blob: 61ccb2a05bb26f341bf8a0ef24e5baeb5eaf6fb7 [file] [log] [blame]
// KMSAN: uninit-value in csum_partial
// https://syzkaller.appspot.com/bug?id=566325c29e627765e4f5d223163e5c15191f0f46
// status:invalid
// autogenerated by syzkaller (http://github.com/google/syzkaller)
#define _GNU_SOURCE
#include <endian.h>
#include <stdint.h>
#include <string.h>
#include <sys/syscall.h>
#include <unistd.h>
uint64_t r[1] = {0xffffffffffffffff};
void loop()
{
long res = 0;
res = syscall(__NR_socket, 0xa, 2, 0);
if (res != -1)
r[0] = res;
*(uint16_t*)0x205fa000 = 0xa;
*(uint16_t*)0x205fa002 = htobe16(0x4e22);
*(uint32_t*)0x205fa004 = 0;
*(uint8_t*)0x205fa008 = 0;
*(uint8_t*)0x205fa009 = 0;
*(uint8_t*)0x205fa00a = 0;
*(uint8_t*)0x205fa00b = 0;
*(uint8_t*)0x205fa00c = 0;
*(uint8_t*)0x205fa00d = 0;
*(uint8_t*)0x205fa00e = 0;
*(uint8_t*)0x205fa00f = 0;
*(uint8_t*)0x205fa010 = 0;
*(uint8_t*)0x205fa011 = 0;
*(uint8_t*)0x205fa012 = 0;
*(uint8_t*)0x205fa013 = 0;
*(uint8_t*)0x205fa014 = 0;
*(uint8_t*)0x205fa015 = 0;
*(uint8_t*)0x205fa016 = 0;
*(uint8_t*)0x205fa017 = 0;
*(uint32_t*)0x205fa018 = 0;
syscall(__NR_sendto, r[0], 0x208d1000, 0x254, 0x4c080, 0x205fa000, 0x1c);
*(uint64_t*)0x20610fc8 = 0;
*(uint32_t*)0x20610fd0 = 0;
*(uint64_t*)0x20610fd8 = 0x209f8000;
*(uint64_t*)0x209f8000 = 0x20554000;
memcpy(
(void*)0x20554000,
"\xed\x87\x16\x62\x85\x5a\x22\x1f\xd9\x92\xa5\x77\xfb\xda\xff\xdf\x10\x6d"
"\x2b\x39\x08\x52\xd7\x08\xe3\x22\x2e\x84\x0a\x19\x2a\x95\x8c\x1d\xd9\xe1"
"\x38\x72\xfa\x78\xe9\x97\xe8\x09\x59\xb7\xf4\x21\xf9\xf0\xf4\x5b\x88\x14"
"\x60\x48\x5b\x48\x77\x4c\xea\x67\x84\x4c\x41\x43\x3b\x0c\x7e\x6f\x62\xc0"
"\x7f\x9f\x79\xb6\x2b\xb9\x9a\xaf\x31\x6c\xba\x5c\x29\x3d\xeb\x6d\x5f\x8f"
"\xe4\xa5\x9e\xbe\x0c\x0d\xd2\x58\x23\xca\x18\x0b\x8f\xf5\xdc\xb1\xde\xd3"
"\x6a\x36\x67\x6b\x9d\x55\x53\xd4\x6b\xac\x52\xaf\x6e\x96\x77\x0e\x0f\xb0"
"\x1c\x0b\x34\x84\xfb\xac\xac\xc0\xbe\x7f\x50\xa3\x9b\x33\x56\x44\x56\x85"
"\x36\xf3\x3a\x74\x55\xb3\xad\xb6\x49\x49\xd3\x8d\xc9\x45\x72\xa4\xb3\x8a"
"\x94\x3b\xfd\x48\xb4\x18\xe0\xfc\xa0\xe0\xbc\x17\xdf\x96\xfb\x2f\x41\xde"
"\x06\xc3\x7f\x0f\x56\x3c\x5c\xcd\x8c\x10\x9a\x26\x16\xbc\x1f\x5c\x56\x41"
"\x88\x1c\xaa\xb9\xbd\x54\x88\x26\x59\xbb\x76\x06\x5e\xc7\x9e\xf0\x00\xac"
"\x8d\x72\x41\x67\x44\xd4\xb2\xff\xc9\x7f\xd3\x5e\x7d\xe5\xd6\xb4\x9d\x29"
"\xf8\xc7\x14\xdc\x90\x1b\x70\x7d\x55\x89\x53\xec\xf4\x35\x43\x31\x76\x7b"
"\x86\xe1\x19\x59\x54\x29\xa7\x26\x6a\x4f\x5c\x17\x43\x89\x69\x31\x5c\x96"
"\xaf\xc0\x10\xc3\xc1\x43\x74\xda\x55\xde\x64\x62\x7b\x1e\xd4\x18\x3b\x5a"
"\xda\x1c\xab\x6d\x0e\x54\xbb\x0c\x96\x16\xb7\x30\x39\x53\x3d\x4d\xe0\x8d"
"\x51\xe0\x62\x25\xb8\x8d\x26\xae\x69\x3c\x61\x36\x24\x11\x18\xdb\x79\x83"
"\x16\x3c\x4c\xfd\xd8\x71\xc7\x70\x77\x38\x25\xe0\xe9\x9c\xad\x55\xb1\x23"
"\x00\x16\xd6\x0e\xef\x7b\x19\x5b\x4c\xe1\x87\x9b\x67\x30\xc1\x51\x65\x7a"
"\x21\x9b\x8d\xb3\xe5\x80\x38\xb0\x52\xb9\xbf\xd2\xdf\xcd\x0c\xa1\xb9\x83"
"\xac\x79\x42\xa0\x1f\x79\x5e\x46\x6a\x4b\xf3\x02\x30\xd5\x21\x62\x31\x20"
"\x6d\x78\x4e\xba\x63\xd5\x2c\xb0\x0c\xff\xbb\x29\x14\x53\x8c\xd3\x9d\x47"
"\xe5\xa5\x5a\x37\x9b\xc8\x13\x1a\xfa\x79\x8f\xc4\xb8\xd7\x36\x1c\xaf\x04"
"\x8e\xb4\xf9\xad\x3c\x30\x4e\xaf\x12\xa2\xf2\x47\x31\x97\x5e\xc9\x8b\x04"
"\x97\x30\x1e\x95\xbc\x73\xe5\x88\xab\x44\x0c\x1b\x25\x6f\x53\x12\xa6\x31"
"\x8a\x16\x78\x79\x27\x4a\x71\xef\x3e\x48\x07\x1f\x23\x11\x8b\xab\x6f\xd6"
"\xd9\x68\xce\x8f\x99\x2b\x00\xd7\x75\x69\x9d\xad\x48\x88\x4a\x6c\xad\x28"
"\x29\xaa\xa2\x04\x4e\x08\x04\x0d\x43\x37\x5f\xe4\x78\xa2\x14\x4f\xf1\x23"
"\x1c\xfb\x84\xd4\xdc\x27\xba\xf6\xf0\xd8\x6c\x5c\xa3\x94\x7b\x20\xc7\x51"
"\xcb\x37\x67\x3d\x2a\xf1\x2a\x34\x79\x81\x50\xe8\x95\xfc\xdb\x11\x8c\x6a"
"\x68\xc9\xc1\x4f\xeb\x27\xa7\xe4\x65\x69\xa0\xab\x52\xa2\x4f\x13\xe8\x80"
"\x2d\x19\xbb\x80\xa9\xea\x69\xb7\x8e\x0f\x7a\xbe\x67\x98\xc7\xba\x43\xfa"
"\xc4\xa1\x56\xb8\x14\x11\x18\x8e\xc5\x03\xf3\x21\x12\x12\x68\xff\xfe\x33"
"\xaf\xd4\x43\xda\xa8\x7b\x86\xeb\x55\x18\x3a\x5c\x4e\xb2\xd5\x70\x83\x98"
"\x59\x49\x9d\x50\x1f\x98\xcd\x10\x15\xc5\xcd\x2c\x9b\xf7\x44\xd9\x46\xf6"
"\x39\xa2\x8c\x05\x30\x36\xc2\x18\x69\x53\xa1\xf2\x60\x54\x4b\x8b\x1e\x99"
"\xae\x1b\x88\xf2\xc5\x8f\xfd\x9e\xe2\xab\x20\x6f\xbf\x3a\xc8\x8d\x09\xb7"
"\x8c\x38\xf7\x16\x11\x15\x94\xc5\x05\xff\x88\x5a\x08\x74\x69\x57\x95\x42"
"\x29\x82\x5d\xb1\x7f\x11\xb8\xcb\x25\x2b\x60\xf0\x76\x5d\x7d\x99\x02\xfc"
"\x1e\xdf\xd9\x03\xdd\x71\x44\x2b\x09\x5c\x97\xbb\xf5\x28\x27\x5a\xf4\x4f"
"\xbe\x52\xf2\x48\x95\xc8\x1c\xc2\x7e\xc7\x34\x94\xce\x3d\x12\x5e\x86\xe0"
"\x5e\x1c\x8d\x23\xb1\xa1\x1d\x62\x71\x73\x7c\x29\xf3\x31\xe9\x45\xd1\xfe"
"\x85\x8d\x24\xc9\x8b\x5f\x1b\x2e\x9e\x00\x3c\x84\x16\x66\xa8\xf7\xb1\x6a"
"\x8c\x4d\xf1\xa8\x0b\x1e\xfa\xf2\xe4\xd9\x53\x47\x1a\xf5\x79\x4d\x4d\x39"
"\x75\x4f\x77\x25\xf2\xdd\x44\x89\xb9\xc9\x24\x79\x2d\xde\x5a\xd7\x64\x1f"
"\xe6\x3f\x69\x31\x48\x95\xae\x68\x0c\x7d\x98\x03\x93\x98\x72\x66\x7e\xdf"
"\x2f\x58\xfd\x83\xa2\x0f\x6d\x9d\x1f\xad\xe8\x05\x8b\x00\x9f\x81\xf2\x1b"
"\xe4\xeb\x20\x2f\xf1\xb2\xcf\x57\x9a\x82\xbf\x21\x99\xa2\xe2\x22\xd6\x29"
"\x42\x73\x0d\x04\xb3\xa8\x3c\x23\x9a\x5b\x03\x91\x72\x14\x79\xf9\x20\xe3"
"\xc5\x3e\xa4\xf0\x5f\x54\x80\x58\xec\x0b\x5e\xf6\x53\x1e\x0c\xfd\x1c\xfd"
"\x66\x6d\xa4\xa2\xde\xee\x3c\x54\x47\xdb\xf4\xe2\xd6\xb8\x2e\xad\x52\x24"
"\xfd\xe6\x09\x25\x53\xae\xd2\xae\x2b\xab\xf3\x93\xcf\x20\x85\x96\x49\xb8"
"\x08\x23\x12\xd9\x19\x7e\xb2\x79\x45\x55\x16\x6a\x7a\xa9\xf5\x96\x28\x4f"
"\xd7\xce\xf3\x7c\x3c\x1c\x83\x5e\xdf\xc4\x6d\xdf\xaf\x0c\x69\xb8\xfd\x9d"
"\x12\x61\x42\x89\x2a\xcc\x05\x0d\x46\x66\x8d\x3a\x7d\x04\x34\x43\xe2\x8a"
"\x30\x20\x00\xca\x52\xad\x71\xa9\x1c\xa9\x96\x1c\x0f\x19\x39\x29\x75\xae"
"\x26\x9a\xfb\x59\x96\x1c\xe7\x6a\x79\x53\x7e\x21\x78\x0a\xdd\xec\xde\x25"
"\x75\x20\xad\x97\x30\x16\x11\xbc\xf7\x7a\xf7\x2a\x04\xd3\xb4\x35\xfb\x65"
"\x6b\x97\xf3\x37\x92\xfd\xc4\x31\x8e\x4e\x05\x8a\x0b\xdd\x5d\x93\x6f\xa1"
"\x98\xbf\x29\xb3\x98\x7f\x44\x15\xef\xcf\x35\x28\x9f\xfe\xe2\xfb\x6e\xf3"
"\x02\x65\xf7\x5b\xa8\x06\xdf\x91\x1e\xf8\xd5\xb9\xa6\xc2\xad\x36\x9c\xc0"
"\x6e\x82\xec\x72\x90\x5d\x67\x1b\xb1\x81\xec\x10\xd1\x04\x01\x0f\xd5\x7b"
"\xa9\xac\x12\xd5\xc4\x8d\x8c\x95\x46\x4a\x78\x62\xd3\x8b\x58\x00\xe0\x0d"
"\x14\x01\x5e\xbc\xf4\x5e\xec\x48\xa4\x18\x35\x27\xc5\x6c\x5a\x34\x64\x64"
"\x20\xc8\xc7\x2a\xa8\x45\x9b\xb1\xf6\xcf\x6c\xd4\x8b\x8b\x0f\x0f\x9f\xb5"
"\xe8\x86\xb4\xf5\x7d\x1e\x61\x46\x86\x03\x0e\x8b\xd5\xb8\x84\x2d\x71\x43"
"\xbe\x6a\xb2\xc3\xe9\xfc\x47\x66\xc1\x3a\xad\x2a\xde\xa3\x68\x12\xfa\x2d"
"\x11\xcf\xa4\x5e\x3b\x03\x36\x67\x31\x87\xea\xc8\xed\x70\xb3\x17\xfa\x14"
"\x2f\xf5\x60\xed\x94\xc1\xa8\xd7\x14\xc8\x37\x26\xba\xa7\x81\x3b\x12\x9a"
"\xef\xbf\xb5\x7b\xb4\xe4\x7b\x8a\x20\x51\x99\x65\xff\x3c\x56\x06\xf7\xf9"
"\xd2\xe0\x28\x12\xcc\x20\x39\x12\xe8\x3a\x37\x26\x60\x23\x54\x06\x2f\x4b"
"\x3e\x09\x73\x2c\x99\x83\xb3\x9f\x90\x51\xc1\x0e\x96\xa8\xa3\xd5\xbc\x5c"
"\xfe\x97\xf0\x9b\x4b\x0d\x88\xa7\x73\x8f\x56\xfa\x77\x16\x09\xdd\xd6\x91"
"\xa6\x40\x90\x75\xf4\x8a\xf3\x87\x26\xeb\x8b\x83\x9e\xc3\xdc\xfd\x25\xf3"
"\x5b\x8c\x64\x17\x86\x5d\x48\x66\xbd\x57\x74\x75\xb0\x94\x45\x2d\x22\x93"
"\x9d\x8b\x56\x73\xd8\x74\x85\x9b\x38\xc8\xd6\xef\xf7\x5a\x47\xca\x8c\x38"
"\x96\xb8\xee\x0d\x83\x28\xf7\xa6\xc3\x10\x12\x63\xec\x78\x5e\xc2\xad\x0c"
"\x2e\xcf\x6e\x8d\x86\x65\x1c\xde\x83\x05\xe2\x94\x84\xed\xb1\x4b\xb1\x4b"
"\xde\x24\x97\xce\xca\x82\x36\x21\x3d\x47\x1f\x09\x38\x1b\x66\x2f\x9e\xa3"
"\xca",
1441);
*(uint64_t*)0x209f8008 = 0x5a1;
*(uint64_t*)0x20610fe0 = 1;
*(uint64_t*)0x20610fe8 = 0x20864bb8;
*(uint64_t*)0x20610ff0 = 0;
*(uint32_t*)0x20610ff8 = 0;
syscall(__NR_sendmsg, r[0], 0x20610fc8, 0);
}
int main()
{
syscall(__NR_mmap, 0x20000000, 0x1000000, 3, 0x32, -1, 0);
loop();
return 0;
}