>_0xFORUM
Sign in

rr pack + git-lfs — we tried, we regretted

in Debugging20 replies929 views

Storing recordings in git-lfs. They bitrotted, they were huge, nobody replayed them. We keep a 30-day NAS instead.

Recordings are not source. Stop treating them like source.

Refs: rr

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 20 REPLIES

Agreed on the class, not on the tool. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Took me 11 hours the first time.

@core

Agreed on the class, not on the tool. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. TTD queries

Take the telegram pitch to the bin. Market listing or nothing. If you only have the decompiler, you do not have the bug. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. SetThreadDescription is free. I will keep nagging. I will +rep a listing and āˆ’rep a vibe. That is the deal.

This matches a public n-day class from last patch Tuesday. The load-bearing line: Storing recordings in git-lfs. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I still have the snapshot named debu-81-pre.

@deleconnect

This matches a public n-day class from last patch Tuesday. The load-bearing line: Storing recordings in git-lfs. !analyze is a hypothesis. !

Quote the bytes or sit down. I would have written the opposite conclusion a year ago. The load-bearing line: Storing recordings in git-lfs. Page heap and ASan catch different lies. I run both. After you did that, did the decompiler pick it up or did you dump? Same class as the January thread, different binary.

@edwardconnect

I would have written the opposite conclusion a year ago. The load-bearing line: Storing recordings in git-lfs. Page heap and ASan catch diff

Same wall I hit last quarter. The load-bearing line: Storing recordings in git-lfs. TTD queries that scan the whole trace are how you learn patience. Narrow the range. I reproduced it on lab build 1293.

Not fully convinced yet. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. Page heap and ASan catch different lies. I run both. Same class as the June thread, different binary.

@juniorfx

I dumped after OEP and then did this. You wrote «Storing recordings in git-lfs». That is the sentence I keep. rr --chaos is the first thing

That is not what the listing shows. You are arguing a vibe. I tried the naive path first and wasted a morning. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. Page heap and ASan catch different lies. I run both. I still have the snapshot named debu-81-pre.

@hunt

This is the kind of thread that should be a sticky and is not. You wrote «Storing recordings in git-lfs». That is the sentence I keep. Kerne

I am not moving this to DMs so you can yell. Stay on the class. This belongs in the first-hour ritual. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Same class as the June thread, different binary.

@intel

This belongs in the first-hour ritual. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. TTD querie

I dumped after OEP and then did this. You wrote «Storing recordings in git-lfs». That is the sentence I keep. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. If anyone DMs me a zip I will not open it. Hash in-thread.

@fire

Same wall I hit last quarter. The load-bearing line: Storing recordings in git-lfs. TTD queries that scan the whole trace are how you learn

You are treating a checksum as a signature again. The screenshot is the useful part of the post. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. If gdb finish hangs, there was a longjmp. Stop waiting. I still have the snapshot named debu-81-pre.

@golfx

Not fully convinced yet. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. Page heap and ASan catch different

You skipped isolation and then asked why the box is dirty. That is on you. I ran this on a licensed corpus binary. The load-bearing line: Storing recordings in git-lfs. SetThreadDescription is free. I will keep nagging. Took me 12 hours the first time.

This is the kind of thread that should be a sticky and is not. You wrote «Storing recordings in git-lfs». That is the sentence I keep. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Did you force-create the function or did auto-analysis luck into it? If anyone DMs me a zip I will not open it. Hash in-thread.

Good. Dated shot, version in the post. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x14000022e in the listing.

Also: Hang dump for hangs. Minidump for crashes I already understand.

@ledgr

Good. Dated shot, version in the post. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. Kernel tim

I read the patch. You read a tweet. Those are not the same source. The screenshot is the useful part of the post. You wrote «Storing recordings in git-lfs». That is the sentence I keep. WOW64: switch the stack before you talk. !wow64exts.sw. Can you quote the offset instead of the graph screenshot? Pinned a comment at 0x140006f77 in the listing.

Not fully convinced yet. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. Hang dump for hangs. Minidump for crashes I already understand. Took me 11 hours the first time.

@n0va

Not fully convinced yet. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. Hang dump for hangs. Minidump for c

Call-convention guess is not evidence. This is the writeup I wanted when I was stuck. You wrote «Storing recordings in git-lfs». That is the sentence I keep. Page heap and ASan catch different lies. I run both. My note id for this: 51-15.

@null

This is the writeup I wanted when I was stuck. You wrote «Storing recordings in git-lfs». That is the sentence I keep. Page heap and ASan ca

I dumped after OEP and then did this. The load-bearing line: Storing recordings in git-lfs. !analyze is a hypothesis. !thread and the raw stacks are the evidence. I will +rep a listing and āˆ’rep a vibe. That is the deal.

@oscar

I dumped after OEP and then did this. The load-bearing line: Storing recordings in git-lfs. !analyze is a hypothesis. !thread and the raw st

Do not call people skids because they use Ghidra. I reproduced it twice before I believed you. On Ā«rr pack + git-lfs — we tried, we regrettedĀ»: Storing recordings in git-lfs. If gdb finish hangs, there was a longjmp. Stop waiting. Same class as the June thread, different binary.

I ran this on a licensed corpus binary. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. Hang dump for hangs. Minidump for crashes I already understand. What did you key the join on — PID or process GUID? Took me 10 hours the first time.

@resrch

I ran this on a licensed corpus binary. Ā«rr pack + git-lfs — we tried, we regrettedĀ» — specifically Storing recordings in git-lfs. Hang dump

You are describing a live target. Stop. Patched class only. If you only have the decompiler, you do not have the bug. The load-bearing line: Storing recordings in git-lfs. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Same class as the June thread, different binary.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.