to use this ,you have to put the CFG_pb2.py file,which from the mcsema/tools/mcsema_disass/ida7/ ,into the same dir with this script
type python show_cfg.py "xxx.cfg" "xxx.txt"
the first arg is the location of the cfg file you want to see, like "./maze.cfg"
the second arg is the location of the generated cfg details if the cfg file, like "./cfgdetails.txt"
* Try reworking Docker image
* Fix some old behavior for building abi libraries
I don't think the result is actually usable...
* Remove most Python2 references
Still left some references to python2 for helper scripts since they
aren't tested (afaik) in CI
* Fix CI
* Remove old CMakeLists.txt and remove support for old TRAILOFBITS_LIBRARIES method of building
* Update README
* API improvements. Must be used with the api_improvements branch of both Remill and McSema
fixes for x86 and running the lifted code with klee
* Update dockerfile to clone anvill
* update remill commit id
* Add python3 to dockerfile
* update python3
* disable abi script
* Updated cmake to find anvill
* Update main.cpp
* update find_package for anvill
* WIP:updated prebuild cfg
* update prebuild cfg files
* enable abi build for testsuite
* Fix memory leak
* install missing package for testcases
* frontend: Reflect cfg file changes in dyninst frontend.
* frontend: Update local files copyrights to reflect overall change to agplv3.
* fix failing testcases
* update test cfgs
* Fix test failure with local state pointer
* set the flag to use local state_ptr in default mode
Co-authored-by: kumarak <iit.akshay@gmail.com>
Co-authored-by: Lukas Korencik <xkorenc1@fi.muni.cz>
* Docs: Update links with the new organization name
* CI/Travis: Update remotes with the new organization name
* mcsema-disass: Update links with the new organization name
* Dockerfile: Update remotes with the new organization name
* Initial attempt at running Binary Ninja in CI instances
* Automatically update Binary Ninja to Dev Channel Latest
* is_update_installation_pending is a function
* More broadly applies lazy xref initialization to all initializations where the xref size is less than teh value size of the xref itself (pointer size, usually). Moves initialization of lazy xrefs into a new function, __mcsema_early_init, which guards itself against multiple executions. Makes sure that __mcsema_constructor calls __mcsema_early_init first. Finally, makes sure that all native-to-lifted entrypoints call __mcsema_early_init as well, as we have observed cases where the lifted binary contains weak implementations of c++ standard library functions, and these functions are called by native libraries initialized before the call to __mcsema_constructor, thereby resulting in re-entrancy issues.
* Update Function.cpp
* Make sure the __mcsema_early_init guard is in the module.
* Make sure the __mcsema_early_init guard is in the module.
* Fixes for __gmon_start__ and stuff.
* Minor fix
* Adds some symbols
* Minor fix for ida7
* Try to resolve things like calls through PLT thunks via xref entry lookups when a flow cross-reference is missing.
* Add a new CMake variable to enable/disable ABI libraries
By default, all ABI libraries are disabled.
To skip the 'Linux' ABI library:
cmake -DMCSEMA_DISABLED_ABI_LIBRARIES:STRING="Linux"
* Enable all ABI libraries in Travis
* CMake: Small refactor, style changes
* CMake: Fix the install target for Windows
* Windows: Add build instructions
* CMake: Add support for find_package(remill)
* CMake: Fail when the Python package can't be installed
* CMake: Fix the 'install' target on Linux
* CMake: Copy the Updated settings.cmake from Remill
* Travis: Update the build script
* Update the remill commit id
* CMake: Only use C++14 when compiling on Windows
* CMake: Fix the Python package installer
* Update the Windows documentation
* Update .remill_commit_id
Update to track the tip of master
* Change default install location to /usr/local
* Indentation fixes
* Fix CMake error introduced in d2582c7
This regression has been in the branch for a while, and it is caused
by the ABI library in mcsema/OS/Linux. The commit that introduced the
problem enabled an 'add_subdirectory' directive that was initially
commented out.
The problem with CMake was primarly due to the 'project(name BC)'
statement, trying to enable back the BC language (which was removed
due to broken Visual Studio support).
I've kept the add_subdirectory enabled, but only when building on
linux. CMake works fine now, but compilation fails due to missing
include headers referenced by ABI_libc.h (like ultrasound.h, which
appears to come from the kernel headers).
=======
alessandro@tob-ubuntu1804-remill:~/Projects/remill/tools/mcsema$ git bisect run /tmp/bisect.sh
running /tmp/bisect.sh
CMake has failed to configure the project!
Bisecting: 5 revisions left to test after this (roughly 3 steps)
[67164c725e] Update README.md
running /tmp/bisect.sh
CMake has successfully configured the project!
Bisecting: 2 revisions left to test after this (roughly 2 steps)
[d2582c7abd] Build Tests in Travis (#406)
running /tmp/bisect.sh
CMake has failed to configure the project!
Bisecting: 0 revisions left to test after this (roughly 1 step)
[a708bafc42] InlineAsm function type mismatch (#409)
running /tmp/bisect.sh
CMake has successfully configured the project!
d2582c7abd is the first bad commit
commit d2582c7abd
Author: artemdinaburg <artem@dinaburg.org>
Date: Tue May 22 21:13:43 2018 -0400
Build Tests in Travis (#406)
Always generate integration tests and then run the generated integration tests travis. We get around a lack of IDA by providing pre-built CFGs for examples.
Closes#407
:100644 100644 4154fe1e118fbfcee113 M CMakeLists.txt
:040000 040000 4bb5e0a484491dba1a1d M mcsema
:040000 040000 28398aa7462461062d36 M scripts
:040000 040000 97f8342b53c1487df961 M tests
bisect run success
* Fix for building 32-bit abi libraries
* Minor cmake tweaks
* Install 32-bit libraries on Travis-CI for Linux
* Fix installation of 32-bit libs to work around travis bug
* Handle C++ bitcode files
* Bump remill commit id
* Support bc file generation on ubuntu 14.04
* Bump the Remill commit ID.
Always generate integration tests and then run the generated integration tests travis. We get around a lack of IDA by providing pre-built CFGs for examples.
Closes#407
* Add initial support for --abi_library flags
* support for abi_library
* Remove the weak linkage for __mcsema_debug_get_reg_state.
* Fix num of agruments for __cxa_allocate_exception
* Remove --library flag and cleanup
* Don't reload/overwrite mcsema::gModule after loading in the protobuf.
* Use PrepareModuleDataLayout to avoid checks for __remill_basic_block function.
* Bump the remill commit id to support --abi_library flag
* Fix travis build failure
* Initialize the test log filename;
* trim newline char from the eof
* The test runner now knows about mcsema installations that aren't global
* We now check the output of the integration test suite in travis. This will cause travis to fail since we're currently failing tests
* Lots of README updates
* Use like 99% less sudo
* Better script to fix local IDA Python installations
* Support for building local installs in a virtualenv
* Remove the protobuf install that led people astray
* Fix incorrect stack var sizes
* Recover references to stack vars
* Fix requested changes
* Skip jump table entries in segment xrefs
* Fix sections being incorrectly considered code
* Ignore some symbols binja inserts
Binja inserts a few symbols it identifies that shouldn't be picked up as
globals, so skip these.
TODO: Look into a better way to identify globals than looking through
and filtering variable symbols
* Fix the links to our repos (#364)
* Bring back the mcsema-lift option for --list-supported (#365)
* Bring back the mcsema-lift option for --list-supported
* Discard changes to whitespace from last commit.
* Fix several xref warnings and issues
* Tail call targets now picked up as control flow xrefs
* Tail call targets added as successors
* Fix duplicate blocks being lifted as a result of tail calls being inlined
* Ignore duplicate xrefs as a result of how binja shows the instruction in IL
* Pick up missing xrefs when an instruction is expanded to multiple IL instructions
* Only classify the memory operand of a LOAD/STORE as a memory/displacement xref
* Fixes an issue where we assume that every symbol in the module passed to --library is external, whereas that's false. (#368)
* Bump up commit id to include support of atomic intrinsic (#367)
* Bump up commit id to include support of atomic intrinsic
* update remill commit id
* change cs_action to catch & cleanup type, not looking into catch types; (#371)
* Klee maze example (#369)
* In progress. Working on an example of using KLEE on a Maze, but with the maze program being compiled to x86, amd64, and aarch64.
* Making lots of progress on getting lifting and runnning an aarch64 maze program on amd64, but using --explicit_args. The key thing I'm working through right now is a jump offset table, but where the offset is a block pc, rather than a table base. Also adding various bits of code here and there to making runnning with klee more directly doable, and working on a debugging facility to track down when the emulated program counter gets out of sync with the original program.
* Fixed a subtle @PAGE and @PAGEOFF-related reference bug on AArch64. Partially disabled the special jump offset table handling I had in table.py, as it doesn't (yet) handle the shifted table values. However, I still have the code there, so that it can recognize that a basic block address is used as a possible offset, so that I can remove the block address as a reference, which permits a new heuristic on the C++ side to work. On the C++ side, when there's a jump instruction that isn't associated with a cross-reference flow, I try to auto-augment it with addition switch cases, targeting blocks with no predecessors (as present in the CFG). This seems to work reasonably well.
* Improved the scripts and updated the READMEs.
* Minor rephrase
* Minor rephrase
* Making the stack start a bit further back reduces things like KLEE messing up (#373)
* Changing indentation level, adding more logging statements to track what's going on.
* Manually merged in Kareem's changes before doing an auto merge.
* Got the Maze example working with binary ninja.
* Travis: Add LLVM35, do not use the Clang static analyzer when using LLVM < 4.0.0
* Travis: Use sudo when cleaning up between tests (see details).
Installing with 'sudo make install' leaves some files that are
owned by root in the build folders.
* Imported the new test framework
* Added the new Travis script
* Change Ubuntu version to Xenial (16.04)
* Travis: Various fixes; also enabled CMAKE_VERBOSE_MAKEFILE
* Travis: The test binaries were being excluded by gitignore. Add clang's static analysis
* Travis: the CC and CXX variables were not being set
* Travis: Explicitly set the compiler (CMAKE_CXX_COMPILER) along with the CXX env var
* Travis: Disable the XZ test (currently broken), show the clang static analyzer summary
* Travis: Move the CI shellscript to the script folder. Add src headers
* Travis: Test a known Remill version to avoid random breakages
* - Upgrade to official llvm 3.8
- remove boost
- unify all cmake files into a single cmake file
- use official protobuf
- start factoring out x86-specific stuff to eventually make an arm port easier
- simplify the CLI; now use mcsema-lift, with -arch, -os, -cfg, -entrypoint, and -o. No more having to specify the target triple.
- moves source code slightly closer to our style guide
Note:
- lifted bitcode is not quite right in some cases, so this isn't a stable branch!
- TODO: re-add test cases to discover source of stability problems.
* Some minor fixes, one to make sure xmm regs in the state struct are properly aligned
* Added missing std defs for option parsing. This makes /bin/ls work properly :-)
* Remove old cmake files
* Minor changes to get_cfg.py and raiseX86.cpp in relation to those changes. Those changes don't fix anything, the purpose was to make symbol names for things match between python and cpp. E.g. get_cfg would name things like dta_0xf00, sub_0xf00, ext_... And it seems that it was dta_ instead of data_ for a reallly flaky and dumb reason but oh well. I also fixed a subtle bug related to saving and restoring of callee saved registers on elf 64. I have not made related changes to elf 32 or pe 32/64, though those may be necessary.
* Minor fix
* Adding mcsema-disass, which is a nice wrapper around get_cfg.py.
* Working on readme and cleaning out (currently) unused stuff from the repo
* Renaming mc-sema dir to mcsema
* new travis file
* Updates to bootstrap and build process
* Minor bootstrap fixes
* Well, don't have windows working yet but this is kind of progress I think
* Travis should work now
* Updating protobuf-cmake files so we can generate a VS2015 solution
* Removing and adding some choco packages from README
* Bootstrap now builds protobuf and generates protobuf files
LLVM should now be built on Windows
* Adding Win32 specific compiler options
* Renamed ConstantInt to CreateConstantInt to satisfy MSVC
* Build Release LLVM to not have linking conflicts of MD vs MDd
* Added some missing instructions
* Adding changes to generate runtimes
* Windows bootstrap works.