tquaf: queue 0xfffff8011756aec8 started (0) tquaf: taskqueue_cancel(t1) = 0 while t1 running (0 = contract violated, EBUSY=16 expected) tquaf: BUG PROVEN: taskqueue_drain(t1) returned while t1 ta_func still executing tquaf: freeing live task context 0xfffff8008d2e0810 tquaf: freed ctx reallocated at 0xfffff8008d2e0810 (alias YES) magic=deadbeef tquaf: UAF CONFIRMED: running task sees ctx 0xfffff8008d2e0810 magic=deadbeef (expected cafebabe) panic: DF-2869: task context freed while task running (magic=deadbeef) cpuid = 0 Trace beginning at frame 0xfffff8011867fa00 t1_func() at t1_func+0x9b 0xffffffff826010ab t1_func() at t1_func+0x9b 0xffffffff826010ab taskqueue_run() at taskqueue_run+0xbb 0xffffffff806a3c5b taskqueue_thread_loop() at taskqueue_thread_loop+0x5d 0xffffffff806a3e1d Debugger("panic") CPU0 stopping CPUs: 0x0000003e stopped Stopped at Debugger+0x7c: movb $0,0xbdaf09(%rip) db>