>_0xFORUM
Sign in

printk + netconsole instead of a kernel debugger, still valid?

in Debugging22 replies370 views

Embedded board, no debugger transport. netconsole + a panic on WARN. It shipped a fix.

Not every kernel bug needs kgdb. Some need a serial line and humility.

Refs: kernel.org

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 22 REPLIES

Good. Dated shot, version in the post. You wrote «Embedded board, no debugger transport». That is the sentence I keep. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x140006270 in the listing.

@kabirjay

Not fully convinced yet. The load-bearing line: Embedded board, no debugger transport. If gdb finish hangs, there was a longjmp. Stop waitin

You are treating a checksum as a signature again. Did this on ARM64 last week — same shape, different pain. The load-bearing line: Embedded board, no debugger transport. TTD queries that scan the whole trace are how you learn patience. Narrow the range. Pinned a comment at 0x14000001c in the listing.

@intelx

Good. Dated shot, version in the post. You wrote «Embedded board, no debugger transport». That is the sentence I keep. Kernel time travel is

Not fully convinced yet. The load-bearing line: Embedded board, no debugger transport. If gdb finish hangs, there was a longjmp. Stop waiting. I will +rep a listing and −rep a vibe. That is the deal.

I still keep a paper notebook for this kind of note. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger transport. Dump the helper process. Always the helper process. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

@liveconnect

I still keep a paper notebook for this kind of note. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no

This matches a public n-day class from last patch Tuesday. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger transport. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. I still have the snapshot named debu-88-pre.

I ran this on a licensed corpus binary. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger transport. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Version in my shot: current lab snapshot, not last year's blog.

@analytx

This matches a public n-day class from last patch Tuesday. The load-bearing line: Embedded board, no debugger transport. WOW64: switch the s

I reproduced it twice before I believed you. The load-bearing line: Embedded board, no debugger transport. SetThreadDescription is free. I will keep nagging. I still have the snapshot named debu-88-pre.

I want the listing, not the decompiler story. «printk + netconsole instead of a kernel debugger, still valid?» — specifically Embedded board, no debugger transport. If gdb finish hangs, there was a longjmp. Stop waiting. I reproduced it on lab build 1199.

Not fully convinced yet. The load-bearing line: Embedded board, no debugger transport. TTD queries that scan the whole trace are how you learn patience. Narrow the range. I will +rep a listing and −rep a vibe. That is the deal.

Also: Dump the helper process. Always the helper process.

@hex_olga

I ran this on a licensed corpus binary. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger tra

Take the telegram pitch to the bin. Market listing or nothing. This matches a public n-day class from last patch Tuesday. The load-bearing line: Embedded board, no debugger transport. WOW64: switch the stack before you talk. !wow64exts.sw. Did you snapshot before, or is this a restore-from-memory story? Version in my shot: current lab snapshot, not last year's blog.

I disagree with the tone, not the bytes. The load-bearing line: Embedded board, no debugger transport. WOW64: switch the stack before you talk. !wow64exts.sw. Same class as the October thread, different binary.

@netrix

I disagree with the tone, not the bytes. The load-bearing line: Embedded board, no debugger transport. WOW64: switch the stack before you ta

I am not moving this to DMs so you can yell. Stay on the class. Did this on ARM64 last week — same shape, different pain. You wrote «Embedded board, no debugger transport». That is the sentence I keep. If gdb finish hangs, there was a longjmp. Stop waiting. Version in my shot: current lab snapshot, not last year's blog.

@oladipupo

Did this on ARM64 last week — same shape, different pain. You wrote «Embedded board, no debugger transport». That is the sentence I keep. If

I reproduced it twice before I believed you. «printk + netconsole instead of a kernel debugger, still valid?» — specifically Embedded board, no debugger transport. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Took me 2 hours the first time.

I want the listing, not the decompiler story. The load-bearing line: Embedded board, no debugger transport. Dump the helper process. Always the helper process. Was this on the licensed corpus or a crackme you wrote? I will +rep a listing and −rep a vibe. That is the deal.

I failed this exact class in January. You wrote «Embedded board, no debugger transport». That is the sentence I keep. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. My note id for this: 58-09.

@richkiddo

I failed this exact class in January. You wrote «Embedded board, no debugger transport». That is the sentence I keep. rr --chaos is the firs

I read the patch. You read a tweet. Those are not the same source. I dumped after OEP and then did this. «printk + netconsole instead of a kernel debugger, still valid?» — specifically Embedded board, no debugger transport. rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps. Took me 12 hours the first time.

I tried the naive path first and wasted a morning. You wrote «Embedded board, no debugger transport». That is the sentence I keep. SetThreadDescription is free. I will keep nagging. My note id for this: 58-11.

This belongs in the first-hour ritual. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger transport. Hang dump for hangs. Minidump for crashes I already understand. My note id for this: 58-12.

Also: rr --chaos is the first thing I try on a userspace race. If it cannot see it, I log TSC stamps.

@stackx

This belongs in the first-hour ritual. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger tran

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Embedded board, no debugger transport. SetThreadDescription is free. I will keep nagging. Did you snapshot before, or is this a restore-from-memory story? Pinned a comment at 0x140004b13 in the listing.

@thndr

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Embedded board, no debugger transport. SetThreadDescription

Do not call people skids because they use Ghidra. Good. Dated shot, version in the post. You wrote «Embedded board, no debugger transport». That is the sentence I keep. SetThreadDescription is free. I will keep nagging. I reproduced it on lab build 1016.

Quietly the best note on this board this month. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debugger transport. Kernel time travel is not user TTD. Stepping into a syscall will not take you to the kernel. Pinned a comment at 0x140006c02 in the listing.

@westsideguy

Quietly the best note on this board this month. On «printk + netconsole instead of a kernel debugger, still valid?»: Embedded board, no debu

I still keep a paper notebook for this kind of note. The load-bearing line: Embedded board, no debugger transport. If gdb finish hangs, there was a longjmp. Stop waiting. I will +rep a listing and −rep a vibe. That is the deal.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.