zzqq0103

Untitled

Mar 14th, 2024
163
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
C 15.85 KB | None | 0 0
  1. #define _GNU_SOURCE
  2.  
  3. #include <dirent.h>
  4. #include <endian.h>
  5. #include <errno.h>
  6. #include <fcntl.h>
  7. #include <sched.h>
  8. #include <signal.h>
  9. #include <stdarg.h>
  10. #include <stdbool.h>
  11. #include <stdint.h>
  12. #include <stdio.h>
  13. #include <stdlib.h>
  14. #include <string.h>
  15. #include <sys/ioctl.h>
  16. #include <sys/mount.h>
  17. #include <sys/prctl.h>
  18. #include <sys/resource.h>
  19. #include <sys/stat.h>
  20. #include <sys/syscall.h>
  21. #include <sys/time.h>
  22. #include <sys/types.h>
  23. #include <sys/wait.h>
  24. #include <time.h>
  25. #include <unistd.h>
  26.  
  27. #include <linux/capability.h>
  28.  
  29. static unsigned long long procid;
  30.  
  31. static void sleep_ms(uint64_t ms)
  32. {
  33.   usleep(ms * 1000);
  34. }
  35.  
  36. static uint64_t current_time_ms(void)
  37. {
  38.   struct timespec ts;
  39.   if (clock_gettime(CLOCK_MONOTONIC, &ts))
  40.     exit(1);
  41.   return (uint64_t)ts.tv_sec * 1000 + (uint64_t)ts.tv_nsec / 1000000;
  42. }
  43.  
  44. static void use_temporary_dir(void)
  45. {
  46.   char tmpdir_template[] = "./syzkaller.XXXXXX";
  47.   char* tmpdir = mkdtemp(tmpdir_template);
  48.   if (!tmpdir)
  49.     exit(1);
  50.   if (chmod(tmpdir, 0777))
  51.     exit(1);
  52.   if (chdir(tmpdir))
  53.     exit(1);
  54. }
  55.  
  56. #define BITMASK(bf_off, bf_len) (((1ull << (bf_len)) - 1) << (bf_off))
  57. #define STORE_BY_BITMASK(type, htobe, addr, val, bf_off, bf_len)               \
  58.   *(type*)(addr) =                                                             \
  59.       htobe((htobe(*(type*)(addr)) & ~BITMASK((bf_off), (bf_len))) |           \
  60.             (((type)(val) << (bf_off)) & BITMASK((bf_off), (bf_len))))
  61.  
  62. static bool write_file(const char* file, const char* what, ...)
  63. {
  64.   char buf[1024];
  65.   va_list args;
  66.   va_start(args, what);
  67.   vsnprintf(buf, sizeof(buf), what, args);
  68.   va_end(args);
  69.   buf[sizeof(buf) - 1] = 0;
  70.   int len = strlen(buf);
  71.   int fd = open(file, O_WRONLY | O_CLOEXEC);
  72.   if (fd == -1)
  73.     return false;
  74.   if (write(fd, buf, len) != len) {
  75.     int err = errno;
  76.     close(fd);
  77.     errno = err;
  78.     return false;
  79.   }
  80.   close(fd);
  81.   return true;
  82. }
  83.  
  84. #define MAX_FDS 30
  85.  
  86. static void mount_cgroups(const char* dir, const char** controllers, int count)
  87. {
  88.   if (mkdir(dir, 0777)) {
  89.     return;
  90.   }
  91.   char enabled[128] = {0};
  92.   int i = 0;
  93.   for (; i < count; i++) {
  94.     if (mount("none", dir, "cgroup", 0, controllers[i])) {
  95.       continue;
  96.     }
  97.     umount(dir);
  98.     strcat(enabled, ",");
  99.     strcat(enabled, controllers[i]);
  100.   }
  101.   if (enabled[0] == 0) {
  102.     if (rmdir(dir) && errno != EBUSY)
  103.       exit(1);
  104.     return;
  105.   }
  106.   if (mount("none", dir, "cgroup", 0, enabled + 1)) {
  107.     if (rmdir(dir) && errno != EBUSY)
  108.       exit(1);
  109.   }
  110.   if (chmod(dir, 0777)) {
  111.   }
  112. }
  113.  
  114. static void mount_cgroups2(const char** controllers, int count)
  115. {
  116.   if (mkdir("/syzcgroup/unified", 0777)) {
  117.     return;
  118.   }
  119.   if (mount("none", "/syzcgroup/unified", "cgroup2", 0, NULL)) {
  120.     if (rmdir("/syzcgroup/unified") && errno != EBUSY)
  121.       exit(1);
  122.     return;
  123.   }
  124.   if (chmod("/syzcgroup/unified", 0777)) {
  125.   }
  126.   int control = open("/syzcgroup/unified/cgroup.subtree_control", O_WRONLY);
  127.   if (control == -1)
  128.     return;
  129.   int i;
  130.   for (i = 0; i < count; i++)
  131.     if (write(control, controllers[i], strlen(controllers[i])) < 0) {
  132.     }
  133.   close(control);
  134. }
  135.  
  136. static void setup_cgroups()
  137. {
  138.   const char* unified_controllers[] = {"+cpu", "+io", "+pids"};
  139.   const char* net_controllers[] = {"net", "net_prio", "devices", "blkio",
  140.                                    "freezer"};
  141.   const char* cpu_controllers[] = {"cpuset", "cpuacct", "hugetlb", "rlimit",
  142.                                    "memory"};
  143.   if (mkdir("/syzcgroup", 0777)) {
  144.     return;
  145.   }
  146.   mount_cgroups2(unified_controllers,
  147.                  sizeof(unified_controllers) / sizeof(unified_controllers[0]));
  148.   mount_cgroups("/syzcgroup/net", net_controllers,
  149.                 sizeof(net_controllers) / sizeof(net_controllers[0]));
  150.   mount_cgroups("/syzcgroup/cpu", cpu_controllers,
  151.                 sizeof(cpu_controllers) / sizeof(cpu_controllers[0]));
  152.   write_file("/syzcgroup/cpu/cgroup.clone_children", "1");
  153.   write_file("/syzcgroup/cpu/cpuset.memory_pressure_enabled", "1");
  154. }
  155.  
  156. static void setup_cgroups_loop()
  157. {
  158.   int pid = getpid();
  159.   char file[128];
  160.   char cgroupdir[64];
  161.   snprintf(cgroupdir, sizeof(cgroupdir), "/syzcgroup/unified/syz%llu", procid);
  162.   if (mkdir(cgroupdir, 0777)) {
  163.   }
  164.   snprintf(file, sizeof(file), "%s/pids.max", cgroupdir);
  165.   write_file(file, "32");
  166.   snprintf(file, sizeof(file), "%s/cgroup.procs", cgroupdir);
  167.   write_file(file, "%d", pid);
  168.   snprintf(cgroupdir, sizeof(cgroupdir), "/syzcgroup/cpu/syz%llu", procid);
  169.   if (mkdir(cgroupdir, 0777)) {
  170.   }
  171.   snprintf(file, sizeof(file), "%s/cgroup.procs", cgroupdir);
  172.   write_file(file, "%d", pid);
  173.   snprintf(file, sizeof(file), "%s/memory.soft_limit_in_bytes", cgroupdir);
  174.   write_file(file, "%d", 299 << 20);
  175.   snprintf(file, sizeof(file), "%s/memory.limit_in_bytes", cgroupdir);
  176.   write_file(file, "%d", 300 << 20);
  177.   snprintf(cgroupdir, sizeof(cgroupdir), "/syzcgroup/net/syz%llu", procid);
  178.   if (mkdir(cgroupdir, 0777)) {
  179.   }
  180.   snprintf(file, sizeof(file), "%s/cgroup.procs", cgroupdir);
  181.   write_file(file, "%d", pid);
  182. }
  183.  
  184. static void setup_cgroups_test()
  185. {
  186.   char cgroupdir[64];
  187.   snprintf(cgroupdir, sizeof(cgroupdir), "/syzcgroup/unified/syz%llu", procid);
  188.   if (symlink(cgroupdir, "./cgroup")) {
  189.   }
  190.   snprintf(cgroupdir, sizeof(cgroupdir), "/syzcgroup/cpu/syz%llu", procid);
  191.   if (symlink(cgroupdir, "./cgroup.cpu")) {
  192.   }
  193.   snprintf(cgroupdir, sizeof(cgroupdir), "/syzcgroup/net/syz%llu", procid);
  194.   if (symlink(cgroupdir, "./cgroup.net")) {
  195.   }
  196. }
  197.  
  198. static void setup_common()
  199. {
  200.   if (mount(0, "/sys/fs/fuse/connections", "fusectl", 0, 0)) {
  201.   }
  202. }
  203.  
  204. static void setup_binderfs()
  205. {
  206.   if (mkdir("/dev/binderfs", 0777)) {
  207.   }
  208.   if (mount("binder", "/dev/binderfs", "binder", 0, NULL)) {
  209.   }
  210. }
  211.  
  212. static void loop();
  213.  
  214. static void sandbox_common()
  215. {
  216.   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
  217.   setsid();
  218.   struct rlimit rlim;
  219.   rlim.rlim_cur = rlim.rlim_max = (200 << 20);
  220.   setrlimit(RLIMIT_AS, &rlim);
  221.   rlim.rlim_cur = rlim.rlim_max = 32 << 20;
  222.   setrlimit(RLIMIT_MEMLOCK, &rlim);
  223.   rlim.rlim_cur = rlim.rlim_max = 136 << 20;
  224.   setrlimit(RLIMIT_FSIZE, &rlim);
  225.   rlim.rlim_cur = rlim.rlim_max = 1 << 20;
  226.   setrlimit(RLIMIT_STACK, &rlim);
  227.   rlim.rlim_cur = rlim.rlim_max = 128 << 20;
  228.   setrlimit(RLIMIT_CORE, &rlim);
  229.   rlim.rlim_cur = rlim.rlim_max = 256;
  230.   setrlimit(RLIMIT_NOFILE, &rlim);
  231.   if (unshare(CLONE_NEWNS)) {
  232.   }
  233.   if (mount(NULL, "/", NULL, MS_REC | MS_PRIVATE, NULL)) {
  234.   }
  235.   if (unshare(CLONE_NEWIPC)) {
  236.   }
  237.   if (unshare(0x02000000)) {
  238.   }
  239.   if (unshare(CLONE_NEWUTS)) {
  240.   }
  241.   if (unshare(CLONE_SYSVSEM)) {
  242.   }
  243.   typedef struct {
  244.     const char* name;
  245.     const char* value;
  246.   } sysctl_t;
  247.   static const sysctl_t sysctls[] = {
  248.       {"/proc/sys/kernel/shmmax", "16777216"},
  249.       {"/proc/sys/kernel/shmall", "536870912"},
  250.       {"/proc/sys/kernel/shmmni", "1024"},
  251.       {"/proc/sys/kernel/msgmax", "8192"},
  252.       {"/proc/sys/kernel/msgmni", "1024"},
  253.       {"/proc/sys/kernel/msgmnb", "1024"},
  254.       {"/proc/sys/kernel/sem", "1024 1048576 500 1024"},
  255.   };
  256.   unsigned i;
  257.   for (i = 0; i < sizeof(sysctls) / sizeof(sysctls[0]); i++)
  258.     write_file(sysctls[i].name, sysctls[i].value);
  259. }
  260.  
  261. static int wait_for_loop(int pid)
  262. {
  263.   if (pid < 0)
  264.     exit(1);
  265.   int status = 0;
  266.   while (waitpid(-1, &status, __WALL) != pid) {
  267.   }
  268.   return WEXITSTATUS(status);
  269. }
  270.  
  271. static void drop_caps(void)
  272. {
  273.   struct __user_cap_header_struct cap_hdr = {};
  274.   struct __user_cap_data_struct cap_data[2] = {};
  275.   cap_hdr.version = _LINUX_CAPABILITY_VERSION_3;
  276.   cap_hdr.pid = getpid();
  277.   if (syscall(SYS_capget, &cap_hdr, &cap_data))
  278.     exit(1);
  279.   const int drop = (1 << CAP_SYS_PTRACE) | (1 << CAP_SYS_NICE);
  280.   cap_data[0].effective &= ~drop;
  281.   cap_data[0].permitted &= ~drop;
  282.   cap_data[0].inheritable &= ~drop;
  283.   if (syscall(SYS_capset, &cap_hdr, &cap_data))
  284.     exit(1);
  285. }
  286.  
  287. static int do_sandbox_none(void)
  288. {
  289.   if (unshare(CLONE_NEWPID)) {
  290.   }
  291.   int pid = fork();
  292.   if (pid != 0)
  293.     return wait_for_loop(pid);
  294.   setup_common();
  295.   sandbox_common();
  296.   drop_caps();
  297.   if (unshare(CLONE_NEWNET)) {
  298.   }
  299.   write_file("/proc/sys/net/ipv4/ping_group_range", "0 65535");
  300.   setup_binderfs();
  301.   loop();
  302.   exit(1);
  303. }
  304.  
  305. #define FS_IOC_SETFLAGS _IOW('f', 2, long)
  306. static void remove_dir(const char* dir)
  307. {
  308.   int iter = 0;
  309.   DIR* dp = 0;
  310. retry:
  311.   while (umount2(dir, MNT_DETACH | UMOUNT_NOFOLLOW) == 0) {
  312.   }
  313.   dp = opendir(dir);
  314.   if (dp == NULL) {
  315.     if (errno == EMFILE) {
  316.       exit(1);
  317.     }
  318.     exit(1);
  319.   }
  320.   struct dirent* ep = 0;
  321.   while ((ep = readdir(dp))) {
  322.     if (strcmp(ep->d_name, ".") == 0 || strcmp(ep->d_name, "..") == 0)
  323.       continue;
  324.     char filename[FILENAME_MAX];
  325.     snprintf(filename, sizeof(filename), "%s/%s", dir, ep->d_name);
  326.     while (umount2(filename, MNT_DETACH | UMOUNT_NOFOLLOW) == 0) {
  327.     }
  328.     struct stat st;
  329.     if (lstat(filename, &st))
  330.       exit(1);
  331.     if (S_ISDIR(st.st_mode)) {
  332.       remove_dir(filename);
  333.       continue;
  334.     }
  335.     int i;
  336.     for (i = 0;; i++) {
  337.       if (unlink(filename) == 0)
  338.         break;
  339.       if (errno == EPERM) {
  340.         int fd = open(filename, O_RDONLY);
  341.         if (fd != -1) {
  342.           long flags = 0;
  343.           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0) {
  344.           }
  345.           close(fd);
  346.           continue;
  347.         }
  348.       }
  349.       if (errno == EROFS) {
  350.         break;
  351.       }
  352.       if (errno != EBUSY || i > 100)
  353.         exit(1);
  354.       if (umount2(filename, MNT_DETACH | UMOUNT_NOFOLLOW))
  355.         exit(1);
  356.     }
  357.   }
  358.   closedir(dp);
  359.   for (int i = 0;; i++) {
  360.     if (rmdir(dir) == 0)
  361.       break;
  362.     if (i < 100) {
  363.       if (errno == EPERM) {
  364.         int fd = open(dir, O_RDONLY);
  365.         if (fd != -1) {
  366.           long flags = 0;
  367.           if (ioctl(fd, FS_IOC_SETFLAGS, &flags) == 0) {
  368.           }
  369.           close(fd);
  370.           continue;
  371.         }
  372.       }
  373.       if (errno == EROFS) {
  374.         break;
  375.       }
  376.       if (errno == EBUSY) {
  377.         if (umount2(dir, MNT_DETACH | UMOUNT_NOFOLLOW))
  378.           exit(1);
  379.         continue;
  380.       }
  381.       if (errno == ENOTEMPTY) {
  382.         if (iter < 100) {
  383.           iter++;
  384.           goto retry;
  385.         }
  386.       }
  387.     }
  388.     exit(1);
  389.   }
  390. }
  391.  
  392. static void kill_and_wait(int pid, int* status)
  393. {
  394.   kill(-pid, SIGKILL);
  395.   kill(pid, SIGKILL);
  396.   for (int i = 0; i < 100; i++) {
  397.     if (waitpid(-1, status, WNOHANG | __WALL) == pid)
  398.       return;
  399.     usleep(1000);
  400.   }
  401.   DIR* dir = opendir("/sys/fs/fuse/connections");
  402.   if (dir) {
  403.     for (;;) {
  404.       struct dirent* ent = readdir(dir);
  405.       if (!ent)
  406.         break;
  407.       if (strcmp(ent->d_name, ".") == 0 || strcmp(ent->d_name, "..") == 0)
  408.         continue;
  409.       char abort[300];
  410.       snprintf(abort, sizeof(abort), "/sys/fs/fuse/connections/%s/abort",
  411.                ent->d_name);
  412.       int fd = open(abort, O_WRONLY);
  413.       if (fd == -1) {
  414.         continue;
  415.       }
  416.       if (write(fd, abort, 1) < 0) {
  417.       }
  418.       close(fd);
  419.     }
  420.     closedir(dir);
  421.   } else {
  422.   }
  423.   while (waitpid(-1, status, __WALL) != pid) {
  424.   }
  425. }
  426.  
  427. static void setup_loop()
  428. {
  429.   setup_cgroups_loop();
  430. }
  431.  
  432. static void setup_test()
  433. {
  434.   prctl(PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0);
  435.   setpgrp();
  436.   setup_cgroups_test();
  437.   write_file("/proc/self/oom_score_adj", "1000");
  438.   if (symlink("/dev/binderfs", "./binderfs")) {
  439.   }
  440. }
  441.  
  442. static void close_fds()
  443. {
  444.   for (int fd = 3; fd < MAX_FDS; fd++)
  445.     close(fd);
  446. }
  447.  
  448. static void execute_one(void);
  449.  
  450. #define WAIT_FLAGS __WALL
  451.  
  452. static void loop(void)
  453. {
  454.   setup_loop();
  455.   int iter = 0;
  456.   for (;; iter++) {
  457.     char cwdbuf[32];
  458.     sprintf(cwdbuf, "./%d", iter);
  459.     if (mkdir(cwdbuf, 0777))
  460.       exit(1);
  461.     int pid = fork();
  462.     if (pid < 0)
  463.       exit(1);
  464.     if (pid == 0) {
  465.       if (chdir(cwdbuf))
  466.         exit(1);
  467.       setup_test();
  468.       execute_one();
  469.       close_fds();
  470.       exit(0);
  471.     }
  472.     int status = 0;
  473.     uint64_t start = current_time_ms();
  474.     for (;;) {
  475.       if (waitpid(-1, &status, WNOHANG | WAIT_FLAGS) == pid)
  476.         break;
  477.       sleep_ms(1);
  478.       if (current_time_ms() - start < 5000)
  479.         continue;
  480.       kill_and_wait(pid, &status);
  481.       break;
  482.     }
  483.     remove_dir(cwdbuf);
  484.   }
  485. }
  486.  
  487. uint64_t r[3] = {0xffffffffffffffff, 0xffffffffffffffff, 0xffffffffffffffff};
  488.  
  489. void execute_one(void)
  490. {
  491.   intptr_t res = 0;
  492.   memcpy((void*)0x20000200, "./cgroup\000", 9);
  493.   res = syscall(__NR_openat, /*fd=*/0xffffff9c, /*file=*/0x20000200ul,
  494.                 /*flags=*/0ul, /*mode=*/0ul);
  495.   if (res != -1)
  496.     r[0] = res;
  497.   *(uint32_t*)0x20000080 = 0;
  498.   *(uint32_t*)0x20000084 = 0x80;
  499.   *(uint8_t*)0x20000088 = 0;
  500.   *(uint8_t*)0x20000089 = 0;
  501.   *(uint8_t*)0x2000008a = 0;
  502.   *(uint8_t*)0x2000008b = 0;
  503.   *(uint32_t*)0x2000008c = 0;
  504.   *(uint64_t*)0x20000090 = 0;
  505.   *(uint64_t*)0x20000098 = 0;
  506.   *(uint64_t*)0x200000a0 = 0;
  507.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 0, 1);
  508.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 1, 1);
  509.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 2, 1);
  510.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 3, 1);
  511.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 4, 1);
  512.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 5, 1);
  513.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 6, 1);
  514.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 7, 1);
  515.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 8, 1);
  516.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 9, 1);
  517.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 10, 1);
  518.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 11, 1);
  519.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 12, 1);
  520.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 13, 1);
  521.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 14, 1);
  522.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 15, 2);
  523.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 17, 1);
  524.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 18, 1);
  525.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 19, 1);
  526.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 20, 1);
  527.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 21, 1);
  528.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 22, 1);
  529.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 23, 1);
  530.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 24, 1);
  531.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 25, 1);
  532.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 26, 1);
  533.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 27, 1);
  534.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 28, 1);
  535.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 29, 1);
  536.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 30, 1);
  537.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 31, 1);
  538.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 32, 1);
  539.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 33, 1);
  540.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 34, 1);
  541.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 35, 1);
  542.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 36, 1);
  543.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 37, 1);
  544.   STORE_BY_BITMASK(uint64_t, , 0x200000a8, 0, 38, 26);
  545.   *(uint32_t*)0x200000b0 = 0;
  546.   *(uint32_t*)0x200000b4 = 0;
  547.   *(uint64_t*)0x200000b8 = 0;
  548.   *(uint64_t*)0x200000c0 = 0;
  549.   *(uint64_t*)0x200000c8 = 0;
  550.   *(uint64_t*)0x200000d0 = 0;
  551.   *(uint32_t*)0x200000d8 = 0;
  552.   *(uint32_t*)0x200000dc = 0;
  553.   *(uint64_t*)0x200000e0 = 0;
  554.   *(uint32_t*)0x200000e8 = 0;
  555.   *(uint16_t*)0x200000ec = 0;
  556.   *(uint16_t*)0x200000ee = 0;
  557.   *(uint32_t*)0x200000f0 = 0;
  558.   *(uint32_t*)0x200000f4 = 0;
  559.   *(uint64_t*)0x200000f8 = 0;
  560.   res = syscall(__NR_perf_event_open, /*attr=*/0x20000080ul, /*fd=*/r[0],
  561.                 /*cpu=*/0ul, /*group=*/-1, /*flags=PERF_FLAG_PID_CGROUP*/ 4ul);
  562.   if (res != -1)
  563.     r[1] = res;
  564.   res = syscall(__NR_openat, /*fd=*/0xffffffffffffff9cul, /*file=*/0ul,
  565.                 /*flags=*/0ul, /*mode=*/0ul);
  566.   if (res != -1)
  567.     r[2] = res;
  568.   syscall(__NR_dup3, /*oldfd=*/r[2], /*newfd=*/r[1], /*flags=*/0ul);
  569. }
  570. int main(void)
  571. {
  572.   syscall(__NR_mmap, /*addr=*/0x1ffff000ul, /*len=*/0x1000ul, /*prot=*/0ul,
  573.           /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
  574.           /*offset=*/0ul);
  575.   syscall(__NR_mmap, /*addr=*/0x20000000ul, /*len=*/0x1000000ul,
  576.           /*prot=PROT_WRITE|PROT_READ|PROT_EXEC*/ 7ul,
  577.           /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
  578.           /*offset=*/0ul);
  579.   syscall(__NR_mmap, /*addr=*/0x21000000ul, /*len=*/0x1000ul, /*prot=*/0ul,
  580.           /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
  581.           /*offset=*/0ul);
  582.   setup_cgroups();
  583.   for (procid = 0; procid < 7; procid++) {
  584.     if (fork() == 0) {
  585.       use_temporary_dir();
  586.       do_sandbox_none();
  587.     }
  588.   }
  589.   sleep(1000000);
  590.   return 0;
  591. }
Advertisement
Add Comment
Please, Sign In to add comment