>_0xFORUM
Sign in

AddressSanitizer suppressions that became the product

in Debugging16 replies1.5k views

A 200-line suppression file. Half of it was real bugs we papered over. I deleted 80 lines and CI went red in a good way.

If your suppression file is a novel, you are not using ASan. You are ignoring it.

Refs: rr

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

This is the writeup I wanted when I was stuck. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. Hang dump for hangs. Minidump for crashes I already understand. Did page heap see it, or only the sanitizer? Took me 5 hours the first time.

@yunuszone

I disagree with the tone, not the bytes. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file.

You are describing a live target. Stop. Patched class only. Quietly the best note on this board this month. The load-bearing line: A 200-line suppression file. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Version in my shot: current lab snapshot, not last year's blog.

I reproduced it twice before I believed you. The load-bearing line: A 200-line suppression file. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. My note id for this: 4a-05.

@alexwise

This is the writeup I wanted when I was stuck. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression

I still keep a paper notebook for this kind of note. The load-bearing line: A 200-line suppression file. If gdb finish hangs, there was a longjmp. Stop waiting. Same class as the January thread, different binary.

Quietly the best note on this board this month. The load-bearing line: A 200-line suppression file. WOW64: switch the stack before you talk. !wow64exts.sw. Was this on the licensed corpus or a crackme you wrote? I will +rep a listing and −rep a vibe. That is the deal.

@binx

I reproduced it twice before I believed you. The load-bearing line: A 200-line suppression file. rr --chaos is the first thing I try on a us

Quote the bytes or sit down. I want the listing, not the decompiler story. The load-bearing line: A 200-line suppression file. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 4a-06.

@brightonx

I want the listing, not the decompiler story. The load-bearing line: A 200-line suppression file. Hang dump for hangs. Minidump for crashes

Bookmarking this for the lab wiki. The load-bearing line: A 200-line suppression file. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I still have the snapshot named debu-74-pre.

I failed this exact class in January. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. WOW64: switch the stack before you talk. !wow64exts.sw. I still have the snapshot named debu-74-pre.

Also: Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel.

@cookx

Please keep the hashes and drop the mystery zips. On «AddressSanitizer suppressions that became the product»: A 200-line suppression file. H

You skipped isolation and then asked why the box is dirty. That is on you. I reproduced it twice before I believed you. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Same class as the October thread, different binary.

Not fully convinced yet. On «AddressSanitizer suppressions that became the product»: A 200-line suppression file. WOW64: switch the stack before you talk. !wow64exts.sw. I reproduced it on lab build 1265.

Please keep the hashes and drop the mystery zips. On «AddressSanitizer suppressions that became the product»: A 200-line suppression file. Hang dump for hangs. Minidump for crashes I already understand. I reproduced it on lab build 1039.

@edgex

I failed this exact class in January. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. WO

I would have written the opposite conclusion a year ago. The load-bearing line: A 200-line suppression file. !analyze is a hypothesis. !thread and the raw stacks are the evidence. Hash of the public file, or are we arguing a shape? My note id for this: 4a-13.

I ran this on a licensed corpus binary. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. Page heap and ASan catch different lies. I run both. If anyone DMs me a zip I will not open it. Hash in-thread.

@felixzone

I would have written the opposite conclusion a year ago. The load-bearing line: A 200-line suppression file. !analyze is a hypothesis. !thre

That is not what the listing shows. You are arguing a vibe. The screenshot is the useful part of the post. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. Page heap and ASan catch different lies. I run both. Version in my shot: current lab snapshot, not last year's blog.

I failed this exact class in January. On «AddressSanitizer suppressions that became the product»: A 200-line suppression file. TTD queries that scan the whole trace are how you learn patience. Narrow the range. I will +rep a listing and −rep a vibe. That is the deal.

@vulnx

I failed this exact class in January. On «AddressSanitizer suppressions that became the product»: A 200-line suppression file. TTD queries t

I disagree with the tone, not the bytes. «AddressSanitizer suppressions that became the product» — specifically A 200-line suppression file. Dump the helper process. Always the helper process. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.