skeletonkey_offsets_resolve() runs sources in priority order: env vars first,
then /proc/kallsyms. On any default host kallsyms returns all-zero addresses
(kptr_restrict), and parse_symfile treated "all zero" by UNCONDITIONALLY zeroing
modprobe_path/init_task — clobbering the values apply_env had just set from
SKELETONKEY_MODPROBE_PATH / SKELETONKEY_INIT_TASK. Net effect: the documented
env-var offset override silently did nothing, so every --full-chain kernel
primitive reported "offsets couldn't be resolved" even when correct offsets were
supplied. Now the all-zero path only clears fields it tagged OFFSETS_FROM_KALLSYMS
itself, preserving env (and table/System.map) values.
Verified on Ubuntu 22.04.0 / 5.15.0-25: with SKELETONKEY_MODPROBE_PATH set, the
resolver now reports "modprobe_path=0x... (env)", the modprobe_path finisher
engages, and nf_tables' pipapo arb-write fires. (nf_tables itself still returns
an honest EXPLOIT_FAIL: the reconstructed double-free arb-write doesn't reliably
land the write yet — recorded in docs/EXPLOITED.md.) This fix is the prerequisite
for verifying any of the ~13 primitive full-chains. Unit harness green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0118iUgHY44hdRtANgyCmu7y
Adds the infrastructure the 7 🟡 PRIMITIVE modules can wire into for
full-chain root pops.
core/offsets.{c,h}: four-source kernel-symbol resolution chain
1. env vars (IAMROOT_MODPROBE_PATH, IAMROOT_INIT_TASK, …)
2. /proc/kallsyms (only useful when kptr_restrict=0 or root)
3. /boot/System.map-$(uname -r) (world-readable on some distros)
4. embedded table keyed by uname-r glob (entries are
relative-to-_text, applied on top of an EntryBleed kbase leak;
seeded empty in v0.2.0 — schema-only — to honor the
no-fabricated-offsets rule).
core/finisher.{c,h}: shared root-pop helpers given a module's
arb-write primitive.
Pattern A (modprobe_path):
write payload script /tmp/iamroot-mp-<pid>.sh, arb-write
modprobe_path ← that path, execve unknown-format trigger,
wait for /tmp/iamroot-pwn-<pid> sentinel + setuid bash copy,
spawn root shell.
Pattern B (cred uid): stub — needs arb-READ too; modules use
Pattern A unless they have read+write.
On offset-resolution failure: prints a verbose how-to-populate
diagnostic and returns EXPLOIT_FAIL honestly.
core/module.h: + bool full_chain in iamroot_ctx
iamroot.c: + --full-chain flag (longopt 7, sets ctx.full_chain)
+ help text describing primitive-only-by-default + the
opt-in to attempt the full chain.
Makefile: add core/offsets.o + core/finisher.o to CORE_SRCS.
Build clean on Debian 6.12.86; --help renders the new flag.