summaryrefslogtreecommitdiff
path: root/python
diff options
context:
space:
mode:
Diffstat (limited to 'python')
-rw-r--r--python/function.py42
-rw-r--r--python/lowlevelil.py98
-rw-r--r--python/mediumlevelil.py149
3 files changed, 223 insertions, 66 deletions
diff --git a/python/function.py b/python/function.py
index ed2a537c..928597a7 100644
--- a/python/function.py
+++ b/python/function.py
@@ -459,36 +459,6 @@ class Function(object):
core.BNFreeRegisterValue(value)
return result
- def get_reg_value_at_low_level_il_instruction(self, i, reg, arch=None):
- """
- ``get_reg_value_at_low_level_il_instruction`` returns the value of the specified register ``reg`` at the il address
- i
-
- :param int i: il address of instruction to query
- :param Architecture arch: (optional) Architecture for the given function
- :rtype: function.RegisterValue
- :Example:
-
- >>> func.get_reg_value_at_low_level_il_instruction(15, 'rdi')
- <const 0x2>
- """
- if arch is None:
- arch = self.arch
- if isinstance(reg, str):
- reg = self.arch.regs[reg].index
- value = core.BNGetRegisterValueAtLowLevelILInstruction(self.handle, i, reg)
- result = RegisterValue(arch, value)
- core.BNFreeRegisterValue(value)
- return result
-
- def get_reg_value_after_low_level_il_instruction(self, i, reg):
- if isinstance(reg, str):
- reg = self.arch.regs[reg].index
- value = core.BNGetRegisterValueAfterLowLevelILInstruction(self.handle, i, reg)
- result = RegisterValue(self.arch, value)
- core.BNFreeRegisterValue(value)
- return result
-
def get_stack_contents_at(self, addr, offset, size, arch=None):
"""
``get_stack_contents_at`` returns the RegisterValue for the item on the stack in the current function at the
@@ -523,18 +493,6 @@ class Function(object):
core.BNFreeRegisterValue(value)
return result
- def get_stack_contents_at_low_level_il_instruction(self, i, offset, size):
- value = core.BNGetStackContentsAtLowLevelILInstruction(self.handle, i, offset, size)
- result = RegisterValue(self.arch, value)
- core.BNFreeRegisterValue(value)
- return result
-
- def get_stack_contents_after_low_level_il_instruction(self, i, offset, size):
- value = core.BNGetStackContentsAfterInstruction(self.handle, i, offset, size)
- result = RegisterValue(self.arch, value)
- core.BNFreeRegisterValue(value)
- return result
-
def get_parameter_at(self, addr, func_type, i, arch=None):
if arch is None:
arch = self.arch
diff --git a/python/lowlevelil.py b/python/lowlevelil.py
index 462d4ade..74b030d7 100644
--- a/python/lowlevelil.py
+++ b/python/lowlevelil.py
@@ -260,12 +260,108 @@ class LowLevelILInstruction(object):
@property
def value(self):
- """Value of expression using static data flow analysis (read-only)"""
+ """Value of expression if constant or a known value (read-only)"""
value = core.BNGetLowLevelILExprValue(self.function.handle, self.expr_index)
result = function.RegisterValue(self.function.arch, value)
core.BNFreeRegisterValue(value)
return result
+ @property
+ def possible_values(self):
+ """Possible values of expression using path-sensitive static data flow analysis (read-only)"""
+ value = core.BNGetLowLevelILPossibleExprValues(self.function.handle, self.expr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_reg_value(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetLowLevelILRegisterValueAtInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_reg_value_after(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetLowLevelILRegisterValueAfterInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_reg_values(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetLowLevelILPossibleRegisterValuesAtInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_reg_values_after(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetLowLevelILPossibleRegisterValuesAfterInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_flag_value(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetLowLevelILFlagValueAtInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_flag_value_after(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetLowLevelILFlagValueAfterInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_flag_values(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetLowLevelILPossibleFlagValuesAtInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_flag_values_after(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetLowLevelILPossibleFlagValuesAfterInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_stack_contents(self, offset, size):
+ value = core.BNGetLowLevelILStackContentsAtInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_stack_contents_after(self, offset, size):
+ value = core.BNGetLowLevelILStackContentsAfterInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_stack_contents(self, offset, size):
+ value = core.BNGetLowLevelILPossibleStackContentsAtInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_stack_contents_after(self, offset, size):
+ value = core.BNGetLowLevelILPossibleStackContentsAfterInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
def __setattr__(self, name, value):
try:
object.__setattr__(self, name, value)
diff --git a/python/mediumlevelil.py b/python/mediumlevelil.py
index a63e1b31..6f482221 100644
--- a/python/mediumlevelil.py
+++ b/python/mediumlevelil.py
@@ -274,7 +274,13 @@ class MediumLevelILInstruction(object):
@property
def branch_dependence(self):
"""Set of branching instructions that must take the true or false path to reach this instruction"""
- return self.function.get_all_branch_dependence_at_instruction(self.instr_index)
+ count = ctypes.c_ulonglong()
+ deps = core.BNGetAllMediumLevelILBranchDependence(self.function.handle, self.instr_index, count)
+ result = {}
+ for i in xrange(0, count.value):
+ result[deps[i].branch] = ILBranchDependence(deps[i].dependence)
+ core.BNFreeILBranchDependenceList(deps)
+ return result
@property
def low_level_il(self):
@@ -284,6 +290,11 @@ class MediumLevelILInstruction(object):
return None
return lowlevelil.LowLevelILInstruction(self.function.low_level_il.ssa_form, expr)
+ @property
+ def ssa_memory_index(self):
+ """Index of active memory contents in SSA form for this instruction"""
+ return core.BNGetMediumLevelILSSAMemoryIndexAtILInstruction(self.function.handle, self.instr_index)
+
def get_ssa_var_possible_values(self, var, index):
var_data = core.BNILVariable()
var_data.type = var.type
@@ -294,6 +305,120 @@ class MediumLevelILInstruction(object):
core.BNFreeRegisterValue(value)
return result
+ def get_ssa_var_index(self, var):
+ var_data = core.BNILVariable()
+ var_data.type = var.type
+ var_data.index = var.index
+ var_data.identifier = var.identifier
+ return core.BNGetMediumLevelILSSAVarIndexAtILInstruction(self.function.handle, var_data, self.instr_index)
+
+ def get_var_for_reg(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ result = core.BNGetMediumLevelILVariableForRegisterAtInstruction(self.function.handle, reg, self.instr_index)
+ return function.ILVariable(self.function.source_function, result.type, result.index, result.identifier)
+
+ def get_var_for_flag(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.regs[flag].index
+ result = core.BNGetMediumLevelILVariableForFlagAtInstruction(self.function.handle, flag, self.instr_index)
+ return function.ILVariable(self.function.source_function, result.type, result.index, result.identifier)
+
+ def get_var_for_stack_location(self, offset):
+ result = core.BNGetMediumLevelILVariableForStackLocationAtInstruction(self.function.handle, offset, self.instr_index)
+ return function.ILVariable(self.function.source_function, result.type, result.index, result.identifier)
+
+ def get_reg_value(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetMediumLevelILRegisterValueAtInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_reg_value_after(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetMediumLevelILRegisterValueAfterInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_reg_values(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetMediumLevelILPossibleRegisterValuesAtInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_reg_values_after(self, reg):
+ if isinstance(reg, str):
+ reg = self.function.arch.regs[reg].index
+ value = core.BNGetMediumLevelILPossibleRegisterValuesAfterInstruction(self.function.handle, reg, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_flag_value(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetMediumLevelILFlagValueAtInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_flag_value_after(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetMediumLevelILFlagValueAfterInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_flag_values(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetMediumLevelILPossibleFlagValuesAtInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_flag_values_after(self, flag):
+ if isinstance(flag, str):
+ flag = self.function.arch.flags[flag].index
+ value = core.BNGetMediumLevelILPossibleFlagValuesAfterInstruction(self.function.handle, flag, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_stack_contents(self, offset, size):
+ value = core.BNGetMediumLevelILStackContentsAtInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_stack_contents_after(self, offset, size):
+ value = core.BNGetMediumLevelILStackContentsAfterInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_stack_contents(self, offset, size):
+ value = core.BNGetMediumLevelILPossibleStackContentsAtInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_possible_stack_contents_after(self, offset, size):
+ value = core.BNGetMediumLevelILPossibleStackContentsAfterInstruction(self.function.handle, offset, size, self.instr_index)
+ result = function.RegisterValue(self.function.arch, value)
+ core.BNFreeRegisterValue(value)
+ return result
+
+ def get_branch_dependence(self, branch_instr):
+ return ILBranchDependence(core.BNGetMediumLevelILBranchDependence(self.function.handle, self.instr_index, branch_instr))
+
def __setattr__(self, name, value):
try:
object.__setattr__(self, name, value)
@@ -584,28 +709,6 @@ class MediumLevelILFunction(object):
core.BNFreeRegisterValue(value)
return result
- def get_ssa_var_index_at_instruction(self, var, instr):
- var_data = core.BNILVariable()
- var_data.type = var.type
- var_data.index = var.index
- var_data.identifier = var.identifier
- return core.BNGetMediumLevelILSSAVarIndexAtILInstruction(self.handle, var_data, instr)
-
- def get_ssa_memory_index_at_instruction(self, instr):
- return core.BNGetMediumLevelILSSAMemoryIndexAtILInstruction(self.handle, instr)
-
- def get_branch_dependence_at_instruction(self, cur_instr, branch_instr):
- return ILBranchDependence(core.BNGetMediumLevelILBranchDependence(self.handle, cur_instr, branch_instr))
-
- def get_all_branch_dependence_at_instruction(self, instr):
- count = ctypes.c_ulonglong()
- deps = core.BNGetAllMediumLevelILBranchDependence(self.handle, instr, count)
- result = {}
- for i in xrange(0, count.value):
- result[deps[i].branch] = ILBranchDependence(deps[i].dependence)
- core.BNFreeILBranchDependenceList(deps)
- return result
-
def get_low_level_il_instruction_index(self, instr):
low_il = self.low_level_il
if low_il is None: