Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #define _GNU_SOURCE
- #include <endian.h>
- #include <errno.h>
- #include <fcntl.h>
- #include <setjmp.h>
- #include <stdbool.h>
- #include <stddef.h>
- #include <stdint.h>
- #include <stdio.h>
- #include <stdlib.h>
- #include <string.h>
- #include <sys/ioctl.h>
- #include <sys/mman.h>
- #include <sys/mount.h>
- #include <sys/stat.h>
- #include <sys/syscall.h>
- #include <sys/types.h>
- #include <unistd.h>
- #include <linux/loop.h>
- #ifndef __NR_memfd_create
- #define __NR_memfd_create 319
- #endif
- static unsigned long long procid;
- //% This code is derived from puff.{c,h}, found in the zlib development. The
- //% original files come with the following copyright notice:
- //% Copyright (C) 2002-2013 Mark Adler, all rights reserved
- //% version 2.3, 21 Jan 2013
- //% This software is provided 'as-is', without any express or implied
- //% warranty. In no event will the author be held liable for any damages
- //% arising from the use of this software.
- //% Permission is granted to anyone to use this software for any purpose,
- //% including commercial applications, and to alter it and redistribute it
- //% freely, subject to the following restrictions:
- //% 1. The origin of this software must not be misrepresented; you must not
- //% claim that you wrote the original software. If you use this software
- //% in a product, an acknowledgment in the product documentation would be
- //% appreciated but is not required.
- //% 2. Altered source versions must be plainly marked as such, and must not be
- //% misrepresented as being the original software.
- //% 3. This notice may not be removed or altered from any source distribution.
- //% Mark Adler [email protected]
- //% BEGIN CODE DERIVED FROM puff.{c,h}
- #define MAXBITS 15
- #define MAXLCODES 286
- #define MAXDCODES 30
- #define MAXCODES (MAXLCODES + MAXDCODES)
- #define FIXLCODES 288
- struct puff_state {
- unsigned char* out;
- unsigned long outlen;
- unsigned long outcnt;
- const unsigned char* in;
- unsigned long inlen;
- unsigned long incnt;
- int bitbuf;
- int bitcnt;
- jmp_buf env;
- };
- static int puff_bits(struct puff_state* s, int need)
- {
- long val = s->bitbuf;
- while (s->bitcnt < need) {
- if (s->incnt == s->inlen)
- longjmp(s->env, 1);
- val |= (long)(s->in[s->incnt++]) << s->bitcnt;
- s->bitcnt += 8;
- }
- s->bitbuf = (int)(val >> need);
- s->bitcnt -= need;
- return (int)(val & ((1L << need) - 1));
- }
- static int puff_stored(struct puff_state* s)
- {
- s->bitbuf = 0;
- s->bitcnt = 0;
- if (s->incnt + 4 > s->inlen)
- return 2;
- unsigned len = s->in[s->incnt++];
- len |= s->in[s->incnt++] << 8;
- if (s->in[s->incnt++] != (~len & 0xff) ||
- s->in[s->incnt++] != ((~len >> 8) & 0xff))
- return -2;
- if (s->incnt + len > s->inlen)
- return 2;
- if (s->outcnt + len > s->outlen)
- return 1;
- for (; len--; s->outcnt++, s->incnt++) {
- if (s->in[s->incnt])
- s->out[s->outcnt] = s->in[s->incnt];
- }
- return 0;
- }
- struct puff_huffman {
- short* count;
- short* symbol;
- };
- static int puff_decode(struct puff_state* s, const struct puff_huffman* h)
- {
- int first = 0;
- int index = 0;
- int bitbuf = s->bitbuf;
- int left = s->bitcnt;
- int code = first = index = 0;
- int len = 1;
- short* next = h->count + 1;
- while (1) {
- while (left--) {
- code |= bitbuf & 1;
- bitbuf >>= 1;
- int count = *next++;
- if (code - count < first) {
- s->bitbuf = bitbuf;
- s->bitcnt = (s->bitcnt - len) & 7;
- return h->symbol[index + (code - first)];
- }
- index += count;
- first += count;
- first <<= 1;
- code <<= 1;
- len++;
- }
- left = (MAXBITS + 1) - len;
- if (left == 0)
- break;
- if (s->incnt == s->inlen)
- longjmp(s->env, 1);
- bitbuf = s->in[s->incnt++];
- if (left > 8)
- left = 8;
- }
- return -10;
- }
- static int puff_construct(struct puff_huffman* h, const short* length, int n)
- {
- int len;
- for (len = 0; len <= MAXBITS; len++)
- h->count[len] = 0;
- int symbol;
- for (symbol = 0; symbol < n; symbol++)
- (h->count[length[symbol]])++;
- if (h->count[0] == n)
- return 0;
- int left = 1;
- for (len = 1; len <= MAXBITS; len++) {
- left <<= 1;
- left -= h->count[len];
- if (left < 0)
- return left;
- }
- short offs[MAXBITS + 1];
- offs[1] = 0;
- for (len = 1; len < MAXBITS; len++)
- offs[len + 1] = offs[len] + h->count[len];
- for (symbol = 0; symbol < n; symbol++)
- if (length[symbol] != 0)
- h->symbol[offs[length[symbol]]++] = symbol;
- return left;
- }
- static int puff_codes(struct puff_state* s, const struct puff_huffman* lencode,
- const struct puff_huffman* distcode)
- {
- static const short lens[29] = {3, 4, 5, 6, 7, 8, 9, 10, 11, 13,
- 15, 17, 19, 23, 27, 31, 35, 43, 51, 59,
- 67, 83, 99, 115, 131, 163, 195, 227, 258};
- static const short lext[29] = {0, 0, 0, 0, 0, 0, 0, 0, 1, 1, 1, 1, 2, 2, 2,
- 2, 3, 3, 3, 3, 4, 4, 4, 4, 5, 5, 5, 5, 0};
- static const short dists[30] = {
- 1, 2, 3, 4, 5, 7, 9, 13, 17, 25,
- 33, 49, 65, 97, 129, 193, 257, 385, 513, 769,
- 1025, 1537, 2049, 3073, 4097, 6145, 8193, 12289, 16385, 24577};
- static const short dext[30] = {0, 0, 0, 0, 1, 1, 2, 2, 3, 3,
- 4, 4, 5, 5, 6, 6, 7, 7, 8, 8,
- 9, 9, 10, 10, 11, 11, 12, 12, 13, 13};
- int symbol;
- do {
- symbol = puff_decode(s, lencode);
- if (symbol < 0)
- return symbol;
- if (symbol < 256) {
- if (s->outcnt == s->outlen)
- return 1;
- if (symbol)
- s->out[s->outcnt] = symbol;
- s->outcnt++;
- } else if (symbol > 256) {
- symbol -= 257;
- if (symbol >= 29)
- return -10;
- int len = lens[symbol] + puff_bits(s, lext[symbol]);
- symbol = puff_decode(s, distcode);
- if (symbol < 0)
- return symbol;
- unsigned dist = dists[symbol] + puff_bits(s, dext[symbol]);
- if (dist > s->outcnt)
- return -11;
- if (s->outcnt + len > s->outlen)
- return 1;
- while (len--) {
- if (dist <= s->outcnt && s->out[s->outcnt - dist])
- s->out[s->outcnt] = s->out[s->outcnt - dist];
- s->outcnt++;
- }
- }
- } while (symbol != 256);
- return 0;
- }
- static int puff_fixed(struct puff_state* s)
- {
- static int virgin = 1;
- static short lencnt[MAXBITS + 1], lensym[FIXLCODES];
- static short distcnt[MAXBITS + 1], distsym[MAXDCODES];
- static struct puff_huffman lencode, distcode;
- if (virgin) {
- lencode.count = lencnt;
- lencode.symbol = lensym;
- distcode.count = distcnt;
- distcode.symbol = distsym;
- short lengths[FIXLCODES];
- int symbol;
- for (symbol = 0; symbol < 144; symbol++)
- lengths[symbol] = 8;
- for (; symbol < 256; symbol++)
- lengths[symbol] = 9;
- for (; symbol < 280; symbol++)
- lengths[symbol] = 7;
- for (; symbol < FIXLCODES; symbol++)
- lengths[symbol] = 8;
- puff_construct(&lencode, lengths, FIXLCODES);
- for (symbol = 0; symbol < MAXDCODES; symbol++)
- lengths[symbol] = 5;
- puff_construct(&distcode, lengths, MAXDCODES);
- virgin = 0;
- }
- return puff_codes(s, &lencode, &distcode);
- }
- static int puff_dynamic(struct puff_state* s)
- {
- static const short order[19] = {16, 17, 18, 0, 8, 7, 9, 6, 10, 5,
- 11, 4, 12, 3, 13, 2, 14, 1, 15};
- int nlen = puff_bits(s, 5) + 257;
- int ndist = puff_bits(s, 5) + 1;
- int ncode = puff_bits(s, 4) + 4;
- if (nlen > MAXLCODES || ndist > MAXDCODES)
- return -3;
- short lengths[MAXCODES];
- int index;
- for (index = 0; index < ncode; index++)
- lengths[order[index]] = puff_bits(s, 3);
- for (; index < 19; index++)
- lengths[order[index]] = 0;
- short lencnt[MAXBITS + 1], lensym[MAXLCODES];
- struct puff_huffman lencode = {lencnt, lensym};
- int err = puff_construct(&lencode, lengths, 19);
- if (err != 0)
- return -4;
- index = 0;
- while (index < nlen + ndist) {
- int symbol;
- int len;
- symbol = puff_decode(s, &lencode);
- if (symbol < 0)
- return symbol;
- if (symbol < 16)
- lengths[index++] = symbol;
- else {
- len = 0;
- if (symbol == 16) {
- if (index == 0)
- return -5;
- len = lengths[index - 1];
- symbol = 3 + puff_bits(s, 2);
- } else if (symbol == 17)
- symbol = 3 + puff_bits(s, 3);
- else
- symbol = 11 + puff_bits(s, 7);
- if (index + symbol > nlen + ndist)
- return -6;
- while (symbol--)
- lengths[index++] = len;
- }
- }
- if (lengths[256] == 0)
- return -9;
- err = puff_construct(&lencode, lengths, nlen);
- if (err && (err < 0 || nlen != lencode.count[0] + lencode.count[1]))
- return -7;
- short distcnt[MAXBITS + 1], distsym[MAXDCODES];
- struct puff_huffman distcode = {distcnt, distsym};
- err = puff_construct(&distcode, lengths + nlen, ndist);
- if (err && (err < 0 || ndist != distcode.count[0] + distcode.count[1]))
- return -8;
- return puff_codes(s, &lencode, &distcode);
- }
- static int puff(unsigned char* dest, unsigned long* destlen,
- const unsigned char* source, unsigned long sourcelen)
- {
- struct puff_state s = {
- .out = dest,
- .outlen = *destlen,
- .outcnt = 0,
- .in = source,
- .inlen = sourcelen,
- .incnt = 0,
- .bitbuf = 0,
- .bitcnt = 0,
- };
- int err;
- if (setjmp(s.env) != 0)
- err = 2;
- else {
- int last;
- do {
- last = puff_bits(&s, 1);
- int type = puff_bits(&s, 2);
- err = type == 0 ? puff_stored(&s)
- : (type == 1 ? puff_fixed(&s)
- : (type == 2 ? puff_dynamic(&s) : -1));
- if (err != 0)
- break;
- } while (!last);
- }
- *destlen = s.outcnt;
- return err;
- }
- //% END CODE DERIVED FROM puff.{c,h}
- #define ZLIB_HEADER_WIDTH 2
- static int puff_zlib_to_file(const unsigned char* source,
- unsigned long sourcelen, int dest_fd)
- {
- if (sourcelen < ZLIB_HEADER_WIDTH)
- return 0;
- source += ZLIB_HEADER_WIDTH;
- sourcelen -= ZLIB_HEADER_WIDTH;
- const unsigned long max_destlen = 132 << 20;
- void* ret = mmap(0, max_destlen, PROT_WRITE | PROT_READ,
- MAP_PRIVATE | MAP_ANON, -1, 0);
- if (ret == MAP_FAILED)
- return -1;
- unsigned char* dest = (unsigned char*)ret;
- unsigned long destlen = max_destlen;
- int err = puff(dest, &destlen, source, sourcelen);
- if (err) {
- munmap(dest, max_destlen);
- errno = -err;
- return -1;
- }
- if (write(dest_fd, dest, destlen) != (ssize_t)destlen) {
- munmap(dest, max_destlen);
- return -1;
- }
- return munmap(dest, max_destlen);
- }
- static int setup_loop_device(unsigned char* data, unsigned long size,
- const char* loopname, int* loopfd_p)
- {
- int err = 0, loopfd = -1;
- int memfd = syscall(__NR_memfd_create, "syzkaller", 0);
- if (memfd == -1) {
- err = errno;
- goto error;
- }
- if (puff_zlib_to_file(data, size, memfd)) {
- err = errno;
- goto error_close_memfd;
- }
- loopfd = open(loopname, O_RDWR);
- if (loopfd == -1) {
- err = errno;
- goto error_close_memfd;
- }
- if (ioctl(loopfd, LOOP_SET_FD, memfd)) {
- if (errno != EBUSY) {
- err = errno;
- goto error_close_loop;
- }
- ioctl(loopfd, LOOP_CLR_FD, 0);
- usleep(1000);
- if (ioctl(loopfd, LOOP_SET_FD, memfd)) {
- err = errno;
- goto error_close_loop;
- }
- }
- close(memfd);
- *loopfd_p = loopfd;
- return 0;
- error_close_loop:
- close(loopfd);
- error_close_memfd:
- close(memfd);
- error:
- errno = err;
- return -1;
- }
- static void reset_loop_device(const char* loopname)
- {
- int loopfd = open(loopname, O_RDWR);
- if (loopfd == -1) {
- return;
- }
- if (ioctl(loopfd, LOOP_CLR_FD, 0)) {
- }
- close(loopfd);
- }
- static long syz_mount_image(volatile long fsarg, volatile long dir,
- volatile long flags, volatile long optsarg,
- volatile long change_dir,
- volatile unsigned long size, volatile long image)
- {
- unsigned char* data = (unsigned char*)image;
- int res = -1, err = 0, need_loop_device = !!size;
- char* mount_opts = (char*)optsarg;
- char* target = (char*)dir;
- char* fs = (char*)fsarg;
- char* source = NULL;
- char loopname[64];
- if (need_loop_device) {
- int loopfd;
- memset(loopname, 0, sizeof(loopname));
- snprintf(loopname, sizeof(loopname), "/dev/loop%llu", procid);
- if (setup_loop_device(data, size, loopname, &loopfd) == -1)
- return -1;
- close(loopfd);
- source = loopname;
- }
- mkdir(target, 0777);
- char opts[256];
- memset(opts, 0, sizeof(opts));
- if (strlen(mount_opts) > (sizeof(opts) - 32)) {
- }
- strncpy(opts, mount_opts, sizeof(opts) - 32);
- if (strcmp(fs, "iso9660") == 0) {
- flags |= MS_RDONLY;
- } else if (strncmp(fs, "ext", 3) == 0) {
- bool has_remount_ro = false;
- char* remount_ro_start = strstr(opts, "errors=remount-ro");
- if (remount_ro_start != NULL) {
- char after = *(remount_ro_start + strlen("errors=remount-ro"));
- char before = remount_ro_start == opts ? '\0' : *(remount_ro_start - 1);
- has_remount_ro = ((before == '\0' || before == ',') &&
- (after == '\0' || after == ','));
- }
- if (strstr(opts, "errors=panic") || !has_remount_ro)
- strcat(opts, ",errors=continue");
- } else if (strcmp(fs, "xfs") == 0) {
- strcat(opts, ",nouuid");
- }
- res = mount(source, target, fs, flags, opts);
- if (res == -1) {
- err = errno;
- goto error_clear_loop;
- }
- res = open(target, O_RDONLY | O_DIRECTORY);
- if (res == -1) {
- err = errno;
- goto error_clear_loop;
- }
- if (change_dir) {
- res = chdir(target);
- if (res == -1) {
- err = errno;
- }
- }
- error_clear_loop:
- if (need_loop_device)
- reset_loop_device(loopname);
- errno = err;
- return res;
- }
- uint64_t r[3] = {0xffffffffffffffff, 0xffffffffffffffff, 0xffffffffffffffff};
- int main(void)
- {
- syscall(__NR_mmap, /*addr=*/0x1ffff000ul, /*len=*/0x1000ul, /*prot=*/0ul,
- /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
- /*offset=*/0ul);
- syscall(__NR_mmap, /*addr=*/0x20000000ul, /*len=*/0x1000000ul,
- /*prot=PROT_WRITE|PROT_READ|PROT_EXEC*/ 7ul,
- /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
- /*offset=*/0ul);
- syscall(__NR_mmap, /*addr=*/0x21000000ul, /*len=*/0x1000ul, /*prot=*/0ul,
- /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
- /*offset=*/0ul);
- intptr_t res = 0;
- memcpy((void*)0x20000040, "ext4\000", 5);
- memcpy((void*)0x20000500, "./file1\000", 8);
- memcpy((void*)0x20000540, "errors=remount-ro", 17);
- *(uint8_t*)0x20000551 = 0x2c;
- memcpy((void*)0x20000552, "sysvgroups", 10);
- *(uint8_t*)0x2000055c = 0x2c;
- memcpy((void*)0x2000055d, "dioread_lock", 12);
- *(uint8_t*)0x20000569 = 0x2c;
- memcpy((void*)0x2000056a, "grpquota", 8);
- *(uint8_t*)0x20000572 = 0x2c;
- memcpy((void*)0x20000573, "noauto_da_alloc", 15);
- *(uint8_t*)0x20000582 = 0x2c;
- memcpy((void*)0x20000583, "resgid", 6);
- *(uint8_t*)0x20000589 = 0x3d;
- sprintf((char*)0x2000058a, "0x%016llx", (long long)0);
- *(uint8_t*)0x2000059c = 0x2c;
- memcpy((void*)0x2000059d, "barrier", 7);
- *(uint8_t*)0x200005a4 = 0x2c;
- memcpy((void*)0x200005a5, "auto_da_alloc", 13);
- *(uint8_t*)0x200005b2 = 0x2c;
- memcpy((void*)0x200005b3, "usrquota", 8);
- *(uint8_t*)0x200005bb = 0x2c;
- *(uint8_t*)0x200005bc = 0;
- memcpy(
- (void*)0x20001b00,
- "\x78\x9c\xec\xdd\xdf\x6b\x5b\xd7\x1d\x00\xf0\xef\xbd\xb6\xb2\xfc\x70\x66"
- "\x67\xdb\x43\x16\x58\x16\x96\x0c\x27\x6c\x91\xec\x78\x49\xcc\x1e\xb2\x0c"
- "\xc6\xf2\x14\xd8\x96\xbd\x67\x9e\x2d\x1b\x63\xd9\x32\x96\x9c\xc4\x26\x0c"
- "\x87\xfd\x01\x83\x31\xd6\x42\x9f\xfa\xd4\x97\x42\xff\x80\x42\xc9\x9f\x50"
- "\x0a\x81\xf6\xbd\xb4\xa5\xa5\xb4\x49\xfb\xd0\x87\xb6\x2a\x92\xae\xd2\xc4"
- "\x95\x62\x87\xc8\xbe\x60\x7f\x3e\x70\x7c\xcf\xb9\x57\xd2\xf7\x7b\x6c\x74"
- "\x75\xcf\xbd\xc7\xba\x01\xec\x5b\xa7\x22\xe2\x6a\x44\x0c\x44\xc4\xb9\x88"
- "\x18\xce\xd6\xa7\x59\xb9\xd6\x6c\x6c\xb4\x1f\xf7\xe8\xe1\xdd\xe9\x66\x49"
- "\xa2\xd1\xb8\xf1\x59\x12\x49\xb6\xae\xf3\x5a\x49\xb6\x3c\xd2\x7e\x4a\x1c"
- "\x8c\x88\xbf\x5d\x8b\xf8\x67\xf2\xc3\xb8\xb5\xb5\xf5\x85\xa9\x4a\xa5\xbc"
- "\x92\xb5\x4b\xf5\xc5\xe5\x52\x6d\x6d\xfd\xfc\xfc\xe2\xd4\x5c\x79\xae\xbc"
- "\x34\x31\x31\x7e\x69\xf2\xf2\xe4\xc5\xc9\xb1\xbe\xf4\x73\x24\x22\xae\xfc"
- "\xe9\xa3\xff\xff\xe7\xb5\x3f\x5f\x79\xeb\xb7\xb7\xdf\xbf\xf9\xc9\xd9\x7f"
- "\x35\xd3\x1a\xca\xb6\x3f\xd9\x8f\x7e\x6a\x77\xbd\xd0\xfa\x5d\x74\x0c\x46"
- "\xc4\xca\x4e\x04\xcb\xc1\x40\xb6\x2c\xe4\x9c\x07\x00\x00\xdb\xd3\x3c\xc6"
- "\xff\x49\x44\xfc\xaa\x75\xfc\x3f\x1c\x03\xad\xa3\x53\x00\x00\x00\x60\x2f"
- "\x69\xfc\x61\x28\xbe\x4e\x22\x1a\x00\x00\x00\xc0\x9e\x95\xb6\xe6\xc0\x26"
- "\x69\x31\x9b\x0b\x30\x14\x69\x5a\x2c\xb6\xe7\xf0\xfe\x2c\x0e\xa7\x95\x6a"
- "\xad\xfe\x9b\xd9\xea\xea\xd2\x4c\x7b\xae\xec\x48\x14\xd2\xd9\xf9\x4a\x79"
- "\x2c\x9b\x2b\x3c\x12\x85\xa4\xd9\x1e\xcf\xe6\xd8\x76\xda\x17\x36\xb5\x27"
- "\x22\xe2\x58\x44\xfc\x6f\xf8\x50\xab\x5d\x9c\xae\x56\x66\xf2\x3e\xf9\x01"
- "\x00\x00\x00\xfb\xc4\x91\x4d\xe3\xff\x2f\x87\xdb\xe3\x7f\x00\x00\x00\x60"
- "\x8f\x19\xc9\x3b\x01\x00\x00\x00\x60\xc7\x19\xff\x03\x00\x00\xc0\xde\x67"
- "\xfc\x0f\x00\x00\x00\x7b\xda\x5f\xae\x5f\x6f\x96\x46\xe7\xfe\xd7\x33\xb7"
- "\xd6\x56\x17\xaa\xb7\xce\xcf\x94\x6b\x0b\xc5\xc5\xd5\xe9\xe2\x74\x75\x65"
- "\xb9\x38\x57\xad\xce\xb5\xbe\xb3\x6f\x71\xab\xd7\xab\x54\xab\xcb\xbf\x8b"
- "\xa5\xd5\x3b\xa5\x7a\xb9\x56\x2f\xd5\xd6\xd6\x6f\x2e\x56\x57\x97\xea\x37"
- "\xe7\x9f\xba\x05\x36\x00\x00\x00\xb0\x8b\x8e\xfd\xf2\xfe\x7b\x49\x44\x6c"
- "\xfc\xfe\x50\xab\x34\x1d\xc8\x3b\x29\x60\x57\x24\xcf\xf3\xe0\x0f\x77\x2e"
- "\x0f\x60\xf7\x0d\xe4\x9d\x00\x90\x9b\xc1\xbc\x13\x00\x72\x53\xc8\x3b\x01"
- "\x20\x77\x5b\x9d\x07\xe8\x39\x79\xe7\xed\xfe\xe7\x02\x00\x00\xec\x8c\xd1"
- "\x9f\xf7\xbe\xfe\xef\xdc\x00\xec\x6d\x69\xde\x09\x00\x00\xbb\xce\xf5\x7f"
- "\xd8\xbf\x0a\x66\x00\xc2\xbe\xf7\xe3\x2d\xb6\xbf\xf8\xf5\xff\x46\xe3\xb9"
- "\x12\x02\x00\x00\xfa\x6e\xa8\x55\x92\xb4\x98\x5d\x0b\x1c\x8a\x34\x2d\x16"
- "\x23\x8e\xb6\x6e\x0b\x50\x48\x66\xe7\x2b\xe5\xb1\x6c\x7c\xf0\xee\x70\xe1"
- "\x47\xcd\xf6\x78\xeb\x99\xc9\xf3\xfd\xef\x30\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xec\x63\x8d\x46\x12\x0d"
- "\x00\x00\x00\x60\x4f\x8b\x48\x3f\x4e\x5a\xdf\xe6\x1f\x31\x3a\x7c\x66\x68"
- "\xf3\xf9\x81\x03\xc9\x57\xc3\xad\x65\x44\xdc\x7e\xe5\xc6\x4b\x77\xa6\xea"
- "\xf5\x95\xf1\xe6\xfa\xcf\x1f\xaf\xaf\xbf\x9c\xad\xbf\x90\xc7\x19\x0c\x00"
- "\x00\x00\x60\xb3\xce\x38\xbd\x33\x8e\x07\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x7e\x7a\xf4\xf0\xee\x74\xa7"
- "\xec\x66\xdc\x4f\xff\x18\x11\x23\xdd\xe2\x0f\xc6\xc1\xd6\xf2\x60\x14\x22"
- "\xe2\xf0\x17\x49\x0c\x3e\xf1\xbc\x24\x22\x06\xfa\x10\x7f\xe3\x5e\x44\x1c"
- "\xef\x16\x3f\x69\xa6\x15\x23\x59\x16\xdd\xe2\x1f\xca\x31\x7e\x1a\x11\x47"
- "\xfa\x10\x1f\xf6\xb3\xfb\xcd\xfd\xcf\xd5\x6e\xef\xbf\x34\x4e\xb5\x96\xdd"
- "\xdf\x7f\x83\x59\x79\x51\xbd\xf7\x7f\xe9\xe3\xfd\xdf\x40\x8f\xfd\xcf\xd1"
- "\x6d\xc6\x38\xf1\xe0\x8d\x52\xcf\xf8\xf7\x22\x4e\x0c\x76\xdf\xff\x74\xe2"
- "\x27\x3d\xe2\x9f\xde\x66\xfc\x7f\xfc\x7d\x7d\xbd\xd7\xb6\xc6\xab\x11\xa3"
- "\x5d\x3f\x7f\x92\xa7\x62\x95\xea\x8b\xcb\xa5\xda\xda\xfa\xf9\xf9\xc5\xa9"
- "\xb9\xf2\x5c\x79\x69\x62\x62\xfc\xd2\xe4\xe5\xc9\x8b\x93\x63\xa5\xd9\xf9"
- "\x4a\x39\xfb\xd9\x35\xc6\x7f\x7f\xf1\xe6\xb7\xcf\xea\xff\xe1\x1e\xf1\x47"
- "\xb6\xe8\xff\x99\x6d\xf6\xff\x9b\x07\x77\x1e\xfe\xb4\x5d\x2d\x74\x8b\x7f"
- "\xf6\x74\xf7\xcf\xdf\xe3\x3d\xe2\xa7\xd9\x67\xdf\xaf\xb3\x7a\x73\xfb\x68"
- "\xa7\xbe\xd1\xae\x3f\xe9\xe4\xeb\xef\x9c\x7c\x56\xff\x67\x7a\xf4\x7f\xab"
- "\xbf\xff\xd9\x6d\xf6\xff\xdc\x5f\xff\xfd\xc1\x36\x1f\x0a\x00\xec\x82\xda"
- "\xda\xfa\xc2\x54\xa5\x52\x5e\x51\x51\x51\x51\x79\x5c\xc9\x7b\xcf\x04\x00"
- "\x00\xf4\xdb\xf7\x07\xfd\x79\x67\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\xfb\xd7\x6e\x7c\x9d\xd8\xe6\x98\x1b\xf9\x74\x15"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
- "\x00\x00\x00\x00\xe0\x99\xbe\x0b\x00\x00\xff\xff\xf7\xa0\xd4\xed",
- 1204);
- syz_mount_image(/*fs=*/0x20000040, /*dir=*/0x20000500,
- /*flags=MS_REC|MS_NOATIME|0x100*/ 0x4500, /*opts=*/0x20000540,
- /*chdir=*/0x12, /*size=*/0x4b4, /*img=*/0x20001b00);
- memcpy((void*)0x200000c0, "./file1\000", 8);
- res = syscall(
- __NR_open, /*file=*/0x200000c0ul,
- /*flags=O_SYNC|O_NONBLOCK|O_NOCTTY|O_NOATIME|O_DIRECT|O_CREAT|0x2002*/
- 0x147942ul, /*mode=*/0ul);
- if (res != -1)
- r[0] = res;
- memcpy((void*)0x20000180, "./bus\000", 6);
- res = syscall(
- __NR_open, /*file=*/0x20000180ul,
- /*flags=O_TRUNC|O_SYNC|O_NOATIME|O_LARGEFILE|O_DIRECT|O_CREAT|0x3e*/
- 0x14d27eul, /*mode=*/0ul);
- if (res != -1)
- r[1] = res;
- *(uint64_t*)0x20008840 = 0;
- *(uint32_t*)0x20008848 = 0;
- *(uint64_t*)0x20008850 = 0;
- *(uint64_t*)0x20008858 = 0;
- *(uint64_t*)0x20008860 = 0;
- *(uint64_t*)0x20008868 = 0;
- *(uint32_t*)0x20008870 = 0x4000;
- *(uint32_t*)0x20008878 = 0;
- *(uint64_t*)0x20008880 = 0;
- *(uint32_t*)0x20008888 = 0;
- *(uint64_t*)0x20008890 = 0;
- *(uint64_t*)0x20008898 = 0;
- *(uint64_t*)0x200088a0 = 0;
- *(uint64_t*)0x200088a8 = 0;
- *(uint32_t*)0x200088b0 = 0x4000;
- *(uint32_t*)0x200088b8 = 0;
- *(uint64_t*)0x200088c0 = 0;
- *(uint32_t*)0x200088c8 = 0;
- *(uint64_t*)0x200088d0 = 0;
- *(uint64_t*)0x200088d8 = 0;
- *(uint64_t*)0x200088e0 = 0;
- *(uint64_t*)0x200088e8 = 0;
- *(uint32_t*)0x200088f0 = 0x20044014;
- *(uint32_t*)0x200088f8 = 0;
- *(uint64_t*)0x20008900 = 0;
- *(uint32_t*)0x20008908 = 0;
- *(uint64_t*)0x20008910 = 0;
- *(uint64_t*)0x20008918 = 0;
- *(uint64_t*)0x20008920 = 0;
- *(uint64_t*)0x20008928 = 0;
- *(uint32_t*)0x20008930 = 0x4000040;
- *(uint32_t*)0x20008938 = 0;
- *(uint64_t*)0x20008940 = 0;
- *(uint32_t*)0x20008948 = 0;
- *(uint64_t*)0x20008950 = 0;
- *(uint64_t*)0x20008958 = 0;
- *(uint64_t*)0x20008960 = 0;
- *(uint64_t*)0x20008968 = 0;
- *(uint32_t*)0x20008970 = 0;
- *(uint32_t*)0x20008978 = 0;
- *(uint64_t*)0x20008980 = 0;
- *(uint32_t*)0x20008988 = 0;
- *(uint64_t*)0x20008990 = 0;
- *(uint64_t*)0x20008998 = 0;
- *(uint64_t*)0x200089a0 = 0;
- *(uint64_t*)0x200089a8 = 0;
- *(uint32_t*)0x200089b0 = 0x24000840;
- *(uint32_t*)0x200089b8 = 0;
- *(uint64_t*)0x200089c0 = 0;
- *(uint32_t*)0x200089c8 = 0;
- *(uint64_t*)0x200089d0 = 0x20006bc0;
- *(uint64_t*)0x20006bc0 = 0;
- *(uint64_t*)0x20006bc8 = 0;
- *(uint64_t*)0x20006bd0 = 0x200059c0;
- memcpy(
- (void*)0x200059c0,
- "\x53\xbe\x82\x15\x2d\x24\x82\x12\x75\x6a\xbe\x1f\x2d\xe0\x79\x0f\x2c\xb4"
- "\x4a\x52\x38\x06\x29\xb3\xd4\xa8\x2e\x0f\x69\x4c\xbf\xea\x1c\x46\x63\x54"
- "\x19\x34\x45\x6b\x48\x47\x62\x51\x89\xa3\xd3\xab\x6a\x14\xd8\x7a\x45\x0c"
- "\xec\xd3\x8e\x4d\x03\xcf\xfa\x43\xc6\x0b\x2e\x91\xaf\x32\x8c\xf7\x78\x64"
- "\xb7\x28\x0a\x1f\x8b\x12\xc4\x89\x13\xa9\x59\x0b\x34\x61\x13\x86\x83\x71"
- "\x78\x11\x9b\x7a\x7c\x45\xb3\xe7\xa8\xbe\xa8\x49\x86\x32\x7d\x96\xd0\xb7"
- "\xe3\xb4\x52\x65\xbd\xd3\x2c\xe5\x80\x40\xb4\x1d\x28\xde\x7e\xfe\x82\xf7"
- "\xed\xa2\xe3\xe5\x5d\x8e\x6d\x7e\xa7\x29\x9a\xb7\x68\x27\x60\x12\x1c\xab"
- "\x4a\x43\x77\x13\xbf\x99\xb4\x27\xa4\x7f\xb3\x51\xd7\xe1\x80\xf9\x7b\x4c"
- "\x39\x0f\x30\xf7\x32\xae\xd1\x92\x30\x32\x71\x54\x64\x0f\xb4\x1f\xa8\xa2"
- "\xeb\x1f\x3e\x09\x86\x6c\x72\xdb\x64\x89\xbb\xe2\xb1\xe2\xc1\x8f\x26\xeb"
- "\x3e\x78\xb4\x32\xd1\x5c\xeb\x4b\x75\xe6\x26\xa3\x26\x8c\xc3\x4d\xda\x1d"
- "\x42\x8d\x25\x99\x77\x02\xb9\xae\x6a\xae\x17\x04\x66\x8d\xaa\xa5\x50\xb6"
- "\x1c\x14\x15\x7c\xed\xa4\xfa\x19\x89\x98\x1d\x50\xc8\xab\x32\xe6\x7f\x2e"
- "\x74\x5a\x05\x17\xc3\x0f\x29\xea\x20\xea\x07\x30\x22\xff\x89\x86\x6e\xc7"
- "\x79\x19\x04\x32\x9c\x10\x19\xf1\xb7\x2d\xb5\x80\x3f\xa3\xd2\xe1\x0a\x38"
- "\x77\xb0\xde\x4a\x47\xa1\x40\x4e\x02\xe2\xba\x14\x5a\xb1\x0e\xcf\x81\x27"
- "\xff\x8d\x6c\x78\xc5\x83\xbd\xb5\x15\xd8\x51\x2f\x50\xba\x65\xed\xc0\xf7"
- "\x0b\x52\xd5\xf6\x2c\x9c\xc1\x46\xb5\xb4\xa0\x67\x4c\x5e\x6e\x7c\x8e\x7a"
- "\x64\xb4\x0f\xbe\xf6\x15\x53\xaa\xaa\x31\x2f\x37\x5e\xe5\xce\x48\x9c\xb2"
- "\x3d\x38\x18\x7e\x37\x23\x6e\x53\xa4\x60\xc8\x83\x9a\x9e\x56\x07\x77\xc3"
- "\x57\x8b\x14\xe8\x1d\x11\x69\x07\x5c\xbb\xf9\x4a\xed\x05\x24\x6e\x00\xb3"
- "\xa2\x04\x4a\x10\xbc\x8b\xbe\x25\x07\x5f\x2a\x5d\x0d\xcf\x7c\x5c\xf8\xc8"
- "\x41\xa1\xdc\x09\x58\x15\x0c\xb5\x8c\x98\x9f\xc9\x4e\x37\xe0\xaa\x0a\x81"
- "\x44\x3e\xc2\xfa\xa7\x5d\x18\x75\x01\x2f\x9d\x25\x42\xc6\xe5\xcd\x06\x69"
- "\x45\xc8\x28\x46\x53\x12\xe1\x84\xd2\x9f\xf1\x06\xac\x41\x32\x5a\x2c\xa2"
- "\x31\xf4\x18\x9a\xf6\xc9\xae\x8d\xd6\x03\xe1\xa0\x30\x0a\xca\xbb\x0d\xfa"
- "\x21\x1d\x5a\xc2\xea\xe7\xce\xd8\xed\xf3\x1a\xce\x9e\x17\x57\xfc\x0a\x5c"
- "\x9e\xe9\xed\x2a\xde\x4d\x9f\x64\xca\x84\xbc\x5d\xc6\x91\x19\xfd\x3b\x70"
- "\x00\xfd\xfd\x11\x6d\x73\x5e\x42\xfe\x16\x34\xc1\x33\xc7\xf2\x97\x9c\xf8"
- "\xf8\x7e\x52\xb1\x0d\x75\xb0\x28\xc5\x60\xd7\x7a\xa1\xed\x90\x4e\xb9\x41"
- "\x45\x82\xb0\x7a\x07\x33\x2a\xb3\x27\x94\x5f\xdb\x76\x3f\xa6\x71\xce\x2f"
- "\x14\x6d\x75\xea\x81\x3b\x63\xff\x1a\x3e\x97\x3a\xa4\xd8\xd5\x69\xe3\x21"
- "\xe7\x2b\x60\xe7\x99\xa5\xb1\x88\xf3\xe9\xfb\x64\x8a\xf3\x25\xcf\x73\x9c"
- "\xa0\x10\x8d\xd9\x1f\xcd\xdd\x23\xf6\xcd\xba\xd7\xe6\x7a\x89\x97\xec\xf7"
- "\xfb\x70\x5b\x6c\x48\x81\xca\xf7\x0d\x8b\x9a\x08\xb4\xe1\xb8\xe0\x0a\x9e"
- "\x4f\xda\x14\xe1\x2e\xe7\x93\x87\x25\x41\x81\xa2\xc7\xe6\x1e\x7b\x52\x28"
- "\x3e\xfb\xf7\x68\x0f\x79\xa2\x6b\xbd\x4b\x1d\x7f\xc3\xe1\x86\x18\xee\x07"
- "\x6f\xbd\x52\x55\x4a\x35\x15\x8c\x77\x1f\x3b\x0f\x09\x17\xda\xe9\xb2\x5c"
- "\xef\xbe\x69\xed\xfd\x6a\x44\x2e\x8f\x96\x0b\xd1\xe6\x80\xd9\x95\x2c\xa2"
- "\xa0\x33\x4f\xc5\x08\xdd\x63\x7b\xf1\x60\x83\x55\x97\xdf\xa9\x90\x26\x90"
- "\xe9\x99\x20\xd8\x1e\xb3\x51\x5f\xf0\x0f\xa0\xf3\xaf\x2b\xe3\xa7\x1e\x8a"
- "\x55\xc1\x22\xc5\x9d\x0d\x13\xc2\xc8\x4e\xd1\x69\x3f\x54\xde\xcf\x0e\x89"
- "\xab\xdb\xee\xce\x1b\x5f\x7f\x42\x5c\x54\x83\x72\x26\xa7\x7c\x05\x9b\xa0"
- "\x6a\xae\x4c\x64\x86\xb8\xf4\x1e\x55\x1f\xd2\x25\x01\x73\x3a\xe8\xfa\xc3"
- "\xf3\x88\x44\x6d\x65\x78\x54\x34\x01\x73\x76\x9f\x7e\x19\x07\xc6\x86\x07"
- "\x51\x72\xf0\xaf\x30\xc7\x7e\x6d\xc1\xd5\x58\x78\x4b\x7b\xf0\x8c\xbb\x94"
- "\x15\xc9\x49\x9e\x05\x93\x3b\x49\xe6\x95\xe6\x99\x6c\x0b\x94\xa9\xef\x98"
- "\x78\x0c\x0b\x07\x16\x67\x17\xbc\xa5\x3b\x0e\x62\xb1\x74\x7d\x8f\x25\xc1"
- "\xe0\x8d\x8e\x57\x3e\x42\x59\x5f\x70\xaf\x05\x01\x05\x32\x87\xc5\xc5\xd0"
- "\x38\x2d\x46\xfe\x53\x15\x81\xa2\x32\xd9\xc7\x8f\xb2\x9a\x95\x21\x59\x7d"
- "\x63\xc7\x53\x65\xb2\x66\x11\x7e\xa1\xf8\x75\xe6\x38\x8c\xf4\x9d\xdc\x4b"
- "\x18\x14\x6e\xf3\xaf\x97\xd0\x5c\xd7\x10\xe7\x4c\xc5\x81\x34\xd3\x9f\x7c"
- "\x2d\x42\xb2\x1a\xef\x81\x8c\xa8\x1b\xe3\xd4\x13\xd2\x79\x48\x22\x96\x12"
- "\x0c\x21\xb0\x94\x1e\x31\x70\x97\x09\x9a\x36\x07\x5a\x63\x5d\xfb\x69\xf6"
- "\xa6\x95\xaa\xfc\xee\x49\x10\xf5\xe2\x88\xea\xf1\x14\x25\x59\xe1\xef\x65"
- "\x1b\xe5\xb6\xf1\xf9\x4b\x36\x2c\x82\xce\xbb\xe9\xd7\xe2\x94\x8b\x34\x3b"
- "\xbd\x2a\x3f\xe1\x5a\xc1\x8e\xeb\x44\xf3\x6d\xd3\xd0\x16\xa7\x02\x4e\x86"
- "\x2c\x26\xff\xac\x0b\x8c\xf3\x5e\x26\x64\x0f\x63\xbe\xc8\x3a\x4f\xee\xcf"
- "\x18\x7d\x24\x3d\x4e\x3d\x6b\x32\xfa\x27\x79\x82\xc2\x03\x19\x1a\x0d\x30"
- "\xb1\xa8\x51\xc9\x8b\x25\x0e\x96\x83\x1e\xf0\x0f\x6e\x97\xbc\xd8\xdb\xf2"
- "\xad\x55\xe0\x3f\x65\x0b\x7e\xcf\xde\xd5\x6a\xcc\x31\xf7\x61\x38\xa6\xce"
- "\xd9\x5b\xf8\xdf\x4d\x05\xfb\xcc\x25\x54\x47\x22\x06\xe6\x97\x6a\x1d\x02"
- "\x1d\x4e\xdb\x77\x23\x40\xc8\x49\x2f\x0a\x53\x42\x34\x06\xe1\x03\x25\x8b"
- "\x05\xd5\xea\xa5\xee\x65\xd2\xdf\x30\xe9\xae\x2a\xf1\x4a\x83\xb5\xad\x8e"
- "\xf8\xef\x83\x60\xc2\xa5\xda\xc9\x55\x28\x14\x01\x08\xdc\xfd\x28\x84\x17"
- "\x5c\xbc\x7d\x7d\x06\xea\x9f\x57\x3e\xe6\xe7\x85\x19\x5c\x12\x98\x74\x8e"
- "\x42\x8e\xd3\x0c\xfd\x6a\x57\x39\x8a\xf5\x2b\x4b\xad\x87\x5c\x53\x5a\x54"
- "\xa0\x7c\xa0\x24\x0f\x6d\xf1\xd5\xfb\x15\x40\x08\xdb\xd0\x84\x2d\xe6\x91"
- "\xa3\x60\x09\x1a\xac\x4b\x9c\xd3\x13\x28\x78\x14\x39\x85\xe1\x6e\x44\x8b"
- "\xe2\xfc\x7e\xcb\xd6\x2c\x9f\xb6\x2f\x2f\x71\x35\xb0\x28\xec\x0b\x8e\x69"
- "\x5a\x92\xd1\xd9\x31\xd3\x71\xbd\x2c\xbc\x44\x71\xd5\x2a\xa6\x29\x37\xdf"
- "\xc1\x49\xc8\x35\x4a\x7b\xf1\x63\xd9\x69\xd5\xf6\x50\x5d\x91\x3a\x03\xa4"
- "\x6c\x93\xb5\xbc\xbd\x0a\x7e\xf1\x0d\xcd\xf3\x52\x07\xaf\x96\x0d\x8e\x43"
- "\x2d\x52\x4b\x09\xde\xa7\x92\xe5\x1d\x14\xc3\x21\xb8\x63\x1c\xe3\xdc\x38"
- "\xce\x5f\x8f\xa1\xb7\xf1\xbc\x3a\x51\xf1\x3e\xa2\xa8\x45\xd1\x90\x5d\x59"
- "\xe5\xef\xb5\x75\xa4\xb2\xa8\xa5\x5f\x5c\x9e\xec\x5f\x15\xa7\x20\xc6\x7d"
- "\x98\x26\x10\x36\xaf\x7c\x52\x74\xad\x78\xd1\xc0\xf4\xb2\xd1\x52\x4a\x1d"
- "\x23\x11\x20\x73\x6d\xad\x9c\x25\xb3\x03\x31\x29\xcd\x46\xca\x78\x74\x47"
- "\x7c\x79\xbf\x07\x49\x60\x44\x6c\x7f\xda\xa5\xb7\xf1\xff\x9c\xe2\xfa\xb4"
- "\x7d\x2b\xfc\xb9\xc4\xdc\xd8\x0d\x21\xca\x55\x10\xbc\x29\xca\x51\x7a\x02"
- "\xbc\xbf\x61\x43\x51\x63\x17\x73\xf6\x34\x00\x2e\x7f\x60\x92\x25\x63\x28"
- "\x00\x8c\x4a\xe8\xc9\xe1\x6e\xaf\xde\xd5\xc9\xb0\xb7\x0b\xd8\x3b\xdf\x9b"
- "\x95\xb4\xb3\x11\x2c\xa5\x25\x14\x9f\x78\x9a\xc0\xe5\x78\x36\x21\xce\xd8"
- "\x42\x67\x34\xd6\x39\xd0\xaa\x5f\xe5\x32\xf4\x6c\xa6\xdb\xdb\x8d\xea\x94"
- "\xd4\x55\x0a\x84\xf5\xf3\xb2\x0f\xb8\x94\x53\x0c\x7a\x89\x4a\x1f\x1c\x9b"
- "\xa2\x5e\xc6\x32\xa3\xb8\x25\xf7\x54\xa5\x90\xcc\x38\x72\xb3\x87\x44\x95"
- "\xab\xc3\x88\xdd\x2d\x9c\x49\x1c\xf4\x3a\x85\x6f\x7b\xe2\x18\x01\xf1\xaf"
- "\x6c\x74\x3c\x76\x2e\xeb\xc3\x17\x6d\xdb\xec\x76\xc3\x99\xe7\xb2\xac\x85"
- "\x56\x9f\x39\x10\xda\x36\xfa\xf2\xcd\xec\xc7\x0d\x7a\xde\x06\x6e\x54\x15"
- "\x2e\x12\x64\x50\x2d\x4a\x8b\x8f\xd4\x51\xc5\x85\x2d\xfb\xcc\xe8\x27\x2b"
- "\x52\xeb\x45\x2a\xe3\x22\x48\x74\xc8\x50\xa7\xae\xe2\xcb\x13\x5e\xc2\xb2"
- "\xac\xba\xdb\xbe\x8a\x20\x99\x6e\x44\x8d\xc4\x9b\x48\xea\x3e\x19\xef\x1f"
- "\x90\xb6\x50\x1d\x39\x99\xf5\x2f\xb0\xb6\x40\xc0\x33\xe3\xd1\x1e\x0f\x55"
- "\x9e\x82\xdd\x00\x98\xaf\x16\xb8\xf7\x01\x45\x5b\xcc\x53\x0c\xd1\x3e\x02"
- "\xed\x78\x83\x5b\x01\x66\x85\xf6\xd4\x39\x46\xc7\x99\x2f\x6b\xb4\x09\x18"
- "\x56\x76\xce\xe1\x14\xa9\x66\x57\x49\xae\xdd\x13\x36\x1e\x7c\x5a\xd7\xb5"
- "\x65\x2c\x72\x2f\x96\x9d\x2a\xfe\xe8\x50\xb2\x03\x61\xce\x86\xa1\xb0\xc7"
- "\xa1\xb1\x7a\xc6\x9e\x62\x3c\x1e\xf0\xa8\xca\x4c\x07\x93\xb0\x69\xd8\xf8"
- "\xc7\xa8\xa1\x98\x90\x48\xd7\x42\xac\xa7\x88\x6a\x49\x51\x29\x24\x59\xe2"
- "\x78\x8a\xeb\x13\x3c\xf2\x0a\x0f\x4f\xc4\xa8\x2d\x22\x96\x9a\x4d\x95\x48"
- "\x89\x74\xd5\x2d\x54\xf1\x7e\x50\x40\x82\x4a\xaf\xfa\x31\x49\xd8\x96\xc2"
- "\xf5\x36\x6b\xa7\xd9\xc8\xe5\x08\x6d\xce\x49\xdb\xcc\x29\xcf\x85\xfd\xc4"
- "\x4d\x8d\x82\x7f\x9d\xb4\x8a\x67\x71\xa5\x86\xb2\x67\xcf\x73\x42\x65\xbe"
- "\xde\x4c\x3c\x86\xce\xaa\x46\x8b\x5f\xe7\xfd\x5c\x55\x22\x9f\x4b\xb8\x37"
- "\x41\xc5\xd3\x5b\xce\xa8\xc1\x02\x75\x31\xb8\x0b\x31\x86\xcf\xf5\x31\x17"
- "\x63\x18\x8e\x2b\x55\x1b\x21\x33\x7f\xda\xae\xcc\xf4\x14\x41\x97\x88\xd1"
- "\x69\x40\xa4\xb9\x87\xcf\x10\x92\xd0\x30\x7b\xd3\xd0\xf2\xed\x93\xf3\x1c"
- "\xc1\x81\x04\xad\xca\x13\x3e\xf1\xfc\x12\x12\x8d\xee\x0e\x20\xc2\x85\x89"
- "\x10\xcc\x90\xef\x74\x1b\xa2\x41\xf5\xe7\x49\x54\x5b\x2b\x4a\x82\xc9\xb0"
- "\x83\xe7\xa8\x4c\xd5\x22\x48\x61\x7b\x2d\x16\x9b\xb7\xde\xed\xa9\x65\x1b"
- "\x31\x5b\x8d\x03\xee\xa0\xa2\x09\x5b\x37\xaa\x94\xcc\x00\x25\x57\x91\xe9"
- "\x07\x73\xda\x18\x2f\xa4\x58\x63\xe4\xf4\x76\x5d\x97\x2f\x7d\x21\xd5\xd0"
- "\x01\xf4\x33\x20\x8b\x1f\x7d\x8f\x62\xd9\x00\xea\x5c\x47\x78\x03\x4c\x75"
- "\x46\xb0\x06\xe8\x73\xf7\xa8\x4c\x72\xa2\x94\x27\xaa\x44\x2a\xab\x95\x7a"
- "\x87\x71\x55\x6e\xbe\xec\x41\xbb\x52\x9c\x34\xb3\xed\xa8\xb9\x6d\x7f\x64"
- "\x2f\x04\xf7\x68\x4a\x9e\xde\x0b\xfc\x57\x8b\x20\x1d\xe0\x64\xae\x43\x76"
- "\x7e\xbb\xd7\x94\xae\x06\x68\xbf\x40\x1c\x29\x3c\xa6\x8c\x42\x00\xff\x09"
- "\x56\xa8\x24\x33\xc0\x77\xec\x44\x90\x66\xf5\x5c\x3a\x5b\x07\x71\x54\x68"
- "\x35\x17\xcd\x97\xe0\x90\x92\x48\x34\x90\xaa\x7b\x82\xa0\xba\x1b\x55\x42"
- "\x03\xdd\x2e\x96\x6b\x63\x27\x07\x1a\x75\x8a\xba\xc7\x64\xcf\xb9\x63\xfc"
- "\x92\x7a\x33\x58\x53\x14\x9a\xd1\xfd\x39\x35\x71\x8a\x1a\x41\x31\x8b\x6f"
- "\x83\x4c\xe8\xd7\x1c\x91\x30\x4b\x68\xf8\x44\x7c\xb5\xd2\x72\x09\x03\xc8"
- "\xc9\xee\x0f\x8e\x6d\xcc\xba\x44\xf2\x45\x5f\x51\x28\x41\x9f\x53\x5e\x4d"
- "\x0d\x10\x18\xe4\x1e\x55\x74\xa2\x17\x6f\x29\x1c\x13\x9b\x40\xa0\x55\x2d"
- "\xa5\x12\x25\x4c\x37\x50\xfa\xb7\xed\x5b\xc0\x3d\xe0\xc3\x55\x93\x9d\x78"
- "\xca\xfe\x89\x75\xe8\x52\x9f\x36\x8a\xe0\x22\x4b\x56\x3a\x4a\x1d\x1e\x5f"
- "\xf0\x87\x19\xb8\x29\x1a\xd9\x63\x87\x2a\x82\xf4\x4a\x14\xe0\x74\x2f\x16"
- "\xd1\xec\x88\xf9\xf6\x79\x7b\x58\x73\x89\x61\xa0\xdb\xed\x63\xe0\xa3\x7a"
- "\x69\xd2\x6b\x1a\xea\x4c\xb0\x0c\x26\x14\x01\x7b\xbb\xea\x9d\x79\x25\x3f"
- "\x54\xfb\xd2\xd1\x1f\x32\x82\xf5\x0a\xbd\x15\x29\x51\x99\xdf\x60\xd7\x4f"
- "\x0a\xa9\x62\x18\x54\xaa\x6b\xab\x6d\x64\xad\xad\x1e\x2c\xd2\x97\xa6\x02"
- "\x10\x7f\x94\x6e\x63\xa2\xe1\xb5\x99\x18\x28\x19\x14\xf0\xe4\x48\x25\xd2"
- "\x49\xd7\x4b\x02\x50\xac\x9d\x09\xc9\x15\x68\xe9\x48\x6d\xe7\x26\x6e\x44"
- "\x63\x5e\x77\x85\xdb\x76\xc4\x02\x27\x2d\x96\xca\xd8\x34\xf0\x58\xcd\x0f"
- "\x0d\xd3\x93\x44\x60\x79\x46\x65\x94\x71\xdf\xb1\x37\x80\xf0\x32\x0b\xa8"
- "\x81\x49\x04\xff\x48\x7d\x33\x1f\x3d\x6a\x56\xfb\xfe\x82\xff\x0d\x9a\xdf"
- "\xe5\x16\xd7\xf5\xf2\x6f\x89\x83\x61\xa3\x8e\xce\xb6\x23\xc8\xf2\x58\x40"
- "\xb4\x49\x53\x28\xd5\x0d\xea\xc3\xee\x5a\x8f\xaa\x7d\xa1\x16\xfb\x9c\x6e"
- "\xfc\x20\x50\x83\x41\xd1\xf0\x4f\xdc\x44\x97\x48\x86\x8d\x35\xa2\xc6\x95"
- "\xbc\x77\x61\x24\xec\xd4\x19\x2c\x64\x3b\x4f\x76\x2c\x29\x7e\x85\x7c\xdd"
- "\x62\xad\x0b\x9a\x2e\x05\x49\xb8\x44\x8c\xca\x7e\xfd\xe3\xcc\x5b\xe7\x15"
- "\x30\x5d\x51\xed\x99\x2c\x45\x18\x28\xf9\x25\x0c\xb3\x93\xc0\xda\x03\x55"
- "\x8f\xd2\x57\xc6\xd4\xd1\x4e\x51\xa4\xc5\xdb\x3c\x39\xe4\x88\x84\x39\x38"
- "\x02\xeb\xdb\xe4\xff\x82\xb6\xa1\x2b\x9d\xb6\x8b\x30\x32\xd6\x48\xee\x8b"
- "\x19\xc8\x48\xb0\x33\x7c\x66\xec\x33\xa8\x4c\x9c\xa7\x1d\x9c\x2b\xb2\x0f"
- "\x04\x2f\xb3\xee\x9e\xd9\x75\xec\xd9\xe9\xcc\x43\x34\xaf\xa2\x52\x4d\x5d"
- "\xb7\x23\x92\x72\x58\x94\x59\xc0\xe9\x5a\xb8\xe6\x8e\x6f\xc9\x1a\xd9\x58"
- "\x3f\xcd\x1f\xbb\x7a\xe0\x2a\xfa\xf1\xc8\xb5\x5e\x90\xf0\x5b\x9e\xdc\xa5"
- "\x13\xb0\xff\xb5\xfb\xac\x38\xc8\x1e\x7d\x6f\xa6\x91\xc6\xcf\xcf\x9c\x3b"
- "\xf6\xac\x1b\x0a\x2a\x1e\x64\x7d\x59\xaa\x13\xd8\xe7\x5e\x6c\x0f\x15\x9f"
- "\x39\x73\x67\xc2\x65\x2e\x3b\xee\x0a\x76\x20\x3c\x73\xac\xa3\x22\xb6\xbf"
- "\x84\x86\x24\x76\x7c\xcc\x52\x2c\xcb\x91\xf5\xb6\x0c\xc3\xe5\x84\xba\xa8"
- "\x82\xea\x89\xe8\xda\xfe\xa4\x58\xae\xa5\xdf\x43\x9d\x93\x88\xac\x38\x81"
- "\x5f\xc3\x75\x17\x95\xdb\x3e\x08\x35\xc0\x08\x40\x40\x2a\xc3\xba\xe5\x89"
- "\xb6\x61\x66\xba\xb0\x96\x96\x76\xee\x5a\x5d\xf0\xab\xd3\xc2\x15\x00\x9a"
- "\x16\xad\x29\xcb\xa6\x50\x16\xe4\xd7\xbb\xc2\x47\x55\x93\x6c\x0d\x72\x3a"
- "\x27\xa2\x5a\x23\xa3\xb0\x3e\xc1\x6d\xe5\x6b\x87\x47\x33\x1c\xcb\x78\xde"
- "\x30\x78\xf7\xa7\x41\x81\xe3\xe7\x6d\x8e\xf1\xfa\xf3\x80\x4e\x5f\x30\xbf"
- "\xd4\x34\xf0\xf0\x47\x9b\x22\xe0\x45\x0b\x35\xc8\x16\x80\x8a\xba\xa8\xbf"
- "\x9b\x8d\xc2\xa4\xa8\x6b\xfb\x89\xb7\xb1\x09\x52\x08\x3c\x23\xc1\xd5\xc5"
- "\x46\x8c\x72\x8c\x59\x36\xe2\xe9\xed\x56\x60\x09\x00\x9e\x2f\xbd\xa8\x98"
- "\xcb\xc8\xb6\x2a\xac\xf3\x13\x34\x82\xbc\xa0\x8d\xd4\x22\xb9\xfa\x8a\xb4"
- "\x67\x89\x64\x65\xe2\x21\x37\x35\xca\xc7\x73\x17\x07\x09\x59\x63\xc1\x7b"
- "\xd1\x5f\x9a\x1e\x6e\x14\xde\x4c\x46\x18\x28\xf5\xcd\x7a\x50\xf4\xdf\x23"
- "\x79\x08\xe6\x64\x10\xc8\xb7\x49\x4b\x36\x15\xff\xac\x24\x57\x7c\xcd\xcf"
- "\xb1\xf6\x54\xd3\x8c\x90\xdb\x7a\x1f\x20\x37\x2f\x49\x6a\x14\xbf\xaf\xf4"
- "\xce\x53\xc9\x4d\x9b\x8c\x60\xc5\x39\x39\x53\x3a\xd5\x59\x14\x83\x49\xc1"
- "\xfa\x7f\xab\xa9\x18\x20\xb3\xb2\x32\x95\xb0\x7b\xb5\xed\x17\x30\xd8\xe8"
- "\x25\x7e\xe7\xf4\x35\x55\xc8\xcd\x5b\x2e\x3b\x40\x68\x8a\x8a\x45\x29\x0b"
- "\x38\x19\xa8\xf3\xcb\xbd\xb5\xae\x19\x95\x83\x89\x3a\x43\x06\x82\xc8\xb4"
- "\x85\x8a\x1e\x78\x50\xb7\x99\x5d\x73\xdf\xd6\x2f\xfc\x76\x91\xa9\xbc\x42"
- "\x1a\x5d\xfe\x16\xfd\xea\xcd\x20\x52\x55\xbd\x09\x53\x67\xa7\x97\xb7\x5e"
- "\x9c\x69\x2d\x0d\xbc\x8e\xef\xc7\x0e\x19\x89\x33\x24\xad\x71\x54\xa4\x3b"
- "\x33\x49\xeb\x39\x6f\x40\x66\x73\xc5\xa0\x65\xc2\xe9\x97\x76\x22\x1a\xb9"
- "\xc0\xf1\x78\xe0\x1a\x8c\x22\xa6\x4f\xc7\xe5\x9e\xc6\x3a\xb0\x59\x2a\xbc"
- "\xed\x1b\xdd\x6e\x85\x98\x99\x0d\xc9\xa3\xc4\xf1\xab\xf0\xdb\x57\x64\x03"
- "\x8e\xf7\xe9\x70\x8e\x91\x67\xe6\xd7\x9b\xb8\xbb\xf5\xa2\x78\xb0\x06\xb8"
- "\x7d\x40\x56\x92\x27\x1a\xf1\x13\x53\x0e\x7e\xb9\x53\x8d\xdf\x50\xb9\x8d"
- "\xdf\x27\x67\x05\x07\xe6\xba\x15\x31\x7b\x78\xf8\x28\x2d\x25\x80\x69\xee"
- "\xcd\x55\x0f\x53\xf1\xb3\xa7\x45\x77\x59\x9b\x99\x94\xcd\x23\x3e\x97\xb0"
- "\x10\x26\x90\x9b\x51\x0d\xb9\x1b\x00\xa5\x95\xf8\x79\x76\xfd\x69\x26\x8e"
- "\x9f\xd9\xee\xc0\x1c\x7e\xab\x2b\x7c\xbb\x63\x15\xde\x66\xea\xd4\x0e\x0f"
- "\x30\x82\x89\x18\xfc\x1b\x4f\xaa\xe7\x82\x82\xcf\xd0\xa7\x27\xd0\xf7\x42"
- "\x4f\x3d\x65\x7f\x29\xfa\xcc\x1d\xb3\x34\xdc\x70\xcd\x75\xb4\xd0\x4d\xf0"
- "\x74\x65\xfa\x42\x8f\xc9\x30\x3f\x69\x59\xd0\xcf\x54\x08\x0f\x5e\xb9\x83"
- "\x4e\x1a\xe1\x50\x1b\x13\x2e\x5c\x7b\x7f\xe1\x2e\x88\x58\x1a\x86\x5f\x6b"
- "\xa7\x61\x9b\xc8\x02\xde\x5a\x9a\x7e\x55\xcd\x8b\xd6\x1c\xcd\xc8\x7e\x3c"
- "\x73\xf5\x67\xd2\x29\x36\x4e\xfd\xb9\xb2\x81\xf4\xa2\x40\x95\x8b\x67\x21"
- "\xeb\x3b\xb1\x22\xa4\x49\x29\x1b\x13\x28\x89\xc6\x3a\x7c\x6f\x13\x63\x1c"
- "\x72\x31\x9d\x97\xad\x3a\x27\x70\x20\x8e\xb3\xc1\x02\x0c\x41\x20\x5d\x53"
- "\x0a\x69\x7e\x5b\x00\x49\xf5\xcd\xcc\xb6\xd8\x42\x82\xf4\x69\xa2\x97\x1c"
- "\xd8\x48\xeb\xfb\x85\xdb\x6a\x81\x11\xb6\x45\x08\x5b\x8d\xef\xe5\x92\xbf"
- "\x4c\x29\x99\xc2\x4c\x8b\x5a\x3e\x9b\x7b\xcd\xfc\xcd\x19\x47\x16\x31\x87"
- "\xbb\xb5\x16\x97\xd9\x71\x57\x10\x23\xdd\xd7\x07\x41\xbe\x85\x9a\xba\x7f"
- "\xb6\x4c\xd8\xbb\xab\x70\x5c\xf2\x51\xd7\x02\x20\xf2\x67\x61\x4b\xf8\xcf"
- "\x32\xab\xe4\x92\xe3\x30\x29\x26\x2f\x72\x15\x8a\x59\xfc\x81\xdd\xdc\xe0"
- "\x8a\x5d\xc4\x6a\xa0\x62\xd7\x23\x88\x05\x8e\x3e\x36\x35\x75\x79\x85\x58"
- "\xe9\xed\x5c\x76\x9b\xb2\x0e\xca\x95\x9f\x9e\xc6\xa6\xfc\xd7\xb7\x0c\x38"
- "\x99\xaf\x8b\x9a\x74\x7b\x7e\xd5\x1f\x24\x99\x80\x04\x8e\x67\x22\x48\x40"
- "\x61\x29\x6b\x93\x86\x31\x72\xd9\x33\x45\xfe\x19\x4d\x9f\x23\x1d\x56\xab"
- "\xeb\x19\x49\x88\x53\x34\x8a\xf1\x6c\x43\xe0\xc4\x40\xdc\xad\x33\x02\x33"
- "\xa7\x13\x1d\xda\xf6\x4c\x44\xb8\xcb\x71\xca\x56\x3d\xf3\x09\xbd\x10\x02"
- "\x1d\x46\x09\xce\x24\xa3\x12\x92\xc0\xd8\x43\xe3\xbe\xb9\x0d\x4b\x33\x60"
- "\x48\x1d\xd0\x05\xd0\x35\xab\xdf\x8c\x30\x9d\xdc\xdc\x0f\x50\x58\xf4\xc0"
- "\xca\xfd\x79\xe6\x10\x74\xc7\xaa\xb1\xb9\x19\xdd\xd1\xce\x1e\x00\x23\x3e"
- "\x0a\x2b\x74\x5c\xbf\x3c\x64\x54\xb1\x9d\x64\x83\x14\x75\xab\xb0\x02\x26"
- "\x31\x87\xe3\xe7\x61\x75\x2f\xaa\x89\xdb\xd6\xb6\xf1\x79\x52\x47\xc6\x5f"
- "\x26\xf8\x33\x11\xc9\xfe\x85\x35\x23\xd0\x60\xb5\x34\x8e\xee\x45\xf9\x61"
- "\xa2\x53\x2e\x0a\x7d\xfc\x35\x9f\xac\x07\x69\x4e\x9a\xc4\x22\x1f\x2d\x0b"
- "\x33\x53\x8c\x80\xef\x9c\xac\x56\x60\x37\x49\xb6\xdb\x91\x17\xdb\xd7\xf0"
- "\xdc\x5f\xb6\x09\x47\x9d\x4e\xd9\xd2\xa1\xd6\x36\x2b\x92\xcb\xaf\x8e\xa9"
- "\xf8\xcd\xf3\xde\x6b\x42\x23\xf4\xef\xb6\x74\x42\x92\x6e\x66\x9d\x3a\x7d"
- "\x60\x40\x6e\x1b\x69\xd4\x6f\xc3\xe0\x34\x4b\xff\x8e\x6c\x1b\xb6\x4f\xc9"
- "\x6a\xb4\x7d\x11\x08\x26\x33\x08\x48\xa1\x14\xb6\xd4\xa9\xa7\x94\x2a\xb8"
- "\x30\x02\x5c\x62\xce\x00\x8c\xff\xa8\x6f\x42\x59\xd3\x9e\xf2\x3b\x5f\x40"
- "\x9b\x01\xd7\x67\xd4\xad\x9e\x32\x9b\x75\xc5\x7b\x53\x10\x46\xca\xf4\xaa"
- "\x4e\x51\xdd\x8e\x95\xa0\xa9\xc6\xf3\x6c\x88\xc2\xb3\x19\x93\xa3\x72\x32"
- "\xb8\xdd\x20\xd1\x7b\xe6\x3f\xf2\x18\xc7\x63\x0e\xc9\xb7\x48\xb9\xfc\x9d"
- "\x14\x64\x9f\xb2\x76\xa1\xd5\x24\x3e\xbb\x3e\x45\xb3\xec\xf6\xbd\x5f\x6c"
- "\x6c\x23\x1c\x46\x7c\x5b\x14\x99\xcd\xe2\x31\x10\x24\xc0\x3e\x6c\x96\x21"
- "\xdf\x7d\xd8\x88\x80\x42\xe8\x95\x58\x32\x1c\x2f\xd9\xd8\x79\x7c\x47\xd4"
- "\xe6\x50\x24\xea\x39\x65\xdb\x03\xb5\xc5\x35\xf1\xfd\xc2\xf1\xa3\x9b\xf7"
- "\x90\xf0\x7b\x39\x21\xbd\xd7\x04\x7a\xf5\x49\x86\xed\xd2\xe7\xd2\x25\x9c"
- "\x80\x21\xd1\xc3\xe2\xe1\xcb\x7f\x08\x76\xc0\x09\x5b\x73\xb8\x19\x20\x23"
- "\x68\x23\xd8\xff\x09\x65\xc2\x72\x91\x15\xf9\xf8\x54\x22\xfe\xc6\x8d\x9d"
- "\xb7\x42\x72\xee\x15\xfc\x11\xa2\x2a\x3e\xbf\x65\x61\x23\x60\xc4\x55\x17"
- "\x3b\xe9\xe7\x94\x48\xc1\xda\x38\x5c\x6b",
- 4096);
- *(uint64_t*)0x20006bd8 = 0x1000;
- *(uint64_t*)0x20006be0 = 0;
- *(uint64_t*)0x20006be8 = 0;
- *(uint64_t*)0x20006bf0 = 0;
- *(uint64_t*)0x20006bf8 = 0;
- *(uint64_t*)0x20006c00 = 0;
- *(uint64_t*)0x20006c08 = 0;
- *(uint64_t*)0x20006c10 = 0;
- *(uint64_t*)0x20006c18 = 0;
- *(uint64_t*)0x200089d8 = 6;
- *(uint64_t*)0x200089e0 = 0;
- *(uint64_t*)0x200089e8 = 0;
- *(uint32_t*)0x200089f0 = 0x814;
- *(uint32_t*)0x200089f8 = 0;
- *(uint64_t*)0x20008a00 = 0;
- *(uint32_t*)0x20008a08 = 0;
- *(uint64_t*)0x20008a10 = 0;
- *(uint64_t*)0x20008a18 = 0;
- *(uint64_t*)0x20008a20 = 0;
- *(uint64_t*)0x20008a28 = 0;
- *(uint32_t*)0x20008a30 = 0x20008840;
- *(uint32_t*)0x20008a38 = 0;
- syscall(__NR_sendmmsg, /*fd=*/r[1], /*mmsg=*/0x20008840ul, /*vlen=*/8ul,
- /*f=*/0ul);
- memcpy((void*)0x20000380, "/dev/loop", 9);
- *(uint8_t*)0x20000389 = 0x30;
- *(uint8_t*)0x2000038a = 0;
- memcpy((void*)0x20000140, "./bus\000", 6);
- syscall(__NR_mount, /*src=*/0x20000380ul, /*dst=*/0x20000140ul, /*type=*/0ul,
- /*flags=MS_BIND*/ 0x1000ul, /*data=*/0ul);
- memcpy((void*)0x20000400, "./bus\000", 6);
- res = syscall(__NR_open, /*file=*/0x20000400ul,
- /*flags=O_SYNC|O_NOCTTY|O_NOATIME|O_RDWR|0x3c*/ 0x14113eul,
- /*mode=*/0ul);
- if (res != -1)
- r[2] = res;
- syscall(__NR_sendfile, /*fdout=*/r[0], /*fdin=*/r[2], /*off=*/0ul,
- /*count=*/0x8000005cul);
- syscall(__NR_write, /*fd=*/r[2], /*data=*/0x20000100ul, /*len=*/0x208e24bul);
- *(uint16_t*)0x20000080 = 0;
- *(uint16_t*)0x20000082 = 0;
- *(uint64_t*)0x20000088 = 0;
- *(uint64_t*)0x20000090 = 0x1ff7fdfd000;
- *(uint32_t*)0x20000098 = 0;
- *(uint32_t*)0x2000009c = 0x48000000;
- memset((void*)0x200000a0, 0, 16);
- syscall(__NR_ioctl, /*fd=*/r[0], /*cmd=*/0x40305829, /*arg=*/0x20000080ul);
- return 0;
- }
Advertisement
Add Comment
Please, Sign In to add comment