DF-0917 / fix_run.log
=== PATCHED fuse.ko live run (fused0917 2) === DONE rc=0 === daemon log === [daemon 1193] opened /dev/fuse fd=4 [daemon 1193] I/O loop started (RACE_DELAY_SEC=35, iters=2) [daemon 1194] child: mount(fuse,/mnt/fuse,fd=4) [daemon 1193] REQ op=26 unique=0 nodeid=1 t=259.280 [daemon 1193] reply unique=0 error=0 payload=64 w=80 [daemon 1193] REQ op=17 unique=1 nodeid=1 t=259.284 [daemon 1193] reply unique=1 error=0 payload=80 w=96 [daemon 1194] child: mount ok; starting stat() stress loop [daemon 1193] REQ op=3 unique=2 nodeid=1 t=259.393 [daemon 1193] GETATTR unique=2: sleeping 35s to align write with tx timeout (race attempt 1/2) <<<< [daemon 1194] child: stat[0] rc=-1 (FAIL); errno=Operation timed out [daemon 1193] GETATTR unique=2: writing reply at t=294.393 (slept 35.000) -> fuse_device_write will deref fip with no ref held <<<< [daemon 1193] reply unique=2 error=0 payload=104 w=-1 [daemon 1193] REQ op=3 unique=3 nodeid=1 t=294.394 [daemon 1193] GETATTR unique=3: sleeping 35s to align write with tx timeout (race attempt 2/2) <<<< [daemon 1194] child: stat[1] rc=-1 (FAIL); errno=Operation timed out [daemon 1193] GETATTR unique=3: writing reply at t=329.394 (slept 35.000) -> fuse_device_write will deref fip with no ref held <<<< [daemon 1193] reply unique=3 error=0 payload=104 w=-1 [daemon 1193] REQ op=3 unique=4 nodeid=1 t=329.394 [daemon 1193] reply unique=4 error=0 payload=104 w=120 [daemon 1193] REQ op=1 unique=5 nodeid=1 t=329.394 [daemon 1193] reply unique=5 error=0 payload=128 w=144 [daemon 1193] REQ op=3 unique=6 nodeid=2 t=329.394 [daemon 1193] reply unique=6 error=0 payload=104 w=120 [daemon 1194] child: stat[2] rc=0 (ok); errno=Operation timed out [daemon 1193] REQ op=38 unique=7 nodeid=1 t=329.654 [daemon 1193] unhandled op 38 -> ENOSYS [daemon 1193] reply unique=7 error=-78 payload=0 w=16 [daemon 1193] read req failed: Socket is not connected [daemon 1194] child: unmounted; exiting [daemon 1193] parent: child status=0; DONE (if kernel still up, the race did not fire in 2 attempts; the UAF pattern is proven by harness.c) === guest still up? === 1:17PM up 7 mins, 0 users, load averages: 0.00, 0.02, 0.00 === loaded module === 4 1 0xffffffff82600000 d000 fuse.ko (/boot/kernel/fuse.ko) 325 fuse SHA256 (/boot/kernel/fuse.ko) = 2eff54d309a427907bf2624f1d3a09b4967022a4d0b5aba853bd46d0553c8d86