When a function is relocated, each variable access offset (stored relative
to the function's entry point) is rebased by the relocation delta so that the
accesses keep pointing at the same absolute addresses. This was done as a
signed st64 subtraction:
st64 delta = addr - fcn->addr;
...
acc->offset -= delta;
Relocating to an address near the int64 boundary makes delta close to
INT64_MIN, and 'acc->offset - delta' then overflows st64. UBSAN aborts:
librz/arch/function.c:241:16: runtime error: signed integer overflow:
65568 - -9223372036854710512 cannot be represented in type 'long int'
(reproducible via test/unit/test_analysis_var, which relocates to
0x8000000000000010 and 0x7ffffffffffffe00).
Addresses and their differences are meant to wrap modulo 2^64, and the
offsets are only ever looked up as exact values (get_vars_used_at computes
op_addr - fcn->addr in ut64 as well), so perform the arithmetic in ut64.
delta becomes ut64 and the rebase is '(st64)((ut64)acc->offset - delta)';
the result is bit-identical for every non-overflowing case and well-defined
for the rest. The inst_vars rebase callback already subtracted in ut64.
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
|
||
|---|---|---|
| .builds | ||
| .github | ||
| .woodpecker | ||
| binrz | ||
| dist | ||
| doc | ||
| examples | ||
| librz | ||
| LICENSES | ||
| patches | ||
| subprojects | ||
| sys | ||
| test | ||
| .appveyor.yml | ||
| .clang-format | ||
| .dockerignore | ||
| .git-blame-ignore-revs | ||
| .gitattributes | ||
| .gitignore | ||
| .lgtm.yml | ||
| .prettierignore | ||
| .pylintrc | ||
| .travis.yml | ||
| AGENTS.md | ||
| BUILDING.md | ||
| CODE_OF_CONDUCT.md | ||
| codecov.yml | ||
| CODEOWNERS | ||
| CONTRIBUTING.md | ||
| COPYING | ||
| COPYING.LESSER | ||
| DEVELOPERS.md | ||
| Dockerfile | ||
| Doxyfile | ||
| meson.build | ||
| meson_options.txt | ||
| README.md | ||
| REUSE.toml | ||
| SECURITY.md | ||
| snapcraft.yaml | ||
| travis-extract-var.sh | ||
| travis-script | ||
Rizin
Rizin is a reverse engineering framework, born as a fork of the radare2, with a focus on usability, features and cleanliness.
Rizin is portable and it can be used to analyze binaries, disassemble code, debug programs, as a forensic tool, as a scriptable command-line hexadecimal editor able to open disk files, and much more!
To learn more on Rizin you may want to read the official Rizin book.
How to install
Look at install instructions on our web page.
How to build
Use meson to compile and install Rizin. Please make sure to get an updated
meson (e.g. get it with pip install meson if your system does not provide
one that is at least version 0.55.0).
Clone this repository:
$ git clone https://github.com/rizinorg/rizin
Then compile and install with:
$ meson setup build
$ meson compile -C build
$ sudo meson install -C build
Now you can use rizin:
$ rizin
-- Thank you for using rizin. Have a nice night!
[0x00000000]>
To uninstall rizin, execute sudo ninja -C build uninstall.
Please have a look at BUILDING.md for more information about building Rizin.
Contributing
We very much welcome any kind of contributions, from typos, to documentation, to refactoring, up to completely new features you may think of. Before contributing, we would like you to read the file CONTRIBUTING.md, so that we can all be on the same page.
Tests
Look at test/README.md.
Supported features
Supported Operating Systems
Windows 7 and higher, Apple macOS/iOS/iPadOS, GNU/Linux, [Dragonfly|Net|Free|Open]BSD, Android, QNX, Solaris/Illumos, Haiku, GNU/Darwin, GNU/Hurd.
Supported Architectures
i386, x86-64, ARM/ARM64, RISC-V, PowerPC, MIPS, AVR, SPARC, System Z (S390), SuperH, m68k, m680x, XAP, XCore, CR16, HPPA, ARC, Blackfin, Z80, H8/300, Renesas (V810, V850, RL78), CRIS, XAP, PIC, LM32, 8051, 6502, i4004, i8080, Propeller, Tricore, CHIP-8, LH5801, T8200, GameBoy, SNES, SPC700, MSP430, Xtensa, NIOS II, TMS320 (c54x, c55x, c55+, c64x), Hexagon, DCPU16, LANAI, MCORE, mcs96, RSP, C-SKY(MCore), VAX, AMD Am29000.
There is also support for the following bytecode formats:
Dalvik, EBC, Java, Lua, Python, WebAssembly, Brainfuck, Malbolge
Supported File Formats
ELF, Mach-O, Fatmach-O, PE, PE+, MZ, COFF, OMF, NE, LE, LX, TE, XBE, BIOS/UEFI, Dyldcache, DEX, ART, CGC, ELF, Java class, Android boot image, Plan9 executable, ZIMG, MBN/SBL bootloader, ELF coredump, MDMP (Windows minidump), DMP (Windows pagedump), WASM (WebAssembly binary), Commodore VICE emulator, QNX, Game Boy (Advance), Nintendo DS ROMs and Nintendo 3DS FIRMs.
Tools
Apart from the main tool rizin, there are also other tools tailored for specific purposes and
useful for shell scripting or as separate standalone tools:
rz-bin- provides all kind of information about binary formatsrz-ar- list and extract members from static archives (.a and .lib)rz-asm- a command-line assembler and disassemblersrz-diff- a tool to compare two binaries as raw data or analyzed executablesrz-hash- allows to calculate different hashes or even encrypt datarz-gg- a small "eggs" code generator useful for exploitation purposesrz-find- binary analog offindtool, allowing to search patterns and bit masksrz-sign- tool to create, convert and parse FLIRT signaturesrz-ax- a calculator and number format converterrz-run- a tool that allows to specify running environment and arguments for debugged file
Scripting
We provide a way to interact with Rizin from Python, Haskell, OCaml, Ruby, Rust, and Go languages through rzpipe. Other languages although not currently supported could be easily added.
Community
Our website and blog: https://www.rizin.re/
Join our Mattermost community to discuss Rizin, its development, and general topics related to the project.
We also provide the following partial bridges to other messaging platforms: