Conversation
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Validation record for head
Corpus A/B, 1,557 PE objects, one process per object per side. The oracle is each
The last two rows are objects this change cannot help: 37 whose machine type the Each object was then loaded twice, at its nominal base and 0x10000 higher, and
CFG effect. Applying a base relocation only changes bytes when the image moves,
15 of those objects cover 252,544 more bytes and 42 cover 25,090 fewer. The The reductions are the fix working: with the pointers still naming the old base,
Caveats: the corpus is a private dataset, so objects are named by machine type and count rather than by path; the fixtures in angr/binaries#183 reproduce both architectures publicly. CI on this PR: all 20 checks are green at head Correction, 2026-09-03. An earlier version of this comment said that Re-keyed 2026-08-28. The figures above were measured at Re-keyed 2026-09-04, after a rebase onto cle master Hosted CI at Correction, 2026-09-04. An earlier version of the paragraph above read this same head at 16:24Z as 15 |
|
Corpus decompilation diffs can be found at angr/dec-snapshots@master...angr/cle_755 |
0775fe8 to
58d16f7
Compare
58d16f7 to
988c008
Compare
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Full base-relocation report for the ARM64 and ARMNT PE fixtures of angr/binaries#183, loaded at their linked base and rebased by Before — every base relocation is dropped, so rebasing moves nothing ( cle at the merge base, 46a3733After — each type is recognised and applied, and every fixup moves by the rebase delta: with this change, 988c008 |
ALL_RELOCATIONS was keyed on "arm", "mips" and "RISCV", which archinfo does not produce, and had no AARCH64 entry, so get_relocation returned None for every type on those architectures and the whole .reloc directory was discarded. Key the table on arch.name instead. That alone is not safe. PEReloc.value falls through to self.resolvedby.rebased_addr, which is None for a base relocation, so making the ARM table reachable turns every IMAGE_REL_BASED_THUMB_MOV32 into an AttributeError during loading. Implement that relocation, and let the base class skip a recognised but unimplemented type with a warning rather than raising.
988c008 to
04d5874
Compare
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS
Problem
A PE's whole
.relocdirectory is discarded on ARM64, ARMNT, MIPS and RISC-V. Loadingtests/aarch64/windows/pe_reloc_arm64.exe, linked at0x140000000, keeps only the padding entry, and rebasing the image then moves no pointer at all:That is invisible at the preferred base and silently wrong anywhere else, including an image whose
ImageBaseis 0, where every absolute pointer in the file keeps a link-time value.Root cause
PE._make_reloclooks the table up byself.arch.name, butALL_RELOCATIONSwas keyed on strings archinfo does not produce, and had no AArch64 entry at all:archinfo names those architectures
AARCH64,ARMEL,ARMHF,ARMCortexM,MIPS32andRISCV64, soget_relocationreturnedNonefor every type and the loader loggedUnknown reloc 10 on AARCH64. Re-keying alone is not enough:PEReloc.valuefell through toself.resolvedby.rebased_addr, which no base relocation has, so a recognised type would have been dropped without a word.Fix
The table is keyed on
arch.name,IMAGE_REL_BASED_THUMB_MOV32gains avaluethat reads and rewrites theimm4:i:imm3:imm8halves of the MOVW.W/MOVT.W pair, and the base class returnsNonefor a symbol-less relocation after warning once per type, so a recognised but unimplemented fixup is reported instead of being silently skipped.IMAGE_REL_BASED_ARM64_MOV32AandMOV32Tstay unimplemented and now say so.Rebasing by
0x10000then moves every fixup:Testing
tests/test_pe_relocations.pyloads both ARM images at their linked base and rebased:test_aarch64assertsobj.memory.unpack_word(0x2000, size=8) == 0x1400011B8,test_armntassertsthumb_mov32_immediate(obj.memory.load(0x104C, 8)) == 0x402000, and the two rebased cases assertrebased == linked + REBASE_DELTAfor every fixup.test_x86_64_unchangedpins thattests/x86_64/windows/sioctl.syskeeps its 13IMAGE_REL_BASED_DIR64entries. All four ARM tests fail on the merge base, where the relocations do not exist.Fixes #752. Needs angr/binaries#183 for the fixtures.
Validation: #755 (comment)
sync: angr/binaries#183
session: sharpen