>_0xFORUM
Sign in

Rust async state machines in Ghidra — naming the poll functions

in Reversing19 replies355 views

Tokio-ish lab tool. The interesting logic is in a generated poll() state machine. Function names are hash soup.

I named them from the future type in the DWARF we accidentally shipped. Without DWARF, how do you name these?

Refs: Ghidra

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 19 REPLIES

@anthonyhub

I dumped after OEP and then did this. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. I

Take the telegram pitch to the bin. Market listing or nothing. Came back to this after a coffee. Still hold. The load-bearing line: Tokio-ish lab tool. Call-convention mass-correct with a script. Still too much clicking. I will +rep a listing and −rep a vibe. That is the deal.

@wiseking

Please keep the hashes and drop the mystery zips. You wrote «Tokio-ish lab tool». That is the sentence I keep. I bookmark the decoder then r

This is the writeup I wanted when I was stuck. On «Rust async state machines in Ghidra — naming the poll functions»: Tokio-ish lab tool. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. I wrote a 12-line script and then threw it away. The listing was enough.

@flux

This is the writeup I wanted when I was stuck. On «Rust async state machines in Ghidra — naming the poll functions»: Tokio-ish lab tool. I b

You are describing a live target. Stop. Patched class only. This is the writeup I wanted when I was stuck. On «Rust async state machines in Ghidra — naming the poll functions»: Tokio-ish lab tool. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. My note id for this: 2f-05.

If you only have the decompiler, you do not have the bug. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. My note id for this: 2f-12.

Also: Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there.

I dumped after OEP and then did this. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. I leave CET ops in the listing. They document that CET is on. Pinned a comment at 0x1400041a2 in the listing.

Same wall I hit last quarter. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1056.

I ran this on a licensed corpus binary. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. Listing first. The decompiler invented a cast last week that hid a signed compare. I still have the snapshot named reve-47-pre.

@bluehat

Same wall I hit last quarter. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. Recursive

Quote the bytes or sit down. Not fully convinced yet. You wrote «Tokio-ish lab tool». That is the sentence I keep. FID for your own libs is worth the CI time. Watch COMDAT folding or the database will lie. I still have the snapshot named reve-47-pre.

@encode

Bookmarking this for the lab wiki. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. Vtab

This is the writeup I wanted when I was stuck. You wrote «Tokio-ish lab tool». That is the sentence I keep. Call-convention mass-correct with a script. Still too much clicking. I wrote a 12-line script and then threw it away. The listing was enough.

@byte

Not fully convinced yet. You wrote «Tokio-ish lab tool». That is the sentence I keep. FID for your own libs is worth the CI time. Watch COMD

Same wall I hit last quarter. The load-bearing line: Tokio-ish lab tool. I trust FLOSS after I have seen the decoder. Before that I read the stores. I reproduced it on lab build 1155.

@cryptx

If you only have the decompiler, you do not have the bug. «Rust async state machines in Ghidra — naming the poll functions» — specifically T

You skipped isolation and then asked why the box is dirty. That is on you. This belongs in the first-hour ritual. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. Recursive descent kills overlapping-instruction tricks. Linear sweep will always lie there. Is the hang the incomplete patch, or a second bug? Same class as the June thread, different binary.

I reproduced it twice before I believed you. On «Rust async state machines in Ghidra — naming the poll functions»: Tokio-ish lab tool. Vtable grouping without RTTI: xref clusters plus IUnknown shape. Was this on the licensed corpus or a crackme you wrote? I will +rep a listing and −rep a vibe. That is the deal.

@downtownjay

I ran this on a licensed corpus binary. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool.

I am not moving this to DMs so you can yell. Stay on the class. Bookmarking this for the lab wiki. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I still have the snapshot named reve-47-pre.

@christopherx

Same wall I hit last quarter. The load-bearing line: Tokio-ish lab tool. I trust FLOSS after I have seen the decoder. Before that I read the

You are treating a checksum as a signature again. This is the writeup I wanted when I was stuck. You wrote «Tokio-ish lab tool». That is the sentence I keep. UPX with a skipped magic is still UPX. Restore four bytes and move on. Pinned a comment at 0x1400022bb in the listing.

@Flybancode

This is the writeup I wanted when I was stuck. You wrote «Tokio-ish lab tool». That is the sentence I keep. Call-convention mass-correct wit

That is not what the listing shows. You are arguing a vibe. I want the listing, not the decompiler story. The load-bearing line: Tokio-ish lab tool. I leave CET ops in the listing. They document that CET is on. I reproduced it on lab build 1246.

I tried the naive path first and wasted a morning. The load-bearing line: Tokio-ish lab tool. Vtable grouping without RTTI: xref clusters plus IUnknown shape. I wrote a 12-line script and then threw it away. The listing was enough.

@stanleycool

I tried the naive path first and wasted a morning. The load-bearing line: Tokio-ish lab tool. Vtable grouping without RTTI: xref clusters pl

Call-convention guess is not evidence. This is the writeup I wanted when I was stuck. The load-bearing line: Tokio-ish lab tool. I trust FLOSS after I have seen the decoder. Before that I read the stores. Pinned a comment at 0x140006315 in the listing.

This is the kind of thread that should be a sticky and is not. «Rust async state machines in Ghidra — naming the poll functions» — specifically Tokio-ish lab tool. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. If anyone DMs me a zip I will not open it. Hash in-thread.

@virtz

This is the kind of thread that should be a sticky and is not. «Rust async state machines in Ghidra — naming the poll functions» — specifica

Do not call people skids because they use Ghidra. Please keep the hashes and drop the mystery zips. You wrote «Tokio-ish lab tool». That is the sentence I keep. I bookmark the decoder then re-analyze. Reloading the file is the honest fallback. Did you force-create the function or did auto-analysis luck into it? Took me 2 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.