Saturday, August 13, 2011

IDA Pro GUI Plugin "Trivial" Bug


If you are using IDA Pro (probably version > 5.4) plugin template to develop a GUI-based plugin, you'll probably encounter this bug: The GUI of the plugin suddenly vanish after the plugin activated (run() function invoked)


This "trivial" bug manifests if you don't change the default value of the plugin flags in the plugin_t structure.
The default value for the plugin flags is PLUGIN_UNL which means: Unload the plugin immediately after calling 'run'. This flag may be set anytime. The kernel checks it after each call to 'run'. The main purpose of this flag is to ease the debugging of new plugins.. This explanation comes from loader.hpp. Now, to avoid the "suddenly vanishing GUI" bug,
you should change the plugin flag to suit your need. For example:



...
//--------------------------------------------------------------------------
//
// PLUGIN DESCRIPTION BLOCK
//
//--------------------------------------------------------------------------
plugin_t PLUGIN =
{
IDP_INTERFACE_VERSION,
PLUGIN_DRAW, // plugin flags

init, // initialize

term, // terminate. this pointer may be NULL.

run, // invoke plugin

comment, // long comment about the plugin
// it could appear in the status line
// or as a hint

help, // multiline help about the plugin

wanted_name, // the preferred short name of the plugin
wanted_hotkey // the preferred hotkey to run the plugin
};
...



The PLUGIN_DRAW flag means:



...
#define PLUGIN_DRAW 0x0002 // IDA should redraw everything after calling
// the plugin
...


Monday, August 8, 2011

Qemu CPU Freeze Bug in Slackware 13 x86_64

So, I have this requirement to debug BIOS in Qemu, so I need to "freeze" the CPU on Qemu in the very first instruction. I've tried using Qemu version 0.9.x, 0.12.x and 0.13.x in Slackware 13 x86_64, passing the "-s -S" (without quote) as qemu parameter but none of them worked.

In frustration, I tried version 0.14.1 and it finally worked as expected. The following is a modified slackbuild script (originally coded by Andrew Brouwers for Slackware 13 i486) to build Qemu 0.14.1 in Slackware 13 x86_64.

#!/bin/sh

# Slackware build script for qemu

# Copyright 2009, 2010 Andrew Brouwers
# All rights reserved.
#
# Redistribution and use of this script, with or without modification, is
# permitted provided that the following conditions are met:
#
# 1. Redistributions of this script must retain the above copyright
# notice, this list of conditions and the following disclaimer.
#
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR ''AS IS'' AND ANY EXPRESS OR IMPLIED
# WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
# MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO
# EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
# PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
# OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
# WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
# OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
# ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.

# Modified by the SlackBuilds.org project

PRGNAM=qemu
VERSION=0.14.1
ARCH=${ARCH:-x86_64}
BUILD=${BUILD:-1}
TAG=${TAG:-_SBo}

CWD=$(pwd)
TMP=${TMP:-/tmp/SBo}
PKG=$TMP/package-$PRGNAM
OUTPUT=${OUTPUT:-/tmp}

if [ "$ARCH" = "i486" ]; then
SLKCFLAGS="-O2 -march=i486 -mtune=i686"
LIBDIRSUFFIX=""
elif [ "$ARCH" = "i686" ]; then
SLKCFLAGS="-O2 -march=i686 -mtune=i686"
LIBDIRSUFFIX=""
elif [ "$ARCH" = "x86_64" ]; then
SLKCFLAGS="-O2 -fPIC"
LIBDIRSUFFIX="64"
fi

set -e

rm -rf $PKG
mkdir -p $TMP $PKG $OUTPUT
cd $TMP
rm -rf $PRGNAM-$VERSION
tar xvf $CWD/$PRGNAM-$VERSION.tar.gz
cd $PRGNAM-$VERSION
chown -R root:root .
chmod -R u+w,go+r-w,a-s .

# --libdir isn't recognized and isn't needed anyway
CFLAGS="$SLKCFLAGS" \
CXXFLAGS="$SLKCFLAGS" \
./configure \
--prefix=/usr \
--enable-system \
--enable-user \
--audio-drv-list=alsa,oss,sdl,esd

make OS_CFLAGS="$SLKCFLAGS"
make install DESTDIR=$PKG

find $PKG | xargs file | grep -e "executable" -e "shared object" | grep ELF \
| cut -f 1 -d : | xargs strip --strip-unneeded 2> /dev/null || true

# move any generated man pages to their proper location
if [ -d $PKG/usr/share/man ]; then
mv $PKG/usr/share/man $PKG/usr
gzip -9 $PKG/usr/man/man?/*.?
fi

# Add docs, and if present, built documentation to the proper location
mkdir -p $PKG/usr/doc/$PRGNAM-$VERSION
cp -a TODO README LICENSE COPYING COPYING.LIB MAINTAINERS \
$PKG/usr/doc/$PRGNAM-$VERSION
if [ -d $PKG/usr/share/doc ]; then
mv $PKG/usr/share/doc/qemu/* $PKG/usr/doc/$PRGNAM-$VERSION/
rm -rf $PKG/usr/share/doc
fi

cat $CWD/$PRGNAM.SlackBuild > $PKG/usr/doc/$PRGNAM-$VERSION/$PRGNAM.SlackBuild

mkdir -p $PKG/install
cat $CWD/slack-desc > $PKG/install/slack-desc

cd $PKG
/sbin/makepkg -l y -c n $OUTPUT/$PRGNAM-$VERSION-$ARCH-$BUILD$TAG.${PKGTYPE:-tgz}


The changes that I made to the original slackbuild script as follows:

...
VERSION=0.14.1
ARCH=${ARCH:-x86_64}
...
./configure \
--prefix=/usr \
--enable-system \
--enable-user \
--audio-drv-list=alsa,oss,sdl,esd
...

I added "--enable-user" switch to configure script invocation.

That's it. After these changes, Qemu works as expected. I was using coreboot binary as a test case for "-s -S" Qemu parameters and it worked.

Friday, August 5, 2011

Hydrogen Peroxide Use in Medical and Rocketry Applications

So, what this Hydrogen Peroxide have to do with programming? Well, nothing actually. At least nothing directly related. It's just I can't keep this thing in my mind so it's better to write it out.

I went to a doctor to treat my wound and I found out that he used H2O2 (Hydrogen Peroxide) to clean the wound. I found it rather surprising because I didn't know H2O2 is also used as "cleaning agent" in medical application previously. All I knew about H2O2 was it's use in rocketry (http://en.wikipedia.org/wiki/Armadillo_Aerospace).

If you look at http://en.wikipedia.org/wiki/Hydrogen_peroxide. This chemical compound has a lot of uses. Still, it's just incredible to think that you can use the same compound to treat your wound and to do rocketry.

Building Qemu 0.12.3 for Slackware 13 x86_64

The Qemu package slackbuild file from slackbuilds.org ( http://slackbuilds.org/repository/13.0/system/qemu/) by default compiles for x86 (i486) target. This will cause a build error on Slackware 13.0 x86_64 systems. In order to build the package from the source, you have to change the target in the slackbuild file to:

...
ARCH=${ARCH:-x86_64}
...


This way the package build should be successful in Slackware 13 x86_64 systems.