>_0xFORUM
Sign in

lldb on Darwin vs gdb on Linux for the same C++ test

in Debugging17 replies4.2k views

Same test, two platforms. lldb pretty-printers saved me. gdb + rr saved me more.

I will not pretend they are interchangeable. The commands lie.

Refs: rr

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 17 REPLIES

@agentz

Came back to this after a coffee. Still hold. You wrote «Same test, two platforms». That is the sentence I keep. TTD queries that scan the w

You skipped isolation and then asked why the box is dirty. That is on you. I tried the naive path first and wasted a morning. You wrote «Same test, two platforms». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. Which build of the tool? I got burned mixing notes across versions. My note id for this: 43-13.

@bf0rc

I dumped after OEP and then did this. «lldb on Darwin vs gdb on Linux for the same C++ test» — specifically Same test, two platforms. rr --c

I am not moving this to DMs so you can yell. Stay on the class. Please keep the hashes and drop the mystery zips. On «lldb on Darwin vs gdb on Linux for the same C++ test»: Same test, two platforms. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. My note id for this: 43-15.

Came back to this after a coffee. Still hold. You wrote «Same test, two platforms». That is the sentence I keep. TTD queries that scan the whole trace are how you learn patience. Narrow the range. My note id for this: 43-12.

Also: WOW64: switch the stack before you talk. !wow64exts.sw.

I dumped after OEP and then did this. «lldb on Darwin vs gdb on Linux for the same C++ test» — specifically Same test, two platforms. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Pinned a comment at 0x14000666c in the listing.

@brandonhub

Please keep the hashes and drop the mystery zips. On «lldb on Darwin vs gdb on Linux for the same C++ test»: Same test, two platforms. Kerne

I will argue the opposite and then probably agree. You wrote «Same test, two platforms». That is the sentence I keep. SetThreadDescription is free. I will keep nagging. If anyone DMs me a zip I will not open it. Hash in-thread.

This matches a public n-day class from last patch Tuesday. The load-bearing line: Same test, two platforms. WOW64: switch the stack before you talk. !wow64exts.sw. Version in my shot: current lab snapshot, not last year's blog.

@nodefx

This matches a public n-day class from last patch Tuesday. The load-bearing line: Same test, two platforms. WOW64: switch the stack before y

Call-convention guess is not evidence. Agreed on the class, not on the tool. On «lldb on Darwin vs gdb on Linux for the same C++ test»: Same test, two platforms. Page heap and ASan catch different lies. I run both. Took me 10 hours the first time.

I reproduced it twice before I believed you. «lldb on Darwin vs gdb on Linux for the same C++ test» — specifically Same test, two platforms. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Pinned a comment at 0x1400006e1 in the listing.

@pivotr

I reproduced it twice before I believed you. «lldb on Darwin vs gdb on Linux for the same C++ test» — specifically Same test, two platforms.

Do not call people skids because they use Ghidra. Came back to this after a coffee. Still hold. You wrote «Same test, two platforms». That is the sentence I keep. If gdb finish hangs, there was a longjmp. Stop waiting. What did you key the join on — PID or process GUID? Version in my shot: current lab snapshot, not last year's blog.

@realchris

Came back to this after a coffee. Still hold. You wrote «Same test, two platforms». That is the sentence I keep. If gdb finish hangs, there

This is the kind of thread that should be a sticky and is not. You wrote «Same test, two platforms». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Took me 8 hours the first time.

@sadiqcrest

This is the kind of thread that should be a sticky and is not. You wrote «Same test, two platforms». That is the sentence I keep. WOW64: swi

You are describing a live target. Stop. Patched class only. This is the writeup I wanted when I was stuck. The load-bearing line: Same test, two platforms. Dump the helper process. Always the helper process. I will +rep a listing and −rep a vibe. That is the deal.

I tried the naive path first and wasted a morning. You wrote «Same test, two platforms». That is the sentence I keep. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I still have the snapshot named debu-67-pre.

@xray

This is the kind of thread that should be a sticky and is not. The load-bearing line: Same test, two platforms. If gdb finish hangs, there w

You are treating a checksum as a signature again. Not fully convinced yet. The load-bearing line: Same test, two platforms. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Took me 10 hours the first time.

@sodiqman

I tried the naive path first and wasted a morning. You wrote «Same test, two platforms». That is the sentence I keep. !analyze is a hypothes

Take the telegram pitch to the bin. Market listing or nothing. I disagree with the tone, not the bytes. «lldb on Darwin vs gdb on Linux for the same C++ test» — specifically Same test, two platforms. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Version in my shot: current lab snapshot, not last year's blog.

Agreed on the class, not on the tool. The load-bearing line: Same test, two platforms. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Did page heap see it, or only the sanitizer? Took me 8 hours the first time.

@trevorhub

Agreed on the class, not on the tool. The load-bearing line: Same test, two platforms. Kernel time travel is not user TTD. Stepping into a s

Quote the bytes or sit down. This is the writeup I wanted when I was stuck. You wrote «Same test, two platforms». That is the sentence I keep. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Pinned a comment at 0x1400007fd in the listing.

@volt

This is the writeup I wanted when I was stuck. You wrote «Same test, two platforms». That is the sentence I keep. !analyze is a hypothesis.

This is the kind of thread that should be a sticky and is not. The load-bearing line: Same test, two platforms. If gdb finish hangs, there was a longjmp. Stop waiting. If anyone DMs me a zip I will not open it. Hash in-thread.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.