From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.8 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id DCBCEC4727C for ; Thu, 1 Oct 2020 12:38:45 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 7F58021707 for ; Thu, 1 Oct 2020 12:38:45 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732058AbgJAMh5 (ORCPT ); Thu, 1 Oct 2020 08:37:57 -0400 Received: from youngberry.canonical.com ([91.189.89.112]:44554 "EHLO youngberry.canonical.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731993AbgJAMgc (ORCPT ); Thu, 1 Oct 2020 08:36:32 -0400 Received: from mail-ed1-f72.google.com ([209.85.208.72]) by youngberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1kNxov-0002NR-HV for bpf@vger.kernel.org; Thu, 01 Oct 2020 12:36:25 +0000 Received: by mail-ed1-f72.google.com with SMTP id n19so2116648eds.8 for ; Thu, 01 Oct 2020 05:36:25 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:content-transfer-encoding :in-reply-to; bh=pQLrcvtjwaxa29P29Fz05lhxl5sbodvi8xVJcSTTUgA=; b=r2n48LtIdZMdoeZWjCryDi3wAAVVuhzzMIIE+y8oGusVCiexAHCZt+kbSmQVjQhFXa UKBLLEhv4SlunfANxTLuiymf6zxhBoDJgyBqKWaptQVbYb0TSLGuRVcnEujAzZMDK+ep n1TbZjwgM2l2D2gpqqNneCtVcXovNj68ZgDUWTEhTyBqjViPq1nbYuLsZNHN/aOyaZ9o 7sKmEEG0VSih8WK2CUQzlGgtDP24cERqxj4L7BsvWidwSQOBCssx+O4V2ucEuKgkZ1yI B+HWg+yIAkItxyRFrtfVsqXFr6/22BhbmJ0KzffU1IF9QUajJJvc/P7LIns1qGiRvYSQ /5GA== X-Gm-Message-State: AOAM531hlgqQ7RGkCS3bG/94An+3+tcuEazAeaJwBYBApGsWLaHN9nfp 2q/fmfYxxwW/fr4dE9dUEGwPpVLf+RZORBqJrFdK9UrLbPStRhDDrxjefF+CQKUeqP/CEe/mmrl Mb3zjpj2iR/3XqaXwVsjq6K1JVOeDRw== X-Received: by 2002:aa7:dd01:: with SMTP id i1mr7978421edv.121.1601555784610; Thu, 01 Oct 2020 05:36:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyO0PuIPAj7CQqmD3gjlr7AX1vJKwoilsE2LbwS5ZRQWOzgWJ3pkDiEQo3Et4wi8YvUTuzNyQ== X-Received: by 2002:aa7:dd01:: with SMTP id i1mr7978359edv.121.1601555783896; Thu, 01 Oct 2020 05:36:23 -0700 (PDT) Received: from gmail.com ([176.32.19.8]) by smtp.gmail.com with ESMTPSA id r27sm3932646edx.33.2020.10.01.05.36.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 01 Oct 2020 05:36:23 -0700 (PDT) Date: Thu, 1 Oct 2020 14:36:19 +0200 From: Christian Brauner To: "Michael Kerrisk (man-pages)" Cc: Tycho Andersen , Sargun Dhillon , linux-man , Song Liu , wad@chromium.org, Kees Cook , Daniel Borkmann , Jann Horn , Robert Sesek , Linux Containers , lkml , Alexei Starovoitov , Giuseppe Scrivano , bpf@vger.kernel.org, Andy Lutomirski , Christian Brauner Subject: Re: For review: seccomp_user_notif(2) manual page Message-ID: <20201001123619.fdlk2xb56lej6rx3@gmail.com> References: <45f07f17-18b6-d187-0914-6f341fe90857@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <45f07f17-18b6-d187-0914-6f341fe90857@gmail.com> Precedence: bulk List-ID: X-Mailing-List: bpf@vger.kernel.org [I'm on vacation so I'll just give this a quick glance for now.] On Wed, Sep 30, 2020 at 01:07:38PM +0200, Michael Kerrisk (man-pages) wrote: > Hi Tycho, Sargun (and all), > > I knew it would be a big ask, but below is kind of the manual page > I was hoping you might write [1] for the seccomp user-space notification > mechanism. Since you didn't (and because 5.9 adds various new pieces > such as SECCOMP_ADDFD_FLAG_SETFD and SECCOMP_IOCTL_NOTIF_ADDFD > that also will need documenting [2]), I did :-). But of course I may > have made mistakes... > > I've shown the rendered version of the page below, and would love > to receive review comments from you and others, and acks, etc. > > There are a few FIXMEs sprinkled into the page, including one > that relates to what appears to me to be a misdesign (possibly > fixable) in the operation of the SECCOMP_IOCTL_NOTIF_RECV > operation. I would be especially interested in feedback on that > FIXME, and also of course the other FIXMEs. > > The page includes an extensive (albeit slightly contrived) > example program, and I would be happy also to receive comments > on that program. > > The page source currently sits in a branch (along with the text > that you sent me for the seccomp(2) page) at > https://git.kernel.org/pub/scm/docs/man-pages/man-pages.git/log/?h=seccomp_user_notif > > Thanks, > > Michael > > [1] https://lore.kernel.org/linux-man/2cea5fec-e73e-5749-18af-15c35a4bd23c@gmail.com/#t > [2] Sargun, can you prepare something on SECCOMP_ADDFD_FLAG_SETFD > and SECCOMP_IOCTL_NOTIF_ADDFD to be added to this page? > > ===== > > NAME > seccomp_user_notif - Seccomp user-space notification mechanism > > SYNOPSIS > #include > #include > #include > > int seccomp(unsigned int operation, unsigned int flags, void *args); > > DESCRIPTION > This page describes the user-space notification mechanism pro‐ > vided by the Secure Computing (seccomp) facility. As well as the > use of the SECCOMP_FILTER_FLAG_NEW_LISTENER flag, the SEC‐ > COMP_RET_USER_NOTIF action value, and the SECCOMP_GET_NOTIF_SIZES > operation described in seccomp(2), this mechanism involves the > use of a number of related ioctl(2) operations (described below). > > Overview > In conventional usage of a seccomp filter, the decision about how > to treat a particular system call is made by the filter itself. > The user-space notification mechanism allows the handling of the > system call to instead be handed off to a user-space process. "In contrast, the user notification mechanism allows to delegate the handling of the system call of one process (target) to another user-space process (supervisor)."? > The advantages of doing this are that, by contrast with the sec‐ > comp filter, which is running on a virtual machine inside the > kernel, the user-space process has access to information that is > unavailable to the seccomp filter and it can perform actions that > can't be performed from the seccomp filter. This section reads a bit difficult imho: "A suitably privileged supervisor can use the user notification mechanism to perform actions in lieu of the target. The supervisor will usually be able to retrieve information about the target and the performed system call that the seccomp filter itself cannot." > > In the discussion that follows, the process that has installed > the seccomp filter is referred to as the target, and the process > that is notified by the user-space notification mechanism is > referred to as the supervisor. An overview of the steps per‐ > formed by these two processes is as follows: > > 1. The target process establishes a seccomp filter in the usual > manner, but with two differences: > > · The seccomp(2) flags argument includes the flag SECCOMP_FIL‐ > TER_FLAG_NEW_LISTENER. Consequently, the return value of > the (successful) seccomp(2) call is a new "listening" file > descriptor that can be used to receive notifications. I think it would be good to mention that seccomp notify fds are O_CLOEXEC by default somewhere. > > · In cases where it is appropriate, the seccomp filter returns > the action value SECCOMP_RET_USER_NOTIF. This return value > will trigger a notification event. > > 2. In order that the supervisor process can obtain notifications > using the listening file descriptor, (a duplicate of) that > file descriptor must be passed from the target process to the > supervisor process. One way in which this could be done is by > passing the file descriptor over a UNIX domain socket connec‐ > tion between the two processes (using the SCM_RIGHTS ancillary > message type described in unix(7)). Another possibility is > that the supervisor might inherit the file descriptor via > fork(2). I think a few people have already pointed out other ways of retrieving an fd. :) > > 3. The supervisor process will receive notification events on the > listening file descriptor. These events are returned as > structures of type seccomp_notif. Because this structure and > its size may evolve over kernel versions, the supervisor must > first determine the size of this structure using the sec‐ > comp(2) SECCOMP_GET_NOTIF_SIZES operation, which returns a > structure of type seccomp_notif_sizes. The supervisor allo‐ > cates a buffer of size seccomp_notif_sizes.seccomp_notif bytes > to receive notification events. In addition,the supervisor > allocates another buffer of size seccomp_notif_sizes.sec‐ > comp_notif_resp bytes for the response (a struct sec‐ > comp_notif_resp structure) that it will provide to the kernel > (and thus the target process). > > 4. The target process then performs its workload, which includes > system calls that will be controlled by the seccomp filter. > Whenever one of these system calls causes the filter to return > the SECCOMP_RET_USER_NOTIF action value, the kernel does not > execute the system call; instead, execution of the target > process is temporarily blocked inside the kernel and a notifi‐ Maybe mention that the task is killable when so blocked? > cation event is generated on the listening file descriptor. > > 5. The supervisor process can now repeatedly monitor the listen‐ > ing file descriptor for SECCOMP_RET_USER_NOTIF-triggered > events. To do this, the supervisor uses the SEC‐ > COMP_IOCTL_NOTIF_RECV ioctl(2) operation to read information > about a notification event; this operation blocks until an > event is available. The operation returns a seccomp_notif > structure containing information about the system call that is > being attempted by the target process. > > 6. The seccomp_notif structure returned by the SEC‐ > COMP_IOCTL_NOTIF_RECV operation includes the same information > (a seccomp_data structure) that was passed to the seccomp fil‐ > ter. This information allows the supervisor to discover the > system call number and the arguments for the target process's > system call. In addition, the notification event contains the > PID of the target process. (Technically TID.) > > The information in the notification can be used to discover > the values of pointer arguments for the target process's sys‐ > tem call. (This is something that can't be done from within a > seccomp filter.) To do this (and assuming it has suitable > permissions), the supervisor opens the corresponding > /proc/[pid]/mem file, seeks to the memory location that corre‐ > sponds to one of the pointer arguments whose value is supplied > in the notification event, and reads bytes from that location. > (The supervisor must be careful to avoid a race condition that > can occur when doing this; see the description of the SEC‐ > COMP_IOCTL_NOTIF_ID_VALID ioctl(2) operation below.) In addi‐ > tion, the supervisor can access other system information that > is visible in user space but which is not accessible from a > seccomp filter. > > ┌─────────────────────────────────────────────────────┐ > │FIXME │ > ├─────────────────────────────────────────────────────┤ > │Suppose we are reading a pathname from /proc/PID/mem │ > │for a system call such as mkdir(). The pathname can │ > │be an arbitrary length. How do we know how much (how │ > │many pages) to read from /proc/PID/mem? │ > └─────────────────────────────────────────────────────┘ This has already been answered, I believe. > > 7. Having obtained information as per the previous step, the > supervisor may then choose to perform an action in response to > the target process's system call (which, as noted above, is > not executed when the seccomp filter returns the SEC‐ > COMP_RET_USER_NOTIF action value). Nit: It is not _yet_ executed it may very well be if the response is "continue". This should either mention that when the fd becomes _RECVable the system call is guaranteed to not have executed yet or specify that it is not yet executed, I think. > > One example use case here relates to containers. The target > process may be located inside a container where it does not > have sufficient capabilities to mount a filesystem in the con‐ > tainer's mount namespace. However, the supervisor may be a > more privileged process that that does have sufficient capa‐ > bilities to perform the mount operation. > > 8. The supervisor then sends a response to the notification. The > information in this response is used by the kernel to con‐ > struct a return value for the target process's system call and > provide a value that will be assigned to the errno variable of > the target process. > > The response is sent using the SECCOMP_IOCTL_NOTIF_RECV > ioctl(2) operation, which is used to transmit a sec‐ > comp_notif_resp structure to the kernel. This structure > includes a cookie value that the supervisor obtained in the > seccomp_notif structure returned by the SEC‐ > COMP_IOCTL_NOTIF_RECV operation. This cookie value allows the > kernel to associate the response with the target process. I think here or above you should mention that the id or "cookie" _must_ be used when a file descriptor to /proc//mem or any /proc//* is opened: fd = open(/proc/pid/*); verify_via_cookie_that_pid_still_alive(cookie); operate_on(fd) Otherwise this is a potential security issue. > > 9. Once the notification has been sent, the system call in the > target process unblocks, returning the information that was > provided by the supervisor in the notification response. > > As a variation on the last two steps, the supervisor can send a > response that tells the kernel that it should execute the target > process's system call; see the discussion of SEC‐ > COMP_USER_NOTIF_FLAG_CONTINUE, below. > > ioctl(2) operations > The following ioctl(2) operations are provided to support seccomp > user-space notification. For each of these operations, the first > (file descriptor) argument of ioctl(2) is the listening file > descriptor returned by a call to seccomp(2) with the SECCOMP_FIL‐ > TER_FLAG_NEW_LISTENER flag. > > SECCOMP_IOCTL_NOTIF_RECV > This operation is used to obtain a user-space notification > event. If no such event is currently pending, the opera‐ > tion blocks until an event occurs. The third ioctl(2) > argument is a pointer to a structure of the following form > which contains information about the event. This struc‐ > ture must be zeroed out before the call. > > struct seccomp_notif { > __u64 id; /* Cookie */ > __u32 pid; /* PID of target process */ > __u32 flags; /* Currently unused (0) */ > struct seccomp_data data; /* See seccomp(2) */ > }; > > The fields in this structure are as follows: > > id This is a cookie for the notification. Each such > cookie is guaranteed to be unique for the corre‐ > sponding seccomp filter. In other words, this > cookie is unique for each notification event from > the target process. The cookie value has the fol‐ > lowing uses: > > · It can be used with the SEC‐ > COMP_IOCTL_NOTIF_ID_VALID ioctl(2) operation to > verify that the target process is still alive. > > · When returning a notification response to the > kernel, the supervisor must include the cookie > value in the seccomp_notif_resp structure that is > specified as the argument of the SEC‐ > COMP_IOCTL_NOTIF_SEND operation. > > pid This is the PID of the target process that trig‐ > gered the notification event. > > ┌─────────────────────────────────────────────────────┐ > │FIXME │ > ├─────────────────────────────────────────────────────┤ > │This is a thread ID, rather than a PID, right? │ > └─────────────────────────────────────────────────────┘ Yes. > > flags This is a bit mask of flags providing further > information on the event. In the current implemen‐ > tation, this field is always zero. > > data This is a seccomp_data structure containing infor‐ > mation about the system call that triggered the > notification. This is the same structure that is > passed to the seccomp filter. See seccomp(2) for > details of this structure. > > On success, this operation returns 0; on failure, -1 is > returned, and errno is set to indicate the cause of the > error. This operation can fail with the following errors: > > EINVAL (since Linux 5.5) > The seccomp_notif structure that was passed to the > call contained nonzero fields. > > ENOENT The target process was killed by a signal as the > notification information was being generated. > > ┌─────────────────────────────────────────────────────┐ > │FIXME │ > ├─────────────────────────────────────────────────────┤ > │From my experiments, it appears that if a SEC‐ │ > │COMP_IOCTL_NOTIF_RECV is done after the target │ > │process terminates, then the ioctl() simply blocks │ > │(rather than returning an error to indicate that the │ > │target process no longer exists). │ > │ │ > │I found that surprising, and it required some con‐ │ > │tortions in the example program. It was not possi‐ │ > │ble to code my SIGCHLD handler (which reaps the zom‐ │ > │bie when the worker/target process terminates) to │ > │simply set a flag checked in the main handleNotifi‐ │ > │cations() loop, since this created an unavoidable │ > │race where the child might terminate just after I │ > │had checked the flag, but before I blocked (for‐ │ > │ever!) in the SECCOMP_IOCTL_NOTIF_RECV operation. │ > │Instead, I had to code the signal handler to simply │ > │call _exit(2) in order to terminate the parent │ > │process (the supervisor). │ > │ │ > │Is this expected behavior? It seems to me rather │ > │desirable that SECCOMP_IOCTL_NOTIF_RECV should give │ > │an error if the target process has terminated. │ > └─────────────────────────────────────────────────────┘ This has been discussed later in the thread too, I believe. My patchset fixed a different but related bug in ->poll() when a filter becomes unused. I hadn't noticed this behavior since I'm always polling. (Pure ioctls() feel a bit fishy to me. :) But obviously a valid use.) > > SECCOMP_IOCTL_NOTIF_ID_VALID > This operation can be used to check that a notification ID > returned by an earlier SECCOMP_IOCTL_NOTIF_RECV operation > is still valid (i.e., that the target process still > exists). > > The third ioctl(2) argument is a pointer to the cookie > (id) returned by the SECCOMP_IOCTL_NOTIF_RECV operation. > > This operation is necessary to avoid race conditions that > can occur when the pid returned by the SEC‐ > COMP_IOCTL_NOTIF_RECV operation terminates, and that > process ID is reused by another process. An example of > this kind of race is the following > > 1. A notification is generated on the listening file > descriptor. The returned seccomp_notif contains the > PID of the target process. > > 2. The target process terminates. > > 3. Another process is created on the system that by chance > reuses the PID that was freed when the target process > terminates. > > 4. The supervisor open(2)s the /proc/[pid]/mem file for > the PID obtained in step 1, with the intention of (say) > inspecting the memory locations that contains the argu‐ > ments of the system call that triggered the notifica‐ > tion in step 1. > > In the above scenario, the risk is that the supervisor may > try to access the memory of a process other than the tar‐ > get. This race can be avoided by following the call to > open with a SECCOMP_IOCTL_NOTIF_ID_VALID operation to ver‐ > ify that the process that generated the notification is > still alive. (Note that if the target process subse‐ > quently terminates, its PID won't be reused because there > remains an open reference to the /proc[pid]/mem file; in > this case, a subsequent read(2) from the file will return > 0, indicating end of file.) > > On success (i.e., the notification ID is still valid), > this operation returns 0 On failure (i.e., the notifica‐ Missing a ".", I think. > tion ID is no longer valid), -1 is returned, and errno is > set to ENOENT. > > SECCOMP_IOCTL_NOTIF_SEND > This operation is used to send a notification response > back to the kernel. The third ioctl(2) argument of this > structure is a pointer to a structure of the following > form: > > struct seccomp_notif_resp { > __u64 id; /* Cookie value */ > __s64 val; /* Success return value */ > __s32 error; /* 0 (success) or negative > error number */ > __u32 flags; /* See below */ > }; > > The fields of this structure are as follows: > > id This is the cookie value that was obtained using > the SECCOMP_IOCTL_NOTIF_RECV operation. This > cookie value allows the kernel to correctly asso‐ > ciate this response with the system call that trig‐ > gered the user-space notification. > > val This is the value that will be used for a spoofed > success return for the target process's system > call; see below. > > error This is the value that will be used as the error > number (errno) for a spoofed error return for the > target process's system call; see below. Nit: "val" is only used when "error" is not set. > > flags This is a bit mask that includes zero or more of > the following flags > > SECCOMP_USER_NOTIF_FLAG_CONTINUE (since Linux 5.5) > Tell the kernel to execute the target > process's system call. > > Two kinds of response are possible: > > · A response to the kernel telling it to execute the tar‐ > get process's system call. In this case, the flags > field includes SECCOMP_USER_NOTIF_FLAG_CONTINUE and the > error and val fields must be zero. > > This kind of response can be useful in cases where the > supervisor needs to do deeper analysis of the target's > system call than is possible from a seccomp filter > (e.g., examining the values of pointer arguments), and, > having verified that the system call is acceptable, the > supervisor wants to allow it to proceed. I think Jann has pointed this out. This needs to come with a big warning and I would explicitly put a: "The user notification mechanism cannot be used to implement a syscall security policy in user space!" You might want to take a look at the seccomp.h header file where I placed a giant warning about how to use this too. > > · A spoofed return value for the target process's system > call. In this case, the kernel does not execute the > target process's system call, instead causing the system > call to return a spoofed value as specified by fields of > the seccomp_notif_resp structure. The supervisor should > set the fields of this structure as follows: > > + flags does not contain SECCOMP_USER_NOTIF_FLAG_CON‐ > TINUE. > > + error is set either to 0 for a spoofed "success" > return or to a negative error number for a spoofed > "failure" return. In the former case, the kernel > causes the target process's system call to return the > value specified in the val field. In the later case, > the kernel causes the target process's system call to > return -1, and errno is assigned the negated error > value. > > + val is set to a value that will be used as the return > value for a spoofed "success" return for the target > process's system call. The value in this field is > ignored if the error field contains a nonzero value. > > On success, this operation returns 0; on failure, -1 is > returned, and errno is set to indicate the cause of the > error. This operation can fail with the following errors: > > EINPROGRESS > A response to this notification has already been > sent. > > EINVAL An invalid value was specified in the flags field. > > EINVAL The flags field contained SEC‐ > COMP_USER_NOTIF_FLAG_CONTINUE, and the error or val > field was not zero. > > ENOENT The blocked system call in the target process has > been interrupted by a signal handler. > > NOTES > The file descriptor returned when seccomp(2) is employed with the > SECCOMP_FILTER_FLAG_NEW_LISTENER flag can be monitored using > poll(2), epoll(7), and select(2). When a notification is pend‐ > ing, these interfaces indicate that the file descriptor is read‐ > able. This should also note that when a filter becomes unused, i.e. the last task using that filter in its filter hierarchy is dead (been reaped/autoreaped) ->poll() will notify with (E)POLLHUP. > > ┌─────────────────────────────────────────────────────┐ > │FIXME │ > ├─────────────────────────────────────────────────────┤ > │Interestingly, after the event had been received, │ > │the file descriptor indicates as writable (verified │ > │from the source code and by experiment). How is this │ > │useful? │ > └─────────────────────────────────────────────────────┘ > > EXAMPLES > The (somewhat contrived) program shown below demonstrates the use > of the interfaces described in this page. The program creates a > child process that serves as the "target" process. The child > process installs a seccomp filter that returns the SEC‐ > COMP_RET_USER_NOTIF action value if a call is made to mkdir(2). > The child process then calls mkdir(2) once for each of the sup‐ > plied command-line arguments, and reports the result returned by > the call. After processing all arguments, the child process ter‐ > minates. > > The parent process acts as the supervisor, listening for the > notifications that are generated when the target process calls > mkdir(2). When such a notification occurs, the supervisor exam‐ > ines the memory of the target process (using /proc/[pid]/mem) to > discover the pathname argument that was supplied to the mkdir(2) > call, and performs one of the following actions: > > · If the pathname begins with the prefix "/tmp/", then the super‐ > visor attempts to create the specified directory, and then > spoofs a return for the target process based on the return > value of the supervisor's mkdir(2) call. In the event that > that call succeeds, the spoofed success return value is the > length of the pathname. > > · If the pathname begins with "./" (i.e., it is a relative path‐ > name), the supervisor sends a SECCOMP_USER_NOTIF_FLAG_CONTINUE > response to the kernel to say that kernel should execute the > target process's mkdir(2) call. Potentially problematic if the two processes have the same privilege level and the supervisor intends _CONTINUE to mean "is safe to execute". An attacker could try to re-write arguments afaict. A good an easy example is usually mknod() in a user namespace. A _CONTINUE is always safe since you can't create device nodes anyway. Sorry, I can't review the rest in sufficient detail since I'm on vacation still so I'm just going to shut up now. :) Christian From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.7 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,MENTIONS_GIT_HOSTING, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id E9D37C4727C for ; Thu, 1 Oct 2020 12:36:36 +0000 (UTC) Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 1A586208B6 for ; Thu, 1 Oct 2020 12:36:35 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 1A586208B6 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=canonical.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=containers-bounces@lists.linux-foundation.org Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 7EBBA2049B; Thu, 1 Oct 2020 12:36:35 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WxZncSTuB0Yz; Thu, 1 Oct 2020 12:36:31 +0000 (UTC) Received: from lists.linuxfoundation.org (lf-lists.osuosl.org [140.211.9.56]) by silver.osuosl.org (Postfix) with ESMTP id 7B22F20497; Thu, 1 Oct 2020 12:36:31 +0000 (UTC) Received: from lf-lists.osuosl.org (localhost [127.0.0.1]) by lists.linuxfoundation.org (Postfix) with ESMTP id 62CDDC0889; Thu, 1 Oct 2020 12:36:31 +0000 (UTC) Received: from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137]) by lists.linuxfoundation.org (Postfix) with ESMTP id 524F0C0051 for ; Thu, 1 Oct 2020 12:36:30 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by fraxinus.osuosl.org (Postfix) with ESMTP id 3F0BE86C82 for ; Thu, 1 Oct 2020 12:36:30 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from fraxinus.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id to6i-89U9YL3 for ; Thu, 1 Oct 2020 12:36:28 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from youngberry.canonical.com (youngberry.canonical.com [91.189.89.112]) by fraxinus.osuosl.org (Postfix) with ESMTPS id BCF1F86C7A for ; Thu, 1 Oct 2020 12:36:27 +0000 (UTC) Received: from mail-ej1-f70.google.com ([209.85.218.70]) by youngberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1kNxov-0002NQ-Gt for containers@lists.linux-foundation.org; Thu, 01 Oct 2020 12:36:25 +0000 Received: by mail-ej1-f70.google.com with SMTP id f17so2198954ejq.5 for ; Thu, 01 Oct 2020 05:36:25 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:content-transfer-encoding :in-reply-to; bh=pQLrcvtjwaxa29P29Fz05lhxl5sbodvi8xVJcSTTUgA=; b=Sl1S51zdrIDtQjqEPVu8CPyIoFZafBFTLhFmq2Y3pMSIEtCZGRkg27iiNLE34mXxrX ghngcL1qIfWpSLNEK9q+FQzaJVbOjf4BW5J8npoXja+lKzdUzpnpXclDooTXUZ7O+yq1 RKVWBwVSDLZ9EO80q7aEGOfrYH6P0FRo9Rv1Y7lg8REGkIsigL92zoumYuDSxT2HPYew L7Q1l04aSwDYdR2f9lF0oI14G2BXYTeYMp0axeEw4DCvxVIiyA515ggnWmI+bZ++ARwB LoZwzW47ulYP6jBzx3lZqBH2fQ20ANKowQ4yvlqHxsk2+qH2XCRq9rbHFHyYuwUCOO6m CvrQ== X-Gm-Message-State: AOAM531ezQn7Pn7mLjfbLMve4VbaWU5GoYtAh2iqitkGVj0qUQbfbx01 +J1+i3OdmTQJVkjeKFu4xiTiAEZAVCZ5cpg3WvfBOWH+qG7EPDvNwSWNUeBJX+Xo8iIbqMuytQ1 SOUIuKCyLB73dboCP6Y7lKtoXqKiN/Zk0GlbMUe4njsp/34xfFXiwbQ== X-Received: by 2002:aa7:dd01:: with SMTP id i1mr7978423edv.121.1601555784611; Thu, 01 Oct 2020 05:36:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyO0PuIPAj7CQqmD3gjlr7AX1vJKwoilsE2LbwS5ZRQWOzgWJ3pkDiEQo3Et4wi8YvUTuzNyQ== X-Received: by 2002:aa7:dd01:: with SMTP id i1mr7978359edv.121.1601555783896; Thu, 01 Oct 2020 05:36:23 -0700 (PDT) Received: from gmail.com ([176.32.19.8]) by smtp.gmail.com with ESMTPSA id r27sm3932646edx.33.2020.10.01.05.36.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 01 Oct 2020 05:36:23 -0700 (PDT) Date: Thu, 1 Oct 2020 14:36:19 +0200 From: Christian Brauner To: "Michael Kerrisk (man-pages)" Subject: Re: For review: seccomp_user_notif(2) manual page Message-ID: <20201001123619.fdlk2xb56lej6rx3@gmail.com> References: <45f07f17-18b6-d187-0914-6f341fe90857@gmail.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <45f07f17-18b6-d187-0914-6f341fe90857@gmail.com> Cc: linux-man , Song Liu , wad@chromium.org, Kees Cook , Daniel Borkmann , Jann Horn , Robert Sesek , Linux Containers , lkml , Alexei Starovoitov , Giuseppe Scrivano , bpf@vger.kernel.org, Andy Lutomirski , Christian Brauner X-BeenThere: containers@lists.linux-foundation.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: Linux Containers List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: containers-bounces@lists.linux-foundation.org Sender: "Containers" W0knbSBvbiB2YWNhdGlvbiBzbyBJJ2xsIGp1c3QgZ2l2ZSB0aGlzIGEgcXVpY2sgZ2xhbmNlIGZv ciBub3cuXQoKT24gV2VkLCBTZXAgMzAsIDIwMjAgYXQgMDE6MDc6MzhQTSArMDIwMCwgTWljaGFl bCBLZXJyaXNrIChtYW4tcGFnZXMpIHdyb3RlOgo+IEhpIFR5Y2hvLCBTYXJndW4gKGFuZCBhbGwp LAo+IAo+IEkga25ldyBpdCB3b3VsZCBiZSBhIGJpZyBhc2ssIGJ1dCBiZWxvdyBpcyBraW5kIG9m IHRoZSBtYW51YWwgcGFnZQo+IEkgd2FzIGhvcGluZyB5b3UgbWlnaHQgd3JpdGUgWzFdIGZvciB0 aGUgc2VjY29tcCB1c2VyLXNwYWNlIG5vdGlmaWNhdGlvbgo+IG1lY2hhbmlzbS4gU2luY2UgeW91 IGRpZG4ndCAoYW5kIGJlY2F1c2UgNS45IGFkZHMgdmFyaW91cyBuZXcgcGllY2VzIAo+IHN1Y2gg YXMgU0VDQ09NUF9BRERGRF9GTEFHX1NFVEZEIGFuZCBTRUNDT01QX0lPQ1RMX05PVElGX0FEREZE IAo+IHRoYXQgYWxzbyB3aWxsIG5lZWQgZG9jdW1lbnRpbmcgWzJdKSwgSSBkaWQgOi0pLiBCdXQg b2YgY291cnNlIEkgbWF5IAo+IGhhdmUgbWFkZSBtaXN0YWtlcy4uLgo+IAo+IEkndmUgc2hvd24g dGhlIHJlbmRlcmVkIHZlcnNpb24gb2YgdGhlIHBhZ2UgYmVsb3csIGFuZCB3b3VsZCBsb3ZlCj4g dG8gcmVjZWl2ZSByZXZpZXcgY29tbWVudHMgZnJvbSB5b3UgYW5kIG90aGVycywgYW5kIGFja3Ms IGV0Yy4KPiAKPiBUaGVyZSBhcmUgYSBmZXcgRklYTUVzIHNwcmlua2xlZCBpbnRvIHRoZSBwYWdl LCBpbmNsdWRpbmcgb25lCj4gdGhhdCByZWxhdGVzIHRvIHdoYXQgYXBwZWFycyB0byBtZSB0byBi ZSBhIG1pc2Rlc2lnbiAocG9zc2libHkgCj4gZml4YWJsZSkgaW4gdGhlIG9wZXJhdGlvbiBvZiB0 aGUgU0VDQ09NUF9JT0NUTF9OT1RJRl9SRUNWIAo+IG9wZXJhdGlvbi4gSSB3b3VsZCBiZSBlc3Bl Y2lhbGx5IGludGVyZXN0ZWQgaW4gZmVlZGJhY2sgb24gdGhhdAo+IEZJWE1FLCBhbmQgYWxzbyBv ZiBjb3Vyc2UgdGhlIG90aGVyIEZJWE1Fcy4KPiAKPiBUaGUgcGFnZSBpbmNsdWRlcyBhbiBleHRl bnNpdmUgKGFsYmVpdCBzbGlnaHRseSBjb250cml2ZWQpCj4gZXhhbXBsZSBwcm9ncmFtLCBhbmQg SSB3b3VsZCBiZSBoYXBweSBhbHNvIHRvIHJlY2VpdmUgY29tbWVudHMKPiBvbiB0aGF0IHByb2dy YW0uCj4gCj4gVGhlIHBhZ2Ugc291cmNlIGN1cnJlbnRseSBzaXRzIGluIGEgYnJhbmNoIChhbG9u ZyB3aXRoIHRoZSB0ZXh0Cj4gdGhhdCB5b3Ugc2VudCBtZSBmb3IgdGhlIHNlY2NvbXAoMikgcGFn ZSkgYXQKPiBodHRwczovL2dpdC5rZXJuZWwub3JnL3B1Yi9zY20vZG9jcy9tYW4tcGFnZXMvbWFu LXBhZ2VzLmdpdC9sb2cvP2g9c2VjY29tcF91c2VyX25vdGlmCj4gCj4gVGhhbmtzLAo+IAo+IE1p Y2hhZWwKPiAKPiBbMV0gaHR0cHM6Ly9sb3JlLmtlcm5lbC5vcmcvbGludXgtbWFuLzJjZWE1ZmVj LWU3M2UtNTc0OS0xOGFmLTE1YzM1YTRiZDIzY0BnbWFpbC5jb20vI3QKPiBbMl0gU2FyZ3VuLCBj YW4geW91IHByZXBhcmUgc29tZXRoaW5nIG9uIFNFQ0NPTVBfQURERkRfRkxBR19TRVRGRAo+ICAg ICBhbmQgU0VDQ09NUF9JT0NUTF9OT1RJRl9BRERGRCB0byBiZSBhZGRlZCB0byB0aGlzIHBhZ2U/ Cj4gCj4gPT09PT0KPiAKPiBOQU1FCj4gICAgICAgIHNlY2NvbXBfdXNlcl9ub3RpZiAtIFNlY2Nv bXAgdXNlci1zcGFjZSBub3RpZmljYXRpb24gbWVjaGFuaXNtCj4gCj4gU1lOT1BTSVMKPiAgICAg ICAgI2luY2x1ZGUgPGxpbnV4L3NlY2NvbXAuaD4KPiAgICAgICAgI2luY2x1ZGUgPGxpbnV4L2Zp bHRlci5oPgo+ICAgICAgICAjaW5jbHVkZSA8bGludXgvYXVkaXQuaD4KPiAKPiAgICAgICAgaW50 IHNlY2NvbXAodW5zaWduZWQgaW50IG9wZXJhdGlvbiwgdW5zaWduZWQgaW50IGZsYWdzLCB2b2lk ICphcmdzKTsKPiAKPiBERVNDUklQVElPTgo+ICAgICAgICBUaGlzICBwYWdlICBkZXNjcmliZXMg IHRoZSB1c2VyLXNwYWNlIG5vdGlmaWNhdGlvbiBtZWNoYW5pc20gcHJv4oCQCj4gICAgICAgIHZp ZGVkIGJ5IHRoZSBTZWN1cmUgQ29tcHV0aW5nIChzZWNjb21wKSBmYWNpbGl0eS4gIEFzIHdlbGwg YXMgdGhlCj4gICAgICAgIHVzZSAgIG9mICB0aGUgIFNFQ0NPTVBfRklMVEVSX0ZMQUdfTkVXX0xJ U1RFTkVSICBmbGFnLCAgdGhlICBTRUPigJAKPiAgICAgICAgQ09NUF9SRVRfVVNFUl9OT1RJRiBh Y3Rpb24gdmFsdWUsIGFuZCB0aGUgU0VDQ09NUF9HRVRfTk9USUZfU0laRVMKPiAgICAgICAgb3Bl cmF0aW9uICBkZXNjcmliZWQgIGluICBzZWNjb21wKDIpLCB0aGlzIG1lY2hhbmlzbSBpbnZvbHZl cyB0aGUKPiAgICAgICAgdXNlIG9mIGEgbnVtYmVyIG9mIHJlbGF0ZWQgaW9jdGwoMikgb3BlcmF0 aW9ucyAoZGVzY3JpYmVkIGJlbG93KS4KPiAKPiAgICBPdmVydmlldwo+ICAgICAgICBJbiBjb252 ZW50aW9uYWwgdXNhZ2Ugb2YgYSBzZWNjb21wIGZpbHRlciwgdGhlIGRlY2lzaW9uIGFib3V0IGhv dwo+ICAgICAgICB0byAgdHJlYXQgIGEgcGFydGljdWxhciBzeXN0ZW0gY2FsbCBpcyBtYWRlIGJ5 IHRoZSBmaWx0ZXIgaXRzZWxmLgo+ICAgICAgICBUaGUgdXNlci1zcGFjZSBub3RpZmljYXRpb24g bWVjaGFuaXNtIGFsbG93cyB0aGUgaGFuZGxpbmcgb2YgIHRoZQo+ICAgICAgICBzeXN0ZW0gIGNh bGwgIHRvICBpbnN0ZWFkICBiZSBoYW5kZWQgb2ZmIHRvIGEgdXNlci1zcGFjZSBwcm9jZXNzLgoK IkluIGNvbnRyYXN0LCB0aGUgdXNlciBub3RpZmljYXRpb24gbWVjaGFuaXNtIGFsbG93cyB0byBk ZWxlZ2F0ZSB0aGUKaGFuZGxpbmcgb2YgdGhlIHN5c3RlbSBjYWxsIG9mIG9uZSBwcm9jZXNzICh0 YXJnZXQpIHRvIGFub3RoZXIKdXNlci1zcGFjZSBwcm9jZXNzIChzdXBlcnZpc29yKS4iPwoKPiAg ICAgICAgVGhlIGFkdmFudGFnZXMgb2YgZG9pbmcgdGhpcyBhcmUgdGhhdCwgYnkgY29udHJhc3Qg d2l0aCB0aGUgIHNlY+KAkAo+ICAgICAgICBjb21wICBmaWx0ZXIsICB3aGljaCAgaXMgIHJ1bm5p bmcgb24gYSB2aXJ0dWFsIG1hY2hpbmUgaW5zaWRlIHRoZQo+ICAgICAgICBrZXJuZWwsIHRoZSB1 c2VyLXNwYWNlIHByb2Nlc3MgaGFzIGFjY2VzcyB0byBpbmZvcm1hdGlvbiB0aGF0ICBpcwo+ICAg ICAgICB1bmF2YWlsYWJsZSB0byB0aGUgc2VjY29tcCBmaWx0ZXIgYW5kIGl0IGNhbiBwZXJmb3Jt IGFjdGlvbnMgdGhhdAo+ICAgICAgICBjYW4ndCBiZSBwZXJmb3JtZWQgZnJvbSB0aGUgc2VjY29t cCBmaWx0ZXIuCgpUaGlzIHNlY3Rpb24gcmVhZHMgYSBiaXQgZGlmZmljdWx0IGltaG86CiJBIHN1 aXRhYmx5IHByaXZpbGVnZWQgc3VwZXJ2aXNvciBjYW4gdXNlIHRoZSB1c2VyIG5vdGlmaWNhdGlv bgptZWNoYW5pc20gdG8gcGVyZm9ybSBhY3Rpb25zIGluIGxpZXUgb2YgdGhlIHRhcmdldC4gVGhl IHN1cGVydmlzb3Igd2lsbAp1c3VhbGx5IGJlIGFibGUgdG8gcmV0cmlldmUgaW5mb3JtYXRpb24g YWJvdXQgdGhlIHRhcmdldCBhbmQgdGhlCnBlcmZvcm1lZCBzeXN0ZW0gY2FsbCB0aGF0IHRoZSBz ZWNjb21wIGZpbHRlciBpdHNlbGYgY2Fubm90LiIKCj4gCj4gICAgICAgIEluIHRoZSBkaXNjdXNz aW9uIHRoYXQgZm9sbG93cywgdGhlIHByb2Nlc3MgIHRoYXQgIGhhcyAgaW5zdGFsbGVkCj4gICAg ICAgIHRoZSAgc2VjY29tcCBmaWx0ZXIgaXMgcmVmZXJyZWQgdG8gYXMgdGhlIHRhcmdldCwgYW5k IHRoZSBwcm9jZXNzCj4gICAgICAgIHRoYXQgaXMgbm90aWZpZWQgYnkgIHRoZSAgdXNlci1zcGFj ZSAgbm90aWZpY2F0aW9uICBtZWNoYW5pc20gIGlzCj4gICAgICAgIHJlZmVycmVkICB0byAgYXMg IHRoZSAgc3VwZXJ2aXNvci4gIEFuIG92ZXJ2aWV3IG9mIHRoZSBzdGVwcyBwZXLigJAKPiAgICAg ICAgZm9ybWVkIGJ5IHRoZXNlIHR3byBwcm9jZXNzZXMgaXMgYXMgZm9sbG93czoKPiAKPiAgICAg ICAgMS4gVGhlIHRhcmdldCBwcm9jZXNzIGVzdGFibGlzaGVzIGEgc2VjY29tcCBmaWx0ZXIgaW4g IHRoZSAgdXN1YWwKPiAgICAgICAgICAgbWFubmVyLCBidXQgd2l0aCB0d28gZGlmZmVyZW5jZXM6 Cj4gCj4gICAgICAgICAgIMK3IFRoZSBzZWNjb21wKDIpIGZsYWdzIGFyZ3VtZW50IGluY2x1ZGVz IHRoZSBmbGFnIFNFQ0NPTVBfRklM4oCQCj4gICAgICAgICAgICAgVEVSX0ZMQUdfTkVXX0xJU1RF TkVSLiAgQ29uc2VxdWVudGx5LCB0aGUgcmV0dXJuICB2YWx1ZSAgIG9mCj4gICAgICAgICAgICAg dGhlICAoc3VjY2Vzc2Z1bCkgIHNlY2NvbXAoMikgY2FsbCBpcyBhIG5ldyAibGlzdGVuaW5nIiBm aWxlCj4gICAgICAgICAgICAgZGVzY3JpcHRvciB0aGF0IGNhbiBiZSB1c2VkIHRvIHJlY2VpdmUg bm90aWZpY2F0aW9ucy4KCkkgdGhpbmsgaXQgd291bGQgYmUgZ29vZCB0byBtZW50aW9uIHRoYXQg c2VjY29tcCBub3RpZnkgZmRzIGFyZQpPX0NMT0VYRUMgYnkgZGVmYXVsdCBzb21ld2hlcmUuCgo+ IAo+ICAgICAgICAgICDCtyBJbiBjYXNlcyB3aGVyZSBpdCBpcyBhcHByb3ByaWF0ZSwgdGhlIHNl Y2NvbXAgZmlsdGVyIHJldHVybnMKPiAgICAgICAgICAgICB0aGUgIGFjdGlvbiB2YWx1ZSBTRUND T01QX1JFVF9VU0VSX05PVElGLiAgVGhpcyByZXR1cm4gdmFsdWUKPiAgICAgICAgICAgICB3aWxs IHRyaWdnZXIgYSBub3RpZmljYXRpb24gZXZlbnQuCj4gCj4gICAgICAgIDIuIEluIG9yZGVyIHRo YXQgdGhlIHN1cGVydmlzb3IgcHJvY2VzcyBjYW4gb2J0YWluICBub3RpZmljYXRpb25zCj4gICAg ICAgICAgIHVzaW5nICB0aGUgIGxpc3RlbmluZyAgZmlsZSAgZGVzY3JpcHRvciwgKGEgZHVwbGlj YXRlIG9mKSB0aGF0Cj4gICAgICAgICAgIGZpbGUgZGVzY3JpcHRvciBtdXN0IGJlIHBhc3NlZCBm cm9tIHRoZSB0YXJnZXQgcHJvY2VzcyB0byAgdGhlCj4gICAgICAgICAgIHN1cGVydmlzb3IgcHJv Y2Vzcy4gIE9uZSB3YXkgaW4gd2hpY2ggdGhpcyBjb3VsZCBiZSBkb25lIGlzIGJ5Cj4gICAgICAg ICAgIHBhc3NpbmcgdGhlIGZpbGUgZGVzY3JpcHRvciBvdmVyIGEgVU5JWCBkb21haW4gc29ja2V0 ICBjb25uZWPigJAKPiAgICAgICAgICAgdGlvbiBiZXR3ZWVuIHRoZSB0d28gcHJvY2Vzc2VzICh1 c2luZyB0aGUgU0NNX1JJR0hUUyBhbmNpbGxhcnkKPiAgICAgICAgICAgbWVzc2FnZSB0eXBlIGRl c2NyaWJlZCBpbiB1bml4KDcpKS4gICBBbm90aGVyICBwb3NzaWJpbGl0eSAgaXMKPiAgICAgICAg ICAgdGhhdCAgdGhlICBzdXBlcnZpc29yICBtaWdodCAgaW5oZXJpdCAgdGhlIGZpbGUgZGVzY3Jp cHRvciB2aWEKPiAgICAgICAgICAgZm9yaygyKS4KCkkgdGhpbmsgYSBmZXcgcGVvcGxlIGhhdmUg YWxyZWFkeSBwb2ludGVkIG91dCBvdGhlciB3YXlzIG9mIHJldHJpZXZpbmcKYW4gZmQuIDopCgo+ IAo+ICAgICAgICAzLiBUaGUgc3VwZXJ2aXNvciBwcm9jZXNzIHdpbGwgcmVjZWl2ZSBub3RpZmlj YXRpb24gZXZlbnRzIG9uIHRoZQo+ICAgICAgICAgICBsaXN0ZW5pbmcgIGZpbGUgIGRlc2NyaXB0 b3IuICAgVGhlc2UgIGV2ZW50cyAgYXJlICByZXR1cm5lZCBhcwo+ICAgICAgICAgICBzdHJ1Y3R1 cmVzIG9mIHR5cGUgc2VjY29tcF9ub3RpZi4gIEJlY2F1c2UgdGhpcyBzdHJ1Y3R1cmUgIGFuZAo+ ICAgICAgICAgICBpdHMgIHNpemUgbWF5IGV2b2x2ZSBvdmVyIGtlcm5lbCB2ZXJzaW9ucywgdGhl IHN1cGVydmlzb3IgbXVzdAo+ICAgICAgICAgICBmaXJzdCBkZXRlcm1pbmUgdGhlIHNpemUgb2Yg IHRoaXMgIHN0cnVjdHVyZSAgdXNpbmcgIHRoZSAgc2Vj4oCQCj4gICAgICAgICAgIGNvbXAoMikg IFNFQ0NPTVBfR0VUX05PVElGX1NJWkVTICBvcGVyYXRpb24sICB3aGljaCAgcmV0dXJucyBhCj4g ICAgICAgICAgIHN0cnVjdHVyZSBvZiB0eXBlIHNlY2NvbXBfbm90aWZfc2l6ZXMuICBUaGUgIHN1 cGVydmlzb3IgIGFsbG/igJAKPiAgICAgICAgICAgY2F0ZXMgYSBidWZmZXIgb2Ygc2l6ZSBzZWNj b21wX25vdGlmX3NpemVzLnNlY2NvbXBfbm90aWYgYnl0ZXMKPiAgICAgICAgICAgdG8gcmVjZWl2 ZSBub3RpZmljYXRpb24gZXZlbnRzLiAgIEluICBhZGRpdGlvbix0aGUgIHN1cGVydmlzb3IKPiAg ICAgICAgICAgYWxsb2NhdGVzICBhbm90aGVyICBidWZmZXIgIG9mICBzaXplICBzZWNjb21wX25v dGlmX3NpemVzLnNlY+KAkAo+ICAgICAgICAgICBjb21wX25vdGlmX3Jlc3AgIGJ5dGVzICBmb3Ig IHRoZSAgcmVzcG9uc2UgIChhICAgc3RydWN0ICAgc2Vj4oCQCj4gICAgICAgICAgIGNvbXBfbm90 aWZfcmVzcCAgc3RydWN0dXJlKSB0aGF0IGl0IHdpbGwgcHJvdmlkZSB0byB0aGUga2VybmVsCj4g ICAgICAgICAgIChhbmQgdGh1cyB0aGUgdGFyZ2V0IHByb2Nlc3MpLgo+IAo+ICAgICAgICA0LiBU aGUgdGFyZ2V0IHByb2Nlc3MgdGhlbiBwZXJmb3JtcyBpdHMgd29ya2xvYWQsIHdoaWNoICBpbmNs dWRlcwo+ICAgICAgICAgICBzeXN0ZW0gIGNhbGxzICB0aGF0ICB3aWxsIGJlIGNvbnRyb2xsZWQg YnkgdGhlIHNlY2NvbXAgZmlsdGVyLgo+ICAgICAgICAgICBXaGVuZXZlciBvbmUgb2YgdGhlc2Ug c3lzdGVtIGNhbGxzIGNhdXNlcyB0aGUgZmlsdGVyIHRvIHJldHVybgo+ICAgICAgICAgICB0aGUg IFNFQ0NPTVBfUkVUX1VTRVJfTk9USUYgIGFjdGlvbiB2YWx1ZSwgdGhlIGtlcm5lbCBkb2VzIG5v dAo+ICAgICAgICAgICBleGVjdXRlIHRoZSBzeXN0ZW0gY2FsbDsgIGluc3RlYWQsICBleGVjdXRp b24gIG9mICB0aGUgIHRhcmdldAo+ICAgICAgICAgICBwcm9jZXNzIGlzIHRlbXBvcmFyaWx5IGJs b2NrZWQgaW5zaWRlIHRoZSBrZXJuZWwgYW5kIGEgbm90aWZp4oCQCgpNYXliZSBtZW50aW9uIHRo YXQgdGhlIHRhc2sgaXMga2lsbGFibGUgd2hlbiBzbyBibG9ja2VkPwoKPiAgICAgICAgICAgY2F0 aW9uIGV2ZW50IGlzIGdlbmVyYXRlZCBvbiB0aGUgbGlzdGVuaW5nIGZpbGUgZGVzY3JpcHRvci4K PiAKPiAgICAgICAgNS4gVGhlIHN1cGVydmlzb3IgcHJvY2VzcyBjYW4gbm93IHJlcGVhdGVkbHkg bW9uaXRvciB0aGUgIGxpc3RlbuKAkAo+ICAgICAgICAgICBpbmcgICBmaWxlICAgZGVzY3JpcHRv ciAgZm9yICBTRUNDT01QX1JFVF9VU0VSX05PVElGLXRyaWdnZXJlZAo+ICAgICAgICAgICBldmVu dHMuICAgVG8gIGRvICB0aGlzLCAgIHRoZSAgIHN1cGVydmlzb3IgICB1c2VzICAgdGhlICAgU0VD 4oCQCj4gICAgICAgICAgIENPTVBfSU9DVExfTk9USUZfUkVDViAgaW9jdGwoMikgIG9wZXJhdGlv biB0byByZWFkIGluZm9ybWF0aW9uCj4gICAgICAgICAgIGFib3V0IGEgbm90aWZpY2F0aW9uIGV2 ZW50OyB0aGlzICBvcGVyYXRpb24gIGJsb2NrcyAgdW50aWwgIGFuCj4gICAgICAgICAgIGV2ZW50 ICBpcyAgYXZhaWxhYmxlLiAgIFRoZSAgb3BlcmF0aW9uIHJldHVybnMgYSBzZWNjb21wX25vdGlm Cj4gICAgICAgICAgIHN0cnVjdHVyZSBjb250YWluaW5nIGluZm9ybWF0aW9uIGFib3V0IHRoZSBz eXN0ZW0gY2FsbCB0aGF0IGlzCj4gICAgICAgICAgIGJlaW5nIGF0dGVtcHRlZCBieSB0aGUgdGFy Z2V0IHByb2Nlc3MuCj4gCj4gICAgICAgIDYuIFRoZSAgICBzZWNjb21wX25vdGlmICAgIHN0cnVj dHVyZSAgIHJldHVybmVkICAgYnkgICB0aGUgICBTRUPigJAKPiAgICAgICAgICAgQ09NUF9JT0NU TF9OT1RJRl9SRUNWIG9wZXJhdGlvbiBpbmNsdWRlcyB0aGUgc2FtZSAgaW5mb3JtYXRpb24KPiAg ICAgICAgICAgKGEgc2VjY29tcF9kYXRhIHN0cnVjdHVyZSkgdGhhdCB3YXMgcGFzc2VkIHRvIHRo ZSBzZWNjb21wIGZpbOKAkAo+ICAgICAgICAgICB0ZXIuICBUaGlzIGluZm9ybWF0aW9uIGFsbG93 cyB0aGUgc3VwZXJ2aXNvciB0byAgZGlzY292ZXIgIHRoZQo+ICAgICAgICAgICBzeXN0ZW0gIGNh bGwgbnVtYmVyIGFuZCB0aGUgYXJndW1lbnRzIGZvciB0aGUgdGFyZ2V0IHByb2Nlc3Mncwo+ICAg ICAgICAgICBzeXN0ZW0gY2FsbC4gIEluIGFkZGl0aW9uLCB0aGUgbm90aWZpY2F0aW9uIGV2ZW50 IGNvbnRhaW5zIHRoZQo+ICAgICAgICAgICBQSUQgb2YgdGhlIHRhcmdldCBwcm9jZXNzLgoKKFRl Y2huaWNhbGx5IFRJRC4pCgo+IAo+ICAgICAgICAgICBUaGUgIGluZm9ybWF0aW9uICBpbiAgdGhl IG5vdGlmaWNhdGlvbiBjYW4gYmUgdXNlZCB0byBkaXNjb3Zlcgo+ICAgICAgICAgICB0aGUgdmFs dWVzIG9mIHBvaW50ZXIgYXJndW1lbnRzIGZvciB0aGUgdGFyZ2V0IHByb2Nlc3MncyAgc3lz4oCQ Cj4gICAgICAgICAgIHRlbSBjYWxsLiAgKFRoaXMgaXMgc29tZXRoaW5nIHRoYXQgY2FuJ3QgYmUg ZG9uZSBmcm9tIHdpdGhpbiBhCj4gICAgICAgICAgIHNlY2NvbXAgZmlsdGVyLikgIFRvIGRvIHRo aXMgKGFuZCAgYXNzdW1pbmcgIGl0ICBoYXMgIHN1aXRhYmxlCj4gICAgICAgICAgIHBlcm1pc3Np b25zKSwgICB0aGUgICBzdXBlcnZpc29yICAgb3BlbnMgICB0aGUgICBjb3JyZXNwb25kaW5nCj4g ICAgICAgICAgIC9wcm9jL1twaWRdL21lbSBmaWxlLCBzZWVrcyB0byB0aGUgbWVtb3J5IGxvY2F0 aW9uIHRoYXQgY29ycmXigJAKPiAgICAgICAgICAgc3BvbmRzIHRvIG9uZSBvZiB0aGUgcG9pbnRl ciBhcmd1bWVudHMgd2hvc2UgdmFsdWUgaXMgc3VwcGxpZWQKPiAgICAgICAgICAgaW4gdGhlIG5v dGlmaWNhdGlvbiBldmVudCwgYW5kIHJlYWRzIGJ5dGVzIGZyb20gdGhhdCBsb2NhdGlvbi4KPiAg ICAgICAgICAgKFRoZSBzdXBlcnZpc29yIG11c3QgYmUgY2FyZWZ1bCB0byBhdm9pZCBhIHJhY2Ug Y29uZGl0aW9uIHRoYXQKPiAgICAgICAgICAgY2FuIG9jY3VyIHdoZW4gZG9pbmcgdGhpczsgc2Vl IHRoZSAgZGVzY3JpcHRpb24gIG9mICB0aGUgIFNFQ+KAkAo+ICAgICAgICAgICBDT01QX0lPQ1RM X05PVElGX0lEX1ZBTElEIGlvY3RsKDIpIG9wZXJhdGlvbiBiZWxvdy4pICBJbiBhZGRp4oCQCj4g ICAgICAgICAgIHRpb24sIHRoZSBzdXBlcnZpc29yIGNhbiBhY2Nlc3Mgb3RoZXIgc3lzdGVtIGlu Zm9ybWF0aW9uICB0aGF0Cj4gICAgICAgICAgIGlzICB2aXNpYmxlICBpbiAgdXNlciBzcGFjZSBi dXQgd2hpY2ggaXMgbm90IGFjY2Vzc2libGUgZnJvbSBhCj4gICAgICAgICAgIHNlY2NvbXAgZmls dGVyLgo+IAo+ICAgICAgICAgICDilIzilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilJAKPiAgICAgICAgICAg4pSCRklYTUUgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICDilIIKPiAgICAgICAgICAg4pSc4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSkCj4gICAgICAgICAgIOKUglN1cHBv c2Ugd2UgYXJlIHJlYWRpbmcgYSBwYXRobmFtZSBmcm9tIC9wcm9jL1BJRC9tZW0g4pSCCj4gICAg ICAgICAgIOKUgmZvciAgYSBzeXN0ZW0gY2FsbCBzdWNoIGFzIG1rZGlyKCkuIFRoZSBwYXRobmFt ZSBjYW4g4pSCCj4gICAgICAgICAgIOKUgmJlIGFuIGFyYml0cmFyeSBsZW5ndGguIEhvdyBkbyB3 ZSBrbm93IGhvdyBtdWNoIChob3cg4pSCCj4gICAgICAgICAgIOKUgm1hbnkgcGFnZXMpIHRvIHJl YWQgZnJvbSAvcHJvYy9QSUQvbWVtPyAgICAgICAgICAgICAg4pSCCj4gICAgICAgICAgIOKUlOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUmAoKVGhpcyBoYXMg YWxyZWFkeSBiZWVuIGFuc3dlcmVkLCBJIGJlbGlldmUuCgo+IAo+ICAgICAgICA3LiBIYXZpbmcg IG9idGFpbmVkICBpbmZvcm1hdGlvbiAgYXMgIHBlciAgdGhlIHByZXZpb3VzIHN0ZXAsIHRoZQo+ ICAgICAgICAgICBzdXBlcnZpc29yIG1heSB0aGVuIGNob29zZSB0byBwZXJmb3JtIGFuIGFjdGlv biBpbiByZXNwb25zZSB0bwo+ICAgICAgICAgICB0aGUgIHRhcmdldCAgcHJvY2VzcydzICBzeXN0 ZW0gY2FsbCAod2hpY2gsIGFzIG5vdGVkIGFib3ZlLCBpcwo+ICAgICAgICAgICBub3QgIGV4ZWN1 dGVkICB3aGVuICB0aGUgIHNlY2NvbXAgIGZpbHRlciAgcmV0dXJucyAgdGhlICAgU0VD4oCQCj4g ICAgICAgICAgIENPTVBfUkVUX1VTRVJfTk9USUYgYWN0aW9uIHZhbHVlKS4KCk5pdDogSXQgaXMg bm90IF95ZXRfIGV4ZWN1dGVkIGl0IG1heSB2ZXJ5IHdlbGwgYmUgaWYgdGhlIHJlc3BvbnNlIGlz CiJjb250aW51ZSIuIFRoaXMgc2hvdWxkIGVpdGhlciBtZW50aW9uIHRoYXQgd2hlbiB0aGUgZmQg YmVjb21lcwpfUkVDVmFibGUgdGhlIHN5c3RlbSBjYWxsIGlzIGd1YXJhbnRlZWQgdG8gbm90IGhh dmUgZXhlY3V0ZWQgeWV0IG9yCnNwZWNpZnkgdGhhdCBpdCBpcyBub3QgeWV0IGV4ZWN1dGVkLCBJ IHRoaW5rLgoKPiAKPiAgICAgICAgICAgT25lICBleGFtcGxlICB1c2UgY2FzZSBoZXJlIHJlbGF0 ZXMgdG8gY29udGFpbmVycy4gIFRoZSB0YXJnZXQKPiAgICAgICAgICAgcHJvY2VzcyBtYXkgYmUg bG9jYXRlZCBpbnNpZGUgYSBjb250YWluZXIgd2hlcmUgIGl0ICBkb2VzICBub3QKPiAgICAgICAg ICAgaGF2ZSBzdWZmaWNpZW50IGNhcGFiaWxpdGllcyB0byBtb3VudCBhIGZpbGVzeXN0ZW0gaW4g dGhlIGNvbuKAkAo+ICAgICAgICAgICB0YWluZXIncyBtb3VudCBuYW1lc3BhY2UuICBIb3dldmVy LCB0aGUgc3VwZXJ2aXNvciAgbWF5ICBiZSAgYQo+ICAgICAgICAgICBtb3JlICBwcml2aWxlZ2Vk ICBwcm9jZXNzIHRoYXQgdGhhdCBkb2VzIGhhdmUgc3VmZmljaWVudCBjYXBh4oCQCj4gICAgICAg ICAgIGJpbGl0aWVzIHRvIHBlcmZvcm0gdGhlIG1vdW50IG9wZXJhdGlvbi4KPiAKPiAgICAgICAg OC4gVGhlIHN1cGVydmlzb3IgdGhlbiBzZW5kcyBhIHJlc3BvbnNlIHRvIHRoZSBub3RpZmljYXRp b24uICBUaGUKPiAgICAgICAgICAgaW5mb3JtYXRpb24gIGluICB0aGlzICByZXNwb25zZSAgaXMg dXNlZCBieSB0aGUga2VybmVsIHRvIGNvbuKAkAo+ICAgICAgICAgICBzdHJ1Y3QgYSByZXR1cm4g dmFsdWUgZm9yIHRoZSB0YXJnZXQgcHJvY2VzcydzIHN5c3RlbSBjYWxsIGFuZAo+ICAgICAgICAg ICBwcm92aWRlIGEgdmFsdWUgdGhhdCB3aWxsIGJlIGFzc2lnbmVkIHRvIHRoZSBlcnJubyB2YXJp YWJsZSBvZgo+ICAgICAgICAgICB0aGUgdGFyZ2V0IHByb2Nlc3MuCj4gCj4gICAgICAgICAgIFRo ZSAgcmVzcG9uc2UgIGlzICBzZW50ICB1c2luZyAgdGhlICAgU0VDQ09NUF9JT0NUTF9OT1RJRl9S RUNWCj4gICAgICAgICAgIGlvY3RsKDIpICAgb3BlcmF0aW9uLCAgIHdoaWNoICBpcyAgdXNlZCAg dG8gIHRyYW5zbWl0ICBhICBzZWPigJAKPiAgICAgICAgICAgY29tcF9ub3RpZl9yZXNwICBzdHJ1 Y3R1cmUgIHRvICB0aGUgIGtlcm5lbC4gICBUaGlzICBzdHJ1Y3R1cmUKPiAgICAgICAgICAgaW5j bHVkZXMgIGEgIGNvb2tpZSAgdmFsdWUgdGhhdCB0aGUgc3VwZXJ2aXNvciBvYnRhaW5lZCBpbiB0 aGUKPiAgICAgICAgICAgc2VjY29tcF9ub3RpZiAgICBzdHJ1Y3R1cmUgICAgcmV0dXJuZWQgICAg IGJ5ICAgICB0aGUgICAgIFNFQ+KAkAo+ICAgICAgICAgICBDT01QX0lPQ1RMX05PVElGX1JFQ1Yg b3BlcmF0aW9uLiAgVGhpcyBjb29raWUgdmFsdWUgYWxsb3dzIHRoZQo+ICAgICAgICAgICBrZXJu ZWwgdG8gYXNzb2NpYXRlIHRoZSByZXNwb25zZSB3aXRoIHRoZSB0YXJnZXQgcHJvY2Vzcy4KCkkg dGhpbmsgaGVyZSBvciBhYm92ZSB5b3Ugc2hvdWxkIG1lbnRpb24gdGhhdCB0aGUgaWQgb3IgImNv b2tpZSIgX211c3RfCmJlIHVzZWQgd2hlbiBhIGZpbGUgZGVzY3JpcHRvciB0byAvcHJvYy88cGlk Pi9tZW0gb3IgYW55IC9wcm9jLzxwaWQ+LyoKaXMgb3BlbmVkOgpmZCA9IG9wZW4oL3Byb2MvcGlk LyopOwp2ZXJpZnlfdmlhX2Nvb2tpZV90aGF0X3BpZF9zdGlsbF9hbGl2ZShjb29raWUpOwpvcGVy YXRlX29uKGZkKQoKT3RoZXJ3aXNlIHRoaXMgaXMgYSBwb3RlbnRpYWwgc2VjdXJpdHkgaXNzdWUu Cgo+IAo+ICAgICAgICA5LiBPbmNlIHRoZSBub3RpZmljYXRpb24gaGFzIGJlZW4gc2VudCwgdGhl IHN5c3RlbSAgY2FsbCAgaW4gIHRoZQo+ICAgICAgICAgICB0YXJnZXQgIHByb2Nlc3MgIHVuYmxv Y2tzLCAgcmV0dXJuaW5nIHRoZSBpbmZvcm1hdGlvbiB0aGF0IHdhcwo+ICAgICAgICAgICBwcm92 aWRlZCBieSB0aGUgc3VwZXJ2aXNvciBpbiB0aGUgbm90aWZpY2F0aW9uIHJlc3BvbnNlLgo+IAo+ ICAgICAgICBBcyBhIHZhcmlhdGlvbiBvbiB0aGUgbGFzdCB0d28gc3RlcHMsIHRoZSBzdXBlcnZp c29yIGNhbiAgc2VuZCAgYQo+ICAgICAgICByZXNwb25zZSAgdGhhdCB0ZWxscyB0aGUga2VybmVs IHRoYXQgaXQgc2hvdWxkIGV4ZWN1dGUgdGhlIHRhcmdldAo+ICAgICAgICBwcm9jZXNzJ3MgICBz eXN0ZW0gICBjYWxsOyAgIHNlZSAgIHRoZSAgIGRpc2N1c3Npb24gICAgb2YgICAgU0VD4oCQCj4g ICAgICAgIENPTVBfVVNFUl9OT1RJRl9GTEFHX0NPTlRJTlVFLCBiZWxvdy4KPiAKPiAgICBpb2N0 bCgyKSBvcGVyYXRpb25zCj4gICAgICAgIFRoZSBmb2xsb3dpbmcgaW9jdGwoMikgb3BlcmF0aW9u cyBhcmUgcHJvdmlkZWQgdG8gc3VwcG9ydCBzZWNjb21wCj4gICAgICAgIHVzZXItc3BhY2Ugbm90 aWZpY2F0aW9uLiAgRm9yIGVhY2ggb2YgdGhlc2Ugb3BlcmF0aW9ucywgdGhlIGZpcnN0Cj4gICAg ICAgIChmaWxlICBkZXNjcmlwdG9yKSAgYXJndW1lbnQgIG9mICBpb2N0bCgyKSAgaXMgdGhlIGxp c3RlbmluZyBmaWxlCj4gICAgICAgIGRlc2NyaXB0b3IgcmV0dXJuZWQgYnkgYSBjYWxsIHRvIHNl Y2NvbXAoMikgd2l0aCB0aGUgU0VDQ09NUF9GSUzigJAKPiAgICAgICAgVEVSX0ZMQUdfTkVXX0xJ U1RFTkVSIGZsYWcuCj4gCj4gICAgICAgIFNFQ0NPTVBfSU9DVExfTk9USUZfUkVDVgo+ICAgICAg ICAgICAgICAgVGhpcyBvcGVyYXRpb24gaXMgdXNlZCB0byBvYnRhaW4gYSB1c2VyLXNwYWNlIG5v dGlmaWNhdGlvbgo+ICAgICAgICAgICAgICAgZXZlbnQuICBJZiBubyBzdWNoIGV2ZW50IGlzIGN1 cnJlbnRseSBwZW5kaW5nLCB0aGUgIG9wZXJh4oCQCj4gICAgICAgICAgICAgICB0aW9uICBibG9j a3MgIHVudGlsICBhbiAgZXZlbnQgb2NjdXJzLiAgVGhlIHRoaXJkIGlvY3RsKDIpCj4gICAgICAg ICAgICAgICBhcmd1bWVudCBpcyBhIHBvaW50ZXIgdG8gYSBzdHJ1Y3R1cmUgb2YgdGhlIGZvbGxv d2luZyBmb3JtCj4gICAgICAgICAgICAgICB3aGljaCAgY29udGFpbnMgIGluZm9ybWF0aW9uIGFi b3V0IHRoZSBldmVudC4gIFRoaXMgc3RydWPigJAKPiAgICAgICAgICAgICAgIHR1cmUgbXVzdCBi ZSB6ZXJvZWQgb3V0IGJlZm9yZSB0aGUgY2FsbC4KPiAKPiAgICAgICAgICAgICAgICAgICBzdHJ1 Y3Qgc2VjY29tcF9ub3RpZiB7Cj4gICAgICAgICAgICAgICAgICAgICAgIF9fdTY0ICBpZDsgICAg ICAgICAgICAgIC8qIENvb2tpZSAqLwo+ICAgICAgICAgICAgICAgICAgICAgICBfX3UzMiAgcGlk OyAgICAgICAgICAgICAvKiBQSUQgb2YgdGFyZ2V0IHByb2Nlc3MgKi8KPiAgICAgICAgICAgICAg ICAgICAgICAgX191MzIgIGZsYWdzOyAgICAgICAgICAgLyogQ3VycmVudGx5IHVudXNlZCAoMCkg Ki8KPiAgICAgICAgICAgICAgICAgICAgICAgc3RydWN0IHNlY2NvbXBfZGF0YSBkYXRhOyAgIC8q IFNlZSBzZWNjb21wKDIpICovCj4gICAgICAgICAgICAgICAgICAgfTsKPiAKPiAgICAgICAgICAg ICAgIFRoZSBmaWVsZHMgaW4gdGhpcyBzdHJ1Y3R1cmUgYXJlIGFzIGZvbGxvd3M6Cj4gCj4gICAg ICAgICAgICAgICBpZCAgICAgVGhpcyBpcyBhIGNvb2tpZSBmb3IgdGhlIG5vdGlmaWNhdGlvbi4g ICBFYWNoICBzdWNoCj4gICAgICAgICAgICAgICAgICAgICAgY29va2llICBpcyAgZ3VhcmFudGVl ZCAgdG8gYmUgdW5pcXVlIGZvciB0aGUgY29ycmXigJAKPiAgICAgICAgICAgICAgICAgICAgICBz cG9uZGluZyBzZWNjb21wICBmaWx0ZXIuICAgSW4gIG90aGVyICB3b3JkcywgIHRoaXMKPiAgICAg ICAgICAgICAgICAgICAgICBjb29raWUgIGlzICB1bmlxdWUgZm9yIGVhY2ggbm90aWZpY2F0aW9u IGV2ZW50IGZyb20KPiAgICAgICAgICAgICAgICAgICAgICB0aGUgdGFyZ2V0IHByb2Nlc3MuICBU aGUgY29va2llIHZhbHVlIGhhcyB0aGUgIGZvbOKAkAo+ICAgICAgICAgICAgICAgICAgICAgIGxv d2luZyB1c2VzOgo+IAo+ICAgICAgICAgICAgICAgICAgICAgIMK3IEl0ICAgICBjYW4gICAgIGJl ICAgICB1c2VkICAgIHdpdGggICAgdGhlICAgIFNFQ+KAkAo+ICAgICAgICAgICAgICAgICAgICAg ICAgQ09NUF9JT0NUTF9OT1RJRl9JRF9WQUxJRCBpb2N0bCgyKSAgb3BlcmF0aW9uICB0bwo+ICAg ICAgICAgICAgICAgICAgICAgICAgdmVyaWZ5IHRoYXQgdGhlIHRhcmdldCBwcm9jZXNzIGlzIHN0 aWxsIGFsaXZlLgo+IAo+ICAgICAgICAgICAgICAgICAgICAgIMK3IFdoZW4gIHJldHVybmluZyAg YSAgbm90aWZpY2F0aW9uICByZXNwb25zZSB0byB0aGUKPiAgICAgICAgICAgICAgICAgICAgICAg IGtlcm5lbCwgdGhlIHN1cGVydmlzb3IgbXVzdCAgaW5jbHVkZSAgdGhlICBjb29raWUKPiAgICAg ICAgICAgICAgICAgICAgICAgIHZhbHVlIGluIHRoZSBzZWNjb21wX25vdGlmX3Jlc3Agc3RydWN0 dXJlIHRoYXQgaXMKPiAgICAgICAgICAgICAgICAgICAgICAgIHNwZWNpZmllZCAgIGFzICAgdGhl ICAgYXJndW1lbnQgICBvZiAgIHRoZSAgIFNFQ+KAkAo+ICAgICAgICAgICAgICAgICAgICAgICAg Q09NUF9JT0NUTF9OT1RJRl9TRU5EIG9wZXJhdGlvbi4KPiAKPiAgICAgICAgICAgICAgIHBpZCAg ICBUaGlzICBpcyAgdGhlICBQSUQgb2YgdGhlIHRhcmdldCBwcm9jZXNzIHRoYXQgdHJpZ+KAkAo+ ICAgICAgICAgICAgICAgICAgICAgIGdlcmVkIHRoZSBub3RpZmljYXRpb24gZXZlbnQuCj4gCj4g ICAgICAgICAgICAgICAgICAgICAg4pSM4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSQCj4gICAgICAgICAgICAgICAgICAgICAg4pSCRklYTUUgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICDilIIKPiAgICAgICAgICAgICAg ICAgICAgICDilJzilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lKQKPiAgICAgICAgICAgICAgICAgICAgICDilIJUaGlzIGlzIGEgdGhyZWFkIElELCByYXRoZXIg dGhhbiBhIFBJRCwgcmlnaHQ/ICAgICAgIOKUggo+ICAgICAgICAgICAgICAgICAgICAgIOKUlOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUmAoKWWVzLgoKPiAK PiAgICAgICAgICAgICAgIGZsYWdzICBUaGlzIGlzIGEgIGJpdCAgbWFzayAgb2YgIGZsYWdzICBw cm92aWRpbmcgIGZ1cnRoZXIKPiAgICAgICAgICAgICAgICAgICAgICBpbmZvcm1hdGlvbiBvbiB0 aGUgZXZlbnQuICBJbiB0aGUgY3VycmVudCBpbXBsZW1lbuKAkAo+ICAgICAgICAgICAgICAgICAg ICAgIHRhdGlvbiwgdGhpcyBmaWVsZCBpcyBhbHdheXMgemVyby4KPiAKPiAgICAgICAgICAgICAg IGRhdGEgICBUaGlzIGlzIGEgc2VjY29tcF9kYXRhIHN0cnVjdHVyZSBjb250YWluaW5nICBpbmZv cuKAkAo+ICAgICAgICAgICAgICAgICAgICAgIG1hdGlvbiAgYWJvdXQgIHRoZSAgc3lzdGVtICBj YWxsIHRoYXQgdHJpZ2dlcmVkIHRoZQo+ICAgICAgICAgICAgICAgICAgICAgIG5vdGlmaWNhdGlv bi4gIFRoaXMgaXMgdGhlIHNhbWUgc3RydWN0dXJlICB0aGF0ICBpcwo+ICAgICAgICAgICAgICAg ICAgICAgIHBhc3NlZCAgdG8gIHRoZSBzZWNjb21wIGZpbHRlci4gIFNlZSBzZWNjb21wKDIpIGZv cgo+ICAgICAgICAgICAgICAgICAgICAgIGRldGFpbHMgb2YgdGhpcyBzdHJ1Y3R1cmUuCj4gCj4g ICAgICAgICAgICAgICBPbiBzdWNjZXNzLCB0aGlzIG9wZXJhdGlvbiByZXR1cm5zIDA7IG9uICBm YWlsdXJlLCAgLTEgIGlzCj4gICAgICAgICAgICAgICByZXR1cm5lZCwgIGFuZCAgZXJybm8gIGlz IHNldCB0byBpbmRpY2F0ZSB0aGUgY2F1c2Ugb2YgdGhlCj4gICAgICAgICAgICAgICBlcnJvci4g IFRoaXMgb3BlcmF0aW9uIGNhbiBmYWlsIHdpdGggdGhlIGZvbGxvd2luZyBlcnJvcnM6Cj4gCj4g ICAgICAgICAgICAgICBFSU5WQUwgKHNpbmNlIExpbnV4IDUuNSkKPiAgICAgICAgICAgICAgICAg ICAgICBUaGUgc2VjY29tcF9ub3RpZiBzdHJ1Y3R1cmUgdGhhdCB3YXMgcGFzc2VkIHRvICB0aGUK PiAgICAgICAgICAgICAgICAgICAgICBjYWxsIGNvbnRhaW5lZCBub256ZXJvIGZpZWxkcy4KPiAK PiAgICAgICAgICAgICAgIEVOT0VOVCBUaGUgIHRhcmdldCAgcHJvY2VzcyAgd2FzIGtpbGxlZCBi eSBhIHNpZ25hbCBhcyB0aGUKPiAgICAgICAgICAgICAgICAgICAgICBub3RpZmljYXRpb24gaW5m b3JtYXRpb24gd2FzIGJlaW5nIGdlbmVyYXRlZC4KPiAKPiAgICAgICAg4pSM4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSQCj4gICAgICAgIOKUgkZJWE1FICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg4pSCCj4gICAgICAg IOKUnOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUpAo+ICAg ICAgICDilIJGcm9tIG15IGV4cGVyaW1lbnRzLCAgaXQgIGFwcGVhcnMgIHRoYXQgIGlmICBhICBT RUPigJAg4pSCCj4gICAgICAgIOKUgkNPTVBfSU9DVExfTk9USUZfUkVDViAgIGlzICBkb25lICBh ZnRlciAgdGhlICB0YXJnZXQg4pSCCj4gICAgICAgIOKUgnByb2Nlc3MgdGVybWluYXRlcywgdGhl biB0aGUgaW9jdGwoKSAgc2ltcGx5ICBibG9ja3Mg4pSCCj4gICAgICAgIOKUgihyYXRoZXIgdGhh biByZXR1cm5pbmcgYW4gZXJyb3IgdG8gaW5kaWNhdGUgdGhhdCB0aGUg4pSCCj4gICAgICAgIOKU gnRhcmdldCBwcm9jZXNzIG5vIGxvbmdlciBleGlzdHMpLiAgICAgICAgICAgICAgICAgICAg4pSC Cj4gICAgICAgIOKUgiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICAgICAg4pSCCj4gICAgICAgIOKUgkkgZm91bmQgdGhhdCBzdXJwcmlzaW5nLCBhbmQgaXQg cmVxdWlyZWQgIHNvbWUgIGNvbuKAkCDilIIKPiAgICAgICAg4pSCdG9ydGlvbnMgIGluIHRoZSBl eGFtcGxlIHByb2dyYW0uICBJdCB3YXMgbm90IHBvc3Np4oCQIOKUggo+ICAgICAgICDilIJibGUg dG8gY29kZSBteSBTSUdDSExEIGhhbmRsZXIgKHdoaWNoIHJlYXBzIHRoZSB6b23igJAg4pSCCj4g ICAgICAgIOKUgmJpZSAgd2hlbiAgdGhlICB3b3JrZXIvdGFyZ2V0IHByb2Nlc3MgdGVybWluYXRl cykgdG8g4pSCCj4gICAgICAgIOKUgnNpbXBseSBzZXQgYSBmbGFnIGNoZWNrZWQgaW4gdGhlIG1h aW4gIGhhbmRsZU5vdGlmaeKAkCDilIIKPiAgICAgICAg4pSCY2F0aW9ucygpICBsb29wLCAgc2lu Y2UgIHRoaXMgY3JlYXRlZCBhbiB1bmF2b2lkYWJsZSDilIIKPiAgICAgICAg4pSCcmFjZSB3aGVy ZSB0aGUgY2hpbGQgbWlnaHQgdGVybWluYXRlICBqdXN0ICBhZnRlciAgSSDilIIKPiAgICAgICAg 4pSCaGFkICBjaGVja2VkICB0aGUgIGZsYWcsICBidXQgYmVmb3JlIEkgYmxvY2tlZCAoZm9y4oCQ IOKUggo+ICAgICAgICDilIJldmVyISkgaW4gIHRoZSAgU0VDQ09NUF9JT0NUTF9OT1RJRl9SRUNW ICBvcGVyYXRpb24uIOKUggo+ICAgICAgICDilIJJbnN0ZWFkLCAgSSBoYWQgdG8gY29kZSB0aGUg c2lnbmFsIGhhbmRsZXIgdG8gc2ltcGx5IOKUggo+ICAgICAgICDilIJjYWxsIF9leGl0KDIpICBp biAgb3JkZXIgIHRvICB0ZXJtaW5hdGUgIHRoZSAgcGFyZW50IOKUggo+ICAgICAgICDilIJwcm9j ZXNzICh0aGUgc3VwZXJ2aXNvcikuICAgICAgICAgICAgICAgICAgICAgICAgICAgIOKUggo+ICAg ICAgICDilIIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgIOKUggo+ICAgICAgICDilIJJcyAgdGhpcyAgZXhwZWN0ZWQgIGJlaGF2aW9yPyAgSXQgc2Vl bXMgdG8gbWUgcmF0aGVyIOKUggo+ICAgICAgICDilIJkZXNpcmFibGUgdGhhdCBTRUNDT01QX0lP Q1RMX05PVElGX1JFQ1Ygc2hvdWxkICBnaXZlIOKUggo+ICAgICAgICDilIJhbiBlcnJvciBpZiB0 aGUgdGFyZ2V0IHByb2Nlc3MgaGFzIHRlcm1pbmF0ZWQuICAgICAgIOKUggo+ICAgICAgICDilJTi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilJgKClRoaXMgaGFz IGJlZW4gZGlzY3Vzc2VkIGxhdGVyIGluIHRoZSB0aHJlYWQgdG9vLCBJIGJlbGlldmUuIE15IHBh dGNoc2V0CmZpeGVkIGEgZGlmZmVyZW50IGJ1dCByZWxhdGVkIGJ1ZyBpbiAtPnBvbGwoKSB3aGVu IGEgZmlsdGVyIGJlY29tZXMKdW51c2VkLiBJIGhhZG4ndCBub3RpY2VkIHRoaXMgYmVoYXZpb3Ig c2luY2UgSSdtIGFsd2F5cyBwb2xsaW5nLiAoUHVyZQppb2N0bHMoKSBmZWVsIGEgYml0IGZpc2h5 IHRvIG1lLiA6KSBCdXQgb2J2aW91c2x5IGEgdmFsaWQgdXNlLikKCj4gCj4gICAgICAgIFNFQ0NP TVBfSU9DVExfTk9USUZfSURfVkFMSUQKPiAgICAgICAgICAgICAgIFRoaXMgb3BlcmF0aW9uIGNh biBiZSB1c2VkIHRvIGNoZWNrIHRoYXQgYSBub3RpZmljYXRpb24gSUQKPiAgICAgICAgICAgICAg IHJldHVybmVkIGJ5IGFuIGVhcmxpZXIgU0VDQ09NUF9JT0NUTF9OT1RJRl9SRUNWICBvcGVyYXRp b24KPiAgICAgICAgICAgICAgIGlzICBzdGlsbCAgdmFsaWQgIChpLmUuLCAgdGhhdCAgdGhlICB0 YXJnZXQgIHByb2Nlc3Mgc3RpbGwKPiAgICAgICAgICAgICAgIGV4aXN0cykuCj4gCj4gICAgICAg ICAgICAgICBUaGUgdGhpcmQgaW9jdGwoMikgYXJndW1lbnQgaXMgYSAgcG9pbnRlciAgdG8gIHRo ZSAgY29va2llCj4gICAgICAgICAgICAgICAoaWQpIHJldHVybmVkIGJ5IHRoZSBTRUNDT01QX0lP Q1RMX05PVElGX1JFQ1Ygb3BlcmF0aW9uLgo+IAo+ICAgICAgICAgICAgICAgVGhpcyAgb3BlcmF0 aW9uIGlzIG5lY2Vzc2FyeSB0byBhdm9pZCByYWNlIGNvbmRpdGlvbnMgdGhhdAo+ICAgICAgICAg ICAgICAgY2FuICBvY2N1ciAgIHdoZW4gICB0aGUgICBwaWQgICByZXR1cm5lZCAgIGJ5ICAgdGhl ICAgU0VD4oCQCj4gICAgICAgICAgICAgICBDT01QX0lPQ1RMX05PVElGX1JFQ1YgICBvcGVyYXRp b24gICB0ZXJtaW5hdGVzLCAgYW5kICB0aGF0Cj4gICAgICAgICAgICAgICBwcm9jZXNzIElEIGlz IHJldXNlZCBieSBhbm90aGVyIHByb2Nlc3MuICAgQW4gIGV4YW1wbGUgIG9mCj4gICAgICAgICAg ICAgICB0aGlzIGtpbmQgb2YgcmFjZSBpcyB0aGUgZm9sbG93aW5nCj4gCj4gICAgICAgICAgICAg ICAxLiBBICBub3RpZmljYXRpb24gIGlzICBnZW5lcmF0ZWQgIG9uICB0aGUgIGxpc3RlbmluZyBm aWxlCj4gICAgICAgICAgICAgICAgICBkZXNjcmlwdG9yLiAgVGhlIHJldHVybmVkICBzZWNjb21w X25vdGlmICBjb250YWlucyAgdGhlCj4gICAgICAgICAgICAgICAgICBQSUQgb2YgdGhlIHRhcmdl dCBwcm9jZXNzLgo+IAo+ICAgICAgICAgICAgICAgMi4gVGhlIHRhcmdldCBwcm9jZXNzIHRlcm1p bmF0ZXMuCj4gCj4gICAgICAgICAgICAgICAzLiBBbm90aGVyIHByb2Nlc3MgaXMgY3JlYXRlZCBv biB0aGUgc3lzdGVtIHRoYXQgYnkgY2hhbmNlCj4gICAgICAgICAgICAgICAgICByZXVzZXMgdGhl IFBJRCB0aGF0IHdhcyBmcmVlZCB3aGVuIHRoZSAgdGFyZ2V0ICBwcm9jZXNzCj4gICAgICAgICAg ICAgICAgICB0ZXJtaW5hdGVzLgo+IAo+ICAgICAgICAgICAgICAgNC4gVGhlICBzdXBlcnZpc29y ICBvcGVuKDIpcyAgdGhlIC9wcm9jL1twaWRdL21lbSBmaWxlIGZvcgo+ICAgICAgICAgICAgICAg ICAgdGhlIFBJRCBvYnRhaW5lZCBpbiBzdGVwIDEsIHdpdGggdGhlIGludGVudGlvbiBvZiAoc2F5 KQo+ICAgICAgICAgICAgICAgICAgaW5zcGVjdGluZyB0aGUgbWVtb3J5IGxvY2F0aW9ucyB0aGF0 IGNvbnRhaW5zIHRoZSBhcmd14oCQCj4gICAgICAgICAgICAgICAgICBtZW50cyBvZiB0aGUgc3lz dGVtIGNhbGwgdGhhdCB0cmlnZ2VyZWQgIHRoZSAgbm90aWZpY2HigJAKPiAgICAgICAgICAgICAg ICAgIHRpb24gaW4gc3RlcCAxLgo+IAo+ICAgICAgICAgICAgICAgSW4gdGhlIGFib3ZlIHNjZW5h cmlvLCB0aGUgcmlzayBpcyB0aGF0IHRoZSBzdXBlcnZpc29yIG1heQo+ICAgICAgICAgICAgICAg dHJ5IHRvIGFjY2VzcyB0aGUgbWVtb3J5IG9mIGEgcHJvY2VzcyBvdGhlciB0aGFuIHRoZSAgdGFy 4oCQCj4gICAgICAgICAgICAgICBnZXQuICAgVGhpcyAgcmFjZSAgY2FuIGJlIGF2b2lkZWQgYnkg Zm9sbG93aW5nIHRoZSBjYWxsIHRvCj4gICAgICAgICAgICAgICBvcGVuIHdpdGggYSBTRUNDT01Q X0lPQ1RMX05PVElGX0lEX1ZBTElEIG9wZXJhdGlvbiB0byB2ZXLigJAKPiAgICAgICAgICAgICAg IGlmeSAgdGhhdCAgdGhlICBwcm9jZXNzIHRoYXQgZ2VuZXJhdGVkIHRoZSBub3RpZmljYXRpb24g aXMKPiAgICAgICAgICAgICAgIHN0aWxsIGFsaXZlLiAgKE5vdGUgdGhhdCAgaWYgIHRoZSAgdGFy Z2V0ICBwcm9jZXNzICBzdWJzZeKAkAo+ICAgICAgICAgICAgICAgcXVlbnRseSAgdGVybWluYXRl cywgaXRzIFBJRCB3b24ndCBiZSByZXVzZWQgYmVjYXVzZSB0aGVyZQo+ICAgICAgICAgICAgICAg cmVtYWlucyBhbiBvcGVuIHJlZmVyZW5jZSB0byB0aGUgL3Byb2NbcGlkXS9tZW0gIGZpbGU7ICBp bgo+ICAgICAgICAgICAgICAgdGhpcyAgY2FzZSwgYSBzdWJzZXF1ZW50IHJlYWQoMikgZnJvbSB0 aGUgZmlsZSB3aWxsIHJldHVybgo+ICAgICAgICAgICAgICAgMCwgaW5kaWNhdGluZyBlbmQgb2Yg ZmlsZS4pCj4gCj4gICAgICAgICAgICAgICBPbiBzdWNjZXNzIChpLmUuLCB0aGUgbm90aWZpY2F0 aW9uICBJRCAgaXMgIHN0aWxsICB2YWxpZCksCj4gICAgICAgICAgICAgICB0aGlzICBvcGVyYXRp b24gIHJldHVybnMgMCBPbiBmYWlsdXJlIChpLmUuLCB0aGUgbm90aWZpY2HigJAKCk1pc3Npbmcg YSAiLiIsIEkgdGhpbmsuCgo+ICAgICAgICAgICAgICAgdGlvbiBJRCBpcyBubyBsb25nZXIgdmFs aWQpLCAtMSBpcyByZXR1cm5lZCwgYW5kIGVycm5vICBpcwo+ICAgICAgICAgICAgICAgc2V0IHRv IEVOT0VOVC4KPiAKPiAgICAgICAgU0VDQ09NUF9JT0NUTF9OT1RJRl9TRU5ECj4gICAgICAgICAg ICAgICBUaGlzICBvcGVyYXRpb24gIGlzICB1c2VkICB0byBzZW5kIGEgbm90aWZpY2F0aW9uIHJl c3BvbnNlCj4gICAgICAgICAgICAgICBiYWNrIHRvIHRoZSBrZXJuZWwuICBUaGUgdGhpcmQgaW9j dGwoMikgYXJndW1lbnQgIG9mICB0aGlzCj4gICAgICAgICAgICAgICBzdHJ1Y3R1cmUgIGlzICBh ICBwb2ludGVyICB0byBhIHN0cnVjdHVyZSBvZiB0aGUgZm9sbG93aW5nCj4gICAgICAgICAgICAg ICBmb3JtOgo+IAo+ICAgICAgICAgICAgICAgICAgIHN0cnVjdCBzZWNjb21wX25vdGlmX3Jlc3Ag ewo+ICAgICAgICAgICAgICAgICAgICAgICBfX3U2NCBpZDsgICAgICAgICAgICAgICAvKiBDb29r aWUgdmFsdWUgKi8KPiAgICAgICAgICAgICAgICAgICAgICAgX19zNjQgdmFsOyAgICAgICAgICAg ICAgLyogU3VjY2VzcyByZXR1cm4gdmFsdWUgKi8KPiAgICAgICAgICAgICAgICAgICAgICAgX19z MzIgZXJyb3I7ICAgICAgICAgICAgLyogMCAoc3VjY2Vzcykgb3IgbmVnYXRpdmUKPiAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgZXJyb3IgbnVtYmVyICov Cj4gICAgICAgICAgICAgICAgICAgICAgIF9fdTMyIGZsYWdzOyAgICAgICAgICAgIC8qIFNlZSBi ZWxvdyAqLwo+ICAgICAgICAgICAgICAgICAgIH07Cj4gCj4gICAgICAgICAgICAgICBUaGUgZmll bGRzIG9mIHRoaXMgc3RydWN0dXJlIGFyZSBhcyBmb2xsb3dzOgo+IAo+ICAgICAgICAgICAgICAg aWQgICAgIFRoaXMgaXMgdGhlIGNvb2tpZSB2YWx1ZSB0aGF0ICB3YXMgIG9idGFpbmVkICB1c2lu Zwo+ICAgICAgICAgICAgICAgICAgICAgIHRoZSAgIFNFQ0NPTVBfSU9DVExfTk9USUZfUkVDViAg IG9wZXJhdGlvbi4gICAgVGhpcwo+ICAgICAgICAgICAgICAgICAgICAgIGNvb2tpZSB2YWx1ZSBh bGxvd3MgdGhlIGtlcm5lbCB0byAgY29ycmVjdGx5ICBhc3Nv4oCQCj4gICAgICAgICAgICAgICAg ICAgICAgY2lhdGUgdGhpcyByZXNwb25zZSB3aXRoIHRoZSBzeXN0ZW0gY2FsbCB0aGF0IHRyaWfi gJAKPiAgICAgICAgICAgICAgICAgICAgICBnZXJlZCB0aGUgdXNlci1zcGFjZSBub3RpZmljYXRp b24uCj4gCj4gICAgICAgICAgICAgICB2YWwgICAgVGhpcyBpcyB0aGUgdmFsdWUgdGhhdCB3aWxs IGJlIHVzZWQgZm9yICBhICBzcG9vZmVkCj4gICAgICAgICAgICAgICAgICAgICAgc3VjY2VzcyAg cmV0dXJuICBmb3IgIHRoZSAgdGFyZ2V0ICBwcm9jZXNzJ3Mgc3lzdGVtCj4gICAgICAgICAgICAg ICAgICAgICAgY2FsbDsgc2VlIGJlbG93Lgo+IAo+ICAgICAgICAgICAgICAgZXJyb3IgIFRoaXMg aXMgdGhlIHZhbHVlIHRoYXQgd2lsbCBiZSB1c2VkICBhcyAgdGhlICBlcnJvcgo+ICAgICAgICAg ICAgICAgICAgICAgIG51bWJlciAgKGVycm5vKSAgZm9yIGEgc3Bvb2ZlZCBlcnJvciByZXR1cm4g Zm9yIHRoZQo+ICAgICAgICAgICAgICAgICAgICAgIHRhcmdldCBwcm9jZXNzJ3Mgc3lzdGVtIGNh bGw7IHNlZSBiZWxvdy4KCk5pdDogInZhbCIgaXMgb25seSB1c2VkIHdoZW4gImVycm9yIiBpcyBu b3Qgc2V0LgoKPiAKPiAgICAgICAgICAgICAgIGZsYWdzICBUaGlzIGlzIGEgYml0IG1hc2sgdGhh dCBpbmNsdWRlcyB6ZXJvICBvciAgbW9yZSAgb2YKPiAgICAgICAgICAgICAgICAgICAgICB0aGUg Zm9sbG93aW5nIGZsYWdzCj4gCj4gICAgICAgICAgICAgICAgICAgICAgU0VDQ09NUF9VU0VSX05P VElGX0ZMQUdfQ09OVElOVUUgKHNpbmNlIExpbnV4IDUuNSkKPiAgICAgICAgICAgICAgICAgICAg ICAgICAgICAgVGVsbCAgIHRoZSAga2VybmVsICB0byAgZXhlY3V0ZSAgdGhlICB0YXJnZXQKPiAg ICAgICAgICAgICAgICAgICAgICAgICAgICAgcHJvY2VzcydzIHN5c3RlbSBjYWxsLgo+IAo+ICAg ICAgICAgICAgICAgVHdvIGtpbmRzIG9mIHJlc3BvbnNlIGFyZSBwb3NzaWJsZToKPiAKPiAgICAg ICAgICAgICAgIMK3IEEgcmVzcG9uc2UgdG8gdGhlIGtlcm5lbCB0ZWxsaW5nIGl0IHRvIGV4ZWN1 dGUgdGhlICB0YXLigJAKPiAgICAgICAgICAgICAgICAgZ2V0ICBwcm9jZXNzJ3MgIHN5c3RlbSAg Y2FsbC4gICBJbiAgdGhpcyBjYXNlLCB0aGUgZmxhZ3MKPiAgICAgICAgICAgICAgICAgZmllbGQg aW5jbHVkZXMgU0VDQ09NUF9VU0VSX05PVElGX0ZMQUdfQ09OVElOVUUgYW5kICB0aGUKPiAgICAg ICAgICAgICAgICAgZXJyb3IgYW5kIHZhbCBmaWVsZHMgbXVzdCBiZSB6ZXJvLgo+IAo+ICAgICAg ICAgICAgICAgICBUaGlzICBraW5kICBvZiByZXNwb25zZSBjYW4gYmUgdXNlZnVsIGluIGNhc2Vz IHdoZXJlIHRoZQo+ICAgICAgICAgICAgICAgICBzdXBlcnZpc29yIG5lZWRzIHRvIGRvIGRlZXBl ciBhbmFseXNpcyBvZiAgdGhlICB0YXJnZXQncwo+ICAgICAgICAgICAgICAgICBzeXN0ZW0gIGNh bGwgIHRoYW4gIGlzICBwb3NzaWJsZSAgZnJvbSAgYSBzZWNjb21wIGZpbHRlcgo+ICAgICAgICAg ICAgICAgICAoZS5nLiwgZXhhbWluaW5nIHRoZSB2YWx1ZXMgb2YgcG9pbnRlciBhcmd1bWVudHMp LCAgYW5kLAo+ICAgICAgICAgICAgICAgICBoYXZpbmcgIHZlcmlmaWVkIHRoYXQgdGhlIHN5c3Rl bSBjYWxsIGlzIGFjY2VwdGFibGUsIHRoZQo+ICAgICAgICAgICAgICAgICBzdXBlcnZpc29yIHdh bnRzIHRvIGFsbG93IGl0IHRvIHByb2NlZWQuCgpJIHRoaW5rIEphbm4gaGFzIHBvaW50ZWQgdGhp cyBvdXQuIFRoaXMgbmVlZHMgdG8gY29tZSB3aXRoIGEgYmlnIHdhcm5pbmcKYW5kIEkgd291bGQg ZXhwbGljaXRseSBwdXQgYToKIlRoZSB1c2VyIG5vdGlmaWNhdGlvbiBtZWNoYW5pc20gY2Fubm90 IGJlIHVzZWQgdG8gaW1wbGVtZW50IGEgc3lzY2FsbApzZWN1cml0eSBwb2xpY3kgaW4gdXNlciBz cGFjZSEiCllvdSBtaWdodCB3YW50IHRvIHRha2UgYSBsb29rIGF0IHRoZSBzZWNjb21wLmggaGVh ZGVyIGZpbGUgd2hlcmUgSQpwbGFjZWQgYSBnaWFudCB3YXJuaW5nIGFib3V0IGhvdyB0byB1c2Ug dGhpcyB0b28uCgo+IAo+ICAgICAgICAgICAgICAgwrcgQSBzcG9vZmVkIHJldHVybiB2YWx1ZSBm b3IgdGhlIHRhcmdldCAgcHJvY2VzcydzICBzeXN0ZW0KPiAgICAgICAgICAgICAgICAgY2FsbC4g ICBJbiAgdGhpcyAgY2FzZSwgIHRoZSBrZXJuZWwgZG9lcyBub3QgZXhlY3V0ZSB0aGUKPiAgICAg ICAgICAgICAgICAgdGFyZ2V0IHByb2Nlc3MncyBzeXN0ZW0gY2FsbCwgaW5zdGVhZCBjYXVzaW5n IHRoZSBzeXN0ZW0KPiAgICAgICAgICAgICAgICAgY2FsbCB0byByZXR1cm4gYSBzcG9vZmVkIHZh bHVlIGFzIHNwZWNpZmllZCBieSBmaWVsZHMgb2YKPiAgICAgICAgICAgICAgICAgdGhlIHNlY2Nv bXBfbm90aWZfcmVzcCBzdHJ1Y3R1cmUuICBUaGUgc3VwZXJ2aXNvciBzaG91bGQKPiAgICAgICAg ICAgICAgICAgc2V0IHRoZSBmaWVsZHMgb2YgdGhpcyBzdHJ1Y3R1cmUgYXMgZm9sbG93czoKPiAK PiAgICAgICAgICAgICAgICAgKyAgZmxhZ3MgIGRvZXMgIG5vdCBjb250YWluIFNFQ0NPTVBfVVNF Ul9OT1RJRl9GTEFHX0NPTuKAkAo+ICAgICAgICAgICAgICAgICAgICBUSU5VRS4KPiAKPiAgICAg ICAgICAgICAgICAgKyAgZXJyb3IgaXMgc2V0IGVpdGhlciB0byAgMCAgZm9yICBhICBzcG9vZmVk ICAic3VjY2VzcyIKPiAgICAgICAgICAgICAgICAgICAgcmV0dXJuICBvciAgdG8gIGEgbmVnYXRp dmUgZXJyb3IgbnVtYmVyIGZvciBhIHNwb29mZWQKPiAgICAgICAgICAgICAgICAgICAgImZhaWx1 cmUiIHJldHVybi4gIEluIHRoZSAgZm9ybWVyICBjYXNlLCAgdGhlICBrZXJuZWwKPiAgICAgICAg ICAgICAgICAgICAgY2F1c2VzIHRoZSB0YXJnZXQgcHJvY2VzcydzIHN5c3RlbSBjYWxsIHRvIHJl dHVybiB0aGUKPiAgICAgICAgICAgICAgICAgICAgdmFsdWUgc3BlY2lmaWVkIGluIHRoZSB2YWwg ZmllbGQuICBJbiB0aGUgbGF0ZXIgY2FzZSwKPiAgICAgICAgICAgICAgICAgICAgdGhlIGtlcm5l bCBjYXVzZXMgdGhlIHRhcmdldCBwcm9jZXNzJ3Mgc3lzdGVtIGNhbGwgdG8KPiAgICAgICAgICAg ICAgICAgICAgcmV0dXJuIC0xLCBhbmQgZXJybm8gaXMgYXNzaWduZWQgIHRoZSAgbmVnYXRlZCAg ZXJyb3IKPiAgICAgICAgICAgICAgICAgICAgdmFsdWUuCj4gCj4gICAgICAgICAgICAgICAgICsg IHZhbCBpcyBzZXQgdG8gYSB2YWx1ZSB0aGF0IHdpbGwgYmUgdXNlZCBhcyB0aGUgcmV0dXJuCj4g ICAgICAgICAgICAgICAgICAgIHZhbHVlIGZvciBhIHNwb29mZWQgInN1Y2Nlc3MiIHJldHVybiBm b3IgIHRoZSAgdGFyZ2V0Cj4gICAgICAgICAgICAgICAgICAgIHByb2Nlc3MncyAgc3lzdGVtICBj YWxsLiAgIFRoZSB2YWx1ZSBpbiB0aGlzIGZpZWxkIGlzCj4gICAgICAgICAgICAgICAgICAgIGln bm9yZWQgaWYgdGhlIGVycm9yIGZpZWxkIGNvbnRhaW5zIGEgbm9uemVybyB2YWx1ZS4KPiAKPiAg ICAgICAgICAgICAgIE9uIHN1Y2Nlc3MsIHRoaXMgb3BlcmF0aW9uIHJldHVybnMgMDsgb24gIGZh aWx1cmUsICAtMSAgaXMKPiAgICAgICAgICAgICAgIHJldHVybmVkLCAgYW5kICBlcnJubyAgaXMg c2V0IHRvIGluZGljYXRlIHRoZSBjYXVzZSBvZiB0aGUKPiAgICAgICAgICAgICAgIGVycm9yLiAg VGhpcyBvcGVyYXRpb24gY2FuIGZhaWwgd2l0aCB0aGUgZm9sbG93aW5nIGVycm9yczoKPiAKPiAg ICAgICAgICAgICAgIEVJTlBST0dSRVNTCj4gICAgICAgICAgICAgICAgICAgICAgQSByZXNwb25z ZSB0byB0aGlzIG5vdGlmaWNhdGlvbiAgaGFzICBhbHJlYWR5ICBiZWVuCj4gICAgICAgICAgICAg ICAgICAgICAgc2VudC4KPiAKPiAgICAgICAgICAgICAgIEVJTlZBTCBBbiBpbnZhbGlkIHZhbHVl IHdhcyBzcGVjaWZpZWQgaW4gdGhlIGZsYWdzIGZpZWxkLgo+IAo+ICAgICAgICAgICAgICAgRUlO VkFMIFRoZSAgICAgICBmbGFncyAgICAgIGZpZWxkICAgICAgY29udGFpbmVkICAgICAgU0VD4oCQ Cj4gICAgICAgICAgICAgICAgICAgICAgQ09NUF9VU0VSX05PVElGX0ZMQUdfQ09OVElOVUUsIGFu ZCB0aGUgZXJyb3Igb3IgdmFsCj4gICAgICAgICAgICAgICAgICAgICAgZmllbGQgd2FzIG5vdCB6 ZXJvLgo+IAo+ICAgICAgICAgICAgICAgRU5PRU5UIFRoZSAgYmxvY2tlZCAgc3lzdGVtIGNhbGwg aW4gdGhlIHRhcmdldCBwcm9jZXNzIGhhcwo+ICAgICAgICAgICAgICAgICAgICAgIGJlZW4gaW50 ZXJydXB0ZWQgYnkgYSBzaWduYWwgaGFuZGxlci4KPiAKPiBOT1RFUwo+ICAgICAgICBUaGUgZmls ZSBkZXNjcmlwdG9yIHJldHVybmVkIHdoZW4gc2VjY29tcCgyKSBpcyBlbXBsb3llZCB3aXRoIHRo ZQo+ICAgICAgICBTRUNDT01QX0ZJTFRFUl9GTEFHX05FV19MSVNURU5FUiAgZmxhZyAgY2FuICBi ZSAgbW9uaXRvcmVkICB1c2luZwo+ICAgICAgICBwb2xsKDIpLCBlcG9sbCg3KSwgYW5kIHNlbGVj dCgyKS4gIFdoZW4gYSBub3RpZmljYXRpb24gIGlzICBwZW5k4oCQCj4gICAgICAgIGluZywgIHRo ZXNlIGludGVyZmFjZXMgaW5kaWNhdGUgdGhhdCB0aGUgZmlsZSBkZXNjcmlwdG9yIGlzIHJlYWTi gJAKPiAgICAgICAgYWJsZS4KClRoaXMgc2hvdWxkIGFsc28gbm90ZSB0aGF0IHdoZW4gYSBmaWx0 ZXIgYmVjb21lcyB1bnVzZWQsIGkuZS4gdGhlIGxhc3QKdGFzayB1c2luZyB0aGF0IGZpbHRlciBp biBpdHMgZmlsdGVyIGhpZXJhcmNoeSBpcyBkZWFkIChiZWVuCnJlYXBlZC9hdXRvcmVhcGVkKSAt PnBvbGwoKSB3aWxsIG5vdGlmeSB3aXRoIChFKVBPTExIVVAuCgo+IAo+ICAgICAgICDilIzilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDi lIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilIDilJAKPiAgICAgICAg4pSC RklYTUUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICDilIIK PiAgICAgICAg4pSc4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA4pSA 4pSkCj4gICAgICAgIOKUgkludGVyZXN0aW5nbHksIGFmdGVyIHRoZSBldmVudCAgaGFkICBiZWVu ICByZWNlaXZlZCwg4pSCCj4gICAgICAgIOKUgnRoZSAgZmlsZSBkZXNjcmlwdG9yIGluZGljYXRl cyBhcyB3cml0YWJsZSAodmVyaWZpZWQg4pSCCj4gICAgICAgIOKUgmZyb20gdGhlIHNvdXJjZSBj b2RlIGFuZCBieSBleHBlcmltZW50KS4gSG93IGlzIHRoaXMg4pSCCj4gICAgICAgIOKUgnVzZWZ1 bD8gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg4pSCCj4gICAg ICAgIOKUlOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKU gOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUgOKUmAo+ IAo+IEVYQU1QTEVTCj4gICAgICAgIFRoZSAoc29tZXdoYXQgY29udHJpdmVkKSBwcm9ncmFtIHNo b3duIGJlbG93IGRlbW9uc3RyYXRlcyB0aGUgdXNlCj4gICAgICAgIG9mIHRoZSBpbnRlcmZhY2Vz IGRlc2NyaWJlZCBpbiB0aGlzIHBhZ2UuICBUaGUgcHJvZ3JhbSBjcmVhdGVzICBhCj4gICAgICAg IGNoaWxkICBwcm9jZXNzICB0aGF0ICBzZXJ2ZXMgIGFzIHRoZSAidGFyZ2V0IiBwcm9jZXNzLiAg VGhlIGNoaWxkCj4gICAgICAgIHByb2Nlc3MgIGluc3RhbGxzICBhICBzZWNjb21wICBmaWx0ZXIg IHRoYXQgIHJldHVybnMgICB0aGUgICBTRUPigJAKPiAgICAgICAgQ09NUF9SRVRfVVNFUl9OT1RJ RiAgYWN0aW9uICB2YWx1ZSBpZiBhIGNhbGwgaXMgbWFkZSB0byBta2RpcigyKS4KPiAgICAgICAg VGhlIGNoaWxkIHByb2Nlc3MgdGhlbiBjYWxscyBta2RpcigyKSBvbmNlIGZvciBlYWNoIG9mICB0 aGUgIHN1cOKAkAo+ICAgICAgICBwbGllZCAgY29tbWFuZC1saW5lIGFyZ3VtZW50cywgYW5kIHJl cG9ydHMgdGhlIHJlc3VsdCByZXR1cm5lZCBieQo+ICAgICAgICB0aGUgY2FsbC4gIEFmdGVyIHBy b2Nlc3NpbmcgYWxsIGFyZ3VtZW50cywgdGhlIGNoaWxkIHByb2Nlc3MgdGVy4oCQCj4gICAgICAg IG1pbmF0ZXMuCj4gCj4gICAgICAgIFRoZSAgcGFyZW50ICBwcm9jZXNzICBhY3RzICBhcyAgdGhl IHN1cGVydmlzb3IsIGxpc3RlbmluZyBmb3IgdGhlCj4gICAgICAgIG5vdGlmaWNhdGlvbnMgdGhh dCBhcmUgZ2VuZXJhdGVkIHdoZW4gdGhlICB0YXJnZXQgIHByb2Nlc3MgIGNhbGxzCj4gICAgICAg IG1rZGlyKDIpLiAgIFdoZW4gc3VjaCBhIG5vdGlmaWNhdGlvbiBvY2N1cnMsIHRoZSBzdXBlcnZp c29yIGV4YW3igJAKPiAgICAgICAgaW5lcyB0aGUgbWVtb3J5IG9mIHRoZSB0YXJnZXQgcHJvY2Vz cyAodXNpbmcgL3Byb2MvW3BpZF0vbWVtKSAgdG8KPiAgICAgICAgZGlzY292ZXIgIHRoZSBwYXRo bmFtZSBhcmd1bWVudCB0aGF0IHdhcyBzdXBwbGllZCB0byB0aGUgbWtkaXIoMikKPiAgICAgICAg Y2FsbCwgYW5kIHBlcmZvcm1zIG9uZSBvZiB0aGUgZm9sbG93aW5nIGFjdGlvbnM6Cj4gCj4gICAg ICAgIMK3IElmIHRoZSBwYXRobmFtZSBiZWdpbnMgd2l0aCB0aGUgcHJlZml4ICIvdG1wLyIsIHRo ZW4gdGhlIHN1cGVy4oCQCj4gICAgICAgICAgdmlzb3IgIGF0dGVtcHRzICB0byAgY3JlYXRlICB0 aGUgIHNwZWNpZmllZCBkaXJlY3RvcnksIGFuZCB0aGVuCj4gICAgICAgICAgc3Bvb2ZzIGEgcmV0 dXJuIGZvciB0aGUgdGFyZ2V0ICBwcm9jZXNzICBiYXNlZCAgb24gIHRoZSAgcmV0dXJuCj4gICAg ICAgICAgdmFsdWUgIG9mICB0aGUgIHN1cGVydmlzb3IncyAgbWtkaXIoMikgY2FsbC4gIEluIHRo ZSBldmVudCB0aGF0Cj4gICAgICAgICAgdGhhdCBjYWxsIHN1Y2NlZWRzLCB0aGUgc3Bvb2ZlZCBz dWNjZXNzICByZXR1cm4gIHZhbHVlICBpcyAgdGhlCj4gICAgICAgICAgbGVuZ3RoIG9mIHRoZSBw YXRobmFtZS4KPiAKPiAgICAgICAgwrcgSWYgIHRoZSBwYXRobmFtZSBiZWdpbnMgd2l0aCAiLi8i IChpLmUuLCBpdCBpcyBhIHJlbGF0aXZlIHBhdGjigJAKPiAgICAgICAgICBuYW1lKSwgdGhlIHN1 cGVydmlzb3Igc2VuZHMgYSAgU0VDQ09NUF9VU0VSX05PVElGX0ZMQUdfQ09OVElOVUUKPiAgICAg ICAgICByZXNwb25zZSAgdG8gIHRoZSAga2VybmVsIHRvIHNheSB0aGF0IGtlcm5lbCBzaG91bGQg ZXhlY3V0ZSB0aGUKPiAgICAgICAgICB0YXJnZXQgcHJvY2VzcydzIG1rZGlyKDIpIGNhbGwuCgpQ b3RlbnRpYWxseSBwcm9ibGVtYXRpYyBpZiB0aGUgdHdvIHByb2Nlc3NlcyBoYXZlIHRoZSBzYW1l IHByaXZpbGVnZQpsZXZlbCBhbmQgdGhlIHN1cGVydmlzb3IgaW50ZW5kcyBfQ09OVElOVUUgdG8g bWVhbiAiaXMgc2FmZSB0byBleGVjdXRlIi4KQW4gYXR0YWNrZXIgY291bGQgdHJ5IHRvIHJlLXdy aXRlIGFyZ3VtZW50cyBhZmFpY3QuCkEgZ29vZCBhbiBlYXN5IGV4YW1wbGUgaXMgdXN1YWxseSBt a25vZCgpIGluIGEgdXNlciBuYW1lc3BhY2UuIEEKX0NPTlRJTlVFIGlzIGFsd2F5cyBzYWZlIHNp bmNlIHlvdSBjYW4ndCBjcmVhdGUgZGV2aWNlIG5vZGVzIGFueXdheS4KClNvcnJ5LCBJIGNhbid0 IHJldmlldyB0aGUgcmVzdCBpbiBzdWZmaWNpZW50IGRldGFpbCBzaW5jZSBJJ20gb24KdmFjYXRp b24gc3RpbGwgc28gSSdtIGp1c3QgZ29pbmcgdG8gc2h1dCB1cCBub3cuIDopCgpDaHJpc3RpYW4K X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KQ29udGFpbmVy cyBtYWlsaW5nIGxpc3QKQ29udGFpbmVyc0BsaXN0cy5saW51eC1mb3VuZGF0aW9uLm9yZwpodHRw czovL2xpc3RzLmxpbnV4Zm91bmRhdGlvbi5vcmcvbWFpbG1hbi9saXN0aW5mby9jb250YWluZXJz