After yum upgraded pam from pam-0.79-8 to pam-0.79-10 and from coreutils-5.2.1-48 to coreutils-5.2.1-51, I can no longer su, nor log in as root or anybody else. su just gives "incorrect password". See attached strace (NOTE: I erased some string, passwd contents etc). I'm running up-to-date Fedora Rawhide, but vanilla kernel.org 2.6.12-rc4. selinux is disabled on kernel command line and in /etc/sysconfig/selinux. I downgraded back to pam-0.79-8 and coreutils-5.2.1-48 and everything works again. "strace" is with pam-0.79-10, coreutils-5.2.1-51 (DOESN'T WORK) "strace.working" is with pam-0.79-8, coreutils-5.2.1-48 (WORKS) -- v -- v@xxxxxx
execve("/bin/su", ["su"], [/* 60 vars */]) = 0 brk(0) = 0x80007000 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) open("/etc/ld.so.cache", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 3, 0) = 0xb7fd9000 close(3) = 0 open("/lib/libpam.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\260\247"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=35492, ...}) = 0 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7fd8000 old_mmap(NULL, 36800, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7fcf000 old_mmap(0xb7fd7000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0xb7fd7000 close(3) = 0 open("/lib/libpam_misc.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\260<\220"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=10172, ...}) = 0 old_mmap(NULL, 11560, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7fcc000 old_mmap(0xb7fce000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0xb7fce000 close(3) = 0 open("/lib/libcrypt.so.1", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\360\367"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=27660, ...}) = 0 old_mmap(NULL, 184604, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7f9e000 old_mmap(0xb7fa3000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0xb7fa3000 old_mmap(0xb7fa5000, 155932, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7fa5000 close(3) = 0 open("/lib/libdl.so.2", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0LKG4\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=16244, ...}) = 0 old_mmap(NULL, 12404, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7f9a000 old_mmap(0xb7f9c000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0xb7f9c000 close(3) = 0 open("/lib/libc.so.6", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\no7G4\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=1489572, ...}) = 0 old_mmap(NULL, 1219548, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7e70000 old_mmap(0xb7f94000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x124000) = 0xb7f94000 old_mmap(0xb7f98000, 7132, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7f98000 close(3) = 0 open("/lib/libaudit.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\200\217"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=54712, ...}) = 0 old_mmap(NULL, 52104, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7e63000 old_mmap(0xb7e6c000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x9000) = 0xb7e6c000 close(3) = 0 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e62000 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e61000 set_thread_area({entry_number:-1 -> 6, base_addr:0xb7e616c0, limit:1048575, seg_32bit:1, contents:0, read_exec_only:0, limit_in_pages:1, seg_not_present:0, useable:1}) = 0 mprotect(0xb7f94000, 8192, PROT_READ) = 0 mprotect(0xb7f9c000, 4096, PROT_READ) = 0 mprotect(0xb7fa3000, 4096, PROT_READ) = 0 mprotect(0x46b99000, 4096, PROT_READ) = 0 munmap(0xb7fd9000, 123188) = 0 brk(0) = 0x80007000 brk(0x80028000) = 0x80028000 socket(PF_FILE, SOCK_STREAM, 0) = 3 fcntl64(3, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) close(3) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 3 fcntl64(3, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) close(3) = 0 open("/etc/nsswitch.conf", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=1696, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7ff7000 read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1696 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7ff7000, 4096) = 0 open("/etc/ld.so.cache", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 3, 0) = 0xb7fd9000 close(3) = 0 open("/lib/libnss_files.so.2", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0 \33\0\000"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=46552, ...}) = 0 old_mmap(NULL, 41616, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7e56000 old_mmap(0xb7e5f000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x8000) = 0xb7e5f000 close(3) = 0 mprotect(0xb7e5f000, 4096, PROT_READ) = 0 munmap(0xb7fd9000, 123188) = 0 open("/etc/passwd", O_RDONLY) = 3 fcntl64(3, F_GETFD) = 0 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 fstat64(3, {st_mode=S_IFREG|0644, st_size=1998, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7ff7000 read(3, "<erased>"..., 4096) = 1998 close(3) = 0 munmap(0xb7ff7000, 4096) = 0 stat64("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/etc/pam.d/su", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=944, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7ff7000 read(3, "#%PAM-1.0\nauth sufficient "..., 4096) = 944 open("/lib/security/$ISA/pam_rootok.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_rootok.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\360\5\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=3900, ...}) = 0 old_mmap(NULL, 6776, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7ff5000 old_mmap(0xb7ff6000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0) = 0xb7ff6000 close(4) = 0 open("/etc/ld.so.cache", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 4, 0) = 0xb7e37000 close(4) = 0 open("/lib/libselinux.so.1", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\20\5\300"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=68864, ...}) = 0 old_mmap(NULL, 68592, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7e26000 old_mmap(0xb7e36000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x10000) = 0xb7e36000 close(4) = 0 access("/etc/selinux/", F_OK) = -1 ENOENT (No such file or directory) open("/proc/mounts", O_RDONLY|O_LARGEFILE) = 4 fstat64(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7ff4000 read(4, "rootfs / rootfs rw 0 0\n/dev/root"..., 1024) = 1017 read(4, "", 1024) = 0 close(4) = 0 munmap(0xb7ff4000, 4096) = 0 munmap(0xb7e37000, 123188) = 0 open("/lib/security/$ISA/pam_stack.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_stack.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0000\n\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=10996, ...}) = 0 old_mmap(NULL, 13872, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7ff1000 old_mmap(0xb7ff4000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0xb7ff4000 close(4) = 0 open("/lib/security/$ISA/pam_selinux.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_selinux.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\260\f\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=12156, ...}) = 0 old_mmap(NULL, 15048, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7fed000 old_mmap(0xb7ff0000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0xb7ff0000 close(4) = 0 open("/lib/security/$ISA/pam_xauth.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_xauth.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0\22\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=15036, ...}) = 0 old_mmap(NULL, 17960, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7fe8000 old_mmap(0xb7fec000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0xb7fec000 close(4) = 0 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7ff7000, 4096) = 0 open("/etc/pam.d/other", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=154, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7ff7000 read(3, "#%PAM-1.0\nauth required "..., 4096) = 154 open("/lib/security/pam_deny.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\354\4\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=3284, ...}) = 0 old_mmap(NULL, 6208, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7fe6000 old_mmap(0xb7fe7000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0) = 0xb7fe7000 close(4) = 0 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7ff7000, 4096) = 0 getuid32() = 0 getuid32() = 0 open("/etc/passwd", O_RDONLY) = 3 fcntl64(3, F_GETFD) = 0 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 fstat64(3, {st_mode=S_IFREG|0644, st_size=1998, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7ff7000 read(3, "<erased>"..., 4096) = 1998 close(3) = 0 munmap(0xb7ff7000, 4096) = 0 ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0 readlink("/proc/self/fd/0", "/dev/ttyp0 (deleted)", 4095) = 20 time(NULL) = 1119282890 getuid32() = 0 open("/proc/filesystems", O_RDONLY|O_LARGEFILE) = 3 read(3, "nodev\tsysfs\nnodev\trootfs\nnodev\tb"..., 4095) = 223 close(3) = 0 socket(PF_NETLINK, SOCK_RAW, 9) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 readlink("/proc/self/exe", "/bin/su", 4095) = 7 sendto(3, "|\0\0\0L\4\5\0\1\0\0\0\0\0\0\0PAM authenticati"..., 124, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 124 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "$\0\0\0\2\0\0\0\1\0\0\0\311_\0\0\352\377\377\377|\0\0\0"..., 8476, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 36 close(3) = 0 munmap(0xb7ff5000, 6776) = 0 munmap(0xb7ff1000, 13872) = 0 munmap(0xb7fed000, 15048) = 0 munmap(0xb7e26000, 68592) = 0 munmap(0xb7fe8000, 17960) = 0 munmap(0xb7fe6000, 6208) = 0 write(2, "su: ", 4) = 4 write(2, "incorrect password", 18) = 18 write(2, "\n", 1) = 1 exit_group(1) = ?
execve("/bin/su", ["su"], [/* 50 vars */]) = 0 brk(0) = 0x80007000 access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory) open("/etc/ld.so.cache", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 3, 0) = 0xb7f50000 close(3) = 0 open("/lib/libpam.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0p\227\305"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=34820, ...}) = 0 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f4f000 old_mmap(NULL, 36128, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7f46000 old_mmap(0xb7f4e000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0xb7f4e000 close(3) = 0 open("/lib/libpam_misc.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\260<\306"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=10172, ...}) = 0 old_mmap(NULL, 11560, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7f43000 old_mmap(0xb7f45000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0xb7f45000 close(3) = 0 open("/lib/libcrypt.so.1", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\360\367"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=27660, ...}) = 0 old_mmap(NULL, 184604, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7f15000 old_mmap(0xb7f1a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0xb7f1a000 old_mmap(0xb7f1c000, 155932, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7f1c000 close(3) = 0 open("/lib/libdl.so.2", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0LKG4\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=16244, ...}) = 0 old_mmap(NULL, 12404, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7f11000 old_mmap(0xb7f13000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1000) = 0xb7f13000 close(3) = 0 open("/lib/libc.so.6", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\no7G4\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=1489572, ...}) = 0 old_mmap(NULL, 1219548, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7de7000 old_mmap(0xb7f0b000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x124000) = 0xb7f0b000 old_mmap(0xb7f0f000, 7132, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7f0f000 close(3) = 0 open("/lib/libaudit.so.0", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\220O\0"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=53308, ...}) = 0 old_mmap(NULL, 52104, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7dda000 old_mmap(0xb7de3000, 16384, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x9000) = 0xb7de3000 close(3) = 0 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7dd9000 old_mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7dd8000 set_thread_area({entry_number:-1 -> 6, base_addr:0xb7dd86c0, limit:1048575, seg_32bit:1, contents:0, read_exec_only:0, limit_in_pages:1, seg_not_present:0, useable:1}) = 0 mprotect(0xb7f0b000, 8192, PROT_READ) = 0 mprotect(0xb7f13000, 4096, PROT_READ) = 0 mprotect(0xb7f1a000, 4096, PROT_READ) = 0 mprotect(0x46b99000, 4096, PROT_READ) = 0 munmap(0xb7f50000, 123188) = 0 brk(0) = 0x80007000 brk(0x80028000) = 0x80028000 socket(PF_FILE, SOCK_STREAM, 0) = 3 fcntl64(3, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) close(3) = 0 socket(PF_FILE, SOCK_STREAM, 0) = 3 fcntl64(3, F_GETFL) = 0x2 (flags O_RDWR) fcntl64(3, F_SETFL, O_RDWR|O_NONBLOCK) = 0 connect(3, {sa_family=AF_FILE, path="/var/run/nscd/socket"}, 110) = -1 ENOENT (No such file or directory) close(3) = 0 open("/etc/nsswitch.conf", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=1696, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1696 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 open("/etc/ld.so.cache", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 3, 0) = 0xb7f50000 close(3) = 0 open("/lib/libnss_files.so.2", O_RDONLY) = 3 read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0 \33\0\000"..., 512) = 512 fstat64(3, {st_mode=S_IFREG|0755, st_size=46552, ...}) = 0 old_mmap(NULL, 41616, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7dcd000 old_mmap(0xb7dd6000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x8000) = 0xb7dd6000 close(3) = 0 mprotect(0xb7dd6000, 4096, PROT_READ) = 0 munmap(0xb7f50000, 123188) = 0 open("/etc/passwd", O_RDONLY) = 3 fcntl64(3, F_GETFD) = 0 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 fstat64(3, {st_mode=S_IFREG|0644, st_size=1998, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "<erased>"..., 4096) = 1998 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 stat64("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/etc/pam.d/su", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=944, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "#%PAM-1.0\nauth sufficient "..., 4096) = 944 open("/lib/security/$ISA/pam_rootok.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_rootok.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\360\5\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=3900, ...}) = 0 old_mmap(NULL, 6776, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7f6c000 old_mmap(0xb7f6d000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0) = 0xb7f6d000 close(4) = 0 open("/etc/ld.so.cache", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 4, 0) = 0xb7dae000 close(4) = 0 open("/lib/libselinux.so.1", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\20\5\300"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=68864, ...}) = 0 old_mmap(NULL, 68592, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7d9d000 old_mmap(0xb7dad000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x10000) = 0xb7dad000 close(4) = 0 access("/etc/selinux/", F_OK) = -1 ENOENT (No such file or directory) open("/proc/mounts", O_RDONLY|O_LARGEFILE) = 4 fstat64(4, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6b000 read(4, "rootfs / rootfs rw 0 0\n/dev/root"..., 1024) = 1017 read(4, "", 1024) = 0 close(4) = 0 munmap(0xb7f6b000, 4096) = 0 munmap(0xb7dae000, 123188) = 0 open("/lib/security/$ISA/pam_stack.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_stack.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0000\n\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=10996, ...}) = 0 old_mmap(NULL, 13872, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7f68000 old_mmap(0xb7f6b000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0xb7f6b000 close(4) = 0 open("/lib/security/$ISA/pam_selinux.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_selinux.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\260\f\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=12156, ...}) = 0 old_mmap(NULL, 15048, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7f64000 old_mmap(0xb7f67000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0xb7f67000 close(4) = 0 open("/lib/security/$ISA/pam_xauth.so", O_RDONLY) = -1 ENOENT (No such file or directory) open("/lib/security/../../lib/security/pam_xauth.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\0\22\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=15004, ...}) = 0 old_mmap(NULL, 17928, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7f5f000 old_mmap(0xb7f63000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x3000) = 0xb7f63000 close(4) = 0 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 open("/etc/pam.d/other", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=154, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "#%PAM-1.0\nauth required "..., 4096) = 154 open("/lib/security/pam_deny.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\354\4\0"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=3284, ...}) = 0 old_mmap(NULL, 6208, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7f5d000 old_mmap(0xb7f5e000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0) = 0xb7f5e000 close(4) = 0 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 getuid32() = 0 getuid32() = 0 open("/etc/passwd", O_RDONLY) = 3 fcntl64(3, F_GETFD) = 0 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 fstat64(3, {st_mode=S_IFREG|0644, st_size=1998, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "<erased>"..., 4096) = 1998 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0 readlink("/proc/self/fd/0", "/dev/pts/5", 4095) = 10 time(NULL) = 1119338291 getuid32() = 0 open("/proc/filesystems", O_RDONLY|O_LARGEFILE) = 3 read(3, "nodev\tsysfs\nnodev\trootfs\nnodev\tb"..., 4095) = 223 close(3) = 0 socket(PF_NETLINK, SOCK_RAW, 9) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 readlink("/proc/self/exe", "/bin/su", 4095) = 7 sendto(3, "\20\0\0\0\350\3\5\0\1\0\0\0\0\0\0\0", 16, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 16 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\1\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\1\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 close(3) = 0 stat64("/etc/pam.d", {st_mode=S_IFDIR|0755, st_size=4096, ...}) = 0 open("/etc/pam.d/system-auth", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=676, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "#%PAM-1.0\n# This file is auto-ge"..., 4096) = 676 open("/lib/security/pam_unix.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0`&\0\000"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=52576, ...}) = 0 old_mmap(NULL, 100676, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7db4000 old_mmap(0xb7dc0000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xc000) = 0xb7dc0000 old_mmap(0xb7dc1000, 47428, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7dc1000 close(4) = 0 open("/etc/ld.so.cache", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 4, 0) = 0xb7d7e000 close(4) = 0 open("/lib/libnsl.so.1", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0p\5\272"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=96960, ...}) = 0 old_mmap(NULL, 88064, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7d68000 old_mmap(0xb7d7a000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x11000) = 0xb7d7a000 old_mmap(0xb7d7c000, 6144, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7d7c000 close(4) = 0 mprotect(0xb7d7a000, 4096, PROT_READ) = 0 munmap(0xb7d7e000, 123188) = 0 open("/lib/security/pam_cracklib.so", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0@\v\0\000"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=12640, ...}) = 0 old_mmap(NULL, 31936, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7d95000 old_mmap(0xb7d98000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x2000) = 0xb7d98000 old_mmap(0xb7d99000, 15552, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7d99000 close(4) = 0 open("/etc/ld.so.cache", O_RDONLY) = 4 fstat64(4, {st_mode=S_IFREG|0644, st_size=123188, ...}) = 0 old_mmap(NULL, 123188, PROT_READ, MAP_PRIVATE, 4, 0) = 0xb7d49000 close(4) = 0 open("/usr/lib/libcrack.so.2", O_RDONLY) = 4 read(4, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0\200\354"..., 512) = 512 fstat64(4, {st_mode=S_IFREG|0755, st_size=29452, ...}) = 0 old_mmap(NULL, 45920, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0xb7d3d000 old_mmap(0xb7d44000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0x6000) = 0xb7d44000 old_mmap(0xb7d45000, 13152, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7d45000 close(4) = 0 munmap(0xb7d49000, 123188) = 0 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 open("/etc/pam.d/other", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=154, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "#%PAM-1.0\nauth required "..., 4096) = 154 read(3, "", 4096) = 0 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 getuid32() = 0 open("/etc/passwd", O_RDONLY) = 3 fcntl64(3, F_GETFD) = 0 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 fstat64(3, {st_mode=S_IFREG|0644, st_size=1998, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "<erased>"..., 4096) = 1998 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 open("/etc/shadow", O_RDONLY) = 3 fcntl64(3, F_GETFD) = 0 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 fstat64(3, {st_mode=S_IFREG|0600, st_size=1390, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "<erased>"..., 4096) = 1390 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 time(NULL) = 1119338291 socket(PF_NETLINK, SOCK_RAW, 9) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 readlink("/proc/self/exe", "/bin/su", 4095) = 7 sendto(3, "\20\0\0\0\350\3\5\0\2\0\0\0\0\0\0\0", 16, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 16 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\2\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\2\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 close(3) = 0 ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0 getuid32() = 0 getuid32() = 0 time([1119338291]) = 1119338291 open("/etc/localtime", O_RDONLY) = 3 fstat64(3, {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 fstat64(3, {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7f6e000 read(3, "TZif\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\5\0\0\0\5\0"..., 4096) = 682 close(3) = 0 munmap(0xb7f6e000, 4096) = 0 stat64("/etc/localtime", {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 stat64("/etc/localtime", {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 stat64("/etc/localtime", {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 getpid() = 31068 socket(PF_FILE, SOCK_DGRAM, 0) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 connect(3, {sa_family=AF_FILE, path="/dev/log"}, 16) = 0 send(3, "<38>Jun 21 10:18:11 su(pam_unix)"..., 80, MSG_NOSIGNAL) = 80 close(3) = 0 ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, {B38400 opost isig icanon echo ...}) = 0 open("/proc/filesystems", O_RDONLY|O_LARGEFILE) = 3 read(3, "nodev\tsysfs\nnodev\trootfs\nnodev\tb"..., 4095) = 223 close(3) = 0 socket(PF_NETLINK, SOCK_RAW, 9) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 readlink("/proc/self/exe", "/bin/su", 4095) = 7 sendto(3, "\20\0\0\0\350\3\5\0\3\0\0\0\0\0\0\0", 16, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 16 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\3\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\3\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 close(3) = 0 clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0xb7dd8708) = 31069 rt_sigprocmask(SIG_BLOCK, ~[RTMIN RT_1], NULL, 8) = 0 rt_sigaction(SIGTERM, {0x80001a39, [], 0}, NULL, 8) = 0 rt_sigprocmask(SIG_UNBLOCK, [ALRM TERM], NULL, 8) = 0 waitpid(-1, [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], WSTOPPED) = 31069 getuid32() = 0 time([1119338398]) = 1119338398 stat64("/etc/localtime", {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 stat64("/etc/localtime", {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 stat64("/etc/localtime", {st_mode=S_IFREG|0644, st_size=682, ...}) = 0 socket(PF_FILE, SOCK_DGRAM, 0) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 connect(3, {sa_family=AF_FILE, path="/dev/log"}, 16) = 0 send(3, "<38>Jun 21 10:19:58 su(pam_unix)"..., 69, MSG_NOSIGNAL) = 69 close(3) = 0 socket(PF_NETLINK, SOCK_RAW, 9) = 3 fcntl64(3, F_SETFD, FD_CLOEXEC) = 0 readlink("/proc/self/exe", "/bin/su", 4095) = 7 sendto(3, "\20\0\0\0\350\3\5\0\4\0\0\0\0\0\0\0", 16, 0, {sa_family=AF_NETLINK, pid=0, groups=00000000}, 12) = 16 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\4\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_PEEK|MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 select(4, [3], NULL, NULL, {0, 100000}) = 1 (in [3], left {0, 100000}) recvfrom(3, "0\0\0\0\350\3\0\0\4\0\0\0\\y\0\0\240\230;\300\0\0\0\0\1"..., 8476, MSG_DONTWAIT, {sa_family=AF_NETLINK, pid=0, groups=00000000}, [12]) = 48 close(3) = 0 munmap(0xb7db4000, 100676) = 0 munmap(0xb7d68000, 88064) = 0 munmap(0xb7d95000, 31936) = 0 munmap(0xb7d3d000, 45920) = 0 munmap(0xb7f6c000, 6776) = 0 munmap(0xb7f68000, 13872) = 0 munmap(0xb7f64000, 15048) = 0 munmap(0xb7d9d000, 68592) = 0 munmap(0xb7f5f000, 17928) = 0 munmap(0xb7f5d000, 6208) = 0 exit_group(0) = ?