zzqq0103

Untitled

Mar 14th, 2024
197
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
C 21.54 KB | None | 0 0
  1. #define _GNU_SOURCE
  2.  
  3. #include <endian.h>
  4. #include <errno.h>
  5. #include <fcntl.h>
  6. #include <setjmp.h>
  7. #include <stdbool.h>
  8. #include <stddef.h>
  9. #include <stdint.h>
  10. #include <stdio.h>
  11. #include <stdlib.h>
  12. #include <string.h>
  13. #include <sys/ioctl.h>
  14. #include <sys/mman.h>
  15. #include <sys/mount.h>
  16. #include <sys/stat.h>
  17. #include <sys/syscall.h>
  18. #include <sys/types.h>
  19. #include <unistd.h>
  20.  
  21. #include <linux/loop.h>
  22.  
  23. #ifndef __NR_memfd_create
  24. #define __NR_memfd_create 319
  25. #endif
  26.  
  27. static unsigned long long procid;
  28.  
  29. //% This code is derived from puff.{c,h}, found in the zlib development. The
  30. //% original files come with the following copyright notice:
  31.  
  32. //% Copyright (C) 2002-2013 Mark Adler, all rights reserved
  33. //% version 2.3, 21 Jan 2013
  34. //% This software is provided 'as-is', without any express or implied
  35. //% warranty.  In no event will the author be held liable for any damages
  36. //% arising from the use of this software.
  37. //% Permission is granted to anyone to use this software for any purpose,
  38. //% including commercial applications, and to alter it and redistribute it
  39. //% freely, subject to the following restrictions:
  40. //% 1. The origin of this software must not be misrepresented; you must not
  41. //%    claim that you wrote the original software. If you use this software
  42. //%    in a product, an acknowledgment in the product documentation would be
  43. //%    appreciated but is not required.
  44. //% 2. Altered source versions must be plainly marked as such, and must not be
  45. //%    misrepresented as being the original software.
  46. //% 3. This notice may not be removed or altered from any source distribution.
  47. //% Mark Adler    [email protected]
  48.  
  49. //% BEGIN CODE DERIVED FROM puff.{c,h}
  50.  
  51. #define MAXBITS 15
  52. #define MAXLCODES 286
  53. #define MAXDCODES 30
  54. #define MAXCODES (MAXLCODES + MAXDCODES)
  55. #define FIXLCODES 288
  56.  
  57. struct puff_state {
  58.   unsigned char* out;
  59.   unsigned long outlen;
  60.   unsigned long outcnt;
  61.   const unsigned char* in;
  62.   unsigned long inlen;
  63.   unsigned long incnt;
  64.   int bitbuf;
  65.   int bitcnt;
  66.   jmp_buf env;
  67. };
  68. static int puff_bits(struct puff_state* s, int need)
  69. {
  70.   long val = s->bitbuf;
  71.   while (s->bitcnt < need) {
  72.     if (s->incnt == s->inlen)
  73.       longjmp(s->env, 1);
  74.     val |= (long)(s->in[s->incnt++]) << s->bitcnt;
  75.     s->bitcnt += 8;
  76.   }
  77.   s->bitbuf = (int)(val >> need);
  78.   s->bitcnt -= need;
  79.   return (int)(val & ((1L << need) - 1));
  80. }
  81. static int puff_stored(struct puff_state* s)
  82. {
  83.   s->bitbuf = 0;
  84.   s->bitcnt = 0;
  85.   if (s->incnt + 4 > s->inlen)
  86.     return 2;
  87.   unsigned len = s->in[s->incnt++];
  88.   len |= s->in[s->incnt++] << 8;
  89.   if (s->in[s->incnt++] != (~len & 0xff) ||
  90.       s->in[s->incnt++] != ((~len >> 8) & 0xff))
  91.     return -2;
  92.   if (s->incnt + len > s->inlen)
  93.     return 2;
  94.   if (s->outcnt + len > s->outlen)
  95.     return 1;
  96.   for (; len--; s->outcnt++, s->incnt++) {
  97.     if (s->in[s->incnt])
  98.       s->out[s->outcnt] = s->in[s->incnt];
  99.   }
  100.   return 0;
  101. }
  102. struct puff_huffman {
  103.   short* count;
  104.   short* symbol;
  105. };
  106. static int puff_decode(struct puff_state* s, const struct puff_huffman* h)
  107. {
  108.   int first = 0;
  109.   int index = 0;
  110.   int bitbuf = s->bitbuf;
  111.   int left = s->bitcnt;
  112.   int code = first = index = 0;
  113.   int len = 1;
  114.   short* next = h->count + 1;
  115.   while (1) {
  116.     while (left--) {
  117.       code |= bitbuf & 1;
  118.       bitbuf >>= 1;
  119.       int count = *next++;
  120.       if (code - count < first) {
  121.         s->bitbuf = bitbuf;
  122.         s->bitcnt = (s->bitcnt - len) & 7;
  123.         return h->symbol[index + (code - first)];
  124.       }
  125.       index += count;
  126.       first += count;
  127.       first <<= 1;
  128.       code <<= 1;
  129.       len++;
  130.     }
  131.     left = (MAXBITS + 1) - len;
  132.     if (left == 0)
  133.       break;
  134.     if (s->incnt == s->inlen)
  135.       longjmp(s->env, 1);
  136.     bitbuf = s->in[s->incnt++];
  137.     if (left > 8)
  138.       left = 8;
  139.   }
  140.   return -10;
  141. }
  142. static int puff_construct(struct puff_huffman* h, const short* length, int n)
  143. {
  144.   int len;
  145.   for (len = 0; len <= MAXBITS; len++)
  146.     h->count[len] = 0;
  147.   int symbol;
  148.   for (symbol = 0; symbol < n; symbol++)
  149.     (h->count[length[symbol]])++;
  150.   if (h->count[0] == n)
  151.     return 0;
  152.   int left = 1;
  153.   for (len = 1; len <= MAXBITS; len++) {
  154.     left <<= 1;
  155.     left -= h->count[len];
  156.     if (left < 0)
  157.       return left;
  158.   }
  159.   short offs[MAXBITS + 1];
  160.   offs[1] = 0;
  161.   for (len = 1; len < MAXBITS; len++)
  162.     offs[len + 1] = offs[len] + h->count[len];
  163.   for (symbol = 0; symbol < n; symbol++)
  164.     if (length[symbol] != 0)
  165.       h->symbol[offs[length[symbol]]++] = symbol;
  166.   return left;
  167. }
  168. static int puff_codes(struct puff_state* s, const struct puff_huffman* lencode,
  169.                       const struct puff_huffman* distcode)
  170. {
  171.   static const short lens[29] = {3,  4,  5,  6,   7,   8,   9,   10,  11, 13,
  172.                                  15, 17, 19, 23,  27,  31,  35,  43,  51, 59,
  173.                                  67, 83, 99, 115, 131, 163, 195, 227, 258};
  174.   static const short lext[29] = {0, 0, 0, 0, 0, 0, 0, 0, 1, 1, 1, 1, 2, 2, 2,
  175.                                  2, 3, 3, 3, 3, 4, 4, 4, 4, 5, 5, 5, 5, 0};
  176.   static const short dists[30] = {
  177.       1,    2,    3,    4,    5,    7,    9,    13,    17,    25,
  178.       33,   49,   65,   97,   129,  193,  257,  385,   513,   769,
  179.       1025, 1537, 2049, 3073, 4097, 6145, 8193, 12289, 16385, 24577};
  180.   static const short dext[30] = {0, 0, 0,  0,  1,  1,  2,  2,  3,  3,
  181.                                  4, 4, 5,  5,  6,  6,  7,  7,  8,  8,
  182.                                  9, 9, 10, 10, 11, 11, 12, 12, 13, 13};
  183.   int symbol;
  184.   do {
  185.     symbol = puff_decode(s, lencode);
  186.     if (symbol < 0)
  187.       return symbol;
  188.     if (symbol < 256) {
  189.       if (s->outcnt == s->outlen)
  190.         return 1;
  191.       if (symbol)
  192.         s->out[s->outcnt] = symbol;
  193.       s->outcnt++;
  194.     } else if (symbol > 256) {
  195.       symbol -= 257;
  196.       if (symbol >= 29)
  197.         return -10;
  198.       int len = lens[symbol] + puff_bits(s, lext[symbol]);
  199.       symbol = puff_decode(s, distcode);
  200.       if (symbol < 0)
  201.         return symbol;
  202.       unsigned dist = dists[symbol] + puff_bits(s, dext[symbol]);
  203.       if (dist > s->outcnt)
  204.         return -11;
  205.       if (s->outcnt + len > s->outlen)
  206.         return 1;
  207.       while (len--) {
  208.         if (dist <= s->outcnt && s->out[s->outcnt - dist])
  209.           s->out[s->outcnt] = s->out[s->outcnt - dist];
  210.         s->outcnt++;
  211.       }
  212.     }
  213.   } while (symbol != 256);
  214.   return 0;
  215. }
  216. static int puff_fixed(struct puff_state* s)
  217. {
  218.   static int virgin = 1;
  219.   static short lencnt[MAXBITS + 1], lensym[FIXLCODES];
  220.   static short distcnt[MAXBITS + 1], distsym[MAXDCODES];
  221.   static struct puff_huffman lencode, distcode;
  222.   if (virgin) {
  223.     lencode.count = lencnt;
  224.     lencode.symbol = lensym;
  225.     distcode.count = distcnt;
  226.     distcode.symbol = distsym;
  227.     short lengths[FIXLCODES];
  228.     int symbol;
  229.     for (symbol = 0; symbol < 144; symbol++)
  230.       lengths[symbol] = 8;
  231.     for (; symbol < 256; symbol++)
  232.       lengths[symbol] = 9;
  233.     for (; symbol < 280; symbol++)
  234.       lengths[symbol] = 7;
  235.     for (; symbol < FIXLCODES; symbol++)
  236.       lengths[symbol] = 8;
  237.     puff_construct(&lencode, lengths, FIXLCODES);
  238.     for (symbol = 0; symbol < MAXDCODES; symbol++)
  239.       lengths[symbol] = 5;
  240.     puff_construct(&distcode, lengths, MAXDCODES);
  241.     virgin = 0;
  242.   }
  243.   return puff_codes(s, &lencode, &distcode);
  244. }
  245. static int puff_dynamic(struct puff_state* s)
  246. {
  247.   static const short order[19] = {16, 17, 18, 0, 8,  7, 9,  6, 10, 5,
  248.                                   11, 4,  12, 3, 13, 2, 14, 1, 15};
  249.   int nlen = puff_bits(s, 5) + 257;
  250.   int ndist = puff_bits(s, 5) + 1;
  251.   int ncode = puff_bits(s, 4) + 4;
  252.   if (nlen > MAXLCODES || ndist > MAXDCODES)
  253.     return -3;
  254.   short lengths[MAXCODES];
  255.   int index;
  256.   for (index = 0; index < ncode; index++)
  257.     lengths[order[index]] = puff_bits(s, 3);
  258.   for (; index < 19; index++)
  259.     lengths[order[index]] = 0;
  260.   short lencnt[MAXBITS + 1], lensym[MAXLCODES];
  261.   struct puff_huffman lencode = {lencnt, lensym};
  262.   int err = puff_construct(&lencode, lengths, 19);
  263.   if (err != 0)
  264.     return -4;
  265.   index = 0;
  266.   while (index < nlen + ndist) {
  267.     int symbol;
  268.     int len;
  269.     symbol = puff_decode(s, &lencode);
  270.     if (symbol < 0)
  271.       return symbol;
  272.     if (symbol < 16)
  273.       lengths[index++] = symbol;
  274.     else {
  275.       len = 0;
  276.       if (symbol == 16) {
  277.         if (index == 0)
  278.           return -5;
  279.         len = lengths[index - 1];
  280.         symbol = 3 + puff_bits(s, 2);
  281.       } else if (symbol == 17)
  282.         symbol = 3 + puff_bits(s, 3);
  283.       else
  284.         symbol = 11 + puff_bits(s, 7);
  285.       if (index + symbol > nlen + ndist)
  286.         return -6;
  287.       while (symbol--)
  288.         lengths[index++] = len;
  289.     }
  290.   }
  291.   if (lengths[256] == 0)
  292.     return -9;
  293.   err = puff_construct(&lencode, lengths, nlen);
  294.   if (err && (err < 0 || nlen != lencode.count[0] + lencode.count[1]))
  295.     return -7;
  296.   short distcnt[MAXBITS + 1], distsym[MAXDCODES];
  297.   struct puff_huffman distcode = {distcnt, distsym};
  298.   err = puff_construct(&distcode, lengths + nlen, ndist);
  299.   if (err && (err < 0 || ndist != distcode.count[0] + distcode.count[1]))
  300.     return -8;
  301.   return puff_codes(s, &lencode, &distcode);
  302. }
  303. static int puff(unsigned char* dest, unsigned long* destlen,
  304.                 const unsigned char* source, unsigned long sourcelen)
  305. {
  306.   struct puff_state s = {
  307.       .out = dest,
  308.       .outlen = *destlen,
  309.       .outcnt = 0,
  310.       .in = source,
  311.       .inlen = sourcelen,
  312.       .incnt = 0,
  313.       .bitbuf = 0,
  314.       .bitcnt = 0,
  315.   };
  316.   int err;
  317.   if (setjmp(s.env) != 0)
  318.     err = 2;
  319.   else {
  320.     int last;
  321.     do {
  322.       last = puff_bits(&s, 1);
  323.       int type = puff_bits(&s, 2);
  324.       err = type == 0 ? puff_stored(&s)
  325.                       : (type == 1 ? puff_fixed(&s)
  326.                                    : (type == 2 ? puff_dynamic(&s) : -1));
  327.       if (err != 0)
  328.         break;
  329.     } while (!last);
  330.   }
  331.   *destlen = s.outcnt;
  332.   return err;
  333. }
  334.  
  335. //% END CODE DERIVED FROM puff.{c,h}
  336.  
  337. #define ZLIB_HEADER_WIDTH 2
  338.  
  339. static int puff_zlib_to_file(const unsigned char* source,
  340.                              unsigned long sourcelen, int dest_fd)
  341. {
  342.   if (sourcelen < ZLIB_HEADER_WIDTH)
  343.     return 0;
  344.   source += ZLIB_HEADER_WIDTH;
  345.   sourcelen -= ZLIB_HEADER_WIDTH;
  346.   const unsigned long max_destlen = 132 << 20;
  347.   void* ret = mmap(0, max_destlen, PROT_WRITE | PROT_READ,
  348.                    MAP_PRIVATE | MAP_ANON, -1, 0);
  349.   if (ret == MAP_FAILED)
  350.     return -1;
  351.   unsigned char* dest = (unsigned char*)ret;
  352.   unsigned long destlen = max_destlen;
  353.   int err = puff(dest, &destlen, source, sourcelen);
  354.   if (err) {
  355.     munmap(dest, max_destlen);
  356.     errno = -err;
  357.     return -1;
  358.   }
  359.   if (write(dest_fd, dest, destlen) != (ssize_t)destlen) {
  360.     munmap(dest, max_destlen);
  361.     return -1;
  362.   }
  363.   return munmap(dest, max_destlen);
  364. }
  365.  
  366. static int setup_loop_device(unsigned char* data, unsigned long size,
  367.                              const char* loopname, int* loopfd_p)
  368. {
  369.   int err = 0, loopfd = -1;
  370.   int memfd = syscall(__NR_memfd_create, "syzkaller", 0);
  371.   if (memfd == -1) {
  372.     err = errno;
  373.     goto error;
  374.   }
  375.   if (puff_zlib_to_file(data, size, memfd)) {
  376.     err = errno;
  377.     goto error_close_memfd;
  378.   }
  379.   loopfd = open(loopname, O_RDWR);
  380.   if (loopfd == -1) {
  381.     err = errno;
  382.     goto error_close_memfd;
  383.   }
  384.   if (ioctl(loopfd, LOOP_SET_FD, memfd)) {
  385.     if (errno != EBUSY) {
  386.       err = errno;
  387.       goto error_close_loop;
  388.     }
  389.     ioctl(loopfd, LOOP_CLR_FD, 0);
  390.     usleep(1000);
  391.     if (ioctl(loopfd, LOOP_SET_FD, memfd)) {
  392.       err = errno;
  393.       goto error_close_loop;
  394.     }
  395.   }
  396.   close(memfd);
  397.   *loopfd_p = loopfd;
  398.   return 0;
  399.  
  400. error_close_loop:
  401.   close(loopfd);
  402. error_close_memfd:
  403.   close(memfd);
  404. error:
  405.   errno = err;
  406.   return -1;
  407. }
  408.  
  409. static void reset_loop_device(const char* loopname)
  410. {
  411.   int loopfd = open(loopname, O_RDWR);
  412.   if (loopfd == -1) {
  413.     return;
  414.   }
  415.   if (ioctl(loopfd, LOOP_CLR_FD, 0)) {
  416.   }
  417.   close(loopfd);
  418. }
  419.  
  420. static long syz_mount_image(volatile long fsarg, volatile long dir,
  421.                             volatile long flags, volatile long optsarg,
  422.                             volatile long change_dir,
  423.                             volatile unsigned long size, volatile long image)
  424. {
  425.   unsigned char* data = (unsigned char*)image;
  426.   int res = -1, err = 0, need_loop_device = !!size;
  427.   char* mount_opts = (char*)optsarg;
  428.   char* target = (char*)dir;
  429.   char* fs = (char*)fsarg;
  430.   char* source = NULL;
  431.   char loopname[64];
  432.   if (need_loop_device) {
  433.     int loopfd;
  434.     memset(loopname, 0, sizeof(loopname));
  435.     snprintf(loopname, sizeof(loopname), "/dev/loop%llu", procid);
  436.     if (setup_loop_device(data, size, loopname, &loopfd) == -1)
  437.       return -1;
  438.     close(loopfd);
  439.     source = loopname;
  440.   }
  441.   mkdir(target, 0777);
  442.   char opts[256];
  443.   memset(opts, 0, sizeof(opts));
  444.   if (strlen(mount_opts) > (sizeof(opts) - 32)) {
  445.   }
  446.   strncpy(opts, mount_opts, sizeof(opts) - 32);
  447.   if (strcmp(fs, "iso9660") == 0) {
  448.     flags |= MS_RDONLY;
  449.   } else if (strncmp(fs, "ext", 3) == 0) {
  450.     bool has_remount_ro = false;
  451.     char* remount_ro_start = strstr(opts, "errors=remount-ro");
  452.     if (remount_ro_start != NULL) {
  453.       char after = *(remount_ro_start + strlen("errors=remount-ro"));
  454.       char before = remount_ro_start == opts ? '\0' : *(remount_ro_start - 1);
  455.       has_remount_ro = ((before == '\0' || before == ',') &&
  456.                         (after == '\0' || after == ','));
  457.     }
  458.     if (strstr(opts, "errors=panic") || !has_remount_ro)
  459.       strcat(opts, ",errors=continue");
  460.   } else if (strcmp(fs, "xfs") == 0) {
  461.     strcat(opts, ",nouuid");
  462.   }
  463.   res = mount(source, target, fs, flags, opts);
  464.   if (res == -1) {
  465.     err = errno;
  466.     goto error_clear_loop;
  467.   }
  468.   res = open(target, O_RDONLY | O_DIRECTORY);
  469.   if (res == -1) {
  470.     err = errno;
  471.     goto error_clear_loop;
  472.   }
  473.   if (change_dir) {
  474.     res = chdir(target);
  475.     if (res == -1) {
  476.       err = errno;
  477.     }
  478.   }
  479.  
  480. error_clear_loop:
  481.   if (need_loop_device)
  482.     reset_loop_device(loopname);
  483.   errno = err;
  484.   return res;
  485. }
  486.  
  487. uint64_t r[1] = {0xffffffffffffffff};
  488.  
  489. int main(void)
  490. {
  491.   syscall(__NR_mmap, /*addr=*/0x1ffff000ul, /*len=*/0x1000ul, /*prot=*/0ul,
  492.           /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
  493.           /*offset=*/0ul);
  494.   syscall(__NR_mmap, /*addr=*/0x20000000ul, /*len=*/0x1000000ul,
  495.           /*prot=PROT_WRITE|PROT_READ|PROT_EXEC*/ 7ul,
  496.           /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
  497.           /*offset=*/0ul);
  498.   syscall(__NR_mmap, /*addr=*/0x21000000ul, /*len=*/0x1000ul, /*prot=*/0ul,
  499.           /*flags=MAP_FIXED|MAP_ANONYMOUS|MAP_PRIVATE*/ 0x32ul, /*fd=*/-1,
  500.           /*offset=*/0ul);
  501.   intptr_t res = 0;
  502.   memcpy((void*)0x20000040, "ext4\000", 5);
  503.   memcpy((void*)0x20000500, "./file1\000", 8);
  504.   memcpy((void*)0x20000540, "errors=remount-ro", 17);
  505.   *(uint8_t*)0x20000551 = 0x2c;
  506.   memcpy((void*)0x20000552, "sysvgroups", 10);
  507.   *(uint8_t*)0x2000055c = 0x2c;
  508.   memcpy((void*)0x2000055d, "dioread_lock", 12);
  509.   *(uint8_t*)0x20000569 = 0x2c;
  510.   memcpy((void*)0x2000056a, "grpquota", 8);
  511.   *(uint8_t*)0x20000572 = 0x2c;
  512.   memcpy((void*)0x20000573, "noauto_da_alloc", 15);
  513.   *(uint8_t*)0x20000582 = 0x2c;
  514.   memcpy((void*)0x20000583, "resgid", 6);
  515.   *(uint8_t*)0x20000589 = 0x3d;
  516.   sprintf((char*)0x2000058a, "0x%016llx", (long long)0);
  517.   *(uint8_t*)0x2000059c = 0x2c;
  518.   memcpy((void*)0x2000059d, "barrier", 7);
  519.   *(uint8_t*)0x200005a4 = 0x2c;
  520.   memcpy((void*)0x200005a5, "auto_da_alloc", 13);
  521.   *(uint8_t*)0x200005b2 = 0x2c;
  522.   memcpy((void*)0x200005b3, "usrquota", 8);
  523.   *(uint8_t*)0x200005bb = 0x2c;
  524.   *(uint8_t*)0x200005bc = 0;
  525.   memcpy(
  526.       (void*)0x20001b00,
  527.       "\x78\x9c\xec\xdd\xdf\x6b\x5b\xd7\x1d\x00\xf0\xef\xbd\xb6\xb2\xfc\x70\x66"
  528.       "\x67\xdb\x43\x16\x58\x16\x96\x0c\x27\x6c\x91\xec\x78\x49\xcc\x1e\xb2\x0c"
  529.       "\xc6\xf2\x14\xd8\x96\xbd\x67\x9e\x2d\x1b\x63\xd9\x32\x96\x9c\xc4\x26\x0c"
  530.       "\x87\xfd\x01\x83\x31\xd6\x42\x9f\xfa\xd4\x97\x42\xff\x80\x42\xc9\x9f\x50"
  531.       "\x0a\x81\xf6\xbd\xb4\xa5\xa5\xb4\x49\xfb\xd0\x87\xb6\x2a\x92\xae\xd2\xc4"
  532.       "\x95\x62\x87\xc8\xbe\x60\x7f\x3e\x70\x7c\xcf\xb9\x57\xd2\xf7\x7b\x6c\x74"
  533.       "\x75\xcf\xbd\xc7\xba\x01\xec\x5b\xa7\x22\xe2\x6a\x44\x0c\x44\xc4\xb9\x88"
  534.       "\x18\xce\xd6\xa7\x59\xb9\xd6\x6c\x6c\xb4\x1f\xf7\xe8\xe1\xdd\xe9\x66\x49"
  535.       "\xa2\xd1\xb8\xf1\x59\x12\x49\xb6\xae\xf3\x5a\x49\xb6\x3c\xd2\x7e\x4a\x1c"
  536.       "\x8c\x88\xbf\x5d\x8b\xf8\x67\xf2\xc3\xb8\xb5\xb5\xf5\x85\xa9\x4a\xa5\xbc"
  537.       "\x92\xb5\x4b\xf5\xc5\xe5\x52\x6d\x6d\xfd\xfc\xfc\xe2\xd4\x5c\x79\xae\xbc"
  538.       "\x34\x31\x31\x7e\x69\xf2\xf2\xe4\xc5\xc9\xb1\xbe\xf4\x73\x24\x22\xae\xfc"
  539.       "\xe9\xa3\xff\xff\xe7\xb5\x3f\x5f\x79\xeb\xb7\xb7\xdf\xbf\xf9\xc9\xd9\x7f"
  540.       "\x35\xd3\x1a\xca\xb6\x3f\xd9\x8f\x7e\x6a\x77\xbd\xd0\xfa\x5d\x74\x0c\x46"
  541.       "\xc4\xca\x4e\x04\xcb\xc1\x40\xb6\x2c\xe4\x9c\x07\x00\x00\xdb\xd3\x3c\xc6"
  542.       "\xff\x49\x44\xfc\xaa\x75\xfc\x3f\x1c\x03\xad\xa3\x53\x00\x00\x00\x60\x2f"
  543.       "\x69\xfc\x61\x28\xbe\x4e\x22\x1a\x00\x00\x00\xc0\x9e\x95\xb6\xe6\xc0\x26"
  544.       "\x69\x31\x9b\x0b\x30\x14\x69\x5a\x2c\xb6\xe7\xf0\xfe\x2c\x0e\xa7\x95\x6a"
  545.       "\xad\xfe\x9b\xd9\xea\xea\xd2\x4c\x7b\xae\xec\x48\x14\xd2\xd9\xf9\x4a\x79"
  546.       "\x2c\x9b\x2b\x3c\x12\x85\xa4\xd9\x1e\xcf\xe6\xd8\x76\xda\x17\x36\xb5\x27"
  547.       "\x22\xe2\x58\x44\xfc\x6f\xf8\x50\xab\x5d\x9c\xae\x56\x66\xf2\x3e\xf9\x01"
  548.       "\x00\x00\x00\xfb\xc4\x91\x4d\xe3\xff\x2f\x87\xdb\xe3\x7f\x00\x00\x00\x60"
  549.       "\x8f\x19\xc9\x3b\x01\x00\x00\x00\x60\xc7\x19\xff\x03\x00\x00\xc0\xde\x67"
  550.       "\xfc\x0f\x00\x00\x00\x7b\xda\x5f\xae\x5f\x6f\x96\x46\xe7\xfe\xd7\x33\xb7"
  551.       "\xd6\x56\x17\xaa\xb7\xce\xcf\x94\x6b\x0b\xc5\xc5\xd5\xe9\xe2\x74\x75\x65"
  552.       "\xb9\x38\x57\xad\xce\xb5\xbe\xb3\x6f\x71\xab\xd7\xab\x54\xab\xcb\xbf\x8b"
  553.       "\xa5\xd5\x3b\xa5\x7a\xb9\x56\x2f\xd5\xd6\xd6\x6f\x2e\x56\x57\x97\xea\x37"
  554.       "\xe7\x9f\xba\x05\x36\x00\x00\x00\xb0\x8b\x8e\xfd\xf2\xfe\x7b\x49\x44\x6c"
  555.       "\xfc\xfe\x50\xab\x34\x1d\xc8\x3b\x29\x60\x57\x24\xcf\xf3\xe0\x0f\x77\x2e"
  556.       "\x0f\x60\xf7\x0d\xe4\x9d\x00\x90\x9b\xc1\xbc\x13\x00\x72\x53\xc8\x3b\x01"
  557.       "\x20\x77\x5b\x9d\x07\xe8\x39\x79\xe7\xed\xfe\xe7\x02\x00\x00\xec\x8c\xd1"
  558.       "\x9f\xf7\xbe\xfe\xef\xdc\x00\xec\x6d\x69\xde\x09\x00\x00\xbb\xce\xf5\x7f"
  559.       "\xd8\xbf\x0a\x66\x00\xc2\xbe\xf7\xe3\x2d\xb6\xbf\xf8\xf5\xff\x46\xe3\xb9"
  560.       "\x12\x02\x00\x00\xfa\x6e\xa8\x55\x92\xb4\x98\x5d\x0b\x1c\x8a\x34\x2d\x16"
  561.       "\x23\x8e\xb6\x6e\x0b\x50\x48\x66\xe7\x2b\xe5\xb1\x6c\x7c\xf0\xee\x70\xe1"
  562.       "\x47\xcd\xf6\x78\xeb\x99\xc9\xf3\xfd\xef\x30\x00\x00\x00\x00\x00\x00\x00"
  563.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xec\x63\x8d\x46\x12\x0d"
  564.       "\x00\x00\x00\x60\x4f\x8b\x48\x3f\x4e\x5a\xdf\xe6\x1f\x31\x3a\x7c\x66\x68"
  565.       "\xf3\xf9\x81\x03\xc9\x57\xc3\xad\x65\x44\xdc\x7e\xe5\xc6\x4b\x77\xa6\xea"
  566.       "\xf5\x95\xf1\xe6\xfa\xcf\x1f\xaf\xaf\xbf\x9c\xad\xbf\x90\xc7\x19\x0c\x00"
  567.       "\x00\x00\x60\xb3\xce\x38\xbd\x33\x8e\x07\x00\x00\x00\x00\x00\x00\x00\x00"
  568.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  569.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  570.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x7e\x7a\xf4\xf0\xee\x74\xa7"
  571.       "\xec\x66\xdc\x4f\xff\x18\x11\x23\xdd\xe2\x0f\xc6\xc1\xd6\xf2\x60\x14\x22"
  572.       "\xe2\xf0\x17\x49\x0c\x3e\xf1\xbc\x24\x22\x06\xfa\x10\x7f\xe3\x5e\x44\x1c"
  573.       "\xef\x16\x3f\x69\xa6\x15\x23\x59\x16\xdd\xe2\x1f\xca\x31\x7e\x1a\x11\x47"
  574.       "\xfa\x10\x1f\xf6\xb3\xfb\xcd\xfd\xcf\xd5\x6e\xef\xbf\x34\x4e\xb5\x96\xdd"
  575.       "\xdf\x7f\x83\x59\x79\x51\xbd\xf7\x7f\xe9\xe3\xfd\xdf\x40\x8f\xfd\xcf\xd1"
  576.       "\x6d\xc6\x38\xf1\xe0\x8d\x52\xcf\xf8\xf7\x22\x4e\x0c\x76\xdf\xff\x74\xe2"
  577.       "\x27\x3d\xe2\x9f\xde\x66\xfc\x7f\xfc\x7d\x7d\xbd\xd7\xb6\xc6\xab\x11\xa3"
  578.       "\x5d\x3f\x7f\x92\xa7\x62\x95\xea\x8b\xcb\xa5\xda\xda\xfa\xf9\xf9\xc5\xa9"
  579.       "\xb9\xf2\x5c\x79\x69\x62\x62\xfc\xd2\xe4\xe5\xc9\x8b\x93\x63\xa5\xd9\xf9"
  580.       "\x4a\x39\xfb\xd9\x35\xc6\x7f\x7f\xf1\xe6\xb7\xcf\xea\xff\xe1\x1e\xf1\x47"
  581.       "\xb6\xe8\xff\x99\x6d\xf6\xff\x9b\x07\x77\x1e\xfe\xb4\x5d\x2d\x74\x8b\x7f"
  582.       "\xf6\x74\xf7\xcf\xdf\xe3\x3d\xe2\xa7\xd9\x67\xdf\xaf\xb3\x7a\x73\xfb\x68"
  583.       "\xa7\xbe\xd1\xae\x3f\xe9\xe4\xeb\xef\x9c\x7c\x56\xff\x67\x7a\xf4\x7f\xab"
  584.       "\xbf\xff\xd9\x6d\xf6\xff\xdc\x5f\xff\xfd\xc1\x36\x1f\x0a\x00\xec\x82\xda"
  585.       "\xda\xfa\xc2\x54\xa5\x52\x5e\x51\x51\x51\x51\x79\x5c\xc9\x7b\xcf\x04\x00"
  586.       "\x00\xf4\xdb\xf7\x07\xfd\x79\x67\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  587.       "\x00\x00\x00\x00\x00\x00\xfb\xd7\x6e\x7c\x9d\xd8\xe6\x98\x1b\xf9\x74\x15"
  588.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  589.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  590.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  591.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  592.       "\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"
  593.       "\x00\x00\x00\x00\xe0\x99\xbe\x0b\x00\x00\xff\xff\xf7\xa0\xd4\xed",
  594.       1204);
  595.   syz_mount_image(/*fs=*/0x20000040, /*dir=*/0x20000500,
  596.                   /*flags=MS_REC|MS_NOATIME|0x100*/ 0x4500, /*opts=*/0x20000540,
  597.                   /*chdir=*/0x12, /*size=*/0x4b4, /*img=*/0x20001b00);
  598.   syscall(__NR_open, /*file=*/0ul,
  599.           /*flags=O_SYNC|O_NONBLOCK|O_NOCTTY|O_NOATIME|O_DIRECT|O_CREAT|0x2002*/
  600.           0x147942ul, /*mode=*/0ul);
  601.   memcpy((void*)0x20000180, "./bus\000", 6);
  602.   syscall(__NR_open, /*file=*/0x20000180ul,
  603.           /*flags=O_TRUNC|O_SYNC|O_NOATIME|O_LARGEFILE|O_DIRECT|O_CREAT|0x3e*/
  604.           0x14d27eul, /*mode=*/0ul);
  605.   memcpy((void*)0x20000380, "/dev/loop", 9);
  606.   *(uint8_t*)0x20000389 = 0x30;
  607.   *(uint8_t*)0x2000038a = 0;
  608.   memcpy((void*)0x20000140, "./bus\000", 6);
  609.   syscall(__NR_mount, /*src=*/0x20000380ul, /*dst=*/0x20000140ul, /*type=*/0ul,
  610.           /*flags=MS_BIND*/ 0x1000ul, /*data=*/0ul);
  611.   memcpy((void*)0x20000400, "./bus\000", 6);
  612.   res = syscall(__NR_open, /*file=*/0x20000400ul,
  613.                 /*flags=O_SYNC|O_NOCTTY|O_NOATIME|O_RDWR|0x3c*/ 0x14113eul,
  614.                 /*mode=*/0ul);
  615.   if (res != -1)
  616.     r[0] = res;
  617.   syscall(__NR_write, /*fd=*/r[0], /*data=*/0x200001c0ul, /*len=*/0x208e24bul);
  618.   return 0;
  619. }
  620.  
Advertisement
Add Comment
Please, Sign In to add comment