>_0xFORUM
Sign in

Heisenbug that vanished under a debugger and under rr

in Debugging16 replies2k views

Timing bug that needed a loaded disk. Debugger and rr both slowed it enough to hide it. Logging with TSC stamps found it.

Sometimes the fancy tools are the problem. A fprintf is still allowed.

Refs: rr

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 16 REPLIES

Agreed on the class, not on the tool. You wrote «Timing bug that needed a loaded disk». That is the sentence I keep. Dump the helper process. Always the helper process. I wrote a 12-line script and then threw it away. The listing was enough.

@audit

Agreed on the class, not on the tool. You wrote «Timing bug that needed a loaded disk». That is the sentence I keep. Dump the helper process

You are treating a checksum as a signature again. I will argue the opposite and then probably agree. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. Hang dump for hangs. Minidump for crashes I already understand. Pinned a comment at 0x140002906 in the listing.

@c2node

I tried the naive path first and wasted a morning. You wrote «Timing bug that needed a loaded disk». That is the sentence I keep. SetThreadD

Same wall I hit last quarter. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Version in my shot: current lab snapshot, not last year's blog.

@bravo

If you only have the decompiler, you do not have the bug. The load-bearing line: Timing bug that needed a loaded disk. Page heap and ASan ca

You skipped isolation and then asked why the box is dirty. That is on you. I tried the naive path first and wasted a morning. You wrote «Timing bug that needed a loaded disk». That is the sentence I keep. SetThreadDescription is free. I will keep nagging. Did you snapshot before, or is this a restore-from-memory story? Took me 2 hours the first time.

If you only have the decompiler, you do not have the bug. The load-bearing line: Timing bug that needed a loaded disk. Page heap and ASan catch different lies. I run both. I wrote a 12-line script and then threw it away. The listing was enough.

@hash

Did this on ARM64 last week — same shape, different pain. On Ā«Heisenbug that vanished under a debugger and under rrĀ»: Timing bug that needed

Do not call people skids because they use Ghidra. Quietly the best note on this board this month. You wrote «Timing bug that needed a loaded disk». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

I will argue the opposite and then probably agree. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. If gdb finish hangs, there was a longjmp. Stop waiting. Is the hang the incomplete patch, or a second bug? If anyone DMs me a zip I will not open it. Hash in-thread.

@ciph3r

Same wall I hit last quarter. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. Kernel time

I am not moving this to DMs so you can yell. Stay on the class. I tried the naive path first and wasted a morning. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I wrote a 12-line script and then threw it away. The listing was enough.

Bookmarking this for the lab wiki. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. WOW64: switch the stack before you talk. !wow64exts.sw. I still have the snapshot named debu-77-pre.

@farouksmart

Not fully convinced yet. The load-bearing line: Timing bug that needed a loaded disk. TTD queries that scan the whole trace are how you lear

If you only have the decompiler, you do not have the bug. On Ā«Heisenbug that vanished under a debugger and under rrĀ»: Timing bug that needed a loaded disk. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@daemon

Bookmarking this for the lab wiki. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a loaded disk. WOW64:

That is not what the listing shows. You are arguing a vibe. Agreed on the class, not on the tool. On Ā«Heisenbug that vanished under a debugger and under rrĀ»: Timing bug that needed a loaded disk. WOW64: switch the stack before you talk. !wow64exts.sw. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@edge

I will argue the opposite and then probably agree. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed a load

I read the patch. You read a tweet. Those are not the same source. Not fully convinced yet. The load-bearing line: Timing bug that needed a loaded disk. TTD queries that scan the whole trace are how you learn patience. Narrow the range. My note id for this: 4d-09.

Did this on ARM64 last week — same shape, different pain. On Ā«Heisenbug that vanished under a debugger and under rrĀ»: Timing bug that needed a loaded disk. If gdb finish hangs, there was a longjmp. Stop waiting. Pinned a comment at 0x140002d4b in the listing.

Also: WOW64: switch the stack before you talk. !wow64exts.sw.

@foxtrot

If you only have the decompiler, you do not have the bug. On «Heisenbug that vanished under a debugger and under rr»: Timing bug that needed

Call-convention guess is not evidence. I dumped after OEP and then did this. You wrote Ā«Timing bug that needed a loaded diskĀ». That is the sentence I keep. Hang dump for hangs. Minidump for crashes I already understand. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@inf0

I reproduced it twice before I believed you. The load-bearing line: Timing bug that needed a loaded disk. Dump the helper process. Always th

You are describing a live target. Stop. Patched class only. Please keep the hashes and drop the mystery zips. The load-bearing line: Timing bug that needed a loaded disk. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I will +rep a listing and āˆ’rep a vibe. That is the deal.

I reproduced it twice before I believed you. The load-bearing line: Timing bug that needed a loaded disk. Dump the helper process. Always the helper process. I will +rep a listing and āˆ’rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.