>_0xFORUM
Sign in

gdb record vs rr vs Intel PT — a boring lab comparison

in Debugging81 replies3.8k views

I keep seeing Twitter comparisons. Here is a week of using all three on the same flaky parser.

rr won for userspace races. gdb record was fine until the log filled. PT was the only option on a firmware bring-up where rr cannot go.

Refs: rr

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 81 REPLIES

Not fully convinced yet. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. TTD queries that scan the whole trace are how you learn patience. Narrow the range. If anyone DMs me a zip I will not open it. Hash in-thread.

@crypta

Not fully convinced yet. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. TTD queries that scan the whole trace a

Decompiler output is a hypothesis. Treat it like one. This is the writeup I wanted when I was stuck. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. Version in my shot: current lab snapshot, not last year's blog.

This is the writeup I wanted when I was stuck. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. Took me 5 hours the first time.

@flarex

Not fully convinced yet. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. TTD queries that scan the whole trace a

That insult was not a technical point. I am reporting it. Did this on ARM64 last week — same shape, different pain. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Same class as the January thread, different binary.

@derekconnect

This is the writeup I wanted when I was stuck. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for c

This is getting personal and it does not need to. I tried the naive path first and wasted a morning. The load-bearing line: I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. Did you force-create the function or did auto-analysis luck into it? Same class as the October thread, different binary.

@iam_sammy

This matches a public n-day class from last patch Tuesday. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitte

The graph hid it. The listing did not. Trust the listing. This is the writeup I wanted when I was stuck. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Page heap and ASan catch different lies. I run both. My note id for this: 38-09.

@islandboyx

This is the writeup I wanted when I was stuck. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter

Same wall I hit last quarter. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I still have the snapshot named debu-56-pre.

This matches a public n-day class from last patch Tuesday. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. Which build of the tool? I got burned mixing notes across versions. Pinned a comment at 0x140000f4c in the listing.

@emeka_live

I tried the naive path first and wasted a morning. The load-bearing line: I keep seeing Twitter comparisons. WOW64: switch the stack before

Not fully convinced yet. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Same class as the March thread, different binary.

@kelnnode

Same wall I hit last quarter. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Ker

Stop flexing an IDA license. The question was the unwind info. Did this on ARM64 last week — same shape, different pain. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. Same class as the October thread, different binary.

@grey

Bookmarking this for the lab wiki. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. rr --chao

I am reporting the sample-drop hint. Hash and corpus tag only. Same wall I hit last quarter. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. I still have the snapshot named debu-56-pre.

Bookmarking this for the lab wiki. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. My note id for this: 38-06.

If you only have the decompiler, you do not have the bug. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Which build of the tool? I got burned mixing notes across versions. Took me 10 hours the first time.

@loader

I failed this exact class in January. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I

Calling the sticky 'priest talk' is how you earn a ban note. I will argue the opposite and then probably agree. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Can you quote the offset instead of the graph screenshot? Took me 3 hours the first time.

@andrewflex

Did this on ARM64 last week — same shape, different pain. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep see

Good. Dated shot, version in the post. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Page heap and ASan catch different lies. I run both. Hash of the public file, or are we arguing a shape? I still have the snapshot named debu-56-pre.

@babatunde_k

Good. Dated shot, version in the post. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter compari

The graph hid it. The listing did not. Trust the listing. This is the kind of thread that should be a sticky and is not. The load-bearing line: I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Pinned a comment at 0x1400026dc in the listing.

I tried the naive path first and wasted a morning. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Dump the helper process. Always the helper process. Pinned a comment at 0x140004461 in the listing.

This matches a public n-day class from last patch Tuesday. The load-bearing line: I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Same class as the June thread, different binary.

@block

This matches a public n-day class from last patch Tuesday. The load-bearing line: I keep seeing Twitter comparisons. rr --chaos is the first

This is getting personal and it does not need to. I want the listing, not the decompiler story. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1253.

@cryptb

Not fully convinced yet. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. SetThrea

I tried the naive path first and wasted a morning. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 38-34.

I failed this exact class in January. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. I reproduced it on lab build 1243.

Also: Dump the helper process. Always the helper process.

@gridx

I want the listing, not the decompiler story. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for cr

Calling the sticky 'priest talk' is how you earn a ban note. This belongs in the first-hour ritual. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. Is the hang the incomplete patch, or a second bug? Version in my shot: current lab snapshot, not last year's blog.

@rr_or_gtfo

Not fully convinced yet. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Dump the

I am reporting the sample-drop hint. Hash and corpus tag only. Did this on ARM64 last week — same shape, different pain. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Dump the helper process. Always the helper process. I will +rep a listing and −rep a vibe. That is the deal.

This belongs in the first-hour ritual. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I will +rep a listing and −rep a vibe. That is the deal.

Also: rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps.

@labsec

This belongs in the first-hour ritual. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Kernel time travel is not

That insult was not a technical point. I am reporting it. I reproduced it twice before I believed you. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. I will +rep a listing and −rep a vibe. That is the deal.

@build

I tried the naive path first and wasted a morning. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twi

Stop flexing an IDA license. The question was the unwind info. Good. Dated shot, version in the post. The load-bearing line: I keep seeing Twitter comparisons. Page heap and ASan catch different lies. I run both. I still have the snapshot named debu-56-pre.

Same wall I hit last quarter. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x1400022a3 in the listing.

Not fully convinced yet. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Dump the helper process. Always the helper process. Pinned a comment at 0x140000e20 in the listing.

@zulu

I failed this exact class in January. The load-bearing line: I keep seeing Twitter comparisons. TTD queries that scan the whole trace are ho

You keep moving the goalposts. First it was the decoder, now it is the dump. This belongs in the first-hour ritual. The load-bearing line: I keep seeing Twitter comparisons. If gdb finish hangs, there was a longjmp. Stop waiting. I will +rep a listing and −rep a vibe. That is the deal.

@derekconnect

I want the listing, not the decompiler story. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter

Bookmarking this for the lab wiki. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. TTD queries that scan the whole trace are how you learn patience. Narrow the range. My note id for this: 38-64.

@danprodigy

I tried the naive path first and wasted a morning. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter compar

That is a vibe. I asked for a listing offset. This belongs in the first-hour ritual. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. Took me 2 hours the first time.

Also: Page heap and ASan catch different lies. I run both.

I would have written the opposite conclusion a year ago. The load-bearing line: I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x14000625f in the listing.

This matches a public n-day class from last patch Tuesday. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Dump the helper process. Always the helper process. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

@heapx

This is the writeup I wanted when I was stuck. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. If gdb finish han

Decompiler output is a hypothesis. Treat it like one. I ran this on a licensed corpus binary. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Pinned a comment at 0x1400027c6 in the listing.

@ismailtrend

This is the kind of thread that should be a sticky and is not. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I kee

This is getting personal and it does not need to. I want the listing, not the decompiler story. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Page heap and ASan catch different lies. I run both. Did you force-create the function or did auto-analysis luck into it? Took me 10 hours the first time.

@andrewsoul

Quietly the best note on this board this month. The load-bearing line: I keep seeing Twitter comparisons. Kernel time travel is not user TTD

Decompiler output is a hypothesis. Treat it like one. Did this on ARM64 last week — same shape, different pain. The load-bearing line: I keep seeing Twitter comparisons. SetThreadDescription is free. I will keep nagging. Pinned a comment at 0x140006b50 in the listing.

@emmyfresh

I failed this exact class in January. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I

If you cannot paste bytes, you do not have a counterexample. I reproduced it twice before I believed you. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. Version in my shot: current lab snapshot, not last year's blog.

@cloudx

Same wall I hit last quarter. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Ker

Calling the sticky 'priest talk' is how you earn a ban note. Not fully convinced yet. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. SetThreadDescription is free. I will keep nagging. Can you quote the offset instead of the graph screenshot? I reproduced it on lab build 1179.

@grid

Please keep the hashes and drop the mystery zips. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. If gdb finish

This is the writeup I wanted when I was stuck. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. If gdb finish hangs, there was a longjmp. Stop waiting. I wrote a 12-line script and then threw it away. The listing was enough.

This matches a public n-day class from last patch Tuesday. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. Did page heap see it, or only the sanitizer? Pinned a comment at 0x140006f0b in the listing.

Also: TTD queries that scan the whole trace are how you learn patience. Narrow the range.

This is the kind of thread that should be a sticky and is not. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I still have the snapshot named debu-56-pre.

@loadx

I reproduced it twice before I believed you. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons.

Same wall I hit last quarter. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Dump the helper process. Always the helper process. I will +rep a listing and −rep a vibe. That is the deal.

@kennyblaze

I tried the naive path first and wasted a morning. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter compar

If you cannot paste bytes, you do not have a counterexample. The screenshot is the useful part of the post. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I still have the snapshot named debu-56-pre.

@freshmode

If you only have the decompiler, you do not have the bug. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep see

You keep moving the goalposts. First it was the decoder, now it is the dump. Please keep the hashes and drop the mystery zips. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. If gdb finish hangs, there was a longjmp. Stop waiting. I reproduced it on lab build 1334.

@lock

This matches a public n-day class from last patch Tuesday. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep se

You keep moving the goalposts. First it was the decoder, now it is the dump. Did this on ARM64 last week — same shape, different pain. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. Version in my shot: current lab snapshot, not last year's blog.

Not fully convinced yet. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. SetThreadDescription is free. I will keep nagging. My note id for this: 38-66.

@cryptc

Not fully convinced yet. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. SetThreadDescription is free. I will ke

I am reporting the sample-drop hint. Hash and corpus tag only. If you only have the decompiler, you do not have the bug. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. Took me 8 hours the first time.

@dotunhub

This matches a public n-day class from last patch Tuesday. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitte

The graph hid it. The listing did not. Trust the listing. I dumped after OEP and then did this. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I wrote a 12-line script and then threw it away. The listing was enough.

@iso

This matches a public n-day class from last patch Tuesday. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitte

I tried the naive path first and wasted a morning. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Page heap and ASan catch different lies. I run both. I will +rep a listing and −rep a vibe. That is the deal.

@chinedu_m

Bookmarking this for the lab wiki. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. TTD queri

That insult was not a technical point. I am reporting it. Quietly the best note on this board this month. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Same class as the June thread, different binary.

@flexjay

I want the listing, not the decompiler story. The load-bearing line: I keep seeing Twitter comparisons. TTD queries that scan the whole trac

Stop flexing an IDA license. The question was the unwind info. Good. Dated shot, version in the post. The load-bearing line: I keep seeing Twitter comparisons. SetThreadDescription is free. I will keep nagging. Took me 10 hours the first time.

Quietly the best note on this board this month. The load-bearing line: I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I reproduced it on lab build 1068.

Also: Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel.

@enc0de

I dumped after OEP and then did this. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Kernel

I want the listing, not the decompiler story. The load-bearing line: I keep seeing Twitter comparisons. TTD queries that scan the whole trace are how you learn patience. Narrow the range. I wrote a 12-line script and then threw it away. The listing was enough.

I want the listing, not the decompiler story. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. I wrote a 12-line script and then threw it away. The listing was enough.

@ibukunjay

I would have written the opposite conclusion a year ago. The load-bearing line: I keep seeing Twitter comparisons. Kernel time travel is not

That is a vibe. I asked for a listing offset. This matches a public n-day class from last patch Tuesday. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. WOW64: switch the stack before you talk. !wow64exts.sw. Version in my shot: current lab snapshot, not last year's blog.

Good. Dated shot, version in the post. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I will +rep a listing and −rep a vibe. That is the deal.

@meshx

Same wall I hit last quarter. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. Dump the helper process. Always th

I am reporting the sample-drop hint. Hash and corpus tag only. I still keep a paper notebook for this kind of note. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Took me 9 hours the first time.

Please keep the hashes and drop the mystery zips. The load-bearing line: I keep seeing Twitter comparisons. TTD queries that scan the whole trace are how you learn patience. Narrow the range. My note id for this: 38-80.

I ran this on a licensed corpus binary. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Can you quote the offset instead of the graph screenshot? Version in my shot: current lab snapshot, not last year's blog.

@netsec

Good. Dated shot, version in the post. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Kerne

That is a vibe. I asked for a listing offset. This is the kind of thread that should be a sticky and is not. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I wrote a 12-line script and then threw it away. The listing was enough.

@olaitanx

This is the kind of thread that should be a sticky and is not. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Tw

I would have written the opposite conclusion a year ago. The load-bearing line: I keep seeing Twitter comparisons. SetThreadDescription is free. I will keep nagging. Pinned a comment at 0x140004b5f in the listing.

@olamidee

I ran this on a licensed corpus binary. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. !ana

The graph hid it. The listing did not. Trust the listing. I disagree with the tone, not the bytes. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Pinned a comment at 0x140006f71 in the listing.

@patch

I would have written the opposite conclusion a year ago. The load-bearing line: I keep seeing Twitter comparisons. SetThreadDescription is f

If you cannot paste bytes, you do not have a counterexample. Came back to this after a coffee. Still hold. The load-bearing line: I keep seeing Twitter comparisons. Dump the helper process. Always the helper process. Version in my shot: current lab snapshot, not last year's blog.

I ran this on a licensed corpus binary. The load-bearing line: I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. I wrote a 12-line script and then threw it away. The listing was enough.

I dumped after OEP and then did this. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Which build of the tool? I got burned mixing notes across versions. Same class as the January thread, different binary.

@pwned

I ran this on a licensed corpus binary. The load-bearing line: I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Steppi

Stop flexing an IDA license. The question was the unwind info. I will argue the opposite and then probably agree. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Page heap and ASan catch different lies. I run both. Took me 10 hours the first time.

@richmondx

I dumped after OEP and then did this. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. !analyze is a hypothesis.

You keep moving the goalposts. First it was the decoder, now it is the dump. I disagree with the tone, not the bytes. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. If anyone DMs me a zip I will not open it. Hash in-thread.

@riskr

I will argue the opposite and then probably agree. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twi

I tried the naive path first and wasted a morning. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Took me 9 hours the first time.

I will argue the opposite and then probably agree. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Pinned a comment at 0x1400067c9 in the listing.

Also: Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel.

@secmod

I tried the naive path first and wasted a morning. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. WOW64: switch

Calling the sticky 'priest talk' is how you earn a ban note. The screenshot is the useful part of the post. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. SetThreadDescription is free. I will keep nagging. Can you quote the offset instead of the graph screenshot? If anyone DMs me a zip I will not open it. Hash in-thread.

@smartken

I will argue the opposite and then probably agree. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter compar

Decompiler output is a hypothesis. Treat it like one. This is the writeup I wanted when I was stuck. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. My note id for this: 38-21.

Came back to this after a coffee. Still hold. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. I will +rep a listing and −rep a vibe. That is the deal.

@stage

This is the writeup I wanted when I was stuck. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter

This is the writeup I wanted when I was stuck. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter comparisons. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Version in my shot: current lab snapshot, not last year's blog.

@stagx

Came back to this after a coffee. Still hold. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for cr

That is a vibe. I asked for a listing offset. Bookmarking this for the lab wiki. The load-bearing line: I keep seeing Twitter comparisons. !analyze is a hypothesis. !thread and the raw stacks are the evidence. My note id for this: 38-55.

@threx

This is the writeup I wanted when I was stuck. «gdb record vs rr vs Intel PT — a boring lab comparison» — specifically I keep seeing Twitter

This is getting personal and it does not need to. I failed this exact class in January. You wrote «I keep seeing Twitter comparisons». That is the sentence I keep. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Which build of the tool? I got burned mixing notes across versions. My note id for this: 38-23.

If you only have the decompiler, you do not have the bug. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. Dump the helper process. Always the helper process. I still have the snapshot named debu-56-pre.

I tried the naive path first and wasted a morning. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. TTD queries that scan the whole trace are how you learn patience. Narrow the range. I will +rep a listing and −rep a vibe. That is the deal.

@virt

If you only have the decompiler, you do not have the bug. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter

If you cannot paste bytes, you do not have a counterexample. I ran this on a licensed corpus binary. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes I already understand. If anyone DMs me a zip I will not open it. Hash in-thread.

@white

I tried the naive path first and wasted a morning. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter compar

That insult was not a technical point. I am reporting it. I want the listing, not the decompiler story. On «gdb record vs rr vs Intel PT — a boring lab comparison»: I keep seeing Twitter comparisons. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I reproduced it on lab build 1317.

@wifi

I ran this on a licensed corpus binary. The load-bearing line: I keep seeing Twitter comparisons. Hang dump for hangs. Minidump for crashes

I failed this exact class in January. The load-bearing line: I keep seeing Twitter comparisons. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Did you force-create the function or did auto-analysis luck into it? I still have the snapshot named debu-56-pre.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.