From: "Toralf Förster" <toralf.foerster@gmx.de>
To: Linux Kernel <linux-kernel@vger.kernel.org>
Subject: fuzz testing lets kernel audit complains in the linkat syscall only
Date: Mon, 20 May 2013 22:34:06 +0200 [thread overview]
Message-ID: <519A88BE.8030309@gmx.de> (raw)
[-- Attachment #1: Type: text/plain, Size: 2183 bytes --]
While fuzz testing a 3.9.3 kernel I'm wonder why the kernel audit does complain
about a file in the syscall "unlinkat" - but audit does not complain when that file
was created/modified etc.
If this is intended - please press the delete button now.
Not ? Ok.
At a 32bit stable Gentoo linux with kernel 3.9.3 I got messages like:
kernel: type=1702 audit(1369079376.420:37): op=linkat action=denied pid=13536 comm="trinity-child1" path="/dev" dev="loop0" ino=8146
when I chrooted into a 32bit stable Gentoo Linux image and run a fuzz tester:
$> trinity -C 4 -m -x linkat
(4 childs, monochrome, excluded syscall "linkat" to test only those cases,
where linkat was not directly called by the fuzzer),
The appropriate log entry gives:
$> cat x
[13536] [35] unlinkat(dfd=390, pathname="
���T̫̺̳o̬̜ ì̬͎̲̟nv̖̗̻̣̹̕o͖̗̠̜̤k͍͚̹͖̼e̦̗̪͍̪͍ ̬ͅt̕h̠͙̮͕͓e̱̜̗͙̭ ̥͔̫͙̪͍̣͝ḥi̼̦͈̼v̩̟͚̞͎e͈̟̻͙̦̤-m̷̘̝̱í͚̞̦̳n̝̲̯̙̮͞d̴̺̦͕̫ ̗̭̘͎͖r̞͎̜̜͖͎̫͢ep͇r̝̯̝͖͉͎̺e̴s̥e̵̖̳͉͍̩̗n̢͓̪͕̜̰̠̦t̺̞̰i͟n̮̦̖̟g̮͍̱̻͍̜̳ ̳c̖̮̙̣̰̠̩h̷̗͍̖͙̭͇͈a̧͎̯̹̲̺̫ó̭̞̜̣̯͕s̶̤̮̩̘.̨̻̪̖͔ ̳̭̦̭̭̦̞́I̠͍̮n͇̹̪̬v̴͖̭̗̖o̸k̬̤͓͚̠͍i͜n̛̩̹͉̘̹g͙ ̠̥ͅt̰͖͞h̫̼̪e̟̩̝ ̭̠̲̫͔fe̤͇̝̱e͖̮̠̹̭͖͕l͖̲̘͖̠̪i̢̖͎̮̗̯͓̩n̸̰g̙̱̘̗͚̬ͅ ͍o͍͍̩̮͢f̖͓̦̥ ̘͘c̵̫̱̗͚͓̦h͝a̝͍͍̳̣͖͉o͙̟s̤̞.̙̝̭̣̳̼͟ ̢̻͖͓̬̞̰̦W̮̲̝̼̩̝͖i͖͖͡ͅt̘̯͘h̷̬̖̞̙̰̭̳ ̭̪̕o̥̤̺̝̼̰̯͟ṳ̞̭̤t̨͚̥̗ ̟̺̫̩̤̳̩o̟̰̩̖ͅr̞̘̫̩̼d̡͍̬͎̪̺͚͔e͓͖̝̙r̰͖̲̲̻̠.̺̝̺̟͈ ̣̭T̪̩̼h̥̫̪͔̀e̫̯͜ ̨N̟e͔̤zp̮̭͈̟é͉͈ṛ̹̜̺̭͕d̺̪̜͇͓i̞á͕̹
(the file "x" is attached, it contains the next log line of the next
trinity child too due to a missing new line).
FWIW the used Gentoo linux image is an user mode linux image.
I however just mounted it using the loop device, chrooted into it and
run the fuzzer instead of calling that image with a linux exe.
--
MfG/Sincerely
Toralf Förster
pgp finger print: 7B1A 07F4 EC82 0F90 D4C2 8936 872A E508 7DB6 9DA3
[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #2: x --]
[-- Type: text/plain; charset=UTF-8; name="x", Size: 1117 bytes --]
[13536] [35] unlinkat(dfd=390, pathname="
¿ìÃT̫̺̳oÌ¬Ì Ã¬Ì¬Í̲ÌnvÌÌ̻̣̹ÌoÍÌÌ Ì̤kÍÍ̹Í̼e̦Ì̪ÍÌªÍ Ì¬Í
tÌhÌ ÍÌ®ÍÍe̱ÌÌÍÌ Ì¥ÍÌ«Í̪ÍÌ£Íḥi̼̦Í̼vÒÌ©ÌÍÌÍeÍÌÌ»Í̦̤-mÌ·ÌÌ̱ÃÍÌ̦̳nÌ̲̯ÌÌ®Íd̴̺̦ÍÌ« ÌÌÌÍÍrÌÍÌÌÍÍ̫͢epÍrÌ̯ÌÍÍÍ̺eÌ´sÌ¥e̵Ì̳ÍÍÌ©ÌnÌ¢Í̪ÍÌÌ°Ì Ì¦t̺Ḭ̀iÍnÒ̮̦ÌÌgÌ®Í̱̻ÍÌ̳ ̳cÌÌ®ÌÌ£Ì°Ì Ì©hÌ·ÌÍÌÍÌÍÍa̧Í̯̹̲̺̫óÌÌỊ̯̀Ís̶̤̮̩Ì.̨̻̪ÌÍ Ì³Ì̦ÌÌ̦ÌÌIÌ ÍÌ®nÍ̹̪̬vÌ´ÍÌÌÌo̸kÒ̬̤ÍÍÌ ÍiÍnÌ̩̹ÍÌ̹gÍ Ì Ì¥Í
t̰ÍÍh̫̼̪eÌÌ©Ì ÌÌ Ì²Ì«Ífe̤ÍÌ̱eÍÌ®Ì Ì¹ÌÍÍlÍ̲ÌÍÌ ÌªiÌ¢ÌÍÌ®Ì̯ÍÌ©n̸̰gÌ̱ÌÌÍ̬Í
ÍoÍÍ̩̮͢fÌÍ̦̥ ÌÍc̵̫̱ÌÍÍ̦hÍaÌÍÍ̳̣ÍÍoÍÌs̤Ì.ÌÌÌÌ£Ì³Ì¼Í Ì¢Ì»ÍÍ̬Ḭ̦̀W̮̲Ì̼̩ÌÍiÍÍÍ¡Í
tÌ̯Íh̷̬ÌÌḬ̀Ì̳ Ì̪Ìo̥̤̺Ì̼̰̯Íá¹³ÌÌ̤t̨ÍÌ¥Ì Ì̺̫̩̤̳̩oḬ̩̀ÌÍ
rÌÌ̫̩̼dÌ¡Í̬Í̪̺ÍÍeÍÍÌÌr̰ÍÌ²Ì²Ì»Ì .̺Ì̺ÌÍ Ì£ÌT̪̩̼h̥̫̪ÍÌeÌ«Ì¯Í Ì¨NÌeÒÍ̤zpÌ®ÌÍÌéÍÍá¹Ì¹Ì̺ÌÍd̺̪ÌÍÍiÌáÍ̹[13537] [0] setgroups16(gidsetsize=0x61dc2fe3, grouplist=4097) = -1 (Operation not permitted)
next reply other threads:[~2013-05-20 20:34 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-05-20 20:34 Toralf Förster [this message]
2013-05-20 21:03 ` fuzz testing lets kernel audit complains in the linkat syscall only Toralf Förster
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=519A88BE.8030309@gmx.de \
--to=toralf.foerster@gmx.de \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox