
ATrace विंडोज पर बाइनरीज़ के निष्पादन को ट्रेस करने का एक उपकरण है।

EhTrace ("ATrace" उच्चारित) विंडोज़ के लिए एक उच्च-प्रदर्शन बाइनरी ट्रेसिंग और इंस्ट्रुमेंटेशन फ्रेमवर्क है। यह स्रोत कोड, बाइनरी संशोधन या पारंपरिक डिबगिंग की आवश्यकता के बिना विंडोज़ एक्जीक्यूटेबल्स का गहन रनटाइम विश्लेषण सक्षम करता है।
EhTrace विंडोज़ वेक्टर्ड एक्सेप्शन हैंडलिंग (VEH) और ब्लॉक-स्टेपिंग तकनीकों का लाभ उठाकर न्यूनतम ओवरहेड के साथ व्यापक निष्पादन ट्रेसिंग प्रदान करता है। पारंपरिक डिबगिंग या इंस्ट्रुमेंटेशन टूल के विपरीत, EhTrace पूरी तरह से इन-प्रोसेस संचालित होता है और लक्ष्य बाइनरी में किसी पैच की आवश्यकता नहीं होती है।
flowchart TB
subgraph Target["🎯 लक्ष्य प्रक्रिया"]
direction TB
APP[एप्लिकेशन कोड]
VEH[वेक्टर्ड एक्सेप्शन हैंडलर]
style APP fill:#e1f5ff,stroke:#01579b,stroke-width:3px,color:#000
style VEH fill:#fff3e0,stroke:#e65100,stroke-width:3px,color:#000
end
subgraph EhTrace["⚡ EhTrace इंजन"]
direction TB
BLOCK[ब्लॉक स्टेपर]
DISASM[कैप्स्टोन डिसअसेंबलर]
FIGHTERS[BlockFighters]
CTX[संदर्भ प्रबंधक]
style BLOCK fill:#f3e5f5,stroke:#4a148c,stroke-width:3px,color:#000
style DISASM fill:#e8f5e9,stroke:#1b5e20,stroke-width:3px,color:#000
style FIGHTERS fill:#ffebee,stroke:#b71c1c,stroke-width:3px,color:#000
style CTX fill:#e0f2f1,stroke:#004d40,stroke-width:3px,color:#000
end
subgraph Output["📊 विश्लेषण आउटपुट"]
direction TB
SHMEM[साझा मेमोरी लॉग]
GRAPHS[दृश्य ग्राफ़]
REPORTS[कवरेज रिपोर्ट]
style SHMEM fill:#fce4ec,stroke:#880e4f,stroke-width:3px,color:#000
style GRAPHS fill:#f1f8e9,stroke:#33691e,stroke-width:3px,color:#000
style REPORTS fill:#fff8e1,stroke:#f57f17,stroke-width:3px,color:#000
end
APP -->|एक्सेप्शन| VEH
VEH -->|सिंगल स्टेप| BLOCK
BLOCK -->|निर्देश| DISASM
DISASM -->|विश्लेषण| FIGHTERS
FIGHTERS -->|स्थिति| CTX
CTX -->|घटनाएँ| SHMEM
SHMEM -->|डेटा| GRAPHS
SHMEM -->|डेटा| REPORTS
style Target fill:#e3f2fd,stroke:#0d47a1,stroke-width:4px
style EhTrace fill:#f3e5f5,stroke:#6a1b9a,stroke-width:4px
style Output fill:#e8f5e9,stroke:#2e7d32,stroke-width:4px
EhTrace एक परिष्कृत पाइपलाइन के माध्यम से संचालित होता है:
फ्रेमवर्क विशेष संदर्भ संरचनाओं का उपयोग करके प्रति-थ्रेड निष्पादन स्थिति बनाए रखता है और अनुकूलन योग्य इंस्ट्रुमेंटेशन के लिए हुक प्रदान करता है।
graph LR
subgraph Traditional["🐌 पारंपरिक डिबगर"]
T1[सिंगल स्टेप]
T2[संदर्भ स्विच]
T3[कर्नेल मोड]
T4[~1M घटनाएँ/सेकंड]
style T1 fill:#ffcdd2,stroke:#c62828,stroke-width:2px,color:#000
style T2 fill:#ffcdd2,stroke:#c62828,stroke-width:2px,color:#000
style T3 fill:#ffcdd2,stroke:#c62828,stroke-width:2px,color:#000
style T4 fill:#ef5350,stroke:#b71c1c,stroke-width:3px,color:#fff
end
subgraph EhTrace["⚡ EhTrace"]
E1[ब्लॉक स्टेप]
E2[इन-प्रोसेस]
E3[यूज़र मोड]
E4[~43M घटनाएँ/सेकंड]
style E1 fill:#c8e6c9,stroke:#2e7d32,stroke-width:2px,color:#000
style E2 fill:#c8e6c9,stroke:#2e7d32,stroke-width:2px,color:#000
style E3 fill:#c8e6c9,stroke:#2e7d32,stroke-width:2px,color:#000
style E4 fill:#66bb6a,stroke:#1b5e20,stroke-width:3px,color:#fff
end
T1 --> T2 --> T3 --> T4
E1 --> E2 --> E3 --> E4
style Traditional fill:#ffebee,stroke:#d32f2f,stroke-width:3px
style EhTrace fill:#e8f5e9,stroke:#388e3c,stroke-width:3px
EhTrace कई अनुकूलनों के माध्यम से उच्च प्रदर्शन प्राप्त करता है:
📊 बेंचमार्क: 428,833,152 घटनाएँ (प्रत्येक 32 बाइट) 10 सेकंड में कैप्चर = ~43M घटनाएँ/सेकंड
CSW16 डेमो बिना प्रतीकों के notepad.exe ट्रेसिंग:

कैप्स्टोन डिसअसेंबली के साथ बेसिक ब्लॉक ग्राफ़:

कोड कवरेज विज़ुअलाइज़ेशन:
