Skip to content

Instantly share code, notes, and snippets.

@KJTsanaktsidis
Created September 2, 2024 01:08
Show Gist options
  • Save KJTsanaktsidis/5102807d2c9aab383c02d906320db37a to your computer and use it in GitHub Desktop.
Save KJTsanaktsidis/5102807d2c9aab383c02d906320db37a to your computer and use it in GitHub Desktop.
[INFO log_pending_events()] (no pending events)
[RecordSession] 1142629: handle_ptrace_event PTRACE_EVENT_SECCOMP: event (none)
[RecordSession] traced syscall entered: execve
[RecordSession] EXEC_SYSCALL_ENTRY: status=0x7057f (PTRACE_EVENT_SECCOMP)
[RecordTask] Wrote event SYSCALLBUF_FLUSH for time 42069
[RecordTask] Syscallbuf flushed with num_rec_bytes=80
[RecordTask] Wrote event SYSCALL: execve for time 42070
[RecordTask] Syscallbuf reset
[RecordTask] Wrote event SYSCALLBUF_RESET for time 42071
[RecordSession] after cont: status=0x7057f (PTRACE_EVENT_SECCOMP)
[RecordSession] EXEC_START: status=0x7057f (PTRACE_EVENT_SECCOMP)
[Task] resuming execution of 1142629 with PTRACE_SYSCALL tick_period -2 wait 0
[Task] Flushing registers for tid 1142629 { ip:0x70000002 args:(0x73dc5787cc28,0x561ba9b04078,0x561ba99a1ac0,0x2,0,89555749627328) orig_syscall: 59 syscallno: -38 }
[Scheduler] Starting 1142629
[Scheduler] Scheduling next task (ALLOW_SWITCH)
[Scheduler] all tasks blocked, waiting for runnable (482 total)
[Scheduler] 1142629 changed status to 0x4057f (PTRACE_EVENT_EXEC)
[Task] Task 1142629 changed status to 0x4057f (PTRACE_EVENT_EXEC)
[Task] (refreshing register cache)
[Scheduler] Stopping 1142629
[Task] Requesting registers from tracee 1142629
[RecordSession] trace time 42072: Active task is 1142629. Events:
[INFO log_pending_events()] SYSCALL: execve
[INFO log_pending_events()] (none)
[RecordSession] 1142629: handle_ptrace_event PTRACE_EVENT_EXEC: event SYSCALL: execve
[WARN post_exec()] Unmapping buffers using tid 1142502
[AutoRemoteSyscalls] syscall munmap { ip:0x7000000f args:(0x7fa9ca400000,0x200000,0x8,0,0,0) orig_syscall: 0 syscallno: 8 }
[RecordTask] Set signal mask for 1142502 to block all signals (bar SYSCALLBUF_DESCHED_SIGNAL/TIME_SLICE_SIGNAL) while we have a stashed signal
[Task] resuming execution of 1142502 with PTRACE_SINGLESTEP tick_period -2 wait 2
[Task] Flushing registers for tid 1142502 { ip:0x7000000f args:(0x7fa9ca400000,0x200000,0x8,0,0,0) orig_syscall: 11 syscallno: 11 }
[Scheduler] Starting 1142502
[Task] going into blocking wait for 1142502 ...
[Task] Task 1142502 changed status to 0x1e7f (STOP-SIGPWR)
[Task] (refreshing register cache)
[Scheduler] Stopping 1142502
[Task] Requesting registers from tracee 1142502
[AutoRemoteSyscalls] Used singlestep path; status=0x1e7f (STOP-SIGPWR)
[RecordTask] Set signal mask for 1142502 to block all signals (bar SYSCALLBUF_DESCHED_SIGNAL/TIME_SLICE_SIGNAL) while we have a stashed signal
[Task] resuming execution of 1142502 with PTRACE_SINGLESTEP tick_period -2 wait 2
[Scheduler] Starting 1142502
[Task] going into blocking wait for 1142502 ...
[Task] Task 1142502 changed status to 0x1e7f (STOP-SIGPWR)
[Task] (refreshing register cache)
[Scheduler] Stopping 1142502
[Task] Requesting registers from tracee 1142502
[AutoRemoteSyscalls] Used singlestep path; status=0x1e7f (STOP-SIGPWR)
[RecordTask] Set signal mask for 1142502 to block all signals (bar SYSCALLBUF_DESCHED_SIGNAL/TIME_SLICE_SIGNAL) while we have a stashed signal
[Task] resuming execution of 1142502 with PTRACE_SINGLESTEP tick_period -2 wait 2
[Scheduler] Starting 1142502
[Task] going into blocking wait for 1142502 ...
[Task] Task 1142502 changed status to 0x1e7f (STOP-SIGPWR)
[Task] (refreshing register cache)
[Scheduler] Stopping 1142502
[Task] Requesting registers from tracee 1142502
[AutoRemoteSyscalls] Used singlestep path; status=0x1e7f (STOP-SIGPWR)
[RecordTask] Set signal mask for 1142502 to block all signals (bar SYSCALLBUF_DESCHED_SIGNAL/TIME_SLICE_SIGNAL) while we have a stashed signal
[Task] resuming execution of 1142502 with PTRACE_SINGLESTEP tick_period -2 wait 2
[Scheduler] Starting 1142502
[Task] going into blocking wait for 1142502 ...
[Task] Task 1142502 changed status to 0x1e7f (STOP-SIGPWR)
[Task] (refreshing register cache)
[Scheduler] Stopping 1142502
[Task] Requesting registers from tracee 1142502
[AutoRemoteSyscalls] Used singlestep path; status=0x1e7f (STOP-SIGPWR)
[RecordTask] Set signal mask for 1142502 to block all signals (bar SYSCALLBUF_DESCHED_SIGNAL/TIME_SLICE_SIGNAL) while we have a stashed signa
.....
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment