Repository navigation
Conversation
bc779ad to
ad49e88
Compare
|
Corpus decompilation diffs can be found at angr/dec-snapshots@master...angr/cle_765 |
ad49e88 to
67f1f45
Compare
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Validation record for head The loader now uses Regression evidence
Gate and static checks
The hosted macOS, Windows, and Pyodide jobs, downstream angr tests, and decompiler snapshots were not run locally; hosted CI must provide that coverage on the new head. This record replaces the earlier record for |
67f1f45 to
2aafe48
Compare
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Extern-object placement for the ARMEL blob Reproducer (BINARIES names the fixture checkout)import logging
import os
import cle
logging.getLogger("cle").setLevel(logging.CRITICAL)
path = os.path.join(os.environ["BINARIES"], "tests", "armel", "i2c_master_read-nucleol152re.bin")
ld = cle.Loader(path, auto_load_libs=False, main_opts={"backend": "blob", "arch": "ARMEL", "base_addr": 0x90000000})
main, extern = ld.main_object, ld.extern_object
print(f"main object {main.min_addr:#018x}-{main.max_addr:#018x}")
print(f"extern object {extern.min_addr:#018x}-{extern.max_addr:#018x}")
print(f"find_object_containing(0x0) -> {ld.find_object_containing(0)}")
print(f"find_object_containing(0x4) -> {ld.find_object_containing(4)}")Before — address zero belongs to the extern object: cle 7c5e1a2After — the extern object is above the image and address zero is unoccupied: cle e9a5cf0 |
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Resolved: the two pull requests this could not be rolled up withThis pull request has been excluded from every mono rollup because it broke two
Each fix still fails on its own branch's merge base with the error it was One consequence of this change is worth recording here rather than only on #730. #730's Verificationmaster + #765 + #730 + #721 at heads session: sharpen |
d160d97 to
525717e
Compare
525717e to
30ce113
Compare
|
There is already a page size, the null page size is the same size as any other page |
For narrow address spaces and images in the upper half, search above the image before falling back below it. Use the loader's page size for the null page guard, while allowing that page when no other gap fits. Preserve mapped_address_bits when bounding the search. Cover ARM and Z80 placement, the exhausted-space fallback, a larger page size, and DOS MZ placement above the 16-bit register range.
30ce113 to
e9a5cf0
Compare
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS You're right. I removed the separate null-page constant and the 4 KiB floor; the guard is now exactly
The focused loader tests pass all 22 cases. I also rebased the branch onto current |
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS
Problem
Loading this ARMEL blob at
0x90000000places the extern object at zero.find_object_containing(0)then returns that object for an address outside the input image.Root cause
Loader._find_safe_rebase_addrstarts at zero when the mapped address space is narrower than 32 bits or the image reaches its upper half.Fix
Search above both the image and the loader's configured
page_sizefirst, then elsewhere above that null-page guard, and use the low guard region only if those searches cannot fit the object. Keep the mapped address width when calculating the address-space limit.Testing
tests/test_rebase.pycovers ARM and Z80 placement, the exhausted-space fallback, exact one-byte, 4 KiB, and 8 KiB page sizes, an image below the guard, and DOS MZ placement in a 20-bit address space with 16-bit registers. The one-byte regression fails with the removed 4 KiB floor and passes whenpage_sizealone defines the guard.Fixes #745.
Validation: #765 (comment)
session: sharpen