
Android kernel exploit research package for CVE-2026-43499, containing popsicle exploit source, embedded su payload, root bridge helper, and reproducible build artifacts.
Generated: 2026-08-08
This directory has organized the complete popsicle source tree, necessary header files, embedded su payload, production binaries, and runtime scripts that can be recovered from the current project.
A distinction must be made:
source-final-correspondence-20260808/
├─ source/
│ ├─ exploit/
│ │ ├─ popsicle/
│ │ │ ├─ main.c
│ │ │ ├─ util.c
│ │ │ ├─ slide.c
│ │ │ ├─ fops.c
│ │ │ ├─ pipe.c
│ │ │ ├─ preload.c
│ │ │ ├─ root_bridge_helper.c
│ │ │ ├─ su_blob.S
│ │ │ ├─ su_daemon.c
│ │ │ ├─ common.h / offset.h / target.h
│ │ │ ├─ kernelsnitch/
│ │ │ └─ build/embed/su_daemon_aarch64_pie
│ │ └─ ghostlock-oneplus/kernelsnitch/
│ └─ target-files/popsicle-target.h
├─ embed/su_daemon_aarch64_pie
├─ artifacts/production/
├─ runtime/
├─ review-build/
├─ rebuild-current-source.ps1
├─ source-files.sha256
├─ binary-function-size-diff.md
├─ binary-function-size-diff.csv
└─ manifest.json
Production file:
artifacts/production/t807d-popsicle-r562-show-callback-canonical-20260804.so
SHA-256:
B6DED21F90096A2FA2567807F79E7E8CCFDF9802DAF4628277A333DD8FE7DB71
Main source inputs:
| Production Object | Corresponding Source |
|---|---|
| SO main flow | source/exploit/popsicle/main.c |
| Common kernel and userspace utilities | source/exploit/popsicle/util.c |
| slide and address location | source/exploit/popsicle/slide.c |
| fops and pselect trigger path | source/exploit/popsicle/fops.c |
| pipe, reclaim, direct write | source/exploit/popsicle/pipe.c |
| LD_PRELOAD entry and su file write | source/exploit/popsicle/preload.c |
| Embedded su boundary symbols | source/exploit/popsicle/su_blob.S |
| Common definitions | common.h, offset.h, target.h |
| Target configuration | source/target-files/popsicle-target.h |
| KernelSnitch headers | source/exploit/popsicle/kernelsnitch/ and source/exploit/ghostlock-oneplus/kernelsnitch/ |
| Embedded file content | source/exploit/popsicle/build/embed/su_daemon_aarch64_pie |
Production file:
artifacts/production/t807d-root-bridge-helper-r557-show-verify-callback-20260804
SHA-256:
F7FF4C293902993183F98A8D314FA2ECD012A72A36F287A361C4503844EAAB91
Main source inputs:
| Production Object | Corresponding Source |
|---|---|
| root bridge, marker, cred, SELinux, KSU auxiliary logic | source/exploit/popsicle/root_bridge_helper.c |
| Embedded su boundary symbols | source/exploit/popsicle/su_blob.S |
| su content | source/exploit/popsicle/build/embed/su_daemon_aarch64_pie |
| Common definitions and target configuration | Same as r562 |
Two easily overlooked relative path dependencies have been filled in.
First, target.h references:
#include "../../target-files/popsicle-target.h"
Therefore the source must maintain:
source/exploit/popsicle/target.h
source/target-files/popsicle-target.h
Second, popsicle/kernelsnitch/utils.h and kernelsnitch.h continue to reference:
../../ghostlock-oneplus/kernelsnitch/...
Therefore source/exploit/ghostlock-oneplus/kernelsnitch/ must also be preserved.
Copying only source/popsicle would yield an incomplete snapshot that "looks complete but actually cannot compile." This recovery package has been organized according to the original relative path layout.
Toolchain:
NDK: D:Android
dk 29android-ndk-r29 API: 35 ABI: AArch64
Execute:
powershell.exe -NoLogo -NoProfile -ExecutionPolicy Bypass -File .
ebuild-current-source.ps1
Current source recompilation results:
| File | Size | SHA-256 |
|---|---|---|
| review-build/rebuild-current-source.so | 139600 | D5C8CF6D3A0A223F0BB3319FFAE926EF3EDF56DEF520B0A99CF7526B4437EC1A |
| review-build/rebuild-current-source-helper | 75008 | 025FD4BEB793227D9595D5739483798BBB8CDB94B69734399BE4C9F329032D8F |
This proves the source tree is compilable, but it cannot replace the verified production binaries in artifacts/production.
Timeline evidence:
| Object | File Time |
|---|---|
| r557 helper production file | 2026-08-04 22:47:29 |
| r562 SO production file | 2026-08-04 22:59:05 |
| main.c | 2026-08-04 22:22:16 |
| slide.c | 2026-08-04 21:54:58 |
| common.h | 2026-08-05 08:07:26 |
| pipe.c | 2026-08-05 08:07:34 |
| preload.c | 2026-08-05 08:07:30 |
| root_bridge_helper.c | 2026-08-05 08:10:10 |
| util.c | 2026-08-05 08:14:57 |
At least the current contents of common.h, pipe.c, preload.c, root_bridge_helper.c, and util.c were written to disk or modified after the two production binaries were generated.
The project also did not find:
Therefore, based on the available materials, what can be done is to recover all usable source and locate the differences; it is not possible to reverse the production ELF back into the byte-for-byte C source from that time.
binary-function-size-diff.md provides the function size differences between the production files and the current source recompilation files.
Key differences in the r562 SO:
Key differences in the r557 helper:
These differences are consistent with the fix directions recorded in the Round592 source review: environment variable path copying, independent linker symbol address differences, allocation failure handling, reclaim cleanup, etc.
The complete source hashes are in source-files.sha256. The hashes of production artifacts, scripts, embedded files, and review build results are in manifest.json.