I have started a number of projects and most are incomplete, so how about why not start another. But really, there is a natural progression to the projects I’ve been working on.
I started a static analysis tool (was working, but compile is now broken due to mixing stdio and iostream and using part of the sources which I then modified in another project), then wrote an x86 emulator (working, but not complete) which led me into a more ambitious emulator project in symbolic execution of IOS by modifying dynamips (project not working), which I then simplified in a side project to implement a Valgrind like memcheck tool (not really working, too many false positives – an IOS API that modifies the heap which I still have to reverse).
So the next diversion could be Valgrind memcheck for the Linux Kernel. This will really be no different to the code I implemented in dynamips. Except of course, I can’t use dynamips anymore – I’ll probably use Qemu, or alternatively have the option of using Bochs (but I’ll use Qemu). It will really be a simple modification I would make. Intercept malloc/free (or whatever the Linux kernel equivalent is), maintain my own view of the heap in Qemu and then intercept memory reads/writes to the heap and make sure they are in an allocated buffer.
In the past day or two, before I thought of this latest idea, and to spur some new activity (as I haven’t been making progress on my other projects), I started looking at PowerPC assembly. Dynamips uses ppc for the Cisco 1700 emulation, and the images for this machine are alot smaller than the c7200’s (but still pretty big).
But back to the valgrind project.. I’ve looked at the Qemu sources before, but didn’t try any modifications. The biggest hurdle for the Valgrind like code I plan to write is interfacing with Qemu. The actual code itself for maintaining a view of the heap and checking reads/writes is fairly trivial.. Fortunately, even though x86 memory writes are possible in many types of instruction, Qemu generates micro operations for x86 which single out the memory accesses.
I also finished a University assignment today, so might try to play with Qemu over the next couple of days..