Agent Skills
› gadievron/raptor
› rr-debugger
rr-debugger
GitHub基于rr的确定性记录重放调试技能,支持崩溃与ASAN故障分析。提供反向执行命令及自动化脚本,增强GDB安全性以防范恶意脚本执行,辅助逆向追踪错误根源。
Trigger Scenarios
需要调试程序崩溃
处理ASAN内存检测故障
需要反向执行代码
Install
npx skills add gadievron/raptor --skill rr-debugger -g -y
SKILL.md
Frontmatter
{
"name": "rr-debugger",
"description": "Deterministic debugging with rr record-replay. Use when debugging crashes, ASAN faults, or when reverse execution is needed. Provides reverse-next, reverse-step, reverse-continue commands and crash trace extraction.",
"user-invocable": false
}
rr Deterministic Debugger
rr provides deterministic record-replay debugging with full reverse execution capabilities.
Core Workflow
- Record:
rr record <program> [args] - Replay:
rr replay -- -nx -iex 'set auto-load off' -iex 'set auto-load safe-path /dev/null'(enters gdb interface with reverse execution). The flags after--go to gdb and disable auto-load with no trusted directory: the recorded binary is untrusted, and a permissive gdb config (e.g. an operator~/.gdbinitwideningauto-load safe-path) would otherwise execute scripts the binary or its build tree plants (.debug_gdb_scripts, *-gdb.py). Same hardening set as scripts/crash_trace.py — use it on EVERY manual replay.
Reverse Execution Commands
All standard gdb commands work, plus reverse variants:
reverse-next/rn: Step back over function callsreverse-step/rs: Step back into functionsreverse-continue/rc: Continue backward to previous breakpointreverse-stepi/rsi: Step back one instructionreverse-nexti/rni: Step back over one instruction
Crash Trace Extraction
Regular Crashes
After rr record <crashing-program>:
rr replay -- -nx -iex 'set auto-load off' -iex 'set auto-load safe-path /dev/null'
# In gdb:
reverse-next 100 # Go back 100 steps (adjust N as needed)
# Now step forward to see execution leading to crash:
next
next
...
ASAN Crashes
After rr record <asan-program>:
rr replay -- -nx -iex 'set auto-load off' -iex 'set auto-load safe-path /dev/null'
# In gdb:
bt # View stack trace
up # Issue "up" commands until last app frame (before ASAN runtime)
break *$pc # Set breakpoint at that location
reverse-continue # Go back to last app instruction before ASAN
# Now step forward to see execution leading to fault:
next
next
...
Inspecting Variables and Memory
Standard gdb commands work at any point:
print <var>: Print variable valueprint *<ptr>: Dereference pointerx/<format> <address>: Examine memoryx/10xb <addr>: 10 bytes in hexx/s <addr>: String at address
info locals: Show local variablesinfo args: Show function arguments
Source vs Assembly View
list: Show source code around current locationdisassemble: Show assembly around current locationlayout src: TUI source viewlayout asm: TUI assembly viewset disassemble-next-line on: Show assembly with each step
Automation Script
Use scripts/crash_trace.py to automatically extract execution trace before crash.
Version History
-
4d2e852
Current 2026-09-27 22:56
修复手动rr replay未应用GDB auto-load加固配置的安全隐患,统一使用安全参数防止恶意脚本执行,并添加文档测试确保规范一致。
- 91a9686 2026-07-24 22:16


