rr-debugger / rr-debugger/rr

Possible export the trace for taint analysis & symbolic execution?

Open
#2,462 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
10.7k
Forks
662
Avg merge
2d 3h
Merged PRs (30d)
2

Description

Hi, many binary analysis platforms perform taint analysis and symbolic execution base on execution trace. Usually we may use Pin or Valgrind to record binary's execution trace first, including instruction addresses, regs' values and memory change. It seems that rr also finish these work. I wonder how can I export the trace in a tradition format (since trace in rr has been compressed), and whether the trace recorded by rr can work with other analysis framework such as Trtion?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file, test, or entry point is named. Start by reviewing how rr records its compressed execution trace and whether an export path exists, then compare the requested instruction, register, and memory representation with Pin, Valgrind, and Trtion. Done means a concrete compatibility and export scope is defined.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.