| Age | Commit message (Collapse) | Author |
|
|
|
Improves the speed by moving chunks of functions into worker threads, because of how the functions and possible functions are gathered we have many locations to insert fast fails, which is also partially addressed by this commit (see `maximum_possible_functions`).
|
|
of all the functions
This was caused by the internal flatbuffer verifier reaching the max number of tables, this is fine and the solution is to split the large chunk into smaller ones, effectively creating more flatbuffer "views" of tables.
This is fine from a performance perspective because we already have optimized for many small chunks (e.g. we have a lookup table stored next to each chunk).
I left some comments for future improvements but this should be good now.
Also alongside this change we improved generating performance by 2x on some pathological binaries.
|
|
It will just end up freezing the UI for an unreasonable time, just open the generated report in a real web browser or text editor, QTextBrowser falls over and fixing it would be more effort than its worth.
|
|
given
Fixes the case where we are generating many smaller chunks for a given view and then unintentionally merging
them back together, throwing away all data.
|
|
It is important that we only retrieve the medium-level IL if the function has
any user-defined variables, otherwise, we will possibly be generating MLIL for no reason.
For the above reason, we do a filter on user-defined variables first.
|
|
We do not need to consult the lifted IL if we have already cached the function GUID in the function metadata
|
|
These calls set the rpaths used for release builds of the dylibs using a
macro that isn't available in the API repository. They are not necessary
when building the shared cache plug-in outside of the context of the
app.
|
|
Defining `_DEBUG` changes which MSVC runtime library needs to be linked
which breaks clients attempting to use the C++ API with `RelWithDebInfo`.
To fix this we define a new private `BN_ENABLE_LOG_TRACE` macro and use
that within log.cpp where it was previously using `_DEBUG`.
Fixes https://github.com/Vector35/binaryninja-api/issues/7288.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
This is functionally equivalent to the previous workflow_objc, with the
following changes:
1. It mutates the `core.function.metaAnalysis` workflow rather than
registering a new named workflow. The activities now all check for
the presence of the Objective-C metadata added by `ObjCProcessor` to
determine whether they should do work, rather than relying on
`MachoView` to override the function workflow when Objective-C
metadata is present. This fixes
https://github.com/Vector35/binaryninja-api/issues/6779.
2. The auto-inlining of `objc_msgSend` selector stub functions is
performed in a separate activity from the processing of
`objc_msgSend` call sites. The selector stub inlining activity is
configured so that it does not run in `DSCView` as the shared cache
needs different behavior for stub functions more generally that
`SharedCacheWorkflow` already provides.
3. The way that types like `id` and `SEL` are referenced is fixed so
that they show up as `id` rather than `objc_struct*`.
This also replaces the Objective-C portion of the shared cache's
workflow, and incorporates several bug fixes that had been applied to it
but not the standalone Objective-C workflow.
|
|
1. Some SSA-specific functions are now implemented on
`LowLevelILFunction<M, SSA>` rather than `Ref<LowLevelILFunction<M, SSA>>`.
2. A lifting helper for `LLIL_TAILCALL` is added to `LowLevelILFunction`.
3. `PossibleValueSet::ImportedAddressValue` now holds the value.
|
|
These are available on `LowLevelILFunction<M, SSA>`.
|
|
Incorrect parsing of method type encoding strings was causing incorrect
function types to be applied to Objective-C method implementations. In
some cases this would result in confusion about which stack locations
specific parameters resided at.
`q`, `Q` and `d` were being mapped to `NSInteger`, `NSUInteger` and
`CGFloat` respectively. While this works for 64-bit platforms, the type
aliases refer to 32-bit types on 32-bit platforms. These type encodings
are explicitly for 64-bit types. To address this `q`, `Q` and `d` are
now mapped to `int64_t`, `uint64_t` and `double` respectively.
`l` and `L` were incorrectly being interpreted as `int64_t` and
`uint64_t`. While `long` is a 64-bit type on 64-bit Apple platforms, the
`l` / `L` type encodings always refer to a 32-bit type.
`S` was mistakenly being mapped to `uint8_t`. It is now `uint16_t` as
intended.
|
|
The compiler represents block parameters as `@?` in the method type
encoding string. We had been parsing this as two separate parameters
(one `id` and one unknown type that was mapped to `void*`), resulting in
some Objective-C method implementations incorrectly having an extra
parameter.
We cannot represent a Clang block (e.g., `void (^)()`) in the type
system at present. Since these are Objective-C compatible types the
simplest solution for now is to represent them as `id`.
|
|
To avoid non-determinism and provide consistent behavior in all cases,
now only confidence, symbol type, and name are considered when
disambiguating multiple symbols at the same address.
The previously documented behavior was not what was implemented. While
recency was considered in some cases for disambiguating symbols at the
same address, respecting it consistetly results in non-deterministic
behavior when symbols are being added concurrently by multiple sources.
|
|
address are handled"
This reverts commit 6293afcb4e10997838f94c38430feba9742bea75.
|
|
handled
|
|
projects
|
|
|
|
|
|
|
|
Calls to `Workflow::Instance` that were looking up a built-in workflow
name are updated to use `Workflow::Get`. Others use `Workflow::GetOrCreate`.
|
|
|
|
This eliminates a significant amount of wasted work when loading
multiple images containing Objective-C from a shared cache. The time
taken to load 400 images from an iOS shared cache (with an analysis hold
enabled) drops from eight minutes to around six minutes.
|
|
|
|
|
|
|
|
The setting should halt analysis of branch targets that fall within string references.
Previous implementation looked up string references at branch source.
|
|
|
|
C++ plug-ins now consistently use the `plugin_rpath` or
`ui_plugin_rpath` macros to ensure they have `SKIP_BUILD_RPATH` set when
building on Mac (i.e., no `LC_RPATH` is added).
Rust plug-ins have their build.rs updated to only specify `-Wl,-rpath`
when building for Linux. It is not needed on macOS. On macOS we instead
explicitly specify an `@rpath`-relative install name. This doesn't
change any behavior, but avoids leaving an absolute path as the
library's install name and is consistent with CMake's behavior for C++
plug-ins.
|
|
|
|
thumb2 disassembler
|
|
|
|
floating-point/integer cases
|
|
[thumb2] removed redundant format suffixes from disassembly of VFP instruction
[thumb2] Corrected lifting of VCVT instruction
|
|
|
|
instead of deprecated Grako
|
|
PC when calculating address #6947
Updated thumb2 pcode parser used by disassembler generator to use Tatsu instead of deprecated Grako
|
|
|
|
|
|
When the section list gets large GetSectionsAt becomes quite slow instead the the whole list of sections outside the loop and just encour that hit once. It could probably be made even faster if we used an interval tree but then we have to pay the cost of building the tree which may be more nauanced
|
|
|