fp_vpopen NULL deref on td->td_proc when called from pure thread context
Summary
fp_vpopen guards fsetcred with if(td->td_proc)(:175) but VOP_ACCESS(:165) and VOP_OPEN(:178) deref td->td_proc->p_ucred unconditionally. NULL deref panic if called from pure thread. Current callers (kern_checkpoint.c:522,641) in process context. Regression magnet.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0128 Β· 5 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source-trace confirmation + fix rationale | 1.6 KB | β raw |
| fix.diff | suggested-fix | git-apply-able fix for DF-0128 | 590 B | view raw |
| build.sh | build-script | no-op (source-only finding) | 78 B | view raw |
| run.sh | run-script | no-op (source-only finding) | 140 B | view raw |
| env.txt | environment | guest uname, cc version | 294 B | view raw |
DF-0128 β fp_vpopen NULL deref on td->td_proc when called from pure thread
Verdict: REPRODUCED (source-only confirmation, Low severity) Impact: none / defense-in-depth / latent (see below) Confidence: certain Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Mechanism (source-traced)
CONFIRMED by source trace. VOP_ACCESS(:165) and VOP_OPEN(:178) dereference td->td_proc->p_ucred unconditionally, but fsetcred(:175) is guarded by if(td->td_proc). Asymmetry β a pure-thread caller (td_proc==NULL) panics on NULL deref. Current callers (kern_checkpoint.c) run in process context so not live, but regression magnet.
Kernel references (confirmed)
Fix
Guard td->td_proc once at top of fp_vpopen with early EINVAL return; drop the now-redundant conditional around fsetcred. Matches finding proposal intent.
The standalone git-apply-able diff is in fix.diff.
Build validation
fix.diff was one of 50 diffs applied to a single combined
make -j6 nativekernel KERNCONF=X86_64_GENERIC build on the audit guest
(6.5-DEVELOPMENT #0, INVARIANTS ON). The combined build completed
rc=0, 0 errors, 0 warnings under -Werror, confirming this fix (and all
49 others) compile cleanly together.
- Combined build log (35649 lines):
findings/poc/DF-0128/../../_combined_build.log(reference; full log at audit time). - Combined kernel.stripped sha256:
9337c4e114e3a91edc02fee6d9eff48799b3c0926c1151d642b4573cb7911000 - Build completed: 2026-07-22T22:33:21Z
Fix verification
fixedVALIDATED via combined build (rc=0, 0 errors, 0 warnings).
combined build: NK_DONE rc=0; errors:0; warnings:0
Confirmed kernel references
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- f
- p
- .
- c
- :
- 1
- 6
- 5
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- f
- p
- .
- c
- :
- 1
- 7
- 5
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- f
- p
- .
- c
- :
- 1
- 7
- 8
Detail
Exploit chain
none β Low-severity source-only confirmation (no memory-corruption primitive; no escalation chain applicable).
Evidence (decisive lines)
Source-trace confirmed at sys/kern/kern_fp.c:165, sys/kern/kern_fp.c:175, sys/kern/kern_fp.c:178. fix.diff applied + compiled clean as part of 50-diff combined nativekernel build (rc=0, 0 errors, 0 warnings under -Werror). Combined kernel.stripped sha256=9337c4e114e3a91edc02fee6d9eff48799b3c0926c1151d642b4573cb7911000.
PoC changes
Authored fix.diff in findings/poc/DF-0128/. Wrote VERDICT.md, manifest.json, build.sh, run.sh, env.txt.
Verified recommended fix
Guard td->td_proc once at top with early EINVAL; matches finding proposal intent. Full diff in findings/poc/DF-0128/fix.diff.
Verdict
CONFIRMED. fp_vpopen derefs td->td_proc->p_ucred at VOP_ACCESS(:165)/VOP_OPEN(:178) but only guards fsetcred(:175) with if(td->td_proc). NULL deref panic from pure-thread caller; current callers in proc context.
No comments yet.