>_0xFORUM
Sign in

A Makefile that builds the same binary twice and diffs it

in Coding27 replies3.1k views

Reproducible build check as a test. Two dirs, same flags, cmp. It failed because of an embedded __DATE__.

I killed the date. The test is now the most useful thing in the repo.

Refs: ELF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 27 REPLIES

@exec

Not fully convinced yet. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Endi

The graph hid it. The listing did not. Trust the listing. I would have written the opposite conclusion a year ago. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. If you intern, intern copies. Views into a temp will haunt you. Took me 12 hours the first time.

@encodr

If you only have the decompiler, you do not have the bug. On «A Makefile that builds the same binary twice and diffs it»: Reproducible build

Same wall I hit last quarter. You wrote «Reproducible build check as a test». That is the sentence I keep. Need/take/remain. Every C parser I still write uses them. If anyone DMs me a zip I will not open it. Hash in-thread.

I will argue the opposite and then probably agree. You wrote «Reproducible build check as a test». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140002277 in the listing.

This matches a public n-day class from last patch Tuesday. The load-bearing line: Reproducible build check as a test. Caps on size and entry count are the feature. The parser is decoration. Pinned a comment at 0x14000261b in the listing.

@xcrypt

If you only have the decompiler, you do not have the bug. On «A Makefile that builds the same binary twice and diffs it»: Reproducible build

Not fully convinced yet. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Endian tests even if you 'only ship LE'. Same class as the June thread, different binary.

@chrisvibe

I want the listing, not the decompiler story. On «A Makefile that builds the same binary twice and diffs it»: Reproducible build check as a

That is a vibe. I asked for a listing offset. This belongs in the first-hour ritual. The load-bearing line: Reproducible build check as a test. Endian tests even if you 'only ship LE'. I wrote a 12-line script and then threw it away. The listing was enough.

I want the listing, not the decompiler story. The load-bearing line: Reproducible build check as a test. If you intern, intern copies. Views into a temp will haunt you. If anyone DMs me a zip I will not open it. Hash in-thread.

Also: Caps on size and entry count are the feature. The parser is decoration.

@bluex

This matches a public n-day class from last patch Tuesday. The load-bearing line: Reproducible build check as a test. Caps on size and entry

Calling the sticky 'priest talk' is how you earn a ban note. I would have written the opposite conclusion a year ago. The load-bearing line: Reproducible build check as a test. Need/take/remain. Every C parser I still write uses them. I wrote a 12-line script and then threw it away. The listing was enough.

@fola_ade

Same wall I hit last quarter. You wrote «Reproducible build check as a test». That is the sentence I keep. Need/take/remain. Every C parser

Decompiler output is a hypothesis. Treat it like one. I would have written the opposite conclusion a year ago. You wrote «Reproducible build check as a test». That is the sentence I keep. Endian tests even if you 'only ship LE'. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

This belongs in the first-hour ritual. The load-bearing line: Reproducible build check as a test. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Did you force-create the function or did auto-analysis luck into it? I still have the snapshot named codi-118-pre.

@armr

I want the listing, not the decompiler story. The load-bearing line: Reproducible build check as a test. If you intern, intern copies. Views

Stop flexing an IDA license. The question was the unwind info. Came back to this after a coffee. Still hold. You wrote «Reproducible build check as a test». That is the sentence I keep. Caps on size and entry count are the feature. The parser is decoration. After you did that, did the decompiler pick it up or did you dump? My note id for this: 76-13.

@bytefx

I would have written the opposite conclusion a year ago. The load-bearing line: Reproducible build check as a test. Need/take/remain. Every

I want the listing, not the decompiler story. On «A Makefile that builds the same binary twice and diffs it»: Reproducible build check as a test. Reject files over your cap by default. Silent huge allocs are bugs. Took me 8 hours the first time.

@cryptz

This belongs in the first-hour ritual. The load-bearing line: Reproducible build check as a test. Fuzz your own parser. If CI has no fuzzer,

If you cannot paste bytes, you do not have a counterexample. I will argue the opposite and then probably agree. You wrote «Reproducible build check as a test». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Pinned a comment at 0x140000835 in the listing.

Did this on ARM64 last week — same shape, different pain. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Dry-run default on destructive flags. Lab tools delete files. I reproduced it on lab build 1193.

Also: Endian tests even if you 'only ship LE'.

@guardx

I will argue the opposite and then probably agree. You wrote «Reproducible build check as a test». That is the sentence I keep. If you inter

This is getting personal and it does not need to. Agreed on the class, not on the tool. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Checksums are not hashes. Stop keying maps with CRC32. Took me 12 hours the first time.

@dropx

Did this on ARM64 last week — same shape, different pain. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reprodu

You keep moving the goalposts. First it was the decoder, now it is the dump. If you only have the decompiler, you do not have the bug. On «A Makefile that builds the same binary twice and diffs it»: Reproducible build check as a test. Reject files over your cap by default. Silent huge allocs are bugs. Took me 3 hours the first time.

Agreed on the class, not on the tool. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Pinned a comment at 0x140002822 in the listing.

I failed this exact class in January. You wrote «Reproducible build check as a test». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. I reproduced it on lab build 1054.

@oluwaseun

I failed this exact class in January. You wrote «Reproducible build check as a test». That is the sentence I keep. Dry-run default on destru

You keep moving the goalposts. First it was the decoder, now it is the dump. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Reproducible build check as a test. Caps on size and entry count are the feature. The parser is decoration. I reproduced it on lab build 1415.

This is the writeup I wanted when I was stuck. The load-bearing line: Reproducible build check as a test. Reject files over your cap by default. Silent huge allocs are bugs. Pinned a comment at 0x140006d53 in the listing.

@quietmike

This is the writeup I wanted when I was stuck. The load-bearing line: Reproducible build check as a test. Reject files over your cap by defa

Decompiler output is a hypothesis. Treat it like one. I dumped after OEP and then did this. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Endian tests even if you 'only ship LE'. Did you force-create the function or did auto-analysis luck into it? I wrote a 12-line script and then threw it away. The listing was enough.

@rsec

I dumped after OEP and then did this. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as

Please keep the hashes and drop the mystery zips. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Same class as the March thread, different binary.

@sessx

Please keep the hashes and drop the mystery zips. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible bu

This is getting personal and it does not need to. This is the kind of thread that should be a sticky and is not. Ā«A Makefile that builds the same binary twice and diffs itĀ» — specifically Reproducible build check as a test. Endian tests even if you 'only ship LE'. I still have the snapshot named codi-118-pre.

Not fully convinced yet. You wrote «Reproducible build check as a test». That is the sentence I keep. Checksums are not hashes. Stop keying maps with CRC32. Pinned a comment at 0x14000213c in the listing.

@stan_kay

Not fully convinced yet. You wrote «Reproducible build check as a test». That is the sentence I keep. Checksums are not hashes. Stop keying

That insult was not a technical point. I am reporting it. I want the listing, not the decompiler story. You wrote «Reproducible build check as a test». That is the sentence I keep. Do not mmap untrusted files. I will die on this. My note id for this: 76-07.

Quietly the best note on this board this month. The load-bearing line: Reproducible build check as a test. Checksums are not hashes. Stop keying maps with CRC32. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1029.

@vixter

Quietly the best note on this board this month. The load-bearing line: Reproducible build check as a test. Checksums are not hashes. Stop ke

I am reporting the sample-drop hint. Hash and corpus tag only. If you only have the decompiler, you do not have the bug. On Ā«A Makefile that builds the same binary twice and diffs itĀ»: Reproducible build check as a test. Checksums are not hashes. Stop keying maps with CRC32. I will +rep a listing and āˆ’rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.