Closed andyhhp closed 6 months ago
This is reproducible when scanning all of Xen's ENDBR sites, skipping parse_event_log_entry
to work around #13
Files: xen-syms.gz addr-list-all.csv
We have pinpointed this to a few instances where angr transfers all the annotations of the original expression to the new expression during various semplification steps. We fixed some of the cases by rolling our own simplify()
, but internally angr still does this in some cases.
Not closing until we are able to remove all the instances of this.
This includes the minor adjustment in #11
I'm afraid that I can't reproduce it by analysing
free_pirq_struct
in isolation, which means it depends on some prior work. I'll see if I can narrow it down at all.