Added a maximize objective API to DeepState.

This commit is contained in:
Peter Goodman
2017-12-10 13:37:47 -05:00
parent 188d4517d8
commit fcd000dc14
6 changed files with 68 additions and 15 deletions
+6 -3
View File
@@ -93,6 +93,9 @@ class DeepState(object):
def concretize_min(self, val, constrain=False):
raise NotImplementedError("Must be implemented by engine.")
def concretize_max(self, val, constrain=False):
raise NotImplementedError("Must be implemented by engine.")
def concretize_many(self, val, max_num):
raise NotImplementedError("Must be implemented by engine.")
@@ -383,10 +386,10 @@ class DeepState(object):
minimum satisfiable value for `arg`."""
return self.concretize_min(arg, constrain=False)
def api_min_int(self, arg):
"""Implements the `DeepState_MinInt` API function, which returns the
def api_max_uint(self, arg):
"""Implements the `DeepState_MaxUInt` API function, which returns the
minimum satisfiable value for `arg`."""
return self.concretize_min(arg + 2**31, constrain=False)
return self.concretize_max(arg, constrain=False)
def api_is_symbolic_uint(self, arg):
"""Implements the `DeepState_IsSymbolicUInt` API, which returns whether or
+12 -4
View File
@@ -107,6 +107,14 @@ class DeepAngr(DeepState):
self.add_constraint(val == concrete_val)
return concrete_val
def concretize_max(self, val, constrain=False):
if isinstance(val, (int, long)):
return val
concrete_val = self.state.solver.max(val)
if constrain:
self.add_constraint(val == concrete_val)
return concrete_val
def concretize_many(self, val, max_num):
assert 0 < max_num
if isinstance(val, (int, long)):
@@ -197,11 +205,11 @@ class MinUInt(angr.SimProcedure):
return DeepAngr(procedure=self).api_min_uint(val)
class MinInt(angr.SimProcedure):
"""Implements the `Deeptate_MinUInt` API function, which lets the
class MaxUInt(angr.SimProcedure):
"""Implements the `Deeptate_MaxUInt` API function, which lets the
programmer ask for the minimum satisfiable value of a signed integer."""
def run(self, val):
return DeepAngr(procedure=self).api_min_int(val)
return DeepAngr(procedure=self).api_max_uint(val)
class StreamInt(angr.SimProcedure):
@@ -340,7 +348,7 @@ def main():
hook_function(project, apis['ConcretizeData'], ConcretizeData)
hook_function(project, apis['ConcretizeCStr'], ConcretizeCStr)
hook_function(project, apis['MinUInt'], MinUInt)
hook_function(project, apis['MinInt'], MinInt)
hook_function(project, apis['MaxUInt'], MaxUInt)
hook_function(project, apis['Assume'], Assume)
hook_function(project, apis['Pass'], Pass)
hook_function(project, apis['Fail'], Fail)
+12 -4
View File
@@ -106,6 +106,14 @@ class DeepManticore(DeepState):
self.add_constraint(val == concrete_val)
return concrete_val
def concretize_max(self, val, constrain=False):
if isinstance(val, (int, long)):
return val
concrete_val = max(self.state.concretize(val, policy='MINMAX'))
if constrain:
self.add_constraint(val == concrete_val)
return concrete_val
def concretize_many(self, val, max_num):
assert 0 < max_num
if isinstance(val, (int, long)):
@@ -212,10 +220,10 @@ def hook_MinUInt(self, val):
return DeepAngr(procedure=self).api_min_uint(val)
def hook_MinInt(self, val):
"""Implements the `Deeptate_MinUInt` API function, which lets the
def hook_MaxUInt(self, val):
"""Implements the `Deeptate_MaxUInt` API function, which lets the
programmer ask for the minimum satisfiable value of a signed integer."""
return DeepAngr(procedure=self).api_min_int(val)
return DeepAngr(procedure=self).api_max_uint(val)
def hook_Log(state, level, ea):
@@ -253,7 +261,7 @@ def do_run_test(state, apis, test):
m.add_hook(apis['ConcretizeData'], hook(hook_ConcretizeData))
m.add_hook(apis['ConcretizeCStr'], hook(hook_ConcretizeCStr))
m.add_hook(apis['MinUInt'], hook(hook_MinUInt))
m.add_hook(apis['MinInt'], hook(hook_MinInt))
m.add_hook(apis['MaxUInt'], hook(hook_MaxUInt))
m.add_hook(apis['Assume'], hook(hook_Assume))
m.add_hook(apis['Pass'], hook(hook_Pass))
m.add_hook(apis['Fail'], hook(hook_Fail))