00cc9309cb
de6e324bdseparate emu thread10d3daf86Roms List improvements95d202f37Let's make the rom list process on a separate thread so the emulator doesnt take ages to load.fc306967fWow the ROM Header was just completely busted. Game list view works nowbad1691eefuck this shit2b59e5f46game list in progressd26417b83remappable inputs in progressac4af8106inpute72abc240update readme430139dc9Qt6 frontend3080d4d45Fix this small bug too08cd13b85Cop0 unused functions do not actually pose a threat (as per manual). They don't do anything, so shall we.61bb4fb44make idle loop detection a little more specific with where the load goesb037de4c3SAZDFsdff12e81e73eneed to figure out why n64-systemtest loops indefinitely at some address that appears to be valid (i think it's me not invalidating the cache properly)204f0e13bidle skipping seems to work!cb8bb634asdkfjlasdf58e5c89c1Fix compilation issue on my machine (no idea)24fb2898eattempting more serious idle skipping214719577Place rsp.Step inside cached interpreter. Gains about 3 more fpsbb97dcc23mmmmm920b77d38wjkhasdfjhkasdf430ccdab4it's a start...4f42a673aCached interpreter plays Mario 64. Start looking into RSP as wellc9a030787idle skipping works!5fbda03cenew idea366637abaIdle skipping... maybe?609fa2fb0Cache instructions implemented but broken lmao. Commented out for nowe140a6d12- Stop using inheritance for CPU, instead use composition. - Introduce KAIZEN_JIT_ENABLED optional define instead of relying on __aarch64__ and the like. - More cache work68e613057prep cache impl811b4d809fix clang formatfda755f7didkd5024ebbfsmall MI refactor in preparation of (eventually) implementing the RDRAM interface properly694b45341Merge commit '206dcdedf195fb320913584180edb12c7731e396' as 'external/SDL'206dcdedfSquashed 'external/SDL/' content from commit 4d17b99d0a4d16e1cb4need to update sdl848b19920Fix compilation errordb61b5299Merge commit 'e94a94559f28e49678fbcf72199a5258137b0fe9' as 'external/imgui'e94a94559Squashed 'external/imgui/' content from commit 02e9b8cac52edb3757need to update imguic1a705e86Emulate weird JALR behaviour4b4c32f4bFix exception for "unusable COP1" in 4 instructions i missed accidentally (again)df5828142Bug putting 0s in the log everywheref8b580048Make isviewer a sink to file8241e9735Fix exception for "unusable COP1" in 4 instructions i missed accidentallyb29715f20small changesd9a620bc1make use of my new small utility library0d1aa938eAdd 'external/ircolib/' from commit 'ce3cd726c8df8388d554abf8bb55d55020eb4450'e64eb40b3Fuck git git-subtree-dir: external/ircolib git-subtree-split:de6e324bde
127 lines
3.9 KiB
Python
127 lines
3.9 KiB
Python
#!/usr/bin/python
|
|
|
|
# Simple fuzzing tool by disassembling random code. By Nguyen Anh Quynh, 2014
|
|
# Syntax:
|
|
# ./suite/fuzz.py --> Fuzz all archs
|
|
# ./suite/fuzz.py x86 --> Fuzz all X86 (all 16bit, 32bit, 64bit)
|
|
# ./suite/fuzz.py x86-16 --> Fuzz X86-32 arch only
|
|
# ./suite/fuzz.py x86-32 --> Fuzz X86-32 arch only
|
|
# ./suite/fuzz.py x86-64 --> Fuzz X86-64 arch only
|
|
# ./suite/fuzz.py arm --> Fuzz all ARM (arm, thumb)
|
|
# ./suite/fuzz.py aarch64 --> Fuzz AARCH64
|
|
# ./suite/fuzz.py mips --> Fuzz all Mips (32bit, 64bit)
|
|
# ./suite/fuzz.py ppc --> Fuzz PPC
|
|
|
|
from capstone import *
|
|
|
|
from time import time
|
|
from random import randint
|
|
import sys
|
|
|
|
|
|
# file providing code to disassemble
|
|
FILE = '/usr/bin/python'
|
|
|
|
TIMES = 64
|
|
INTERVALS = (4, 5, 7, 9, 11, 13)
|
|
|
|
all_tests = (
|
|
(CS_ARCH_X86, CS_MODE_16, "X86-16bit (Intel syntax)", 0),
|
|
(CS_ARCH_X86, CS_MODE_16, "X86-16bit (ATT syntax)", CS_OPT_SYNTAX_ATT),
|
|
(CS_ARCH_X86, CS_MODE_32, "X86-32 (Intel syntax)", 0),
|
|
(CS_ARCH_X86, CS_MODE_32, "X86-32 (ATT syntax)", CS_OPT_SYNTAX_ATT),
|
|
(CS_ARCH_X86, CS_MODE_64, "X86-64 (Intel syntax)", 0),
|
|
(CS_ARCH_X86, CS_MODE_64, "X86-64 (ATT syntax)", CS_OPT_SYNTAX_ATT),
|
|
(CS_ARCH_ARM, CS_MODE_ARM, "ARM", 0),
|
|
(CS_ARCH_ARM, CS_MODE_THUMB, "THUMB (ARM)", 0),
|
|
(CS_ARCH_MIPS, CS_MODE_MIPS32 + CS_MODE_BIG_ENDIAN, "MIPS-32 (Big-endian)", 0),
|
|
(CS_ARCH_MIPS, CS_MODE_MIPS64 + CS_MODE_LITTLE_ENDIAN, "MIPS-64-EL (Little-endian)", 0),
|
|
(CS_ARCH_AARCH64, CS_MODE_ARM, "AARCH64 (AArch64)", 0),
|
|
(CS_ARCH_PPC, CS_MODE_BIG_ENDIAN, "PPC", 0),
|
|
(CS_ARCH_PPC, CS_MODE_BIG_ENDIAN, "PPC, print register with number only", CS_OPT_SYNTAX_NOREGNAME),
|
|
(CS_ARCH_SPARC, CS_MODE_BIG_ENDIAN, "Sparc", 0),
|
|
(CS_ARCH_SYSTEMZ, 0, "SystemZ", 0),
|
|
(CS_ARCH_XCORE, 0, "XCore", 0),
|
|
(CS_ARCH_M68K, 0, "M68K", 0),
|
|
(CS_ARCH_RISCV, CS_MODE_RISCV32, "riscv32", 0),
|
|
(CS_ARCH_RISCV, CS_MODE_RISCV64, "riscv64", 0),
|
|
)
|
|
|
|
|
|
# for debugging
|
|
def to_hex(s):
|
|
return " ".join("0x" + "{0:x}".format(ord(c)).zfill(2) for c in s) # <-- Python 3 is OK
|
|
|
|
|
|
# read @size bytes from @f & return data.
|
|
# return None when there is not enough data
|
|
def get_code(f, size):
|
|
code = f.read(size)
|
|
if len(code) != size: # reached end-of-file?
|
|
# then reset file position to begin-of-file
|
|
f.seek(0)
|
|
return None
|
|
|
|
return code
|
|
|
|
|
|
def cs(md, code):
|
|
insns = md.disasm(code, 0)
|
|
for i in insns:
|
|
if i.address == 0x100000:
|
|
print i
|
|
|
|
|
|
def cs_lite(md, code):
|
|
insns = md.disasm_lite(code, 0)
|
|
for (addr, size, mnem, ops) in insns:
|
|
if addr == 0x100000:
|
|
print i
|
|
|
|
|
|
cfile = open(FILE)
|
|
|
|
for (arch, mode, comment, syntax) in all_tests:
|
|
try:
|
|
request = sys.argv[1]
|
|
if not request in comment.lower():
|
|
continue
|
|
except:
|
|
pass
|
|
|
|
try:
|
|
md = Cs(arch, mode)
|
|
md.detail = True
|
|
|
|
if syntax != 0:
|
|
md.syntax = syntax
|
|
|
|
# test disasm()
|
|
print("\nFuzzing disasm() @platform: %s" %comment)
|
|
for ii in INTERVALS:
|
|
print("Interval: %u" %ii)
|
|
for j in xrange(1, TIMES):
|
|
while (True):
|
|
code = get_code(cfile, j * ii)
|
|
if code is None:
|
|
# EOF? break
|
|
break
|
|
#print to_hex(code)
|
|
cs(md, code)
|
|
|
|
# test disasm_lite()
|
|
print("Fuzzing disasm_lite() @platform: %s" %comment)
|
|
for ii in INTERVALS:
|
|
print("Interval: %u" %ii)
|
|
for j in xrange(1, TIMES):
|
|
while (True):
|
|
code = get_code(cfile, j * ii)
|
|
if code is None:
|
|
# EOF? break
|
|
break
|
|
#print to_hex(code)
|
|
cs_lite(md, code)
|
|
|
|
except CsError as e:
|
|
print("ERROR: %s" %e)
|