Repository navigation
Conversation
tests/test_pe_coff_symbols.py built its own input: _coff_symbol struct.packed 18-byte symbol records, and _make_pe assembled a PE with object.__new__ and SimpleNamespace stand-ins for pefile's file header, section list and export directory. The table it built starts at file offset 0, the image has one section, there is no string table and there are no auxiliary records; of the 110 PE images angr/binaries tracks, none of the 24 that declare symbols puts its table at offset 0. So both tests passed against a shape no fixture presents, and neither could reach the paths a real image takes. The IndexError this walk raises on a symbol table numbered for some other section list was found by loading real images, not by these tests. Read the same behaviour off committed fixtures instead. tests/x86_64/cfg_0_pe is a MinGW image whose 1341 symbol records mix function and object types with external and local definitions, and whose walk visits 987 of them and takes 380 names out of the string table. tests/x86/windows/packed_pe32.exe keeps the unpacked file's symbol-table pointer and count in a file 0xbe00 bytes shorter, so its table ends past the end of the file and none of it is loaded. tests/x86_64/windows/msvcr120.dll exports 1925 symbols with no symbol table to type them. coff_export_types.dll, added in the angr/binaries pull request this depends on, is the only image carrying both an export directory and a symbol table, which is what the export typing needs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS What each version of Before — the two tests read a table the test packed itself, and no record in it takes its name from the string table, so breaking that path changes nothing. All 23 readable symbol tables in angr/binaries' PE images do take at least one name from it, tests/test_pe_coff_symbols.py at cle master 7c5e1a2After — the five tests read committed fixtures, so a broken string table fails two of them; the storage-class filter is the one thing the manufactured table could check and the fixtures cannot, because no image under tests/test_pe_coff_symbols.py with this change |
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Validation record for head Every row below was measured with the tree at that head.
Caveats: the new fixture |
|
Corpus decompilation diffs can be found at angr/dec-snapshots@master...angr/cle_846 |
|
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS Closing this pull request under the campaign scope: it does not establish qualifying impact on binaries recorded by our sweeps. We are withdrawing it from this campaign. The change is confined to |
THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS
Problem
tests/test_pe_coff_symbols.pybuilds the image it tests._coff_symbolpacks 18-byte COFF symbol records and_make_peassembles a PE out of nothing:The symbol table starts at file offset 0, the image has one section, there is no string table and there are no auxiliary records; of the 110 PE images angr/binaries tracks, none of the 24 that declare symbols puts its table at offset 0. Break the reading of names too long for the eight-byte field -- 380 of the records in
tests/x86_64/cfg_0_pe, which the new tests load, take that path -- and both tests still pass.Root cause
PE._load_symbols_from_coff_headerwalks records that may name any of the image's sections, may take their name from the string table behind the table, and may be followed by auxiliary records. The mock reaches none of that, so it cannot reach the mistakes either: theIndexErrorthis walk raises on a table numbered for some other section list, which #832 guards, was found by loading real images.Fix
Read the same behaviour off committed fixtures.
tests/x86_64/cfg_0_peis a MinGW image whose 1341 records mix function and object types with external and local definitions; the walk visits 987 of them and takes 380 names out of the string table.tests/x86/windows/packed_pe32.exekeeps the unpacked file's symbol-table pointer and count in a file 0xbe00 bytes shorter, so its table ends past the end of the file and none of it loads.tests/x86_64/windows/msvcr120.dllexports 1925 symbols with no table to type them.coff_export_types.dll, added in angr/binaries#237, is the only image that carries both an export directory and a symbol table.One assertion does not survive the move: that a local definition lends no type to an export. No image under
tests/puts an export at an address whose only COFF definition is local, so that one was only assertable against a manufactured table, and the map it inspected is internal to the loader.Testing
Five tests replace the two. They are not vacuous, and the trade is visible: with name reading from the string table broken, the old file passed 2 of 2 and the new one fails 2 of 5; with the walk removed altogether, the old file fails 1 of 2 and the new one 2 of 5. #832 changes the same file and conflicts with this branch in it, so whichever lands first, the other needs a rebase. The fixture comes from angr/binaries#237
Validation: #846 (comment)
🤖 Generated with Claude Code
session: sharpen