PageSourceSearch

https://xdk.dev/about/introduction.html

html xdk.dev collected 2026-09-28 07:13:11 UTC 13,982 bytes, 225 lines download raw bytes

1
2
3<!DOCTYPE html>
4<html class="writer-html5" lang="en" data-content_root="../">
5<head>
6  <meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" />
7
8  <meta name="viewport" content="width=device-width, initial-scale=1.0" />
9  <title>Introduction &mdash; kernelXDK 0.0.1 documentation</title>
10      <link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=80d5e7a1" />
11      <link rel="stylesheet" type="text/css" href="../_static/css/theme.css?v=e59714d7" />
12      <link rel="stylesheet" type="text/css" href="../_static/collapsible-lists/css/tree_view.css?v=a885cde7" />
13
14  
15      
15<script src="../_static/jquery.js?v=5d32c60e"></script>
15
16      
16<script src="../_static/_sphinx_javascript_frameworks_compat.js?v=2cd50e6c"></script>
16
17      
17<script src="../_static/documentation_options.js?v=d45e8c67"></script>
17
18      
18<script src="../_static/doctools.js?v=9bcbadda"></script>
18
19      
19<script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
19
20      
20<script src="../_static/collapsible-lists/js/CollapsibleLists.compressed.js?v=73120307"></script>
20
21      
21<script src="../_static/collapsible-lists/js/apply-collapsible-lists.js?v=660e4f45"></script>
21
22      
22<script type="module" src="https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.esm.min.mjs"></script>
22
23      
23<script type="module" src="https://cdn.jsdelivr.net/npm/@mermaid-js/[email protected]/dist/mermaid-layout-elk.esm.min.mjs"></script>
23
24      
24<script type="module">import mermaid from "https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.esm.min.mjs";import elkLayouts from "https://cdn.jsdelivr.net/npm/@mermaid-js/[email protected]/dist/mermaid-layout-elk.esm.min.mjs";mermaid.registerLayoutLoaders(elkLayouts);mermaid.initialize({startOnLoad:false});</script>
24
25      
25<script src="https://cdn.jsdelivr.net/npm/[email protected]/dist/d3.min.js"></script>
25
26      
26<script type="module">
27import mermaid from "https://cdn.jsdelivr.net/npm/[email protected]/dist/mermaid.esm.min.mjs";
28window.addEventListener("load", () => mermaid.run());
29</script>
29
30    
30<script src="../_static/js/theme.js"></script>
30
31    <link rel="index" title="Index" href="../genindex.html" />
32    <link rel="search" title="Search" href="../search.html" />
33    <link rel="next" title="KXDB Database" href="kxdb_database.html" />
34    <link rel="prev" title="kernelXDK" href="../index.html" /> 
35</head>
36
37<body class="wy-body-for-nav"> 
38  <div class="wy-grid-for-nav">
39    <nav data-toggle="wy-nav-shift" class="wy-nav-side">
40      <div class="wy-side-scroll">
41        <div class="wy-side-nav-search" >
42
43          
44          
45          <a href="../index.html" class="icon icon-home">
46            kernelXDK
47          </a>
48<div role="search">
49  <form id="rtd-search-form" class="wy-form" action="../search.html" method="get">
50    <input type="text" name="q" placeholder="Search docs" aria-label="Search docs" />
51    <input type="hidden" name="check_keywords" value="yes" />
52    <input type="hidden" name="area" value="default" />
53  </form>
54</div>
55        </div><div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="Navigation menu">
56              <p class="caption" role="heading"><span class="caption-text">About</span></p>
57<ul class="current">
58<li class="toctree-l1 current"><a class="current reference internal" href="#">Introduction</a><ul>
59<li class="toctree-l2"><a class="reference internal" href="#rationale-behind-the-kernelxdk">Rationale behind the kernelXDK</a></li>
60<li class="toctree-l2"><a class="reference internal" href="#limitations">Limitations</a></li>
61</ul>
62</li>
63<li class="toctree-l1"><a class="reference internal" href="#what-is-kernelxdk">What is kernelXDK?</a><ul>
64<li class="toctree-l2"><a class="reference internal" href="#tools">Tools</a></li>
65<li class="toctree-l2"><a class="reference internal" href="#future-ambitions">Future ambitions</a><ul>
66<li class="toctree-l3"><a class="reference internal" href="#mid-term-plans">Mid-term plans</a></li>
67<li class="toctree-l3"><a class="reference internal" href="#areas-to-explore">Areas to explore</a></li>
68</ul>
69</li>
70</ul>
71</li>
72<li class="toctree-l1"><a class="reference internal" href="kxdb_database.html">KXDB Database</a></li>
73</ul>
74<p class="caption" role="heading"><span class="caption-text">libxdk</span></p>
75<ul>
76<li class="toctree-l1"><a class="reference internal" href="../libxdk/README.html">What is libxdk?</a></li>
77<li class="toctree-l1"><a class="reference internal" href="../libxdk/README.html#installation">Installation</a></li>
78<li class="toctree-l1"><a class="reference internal" href="../libxdk/how_to_get_started.html">How to get started</a></li>
79<li class="toctree-l1"><a class="reference internal" href="../libxdk/sample_exploit.html">How to port an existing exploit</a></li>
80<li class="toctree-l1"><a class="reference internal" href="../libxdk/api.html">API Reference</a></li>
81</ul>
82<p class="caption" role="heading"><span class="caption-text">Command Line Tools</span></p>
83<ul>
84<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/image_db.html">Kernel Image DB</a></li>
85<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/image_runner.html">Kernel Image Runner</a></li>
86<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/kxdb_tool.html">KXDB Tool</a></li>
87<li class="toctree-l1"><a class="reference internal" href="../commandline_tools/rop_generator.html">Kernel ROP Generator</a></li>
88</ul>
89
90        </div>
91      </div>
92    </nav>
93
94    <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap"><nav class="wy-nav-top" aria-label="Mobile navigation menu" >
95          <i data-toggle="wy-nav-top" class="fa fa-bars"></i>
96          <a href="../index.html">kernelXDK</a>
97      </nav>
98
99      <div class="wy-nav-content">
100        <div class="rst-content">
101          <div role="navigation" aria-label="Page navigation">
102  <ul class="wy-breadcrumbs">
103      <li><a href="../index.html" class="icon icon-home" aria-label="Home"></a></li>
104      <li class="breadcrumb-item active">Introduction</li>
105      <li class="wy-breadcrumbs-aside">
106            <a href="../_sources/about/introduction.md.txt" rel="nofollow"> View page source</a>
107      </li>
108  </ul>
109  <hr/>
110</div>
111          <div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
112           <div itemprop="articleBody">
113             
114  <section id="introduction">
115<h1>Introduction<a class="headerlink" href="#introduction" title="Link to this heading"></a></h1>
116<section id="rationale-behind-the-kernelxdk">
117<h2>Rationale behind the kernelXDK<a class="headerlink" href="#rationale-behind-the-kernelxdk" title="Link to this heading"></a></h2>
118<p>The rationale behind the current Beta version of the kernelXDK (Kernel eXploit Development Kit) is straightforward: we aim to create exploits that can be easily ported between kernelCTF versions.</p>
119<p>Currently, we are <a class="reference external" href="https://google.github.io/security-research/kernelctf/rules.html#3-exploits-for-cos-instances">
119compensating kernelCTF researchers extra</a> to port their exploits - for example, from LTS to COS. In the majority of cases, the only differences between these two exploits are the ROP chains or minimal spraying variations.</p>
120<p>kernelXDK aims to decouple target-specific information (symbol offsets, ROP chain gadgets, structure, and kmalloc cache information) from the exploit itself, thereby making the exploits target-independent. This approach allows us to easily introduce new targets for kernelCTF without the need to manually port existing exploits.</p>
121</section>
122<section id="limitations">
123<h2>Limitations<a class="headerlink" href="#limitations" title="Link to this heading"></a></h2>
124<p>The current beta version of kernelXDK has several limitations and is currently only a proof-of-concept (v0.1, or Minimum Viable Product). It is focused on achieving a single, immediate goal (out of many future goals; see the “Future ambitions” section): <strong>to ensure 50%–90% of kernelCTF exploits work across multiple kernelCTF targets</strong>.</p>
125</section>
126</section>
127<section id="what-is-kernelxdk">
128<h1>What is kernelXDK?<a class="headerlink" href="#what-is-kernelxdk" title="Link to this heading"></a></h1>
129<p>kernelXDK is a set of tools designed to help kernel researchers write (currently Linux) kernel exploits more easily.</p>
130<section id="tools">
131<h2>Tools<a class="headerlink" href="#tools" title="Link to this heading"></a></h2>
132<p>Descriptions of the specific tools are available in the README.md file within each respective folder and on the <a class="reference external" href="https://xdk.dev">xdk.dev</a> website.</p>
133<p>This graph shows how the tools interact with each other:</p>
134<pre  class="mermaid">
135        graph TD;
136    image_runner[**image_runner**: runs kernel images optionally with custom kernel modules] --&gt; |can use vmlinuz images from the image db|image_db[**image_db:** downloads distro images and collects information about them]
137    image_db --&gt; |uses runner to extract runtime information|image_runner
138    rop_generator[**rop_generator**: extracts ROP gadget and stack pivot information from kernel images] --&gt; |can use the vmlinux files from the DB|image_db
139    image_db --&gt; |uses ROP generator to extract ROP gadget and stack pivots information for images in the DB|rop_generator
140    kxdb_tool[**kxdb_tool**: generates .kxdb or .json database with all the target-specific information] --&gt; |processes data from the image DB|image_db
141    libxdk[**libxdk**: C++ library provides target-specific information and exploitation primitives] --&gt; |can use target information from .kxdb files generated by kxdb_tool|kxdb_tool
142    image_runner --&gt; |compiles the kernel module|xdk_device[**xdk_device**: adds fake vulnerabilities, tracing and debugging capabilities for testing]
143    GHA[**Github Actions**] --&gt; |tests the libxdk with image-runner using the xdk_device| libxdk
144    GHA --&gt; |automatically builds database for new kernelCTF targets| kxdb_tool
145    exploit[**kernel exploit**] --&gt; |links to the library|libxdk
146    exploit --&gt; |uses or includes .kxdb files|kxdb_tool
147    exploit --&gt; |optionally, uses the kernel module to introduce fake vulnerabilities|xdk_device
148    </pre></section>
149<section id="future-ambitions">
150<h2>Future ambitions<a class="headerlink" href="#future-ambitions" title="Link to this heading"></a></h2>
151<section id="mid-term-plans">
152<h3>Mid-term plans<a class="headerlink" href="#mid-term-plans" title="Link to this heading"></a></h3>
153<p>The following features are <strong>currently planned</strong> for the kernelXDK mid-term release. Please note that prioritization and inclusion will depend on the received Beta feedback.</p>
154<ul class="simple">
155<li><p>More post-RIP approaches</p>
156<ul>
157<li><p><code class="docutils literal notranslate"><span class="pre">core_pattern</span></code> overwrite support</p></li>
158<li><p>[TBD] eBPF spraying support</p></li>
159</ul>
160</li>
161<li><p>KASLR leaks: EntryBleed / prefetch</p></li>
162<li><p>Smaller utility features</p>
163<ul>
164<li><p>namespace setup</p></li>
165<li><p>CPU pinning</p></li>
166<li><p>communication and synchronization primitives between threads</p></li>
167</ul>
168</li>
169<li><p>Spraying support</p>
170<ul>
171<li><p>Most common spraying primitives (<code class="docutils literal notranslate"><span class="pre">msg_msg</span></code>, <code class="docutils literal notranslate"><span class="pre">msg_msgseg</span></code>, <code class="docutils literal notranslate"><span class="pre">skbuff</span></code>, <code class="docutils literal notranslate"><span class="pre">user_key_payload</span></code>, <code class="docutils literal notranslate"><span class="pre">simple_xattrs</span></code>)</p></li>
172<li><p>Automatic limit bypasses (e.g. via forking)</p></li>
173<li><p>Leaking support (if primitive supports it)</p></li>
174<li><p>Victim object identification (determine which specific sprayed object was corrupted)</p></li>
175<li><p>Cross-cache support</p></li>
176<li><p>Dirty Pagetable support</p></li>
177</ul>
178</li>
179</ul>
180</section>
181<section id="areas-to-explore">
182<h3>Areas to explore<a class="headerlink" href="#areas-to-explore" title="Link to this heading"></a></h3>
183<p>These represent longer-term ideas we plan to explore if the kernelXDK proves successful:</p>
184<ul class="simple">
185<li><p><strong>Structured exploits (exploit recipes):</strong> add option to create exploits in a declarative manner instead of an imperative one, focus on the “what” instead of the “how”.</p></li>
186<li><p><strong>Automatic exploit generation:</strong> enable kernelXDK to chain the right exploit primitives together to reach LPE from a vulnerability trigger.</p></li>
187<li><p><strong>Syzkaller-integration:</strong> generate exploits automatically from crashes.</p></li>
188<li><p><strong>Windows, macOS support.</strong></p></li>
189</ul>
190</section>
191</section>
192</section>
193
194
195           </div>
196          </div>
197          <footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer">
198        <a href="../index.html" class="btn btn-neutral float-left" title="kernelXDK" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a>
199        <a href="kxdb_database.html" class="btn btn-neutral float-right" title="KXDB Database" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a>
200    </div>
201
202  <hr/>
203
204  <div role="contentinfo">
205    <p>&#169; Copyright 2025, Google.</p>
206  </div>
207
208  Built with <a href="https://www.sphinx-doc.org/">Sphinx</a> using a
209    <a href="https://github.com/readthedocs/sphinx_rtd_theme">theme</a>
210    provided by <a href="https://readthedocs.org">Read the Docs</a>.
211   
212
213</footer>
214        </div>
215      </div>
216    </section>
217  </div>
218  
218<script>
219      jQuery(function () {
220          SphinxRtdTheme.Navigation.enable(true);
221      });
222  </script>
222 
223
224</body>
225</html>

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.