 ffff9d8014479280 syz-executor.3 vfork
6704 6704 3 0 0 ffff9d8013d4f980 syz-executor.3 vfork
919 919 3 0 0 ffff9d801384d8c0 syz-executor.3 vfork
924 924 3 0 0 ffff9d8014245ac0 syz-executor.3 vfork
13399 13399 3 0 0 ffff9d8014245240 syz-executor.3 vfork
918 918 3 0 0 ffff9d801423f200 syz-executor.3 vfork
916 916 3 0 0 ffff9d8014232a40 syz-executor.3 vfork
925 925 3 0 0 ffff9d8014232600 syz-executor.3 vfork
908 908 3 0 0 ffff9d80142321c0 syz-executor.3 vfork
905 905 3 0 0 ffff9d8014228a00 syz-executor.3 vfork
913 913 3 0 0 ffff9d80142285c0 syz-executor.3 vfork
926 926 3 0 0 ffff9d8014228180 syz-executor.3 vfork
910 910 3 0 0 ffff9d801421c580 syz-executor.3 vfork
904 904 3 0 0 ffff9d801421c140 syz-executor.3 vfork
2615 2615 3 0 0 ffff9d8014212980 syz-executor.3 vfork
922 922 3 0 0 ffff9d8014212540 syz-executor.3 vfork
12881 12881 3 0 0 ffff9d8014212100 syz-executor.3 vfork
907 907 3 0 0 ffff9d8014035940 syz-executor.3 vfork
900 900 3 0 0 ffff9d8014035500 syz-executor.3 vfork
921 921 3 0 0 ffff9d80140350c0 syz-executor.3 vfork
13097 13097 3 0 0 ffff9d801402b900 syz-executor.3 vfork
13055 13055 3 0 0 ffff9d801402b4c0 syz-executor.3 vfork
1644 1644 3 0 0 ffff9d801402b080 syz-executor.3 vfork
11600 11600 3 0 0 ffff9d80140218c0 syz-executor.3 vfork
765 765 3 0 0 ffff9d8014021480 syz-executor.3 vfork
12927 12927 3 0 0 ffff9d8014021040 syz-executor.3 vfork
903 903 3 1 0 ffff9d8014017bc0 syz-executor.3 vfork
901 901 3 1 0 ffff9d8014017780 syz-executor.3 vfork
902 902 3 1 0 ffff9d8014017340 syz-executor.3 vfork
762 762 3 1 0 ffff9d801400bb80 syz-executor.3 vfork
12591 12591 3 1 0 ffff9d801400b740 syz-executor.3 vfork
12101 12101 3 1 0 ffff9d80137d3240 syz-executor.3 vfork
13145 13145 3 1 0 ffff9d801400b300 syz-executor.3 vfork
896 896 3 1 0 ffff9d8013ffcb40 syz-executor.3 vfork
12619 12619 3 1 0 ffff9d80137f3280 syz-executor.3 vfork
759 759 3 1 0 ffff9d8013ffc700 syz-executor.3 vfork
13653 13653 3 1 0 ffff9d8013ffc2c0 syz-executor.3 vfork
12092 12092 3 1 0 ffff9d8013d83b00 syz-executor.3 vfork
13625 13625 3 1 0 ffff9d8013d836c0 syz-executor.3 vfork
898 898 3 1 0 ffff9d8013d83280 syz-executor.3 vfork
897 897 3 1 0 ffff9d8013d79ac0 syz-executor.3 vfork
12858 12858 3 1 0 ffff9d8013d79680 syz-executor.3 vfork
12620 12620 3 0 0 ffff9d8013d79240 syz-executor.3 vfork
763 763 3 0 0 ffff9d8013d6ea80 syz-executor.3 vfork
13133 13133 3 0 0 ffff9d8013d6e640 syz-executor.3 vfork
13674 13674 3 0 0 ffff9d8013d6e200 syz-executor.3 vfork
766 766 3 0 0 ffff9d8013d5a180 syz-executor.3 vfork
4670 4670 3 0 0 ffff9d8013557a00 syz-executor.3 vfork
12361 12361 3 0 0 ffff9d8013d63a40 syz-executor.3 vfork
1131 1131 3 0 0 ffff9d8013d63600 syz-executor.3 vfork
760 760 3 0 0 ffff9d8013d631c0 syz-executor.3 vfork
761 761 3 0 0 ffff9d8013d5aa00 syz-executor.3 vfork
764 764 3 0 0 ffff9d8013d5a5c0 syz-executor.3 vfork
1129 1129 3 0 0 ffff9d8013d529c0 syz-executor.3 vfork
757 757 3 0 0 ffff9d8013d52580 syz-executor.3 vfork
755 755 3 0 0 ffff9d8013d52140 syz-executor.3 vfork
749 749 3 0 0 ffff9d8013cc1940 syz-executor.3 vfork
751 751 3 0 0 ffff9d8013cc1500 syz-executor.3 vfork
752 752 3 0 0 ffff9d8013cc10c0 syz-executor.3 vfork
13009 13009 3 0 0 ffff9d8013b49900 syz-executor.3 vfork
1631 1631 3 0 0 ffff9d8013b494c0 syz-executor.3 vfork
869 869 3 0 0 ffff9d80137f3b00 syz-executor.3 vfork
1607 1628 3 0 1100000 ffff9d801384d040 syz-executor.3 vfork
1607 1607 2 0 11000040 ffff9d80137f36c0 syz-executor.3
12623 12623 3 0 180 ffff9d8013801b40 syz-executor.3 parked
661 655 3 0 11100000 ffff9d80138012c0 syz-executor.3 vfork
661 661 2 0 11000040 ffff9d801384c340 syz-executor.3
12969 12969 3 0 180 ffff9d801384cbc0 syz-executor.1 parked
411 411 3 0 180 ffff9d8013801700 syz-executor.1 parked
12843 12843 3 0 180 ffff9d801384c780 syz-executor.1 parked
11976 11976 3 0 180 ffff9d80138b6b80 syz-executor.5 parked
1336 1336 3 0 180 ffff9d801371aa80 syz-executor.5 parked
10932 10932 3 0 180 ffff9d801371a640 syz-executor.5 parked
1260 3290 2 1 140 ffff9d8014614780 syz-fuzzer
1260 6064 3 1 1c0 ffff9d8013640a40 syz-fuzzer wait
1260 1211 3 0 180 ffff9d8013640600 syz-fuzzer parked
1260 1247 3 0 180 ffff9d8013557180 syz-fuzzer wait
1260 1238 3 0 1c0 ffff9d801353f9c0 syz-fuzzer parked
1260 1244 3 1 1c0 ffff9d801353f140 syz-fuzzer parked
1260 1202 3 1 180 ffff9d80133fb540 syz-fuzzer parked
1260 1184 3 0 1c0 ffff9d8012c38940 syz-fuzzer wait
1260 1185 3 1 180 ffff9d8012c38500 syz-fuzzer parked
1260 1245 3 1 1c0 ffff9d8012c380c0 syz-fuzzer wait
1260 449 3 1 1c0 ffff9d8012b78900 syz-fuzzer parked
1260 1075 3 1 180 ffff9d8012b784c0 syz-fuzzer parked
1260 931 3 1 180 ffff9d80125bf780 syz-fuzzer parked
1260 1073 3 0 180 ffff9d80122f4b00 syz-fuzzer parked
1260 1260 3 0 180 ffff9d80122f46c0 syz-fuzzer wait
1223 1223 3 1 180 ffff9d80124f9300 sshd select
1236 1236 3 0 180 ffff9d8012b78080 getty nanoslp
1235 1235 3 0 180 ffff9d80121f3ac0 getty nanoslp
1118 1118 3 0 180 ffff9d80122f4280 getty nanoslp
1226 1226 3 0 1c0 ffff9d80121f0200 getty ttyraw
802 802 3 1 180 ffff9d8012b488c0 sshd select
949 949 3 1 180 ffff9d8012b48480 powerd kqueue
694 694 3 1 180 ffff9d80125bfbc0 syslogd kqueue
745 745 3 0 180 ffff9d8012b48040 dhcpcd poll
557 557 3 1 180 ffff9d80124f9b80 dhcpcd poll
576 576 3 1 180 ffff9d8012385700 dhcpcd poll
602 602 3 1 180 ffff9d80123852c0 dhcpcd poll
487 487 3 0 180 ffff9d80125bf340 dhcpcd poll
338 338 3 0 180 ffff9d8012385b40 dhcpcd poll
292 292 3 1 180 ffff9d80124f9740 dhcpcd poll
1 1 3 0 180 ffff9d8011ecf100 init wait
0 4180 3 0 200 ffff9d80137d3680 ktrace ktrwait
0 756 5 0 200 ffff9d801384d480 (zombie)
0 987 3 0 200 ffff9d80121f0640 physiod physiod
0 196 3 0 200 ffff9d80121f3680 pooldrain pooldrain
0 195 3 1 200 ffff9d80121f3240 ioflush syncer
0 194 3 0 200 ffff9d80121f0a80 pgdaemon pgdaemon
0 167 3 1 200 ffff9d8012160a40 usb7 usbevt
0 172 3 1 200 ffff9d8012160600 usb6 usbevt
0 170 3 1 200 ffff9d80121601c0 usb5 usbevt
0 168 3 0 200 ffff9d801212ca00 usb4 usbevt
0 166 3 1 200 ffff9d801212c5c0 usb3 usbevt
0 165 3 1 200 ffff9d801212c180 usb2 usbevt
0 31 3 0 200 ffff9d80120769c0 usb1 usbevt
0 63 3 1 200 ffff9d8012076580 usb0 usbevt
0 126 3 0 200 ffff9d8012076140 usbtask-dr usbtsk
0 125 3 1 200 ffff9d8011ecf980 usbtask-hc usbtsk
0 124 3 0 200 ffff9d80103f5b00 swwreboot swwreboot
0 123 3 0 200 ffff9d8011ecf540 npfgc0 npfgcw
0 122 3 1 200 ffff9d8011ec1940 rt_free rt_free
0 121 3 1 200 ffff9d8011ec1500 unpgc unpgc
0 120 3 0 200 ffff9d8011ec10c0 key_timehandler key_timehandler
0 119 3 1 200 ffff9d8011ebc900 icmp6_wqinput/1 icmp6_wqinput
0 118 3 0 200 ffff9d8011ebc4c0 icmp6_wqinput/0 icmp6_wqinput
0 117 3 0 200 ffff9d8011ebc080 nd6_timer nd6_timer
0 116 3 1 200 ffff9d8011ce0bc0 carp6_wqinput/1 carp6_wqinput
0 115 3 0 200 ffff9d8011ce0780 carp6_wqinput/0 carp6_wqinput
0 114 3 1 200 ffff9d8011ce0340 carp_wqinput/1 carp_wqinput
0 113 3 0 200 ffff9d8011e9b8c0 carp_wqinput/0 carp_wqinput
0 112 3 1 200 ffff9d8011e9b480 icmp_wqinput/1 icmp_wqinput
0 111 3 0 200 ffff9d8011cddb80 icmp_wqinput/0 icmp_wqinput
0 110 3 0 200 ffff9d8011cdd740 rt_timer rt_timer
0 109 3 0 200 ffff9d8011e9b040 vmem_rehash vmem_rehash
0 100 3 1 200 ffff9d8011cdd300 entbutler entropy
0 99 3 1 200 ffff9d80117e0b40 viomb balloon
0 98 3 1 200 ffff9d80117e0700 vioif0_txrx/1 vioif0_txrx
0 97 3 0 200 ffff9d80117e02c0 vioif0_txrx/0 vioif0_txrx
0 30 3 0 200 ffff9d80103f56c0 scsibus0 sccomp
0 29 3 0 200 ffff9d80103f5280 pms0 pmsreset
0 28 3 1 200 ffff9d80103daac0 xcall/1 xcall
0 27 1 1 200 ffff9d80103da680 softser/1
0 26 1 1 200 ffff9d80103da240 softclk/1
0 25 1 1 200 ffff9d80103d8a80 softbio/1
0 24 1 1 200 ffff9d80103d8640 softnet/1
0 23 1 1 201 ffff9d80103d8200 idle/1
0 22 3 0 200 ffff9d800f1f4a40 lnxsyswq lnxsyswq
0 21 3 0 200 ffff9d800f1f4600 lnxubdwq lnxubdwq
0 20 3 0 200 ffff9d800f1f41c0 lnxpwrwq lnxpwrwq
0 19 3 0 200 ffff9d800f1f2a00 lnxlngwq lnxlngwq
0 18 3 0 200 ffff9d800f1f25c0 lnxhipwq lnxhipwq
0 17 3 0 200 ffff9d800f1f2180 lnxrcugc lnxrcugc
0 16 3 0 200 ffff9d800f1ec9c0 sysmon smtaskq
0 15 3 0 200 ffff9d800f1ec580 pmfsuspend pmfsuspend
0 14 3 0 200 ffff9d800f1ec140 pmfevent pmfevent
0 13 3 0 200 ffff9d800f1e9980 sopendfree sopendfr
0 12 3 0 200 ffff9d800f1e9540 ifwdog ifwdog
0 11 3 1 200 ffff9d800f1e9100 iflnkst iflnkst
0 10 3 0 200 ffff9d800f1df940 nfssilly nfssilly
0 9 3 0 200 ffff9d800f1df500 vdrain vdrain
0 8 3 1 200 ffff9d800f1df0c0 modunload mod_unld
0 7 3 0 200 ffff9d800ebdb900 xcall/0 xcall
0 6 1 0 200 ffff9d800ebdb4c0 softser/0
0 5 1 0 200 ffff9d800ebdb080 softclk/0
0 4 1 0 200 ffff9d800ebd98c0 softbio/0
0 3 1 0 200 ffff9d800ebd9480 softnet/0
0 2 1 0 201 ffff9d800ebd9040 idle/0
0 0 3 1 200 ffffffff868695c0 swapper uvm
[Locks tracked through LWPs]

****** LWP 15548.15548 (syz-executor.1) @ 0xffff9d8014918540, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:uvm_map_setup+0x2a0 sys/uvm/uvm_map.c:4785)
lock address : netbsd:kernel_map_store+0x8
type : sleep/adaptive
initialized : netbsd:uvm_map_setup+0x2a0
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8014918540 last held: 0xffff9d8014918540
last locked* : netbsd:uvm_map_prepare+0xd7f
unlocked : netbsd:uvm_map_enter+0x285f
owner/count : 0xffff9d8014918540 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 3884.3884 (syz-executor.1) @ 0xffff9d8014610b80, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:pool_init+0x2061 sys/kern/subr_pool.c:981)
lock address : ffff9d800ebe54b0
type : sleep/adaptive
initialized : netbsd:pool_init+0x2061
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8014610b80 last held: 0xffff9d8014610b80
last locked* : netbsd:pool_get+0x7fc
unlocked : netbsd:pool_get+0x3a54
owner field : 0xffff9d8014610b80 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 3999.3999 (syz-executor.1) @ 0xffff9d8014610300, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:procinit+0x85 sys/kern/kern_proc.c:386)
lock address : netbsd:proc_lock
type : sleep/adaptive
initialized : netbsd:procinit+0x85
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 5
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8014610300 last held: 0xffff9d801489b500
last locked* : netbsd:fork1+0x2525
unlocked : netbsd:lwp_create+0x2ebf
owner field : 0xffff9d801489b500 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 4 waiting writers: 0xffff9d801353f580 0xffff9d80147bd4c0 0xffff9d8014484b40 0xffff9d801489b940

****** LWP 16589.16589 (syz-executor.1) @ 0xffff9d8014616480, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:pmap_ctor+0xc0 sys/arch/x86/x86/pmap.c:2860)
lock address : ffff9d8014884380
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0xc0
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8014616480 last held: 0xffff9d8014616480
last locked* : netbsd:pmap_enter_ma+0x11ce
unlocked : netbsd:pmap_extract+0x72d
owner field : 0xffff9d8014616480 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:pmap_ctor+0xd6 sys/arch/x86/x86/pmap.c:2861)
lock address : ffff9d8014884388
type : sleep/adaptive
initialized : netbsd:pmap_ctor+0xd6
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8014616480 last held: 0xffff9d8014616480
last locked* : netbsd:pmap_enter_ma+0x1580
unlocked : netbsd:pmap_enter_ma+0x19f2
owner/count : 0xffff9d8014616480 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 10950.10950 (syz-executor.1) @ 0xffff9d8014616040, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:uvm_obj_init+0x88 sys/uvm/uvm_object.c:70)
lock address : ffff9d80121dd800
type : sleep/adaptive
initialized : netbsd:uvm_obj_init+0x88
shared holds : 1 exclusive: 0
shares wanted: 1 exclusive: 0
relevant cpu : 1 last held: 65535
relevant lwp : 0xffff9d8014616040 last held: 000000000000000000
last locked : netbsd:uvm_fault_internal+0x4ccf
unlocked* : netbsd:uvm_fault_lower_enter+0x1b49
owner/count : 0x0000000000000020 flags : 000000000000000000
Turnstile: no active turnstile for this lock.

****** LWP 4701.4701 (syz-executor.1) @ 0xffff9d801489b500, l_stat=7

*** Locks held:

* Lock 0 (initialized at netbsd:procinit+0x85 sys/kern/kern_proc.c:386)
lock address : netbsd:proc_lock
type : sleep/adaptive
initialized : netbsd:procinit+0x85
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 5
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801489b500 last held: 0xffff9d801489b500
last locked* : netbsd:fork1+0x2525
unlocked : netbsd:lwp_create+0x2ebf
owner field : 0xffff9d801489b500 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 4 waiting writers: 0xffff9d801353f580 0xffff9d80147bd4c0 0xffff9d8014484b40 0xffff9d801489b940

*** Locks wanted: none

****** LWP 4654.4654 (syz-executor.4) @ 0xffff9d801421c9c0, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:fstrans_init+0x6b sys/kern/vfs_trans.c:137)
lock address : netbsd:fstrans_lock
type : sleep/adaptive
initialized : netbsd:fstrans_init+0x6b
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 2
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d801421c9c0 last held: 000000000000000000
last locked : netbsd:_fstrans_start+0xa85
unlocked* : netbsd:cv_enter+0x80b
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 3502.3730 (syz-executor.1) @ 0xffff9d8014484700, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 uvm_map_setup sys/uvm/uvm_map.c:4785 [inline])
* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 uvmspace_init sys/uvm/uvm_map.c:4128 [inline])
* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 uvmspace_alloc sys/uvm/uvm_map.c:4107 [inline])
* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 sys/uvm/uvm_map.c:4584)
lock address : ffff9d801363d300
type : sleep/adaptive
initialized : netbsd:uvmspace_fork+0x3e4
shared holds : 0 exclusive: 0
shares wanted: 1 exclusive: 1
relevant cpu : 0 last held: 65535
relevant lwp : 0xffff9d8014484700 last held: 000000000000000000
last locked : netbsd:uvm_fault_internal+0xcebb
unlocked* : netbsd:uvm_fault_upper_enter+0x161a
owner/count : 000000000000000000 flags : 0x0000000000000003
Turnstile:
=> 1 waiting readers: 0xffff9d8014614bc0
=> 0 waiting writers:

****** LWP 3502.3502 (syz-executor.1) @ 0xffff9d8014614bc0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 uvm_map_setup sys/uvm/uvm_map.c:4785 [inline])
* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 uvmspace_init sys/uvm/uvm_map.c:4128 [inline])
* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 uvmspace_alloc sys/uvm/uvm_map.c:4107 [inline])
* Lock 0 (initialized at netbsd:uvmspace_fork+0x3e4 sys/uvm/uvm_map.c:4584)
lock address : ffff9d801363d300
type : sleep/adaptive
initialized : netbsd:uvmspace_fork+0x3e4
shared holds : 0 exclusive: 0
shares wanted: 1 exclusive: 1
relevant cpu : 0 last held: 65535
relevant lwp : 0xffff9d8014614bc0 last held: 000000000000000000
last locked : netbsd:uvm_fault_internal+0xcebb
unlocked* : netbsd:uvm_fault_upper_enter+0x161a
owner/count : 000000000000000000 flags : 0x0000000000000003
Turnstile:
=> 1 waiting readers: 0xffff9d8014614bc0
=> 0 waiting writers:

****** LWP 4013.2770 (syz-executor.5) @ 0xffff9d801489b940, l_stat=3

*** Locks held:

* Lock 0 (initialized at netbsd:fstrans_init+0x43 sys/kern/vfs_trans.c:136)
lock address : netbsd:vfs_suspend_lock
type : sleep/adaptive
initialized : netbsd:fstrans_init+0x43
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d801489b940 last held: 0xffff9d801489b940
last locked* : netbsd:vfs_suspend+0x433
unlocked : netbsd:mount_domount+0x2038
owner field : 0xffff9d801489b940 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 1 (initialized at netbsd:vfs_mountalloc+0x219 sys/kern/vfs_mount.c:160)
lock address : ffff9d80147ef800
type : sleep/adaptive
initialized : netbsd:vfs_mountalloc+0x219
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d801489b940 last held: 0xffff9d801489b940
last locked* : netbsd:mount_domount+0x994
unlocked : 0
owner field : 0xffff9d801489b940 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

* Lock 2 (initialized at netbsd:vcache_alloc+0xc6 sys/kern/vfs_vnode.c:1391)
lock address : ffff9d801489e200
type : sleep/adaptive
initialized : netbsd:vcache_alloc+0xc6
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d801489b940 last held: 0xffff9d801489b940
last locked* : netbsd:genfs_lock+0x1d6
unlocked : netbsd:genfs_unlock+0x55
owner/count : 0xffff9d801489b940 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted:

* Lock 0 (initialized at netbsd:procinit+0x85 sys/kern/kern_proc.c:386)
lock address : netbsd:proc_lock
type : sleep/adaptive
initialized : netbsd:procinit+0x85
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 5
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d801489b940 last held: 0xffff9d801489b500
last locked* : netbsd:fork1+0x2525
unlocked : netbsd:lwp_create+0x2ebf
owner field : 0xffff9d801489b500 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 4 waiting writers: 0xffff9d801353f580 0xffff9d80147bd4c0 0xffff9d8014484b40 0xffff9d801489b940

****** LWP 15802.15802 (syz-executor.5) @ 0xffff9d8014484b40, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:procinit+0x85 sys/kern/kern_proc.c:386)
lock address : netbsd:proc_lock
type : sleep/adaptive
initialized : netbsd:procinit+0x85
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 5
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8014484b40 last held: 0xffff9d801489b500
last locked* : netbsd:fork1+0x2525
unlocked : netbsd:lwp_create+0x2ebf
owner field : 0xffff9d801489b500 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 4 waiting writers: 0xffff9d801353f580 0xffff9d80147bd4c0 0xffff9d8014484b40 0xffff9d801489b940

****** LWP 16343.16343 (syz-executor.3) @ 0xffff9d80147bd900, l_stat=2

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:fstrans_init+0x6b sys/kern/vfs_trans.c:137)
lock address : netbsd:fstrans_lock
type : sleep/adaptive
initialized : netbsd:fstrans_init+0x6b
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 2
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d80147bd900 last held: 000000000000000000
last locked : netbsd:_fstrans_start+0xa85
unlocked* : netbsd:cv_enter+0x80b
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 14789.14789 (syz-executor.1) @ 0xffff9d80147bd4c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:procinit+0x85 sys/kern/kern_proc.c:386)
lock address : netbsd:proc_lock
type : sleep/adaptive
initialized : netbsd:procinit+0x85
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 5
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d80147bd4c0 last held: 0xffff9d801489b500
last locked* : netbsd:fork1+0x2525
unlocked : netbsd:lwp_create+0x2ebf
owner field : 0xffff9d801489b500 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 4 waiting writers: 0xffff9d801353f580 0xffff9d80147bd4c0 0xffff9d8014484b40 0xffff9d801489b940

****** LWP 2017.2017 (syz-executor.4) @ 0xffff9d801353f580, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:procinit+0x85 sys/kern/kern_proc.c:386)
lock address : netbsd:proc_lock
type : sleep/adaptive
initialized : netbsd:procinit+0x85
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 5
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d801353f580 last held: 0xffff9d801489b500
last locked* : netbsd:fork1+0x2525
unlocked : netbsd:lwp_create+0x2ebf
owner field : 0xffff9d801489b500 wait/spin: 1/0
Turnstile:
=> 0 waiting readers:
=> 4 waiting writers: 0xffff9d801353f580 0xffff9d80147bd4c0 0xffff9d8014484b40 0xffff9d801489b940

****** LWP 1260.3290 (syz-fuzzer) @ 0xffff9d8014614780, l_stat=2

*** Locks held:

* Lock 0 (initialized at netbsd:amap_ctor+0xdf sys/uvm/uvm_amap.c:265)
lock address : ffff9d801336bcc0
type : sleep/adaptive
initialized : netbsd:amap_ctor+0xdf
shared holds : 0 exclusive: 1
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 1
relevant lwp : 0xffff9d8014614780 last held: 0xffff9d8014614780
last locked* : netbsd:uvm_fault_internal+0x1d28
unlocked : netbsd:uvm_fault_upper_enter+0x12e9
owner/count : 0xffff9d8014614780 flags : 0x0000000000000004
Turnstile: no active turnstile for this lock.

*** Locks wanted: none

****** LWP 557.557 (dhcpcd) @ 0xffff9d80124f9b80, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d80124f9b80 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 576.576 (dhcpcd) @ 0xffff9d8012385700, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d8012385700 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 338.338 (dhcpcd) @ 0xffff9d8012385b40, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 0 last held: 0
relevant lwp : 0xffff9d8012385b40 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 292.292 (dhcpcd) @ 0xffff9d80124f9740, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d80124f9740 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.26 (softclk/1) @ 0xffff9d80103da240, l_stat=1

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d80103da240 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.11 (iflnkst) @ 0xffff9d800f1e9100, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffff9d800f1e9100 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

****** LWP 0.0 (swapper) @ 0xffffffff868695c0, l_stat=3

*** Locks held: none

*** Locks wanted:

* Lock 0 (initialized at netbsd:module_hook_init+0x43 sys/kern/kern_module_hook.c:132)
lock address : netbsd:module_hook
type : sleep/adaptive
initialized : netbsd:module_hook_init+0x43
shared holds : 0 exclusive: 0
shares wanted: 0 exclusive: 0
relevant cpu : 1 last held: 0
relevant lwp : 0xffffffff868695c0 last held: 000000000000000000
last locked : 0
unlocked* : 0
owner field : 000000000000000000 wait/spin: 0/0
Turnstile: no active turnstile for this lock.

[Locks tracked through CPUs]

PAGE FLAG PQ UOBJECT UANON
0xffff9d8000017180 0001 00000000 0x0 0x0
0xffff9d8000017200 0041 00000000 0x0 0x0
0xffff9d8000017280 0041 00000000 0x0 0x0
0xffff9d8000017300 0041 00000000 0x0 0x0
0xffff9d8000017380 0041 00000000 0x0 0x0
0xffff9d8000017400 0041 00000000 0x0 0x0
0xffff9d8000017480 0041 00000000 0x0 0x0
0xffff9d8000017500 0041 00000000 0x0 0x0
0xffff9d8000017580 0041 00000000 0x0 0x0
0xffff9d8000017600 0041 00000000 0x0 0x0
0xffff9d8000017680 0041 00000000 0x0 0x0
0xffff9d8000017700 0041 00000000 0x0 0x0
0xffff9d8000017780 0041 00000000 0x0 0x0
0xffff9d8000017800 0041 00000000 0x0 0x0
0xffff9d8000017880 0041 00000000 0x0 0x0
0xffff9d8000017900 0041 00000000 0x0 0x0
0xffff9d8000017980 0041 00000000 0x0 0x0
0xffff9d8000017a00 0041 00000000 0x0 0x0
0xffff9d8000017a80 0041 00000000 0x0 0x0
0xffff9d8000017b00 0041 00000000 0x0 0x0
0xffff9d8000017b80 0041 00000000 0x0 0x0
0xffff9d8000017c00 0041 00000000 0x0 0x0
0xffff9d8000017c80 0041 00000000 0x0 0x0
0xffff9d8000017d00 0041 00000000 0x0 0x0
0xffff9d8000017d80 0041 00000000 0x0 0x0
0xffff9d8000017e00 0041 00000000 0x0 0x0
0xffff9d8000017e80 0041 00000000 0x0 0x0
0xffff9d8000017f00 0041 00000000 0x0 0x0
0xffff9d8000017f80 0041 00000000 0x0 0x0
0xffff9d8000018000 0041 00000000 0x0 0x0
0xffff9d8000018080 0041 00000000 0x0 0x0
0xffff9d8000018100 0041 00000000 0x0 0x0
0xffff9d8000018180 0041 00000000 0x0 0x0
0xffff9d8000018200 0041 00000000 0x0 0x0
0xffff9d8000018280 0041 00000000 0x0 0x0
0xffff9d8000018300 0041 00000000 0x0 0x0
0xffff9d8000018380 0041 00000000 0x0 0x0
0xffff9d8000018400 0041 00000000 0x0 0x0
0xffff9d8000018480 0041 00000000 0x0 0x0
0xffff9d8000018500 0041 00000000 0x0 0x0
0xffff9d8000018580 0041 00000000 0x0 0x0
0xffff9d8000018600 0041 00000000 0x0 0x0
0xffff9d8000018680 0041 00000000 0x0 0x0
0xffff9d8000018700 0041 00000000 0x0 0x0
0xffff9d8000018780 0041 00000000 0x0 0x0
0xffff9d8000018800 0041 00000000 0x0 0x0
0xffff9d8000018880 0041 00000000 0x0 0x0
0xffff9d8000018900 0041 00000000 0x0 0x0
0xffff9d8000018980 0041 00000000 0x0 0x0
0xffff9d8000018a00 0041 00000000 0x0 0x0
0xffff9d8000018a80 0041 00000000 0x0 0x0
0xffff9d8000018b00 0041 00000000 0x0 0x0
0xffff9d8000018b80 0041 00000000 0x0 0x0
0xffff9d8000018c00 0041 00000000 0x0 0x0
0xffff9d8000018c80 0041 00000000 0x0 0x0
0xffff9d8000018d00 0041 00000000 0x0 0x0
0xffff9d8000018d80 0041 00000000 0x0 0x0
0xffff9d8000018e00 0041 00000000 0x0 0x0
0xffff9d8000018e80 0041 00000000 0x0 0x0
0xffff9d8000018f00 0041 00000000 0x0 0x0
0xffff9d8000018f80 0041 00000000 0x0 0x0
0xffff9d8000019000 0041 00000000 0x0 0x0
0xffff9d8000019080 0041 00000000 0x0 0x0
0xffff9d8000019100 0041 00000000 0x0 0x0
0xffff9d8000019180 0041 00000000 0x0 0x0
0xffff9d8000019200 0041 00000000 0x0 0x0
0xffff9d8000019280 0041 00000000 0x0 0x0
0xffff9d8000019300 0041 00000000 0x0 0x0
0xffff9d8000019380 0041 00000000 0x0 0x0
0xffff9d8000019400 0041 00000000 0x0 0x0
0xffff9d8000019480 0041 00000000 0x0 0x0
0xffff9d8000019500 0041 00000000 0x0 0x0
0xffff9d8000019580 0041 00000000 0x0 0x0
0xffff9d8000019600 0041 00000000 0x0 0x0
0xffff9d8000019680 0041 00000000 0x0 0x0
0xffff9d8000019700 0041 00000000 0x0 0x0
0xffff9d8000019780 0041 00000000 0x0 0x0
0xffff9d8000019800 0041 00000000 0x0 0x0
0xffff9d8000019880 0041 00000000 0x0 0x0
0xffff9d8000019900 0041 00000000 0x0 0x0
0xffff9d8000019980 0041 00000000 0x0 0x0
0xffff9d8000019a00 0041 00000000 0x0 0x0
0xffff9d8000019a80 0041 00000000 0x0 0x0
0xffff9d8000019b00 0041 00000000 0x0 0x0
0xffff9d8000019b80 0041 00000000 0x0 0x0
0xffff9d8000019c00 0041 00000000 0x0 0x0
0xffff9d8000019c80 0041 00000000 0x0 0x0
0xffff9d8000019d00 0041 00000000 0x0 0x0
0xffff9d8000019d80 0041 00000000 0x0 0x0
0xffff9d8000019e00 0041 00000000 0x0 0x0
0xffff9d8000019e80 0041 00000000 0x0 0x0
0xffff9d8000019f00 0041 00000000 0x0 0x0
0xffff9d8000019f80 0041 00000000 0x0 0x0
0xffff9d800001a000 0041 00000000 0x0 0x0
0xffff9d800001a080 0041 00000000 0x0 0x0
0xffff9d800001a100 0041 00000000 0x0 0x0
0xffff9d800001a180 0041 00000000 0x0 0x0
0xffff9d800001a200 0041 00000000 0x0 0x0
0xffff9d800001a280 0041 00000000 0x0 0x0
0xffff9d800001a300 0041 00000000 0x0 0x0
0xffff9d800001a380 0041 00000000 0x0 0x0
0xffff9d800001a400 0041 00000000 0x0 0x0
0xffff9d800001a480 0041 00000000 0x0 0x0
0xffff9d800001a500 0041 00000000 0x0 0x0
0xffff9d800001a580 0041 00000000 0x0 0x0
0xffff9d800001a600 0041 00000000 0x0 0x0
0xffff9d800001a680 0041 00000000 0x0 0x0
0xffff9d800001a700 0041 00000000 0x0 0x0
0xffff9d800001a780 0041 00000000 0x0 0x0
0xffff9d800001a800 0041 00000000 0x0 0x0
0xffff9d800001a880 0041 00000000 0x0 0x0
0xffff9d800001a900 0041 00000000 0x0 0x0
0xffff9d800001a980 0041 00000000 0x0 0x0
0xffff9d800001aa00 0041 00000000 0x0 0x0
0xffff9d800001aa80 0041 00000000 0x0 0x0
0xffff9d800001ab00 0041 00000000 0x0 0x0
0xffff9d800001ab80 0041 00000000 0x0 0x0
0xffff9d800001ac00 0041 00000000 0x0 0x0
0xffff9d800001ac80 0041 00000000 0x0 0x0
0xffff9d800001ad00 0041 00000000 0x0 0x0
0xffff9d800001ad80 0041 00000000 0x0 0x0
0xffff9d800001ae00 0041 00000000 0x0 0x0
0xffff9d800001ae80 0041 00000000 0x0 0x0
0xffff9d800001af00 0041 00000000 0x0 0x0
0xffff9d800001af80 0041 00000000 0x0 0x0
0xffff9d800001b000 0041 00000000 0x0 0x0
0xffff9d800001b080 0041 00000000 0x0 0x0
0xffff9d800001b100 0041 00000000 0x0 0x0
0xffff9d800001b180 0041 00000000 0x0 0x0
0xffff9d800001b200 0041 00000000 0x0 0x0
0xffff9d800001b280 0041 00000000 0x0 0x0
0xffff9d800001b300 0041 00000000 0x0 0x0
0xffff9d800001b380 0041 00000000 0x0 0x0
0xffff9d800001b400 0041 00000000 0x0 0x0
0xffff9d800001b480 0041 00000000 0x0 0x0
0xffff9d800001b500 0041 00000000 0x0 0x0
0xffff9d800001b580 0041 00000000 0x0 0x0
0xffff9d800001b600 0041 00000000 0x0 0x0
0xffff9d800001b680 0041 00000000 0x0 0x0
0xffff9d800001b700 0041 00000000 0x0 0x0
0xffff9d800001b780 0041 00000000 0x0 0x0
0xffff9d800001b800 0041 00000000 0x0 0x0
0xffff9d800001b880 0041 00000000 0x0 0x0
0xffff9d800001b900 0041 00000000 0x0 0x0
0xffff9d800001b980 0041 00000000 0x0 0x0
0xffff9d800001ba00 0041 00000000 0x0 0x0
0xffff9d800001ba80 0041 00000000 0x0 0x0
0xffff9d800001bb00 0041 00000000 0x0 0x0
0xffff9d800001bb80 0041 00000000 0x0 0x0
0xffff9d800001bc00 0041 00000000 0x0 0x0
0xffff9d800001bc80 0041 00000000 0x0 0x0
0xffff9d800001bd00 0041 00000000 0x0 0x0
0xffff9d800001bd80 0041 00000000 0x0 0x0
0xffff9d800001be00 0041 00000000 0x0 0x0
0xffff9d800001be80 0041 00000000 0x0 0x0
0xffff9d800001bf00 0041 00000000 0x0 0x0
0xffff9d800001bf80 0041 00000000 0x0 0x0
0xffff9d800001c000 0041 00000000 0x0 0x0
0xffff9d800001c080 0041 00000000 0x0 0x0
0xffff9d800001c100 0041 00000000 0x0 0x0
0xffff9d800001c180 0041 00000000 0x0 0x0
0xffff9d800001c200 0041 00000000 0x0 0x0
0xffff9d800001c280 0041 00000000 0x0 0x0
0xffff9d800001c300 0041 00000000 0x0 0x0
0xffff9d800001c380 0041 00000000 0x0 0x0
0xffff9d800001c400 0041 00000000 0x0 0x0
0xffff9d800001c480 0041 00000000 0x0 0x0
0xffff9d800001c500 0041 00000000 0x0 0x0
0xffff9d800001c580 0041 00000000 0x0 0x0
0xffff9d800001c600 0041 00000000 0x0 0x0
0xffff9d800001c680 0041 00000000 0x0 0x0
0xffff9d800001c700 0041 00000000 0x0 0x0
0xffff9d800001c780 0001 00000000 0x0 0x0
0xffff9d800001c800 0001 00000000 0x0 0x0
0xffff9d800001c880 0001 00000000 0x0 0x0
0xffff9d800001c900 0001 00000000 0x0 0x0
0xffff9d800001c980 0001 00000000 0x0 0x0
0xffff9d800001ca00 0001 00000000 0x0 0x0
0xffff9d800001ca80 0001 00000000 0x0 0x0
0xffff9d800001cb00 0001 00000000 0x0 0x0
0xffff9d800001cb80 0001 00000000 0x0 0x0
0xffff9d800001cc00 0001 00000000 0x0 0x0
0xffff9d800001cc80 0001 00000000 0x0 0x0
0xffff9d800001cd00 0001 00000000 0x0 0x0
0xffff9d800001cd80 0001 00000000 0x0 0x0
0xffff9d800001ce00 0001 00000000 0x0 0x0
0xffff9d800001ce80 0001 00000000 0x0 0x0
0xffff9d800001cf00 0001 00000000 0x0 0x0
0xffff9d800001cf80 0001 00000000 0x0 0x0
0xffff9d800001d000 0001 00000000 0x0 0x0
0xffff9d800001d080 0001 00000000 0x0 0x0
0xffff9d800001d100 0001 00000000 0x0 0x0
0xffff9d800001d180 0001 00000000 0x0 0x0
0xffff9d800001d200 0001 00000000 0x0 0x0
0xffff9d800001d280 0001 00000000 0x0 0x0
0xffff9d800001d300 0001 00000000 0x0 0x0
0xffff9d800001d380 0001 00000000 0x0 0x0
0xffff9d800001d400 0001 00000000 0x0 0x0
0xffff9d800001d480 0001 00000000 0x0 0x0
0xffff9d800001d500 0001 00000000 0x0 0x0
0xffff9d800001d580 0001 00000000 0x0 0x0
0xffff9d800001d600 0001 00000000 0x0 0x0
0xffff9d800001d680 0001 00000000 0x0 0x0
0xffff9d800001d700 0001 00000000 0x0 0x0
0xffff9d800001d780 0001 00000000 0x0 0x0
0xffff9d800001d800 0001 00000000 0x0 0x0
0xffff9d800001d880 0001 00000000 0x0 0x0
0xffff9d800001d900 0001 00000000 0x0 0x0
0xffff9d800001d980 0001 00000000 0x0 0x0
0xffff9d800001da00 0001 00000000 0x0 0x0
0xffff9d800001da80 0001 00000000 0x0 0x0
0xffff9d800001db00 0001 00000000 0x0 0x0
0xffff9d800001db80 0001 00000000 0x0 0x0
0xffff9d800001dc00 0001 00000000 0x0 0x0
0xffff9d800001dc80 0001 00000000 0x0 0x0
0xffff9d800001dd00 0001 00000000 0x0 0x0
0xffff9d800001dd80 0001 00000000 0x0 0x0
0xffff9d800001de00 0001 00000000 0x0 0x0
0xffff9d800001de80 0001 00000000 0x0 0x0
0xffff9d800001df00 0001 00000000 0x0 0x0
0xffff9d800001df80 0001 00000000 0x0 0x0
0xffff9d800001e000 0001 00000000 0x0 0x0
0xffff9d800001e080 0001 00000000 0x0 0x0
0xffff9d800001e100 0001 00000000 0x0 0x0
0xffff9d800001e180 0001 00000000 0x0 0x0
0xffff9d800001e200 0001 00000000 0x0 0x0
0xffff9d800001e280 0001 00000000 0x0 0x0
0xffff9d800001e300 0001 00000000 0x0 0x0
0xffff9d800001e380 0001 00000000 0x0 0x0
0xffff9d800001e400 0001 00000000 0x0 0x0
0xffff9d800001e480 0001 00000000 0x0 0x0
0xffff9d800001e500 0001 00000000 0x0 0x0
0xffff9d800001e580 0001 00000000 0x0 0x0
0xffff9d800001e600 0001 00000000 0x0 0x0
0xffff9d800001e680 0001 00000000 0x0 0x0
0xffff9d800001e700 0001 00000000 0x0 0x0
0xffff9d800001e780 0001 00000000 0x0 0x0
0xffff9d800001e800 0001 00000000 0x0 0x0
0xffff9d800001e880 0001 00000000 0x0 0x0
0xffff9d800001e900 0001 00000000 0x0 0x0
0xffff9d800001e980 0001 00000000 0x0 0x0
0xffff9d800001ea00 0001 00000000 0x0 0x0
0xffff9d800001ea80 0001 00000000 0x0 0x0
0xffff9d800001eb00 0001 00000000 0x0 0x0
0xffff9d800001eb80 0001 00000000 0x0 0x0
0xffff9d800001ec00 0001 00000000 0x0 0x0
0xffff9d800001ec80 0001 00000000 0x0 0x0
0xffff9d800001ed00 0001 00000000 0x0 0x0
0xffff9d800001ed80 0001 00000000 0x0 0x0
0xffff9d800001ee00 0001 00000000 0x0 0x0
0xffff9d800001ee80 0001 00000000 0x0 0x0
0xffff9d800001ef00 0001 00000000 0x0 0x0
0xffff9d800001ef80 0001 00000000 0x0 0x0
0xffff9d800001f000 0001 00000000 0x0 0x0
0xffff9d800001f080 0001 00000000 0x0 0x0
0xffff9d800001f100 0001 00000000 0x0 0x0
0xffff9d800001f180 0001 00000000 0x0 0x0
0xffff9d800001f200 0001 00000000 0x0 0x0
0xffff9d800001f280 0001 00000000 0x0 0x0
0xffff9d800001f300 0001 00000000 0x0 0x0
0xffff9d800001f380 0001 00000000 0x0 0x0
0xffff9d800001f400 0001 00000000 0x0 0x0
0xffff9d800001f480 0001 00000000 0x0 0x0
0xffff9d800001f500 0001 00000000 0x0 0x0
0xffff9d800001f580 0001 00000000 0x0 0x0
0xffff9d800001f600 0001 00000000 0x0 0x0
0xffff9d800001f680 0001 00000000 0x0 0x0
0xffff9d800001f700 0001 00000000 0x0 0x0
0xffff9d800001f780 0001 00000000 0x0 0x0
0xffff9d800001f800 0001 00000000 0x0 0x0
0xffff9d800001f880 0001 00000000 0x0 0x0
0xffff9d800001f900 0001 00000000 0x0 0x0
0xffff9d800001f980 0001 00000000 0x0 0x0
0xffff9d800001fa00 0001 00000000 0x0 0x0
0xffff9d800001fa80 0001 00000000 0x0 0x0
0xffff9d800001fb00 0001 00000000 0x0 0x0
0xffff9d800001fb80 0001 00000000 0x0 0x0
0xffff9d800001fc00 0001 00000000 0x0 0x0
0xffff9d800001fc80 0001 00000000 0x0 0x0
0xffff9d800001fd00 0001 00000000 0x0 0x0
0xffff9d800001fd80 0001 00000000 0x0 0x0
0xffff9d800001fe00 0001 00000000 0x0 0x0
0xffff9d800001fe80 0001 00000000 0x0 0x0
0xffff9d800001ff00 0001 00000000 0x0 0x0
0xffff9d800001ff80 0001 00000000 0x0 0x0
0xffff9d8000020000 0001 00000000 0x0 0x0
0xffff9d8000020080 0001 00000000 0x0 0x0
0xffff9d8000020100 0001 00000000 0x0 0x0
0xffff9d8000020180 0001 00000000 0x0 0x0
0xffff9d8000020200 0001 00000000 0x0 0x0
0xffff9d8000020280 0001 00000000 0x0 0x0
0xffff9d8000020300 0001 00000000 0x0 0x0
0xffff9d8000020380 0001 00000000 0x0 0x0
0xffff9d8000020400 0001 00000000 0x0 0x0
0xffff9d8000020480 0001 00000000 0x0 0x0
0xffff9d8000020500 0001 00000000 0x0 0x0
0xffff9d8000020580 0001 00000000 0x0 0x0
0xffff9d8000020600 0001 00000000 0x0 0x0
0xffff9d8000020680 0001 00000000 0x0 0x0
0xffff9d8000020700 0001 00000000 0x0 0x0
0xffff9d8000020780 0001 00000000 0x0 0x0
0xffff9d8000020800 0001 00000000 0x0 0x0
0xffff9d8000020880 0001 00000000 0x0 0x0
0xffff9d8000020900 0001 00000000 0x0 0x0
0xffff9d8000020980 0001 00000000 0x0 0x0
0xffff9d8000020a00 0001 00000000 0x0 0x0
0xffff9d8000020a80 0001 00000000 0x0 0x0
0xffff9d8000020b00 0001 00000000 0x0 0x0
0xffff9d8000020b80 0001 00000000 0x0 0x0
0xffff9d8000020c00 0001 00000000 0x0 0x0
0xffff9d8000020c80 0001 00000000 0x0 0x0
0xffff9d8000020d00 0001 00000000 0x0 0x0
0xffff9d8000020d80 0001 00000000 0x0 0x0
0xffff9d8000020e00 0001 00000000 0x0 0x0
0xffff9d8000020e80 0001 00000000 0x0 0x0
0xffff9d8000020f00 0001 00000000 0x0 0x0
0xffff9d8000020f80 0001 00000000 0x0 0x0
0xffff9d8000021000 0001 00000000 0x0 0x0
0xffff9d8000021080 0001 00000000 0x0 0x0
0xffff9d8000021100 0001 00000000 0x0 0x0
0xffff9d8000021180 0001 00000000 0x0 0x0
0xffff9d8000021200 0001 00000000 0x0 0x0
0xffff9d8000021280 0001 00000000 0x0 0x0
0xffff9d8000021300 0001 00000000 0x0 0x0
0xffff9d8000021380 0001 00000000 0x0 0x0
0xffff9d8000021400 0001 00000000 0x0 0x0
0xffff9d8000021480 0001 00000000 0x0 0x0
0xffff9d8000021500 0001 00000000 0x0 0x0
0xffff9d8000021580 0001 00000000 0x0 0x0
0xffff9d8000021600 0001 00000000 0x0 0x0
0xffff9d8000021680 0001 00000000 0x0 0x0
0xffff9d8000021700 0001 00000000 0x0 0x0
0xffff9d8000021780 0001 00000000 0x0 0x0
0xffff9d8000021800 0001 00000000 0x0 0x0
0xffff9d8000021880 0001 00000000 0x0 0x0
0xffff9d8000021900 0001 00000000 0x0 0x0
0xffff9d8000021980 0001 00000000 0x0 0x0
0xffff9d8000021a00 0001 00000000 0x0 0x0
0xffff9d8000021a80 0001 00000000 0x0 0x0
0xffff9d8000021b00 0001 00000000 0x0 0x0
0xffff9d8000021b80 0001 00000000 0x0 0x0
0xffff9d8000021c00 0001 00000000 0x0 0x0
0xffff9d8000021c80 0001 00000000 0x0 0x0
0xffff9d8000021d00 0001 00000000 0x0 0x0
0xffff9d8000021d80 0001 00000000 0x0 0x0
0xffff9d8000021e00 0001 00000000 0x0 0x0
0xffff9d8000021e80 0001 00000000 0x0 0x0
0xffff9d8000021f00 0001 00000000 0x0 0x0
0xffff9d8000021f80 0001 00000000 0x0 0x0
0xffff9d8000022000 0001 00000000 0x0 0x0
0xffff9d8000022080 0001 00000000 0x0 0x0
0xffff9d8000022100 0001 00000000 0x0 0x0
0xffff9d8000022180 0001 00000000 0x0 0x0
0xffff9d8000022200 0001 00000000 0x0 0x0
0xffff9d8000022280 0001 00000000 0x0 0x0
0xffff9d8000022300 0001 00000000 0x0 0x0
0xffff9d8000022380 0001 00000000 0x0 0x0
0xffff9d8000022400 0001 00000000 0x0 0x0
0xffff9d8000022480 0001 00000000 0x0 0x0
0xffff9d8000022500 0001 00000000 0x0 0x0
0xffff9d8000022580 0001 00000000 0x0 0x0
0xffff9d8000022600 0001 00000000 0x0 0x0
0xffff9d8000022680 0001 00000000 0x0 0x0
0xffff9d8000022700 0001 00000000 0x0 0x0
0xffff9d8000022780 0001 00000000 0x0 0x0
0xffff9d8000022800 0001 00000000 0x0 0x0
0xffff9d8000022880 0001 00000000 0x0 0x0
0xffff9d8000022900 0001 00000000 0x0 0x0
0xffff9d8000022980 0001 00000000 0x0 0x0
0xffff9d8000022a00 0001 00000000 0x0 0x0
0xffff9d8000022a80 0001 00000000 0x0 0x0
0xffff9d8000022b00 0001 00000000 0x0 0x0
0xffff9d8000022b80 0001 00000000 0x0 0x0
0xffff9d8000022c00 0001 00000000 0x0 0x0
0xffff9d8000022c80 0001 00000000 0x0 0x0
0xffff9d8000022d00 0001 00000000 0x0 0x0
0xffff9d8000022d80 0001 00000000 0x0 0x0
0xffff9d8000022e00 0001 00000000 0x0 0x0
0xffff9d8000022e80 0001 00000000 0x0 0x0
0xffff9d8000022f00 0001 00000000 0x0 0x0
0xffff9d8000022f80 0001 00000000 0x0 0x0
0xffff9d8000023000 0001 00000000 0x0 0x0
0xffff9d8000023080 0001 00000000 0x0 0x0
0xffff9d8000023100 0001 00000000 0x0 0x0
0xffff9d8000023180 0001 00000000 0x0 0x0
0xffff9d8000023200 0001 00000000 0x0 0x0
0xffff9d8000023280 0001 00000000 0x0 0x0
0xffff9d8000023300 0001 00000000 0x0 0x0
0xffff9d8000023380 0001 00000000 0x0 0x0
0xffff9d8000023400 0001 00000000 0x0 0x0
0xffff9d8000023480 0001 00000000 0x0 0x0
0xffff9d8000023500 0001 00000000 0x0 0x0
0xffff9d8000023580 0001 00000000 0x0 0x0
0xffff9d8000023600 0001 00000000 0x0 0x0
0xffff9d8000023680 0001 00000000 0x0 0x0
0xffff9d8000023700 0001 00000000 0x0 0x0
0xffff9d8000023780 0001 00000000 0x0 0x0
0xffff9d8000023800 0001 00000000 0x0 0x0
0xffff9d8000023880 0001 00000000 0x0 0x0
0xffff9d8000023900 0001 00000000 0x0 0x0
0xffff9d8000023980 0001 00000000 0x0 0x0
0xffff9d8000023a00 0001 00000000 0x0 0x0
0xffff9d8000023a80 0001 00000000 0x0 0x0
0xffff9d8000023b00 0001 00000000 0x0 0x0
0xffff9d8000023b80 0001 00000000 0x0 0x0
0xffff9d8000023c00 0001 00000000 0x0 0x0
0xffff9d8000023c80 0001 00000000 0x0 0x0
0xffff9d8000023d00 0001 00000000 0x0 0x0
0xffff9d8000023d80 0001 00000000 0x0 0x0
0xffff9d8000023e00 0001 00000000 0x0 0x0
0xffff9d8000023e80 0001 00000000 0x0 0x0
0xffff9d8000023f00 0001 00000000 0x0 0x0
0xffff9d8000023f80 0001 00000000 0x0 0x0
0xffff9d8000024000 0001 00000000 0x0 0x0
0xffff9d8000024080 0001 00000000 0x0 0x0
0xffff9d8000024100 0001 00000000 0x0 0x0
0xffff9d8000024180 0001 00000000 0x0 0x0
0xffff9d8000024200 0001 00000000 0x0 0x0
0xffff9d8000024280 0001 00000000 0x0 0x0
0xffff9d8000024300 0001 00000000 0x0 0x0
0xffff9d8000024380 0001 00000000 0x0 0x0
0xffff9d8000024400 0001 00000000 0x0 0x0
0xffff9d8000024480 0001 00000000 0x0 0x0
0xffff9d8000024500 0001 00000000 0x0

---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Apr 16, 2023, 5:03:40 AM4/16/23
to syzkaller-...@googlegroups.com
Auto-closing this bug as obsolete.
Crashes did not happen for a while, no reproducer and no activity.
Reply all
Reply to author
Forward
0 new messages