Skip to content

Instantly share code, notes, and snippets.

@Marc-Aldorasi-Imprivata
Created August 23, 2018 15:11
Show Gist options
  • Select an option

  • Save Marc-Aldorasi-Imprivata/7f213a00909aa72a1ff42123efbf0505 to your computer and use it in GitHub Desktop.

Select an option

Save Marc-Aldorasi-Imprivata/7f213a00909aa72a1ff42123efbf0505 to your computer and use it in GitHub Desktop.
175 execve("/usr/bin/unshare", ["unshare", "--pid", "--fork", "sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7fffe97ccc30 /* 14 vars */) = 0
175 brk(NULL) = 0x7ffff6db7000
175 access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
175 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
175 openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=22386, ...}) = 0
175 mmap(NULL, 22386, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f26b000
175 close(3) = 0
175 access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
175 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
175 read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260\34\2\0\0\0\0\0@\0\0\0\0\0\0\0\220\351\36\0\0\0\0\0\0\0\0\0@\0008\0\n\0@\0I\0H\0\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\3\0\0\0\4\0\0\0P\335\33\0\0\0\0\0P\335\33\0\0\0\0\0P\335\33\0\0\0\0\0\34\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\240j\36\0\0\0\0\0\240j\36\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0 v\36\0\0\0\0\0 v>\0\0\0\0\0"..., 832) = 832
175 fstat(3, {st_mode=S_IFREG|0755, st_size=2030544, ...}) = 0
175 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f438f260000
175 mmap(NULL, 4131552, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f438ec00000
175 mprotect(0x7f438ede7000, 2097152, PROT_NONE) = 0
175 mmap(0x7f438efe7000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1e7000) = 0x7f438efe7000
175 mmap(0x7f438efed000, 15072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f438efed000
175 close(3) = 0
175 arch_prctl(ARCH_SET_FS, 0x7f438f261500) = 0
175 mprotect(0x7f438efe7000, 16384, PROT_READ) = 0
175 mprotect(0x7f438f603000, 4096, PROT_READ) = 0
175 mprotect(0x7f438f227000, 4096, PROT_READ) = 0
175 munmap(0x7f438f26b000, 22386) = 0
175 geteuid() = 0
175 getegid() = 0
175 brk(NULL) = 0x7ffff6db7000
175 brk(0x7ffff6dd8000) = 0x7ffff6dd8000
175 openat(AT_FDCWD, "/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=1683056, ...}) = 0
175 mmap(NULL, 1683056, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f08c000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=2995, ...}) = 0
175 read(3, "# Locale name alias data base.\n# Copyright (C) 1996-2018 Free Software Foundation, Inc.\n#\n# This program is free software; you can redistribute it and/or modify\n# it under the terms of the GNU General Public License as published by\n# the Free Software Foun"..., 512) = 512
175 read(3, "See the\n# GNU General Public License for more details.\n#\n# You should have received a copy of the GNU General Public License\n# along with this program; if not, see <http://www.gnu.org/licenses/>.\n\n# The format of this file is the same as for the correspond"..., 512) = 512
175 read(3, "nd for the time being for\n# backward compatibility. Nobody should rely on the names defined here.\n# Locales should always be specified by their full name.\n\n# Note: This file used to contain the following lines:\n#\tbokmaal\t\tnb_NO.ISO-8859-1\n#\tfranc,ais\tfr_F"..., 512) = 512
175 read(3, "hese lines were removed\n# because they caused 'locale -a' to output text encoded in Latin-1,\n# which broke applications in UTF-8 locales. See:\n# https://sourceware.org/bugzilla/show_bug.cgi?id=18412\n\nbokmal\t\tnb_NO.ISO-8859-1\ncatalan\t\tca_ES.ISO-8859-1\ncroa"..., 512) = 512
175 read(3, "8859-1\ngalego\t\tgl_ES.ISO-8859-1\ngalician\tgl_ES.ISO-8859-1\ngerman\t\tde_DE.ISO-8859-1\ngreek el_GR.ISO-8859-7\nhebrew he_IL.ISO-8859-8\nhrvatski\thr_HR.ISO-8859-2\nhungarian hu_HU.ISO-8859-2\nicelandic is_IS.ISO-8859-1\nitalian "..., 512) = 512
175 read(3, "O.ISO-8859-1 nb_NO.ISO-8859-1\nnorwegian nb_NO.ISO-8859-1\nnynorsk\t\tnn_NO.ISO-8859-1\npolish pl_PL.ISO-8859-2\nportuguese pt_PT.ISO-8859-1\nromanian ro_RO.ISO-8859-2\nrussian ru_RU.KOI8-R\nslovak sk_SK.ISO-8859-2\nsloven"..., 512) = 435
175 read(3, "", 512) = 0
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_IDENTIFICATION", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=252, ...}) = 0
175 mmap(NULL, 252, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f270000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/x86_64-linux-gnu/gconv/gconv-modules.cache", O_RDONLY) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=26376, ...}) = 0
175 mmap(NULL, 26376, PROT_READ, MAP_SHARED, 3, 0) = 0x7f438f269000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MEASUREMENT", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=23, ...}) = 0
175 mmap(NULL, 23, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f268000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_TELEPHONE", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=47, ...}) = 0
175 mmap(NULL, 47, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f267000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_ADDRESS", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=131, ...}) = 0
175 mmap(NULL, 131, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f266000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_NAME", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=62, ...}) = 0
175 mmap(NULL, 62, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f265000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_PAPER", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=34, ...}) = 0
175 mmap(NULL, 34, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f264000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MESSAGES", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFDIR|0755, st_size=512, ...}) = 0
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MESSAGES/SYS_LC_MESSAGES", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=48, ...}) = 0
175 mmap(NULL, 48, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f263000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_MONETARY", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=270, ...}) = 0
175 mmap(NULL, 270, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f262000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_COLLATE", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=1516558, ...}) = 0
175 mmap(NULL, 1516558, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438ea8d000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_TIME", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=3360, ...}) = 0
175 mmap(NULL, 3360, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f25f000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_NUMERIC", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=50, ...}) = 0
175 mmap(NULL, 50, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f25e000
175 close(3) = 0
175 openat(AT_FDCWD, "/usr/lib/locale/C.UTF-8/LC_CTYPE", O_RDONLY|O_CLOEXEC) = 3
175 fstat(3, {st_mode=S_IFREG|0644, st_size=199772, ...}) = 0
175 mmap(NULL, 199772, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f438f22d000
175 close(3) = 0
175 unshare(CLONE_NEWPID) = 0
175 clone(child_stack=NULL, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7f438f2617d0) = 176
175 wait4(176, <unfinished ...>
176 execve("/usr/local/sbin/sh", ["sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7ffffed184b0 /* 14 vars */) = -1 ENOENT (No such file or directory)
176 execve("/usr/local/bin/sh", ["sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7ffffed184b0 /* 14 vars */) = -1 ENOENT (No such file or directory)
176 execve("/usr/sbin/sh", ["sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7ffffed184b0 /* 14 vars */) = -1 ENOENT (No such file or directory)
176 execve("/usr/bin/sh", ["sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7ffffed184b0 /* 14 vars */) = -1 ENOENT (No such file or directory)
176 execve("/sbin/sh", ["sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7ffffed184b0 /* 14 vars */) = -1 ENOENT (No such file or directory)
176 execve("/bin/sh", ["sh", "-c", "/mnt/c/Windows/System32/notepad.exe && true"], 0x7ffffed184b0 /* 14 vars */) = 0
176 brk(NULL) = 0x7ffff27d5000
176 access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
176 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
176 openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
176 fstat(3, {st_mode=S_IFREG|0644, st_size=22386, ...}) = 0
176 mmap(NULL, 22386, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f21b706a000
176 close(3) = 0
176 access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
176 openat(AT_FDCWD, "/lib/x86_64-linux-gnu/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
176 read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260\34\2\0\0\0\0\0@\0\0\0\0\0\0\0\220\351\36\0\0\0\0\0\0\0\0\0@\0008\0\n\0@\0I\0H\0\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0000\2\0\0\0\0\0\0000\2\0\0\0\0\0\0\10\0\0\0\0\0\0\0\3\0\0\0\4\0\0\0P\335\33\0\0\0\0\0P\335\33\0\0\0\0\0P\335\33\0\0\0\0\0\34\0\0\0\0\0\0\0\34\0\0\0\0\0\0\0\20\0\0\0\0\0\0\0\1\0\0\0\5\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\240j\36\0\0\0\0\0\240j\36\0\0\0\0\0\0\0 \0\0\0\0\0\1\0\0\0\6\0\0\0 v\36\0\0\0\0\0 v>\0\0\0\0\0"..., 832) = 832
176 fstat(3, {st_mode=S_IFREG|0755, st_size=2030544, ...}) = 0
176 mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f21b7060000
176 mmap(NULL, 4131552, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f21b6a00000
176 mprotect(0x7f21b6be7000, 2097152, PROT_NONE) = 0
176 mmap(0x7f21b6de7000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1e7000) = 0x7f21b6de7000
176 mmap(0x7f21b6ded000, 15072, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f21b6ded000
176 close(3) = 0
176 arch_prctl(ARCH_SET_FS, 0x7f21b7061540) = 0
176 mprotect(0x7f21b6de7000, 16384, PROT_READ) = 0
176 mprotect(0x7f21b741b000, 8192, PROT_READ) = 0
176 mprotect(0x7f21b7027000, 4096, PROT_READ) = 0
176 munmap(0x7f21b706a000, 22386) = 0
176 getuid() = 0
176 getgid() = 0
176 getpid() = 1
176 rt_sigaction(SIGCHLD, {sa_handler=0x7f21b7212200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER, sa_restorer=0x7f21b6a3ef20}, NULL, 8) = 0
176 geteuid() = 0
176 brk(NULL) = 0x7ffff27d5000
176 brk(0x7ffff27f6000) = 0x7ffff27f6000
176 getppid() = 0
176 getcwd("/home/marc", 4096) = 11
176 geteuid() = 0
176 getegid() = 0
176 rt_sigaction(SIGINT, NULL, {sa_handler=SIG_DFL, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f6e931aef20}, 8) = 0
176 rt_sigaction(SIGINT, {sa_handler=0x7f21b7212200, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER, sa_restorer=0x7f21b6a3ef20}, NULL, 8) = 0
176 rt_sigaction(SIGQUIT, NULL, {sa_handler=SIG_DFL, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f6e931aef20}, 8) = 0
176 rt_sigaction(SIGQUIT, {sa_handler=SIG_DFL, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER, sa_restorer=0x7f21b6a3ef20}, NULL, 8) = 0
176 rt_sigaction(SIGTERM, NULL, {sa_handler=SIG_DFL, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7f6e931aef20}, 8) = 0
176 rt_sigaction(SIGTERM, {sa_handler=SIG_DFL, sa_mask=~[RTMIN RT_1], sa_flags=SA_RESTORER, sa_restorer=0x7f21b6a3ef20}, NULL, 8) = 0
176 clone(child_stack=NULL, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x7f21b7061810) = 2
177 execve("/mnt/c/Windows/System32/notepad.exe", ["/mnt/c/Windows/System32/notepad.exe"], 0x7f21b741fbc0 /* 15 vars */ <unfinished ...>
176 wait4(-1, <unfinished ...>
177 <... execve resumed> ) = 0
177 arch_prctl(ARCH_SET_FS, 0x6186d8) = 0
177 set_tid_address(0x618710) = 2
177 getpid() = 2
177 getcwd("/home/marc", 4096) = 11
177 open("/dev/lxssclient", O_RDWR) = 3
177 ioctl(3, _IOC(0, 0, 0x2f, 0x22), 0x7ffff3612b30) = 0
177 open("/mnt/c/Windows/System32/notepad.exe", O_RDONLY) = 5
177 brk(NULL) = 0x20fc000
177 brk(0x20fd000) = 0x20fd000
177 ioctl(3, _IOC(0, 0, 0x3f, 0x22), 0x7ffff36129d0) = 0
177 close(5) = 0
177 open("/home/marc", O_RDONLY|O_DIRECTORY) = 5
177 ioctl(3, _IOC(0, 0, 0x3f, 0x22), 0x7ffff36129d0) = -1 EINVAL (Invalid argument)
177 close(5) = 0
177 getpid() = 2
177 ioctl(4, _IOC(0, 0, 0x97, 0x22), 0x7ffff3612a70) = -1 EINVAL (Invalid argument)
177 writev(2, [{iov_base="/mnt/c/Windows/System32/notepad.exe: Invalid argument\n", iov_len=54}, {iov_base=NULL, iov_len=0}], 2) = 54
177 close(3) = 0
177 close(4) = 0
177 exit_group(1) = ?
177 +++ exited with 1 +++
176 <... wait4 resumed> [{WIFEXITED(s) && WEXITSTATUS(s) == 1}], 0, NULL) = 2
176 --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=2, si_uid=0, si_status=1, si_utime=0, si_stime=0} ---
176 rt_sigreturn({mask=[]}) = 2
176 exit_group(1) = ?
176 +++ exited with 1 +++
175 <... wait4 resumed> [{WIFEXITED(s) && WEXITSTATUS(s) == 1}], 0, NULL) = 176
175 --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_EXITED, si_pid=176, si_uid=0, si_status=1, si_utime=0, si_stime=0} ---
175 close(1) = 0
175 close(2) = 0
175 exit_group(1) = ?
175 +++ exited with 1 +++
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment