Comments (2)
Yes I think the additional modes are helpful. The following snippet for tritonToZ3.cpp
may help
case ARRAY_NODE: {
auto size = triton::ast::getInteger<triton::uint32>(node->getChildren()[0]);
auto isort = this->context.bv_sort(size);
if(MODE.MEMORY_CONST_ARRAY){
auto value = this->context.bv_val(0, 8);
return to_expr(this->context, Z3_mk_const_array(this->context, isort, value));
} else if(MODE.MEMORY_ARRAY){
auto vsort = this->context.bv_sort(8);
auto arraySort = this->context.array_sort(isort, vsort);
return this->context.constant("memory", arraySort);
}
}
(Of course, the model collecting mechanism in z3solver.cpp
and other related codes may need additional adjustment, since it will result in non-bv sort elements like memory
).
from triton.
Indeed, this is because we consider array as const array
with a default value 0
, like it's pretty much the case when you spawn a process with uninitialized memory. We chosen to define this array as const, otherwise every cell's content is consider as symbolic by the SMT solver which is problematic in several cases.
However, I understand that for some cases, you might want to have these cell's content symbolic. Maybe we can have two modes for this, like MEMORY_CONST_ARRAY
and MEMORY_ARRAY
?
from triton.
Related Issues (20)
- Once contain “inc edi” or “dec edi”,TritonContext.disassembly(block, start) generate TypeError: x8664Cpu::disassembly(): Failed to disassemble the given code. HOT 3
- Will a new official version be released soon? HOT 3
- Problem with getWrittenRegisters() in aarch64
- ARM32 - `ADR` Instruction incorrect behaviour HOT 3
- Why is this POC yielding these results? HOT 2
- Failed to build with the library HOT 5
- Clarification regarding MEMORY_ARRAY mode HOT 7
- symbolizeRegister result is different with setConcreteRegisterValue result ?
- How to determine if a concrete register value is known? HOT 2
- fails to build against LLVM-18
- [OSX ERROR] SystemError: initialization of triton did not return an extension module HOT 7
- lea semantic bugg ?
- LDRSW instruction error ?
- Incorrectly handled x86 instruction, rcl memory, immediate HOT 2
- Trying to collect symbolic address from MemoryAccess HOT 2
- Add Dissasembly callbacks? HOT 2
- Is it possible to symbolize arbitrary memory access before the actual processing? HOT 1
- Building errors on python3.12
- Cannot build using lastest Bitwuzla version HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from triton.