audit
無料Hypothesis-driven, tool-grounded security review of coverage gaps
日本語の概要は準備中です。原文の説明を表示しています。
Deterministic debugging with rr record-replay. Use when debugging crashes, ASAN faults, or when reverse execution is needed. Provides reverse-next, reverse-step, reverse-continue commands and crash trace extraction.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
rr provides deterministic record-replay debugging with full reverse execution capabilities.
Record: rr record <program> [args]
Sandbox exemption (documented decision): rr needs ptrace and perf counters, which libexec/raptor-run-sandboxed denies, so recording runs the untrusted binary unsandboxed — behavior observed under earlier sandboxed runs says nothing about what the payload does with this ambient authority. Keep the recorded invocation to exactly the reproduced crash command (never a broader test suite or build), and treat any unexpected network or filesystem activity during recording as a finding in itself. Replay carries no such residual: it re-executes the recorded trace under gdb, not the binary against the host.
Replay: rr replay -- -nx -iex 'set auto-load off' -iex 'set auto-load safe-path /dev/null' (enters gdb interface with reverse execution). The flags after -- go to gdb and disable auto-load with no trusted directory: the recorded binary is untrusted, and a permissive gdb config (e.g. an operator ~/.gdbinit widening auto-load safe-path) would otherwise execute scripts the binary or its build tree plants (.debug_gdb_scripts, *-gdb.py). Same hardening set as scripts/crash_trace.py — use it on EVERY manual replay.
All standard gdb commands work, plus reverse variants:
reverse-next / rn: Step back over function callsreverse-step / rs: Step back into functionsreverse-continue / rc: Continue backward to previous breakpointreverse-stepi / rsi: Step back one instructionreverse-nexti / rni: Step back over one instructionAfter rr record <crashing-program>:
rr replay -- -nx -iex 'set auto-load off' -iex 'set auto-load safe-path /dev/null'
# In gdb:
reverse-next 100 # Go back 100 steps (adjust N as needed)
# Now step forward to see execution leading to crash:
next
next
...
After rr record <asan-program>:
rr replay -- -nx -iex 'set auto-load off' -iex 'set auto-load safe-path /dev/null'
# In gdb:
bt # View stack trace
up # Issue "up" commands until last app frame (before ASAN runtime)
break *$pc # Set breakpoint at that location
reverse-continue # Go back to last app instruction before ASAN
# Now step forward to see execution leading to fault:
next
next
...
Standard gdb commands work at any point:
print <var>: Print variable valueprint *<ptr>: Dereference pointerx/<format> <address>: Examine memory
x/10xb <addr>: 10 bytes in hexx/s <addr>: String at addressinfo locals: Show local variablesinfo args: Show function argumentslist: Show source code around current locationdisassemble: Show assembly around current locationlayout src: TUI source viewlayout asm: TUI assembly viewset disassemble-next-line on: Show assembly with each stepUse scripts/crash_trace.py to automatically extract execution trace before crash.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Hypothesis-driven, tool-grounded security review of coverage gaps
日本語の概要は準備中です。原文の説明を表示しています。
Add gcov code coverage instrumentation to C/C++ projects
日本語の概要は準備中です。原文の説明を表示しています。
Provides adversarial code comprehension for security research, mapping architecture, tracing data flows, and hunting vulnerability variants to build ground-truth understanding before or alongside static analysis.
日本語の概要は準備中です。原文の説明を表示しています。
Multi-stage pipeline for validating that vulnerability findings are real, reachable, and exploitable, preventing wasted effort on hallucinated findings, dead code paths, or findings with unrealistic preconditions.
日本語の概要は準備中です。原文の説明を表示しています。
Dynamic instrumentation via Frida - attach to or spawn a process, load a JS hook script, capture send() events into a lifecycle-managed run directory. Supports local, USB-attached, and remote frida-server targets.
日本語の概要は準備中です。原文の説明を表示しています。
Instrument C/C++ with -finstrument-functions for execution tracing and Perfetto visualisation
日本語の概要は準備中です。原文の説明を表示しています。