Patch from CDN to add support for an exploitability engine

A=cdn
R=nealsid



git-svn-id: http://google-breakpad.googlecode.com/svn/trunk@662 4c0a9323-5329-0410-9bdc-e9ce6186880e
This commit is contained in:
nealsid 2010-08-24 14:28:10 +00:00
parent 3b7d8ee362
commit 8d2c518c0b
7 changed files with 286 additions and 10 deletions

View file

@ -0,0 +1,89 @@
// Copyright (c) 2010 Google Inc.
// All rights reserved.
//
// Redistribution and use in source and binary forms, with or without
// modification, are permitted provided that the following conditions are
// met:
//
// * Redistributions of source code must retain the above copyright
// notice, this list of conditions and the following disclaimer.
// * Redistributions in binary form must reproduce the above
// copyright notice, this list of conditions and the following disclaimer
// in the documentation and/or other materials provided with the
// distribution.
// * Neither the name of Google Inc. nor the names of its
// contributors may be used to endorse or promote products derived from
// this software without specific prior written permission.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
// "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
// LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
// A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
// OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
// SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
// LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
// DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
// (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
// OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
// exploitability_engine.cc: Generic exploitability engine.
//
// See exploitable_engine.h for documentation.
//
// Author: Cris Neckar
#include <cassert>
#include "google_breakpad/processor/exploitability.h"
#include "google_breakpad/processor/minidump.h"
#include "google_breakpad/processor/process_state.h"
#include "processor/logging.h"
#include "processor/scoped_ptr.h"
namespace google_breakpad {
Exploitability::Exploitability(Minidump *dump,
ProcessState *process_state)
: dump_(dump),
process_state_(process_state) {}
ExploitabilityRating Exploitability::CheckExploitability() {
return CheckPlatformExploitability();
}
Exploitability *Exploitability::ExploitabilityForPlatform(
Minidump *dump,
ProcessState *process_state) {
Exploitability *platform_exploitability = NULL;
MinidumpSystemInfo *minidump_system_info = dump->GetSystemInfo();
if (!minidump_system_info)
return NULL;
const MDRawSystemInfo *raw_system_info =
minidump_system_info->system_info();
if (!raw_system_info)
return NULL;
switch (raw_system_info->platform_id) {
case MD_OS_WIN32_NT:
case MD_OS_WIN32_WINDOWS:
case MD_OS_UNIX:
case MD_OS_MAC_OS_X:
case MD_OS_LINUX:
case MD_OS_SOLARIS:
default: {
platform_exploitability = NULL;
break;
}
}
BPLOG_IF(ERROR, !platform_exploitability) <<
"No Exploitability module for platform: " <<
process_state->system_info()->os;
return platform_exploitability;
}
} // namespace google_breakpad

View file

@ -35,6 +35,7 @@
#include "google_breakpad/processor/call_stack.h"
#include "google_breakpad/processor/minidump.h"
#include "google_breakpad/processor/process_state.h"
#include "google_breakpad/processor/exploitability.h"
#include "processor/logging.h"
#include "processor/scoped_ptr.h"
#include "processor/stackwalker_x86.h"
@ -43,7 +44,15 @@ namespace google_breakpad {
MinidumpProcessor::MinidumpProcessor(SymbolSupplier *supplier,
SourceLineResolverInterface *resolver)
: supplier_(supplier), resolver_(resolver) {
: supplier_(supplier), resolver_(resolver),
enable_exploitability_(false) {
}
MinidumpProcessor::MinidumpProcessor(SymbolSupplier *supplier,
SourceLineResolverInterface *resolver,
bool enable_exploitability)
: supplier_(supplier), resolver_(resolver),
enable_exploitability_(enable_exploitability) {
}
MinidumpProcessor::~MinidumpProcessor() {
@ -230,6 +239,22 @@ ProcessResult MinidumpProcessor::Process(
process_state->requesting_thread_ = -1;
}
// Exploitability defaults to EXPLOITABILITY_NOT_ANALYZED
process_state->exploitability_ = EXPLOITABILITY_NOT_ANALYZED;
// If an exploitability run was requested we perform the platform specific
// rating.
if (enable_exploitability_) {
scoped_ptr<Exploitability> exploitability(
Exploitability::ExploitabilityForPlatform(dump, process_state));
// The engine will be null if the platform is not supported
if (exploitability != NULL) {
process_state->exploitability_ = exploitability->CheckExploitability();
} else {
process_state->exploitability_ = EXPLOITABILITY_ERR_NOENGINE;
}
}
BPLOG(INFO) << "Processed " << dump->path();
return PROCESS_OK;
}

View file

@ -245,6 +245,24 @@ TEST_F(MinidumpProcessorTest, TestSymbolSupplierLookupCounts) {
google_breakpad::PROCESS_OK);
}
TEST_F(MinidumpProcessorTest, TestExploitilityEngine) {
TestSymbolSupplier supplier;
BasicSourceLineResolver resolver;
MinidumpProcessor processor(&supplier, &resolver, true);
string minidump_file = string(getenv("srcdir") ? getenv("srcdir") : ".") +
"/src/processor/testdata/minidump2.dmp";
ProcessState state;
ASSERT_EQ(processor.Process(minidump_file, &state),
google_breakpad::PROCESS_OK);
// Test that exploitability module correctly fails to supply
// an engine for this platform
ASSERT_EQ(google_breakpad::EXPLOITABILITY_ERR_NOENGINE,
state.exploitability());
}
TEST_F(MinidumpProcessorTest, TestBasicProcessing) {
TestSymbolSupplier supplier;
BasicSourceLineResolver resolver;
@ -315,6 +333,11 @@ TEST_F(MinidumpProcessorTest, TestBasicProcessing) {
ASSERT_EQ(state.modules()->GetModuleForAddress(0x77d43210)->version(),
"5.1.2600.2622");
// Test that disabled exploitability engine defaults to
// EXPLOITABILITY_NOT_ANALYZED.
ASSERT_EQ(google_breakpad::EXPLOITABILITY_NOT_ANALYZED,
state.exploitability());
// Test that the symbol supplier can interrupt processing
state.Clear();
supplier.set_interrupt(true);