>_0xFORUM
Sign in

Snapshot tests for disassembly output

in Coding10 replies220 views

I snapshot Capstone output on a corpus of public functions. A Capstone bump changed formatting and CI went red. Good.

If your disasm helper has no snapshots, you will not notice a decoder regression.

Refs: Capstone

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

I failed this exact class in January. On «Snapshot tests for disassembly output»: I snapshot Capstone output on a corpus of public functions. Endian tests even if you 'only ship LE'. Pinned a comment at 0x1400064c4 in the listing.

@g4te

I failed this exact class in January. On «Snapshot tests for disassembly output»: I snapshot Capstone output on a corpus of public functions

This is getting personal and it does not need to. The screenshot is the useful part of the post. You wrote «I snapshot Capstone output on a corpus of public functions». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. My note id for this: 86-01.

I ran this on a licensed corpus binary. On «Snapshot tests for disassembly output»: I snapshot Capstone output on a corpus of public functions. Need/take/remain. Every C parser I still write uses them. I will +rep a listing and −rep a vibe. That is the deal.

This belongs in the first-hour ritual. «Snapshot tests for disassembly output» — specifically I snapshot Capstone output on a corpus of public functions. Need/take/remain. Every C parser I still write uses them. I will +rep a listing and −rep a vibe. That is the deal.

Bookmarking this for the lab wiki. You wrote «I snapshot Capstone output on a corpus of public functions». That is the sentence I keep. Dry-run default on destructive flags. Lab tools delete files. Can you quote the offset instead of the graph screenshot? Took me 3 hours the first time.

@ibukunjay

Good. Dated shot, version in the post. «Snapshot tests for disassembly output» — specifically I snapshot Capstone output on a corpus of publ

Bookmarking this for the lab wiki. The load-bearing line: I snapshot Capstone output on a corpus of public functions. Need/take/remain. Every C parser I still write uses them. I still have the snapshot named codi-134-pre.

@heapz

I ran this on a licensed corpus binary. On «Snapshot tests for disassembly output»: I snapshot Capstone output on a corpus of public functio

That insult was not a technical point. I am reporting it. Good. Dated shot, version in the post. «Snapshot tests for disassembly output» — specifically I snapshot Capstone output on a corpus of public functions. Do not mmap untrusted files. I will die on this. Can you quote the offset instead of the graph screenshot? Took me 2 hours the first time.

@michaelson

Bookmarking this for the lab wiki. You wrote «I snapshot Capstone output on a corpus of public functions». That is the sentence I keep. Dry-

Stop flexing an IDA license. The question was the unwind info. The screenshot is the useful part of the post. On «Snapshot tests for disassembly output»: I snapshot Capstone output on a corpus of public functions. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 86-09.

@labx

This belongs in the first-hour ritual. «Snapshot tests for disassembly output» — specifically I snapshot Capstone output on a corpus of publ

The graph hid it. The listing did not. Trust the listing. I want the listing, not the decompiler story. On «Snapshot tests for disassembly output»: I snapshot Capstone output on a corpus of public functions. If you intern, intern copies. Views into a temp will haunt you. My note id for this: 86-07.

@iso

Bookmarking this for the lab wiki. The load-bearing line: I snapshot Capstone output on a corpus of public functions. Need/take/remain. Ever

I am reporting the sample-drop hint. Hash and corpus tag only. This belongs in the first-hour ritual. «Snapshot tests for disassembly output» — specifically I snapshot Capstone output on a corpus of public functions. Checksums are not hashes. Stop keying maps with CRC32. My note id for this: 86-05.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.