Skip to content

Instantly share code, notes, and snippets.

View zhuowei's full-sized avatar

zhuowei

View GitHub Profile
[ 244.046261] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000200
[ 244.046320] Mem abort info:
[ 244.046322] ESR = 0x0000000086000004
[ 244.046324] EC = 0x21: IABT (current EL), IL = 32 bits
[ 244.046327] SET = 0, FnV = 0
[ 244.046329] EA = 0, S1PTW = 0
[ 244.046333] FSC = 0x04: level 0 translation fault
[ 244.046336] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000116b1f000
[ 244.046338] [0000000000000200] pgd=0000000000000000, p4d=0000000000000000
[ 244.046355] Internal error: Oops: 0000000086000004 [#1] SMP

Please explain why vm_shared_region_map_file is calling vm_shared_region_undo_mappings with an incorrect srf_current_mappings_count argument.


The bug occurs due to a mismatch between the caller's argument interpretation and the parameter design of vm_shared_region.c, which is exacerbated by confusing
parameter names in the function declaration.
──────

1. The Incorrect Call

In vm_shared_region.c, when a slide rel

Chat Conversation

Note: This is purely the output of the chat conversation and does not contain any raw data, codebase snippets, etc. used to generate the output.

User Input

msgctl in bsd/kern/sysv_msg.c, when handling IPC_SET, calls SYSV_MSG_SUBSYS_UNLOCK to drop the lock before running copyin. Why is this unsafe?

Grep searched codebase

@zhuowei
zhuowei / codex_deep_links.md
Last active April 18, 2026 06:21
Codex app deep link schemes
```
{
"value": "00001624-1212-efde-1623-785feabcd123",
"address": "0x7498120"
},
{
"value": "00001625-1212-efde-1623-785feabcd123",
"address": "0x7498128"
},
{
6000.1.17f1
hw4-customer_p11_smartbrick-upgrade-v0.72.1
~P11
ROFS
P11@
Lqlq
0l @
0l @
~o'?
4o$?
6000.1.17f1
p11_smartbrick-upgrade-v0.48.2-hw4.bad.crc
~P11
o(Nc
ROFS
P11@
Lqlq
0l @
0l @
~o'?
$ strings - base/assets/bin/Data/Managed/Metadata/global-metadata.dat |grep ProtocolProcessors
LEGO.Connectkit.ProtocolProcessors
LEGO.Connectkit.ProtocolProcessors.dll
ConnectKit.ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.SignCommand
ConnectKit.ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.Property
ProtocolProcessors
ProtocolProcessors.WirelessDataExchangeProtocol
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.Verify
$ strings - ./assets/bin/Data/Managed/Metadata/global-metadata.dat|grep WDXClient
ConnectKit.ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.SignCommand
ConnectKit.ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.Property
ConnectKit.WirelessDataExchangeProtocol.WDXClient.Validators
ConnectKit.WirelessDataExchangeProtocol.WDXClient.States.FetchFile
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.Verify
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.UploadFile
ProtocolProcessors.WirelessDataExchangeProtocol.WDXClient.States.EraseFile
airshield::SHA256::Incremental::update: 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF
70cc5380a8 05 b5 e3 76 dd 00 17 f1 9a d3 78 b4 95 18 7f 72 ...v......x....r
airshield::SHA256::Incremental::update: 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF
70cc5381b8 01 57 b2 f6 7f fa 0b 00 be f0 05 fd d8 4c b0 5b .W...........L.[
70cc5381c8 dc a2 1f 81 35 a9 c1 12 d5 36 34 e2 85 6c e4 15 ....5....64..l..
airshield::SHA256::Incremental::update: 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF
6e1575a8d0 7e 50 30 2f 39 85 0e 06 9a 1f fb 4d 9c 06 60 e9 ~P0/9......M..`.
6e1575a8e0 72 c7 b1 2d c1 49 68 01 14 11 e3 36 6b 5a b6 ef r..-.Ih....6kZ..
6e1575a8f0 35 85 4c 82 f5 7b e4 23 b0 32 78 6f 1f c8 c0 a5 5.L..{.#.2xo....
6e1575a900 3d a9 16 aa 46 6c 34 cd b2 da d6 4d 1b e4 97 7b =...Fl4....M...{