From f073540795b917be5068e119a0888814a767b019 Mon Sep 17 00:00:00 2001 From: "Liu.andrew.x@gmail.com" Date: Fri, 21 Aug 2015 16:22:19 +0000 Subject: [PATCH] Add check for Linux minidump ending on bad write for exploitability rating. If a crash occurred as a result to a write to unwritable memory, it is reason to suggest exploitability. The processor checks for a bad write by disassembling the command that caused the crash by piping the raw bytes near the instruction pointer through objdump. This allows the processor to see if the instruction that caused the crash is a write to memory and where the target of the address is located. R=ivanpe@chromium.org Review URL: https://codereview.chromium.org/1273823004 git-svn-id: http://google-breakpad.googlecode.com/svn/trunk@1497 4c0a9323-5329-0410-9bdc-e9ce6186880e --- .../processor/exploitability.h | 9 + .../processor/minidump_processor.h | 6 + src/processor/exploitability.cc | 11 +- src/processor/exploitability_linux.cc | 382 +++++++++++++++++- src/processor/exploitability_linux.h | 51 ++- src/processor/exploitability_unittest.cc | 120 ++++++ src/processor/minidump_processor.cc | 13 +- .../linux_jmp_to_module_not_exe_region.dmp | Bin 0 -> 44936 bytes .../linux_write_to_nonwritable_module.dmp | Bin 0 -> 44944 bytes ...linux_write_to_nonwritable_region_math.dmp | Bin 0 -> 40848 bytes .../linux_write_to_outside_module.dmp | Bin 0 -> 44944 bytes ...linux_write_to_outside_module_via_math.dmp | Bin 0 -> 44944 bytes .../testdata/linux_write_to_under_4k.dmp | Bin 0 -> 44944 bytes 13 files changed, 584 insertions(+), 8 deletions(-) create mode 100644 src/processor/testdata/linux_jmp_to_module_not_exe_region.dmp create mode 100644 src/processor/testdata/linux_write_to_nonwritable_module.dmp create mode 100644 src/processor/testdata/linux_write_to_nonwritable_region_math.dmp create mode 100644 src/processor/testdata/linux_write_to_outside_module.dmp create mode 100644 src/processor/testdata/linux_write_to_outside_module_via_math.dmp create mode 100644 src/processor/testdata/linux_write_to_under_4k.dmp diff --git a/src/google_breakpad/processor/exploitability.h b/src/google_breakpad/processor/exploitability.h index 67255a3a..014413c9 100644 --- a/src/google_breakpad/processor/exploitability.h +++ b/src/google_breakpad/processor/exploitability.h @@ -53,6 +53,15 @@ class Exploitability { static Exploitability *ExploitabilityForPlatform(Minidump *dump, ProcessState *process_state); + // The boolean parameter signals whether the exploitability engine is + // enabled to call out to objdump for disassembly. This is disabled by + // default. It is used to check the identity of the instruction that + // caused the program to crash. This should not be enabled if there are + // portability concerns. + static Exploitability *ExploitabilityForPlatform(Minidump *dump, + ProcessState *process_state, + bool enable_objdump); + ExploitabilityRating CheckExploitability(); bool AddressIsAscii(uint64_t); diff --git a/src/google_breakpad/processor/minidump_processor.h b/src/google_breakpad/processor/minidump_processor.h index d2c94e2b..387115ef 100644 --- a/src/google_breakpad/processor/minidump_processor.h +++ b/src/google_breakpad/processor/minidump_processor.h @@ -125,6 +125,8 @@ class MinidumpProcessor { // does not exist or cannot be determined. static string GetAssertion(Minidump* dump); + void set_enable_objdump(bool enabled) { enable_objdump_ = enabled; } + private: StackFrameSymbolizer* frame_symbolizer_; // Indicate whether resolver_helper_ is owned by this instance. @@ -134,6 +136,10 @@ class MinidumpProcessor { // guess how likely it is that the crash represents an exploitable // memory corruption issue. bool enable_exploitability_; + + // This flag permits the exploitability scanner to shell out to objdump + // for purposes of disassembly. + bool enable_objdump_; }; } // namespace google_breakpad diff --git a/src/processor/exploitability.cc b/src/processor/exploitability.cc index 384c499c..6ee1e962 100644 --- a/src/processor/exploitability.cc +++ b/src/processor/exploitability.cc @@ -58,6 +58,13 @@ ExploitabilityRating Exploitability::CheckExploitability() { Exploitability *Exploitability::ExploitabilityForPlatform( Minidump *dump, ProcessState *process_state) { + return ExploitabilityForPlatform(dump, process_state, false); +} + +Exploitability *Exploitability::ExploitabilityForPlatform( + Minidump *dump, + ProcessState *process_state, + bool enable_objdump) { Exploitability *platform_exploitability = NULL; MinidumpSystemInfo *minidump_system_info = dump->GetSystemInfo(); if (!minidump_system_info) @@ -75,7 +82,9 @@ Exploitability *Exploitability::ExploitabilityForPlatform( break; } case MD_OS_LINUX: { - platform_exploitability = new ExploitabilityLinux(dump, process_state); + platform_exploitability = new ExploitabilityLinux(dump, + process_state, + enable_objdump); break; } case MD_OS_MAC_OS_X: diff --git a/src/processor/exploitability_linux.cc b/src/processor/exploitability_linux.cc index 46cad318..a196da79 100644 --- a/src/processor/exploitability_linux.cc +++ b/src/processor/exploitability_linux.cc @@ -36,6 +36,16 @@ #include "processor/exploitability_linux.h" +#ifndef _WIN32 +#include +#include +#include +#include + +#include +#include +#endif // _WIN32 + #include "google_breakpad/common/minidump_exception_linux.h" #include "google_breakpad/processor/call_stack.h" #include "google_breakpad/processor/process_state.h" @@ -53,13 +63,26 @@ const char kStackCheckFailureFunction[] = "__stack_chk_fail"; // can determine that the call would overflow the target buffer. const char kBoundsCheckFailureFunction[] = "__chk_fail"; +#ifndef _WIN32 +const unsigned int MAX_INSTRUCTION_LEN = 15; +const unsigned int MAX_OBJDUMP_BUFFER_LEN = 4096; +#endif // _WIN32 + } // namespace namespace google_breakpad { ExploitabilityLinux::ExploitabilityLinux(Minidump *dump, ProcessState *process_state) - : Exploitability(dump, process_state) { } + : Exploitability(dump, process_state), + enable_objdump_(false) { } + +ExploitabilityLinux::ExploitabilityLinux(Minidump *dump, + ProcessState *process_state, + bool enable_objdump) + : Exploitability(dump, process_state), + enable_objdump_(enable_objdump) { } + ExploitabilityRating ExploitabilityLinux::CheckPlatformExploitability() { // Check the crashing thread for functions suggesting a buffer overflow or @@ -122,18 +145,373 @@ ExploitabilityRating ExploitabilityLinux::CheckPlatformExploitability() { return EXPLOITABILITY_ERR_PROCESSING; } - // Checking for the instruction pointer in a valid instruction region. + // Checking for the instruction pointer in a valid instruction region, + // a misplaced stack pointer, and an executable stack or heap. if (!this->InstructionPointerInCode(instruction_ptr) || this->StackPointerOffStack(stack_ptr) || this->ExecutableStackOrHeap()) { return EXPLOITABILITY_HIGH; } + // Check for write to read only memory or invalid memory, shelling out + // to objdump is enabled. + if (enable_objdump_ && this->EndedOnIllegalWrite(instruction_ptr)) { + return EXPLOITABILITY_HIGH; + } + // There was no strong evidence suggesting exploitability, but the minidump // does not appear totally benign either. return EXPLOITABILITY_INTERESTING; } +bool ExploitabilityLinux::EndedOnIllegalWrite(uint64_t instruction_ptr) { +#ifdef _WIN32 + BPLOG(INFO) << "MinGW does not support fork and exec. Terminating method."; +#else + // Get memory region containing instruction pointer. + MinidumpMemoryList *memory_list = dump_->GetMemoryList(); + MinidumpMemoryRegion *memory_region = + memory_list ? + memory_list->GetMemoryRegionForAddress(instruction_ptr) : NULL; + if (!memory_region) { + BPLOG(INFO) << "No memory region around instruction pointer."; + return false; + } + + // Get exception data to find architecture. + string architecture = ""; + MinidumpException *exception = dump_->GetException(); + // This should never evaluate to true, since this should not be reachable + // without checking for exception data earlier. + if (!exception) { + BPLOG(INFO) << "No exception data."; + return false; + } + const MDRawExceptionStream *raw_exception_stream = exception->exception(); + const MinidumpContext *context = exception->GetContext(); + // This should not evaluate to true, for the same reason mentioned above. + if (!raw_exception_stream || !context) { + BPLOG(INFO) << "No exception or architecture data."; + return false; + } + // Check architecture and set architecture variable to corresponding flag + // in objdump. + switch (context->GetContextCPU()) { + case MD_CONTEXT_X86: + architecture = "i386"; + break; + case MD_CONTEXT_AMD64: + architecture = "i386:x86-64"; + break; + default: + // Unsupported architecture. Note that ARM architectures are not + // supported because objdump does not support ARM. + return false; + break; + } + + // Get memory region around instruction pointer and the number of bytes + // before and after the instruction pointer in the memory region. + const uint8_t *raw_memory = memory_region->GetMemory(); + const uint64_t base = memory_region->GetBase(); + if (base > instruction_ptr) { + BPLOG(ERROR) << "Memory region base value exceeds instruction pointer."; + return false; + } + const uint64_t offset = instruction_ptr - base; + if (memory_region->GetSize() < MAX_INSTRUCTION_LEN + offset) { + BPLOG(INFO) << "Not enough bytes left to guarantee complete instruction."; + return false; + } + + // Convert bytes into objdump output. + char objdump_output_buffer[MAX_OBJDUMP_BUFFER_LEN] = {0}; + DisassembleBytes(architecture, + raw_memory + offset, + MAX_OBJDUMP_BUFFER_LEN, + objdump_output_buffer); + + // Put buffer data into stream to output line-by-line. + std::stringstream objdump_stream; + objdump_stream.str(string(objdump_output_buffer)); + string line; + + // Pipe each output line into the string until the string contains + // the first instruction from objdump. + // Loop until the line shows the first instruction or there are no lines left. + do { + if (!getline(objdump_stream, line)) { + BPLOG(INFO) << "Objdump instructions not found"; + return false; + } + } while (line.find("0:") == string::npos); + // This first instruction contains the above substring. + + // Convert objdump instruction line into the operation and operands. + string instruction = ""; + string dest = ""; + string src = ""; + TokenizeObjdumpInstruction(line, &instruction, &dest, &src); + + // Check if the operation is a write to memory. First, the instruction + // must one that can write to memory. Second, the write destination + // must be a spot in memory rather than a register. Since there are no + // symbols from objdump, the destination will be enclosed by brackets. + if (dest.size() > 2 && dest.at(0) == '[' && dest.at(dest.size() - 1) == ']' && + (!instruction.compare("mov") || !instruction.compare("inc") || + !instruction.compare("dec") || !instruction.compare("and") || + !instruction.compare("or") || !instruction.compare("xor") || + !instruction.compare("not") || !instruction.compare("neg") || + !instruction.compare("add") || !instruction.compare("sub") || + !instruction.compare("shl") || !instruction.compare("shr"))) { + // Strip away enclosing brackets from the destination address. + dest = dest.substr(1, dest.size() - 2); + uint64_t write_address = 0; + CalculateAddress(dest, *context, &write_address); + + // If the program crashed as a result of a write, the destination of + // the write must have been an address that did not permit writing. + // However, if the address is under 4k, due to program protections, + // the crash does not suggest exploitability for writes with such a + // low target address. + return write_address > 4096; + } +#endif // _WIN32 + return false; +} + +#ifndef _WIN32 +bool ExploitabilityLinux::CalculateAddress(const string &address_expression, + const DumpContext &context, + uint64_t *write_address) { + // The destination should be the format reg+a or reg-a, where reg + // is a register and a is a hexadecimal constant. Although more complex + // expressions can make valid instructions, objdump's disassembly outputs + // it in this simpler format. + // TODO(liuandrew): Handle more complex formats, should they arise. + + if (!write_address) { + BPLOG(ERROR) << "Null parameter."; + return false; + } + + // Clone parameter into a non-const string. + string expression = address_expression; + + // Parse out the constant that is added to the address (if it exists). + size_t delim = expression.find('+'); + bool positive_add_constant = true; + // Check if constant is subtracted instead of added. + if (delim == string::npos) { + positive_add_constant = false; + delim = expression.find('-'); + } + uint32_t add_constant = 0; + // Save constant and remove it from the expression. + if (delim != string::npos) { + if (!sscanf(expression.substr(delim + 1).c_str(), "%x", &add_constant)) { + BPLOG(ERROR) << "Failed to scan constant."; + return false; + } + expression = expression.substr(0, delim); + } + + // Set the the write address to the corresponding register. + // TODO(liuandrew): Add support for partial registers, such as + // the rax/eax/ax/ah/al chain. + switch (context.GetContextCPU()) { + case MD_CONTEXT_X86: + if (!expression.compare("eax")) { + *write_address = context.GetContextX86()->eax; + } else if (!expression.compare("ebx")) { + *write_address = context.GetContextX86()->ebx; + } else if (!expression.compare("ecx")) { + *write_address = context.GetContextX86()->ecx; + } else if (!expression.compare("edx")) { + *write_address = context.GetContextX86()->edx; + } else if (!expression.compare("edi")) { + *write_address = context.GetContextX86()->edi; + } else if (!expression.compare("esi")) { + *write_address = context.GetContextX86()->esi; + } else if (!expression.compare("ebp")) { + *write_address = context.GetContextX86()->ebp; + } else if (!expression.compare("esp")) { + *write_address = context.GetContextX86()->esp; + } else if (!expression.compare("eip")) { + *write_address = context.GetContextX86()->eip; + } else { + BPLOG(ERROR) << "Unsupported register"; + return false; + } + break; + case MD_CONTEXT_AMD64: + if (!expression.compare("rax")) { + *write_address = context.GetContextAMD64()->rax; + } else if (!expression.compare("rbx")) { + *write_address = context.GetContextAMD64()->rbx; + } else if (!expression.compare("rcx")) { + *write_address = context.GetContextAMD64()->rcx; + } else if (!expression.compare("rdx")) { + *write_address = context.GetContextAMD64()->rdx; + } else if (!expression.compare("rdi")) { + *write_address = context.GetContextAMD64()->rdi; + } else if (!expression.compare("rsi")) { + *write_address = context.GetContextAMD64()->rsi; + } else if (!expression.compare("rbp")) { + *write_address = context.GetContextAMD64()->rbp; + } else if (!expression.compare("rsp")) { + *write_address = context.GetContextAMD64()->rsp; + } else if (!expression.compare("rip")) { + *write_address = context.GetContextAMD64()->rip; + } else if (!expression.compare("r8")) { + *write_address = context.GetContextAMD64()->r8; + } else if (!expression.compare("r9")) { + *write_address = context.GetContextAMD64()->r9; + } else if (!expression.compare("r10")) { + *write_address = context.GetContextAMD64()->r10; + } else if (!expression.compare("r11")) { + *write_address = context.GetContextAMD64()->r11; + } else if (!expression.compare("r12")) { + *write_address = context.GetContextAMD64()->r12; + } else if (!expression.compare("r13")) { + *write_address = context.GetContextAMD64()->r13; + } else if (!expression.compare("r14")) { + *write_address = context.GetContextAMD64()->r14; + } else if (!expression.compare("r15")) { + *write_address = context.GetContextAMD64()->r15; + } else { + BPLOG(ERROR) << "Unsupported register"; + return false; + } + break; + default: + // This should not occur since the same switch condition + // should have terminated this method. + return false; + break; + } + + // Add or subtract constant from write address (if applicable). + *write_address = + positive_add_constant ? + *write_address + add_constant : *write_address - add_constant; + + return true; +} + +bool ExploitabilityLinux::TokenizeObjdumpInstruction(const string &line, + string *operation, + string *dest, + string *src) { + if (!operation || !dest || !src) { + BPLOG(ERROR) << "Null parameters passed."; + return false; + } + + // Set all pointer values to empty strings. + *operation = ""; + *dest = ""; + *src = ""; + + // Tokenize the objdump line. + vector tokens; + std::istringstream line_stream(line); + copy(std::istream_iterator(line_stream), + std::istream_iterator(), + std::back_inserter(tokens)); + + // Regex for the data in hex form. Each byte is two hex digits. + regex_t regex; + regcomp(®ex, "^[[:xdigit:]]{2}$", REG_EXTENDED | REG_NOSUB); + + // Find and set the location of the operator. The operator appears + // directly after the chain of bytes that define the instruction. The + // operands will be the last token, given that the instruction has operands. + // If not, the operator is the last token. The loop skips the first token + // because the first token is the instruction number (namely "0:"). + string operands = ""; + for (size_t i = 1; i < tokens.size(); i++) { + // Check if current token no longer is in byte format. + if (regexec(®ex, tokens[i].c_str(), 0, NULL, 0)) { + // instruction = tokens[i]; + *operation = tokens[i]; + // If the operator is the last token, there are no operands. + if (i != tokens.size() - 1) { + operands = tokens[tokens.size() - 1]; + } + break; + } + } + regfree(®ex); + + if (operation->empty()) { + BPLOG(ERROR) << "Failed to parse out operation from objdump instruction."; + return false; + } + + // Split operands into source and destination (if applicable). + if (!operands.empty()) { + size_t delim = operands.find(','); + if (delim == string::npos) { + *dest = operands; + } else { + *dest = operands.substr(0, delim); + *src = operands.substr(delim + 1); + } + } + return true; +} + +bool ExploitabilityLinux::DisassembleBytes(const string &architecture, + const uint8_t *raw_bytes, + const unsigned int buffer_len, + char *objdump_output_buffer) { + if (!raw_bytes || !objdump_output_buffer) { + BPLOG(ERROR) << "Bad input parameters."; + return false; + } + + // Write raw bytes around instruction pointer to a temporary file to + // pass as an argument to objdump. + char raw_bytes_tmpfile[] = "/tmp/breakpad_mem_region-raw_bytes-XXXXXX"; + int raw_bytes_fd = mkstemp(raw_bytes_tmpfile); + if (raw_bytes_fd < 0) { + BPLOG(ERROR) << "Failed to create tempfile."; + unlink(raw_bytes_tmpfile); + return false; + } + if (write(raw_bytes_fd, raw_bytes, MAX_INSTRUCTION_LEN) + != MAX_INSTRUCTION_LEN) { + BPLOG(ERROR) << "Writing of raw bytes failed."; + unlink(raw_bytes_tmpfile); + return false; + } + + char cmd[1024] = {0}; + snprintf(cmd, + 1024, + "objdump -D -b binary -M intel -m %s %s", + architecture.c_str(), + raw_bytes_tmpfile); + FILE *objdump_fp = popen(cmd, "r"); + if (!objdump_fp) { + fclose(objdump_fp); + unlink(raw_bytes_tmpfile); + BPLOG(ERROR) << "Failed to call objdump."; + return false; + } + if (fread(objdump_output_buffer, 1, buffer_len, objdump_fp) <= 0) { + fclose(objdump_fp); + unlink(raw_bytes_tmpfile); + BPLOG(ERROR) << "Failed to read objdump output."; + return false; + } + fclose(objdump_fp); + unlink(raw_bytes_tmpfile); + return true; +} +#endif // _WIN32 + bool ExploitabilityLinux::StackPointerOffStack(uint64_t stack_ptr) { MinidumpLinuxMapsList *linux_maps_list = dump_->GetLinuxMapsList(); // Inconclusive if there are no mappings available. diff --git a/src/processor/exploitability_linux.h b/src/processor/exploitability_linux.h index 857185b4..93c5082f 100644 --- a/src/processor/exploitability_linux.h +++ b/src/processor/exploitability_linux.h @@ -37,7 +37,6 @@ #ifndef GOOGLE_BREAKPAD_PROCESSOR_EXPLOITABILITY_LINUX_H_ #define GOOGLE_BREAKPAD_PROCESSOR_EXPLOITABILITY_LINUX_H_ -#include "common/scoped_ptr.h" #include "google_breakpad/common/breakpad_types.h" #include "google_breakpad/processor/exploitability.h" @@ -48,9 +47,21 @@ class ExploitabilityLinux : public Exploitability { ExploitabilityLinux(Minidump *dump, ProcessState *process_state); + // Parameters are the minidump to analyze, the object representing process + // state, and whether to enable objdump disassembly. + // Enabling objdump will allow exploitability analysis to call out to + // objdump for diassembly. It is used to check the identity of the + // instruction that caused the program to crash. If there are any + // portability concerns, this should not be enabled. + ExploitabilityLinux(Minidump *dump, + ProcessState *process_state, + bool enable_objdump); + virtual ExploitabilityRating CheckPlatformExploitability(); private: + friend class ExploitabilityLinuxTest; + // Takes the address of the instruction pointer and returns // whether the instruction pointer lies in a valid instruction region. bool InstructionPointerInCode(uint64_t instruction_ptr); @@ -59,6 +70,40 @@ class ExploitabilityLinux : public Exploitability { // minidump and reports whether the exception suggests no exploitability. bool BenignCrashTrigger(const MDRawExceptionStream *raw_exception_stream); + // This method checks if the crash occurred during a write to read-only or + // invalid memory. It does so by checking if the instruction at the + // instruction pointer is a write instruction, and if the target of the + // instruction is at a spot in memory that prohibits writes. + bool EndedOnIllegalWrite(uint64_t instruction_ptr); + +#ifndef _WIN32 + // Disassembles raw bytes via objdump and pipes the output into the provided + // buffer, given the desired architecture, the file from which objdump will + // read, and the buffer length. The method returns whether the disassembly + // was a success, and the caller owns all pointers. + static bool DisassembleBytes(const string &architecture, + const uint8_t *raw_bytes, + const unsigned int MAX_OBJDUMP_BUFFER_LEN, + char *objdump_output_buffer); + + // Tokenizes out the operation and operands from a line of instruction + // disassembled by objdump. This method modifies the pointers to match the + // tokens of the instruction, and returns if the tokenizing was a success. + // The caller owns all pointers. + static bool TokenizeObjdumpInstruction(const string &line, + string *operation, + string *dest, + string *src); + + // Calculates the effective address of an expression in the form reg+a or + // reg-a, where 'reg' is a register and 'a' is a constant, and writes the + // result in the pointer. The method returns whether the calculation was + // a success. The caller owns the pointer. + static bool CalculateAddress(const string &address_expression, + const DumpContext &context, + uint64_t *write_address); +#endif // _WIN32 + // Checks if the stack pointer points to a memory mapping that is not // labelled as the stack. bool StackPointerOffStack(uint64_t stack_ptr); @@ -66,6 +111,10 @@ class ExploitabilityLinux : public Exploitability { // Checks if the stack or heap are marked executable according // to the memory mappings. bool ExecutableStackOrHeap(); + + // Whether this exploitability engine is permitted to shell out to objdump + // to disassemble raw bytes. + bool enable_objdump_; }; } // namespace google_breakpad diff --git a/src/processor/exploitability_unittest.cc b/src/processor/exploitability_unittest.cc index db7f1cb0..700f9e58 100644 --- a/src/processor/exploitability_unittest.cc +++ b/src/processor/exploitability_unittest.cc @@ -37,11 +37,41 @@ #include "google_breakpad/processor/basic_source_line_resolver.h" #include "google_breakpad/processor/minidump_processor.h" #include "google_breakpad/processor/process_state.h" +#ifndef _WIN32 +#include "processor/exploitability_linux.h" +#endif // _WIN32 #include "processor/simple_symbol_supplier.h" +#ifndef _WIN32 +namespace google_breakpad { + +class ExploitabilityLinuxTest : public ExploitabilityLinux { + public: + using ExploitabilityLinux::DisassembleBytes; + using ExploitabilityLinux::TokenizeObjdumpInstruction; + using ExploitabilityLinux::CalculateAddress; +}; + +class ExploitabilityLinuxTestMinidumpContext : public MinidumpContext { + public: + explicit ExploitabilityLinuxTestMinidumpContext( + const MDRawContextAMD64& context) : MinidumpContext(NULL) { + valid_ = true; + SetContextAMD64(new MDRawContextAMD64(context)); + SetContextFlags(MD_CONTEXT_AMD64); + } +}; + +} // namespace google_breakpad +#endif // _WIN32 + namespace { using google_breakpad::BasicSourceLineResolver; +#ifndef _WIN32 +using google_breakpad::ExploitabilityLinuxTest; +using google_breakpad::ExploitabilityLinuxTestMinidumpContext; +#endif // _WIN32 using google_breakpad::MinidumpProcessor; using google_breakpad::ProcessState; using google_breakpad::SimpleSymbolSupplier; @@ -59,6 +89,7 @@ ExploitabilityFor(const string& filename) { SimpleSymbolSupplier supplier(TestDataDir() + "/symbols"); BasicSourceLineResolver resolver; MinidumpProcessor processor(&supplier, &resolver, true); + processor.set_enable_objdump(true); ProcessState state; string minidump_file = TestDataDir() + "/" + filename; @@ -135,6 +166,95 @@ TEST(ExploitabilityTest, TestLinuxEngine) { ExploitabilityFor("linux_executable_stack.dmp")); ASSERT_EQ(google_breakpad::EXPLOITABILITY_HIGH, ExploitabilityFor("linux_executable_heap.dmp")); + ASSERT_EQ(google_breakpad::EXPLOITABILITY_HIGH, + ExploitabilityFor("linux_jmp_to_module_not_exe_region.dmp")); +#ifndef _WIN32 + ASSERT_EQ(google_breakpad::EXPLOITABILITY_HIGH, + ExploitabilityFor("linux_write_to_nonwritable_module.dmp")); + ASSERT_EQ(google_breakpad::EXPLOITABILITY_HIGH, + ExploitabilityFor("linux_write_to_nonwritable_region_math.dmp")); + ASSERT_EQ(google_breakpad::EXPLOITABILITY_HIGH, + ExploitabilityFor("linux_write_to_outside_module.dmp")); + ASSERT_EQ(google_breakpad::EXPLOITABILITY_HIGH, + ExploitabilityFor("linux_write_to_outside_module_via_math.dmp")); + ASSERT_EQ(google_breakpad::EXPLOITABILITY_INTERESTING, + ExploitabilityFor("linux_write_to_under_4k.dmp")); +#endif // _WIN32 +} +#ifndef _WIN32 +TEST(ExploitabilityLinuxUtilsTest, DisassembleBytesTest) { + ASSERT_FALSE(ExploitabilityLinuxTest::DisassembleBytes("", NULL, 5, NULL)); + uint8_t bytes[6] = {0xc7, 0x0, 0x5, 0x0, 0x0, 0x0}; + char buffer[1024] = {0}; + ASSERT_TRUE(ExploitabilityLinuxTest::DisassembleBytes("i386:x86-64", + bytes, + 1024, + buffer)); + std::stringstream objdump_stream; + objdump_stream.str(string(buffer)); + string line = ""; + while ((line.find("0:") == string::npos) && getline(objdump_stream, line)) { + } + ASSERT_EQ(line, " 0:\tc7 00 05 00 00 00 \tmov DWORD PTR [rax],0x5"); } + +TEST(ExploitabilityLinuxUtilsTest, TokenizeObjdumpInstructionTest) { + ASSERT_FALSE(ExploitabilityLinuxTest::TokenizeObjdumpInstruction("", + NULL, + NULL, + NULL)); + string line = "0: c7 00 05 00 00 00 mov DWORD PTR [rax],0x5"; + string operation = ""; + string dest = ""; + string src = ""; + ASSERT_TRUE(ExploitabilityLinuxTest::TokenizeObjdumpInstruction(line, + &operation, + &dest, + &src)); + ASSERT_EQ(operation, "mov"); + ASSERT_EQ(dest, "[rax]"); + ASSERT_EQ(src, "0x5"); + line = "0: c3 ret"; + ASSERT_TRUE(ExploitabilityLinuxTest::TokenizeObjdumpInstruction(line, + &operation, + &dest, + &src)); + ASSERT_EQ(operation, "ret"); + ASSERT_EQ(dest, ""); + ASSERT_EQ(src, ""); + line = "0: 5f pop rdi"; + ASSERT_TRUE(ExploitabilityLinuxTest::TokenizeObjdumpInstruction(line, + &operation, + &dest, + &src)); + ASSERT_EQ(operation, "pop"); + ASSERT_EQ(dest, "rdi"); + ASSERT_EQ(src, ""); } + +TEST(ExploitabilityLinuxUtilsTest, CalculateAddressTest) { + MDRawContextAMD64 raw_context; + raw_context.rdx = 12345; + ExploitabilityLinuxTestMinidumpContext context(raw_context); + ASSERT_EQ(context.GetContextAMD64()->rdx, 12345); + ASSERT_FALSE(ExploitabilityLinuxTest::CalculateAddress("", context, NULL)); + uint64_t write_address = 0; + ASSERT_TRUE(ExploitabilityLinuxTest::CalculateAddress("rdx-0x4D2", + context, + &write_address)); + ASSERT_EQ(write_address, 11111); + ASSERT_TRUE(ExploitabilityLinuxTest::CalculateAddress("rdx+0x4D2", + context, + &write_address)); + ASSERT_EQ(write_address, 13579); + ASSERT_FALSE(ExploitabilityLinuxTest::CalculateAddress("rdx+rax", + context, + &write_address)); + ASSERT_FALSE(ExploitabilityLinuxTest::CalculateAddress("0x3482+0x4D2", + context, + &write_address)); +} +#endif // _WIN32 + +} // namespace diff --git a/src/processor/minidump_processor.cc b/src/processor/minidump_processor.cc index 71dedaba..3a20dfa5 100644 --- a/src/processor/minidump_processor.cc +++ b/src/processor/minidump_processor.cc @@ -51,7 +51,8 @@ MinidumpProcessor::MinidumpProcessor(SymbolSupplier *supplier, SourceLineResolverInterface *resolver) : frame_symbolizer_(new StackFrameSymbolizer(supplier, resolver)), own_frame_symbolizer_(true), - enable_exploitability_(false) { + enable_exploitability_(false), + enable_objdump_(false) { } MinidumpProcessor::MinidumpProcessor(SymbolSupplier *supplier, @@ -59,14 +60,16 @@ MinidumpProcessor::MinidumpProcessor(SymbolSupplier *supplier, bool enable_exploitability) : frame_symbolizer_(new StackFrameSymbolizer(supplier, resolver)), own_frame_symbolizer_(true), - enable_exploitability_(enable_exploitability) { + enable_exploitability_(enable_exploitability), + enable_objdump_(false) { } MinidumpProcessor::MinidumpProcessor(StackFrameSymbolizer *frame_symbolizer, bool enable_exploitability) : frame_symbolizer_(frame_symbolizer), own_frame_symbolizer_(false), - enable_exploitability_(enable_exploitability) { + enable_exploitability_(enable_exploitability), + enable_objdump_(false) { assert(frame_symbolizer_); } @@ -289,7 +292,9 @@ ProcessResult MinidumpProcessor::Process( // rating. if (enable_exploitability_) { scoped_ptr exploitability( - Exploitability::ExploitabilityForPlatform(dump, process_state)); + Exploitability::ExploitabilityForPlatform(dump, + process_state, + enable_objdump_)); // The engine will be null if the platform is not supported if (exploitability != NULL) { process_state->exploitability_ = exploitability->CheckExploitability(); diff --git a/src/processor/testdata/linux_jmp_to_module_not_exe_region.dmp b/src/processor/testdata/linux_jmp_to_module_not_exe_region.dmp new file mode 100644 index 0000000000000000000000000000000000000000..82e266b2b7589052118759a68c63f76709be5652 GIT binary patch literal 44936 zcmeHw4U`+zdFb8suJMY$g#vK`q{CloiY1MHR}xX8^-A7dyg#y}HFnZeI~vVuWlNgz z%xG8ZmnJ?0QlKQE4Nb{Onz(I32rUQNzC%grD^C5=rtNDFp$&!ePWnhn5}Ka_J*RC* z(%|>qd%vrZM!V}6%n8LBd*{3NyWija?$6AK@o6AL^= z$QDS1;qN&74Z&X-5MSO+$S|a@g}>MwAzK074}Xi0K8NDqZ`(ZOtxP`UC*)~J4?+4* zf%oC}Q{KvCW`Gdm1C+NiIRf;L-b#5Zlg&4Qd`NGDvHEPzBIG zKl~st!2wC~tA9k#>l{ZPNt^_IBt^(e0G@yfyfnTJT_4r=!0XflKm5e4Z~isfhhOcH z9c2=Brn{jKOUE-iQZk2&9A2@P!)1gd#rf&H@ZaH(&`6ku*zxi2cl-0%wa+mBN?3l$ z?kLN{RKeyJ58?$7GtKea_}p^+ce>>r`?r(tr@j&8U;H#LZ~OPyjVS8v3?6%l=a28= zd2;M>h8O-_-usW+Y5N#8S2fl=c3Ah8wsdYy`#O*qM7l+323mK2yESGfmEVY8>IlK!y?$e?J6N!}%!kOJCAm9B+FW@L8fI~p+ zUhJNOwnYrf-7w9#2oaFd(j)s#yG+w}p+DTPb}=I(0t&vpz(?);X%FGg9O~Q1F9zB# zAT}qf-zA`ox@&T7fn2%rCvUy`mmaPB(R*LG=EA>~UVKZS^&iwWs)zDW8hQwSZf7|{ zt^@&eB&Xo-JovkgEE00eclA+n*&Rg6Ts=sRFD_QM-3cA8icDA14^kSZV80V+OuYZBvn+kc^Z}7aG_~#Q;4s|0v=>0T3Qj6SAmp#qpEuwsa zethXrkoiT(+i@tw@;~{96q^u4|K3QRC>QnI@!R~mvxxJ`qd(&L`7KFiPZse<5i%s4 zj-#E=+uYu-pO<1qt@>A4`#!Oi=P8o<>RZrnDHP?~aXxzy<%;?UzdrE5KmCf}rEsJA zPpBCb8zK)M`ffsxN3cE*WoJD8B-U z@hR$)Ktg{s#ZnKUd?Cke-*GH|?g~zS?C$P*it;~vD=!!AA=>YLq^JFb%BFvmW(V5$ z^aSspfMy3Rqld@~c zp!?GMo?`Qg$P2&FJhk~E^q(kyFmuh$FI~C+$y3RFF!O=X{mb`xAIv=SM0Mw!SMa-` zbjdhF3B6S3ddEik&PRXWi|r}y(}bME_jmV;BbdJp;k^hSK=}U{6@-6)@G*qne1y~eCqns8c)pDAqX>WQQI6k@@J@uk zgYaR5AO8ZU`+bD}2jLZe%JJ7Bj3dkh44{?ClG!O;fn|_{&Oxz zLKs3=KzJ9z&mw#o;mG5h?-GPpAPgYfi|}5AqHkX%63_Dc7I7bZ^2gtOoEEk3p|OB1 z4gp_AJ~|)JBL)BHA?`ou-XT52+C<#0it9X)`Snq(4>&d5Bjkq|XJV0<{tA~&?}_Ol z@^rtG9=Gu2FS&qc+j-cA>^j(D6fkS|aDV+gmcD>~;j1n}?!fXc=FZH*WBJb}zjyJ> zMIZad1v~%sso!nIqQz*qlcJyQd!X-uz6bgq=zE~=fxZX&9_V|Z?}5Gt`X1(Bl-MPaeOi}S14wu)5)j|`+&4GpULN^ z=jV!mQ-cgMnagAfnOreFUKlT?r*ldFiema})e`(wmhE!gTUKlZGEJpXHnmlf&&*8E zE$lB&&rKJS2QqmwF|$yh5~gR1v-9bNnM|@(tpgd;lx&uo4ZBGuvy*7g^xW?Gq~B~d z{7p+U{h>f)ED-e{($>ssqvBO$)6`4;icv|(i2wn)v&ojNnRRb45>@q@Zjyb4OmSZ( zN9&Och2=P_#%yM8p_t8Oc2Dn5RvLO;^OF2jW@aV{T1Ara`*S%Y25SlAEXJ z((^Y{Cyxc>SZpjp7P9%mc&;FvooqI$t%OptY*SI~q@S{LulP~9*U~JjsyBo)BJoHR z9>a|))F%w{kz2>dh zhrD&Y+^lJ2ArCHa+IA)nie~0>`D8;+%JPk&*o~1JgW+((w32e7Ty5h*p+v3WZKEiDdMCF9l2)aj08n zMRVI_RN53U7@!Gn%1*j42Mx_lRH-hxh)Q**6}cdztsXh8 zUalT{?CO%+M5E!ZMt06!S8K&h0~p7v+@gAqAVYOV7pE!LTn=ifZhKm*Wf#p_bH#;G zdt9c~-EuSoWtfTodPp;SsY}gjt?cU&ZK~ZS1-i4o#**V5 zt~E2Bp3QVqz-cWRfR$CMOjehG#tMrk?&fn#cV zr-78FrgyeH$8`FXV)UjPW9yw(Q<_rAEvHm-S@^z=Dgeth-C4LlGTmyb4Y>a?YFd{& zs5Wc0(~T5kcT9P_uC~^L>U1JyGS=MHP-}|i3}7xuRn+Cq_Mn`K;&29{bgEXG?fP)U zQmu!kUUhmQCjyMq(-3v2W71`!>xMJXk;ZVV*DH>-tsDMy)iPi?GOIL{3M~Bce9a>`$6=-V)3GVG%olPCg{fkG z9!&7VOyRezWpA!Irti_?R-u+(^@Em%?TgA0SPkQ{cXoUZ7R9jQ(N(49tZ99Rs-}B| zmq;hy}saT&{x)$ zlxEF_S<_x-{)9!}?&(RoD$ghVnyva<gdhdA`8|dCtg{g1 zYjN6kNq<>e@i&^a8sToIHgUJ`Rjz*-7SWE2fZWjSqOI#SSQFlGLO%8KGYSU%(?vD_>|f>XdKcovdmZ=qw4qFQQN6tg!wUd+yn z7k1C*W(!jpxG7N#qpmfY-oti;WN%LM9fZwX12;=e;IJ*fs=#i7-q4D+X4!tdbgvdEa?|{-WSMH-4_hVEyQg6rBbln!lgyg#6+hj#fsKGLnHh(>XsuCP$om!w zyS*_onVu~=NEnK9uz53|JFt20s>A+`V(aD_?_U%1v)So)(R~Hl#bD!O_cZL>;BF0U z<%oi*@q8v3pgLVUI(u@vA`=sHc`+43*L zy(%9nehqrH0r$|lscQbZW>z#K?6cJxZtS?mCf$*VeNKqiSfKN-og7Gq%6xY;>|=OYNGN znTKJro>|ngT>ik^MBB;PFdthTDx1jTItqA3uer+Qc^043d1coKVRq?YidnzmOHLZVqoHU4EbRs zndKr~eXRLKAt|2PbwB+~?r(3pw-e%LgOeu*Mz4d1kpFJrYg-@NMt-yn9ykWvg*O8H z;K0tW4U+E;a@1&O_*)RM;G;uFw~`+ZbKK<-fFBzeetD35YGC+Z2Fd4H`iIEkeWyjp z7YBwP8zx^F7=C1!+%q`*rD5`!!QsChB99IZ-!n{33=aR-5c$Cnmv{AKoRFVvx#GB= zJT$cBUO)NK&`++1%wv8ie@GsNBp7$a#0TNEfPWqser5~#{s5Hx&frG|ApPwvT*_s| zPrz#_AK5beS6j)6Ex!k}U){<}&i&lb@U0`{OCvlx`eyO?wQ$EN;koP$L_$Ixlv@YI zTM8Y>(@cu@Y6ROce1A_sfp^o1_ix1eUB}N+*?U{!`EU38G(ry16qaN!X}6J1;wU`W zz42Qt4&7^=67SOpc%ADwm43k|;Hl_eqjIXAy_fVF$?uEpdw_X>zYmh)-Y}ebDSOi^ za}a&ML*A5^zpqR%P6pMoW6vwobsc5fjCYa0drQdM+X{|tM&G9DO;BB}&3GRk3fR_c zQ`P|!Bt8-#aX4FGr#Pry`LAdH^5D<^>)xX$p8C)YcYJe&mVsXN)$3I^)%zjO=PtQu z{{`PVe)~xEm*Teyy%pFEu%NoW0NAk`{!YKX6=)?D{9<8kY0ddT>$~SafAHYb*WUE> z;c+L`>mr z!Ta$?w?F^Txj%j`ZC(EG?u!RsxEbv+>}C3ER%a_fJP~Hk>9)TCb}X~rsDM4|^#$se zPm}#``QyKON8&q?kH71@?2~K+)?E5ir>%cuecRrC+lgb7wHrSD{U`tWiL1!7AR5}C z(QJ7uu%E#@{97mvdb`uF6*iJYFJ?2FE56#%vO-0%7q4GRu~a)Y+qpdJobf)~LHuk| zA|~7jysW)tc6_RJJWif#+JJdc7qrwLp{wV&N|cCu!N1 z?7C!>0JCO+Luyi^B^hNy3sg#y3B0Ny)#?&#Qo%EF4cPq$a}-luF4BF?y55istz=0h z&|zvu5q3$-QbRXtQVV|Wfk*W!Ymfz2-Qb*zi=HHn{sKhnYBZ{nq1Nin+TrqHuvW98 zVF@HxVWV0qTSXP5t$^tk{K5V?m`e?ZDoRUrsB|k31!V@fp{znhpmC%!I0Fd6#Q+CE zsTHJc1X5R^qK0m$4Ul80#WKvq(C)BVUxn>iNzp8+WhpC~q^y9i0#OxQV8W)kR8y9h zir@#ORELhCfD6FSno;89x&cnFfiJ)fWqTPm*d(y12-}$O5Q4PQs8^+>n$|MRD%+9+ zMq64jz|tkFVwDu$%0;Do5O!~+QoS0W`k|I}Xky3)C6H)I)y4{~o~NW&V2jsa{V^U3 z`QkB;Xlv}|(J=4!MFk$wm1;RL5(or>p}1#` zWn@pb1D9o)cq|$VcnZL(neEcB>{+0cJTAz(z%xk+B4g2@>*U#;&clPti4k~`dD7G& z+)ZL6ECppL2iFe(es!rjg85X zs5BN2#>b>sFc1$(v5*`NO0h^}EG&8U)w2-oBQYXLQXm`;#-u~L0LN|U#?7dl46u^S z$+8fOhH}yaQByb1a#R4K#B!=!KJP}QA=WN(h5|vro_w{kH!&jnA<}Lz7NXf~16l)Kr06<4`Q`Ek z1=Y%~8W`I}9@b)1)N}=0(p3N%S};+u+XVrLBqhs~V?r^e8_Vs2HX|*_n)USyGD}PA z7wmHC5m*w3C$FhA79Fs7CXA*956su#iFc?mrPwLRHc51`6>C+C*2EhKhdi@dy+fX` zekUdZUFCw&v!d4^REa^Xc~rQQ#6YPMZ*!p3m1MK5ZLn5HxeLL5rpW23BdB#tdiH%Y8qgD znpwIgAYJQ$Kq-aX^ezYyl+Lg)GqwruF08fj5HV#UH=Qle0L@n~FfA~Kd~#TV5Lj2Y z$spnlFKlCSnVAd=H$;g&lk@YFGnpPOhz9OStb(8v>{oMTK{*hS#|r7NH*j^EWFCSX zVL&p0E9Ax@h8VozQmSdxmF|EZ{ixdgsM`Ig+BB?pKdLqh8P0-5_oHevH}s=wv!LGn zsM=levHMZA`%$&|rz2?G^L|uq{7M9i;N6d^-H)ox`vXRD?nl+`bVom`c0a22I?=fM zQMI*GN968D)$T{t7T*%9Bc z^Cy4&-N$Kit0>2Ui!fhCC<0NZNQz;G5FbMb0jt?Dg76%K1Y>OSxUT|9h@ca3pheud z^jEm#^N>{J&&T{Nm+`~}uKb%YFTk5Iv3AcRiIeXqgvN=b#|w}1{DnMA?!a=)wgLQb z#(rP&LLx8*Ny+rK3`zX>BrT~4_#rePM}m=9fd6>7{<-7x9{fin_npUSgh|JrlVv#y zo5!*Ywnc?)US=CZ|IBTp?qaslA0Q=j6>Vc){F(YK7>Wg$ZNZQNQSBVtAPqVA<|aL_ z-;SNwcf*${jQ4oPmSUwqOko|x%QK}g{8YYPUkSjEcHv-1j(5rtX^6gG^0#8qVl?c< z0FR9(MYcnmqAo5Tb(O%w}WE~fcR>Z0P?x@hMX{pK~O z7aKdgy_RI!A=Vk&+=qd&plG8`xM6#>L&9Qvaq+xfajL1Ky-FpTbA0$Jb)opSF4jUO z_KlKqrgc&AZCzdMRnpG1E~mYqlFVyjP618eLosf-(~(9P7u>Xg;RAM^4J*(B^I+SZdweYF!PKRnNhePJfs^yy6YFQt~(Iab}u07LgsV1S8%@AVZleIFf z`)gBMrb(y`^0^&55-9B*Q&C1E7((bC_YIM_@WjM8>VzAPDOVh4><3Y%1U1G&%olj6 zlLPS%&#=qtnb63Uv^92h0ro7FXp1wbv7_~4p(R=?F}1x`b)-r}9mAncjganb_!y%R z3{gJQ_uL8N)e;{5Tj$uI;oE_;vB8xvojp;LLO+A(ID=Z&GtVoLj=Cri;P{jbj7De> zb>VlXL3TgbaW#H*bz#EWn)uv_;|p#A!O%0OiQR3pyP3EW-P~(SOChBcruPD18p}l0 zO})lw;@C-9hBCYFm&EmVownzwcdwK!{XHJ>5a7}h?M7fkCxTzhx_Z`za^JmzA(r2R zPwNr#^zZYf+w*mWC!U?Yk*@omMf~z}UtsG%g5Q^T9`V_)eSm*Q1HW+*`vcDY(myV8 zJbq{6Zp1GR;kPjGTOZFN{@9K9Jq}#&?s$;PF@E_zE{E{%kSrtq{#o&@5Kbq~^iw9M zAJ4x#e!YmKFM})|58wID!d`DumzpolcG2$#&_l-ZD|ohT_kX;6l6?&0-oX?r z5&JwlMtENA8+{qe#en=UZV;WzxWE?(FGYClFdr9UUx^spKJg`%M^VuwNH6x2#6HiX v7p7Q=z>i{H`1^k36Z=d;|H~(NeNq>2e)#SctDo4SfbzqaCEiNRPYlTu|*^);e`{+Zy>%sKSyqPJ?ls@vigj_}lk>Ep*&wT8e zd0ryqA}A!`a~wWf;L`xa7k3fz1}NVMpUf;FZv^-ld=5bQVv2*$);Y@CoOnJ;$O};3 z0_8sg-Y4Hjd7Bf(O@x^DQ{Lu82hpLznA;D93e^FO5DYaH_NO+NvBBu~gG04JaWr^Yy)!~xlULbzqd4so8|FGlOEm*jfS5NW!@twR*j=h!PsSJ87 zUiW@x&jGakXE7$c+DO$WOdQ#{{7|C4c7h$ z+PmfQ_<+Cih!;FR{t)-q@wZgILUE@~^MjU$;iD(7xrvt7I_TJ*Nb`P(c50>=GlBC$ zrBi11pqkS?Y^38)2=^f?Cb(ST2Zn>M8?hk#B=8rJ+nC!#avHS!A@qkI>X$PzBB0>g1AHP@IK{@_+zW)1QQvxgG0}bjsUPV< z^=^j`b=Sn~Jh^7+kFR~?m!4|=_j|s7!?v$TFJB$&{gBd7J(P#i&_nq1Dpn)p8W2Du zIS-#p;qwl1fRJO6>yMBtj}obP{bq9fz=77*55k1=93LzVZvszm+4Ps&H%Sj(PyXtY z`;LX)_%Qh(H7pNfJ`9uO4VPVf@#SNn9Vqj_KfI-I)s`d5j?42~Hie2Gmhwj~yWdA(1c7wa6S z7)H5Ug?xl3{+9Cz{X*V)^xsTzI|UsfC!He~ojNV*LjTAA3zsYGz3ky@?-Mi>3P(IR z!R_pQn$!2!XmEJyiSqSSKo$tOQC4ritE`)lq>op{QCIge|N9orEtCeP6XE`6#ZF5{2f2!{t|e>C!nyKAid!0Vf_ki@b`$|6ZE2fz~XjIKG|d_5uc(zStNXS zI?qa<5OyQ<+xH~mzxg&!|H!SPpJR+)wExAmyj_fk7{5o6p3WC4n|>(G4z%xuU*PkT z3BxuaL*OVp_K`ulzquywZSI#>$rpMMQrYzAGx!P+=ImT2{4byw2LT0}=*MdR2nr7W zdiH*{t_ZB~3$0U|uSNff_UB)Ej=urn2*O!}HH006pF;R~gkMAWEreGb;_{*hM-bkHP)B$V z!jB_7iSSyT^WTo}{RlsT@Ck%}g7Ak33vJG~7vU1ZBM5&J;b#$k9^pSAdbRxN7n;-y3bAP=Z>o1{S_*EC2#w@Ic^!zypB?0uKZp2s{vY zAn-uofxrWS2mV8PAQEj@ttHKhlYNDW+TQAHIX6NomC4%JL~*uSD@_%0X&L@1KwB%t zN@Z$pwgxzr(@&I(#cHu!D~wggYK5tCF1n;xQN2}%Pjk^}w8IU>QJ~UQIt@!(CY9p! z)a?Ae+SKe+HMhT5A>-5YRVra>rZzKIn4d1@daX8)F-^H{z1wlRWTG^I_Ds$0n#)D4 zZYSEcH7lBkrAA`u=pk*zYIT}nMYb%X9&MVIhxfD$5Uz5&<%_1trly0 zi)Gr6Tp}rtvX0FZXXk6Ba&gzxzFf0ow6!p)Octl7bD+hF)?1zEVSCZzmFcnh+40F@ zIoCC9N3k3-Hea0s0dxEI=N28uw6oEuX&Jp0)#xm=ni18o%t+HPnz{z%HgAiVic0R7 znk~%TL7hAjlQWr-6qzqos$=D z(r|Ou+)S~yySTqRH9JuopPQ|g=b$?qJC00LcjG8jat2HaU0Dg+s%7YUU9qxYiL(-J zI)}n-qtVqhGG74~xMMqA0Y%eupigm|V`({ScR3Qu*pUPv zn}`I%c<%tIDmgGX8Ou7$yfvM48x6$86DS+{ZabVVk#Om>Uf&<-WcEKtU{<+^7)3M> z4Q=5JO=akZ+sYuu(S1Bl&xbhNG6z|F?RO5gHhj%~tNr@?>gtE% zg97V5fzBETAB*E-X=wF9nU>ieL>%;c+wvn6RU2eEY`AlrIaf7XKFo;E4$D_p%tM1R zo0{J)v)QMBV1OaKy)@y&95gjQQM0w+BdWLEQRITmx~mH@%~cqWpE!-vbSDtU^j68~ zt>#)~kJDQ4n`n0Y-6+la`)V)wX#nGTm0Q$aCCF6W=;AaD-RGd5>bIx2-0;z?beDV> zb(PDswqK5B!s_QPXfTH3Wp~1Ib6To9bvVZHEC}&r3b?F>E16@AWw#d`(@FGIafIWn zB60jAhGl6TKepHQG0rH5w1t-LMgdb$UK3j|)I*xJn!4U?>5a%L(Uv-BQf#mq=`6V3 z;aZDhg_+_YRhi);PS4j9OH&$cZ8bj9c8Av^G}2bALk(luJw0(pwmRe6}8B^(CI97^Uk50>|iv z*FZ|68{U!U7_Uz$#_0Mnj^VYM($wpIId$D<;jehQ04z5QR^j)NlL>qN?AuK2s5>Wb|KFc+jM>Y{f%D5s*hoUt@rs+DfPKOC{3 zucB$U+*!zp0OQUyL>=-hx=eK2bORk}Ouu@g>3W;fSbj0fif2LNf|Gt4rRT>O-g5xs zvQ2kdaaBFrbmtXXX!w=Q%%9VNbnhH;#(?1+@?PF@|?xMnOrxvZSA@ZLUHs z8SZZf-jBQ8Imr+@KRFik)fm6_rW=Vk z7IDX&(;U@kE%^s=S@WLTnUPA*FI(yO*^H*2#%K=GkeRWmX}EqG-woH6$&4%yTwRvN zs*|~>VKt)*mZmi{`;cRp(L&2M;c{d~=_pOO@T>4^9>F;VSE@f7o8rj)LTi&^45lo4P+3x<2OEd{B(|SLNN^h%1+PMp?5TS8C|dQdO)+~)W3|%s zSasK2d8Rs9gdZh}X|}aaH+;8~BBeVDd}tdQjp7*A3ZGx&b2Fu>JL$dxono-@v1LzEldIXc-IFCd;b-RV(%4xID^Arq{1QE6Dh*Of&J@d_66bK#w$v#7t!zgZ z;kPOem8b@@+JxWGhNWuJwq`XoGZ}GI9XED-u}OF2oW+(MhW`+1mZmC>2AcL)C+BAU z5$cH!wab3{M{W3hsdi!VwOfZZGCeoJ2ByDK5ghKFQ?s5~0znZa<9jQ$a%D0H>nADf zoUe%0qDISOg+dwDPX87bU2o|$4mXQ7>=JelCW~xb#3mvvSMD0Oda+^~bl!01YZ%Ay zGK6N*6RmVdaT*MnD-~yR_elLsJ@C10woFZWhfSttVcTtXyqJSs!+q7l94vFQxmG*O zckq~f<@wp_6zr<8eNNv_8YxUwU?JF_%kopw_{GhV zqG3^U*=`=&MCF^JbSJgdQFJmlT{y>UTa>PKHYpaSU@gim!GM+cxfX_qja@EWCe!1! zakc_@*R$ygZaNlwyLvl&h2D4%R?LP{SDK0n;Z~lTs}97PsvF&g=iDR$6XP)vg-Eg* zHG1{25*3Z4c4pW8>??WH-F0_M;?D=w>&T}6`^>ht=gH*#xkqN<@doGGr)cBk1IL~1 z^G|1Vg-jm(*69;>edoRKnA5hmlkeC7=K(i)|97RyqxYVgJlcKv=!pl5-<|xmB2=Dz z@iur!Z1U(Ap1$phF~VfMc;ZLE`q|=lzw``ae71OskTF8(pJh)g-No>g$@hPED?9*n z^mCVjipisYM4#-Me5m++D)e(drsetXL;d7m%z$Ky-0}Yz^5o=04-7Mw=PC9Z)O;YL zx2Xjuf*rWSki{UCRRHF4|=TsRNER1uM-Le zY2bK=?>Lj%0cNP2iT-tJr)IF{6kjL#f!M$U%me)SusrvM>8?wq+h3i7Bw&*_;yqE~ z&!HZW`wDjK?ibIh@D5775wFaj#V6#}zT9IQ(f6rV7pSh@M!ZKphyA*)&wSN%zj#)K zcLMdx8|gav4X*3uNMG)wuTs~|AYpMMUJ0LjKIZmo$4p=CSru*q>Qfu(!eJaxgd>YD8(j_*r0P4gbDp3GNNfXKjeCtGm+9H(OtfZ3`&?}?^&x%@rS%%gE@Dp%KWKk<|GytS@xqO_zi?pdx1Y}c{k8{b z3-s4^8tP3qQN`(q3?63;cfz-K9-W=v=`3l0B{#u8?)M0cRRl69@v-3J{*kL*{DVtg z`DVd>>yx`K-~9bM&>quSq<_!yjsoNtV)mTv_?uwIBAbm0*t6DLpnmxT*?0B-c=opJ zKc{~C&Pz*QWf7?R^ykl7|N8p2-ul2Z$0qcfKJmS;e(A(@ee{|<6~z)UoXWFOKR4SYyz2QL^OS#nMUfM32%ccy{O(Ny zhHSbIo>!mas0r9^Y<0A$j-%;bqThhZbl*=BTp!UHM!#hk?-Z;PbWPCMibYo+6&C6n zU^N&4{5-5BU1)LOTOt)Q1G7vbcK~$*;O&6b0cPMM!zz*mX=(V50hEBZO2z@kp^am_ zYZBxMvkVok>J4isE6JfHts{Ny!tFheNibnI_yO22Al#y9M_(sUQ?; zaxY$I`er5%Qx&neEJtKn4zUeM$%aiaicKZbvb1|=$Xr~pTkt0Ui5V@2>{cD-Xwzn# zA-LB|qb*b}6G{=ZEge$KmMU7{56VspWFU?bFPL4*wW8UySkro{W;$?V7vjJnt%js) zOW+4;O=#Kdlj{no2Q2VOOKnYRXp(7bl4Gk<+qNWA(WJJjNop^{6iT*cN^Qr2mL_dc zB(-fU0hvSD5@|`*7xb>ZC^Z~gQsB-Osom~L3q25JgIM^);Y(U{B&RKzb-=9H;1FHv z^dz%kYO!WrvVd1LCA}@dHWl0@*Ma?iFh{Y}#Twn&Y#SZP)atfW2OXAX)?lBsA$1H> zmwNCAAGlesxdK&SHB8RQxagOp(Z2!FzM7quWU6|*tKZ$Y8?4prbW#GzE!e7-8g@+u zX-i$Y0A~O}vKHeYF7@Jcj6muVbksCV zwF7c&wbp=@7{(p8>szovD=C^S^=xHHlawX!RV=N73oO_+mvm)up$2|X>TQ@93b+9L zteJIAZkXV79ee?9XgG_o#U_D8HQ306+YqFsPP-*7=vvRTT5MAe7#(TJ1WOm}rd?O~ zDA$z6LD;{Q>g`sH>W5yoVThp`mq4N|wK_|*d!f3~giT(P&BxJ9A~Ko@iLu6Mo=);< zUsK=~&JO*{1k5WyDh;@S69%1$qdIVwJfKr=poZs2EV{x4q&vX zoNOrMjs4hp9s99$V?Q2R75niZ_Ji2JkYYc6UdMiX-PljAj{Rg1`$6nqNU@(duVX*4 zZtSO5$9_79{UG))q}WfM*Rc;*PH;`S*7bg7b?j$?*bid=LW=#=c^&(ybz?s!uMU2| z1-pI0Zr=s8+m}ACqksLK{@5D9AH;re=D(26{3GXe?61GmpI9CHi6Hia*uRisKXYEk z{`x!psnxNc3SvKq{R=7fN6+inUw@~6WOeM11hF5){)H6#u*3E5@z%ch$ho<-Z~d+Q z(bd5}8U%k3{1;U4pWpZPZLrtB)^=Yk2>&4b&-d^rWESqn&ko_!R-uXm4{T(I9BBtl zTne|xOY}zWcZI6WRwFwUi^b$bIyB2Fa;W6Nl~`polg`9KRbbUDw{;{mPbqn7kTpSQ zf)b=g(sAEcXjh>EcP?j#;8x}d%YckG*`cHqm!&v-r=(<(-q0MA;S*0wqobozN|s|1 z6(prb<+v12%Ro6IkETcH_lPWwjL509G%^|=9g#Be*l0q^B;;gV%A`^wNh!3qU4n!k z*&#`iV#(2XMmn?;aNLGL+_cKc04vFytOV(3C?`D-HF?JjM}hC+oT^-@_)!H&w~L$! zK~`~u{8$o&6?@$J(2|8jD;$#=AP`3 z9ED`N@l1kNOC1;uc#>k^2vrsv>ol~QJ9RL2fIO*XsHmwXxMZLKDzss|>GT_7kW5OJ zDaW{CPIVUh4Sh!1P_o)Abj8d)id8EAOgngnLWU}>Cb8sn(hHBHT-XqFF(CM1RjE}}doupOmO zBtW(zNYV%KZ%1{z9=0@H18hXI>Nmus8$*yPrCOfa2}yzqMV4sBvEbQ-l|CMFri_=T zN>!So`TBXL1wtqyCnZRNb$y=NhWaB@)%?hgC|_-x)uUY`ZIb2d9{PQ+Cg4zn%FzY ztId*zvvkoxUTx-vAg?w{>mB6P9>|a#U4XY>p_S)(sv%u8J6IPef)D;j zB>yjuvq+RK{+uk!Y1loMWiT!+j0-d482aaL9Ca8oj{XHwvX;>}=EtA6=SJ#i+^Fg` z4$5FEym*s-uRWAr?0ew#6y{x_k%f^_RY}PWU=H(2nkLL!Yr4eX?{>*}LSA#aKnnhP zw3kWO(#bI9chJ|yZuAF0COnhJ0z#cZD)0AC)yU?+DB8ddz3jYgWeP_m%OUiS^YN{^vj$m5<7_28;OB zr$Ojh3SQQnS$kb$@3&fKZS!XoMu&1uTy0%uV=qER*64Xpgv>cri<~1PC^Uk40&*&%QfuAI= zS0AYo(MNiY=$~k5dG)|27>!^^@RfeOvnAaAx5lx~!1r@!&ku45@uPxi{54C9w&c~mtSlvyl_C-{FC<)@*?6F8_#W`b%O7icp34fC*-fJP&~ft zBLDlG{nV!}<9K}E#-oTo@O6AA2EOy-MZ_Pw1mDYn*S+!+T#gy3a5?xs5)<){T_fHZ z!s)~}eWl6S=k*`VV=pr5(>I^+y!h_>9?nIceroHve*eI2ud3fF}apDV-wgR!5kC&ALdY;&jXwvVxCeudidcN zIJ%D?!i^X~_fD*f{SxzvJmV1iC7;?p#_D1}WCy%2jUI1h->zNsJp%NQvHfkl+PC|M zKRwM}it*^?JZlmAJv)YYUF;uy5!*#nK8zbhmoP3uu0nVP!ee7RF2w#4F}Z!>jVw>0 zqU}g8_Lanb&r{p-tVQ65u`c}m81jkzCZYeQr+I(!Z{qy${wvl$v9I+q)<1h0Z$~kG F@NZF^fz1E_ literal 0 HcmV?d00001 diff --git a/src/processor/testdata/linux_write_to_nonwritable_region_math.dmp b/src/processor/testdata/linux_write_to_nonwritable_region_math.dmp new file mode 100644 index 0000000000000000000000000000000000000000..6cf98610f4e128f8d97d54fda51f4ad412ea4cce GIT binary patch literal 40848 zcmeG_Ym^(+dDo5suYlkXLxAuY45Us$n$cS;BG7sz@2VZ z)}f6PN)D!wlG0FeLK3&(B!rwKoIHp*IVny_f=N$%+$1&5o1O;ZGz9!3G;Y)2e)px3 zM!RbacEhnXyV7^>cfZ&D?)~n}T-~`dk(tQd_ZfuFMhFS;!N(6i_T)58A@n9lMBuXr zKFi=!0mR-ILZ?CcO86wML+EsX55s3Oq|d-O_$E)1?fF^x6LIaTg92jWcgOCr>2LQkO9U!`T{o^uF-!;5J#;&27aV-2{@3mw;FC?$v7 zo0t##=iUige(wYrL-G{fjU5cf0R}nWQos?vGQNiyABQV20UR7Ir&-cQxSbNL+zT^| zjzdg~kKA)k1*h+3{_sNmTtbF8(AGY(=9@Gm6<(a;P{9-cuIpi&j^{#{ucGt+{ zG`ghuwM*}P_wMSKZhPs9bN)#OVOUqo3-V4LFel@?#iuL0-j#B&(mNbfl7TwWct3>%h4JC?5a z9$K<|**7UH~Mt|j(nLV5kZ8kpsSARIdvt0j!pP+KNy=Q;u(hqPN47nrj9HDl$ zK27OYp8ru&uVyv{>@D8=z5xeK0T6FIu<$qu~&0`!E z(ys_8ns7zqpvv?|YoqbH_b56MkO)txIV+Zx7yn2N*r>FIYDI zV4Bs;z5{Qi{gVh|Wn2cwVYutQZn}TIB;8ruPWQ;?dKkpA@zG}RBp}Smxt#l-L*5P? zayDKMuYY(shu@wY>}o&m7hH~QzLNQm(`$!rf92_)q%J&~T%fzVSlIKtc4)5rb@KI^s2EW4KZx}qnVD`II-g_B*gu%xd{Ez*#{I?7So}u|NgCAz_Ee9w* z!{D6^ev-j2F!;AWq;#KU@Vg9N^dpMDg26b0lMI#^tTXr!gWqKE`wTwE;CVl$@5A;3I_dwqReGl|K@CNfh zK&)6=Q?;UKV`ikZp*WdO#ZjR!S{fS3P8LhKu}mr^!Bs6TEo2LYv8l-t;FJ)-jO4S~ zVm4pO3>Ak;nX!CIY|56XYi0OUXPrvTUy&UdG7Y(2vD9s-kR2bJoZeU(n;a{qHf0NF zczn8uC5%m!CZ;me$^ zbAoOfhuBLK}+N(uQmv*CQ2 zQZAoeJGL=Zts6Dfj|!vN@$nRBvBa`g7q{E99bOq9nw}gU&E``L({^ObK||BUDG)HV zaZ_s6aZEcYil$|><`knoqg4ZnVVQxdVN`V$(luHZFl7bZI5wG?x)D1$9+VP^coa?N z3dNy(kvlupsB5jHT(%ucR-BZG*{N4Vrrd9$98kW0NDL z;i<`DehR9yxZ}`BaXo8=Ldt+nq04iATd@pXFUwXEEOF-iRcEWeW>gxwilz(T0=I3) z3!rFxDql#|jg%x^8%|ssy*3nyBrQ87B`aDR7Y--&x|@q9YqO9`np!GCSi+1q7>->l z1(UWhKfba6zFhIpgAG`YvH;$&IDM4b9E?dxyFrnVW)%qovdWNP7_A*36*&b4M}kRb z8!e4R+(LulLSZHw>TWxfE*y60)K=Rcu}Jby1JJ8nL=YpY+q)66wWS;3$Q}xPJ9aD8 z5yLX{?KQa@)H*J`gmue$Q~P`ALcN1!tg!o%WtSSo6{ zTc%~!x)EEv-nP65Sy8)Lwi|9AC(cz&&4Y=1?65p}+1%PKv#NUSGOKM02nJ}vb-57_ zW{atMiK^O+hp1e0TagMf%dRelsrFzx{6uM-s@s7mrqv^-)yvgmkE6|aO*HG?YUC!p zb+wyb8o;<-r54qC1euB(U6iJxdmPkKy!N!VRXj9vjiv{q^teo|dF7}kjDGHb25mT; zcRMUKM^oIcLorUrfDnpAfy=76k}1a6=GKB@>fyF3ig27B630toSe9D%Vp}y2T*NVD}f%-meOrfusa*5&$!;9TC+o$iEKAjp5Ovb%Tp6e zl`A#17ayp(&D$X~P?N2#6=R!wdZLch>h9@_V&=Ra3Meyf@1!*N^xth}z*EKcNsa=8|Q>UM#GD7 zj83aDO}XrqQ`S8e{&`0gfaQwrELsy11xLIza?6V`I?n-w%QoF^MOC$I)9qKxLc^Ff&0Bud;}jt7i6~nudGrKNhS$TrWh5aC&C53r8_HzY4o#023#^Lxmeih=Emf@I^9#Eh3{=z^xuH8SYC5yTpK#N+c5DRS zl^0T?>L_BXQpF!Xy?soQds`}q-AUroBqs&6h4sa$oO>fm@5OQ3rNoNb6zdILN7U`u zCh8V?mn+V~O|Y6KrQG;XaqU!oqBxp`ixSy1YihmW zztxGN+>IGJgRq!u;9{u(9F8q2GR!6zb+zQEwj&zlEtLlJOiQh*EfJ&8x~Vm(3f8<4 zrb@=vj=?lWDy`L0#G39qemrjj69Ex4J_J|MYP~dF2uv5(`V(j*Gf{Gp5Q>v9c{7#Y zw0Q5T!TgQv7}gx^U&B)qxv`t@yaMiGF!8Z=3}$ZFYz<81@Pg5yLN*n|Iz2Nw>+@@( z!^4w9;4v~~geN8xa$Xg;TIHysl<3q>X(XN~Z>sYcEN;qW*$fSv^?-?*@eSjkV-zMl zj_PeT&NQ?=0PRv!=h~|BED9(#aXykrJ*9K(5p?jhBhok6>F+h zRn17iQFJ!3)GSqz9ThZfDvnM~dLy(WI+O;v_7`oqzEm2}`D)sB z6^&1gkcMfGRERbAnz6}_UIIZOqTvmNQob;ng7Fh&)=U@pXi>uHp-d(ZW2bit3y-(B z8~dwS8)gX`TOwJ~E_@OZhAVfB>m97f1YKvi(=m)nnZEB_}TxFxNNtkw<9L}a-)^KAnGX=xkWJ;^~=?osRFF!q59D`XkGSBImNkf^j z0t^J3Qb~GB8lKMQ@%$-ksMIu`J0tUJ?nEaETWr_x_!NZ6d}d+G@`X*4!)+($A~d#A z0W-pEa}6ezxxORAjw+&!Fg-asl^-i^I%#W$0Hnz-hpZ z-u{9xy7SKtkM3+7+PUw}>YM6piluDqfj5dQbKxEc$EzgVWP5 zLH^l)m;m`0x$3_O^4ZaQ?pQ%s_G9eNa3z2Yr*|B7MLa~Pze*_Yxg!S*Px0kL+#N@S zXOb252!%T+moDY2?mCc1N$&Wy)kVSAiE`vVw*Hqxj`z~>^`v~g@}6htx=g;FiLVdk z{2X4));GS7FR0=L4DNu1N(-;b^bnuGEHqNrah2ydn(8iQ$Q+IS1eIem$U55-B)>1V z?*ZZgy1p?@y#Qt*7_Yt(fG=-ROuFI!KH1lRft;5p3K za**~~Ocw~v7czxs??nd!OMZ0Qw{~Wq{M?Hl{2127*Ef6`(jsag8(9E#WFQ5}07X=V zv;p5bQXw}B=^9DtNCSEq)lmg_RCqc@L>a=@AQW}vfHaZFF(KtZSsmy~kWxur1WXxi z0e;M30xgzPg-;98E)|xqp(fxh6valvf$QUah7jXnbp@UQ9+d&-2v}UXsS5$b&?O z*=dnKo6Vmupad|cdF}%^{{I{DXTk^I35=!JyVniajwK&}=PjW->+ z+W6Oy8E^YZfcqod!|=BR?Hz@20*?tQ8L{x_qrgCY1&ju9z)!)4SoU;h|!YI*2+4FwF##W)_SS91j{8tF#?yxe6p!2yaaww zb~KQ|aF}?;Y+$ZA)yBz^+EP^0frVWR2M*CHg042f57-*tHnUBx%b*^xz$Y|os!&k{ z(^dt?R)m^u38t(HHANMaR)Q!LY}FKMjs+!ETp|lf&1eFdgW19{LD6UQhCM4(99xiK zWs6X&wS<`#h_XQ}d_wRg%sPTo6U;JT=4^0?F4S9sSuxdMwJcb`tC)gb6JVMOR>{?2 z{vXVdEoHWZXEtj_T`<+MEtElrrJ5y}C#?u|!_orZ7(bbk|X=G9k7#*Q$f~7Nd)h^4ll}mDE3(VgN<(d}6`k|IJXky5Q1dwP8 zTD^&@=PMgknB+A{e;iDN1A_@4Z)?`gV-eczOEN6stm9uMpkDz}uD}9LXmm`5*&{Kb ztbxru8m}s2 z#eV3dj{VSru^;J;{YXFd`>}s2#eVptj{We0u^;P={a8Qt`>}s2#eU?Zj(xauf_u{W z?)MYDv7hM2en0k4rPz>J5It^=JF~vwf$~Y+vjR8U5j?6g;sr z{lR&HzaRVkGykb{=8wN2WB+*l%D3=Lf4DdH!~NLr$Ns4l`-zh}_7|S%kM_oXv>*HZ z*gutGfAFM^{e@@xW_D`kQhZ(Mud1>FmQ~iUz!9Um!{(kVEQo(<6ukBl8 zu7AGizF!V2gd`yZ-%%kF!3&y$5`022VQ_Fzh)PmWz=DM6pcE29F$pN+(qJr(zvGe+ zk4w>*5FZQ;#)U*EI2aZZVJQ+4647WpBKS7ca2UeM2osiVfhVZ=K}I#M zl_@F$+x;>tidjw-<+8TPCdX0BisX?b@Mh3g(5g2i2P6?T+YKecIGd|OYrvBfU5BqQ zTUnq$tFF<(*e>#jn!uvQs^F5Y0?6Qk;i}Uv2*PGkl7u;iWpk`P+b(D`;)0x2o4+7C zGc$j|8n+(78GiT*s)Dzp0~X(~*|1^7ybep=p~jfv8cw!IqKmDhYc{TlKNt!7Ce&Jo zJZ}9pED`J~=ZwClp~H5`vNcyyU?0Siy-jmqqdI7skPjZDSgp)$Z@B&EF>0-&dQx>8`)8w!5Kpe_w6#-i7|Y+Hd@QwGq0U z{Hg(8{rB2G^~(DYI@){f;de9g^O7GDL3k=s5-fkq6!>pX!i?Gz7nj(%%l} z|L%Cf2mKMrd*yKq8>RD~lO-tzv&WJI#>KdCeqtO!|M88(4kO0lUmyi*8#9jh@sI1d zU_^o6vcb4uM8z&_8wY8~!HYNX_xw%SiM<(KPhsBTi_gR(6?i3V1(^Lb6O6-#dGmFb zApC9@35BJ>PB}acTkw~~Rw7o4Mf|Xj8s6iv-oVKA?xsu^70+~q;XSFK%kL)+hTe#C z*ulp~7Zu;u#p=a$;rKYNy0G}Rt}vF)I?f5G7Z%TSMMEml)f3*-hv0ACMxAiM_G<46 z%i4>IXS(7c+)>)?RW9S4+g`6%7ZuNSg-PGASl=ki$5|H<-`3UDUS;CZ<5;h7M|;J? zU4shL3Vg`pmN}i$aN{D2HZZ)!uCrlzdcg*Ex8LQ;hH7DjD*U0;=78u*SI|?(0QcX;)LfW2(j6?@* z*0qkWTB@n7mc%BD9!c$V?eSKNHMP}}?!(WRD#@Lo+G5#UZIq7ftRq1|Z%iqKhBL&N zd%V{~{KS*sanuPHj497n&a59OLfE1PIXdn5S!=@F=1E+HqUX48mW@D#;z_v zR#Tk-jUBD8#uQvD-ufr1j#vq=BfcbaHR4RqV5$-t&M-(v`uRoyxVj0#^1peG1)8C~ zcQ$SCxD=ZK{Zvz2ij$b*&X~`%xRh|~0_zZu+KCwr*TCySFHb{+-R)AZvo1tR$q%0`+<|f-^`4+lfkKf)tOWtyT(7~EaQM+dL;`_aW z3_ttOesceZ*n1`pF?{ax&(n8Yuy|A^(8uU|Z(zUofrGR^vHrpPDW=1R7k-DL+xP+YJ}gf64wgTQ(V6F^N$PBt ze`w_pNnObDtKqF__;@?ZbGz_+1n?oT@{4JIe4{wq>H{=&6GEdSWqw4AZG!T$j|YuJ1M literal 0 HcmV?d00001 diff --git a/src/processor/testdata/linux_write_to_outside_module.dmp b/src/processor/testdata/linux_write_to_outside_module.dmp new file mode 100644 index 0000000000000000000000000000000000000000..2ceeefb698cd3441359b333bd078098f64114f2f GIT binary patch literal 44944 zcmeHw4U`*KdFZtljAp%lbdK8~?>a_fO=npT{ zFJojxK*4tl@KHNo>A}4~ND1|=<`)y~7f{Ses`qmEPxY?`%_9o^-vy4Ll5E4t5}VYYe2x2P|m{VV)(p`>?Pz#=(qd z+q<{9@k21-`i>73H?IRvZ&>#?m#>rVzK(qDle>=uF1VL`h%QK37`x3dN#1zLg%@5n z4%&e-3;dfmcEh?r{=-uC(8ZUD?vM@Cuq-*We)Cgg-Np@%ZG48$%e@GN za`|bFC*S%Mi@*Cn_9?dBtlu@bKK$gpyxyZfc64CHpV|APjEZCZ|C%v-=AW3--qkd-p_a0 z+AHK0zrgEG`umSlIn<5xpyvyEWFO{!x^gR*w-@CCC=mvd0W4dVD$UXy@}^8Gbm^C=jzNKn{j?j{VlIQ z_?tiDq7hHeJN@S;>GQlF-~2<4|ISF3swMaRJ?DR5Bd=2&6%>RoE|6m2T#a&%AQbWh zjr4Uc_nVJ#_~Cc(@#Wlvco6v6*cCAA@lz`m-DHw|2O{ z1YYn7DC~X-*9pP5i2PSPH|TG{C+J0euf^?}I(``oO%b1>KWQXD`(!s!ovPxNz)@r(Aq-oo3(c!=@48|mqMp|a_R(riWhPJD#VPbLi8gbabB@W`9B zf%*P-*JS&fd*vbdLJvYJn;ty|PXWT5oy&#)1r*~TpkNdI81|2#;PC5ze}b(`0xSGN z>(u5g=s(f^RS_*V%3KQM4&mJhKY{SG2>*D5 z(|rcvw-8<(;P~qijv|~xSVh=I_@@XTL--wp&mp|xA}%kCa1`O~2z7*aBK$bQXAy3> znDg&I_}d6Sg76`Pe}(X;2y>TkzFi2H5FSGKM+m=+@G*qnL--=X&6jdHTM$MNmJogj z;U^LPAA}cf;(V7Oyc%H`VFBU&2*upKRumrQ*Dc~Y_|(h){wQtgT|;97yEz1W9r@^b zK#wf^qldWuNU@rGZz3*N#d)3_x{Iw>;{E{1dzZB$&Mv}++_$-8dQD6ZQK$Fw^mre= zXollb4tjOC%^o;@8Ebp~iO>JHV*N$*3%~0kq>1eV%>9)MrF|}7M*%4SXUecDjlU=x3pza&d*HG z&F`*G&rMe{d-7#6F*9GG5~gRXvxVIJOg__Xwt$Rj%5-X-w$mY##YwbhdTx6m6Sg|- zaL3lHa4eD-jU>bSwF6eO-3ThOWf`?_!)&DGbcBH1*-Y2btX43ZNUDZzSY%fvU)_~2 z(SBrNae0h&V>UlGUoDpM+oyMD8f~Mc1xa}-KQog7EmpYJY=;lpi+x_18K0k!JT?B0`EbR5%8hr_02bPuRTd!g9~sfJ~S8ivu(H7K`uTgX&Ya_jV5 zu5c@L@@Pa(rA8BEzF4k|mny>9nNGXeO)E9qu@u$Ggeg1sN*I*~ZOyiuMq4-|F_uWe z!)k@ue067jPicB?vN}P;=z2}D(qM^mAlPvB z2U|wHqibZo3@&iTcBTx9W(uWprfpU{E>{Oe=P*F%0)ydqH%B# zp;-F{5su=a&<|3#ave!3LqFJ31~HEA;c>bi#KERH$l__gZLqcOY4%#})#p`LI~W}l zSn~*URzP@I91lxfs}0Ju%+?@cpV!-#7on)yAj?6+o#V{8s@e2lMm=^|p1NZ0AC%e9 zympz59t8vg4B?LAqzALl)VxHE=7NW))^bOY3o>i2F2pp3FnxaFG)}{vKpfK@lG7dL z8nVY}E_h8e+um*z=e&Kjm%KE9alOhdY7Gf8RX4ggOP{Vwarzd7XgmR2R^64%F~+jn3yx{Wda5|WafV17 zFNtAUTHA~5wmgip%6@I3sk>3Y6qHuP<_vYeW(`xm9B& zKc1V-4^ovFF64AQJ+U;U-qMEgp_V(meL_Pm#oAvtmfh16cVx5ep1wHdfY(DIb-|sT zoQ9tM2h9w5`WjMAH!_jQOJd)lHyw}T;cCJoSU38$%P?bVio3o<;}oNG+(6(M-RL)v z(&$G2$a74;PbtRecrlLAZ#AW<)x2_Qy2rx**4G7Kxqh$;*GHCDO|uQxKc=n?xPxl5 zm;2pFF;3r-$NTDNL#TcyQYQ0&w;QUi*lqxGL8_uI_KyeUR1}vplB7$u(&_bwBNp@_ znpV@Dg`5a5?o30}{=P+*iEf#0pd*dxRc|z0Z*v;UD`r{gThO@RxR*xhdND@-Ie>B5 zraP^;s;+Ii^9n6Ayvk+^yF4Ch^`Gysr~PL)j*5B(wf1{4M*qT$g5q9faW7ZP96~J_ z?zIE&#~tpR7_at*8;Lj; zQOBLr993^Fc?WS>>p!p84WLu(HNv5v*Xhi3)ZoV>AEf>Iq zFsu||+g=QoI-|x;W6ZAT<>fGFX*;2$oPfJwyzQMGpM#rXxZ^QYMR)IML;IVS_YNaFL*Z?s%r~M zM|WV=bQYOE;ihl<^d!A2FK5DgIqW)vDGTpYmXz?m`hG8o?PU=X+y+L$t577jRQmQPnzfEiF}D=QtHqh| z%JxEOwlbB6ixR~&TUxslyu(S5;;lKpgRqus;9{u*9F84U71&KM+FI4oY$t5g_SHKu zGcB#5b;A@zb`-W{>QwV?*eaRcJ`LL#nQXI_Vb%=Z@zZ@9*a(P|nQ^#^*4owia%jG? zJ(wbsx!J0VgixG=&6`4L&)T!A1^YLOV^|0H{F*4t7N>8c`wDc5!N$k-Y1p~J-5S`+ z5e-x0<$NYWb$WJmc9ym!CMM>_!DDR8h;B@%?7SM@Z`Bg2TIE|i)ydIRZBJXoU}aA+ zk2^HD>j4`zGrML$#}sUMoYvd8(2Q3ywnkS1>WFy=YVM&l%x2gxft@LhZo^m zm4`}LgIR6DHMC)=TDYZI4b6;)9974S9Zzi19XV&QX$Rpygqo$Pilc$1J(a1#oHs)I zqC@SlYyYqf*OzJsCSR+0P$M&iNj5OOm5ShSZ=0U$n z>?_UBRix)G0tNv6Efpyn`cw)SRykM)d{u& z^si?#W!!Ykcei)9b#vW`F07b!rKU6#6~e7lC{zYwP1TJ~z3<#40u$pg7KTW&>Q#F8 zaUd)jN%i!ud*v&6*xhw^OX80Sm21hm|MmE$w`R%I`!n~=!RsE*mPcsg)CZ3_m(M?% z(iJjw__7QV4Z{5!D<*DC(VI#Z{b@;0n zgNmucU!rfiP2H3KF%|mNpVRXEkD>nTU(bSMiro4i4EgNTJs;f6Se~ZX?^E-EjF#_$ z!~#OZgN*u1jPjlj7J=aj@j8ld$7$h3>{X~NAzaG1lzvn03k8$5O6cRYR65p45uXsUcu$df!7hhI?%g;mnI#ywj z29CFRj?<|gV1~-+=wGLHY6g36^L3K%i}gLgJiyw3_2Xf0lRKb1&s7p|If%V$zzaUxK%E#wB?`bWX+YV4Z=GmRTZD3pm2}bsdWE#%-B}AT%g~x*d>uy7 zCJsmoGdU)d9B69;T@^|itA_zoBm01#a+p9%7j$AbI+BUe5Dxr<)@ z*PQ(;4{yJ0{f}=&drW7M{ynRI6d>Ocv*%35-vm1r*=$t6o|WbT^~)#7?yLXeiJQ~^ zmiXvx7Z;ym5vY6gXU|yw>iRbR`Uf9BGO6GAi61@n6gJta~54zhB_yOu}|!v#m|H9Zl~y@DHFe)AN%A>k6G=^jn7UPQW@r*948NSakJK zVWGYrR)bN%&%;{Mfffh8B~m7{Fv}!zD^S+~?f|R~Fa;kOR*^JFOTu>qpai@XG666O zZ5-3TCPA(|%TVF2-mpf}k{npl+I7RKHtSI9?@2&4JJN#EYU&4|B^iK6jx>FQ7Gu0D zwUw3zb=L2#rFTfXHKR@8L~&lqCxVe=LY9_dQdWwE67uBK!GP^(rU{RU0aG;4YQl3( zDhP#|+>O?lzS*gRR7E5z%OP2o18hT5vSCwvVk?RVm2Q2VOOD#>RYm#Yel4Gk<%eEv_(WI8DNoqI66iT*cN-f8N zmIiH6B(-HM0hvSDVo6EW7xa$3DAgTXQsBuJsnzOA3tbRpgIM@P;Y(U{B&Q{rHNYIO z!6CZT?n-9e)FO?VWC5>gN_tCzZ7O(5t_}PDV2)y`i&eU_*)rOasnu+$20ARwtinEN zU1}SqE_LA#KJc(!;{a5F)i60Hom7IeBBNrEyH+)!7cBQQ8p9h?CK@oI#FsML+pF#@Se z&{5Mc)i%hn)oLA9ViCP8f7bM%m*@sn!IWMKs(b#Zw%!)U=$Aq6bW48TDZ5~8vD_}Q0zzj*!N@qe2V?(IUW1aRbxLs9Q$!U_WjsDpJG3D zPRD+1)!0uC$9~d}eLwckr`V65)3FbCPH<1U(*1sFIQCP1?EA5QKE;0GoR0m(s<9uD zhl3w*{%)VY+jk!A_9f5h=wE%OKe9sb`?2qz`Ol{_|L8d#`>XHt$A)7+=EuGt`{z^a zr_SlvUwx-PF&z5|Klc6DKc8ZM?3|AM)pzbpv)tB5V4hO))F3N@z$7I| zj3%R=ufXJ)Z_*=iDJn}*_)bXiIDMcwBEu(|l*Y!!q=YO-Bq~Ts zjLA_cnv{WZR31x?((h4O8Xc7rNojN}IyNe$qLHzfl#0pmsFX@1M&nXoSE~pKKhh(T zBt_z5(Ui1*8{oJNgSZ)$lL1zeIav|X(NIo$AZqH?S&jnNp|Dc9>_z1u-7a#*B2m=o z2>FpX3d?uF6I}clQq44L92JLjzi34zFQ^hi*0N#>9Jj2(UP%IPMgrw#K}2L5^C zw#EbOwV~^!8>Z`NDU2Ctc-op6X2oD>oM{^4u-P$9&7o+P4~ixvh8HfvJSDIlrf(!b zwjxN<2k~!*b-Na{G+hI1NV96!N2D79kSe88n%)LUf^vD5XvVSN-Gu`^JmgH7C`}hD zG)41u^GpkbP)LqTkOb?x9vS4k;f*~^DL<2E35O_gV6sq{oXHPqK{RkrViyFZV84zl zi^`FNJX*=cgOTfcBn3!wgel1cu2LF@EMoA6OHJ3PC%qXx{Jh$JUTr_GHcjm9=hbFO z!&$m$Kd&}(gP&KMrSU=~jR;2&UWkxj zj!mBTRUiowbRrM5$UB$&HkW)cl8X8zSbyJ@yl|wg!EvRYuJ7`2sL=&Si{d3#`Vp+2T)3S`%V4)aPasZdG7(stdQHB)!wQx6;tR~|@%<)%)u}lX^lGg?C9d+d%Cb+ zsEfwOS=B|w_jJ{$beuS^L%*na)U^N)Gf-Va;mv&*8I6iD>W8b2S1&6pju#itbuC1q zY=p#k)mSgx@p_HAP<&4pn;RC+jT#%hv#E=U@97#CuNsT2v#HA+uZ2hq^!DZkEkjMj zEq6N72;<^w4lw+RUH`y}@~Q*urr#CHn0!h>A zl(Dl6Th|uiQI&dn#W+d8k2R-OUf0;~TdlITc{2*5L%AmGV=~I77KV(hu^!{pI=gDQ zCZRS)ry2B?pSrYu*PdmyOjA!SQzXuq8a-EuMfPl~rJ97=IA7awB0=BCoA4On6TdUpq0r z;3CisYnV!}RTCB7)3mnN78YXhQF(zguu3dKjak*rj7Ic@SGb0O86eKTD~vryy?d!{ z8@C6-&v@zimck1UZ%okpz2_0X_{A=} z|0DQ26E7jY7`zLAPlNx~MfT4*`^g(rjwk&0HXcCy-U|LE2L9&9^N2t4yO(i#yziAC z;&RN-9_4uaJrWb~NB>0pW(cPf-}EO<&OERGU>901>Uk~61g~EUI*B@w^X4>!1mCrM=2idPf2>vMYzdAcwLw2kKc@oSq zvHxKn{+)sOA?7KiqlXuMgQI)+5!{FobZ^JH*e@}!$TAMGU-GAykF&bi57`R8mqw3Y zVc)J@^mhd4A!GYnc(rHuPk(WW{V2u*>$9vy?DuRP;dQZp^i6CRQF$+J6kWu)2)PR3 z6$pp`pkZe!L%GaV@vnF`|j`E_wJjSx0*YXnaTWT{+N&rgb)cn^my|3AD!kULe79f z6h4RGvkpF0Ks>&UkTaotIeZdRguD&l-SF8B<+CUbKI?Oow>J9SAR$jfc^#C$2D}e^ zl=9X_vug-3KTdgTqduU2=o6H;HahoCkPqecP?muv{dqzLpnNYFX#N2qJ}5s8_=oNX zCODu-e(`7Ydzs^bU)u5t=p$)DjsZ9f9XK|;4BbhfB&3CIvEy?$p8L&%R0kf0#b9yBHl-s@L ze|Y`OweMhs#jkR_iSUXCDopPm#rXi-j_`Sh(_Cp7Q-=w%>$N53ao8WU-7FL5m0ES;yQB@X?np` z8BQr6Arfn*d~`0|G0EHSn50(FI)}f76ZdH`fst=5(6Ds}`R+z~0XI1Q0>b%zkJ!oZ%Rim47GnkX{a8`Luu$C{CNSZ5pppI zppl%0&pGgUFWF7VfxxAUzmg|w_ZyA z_6s`?_}+Fq`4lxQ4P(9uCdru_&N}P7VbBhgY2e?qE_1=UMP2+&-*-uO9#dFRR z-689!VQI3scGFX2&H8nZwEvRN&%+3X@&h7HpXclEXTRoW>&@D^{`KKM@8b0i{WD^n zQQood ze~tN1$lLP$zhd=QzLRDPf|%bc$rJ6OpIbJ3nDIaG5ckVNdw4x}MvB>U0P%+rG9-K* zLOYNAklXu%bJDD-{V$yV@Y{HuBB`%_1oM_c(LRgoSQ??|kMQd~_x#hZ30?|U>JO!- z=W!G5+w`p$Sbr8#?$`^we$R)0%0!!pr{|sC>jUZAydRH$h2y_7kfv(M9WQbIJJ<6% z#Zf_i_+kPn0*(aE$4v-@JV7Hp%jG_f=kHIC^YP`}gt+MiUhoS(fj@%%5OqN(>O!CJ zgXp*LtLPs+9||4{g};O!L|YRI^P&RqTc}^yk!~rh^=9~{eiioq3i9lHPnwlvKZi$d z;`G=|7QfaXm!dz9BmVl|;rAc8$sRGgTr! zMSqe=_K{wUTLZ~GwQ7wvz03ChFq5aV|Y>FIo-vgwD8 z*%q|#=|AW5lL^B%+Ait>9*Dfi;zHE_{^GPK_Q56cg&u@dHa+^7dMXg+>|7`OFQ6C) z0R@Zbhuc4*UBJJ4soZD3@C$9HHeZhZ6Z8k~+j6(@^Xu2m}Al>lK8bM)>w4 z9G^jWE5f@F{t3e0eU8(83E`6nFMOWkFGDzpa0+1=VH4pO5k7+OI|!dec>W7qUJ&6R z!W$9l2yaICd4$g(yyQjBe=Wj~A^Z%&`w<>Q_!ESgA9KDP2%D+SubyFf*uZWM0bfNvx*pIY4gcsNu0Im2*1b0om#gADPY!Hg>$SK)K=RIIt%$R;u_5zq zE}32v(?ith{s}#9;kUo!Twd+eVOyi`_+_j;aftit-B^DK{lf3M2>Bki_c8ZYwx9PO znLBd#oU!>Izxv9(-}=ywb|PMmM|&x}vgZNM1D*#w4|pE%Jm7i2^ML08&jX$ZJP&vt z@I2so!1I9T0nY=T2RsjW9`HQyhIk+ltXlOs&5DwpnbGo&(o`WeNQ%X=^6+SOs#MO8 zXHsz)cI|0vF0Ep46@vlHV}(>u%KQ{$!7u56KvOiY)kgz?GpWG*v3kxjMh4IpEhQmsm>>9ojb zeiZE)pW2p71+7*y*s?V%7zxD&L-F8VZNaKHYkozxETa;vnYE;x3=xn!nQA+l)$oU7 zan;Zbi|i<6%R90K+K*HuDi5)4OlGI1%lSff+xX5@t!XqgKPir7Cni#$#R^vH&EP(J zw#O?I!_!kEW7$HgW!jEnIb?Xclmh{|ox4)Aj$_)%V9>OT_JV3OXX>?pYFK8VW*9YH zgK~qn1x!UH*N;zSa@SKQ4~FDKVlYOg^TpC|p(LE0YBlTaq*AdROHrLvkg{{H1W~!) z)@-|OG=(!_L$Nsgcq%uUEpN~6DvVE!mPc|^r9uw6v%2HRXlXl+LNR5)q|lWGzpYw^ zu2&Q*36?ku{+hGb-!Q5zT_e*)a6xx$CyJnGB3CG;nnp^NuZ|?Hj$Iv&Mw6DEl9SbX z2N#JX^=7v=m~6~KEos(MQN|KM-cTfdwH!*?#`5^;3iwLZMGrPmIqC{{!xHo{ZgVIu zC+!wTLK!;}0b~u4U>NTmAXOy=21i3lXP&plquoXWap4HchQ8Ylr;9|obXvRPk9ais zs{xo*T||f?YWw;TinXU7;V3Q&eIIoz*Ab^O^nDGbALHmQ9;fX>?5msoEUxw&`dh26 zX1CRDeQtG?ec^tA6_-F~8H9_)aj{gjO216YZ1f}cxV>$;5sIqyv+OgvbDTL>HR~?S zpvw-+RaeZt{W5Es+b*-#p@3k3A-py}>cZ?XH8)YMKI0;)G`ge61(}tuF2vN9V0!$- zX`EVj0&z@xiJbOQt|j(3^%=K`X4Bn`{FJ+|_MDprFkP>5iyBJ=nQAw>I89Y|IjF6= z?PS}lDaE#NlAcUha;IgV+$sA+M zcYDDx%}7TTM>x(B630zqSeDjwW7`cEvK7Qde4ay&6~| z+EV*X3iVe5&6%!uxYq1&W-{APRbaS)({}a5(v)gLTZ#`fy2INeG|*72y;WnrdwSxI ztT(%-FOFGodnlmJbY~~0p{M_TGXt)^22`^fnaJcOv2W7rj?3|IHQ^Gh8@<|Pm@yTl zyS{{@6r;4dfxt1k(Q6>3(T(1b=a^ofQjF1ZV;rN`YD!b7xaCxImxaIH(*+6@-2mo-R7IWb9S_Q> zC|%A_oG#T$tJ5Ejn9-NeH0s@1$cX^cooR^L+q390(G9a3=tyI_)f=_0w>gdF7BjE( zENEPC)J>zb-58_y9Kg72vpcQ0s zgR0EAC&!Gw6yw%j>qa7uMcC=iX^yJa=iGxhul1hWnUPA{En8{2*^HW-#;Envkjdfk z3Ale6*$(%X(S$7b-CgE~OJk{^Vby{&mZnuTd#_`d!A#vY;dW$FX(~0i@hkFs9>F;b zcdDty?BR5?dD;INMLJ(Gppl#3k3#~z8yD?;!^x}LFv^1SST#murFy8h~4o|^N zG2HPOs-k!AX#;!fmirDbnPyT0<0Dx=y@3nHLqqYaSgCWrv@G8;Y$TK2HatC1Dq|O zcqd6)lY$h~7Ppsj`Rx8?V+Qi+$?{b5)a1-5i5s;gPQ+5nP zhg;(=G2B`AR$nbIY%g$9f6dU9W{uvV_sU_{8BAGlk20qO_f+?~No+TZkkD;l6ub&W za$TuskD^{_*%WhKez=^U7%pwg6(&n#S-2=sOtYaiTmGAz7|CCs;X4ScxdtwlTEOAh zK~;g>1f!{y9nE%vMrBX61vAsqYFax;QRLd()>M^h-U(YJ}tUNjp7*A0-s+axyk(a z4Rl|DPBGZ{*ftJ3H@I5^TREa(Y`BU;j$uKmnz%W+?*s^;WBf3e)yz@6{l(iu0;2mN|ofJ zli32O#5o+aEj385mF?gxT&wa>32HE_O}K_OEL96OG^?hW(SW1sxUu7kO}ZoJ%+_r` z{D)ApG*xjl(6p;GmYZ@%Xis#gEq3i6wBhT@J2~N!DIFnrl(5du&c)QIbAzxBr{%wg#U}jm@cWl|wf@CLb zPmbjZOpKIA*b30Qo=p^S(=prL*52CAv`5;oVpf%kQd3k2w?Zyg>Wej1 zH(J%6bCU>6jK@e2BFUD|XdP&AVAiCy>VSMp$Y*S%X3+xr{eohD-+Pu(#E4<0y| zJVeoBpFHGjo_;u?D`af{v&RqL_}oX}0i=!ZCePUbrvW$i@fW4B{l9i>Y=7(M{=>Is zUmW|*EL0vll7Yv!#`b^X;cLzxCQR0m!#@Sq2eU6e@hD?_EPISTiN)y8B!Bo$@)&!X z=tkCB9Q)Xd>)`>N{eOK9C>q=U7xc-ivD>mQQ_)}j87)u04E1OJW)kF6jPkZm=7Hfc@py!A#|h!t?1^DQB0ZFA*NUf# zdXOh5E?#N(QS8R&-~{sMU-IW61Qd8Top@eOJdb&3o^F<3#HFn4xka`ZuVZn!%nUe1qhBVm%Kq5Af%=(%c(n zcU{U~``R2N0h_!UugUWZklk`e!Itfv;zXuKY#KvniT_CJb%oLya zv~lO%U%%@kA3gZwHwG6TzJlryzi;>>C!vt6Afy!P;Ri2 zPU=9fkS09KX#r*)S~HBV#VDG@0ck-d$ApptZB3vnLrG)xAYdwF5AahC6KJWN8hqMN z?ov_tbutHdi{-SUcGLd2bEHr_{JH{u&kzU=1#E-XGw`APse`5<$W4$qSP%y}euiy= z?lzQbU|Xw0*#JzK1W1Ss!M6=|ii7HvpP2l{o_9ZY-QuI)z3s~V&(6^{(5t?Fz3QrZ zZ}a`}=C|)W_eY0r9jJe3=o3P34fX?U=x!hcc5H*s$@jMgqojggZ0s%VIX`HBxBu5q z?|=I8YoFe|{zng|zqj#L+5-KxovM1}l~i#&AcMyl!wvA=JC9Dz?{t<_!ICTCANP9z z#wq|Aj`&#casSK(NB;EepZ_ppzw3c*=dFGDdbG!MX6fIvdPf2B|1f(_cKl7SW0uWE z1?*XFE>OSRMRs2J=Z{^Jd_MNM8_vl;#UfC5=}(`u{+0EufBz>RJus?YdDoAhdgAbV z$TJ`s#-Z72`)jbH!6*EM6bG}tJFgWMNn#eWmCco3?eiC>sVJ5x;aHlLI=R`-=GD%( z`#zx4@PAwoIpGH23G=ld=w3HaGuGS!&y(l4L8GwUSZ`|MO-IvvP5f=BOmzGt!Tk}P zVf0&u@s7bdLDvM0typyRQDLFJ3|50dz)!8269cBOuTh8JHK`yJYH~YVVfrS=_E8m~uq+2;S@y9FNy&yyF^Y{v;cpdPTmC(Si9sj5k)tx1lpN)6kR zOhuC#swS!J1XC#4nkh9L3tDQlMUm8oF$ZK0WsAfmRiDvY_N-KOY)OG%wn&XeTbgNu zC>zAWCk$WGtRp!M$*cfo!3KxuQnM|YRZ|PqDv|}fswwFW3AU-=S8`3*{|9pvOPwv# zoy~^PluWH+OBK*zX=WMrNvl%RFm(v&Z3ap07IT;uIk~I1^Alg^6S(i*z zZ?yEAsyBhPnjMcyAh`}()l$_is~~L-Ot;|!JLq68H5|Gq%`~9X?NA()nc#-13LSyL zk*eSfAc&Sj9E7EIn2r%hor8{=hN(6|j;)rfuoA<#!*+cgHfSY9v!%AJ%xRJ`2fhl$ zRd9g?+vbw4%+8d-4@#v06GH(PfS)z9!pRL2oUVf}zztPr7Pi3739-{i8mkk(VsD>qwXiN3x9POU3 zV$@)h*JSf?C=m$^C46G6ahk`YeA<^4_z7o|{$&E@6(E%={D2b%osv=ZXk4n)!DbN+ zS4q(X$IR6&r={pV)0hXpz+Vnvw5Xh<&(|CKp|^DGhgOXJuy0B1hrQVMV*hlC{qUPJ z_G72!ydPdM_M=N_^_5v44uL`6DaFetc={$GzD1V*hlC{pedd_TkP6 z?n#%s-%l)!{e&0$UhJPvu^)R&$9`X#ov_CABoAKH+H8# zv`p}OvG1MvPp32g;F~h`Pt{-fR^I84ERFq$7yDl9pH8u#cuU9r$~*nBrLiCLV&9AX z(<%0c-qNwZ@=pKY(%2vLV&9AX(<%00hwH8U)4r9r`iGVV|Bx5_Uhtn*!T;9&ZQm+; z{mX6lg}m_h!vC!v{)9}y@9~oZ__UR;=)eOT$pJ^&LKBz5&*LTfL+&elrCPn390l$;g`$F0r)BN zsAWLLo8&-L3d>R$zGG4}N`KHClHn7MOG86L68si0BvC<9Y)B4E;kXQxgYr;(kbV!! z(%_&Ri%Ww;;h{k(5e^MSq(nrHhNVO-HW-zBI~sXN_>mltBq&9B8t^1V-{C9H zR##}K*S6|lY#(`4OHfhcHE>B^15{|kNX_XqgdmxeEK`mV#T;+Wb{aa2v>|UbmT$<; z%q-uqwcC%-j5vHnO{MARfWovx zCQ3?0%XE7n3;g*=F5d%o^KqB?I3+30kRcAl0JxkJE+?gzoqFK zU;~;}xhy1I?t@e*rNa1DND`FEvP3hE1?d8>8CLgz# zS6e%APHr!+wwG61yiLr@tBr5E^YUtU6H0q|wb^?Yyu8|P{=C|Ryodc&1HLd10Safs)shIG;Fcq{=DRe zLTC_*lI3rklK9(`G@~Zr@1P+$7N&pST;=F_!3X~%lKaZzBod{IKPSs_9CnXo8H|ey zd1yK5kb=JwY$xL7c+`(M9-A$S>|{4Z zU0l4M>xxw?RF~h+91OFO)~JI|jV>;}qYL|mx|sJ)r7kMIqpQk%$S2Ml&@U<;bqx;j zNxH&#g$BbXHC~;pusB{^Jn9;PpGx$MSA~sU*N3lH7Z=~r#iUy}H!2F%d@6NO@f}@# z<5kg4wXUA=8d4xR%}Q~LPUkejxXP*n3~#YJsR8b$-xbQ3d{kDc^p3FHU5|N0zHVh) zen(mV`sxb*Q=p8>M`h{|8`Y(!LFicwUe=sgeqCelw_0Isb7vGrhjLA*RvThd3zs-q zqvt&_jZdvwu1Tm>m@_eYWUbe=r&ul1)KSZ(k2qs$tnV1Kr&?{#IZLbXwH;5?;9_vH zI2Yoma2jD}72V^$CK4x}#7V`JE0wd*$dqu66}iezIAR`zhI-}!JFT7qji{ufv2O~n zUsH*hcM3I9B^`}yc8k$}qx#4$9oYp0beNqMgho2EzDl16~PN>8PTnaCL?nv#M#~nV!CcXHGbYE1X7X5Pjj7r(t$p={ZBbzP>Qw9Zh`g z#Q1`X!0sXjQz`U1HBsRmO{;rtrW#I!LU=l5mB_1LQ1Lv#7*sxG`euMwE0!61j{4wS z)i!SQiJt+^uz>@sdl4Zv-mgyX2j?)$@{RoWdg8|InR|KZNJHU;#rw9r@=-#LAb$1} z7qL3Q_e>l`e13AnHxB|G!FOGx@8j&pGSBn(Y~cGg?nL}<2j7W-@BBD|_yhNTj??3P zuY5n3WBx;s%g6VTn25jouf;n_tX>`sNd!7r*88YwEWOdEDt+8|d2u_(7rYAAS1+Ez?Z2jc9NobW;6{v~dmq-teu;U0nsJEzk}qx^W_7V2vIX9n zMvr%~@2*|+Jp%NQvHc=m?b!X3UmRyI#kg~Anze}io-G5sF7}Te$955wx8p|9*^G;j z3lN@<@W2mvT!{T8VsiV$8(AJgMVpac>??`=o`*K3S&P7L!n*MH-N+~Qn}q&f9OwN> ZpUe5-{a37iVqfbh)*sx!+fhsh{4ca7(-Qyy literal 0 HcmV?d00001 diff --git a/src/processor/testdata/linux_write_to_under_4k.dmp b/src/processor/testdata/linux_write_to_under_4k.dmp new file mode 100644 index 0000000000000000000000000000000000000000..a3ddd621cbbfc89ae4f23a61bd939620d311b53b GIT binary patch literal 44944 zcmeG_3zQqzRnMuLc$J?Mk`O}UPJYEDku>^$TBTaAq8qI2DOPcY_ zNGqE_O-ng(XnImgLrco3&w*1ypb$O{Nkbc#K+{m@2`#52l#hF$#c9(d94IveF!#QX zMjGv|>(l{`J!4Dvz5DL(-S_Sr&D)tf^SSxrhklKaiwPkTeDHYSfhQMPiICSpAqt

D+#7TBwc{6+tedcS|VR^L!Wo19b zWpaW|0N2n?DU`tD7gd3et2x={d|(P3GOq#nT_*Pfac&@Qxsk(9xbUwdw^F^EcQS%3 zr^}YG7wpKwNK8QIw~%Y;7~z;@2W^6e!4td_0&WE~T6gRZm|YTw#?ebDgMe>f>_kAJ z9mS!(wT@eIj8Z@``;ZUk(|z--{l0m$0_zOEA15Rn&vGdE&I25shn(+0PA}kQB!ELe z95+009PpFm?QWPuA~*y@T0Dy1ujo-cNr5i5&qV)1Lq5gN#Hq?VWNP~y)=hd`E z$h9EgDkx{+gMo7s*+a;Y!1ag7Rfma`zy3UObkCmVrh8z*4ITFsH*Ww>Z`|-lS8R~( zzMlN?uk1SFJO2aZ9&~yZ#%?oAlGk5+!3CF3f_9+H0{`ZXxvMuGQnp^6-MGP*|DcpT zbkXIaJ7gmomL-SI+x%s+VbjLX-Tf$=pT{^9${!YS>iaZ}zx%)T*o7E}=iUEHv@YoW z^$AuV(33wLX+Ol}_Bk{-eCET9Pv{r&)}pWc{^+_v$kF}HKRS6*@Cp4Ndl!={?7jE{ zTizpR5DG`!eF3wxzr^UT`05U7_h#PjJ-5f{+9%`{ORR3E|L#eYgKoqF*K0hoFF!{4 zuUcmE_Hg-oxV#guOw)EDZ|f^FwEkaT$i-wxf98BvM-{zNAs6F>_xic5`Y5k#heUFMh#PN9EK|XOv|IGaUg}-F@ zuS{fV(|wmP{*P>8bwr{dKYUSvh=5~;&qql>E>F-%uV?e*3mX{xV3Un6<0eGt7xV%z z>Vi+;Pw;+-x}Xzvp-=ch^jr8<^bgO6f(N1Sm+*sV>p)>eQ~>@x*DvhIb`{!s7kr~% zg}pzG9vh8I(Vu5I{*F&Ee+j(c6HwS~aC*UaoY$|s>4A~) z7JPzU)c2Uot{F+AC=s8cKWR?*ws@A7F8wsKTgY+SC-L@wd;_B=k2CrYvC}sZ?VsJk z+QoQ?@!Q1dalW8z{2isA?ylP~me$fS?U z7eXM+>A6n$UqCSq0t$N354V3ryMTXk$qRIy5_RDhtfS3axc@}^mmYZM^;iE*{JW=; z`=tlox^w@Qr+r^~;1jnV{o>sh3Vt_~ub8ALp%-E5T_ze!P{5F#pK^-o0M~)xi zwdX#|{Pjj&f06rzFWcmK-af)ST>0FEbGJr*z4V)b%P#6XaPXhz`^k7Uj#u#B;d#LG zfad|v1D*#w4|pE%Jm7i2^ML08&jX$ZJP&vt@I2so!1I9T0nY=T2RsjW9`HPH<~$Gx z*3D*5GecxoZo0a&vQWw-NVz;yot(}uRI0_x!*FrK@!6rnW-L`MKGJ#a-3eh1p7GcfL%f z<`yd`VRpVcU&t-a{^-`jD%u|P&~L# zJ76|D4Zk9rrd|s+j7C~chX}}>&-880Z2QBpxT?2wlkBYIt2^^0>_;XNl~c4E^ZA9v zYO$2xKD#T^=;&?DPs%g-xw#BzF@v>cCwS0W9`efE z*Y3=+Z5viP7&J`1e?ZkcOU*_=)lDPN(Dg=3gL0d-1q?+ccg!y23U{EB6CpX7OvK1y zv0RxfRfMxM-A=QgR%(`QDyp3cB0KX+kSq6Fnq@Whj&MdS6^p~oa)tSPbw_@8X?9_{ zI#pPxlnT(D^&Lm1D?9iolruU^ik5P~Z>grT zZ;?Z3OJ5ydUjtvOyXe6Nl%uYJ*G)kmV>XB4a@y)LB$RnaB7kggBpAke2S`=PfWgsF z+FoI;@u<_Nb6hyWWkcUBo6$ug4xQE?_#+-o|9Ajqm4gT&qH%B(p_qF|5w_x@XdOhi zG97W0(K^^xMlp8F#bftfh=WaIl*QHl_R-e5tJ!U}Tc2B9?O=FRV9h1aUIpP|v0W^6 ztu`vtG}@zxy>4%tZiJ$0qbvt?XO2_nsz%d=Nx1AVU3JCSH!8ECx$QC<0}2QR7{c3% z(=N=PYP2 zhEpYH!ZLH3sxx&M#vWP_!qFITnRQ1p!{{qcFBqm18K`0i+a4pa-6XncY8^MW-*z$1 zEBmyiX3L2Js-UzgHm9rmG;^G~)@`=xficmhI%-mAv>NCvIo@Gf^OL#x{3un4;sSQx z)e}=w>TPWtA80$nJ0vvFR?K~MeZ@IFF-JB#&gqL`4!AuOP?wz9$!PHOKWb*c)z^S( zIFZSj+$7fiR?~Jl9)3-@1h@2I?J~@mn&PZ4;V5F1t`i6h)6$0xM4Fa9Jn{@P>{G<( zT{p(ohpk4MTFot|)^b_+Q$t+pMO zZ45Q+L}W4!xVxdY6w3)B!_PDODzLvdWHmF}QF46)Q2qiHvtS;&Y0m?bcTYH8g`F-BwTI7lyr;uwH--wk1-19NG5YYr%mqc=%A#(rwlRk4>CSHl){p(poMed3 z@M(eST4}o_E0)_G=FrKOGMVk3Th&s_J*Z00Jvo+I;~2O0h7*Z=EW)-krx~i=?70VV zMH@c1QzMnWTei}1v*`^tjouigA@h^7b8!7MwF9m#qe)pFxwXzAF2xEzD4VSd>=Ke+%G#c;)=t4hncrVZ?Cn(iySbe2jD%ueO~cmWrT zhf?udXlZc0v?|{!Y$TW8KDjtoDf2GkC8@Qnm|C!b=NEo87^rJYO1EXhs%bA%f5JuI z_StE?Dlcb(nym)=^#*?Y?D8>9uWgwiekF;mX+a8V%R4HCqH`h2uElZeGQqmm3wFA# z7GZ8jo0wbJRc>$@E}|V50lA^uRa@6vaB1ui!)&t3Nb!yw+d){*HSlAp3mmo;R2A4w&^uby)+{@y*Y?)CFf&c9q4k4^BDWQ` zW$LJT7i^WxZl8s1j7+xK&QNPculRA_1~vksWNs3EMQfevVmYu_+3ru0>D+wPK|&}l zz~)V%w0r&8)rS2W#n#OOY<^7@=8Lm$$9)ByVzBYCeHM0Z_-+ks<%ouv$#OmuLY=N1 zogJlZv8kzrN$?omGQy1sm7Z6F`^;KQRjX`kr#hWT)^>M93|4j*^L&Sf?|Q&S&D_p8 z&@lrW9;fs+UuY&P8B4>J03ERiLCrjrhS?1JC9pGPR%(s?C23nG@V4q?RgrGbRIOX@ zN|SByGjm6A^0bDPPt_Xy65VGgbyAGZ=S!fH&*7kDszLm%Yz3F$w<-&jpa!$rfZx!% zscONtW;Qe<8nD$C-`H`*Cho}D%T3D<{~^>&O;v0SH0`d;6c*eOIusphm;Uw-TJZZ) z?ZV`1HxFuLt}smpX0TEbKHS@87lvjD1VxZc?JQSI<(UkupCq?!u`E`LDwZd6xe~0M z?ky}_Z*dy?8+i+M3A=lvc{(m)6A_jxXN?aaJaKIjA2+ALNhuPt+=B&2Zj`i z`Gw3~(qK~$d~O*{Lz8Z@$m{}ayDd!RGq7v8tCB0gGPjUvw*71ekJ?vST&T>#t{UCv zbnT>(+-w;Zg58-kJ0(pmmP)vP$_Fa5h+$^j`nH~&Sk)3N{i0Ig5{3S9sRh^uDSLU0J`Tq9) zwtlWZ)rS?cuGEx%RY$ zJm~DYJ0-EFU%8HK_?IUyePfo)yf<^-0z7VFZ+R3OXWnNAHPvG-+NdFXldhAY$FVFn+3!C79tizwV2vp1*{uDlGH*;_P zB^3IZ|G@I%OHe=d*?EwR$gTfQk;i84ecxuv@>RtC9hwhhSpHc^Y#>BDM5#YTDerw> z5g48lkHZLeoDyD0pAaV`GDLa)dEzOuA>=8F;`u{CCZ2l~b@CW{{$&7pgPTq~A1R){ zJ^G96IYaS$j(Fa2AeR@e;?L{7TRb4-A~*yO-mLwUp^Nx6tim9T95=a+Q>h+dhRUhv zU!!(3gFZL<8p-#>dLE!2V9)DinKuk)T`J!8>Kr5io4g+HeJq~@*&`1WY~3*^o>t)| zq+XBr<>&b`$Zs9UJ+dDCfNH#ey87$!X5Yk~SKkAtM1EX7CrYOW-vs0@uczw>%PB!# z4h#f;rQ}{xjuw&_`3n{SBW0njq;C zij|SNuf{<+o`MQ*%Lu`;1q;d=> z+0fPjx+;`3S`PxIM)m?fau`61avJdIL)oE1`AyOTyh%dbG1wn>P8@84yDQ*+hCnD4 zuym~F;Dh~Xf~FwIO_DfR5Qp4Yev0jY?mm`*dj9i! z-}wCPho1cEy*D5JMi1LSulj@QRoB&fukY8cxNO%Y-#mKvMDv}gpAmW+upeMScLV5~ z?eIDM{x)EgRPc+%dy7412ljWzzkTnM&)#_3vwJpu^NH+pm)?yn&|k~0t2f__isJzp zJWd(j4&TG`==A)Kv!o7|+zkJi-vcmK0mx{@#)8e`4_$ryw=aCgQGk3;)SlBFe*^4Trn6B2dsdqZ=$DU^UDy2HQ@5tS75nJhFDibSMqtaO zKYQBx*Veb`t?zsC$aL%GkALUOPd{@VIR>I(96H^;zX3ZMY{FlIIGF9uyjEx=iCIin zHdlVN`>)NSD4H1KM3$BYx!Epc)xo#>I$+T7zg!SG;U*xXzL#>MC5- z>*hpSl6^g`Q`gOEvktZ4p7>OwD=jJQX6pd7#C>qfk=B~PVuY2Yj?&hkPW!#J^k!+7 zrgsod6&Iy^%pZ!!WT_XCvQi`vlc#46`Yc;B47g1Un8Lnx6YgtLK`7MZez->U&CeV} z6``;!2V`0H(G5w-f=w~R#v*Z9+Of@NEFZ9%@FxI?8ZG;*W)0?O!=ju%xYtX=7L-ec zA_CjuKE-INq6Pk-Y&Ss$$06~O(M7HUnuW!x)>k#dh8w#$4jj^~OD(Mjen4w{E5?Al zrGR?C0-w}tYf@d43`>)2OO@J|DH)0;wN*`0`$?)$vNS_#+a|O$utky7w%!9W8`&ap zNo_5)y4JE(w=GG5J6oi7yDu&EL6ikz;S+{0Y1x+Swq(=*bHDTL{D5knx#huNz-jNKgW=S>BVQNMd_DSnfM>kqhAO7G2H|sSH zKowYZgK<(W{E{^M8xZ!@=rkomZMD0t{q_A|t!Ble5=d^sR<%^Oswzn9f$0`}UW#6Vc;hjENRY7aVU=!V(>IhI3th z8AAQg%Qg%#RKpTTw4`RIhu!nl^agD58gxFUl950v=@Vnkr+GZerhQd`TR1!TmkF3x zfK=*m11AhRk|BFEF4dY~vxtUUq-c_1dQH>rDlMO(uYh0RF9$GMC@1an4aa`ytd9NA znz0}Djm3W0i+wNl&!yN8pVhG+UNiQi$a*1om3`cvb_ljV?vf}~hV4ol&<43r5u6;I%ILY5K< zITn`^sc193A`Edm79&*(-U$KlI@0*5v&$FFdFbA#mM0+FW1*- zXg0RBz}OM;sFp-gvkh>`NCQ-`VX9#d8bXjvN|uphN-<_T%Y%jiBQ_Mx_UaA!rKQyy zwmJO>Es4Wd)>KSK2Q0oRqiew(^DVgL9eRuuw+OOz3L|XQR@1_s_(Rc%Z(eH;$rIM! z!V961cERZD=`Bc?te6L?D&#?|S}RQ(64k-bgnjTJ#X7C@v7sBJ8)xfjDabR>u(UN1 zo)v?pamF;pL8EIJnvH0h4+;|!!vhyVmJ-+s;u8swtq79zLHt|6mR0kcT1x|LKr?GM zgrpmNkSe88n%xFTf^vD9XvQ|-*@XiGJmgH7D$N!vn40!fDCfp zu*LzVl%LDfghNQ|n=TZl=kjA(I2yR8c^3qwV85Oz3(KLHoT%iY{?PRUk^-bT;wi}l zu2PzWEMoA4ORc5(z?1Hb9$sE;FR!+jR~r+1dwI2K(r}tC+RLj=-QeZbrfI#syxJof zvc0_8US4hX@(9d)?&a0y?}?x}yuG~IUS4fBA9yZjFR%8nJG{KwUS920@^O24wY5{{ zAkmFR?mJh6$MGc{^_&0QkEZ{qvF^ z3ZVoPCDY$GB=NT=X-Q4P-$6ri4F0^AV1GMY{d?#IAMB4v?q43KktkjKIa!wDuzM`a zU|d`n=cmR|^#8qa=rC#={smGpSGaN1kN?-6i$Oj+YFr{RY#fxqRCw_wey={1!`OGg z>nV&oeTk*ml3c5$Qo!tI6*Z-yr19wzg1_5E!x1?(EJu_f1%EBrPsXe9sGsL}>~s-1 z$ZpDYG4WiNma3yJzn?l7W+T?n!DmJn6F<w#l#PE(YayrxlyCN zJd?Um{6N>pc-81kIg`4E#w#4BGfylkU)*WDYi{0?Rit?HR?4;in z%BXy*xJq~5)SlOOfec^C*1S3)?}b3xul4rVYp^Yxl%dvd61w=xW-h9jyylr z$sy_|XNifxZD6Y$r>T)C8E71t0`zVwG4sw?A5)`!9R0oY8ubyC4Em_jaa?cUQz@ho z3^lgWuXVPB+y7QM))#qco5` znvM&rtP=X-{JYB7Gt@hJbxXg~CvF2=TB2tY**}b6mXFM=HRZme$FnToiFcVf$FbjF z<>PII6^ft#`pI__a-8FrD{)#U{5=ydb9}M=QT9F!{;rGcZ!-21^&Z3X_icQHIf4>3=X4i7i{JVOug6MQ2^(7lP*#eRu#WtMV? z{gPk3Vv^Rye#lmMUm6}iO1~Yu@I3-}$h`dxtU9p!yZ?QXz7*pl=VfV&*zego!RliF z=nK4EMCAwgM$v_oi;$~1ypqEs8~%{`L+mdRgV`tE$nq#xbOomu`$}TJ=g~{Ev_;@I q^Sbc&gPc$7Hwpd!eUkMjdkN!*_g~TeiG8h?dHs=#Svwaq0RIE1r;$DY literal 0 HcmV?d00001