mirror of
https://github.com/cea-sec/miasm
synced 2026-06-21 13:48:18 +00:00
Test/Depgraph: add DG emulation regression tests
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
from pdb import pm
|
||||
import sys
|
||||
import subprocess
|
||||
import json
|
||||
|
||||
|
||||
expected_file = sys.argv[1]
|
||||
dg = subprocess.Popen(["python"] + sys.argv[2:], stdout=subprocess.PIPE)
|
||||
|
||||
stdout, _ = dg.communicate()
|
||||
expected = json.load(open(expected_file))
|
||||
result = json.loads(stdout)
|
||||
|
||||
|
||||
expected.sort()
|
||||
result.sort()
|
||||
|
||||
print expected
|
||||
print result
|
||||
assert expected == result
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x1", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x1", "satisfiability": true, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x3", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x3", "satisfiability": true, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x3", "has_loop": false}, {"EAX": "0x4", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x4", "satisfiability": true, "constraints": {"zf_init": "0x1"}}, {"has_loop": false, "EAX": "0x3", "satisfiability": true, "constraints": {"zf_init": "0x0"}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x3", "has_loop": false}, {"EAX": "0x5", "has_loop": true}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x3", "satisfiability": false, "constraints": {}}, {"has_loop": true, "EAX": "0x5", "satisfiability": false, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "EBX_init", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "EBX_init", "satisfiability": true, "constraints": {}}, {"has_loop": true, "EAX": "EBX_init", "satisfiability": false, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x3", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x3", "satisfiability": true, "constraints": {}}, {"has_loop": true, "EAX": "0x3", "satisfiability": false, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x1", "has_loop": false}, {"EAX": "0x2", "has_loop": true}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x1", "satisfiability": true, "constraints": {"EAX_init": "0xffffffff"}}, {"has_loop": true, "EAX": "0x2", "satisfiability": false, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x1", "ECX": "0x2", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x1", "constraints": {}, "satisfiability": true, "ECX": "0x2"}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"ECX": "0x2", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "constraints": {}, "satisfiability": true, "ECX": "0x2"}]
|
||||
@@ -0,0 +1,2 @@
|
||||
[{"EAX": "0x1", "EBX": "0x2", "has_loop": false},
|
||||
{"EAX": "0x3", "EBX": "0x4", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x1", "EBX": "0x2", "satisfiability": true, "constraints": {}}, {"has_loop": false, "EAX": "0x3", "EBX": "0x4", "satisfiability": true, "constraints": {}}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"EAX": "0x1", "EBX": "0x3", "has_loop": false}, {"EAX": "0x1", "EBX": "0x4", "has_loop": false}, {"EAX": "0x2", "EBX": "0x4", "has_loop": false}, {"EAX": "0x2", "EBX": "0x3", "has_loop": false}]
|
||||
@@ -0,0 +1 @@
|
||||
[{"has_loop": false, "EAX": "0x1", "EBX": "0x3", "satisfiability": true, "constraints": {"zf_init": "0x0"}}, {"has_loop": false, "EAX": "0x2", "EBX": "0x3", "satisfiability": false, "constraints": {}}, {"has_loop": false, "EAX": "0x1", "EBX": "0x4", "satisfiability": false, "constraints": {}}, {"has_loop": false, "EAX": "0x2", "EBX": "0x4", "satisfiability": true, "constraints": {"zf_init": "0x1"}}]
|
||||
@@ -0,0 +1,9 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
MOV EBX, ECX
|
||||
JMP lbl2
|
||||
lbl2:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,9 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
MOV EBX, 0x2
|
||||
JMP lbl2
|
||||
lbl2:
|
||||
LEA EAX, DWORD PTR [EBX + ECX]
|
||||
RET
|
||||
@@ -0,0 +1,12 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
JZ lbl2
|
||||
lbl1:
|
||||
MOV EBX, 0x2
|
||||
JMP end
|
||||
lbl2:
|
||||
MOV EBX, 0x3
|
||||
JMP end
|
||||
end:
|
||||
LEA EAX, DWORD PTR [EBX + ECX]
|
||||
RET
|
||||
@@ -0,0 +1,10 @@
|
||||
main:
|
||||
MOV EBX, 0x1
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
ADD EBX, 0x2
|
||||
CMP EBX, 0x0
|
||||
JNZ lbl1
|
||||
end:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,10 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
ADD ECX, 0x2
|
||||
CMP ECX, 0x0
|
||||
JZ lbl1
|
||||
end:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,11 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
MOV EBX, 0x3
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
ADD ECX, 0x2
|
||||
CMP ECX, 0x0
|
||||
JZ lbl1
|
||||
end:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,12 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
MOV EDX, 0x2
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
MOV EBX, ECX
|
||||
MOV ECX, EDX
|
||||
CMP EAX, 0x0
|
||||
JZ lbl1
|
||||
end:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,10 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
MOV EBX, 0x2
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
XCHG EBX, ECX
|
||||
JMP end
|
||||
end:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,10 @@
|
||||
main:
|
||||
MOV ECX, 0x1
|
||||
MOV EBX, 0x2
|
||||
JMP lbl1
|
||||
lbl1:
|
||||
XCHG EBX, ECX
|
||||
JMP end
|
||||
end:
|
||||
MOV EAX, EBX
|
||||
RET
|
||||
@@ -0,0 +1,13 @@
|
||||
main:
|
||||
MOV ECX, 0x8
|
||||
JZ lbl2
|
||||
lbl1:
|
||||
MOV EAX, 0x1
|
||||
MOV EBX, 0x2
|
||||
JMP end
|
||||
lbl2:
|
||||
MOV EAX, 0x3
|
||||
MOV EBX, 0x4
|
||||
JMP end
|
||||
end:
|
||||
RET
|
||||
@@ -0,0 +1,20 @@
|
||||
main:
|
||||
MOV ECX, 0x8
|
||||
JZ lbl2
|
||||
lbl1:
|
||||
MOV EAX, 0x1
|
||||
JMP end1
|
||||
lbl2:
|
||||
MOV EAX, 0x2
|
||||
JMP end1
|
||||
end1:
|
||||
JZ lbl4
|
||||
lbl3:
|
||||
MOV EBX, 0x3
|
||||
JMP end
|
||||
lbl4:
|
||||
MOV EBX, 0x4
|
||||
JMP end
|
||||
|
||||
end:
|
||||
RET
|
||||
@@ -22,11 +22,19 @@ class RegressionTest(Test):
|
||||
- @base_dir: test/@base_dir
|
||||
- @tags: TAGS["regression"]"""
|
||||
|
||||
sample_dir = os.path.join("..", "samples")
|
||||
|
||||
def __init__(self, *args, **kwargs):
|
||||
super(RegressionTest, self).__init__(*args, **kwargs)
|
||||
self.base_dir = os.path.join("test", self.base_dir)
|
||||
self.tags.append(TAGS["regression"])
|
||||
|
||||
@classmethod
|
||||
def get_sample(cls, sample_name):
|
||||
"Return the relative path of @sample_name"
|
||||
return os.path.join(cls.sample_dir, sample_name)
|
||||
|
||||
|
||||
## Architecture
|
||||
testset += RegressionTest(["x86/arch.py"], base_dir="arch",
|
||||
products=["x86_speed_reg_test.bin",
|
||||
@@ -242,6 +250,56 @@ testset += RegressionTest(["depgraph.py"], base_dir="analysis",
|
||||
(14, 1), (15, 1)))
|
||||
for fname in fnames])
|
||||
|
||||
## Degraph
|
||||
class TestDepgraph(RegressionTest):
|
||||
"""Dependency graph test"""
|
||||
example_depgraph = os.path.join("..", "..", "example", "symbol_exec",
|
||||
"depgraph.py")
|
||||
launcher = "dg_check.py"
|
||||
|
||||
|
||||
def __init__(self, test_nb, implicit, base_addr, target_addr, elements,
|
||||
*args, **kwargs):
|
||||
super(TestDepgraph, self).__init__([self.launcher],
|
||||
*args, **kwargs)
|
||||
self.base_dir = os.path.join(self.base_dir, "analysis")
|
||||
if implicit:
|
||||
expected_fname = "dg_test_%.2d_implicit_expected.json"
|
||||
self.tags.append(TAGS["z3"])
|
||||
else:
|
||||
expected_fname = "dg_test_%.2d_expected.json"
|
||||
|
||||
self.command_line += [
|
||||
expected_fname % test_nb,
|
||||
self.example_depgraph,
|
||||
"-m", "x86_32",
|
||||
"--json",
|
||||
self.get_sample(os.path.join("x86_32",
|
||||
"dg_test_%.2d.bin" % test_nb)),
|
||||
hex(base_addr),
|
||||
hex(target_addr)] + elements
|
||||
if implicit:
|
||||
self.command_line.append("-i")
|
||||
|
||||
# Depgraph emulation regression test
|
||||
test_args = [(0x401000, 0x40100d, ["EAX"]),
|
||||
(0x401000, 0x401011, ["EAX"]),
|
||||
(0x401000, 0x401018, ["EAX"]),
|
||||
(0x401000, 0x401011, ["EAX"]),
|
||||
(0x401000, 0x401011, ["EAX"]),
|
||||
(0x401000, 0x401016, ["EAX"]),
|
||||
(0x401000, 0x401017, ["EAX"]),
|
||||
(0x401000, 0x401012, ["EAX", "ECX"]),
|
||||
(0x401000, 0x401012, ["ECX"]),
|
||||
(0x401000, 0x40101f, ["EAX", "EBX"]),
|
||||
(0x401000, 0x401025, ["EAX", "EBX"]),
|
||||
]
|
||||
for i, test_args in enumerate(test_args):
|
||||
test_dg = SemanticTestAsm("x86_32", "PE", ["dg_test_%.2d" % i])
|
||||
testset += test_dg
|
||||
testset += TestDepgraph(i, False, *test_args, depends=[test_dg])
|
||||
testset += TestDepgraph(i, True, *test_args, depends=[test_dg])
|
||||
|
||||
## Jitter
|
||||
for script in ["jitload.py",
|
||||
]:
|
||||
|
||||
Reference in New Issue
Block a user