panda icon indicating copy to clipboard operation
panda copied to clipboard

Add PANDA API to inject page faults for i386 and mips

Open AndrewFasano opened this issue 3 years ago • 0 comments

If a panda_virtual_memory_... function fails due to paged out memory, panda_page_fault() allows you to force the guest to page in that memory and return execution to a PC of your choice (typically the same PC you were at before).

Using this as a fallback for when memory is unavailable requires some intentional design of your analysis code - if you identify that memory is unavailable, you should request the page fault, bail, and then have your analysis restart after the page fault is resolved. With syscalls2 based callbacks, this is easy as you will get the on_sys_... callback again after the fault is resolved. In other situations, it may be more difficult.

AndrewFasano avatar Oct 13 '21 21:10 AndrewFasano