summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2025-07-10Fix the Triage Summary view's exports list to only update when visibleMark Rowe
The `ExportsTreeView` now asks the model to pause / resume updates when its visibility changes. When paused, all notifications from the view are ignored. When resumed, notifications set a flag to indicate that an update is needed and resume the update timer if it is not already active. The timer is stopped after an update is processed. There's some extra complexity here to avoid emitting a signal for every `BinaryView` notification that is processed. These notifications are typically generated on background threads. The overhead of emitting a signal and it being routed to the main thread adds up given the number of notifications involved when loading a large binary.
2025-07-10Fix building rapidjson with clang on windowsJosh Ferrell
2025-07-10Improve DWARF local variable recoveryJosh Ferrell
2025-07-09reimplement llil validation for caller_sites and implement plural IL forms ↵Jordan Wiens
on references
2025-07-09Improve DWARF local variable offset calculationJosh Ferrell
2025-07-09Update current abi version for get system cache directoryAlexander Khosrowshahi
2025-07-09Quiesce the FeatureMap widget when hidden or disabled.Brian Potchik
2025-07-09Add get_system_cache_directory and GetSystemCacheDirectory to APIAlexander Khosrowshahi
2025-07-09[MachO] Treat a binary as containing Objective-C metadata if it has __objc_stubsMark Rowe
`__objc_stubs` is not technically Objective-C metadata, but binaries containing Objective-C stubs need the same processing. `MachoView` was previously only enabling the Objective-C workflow if it thinks there is type metadata. The same criteria was used to determine whether to process Objective-C metadata via `MachoObjCProcessor`. This meant binaries with `__objc_stubs` but no Objective-C type metadata were not running the Objective-C workflow, preventing stub functions from being inlined during analysis.
2025-07-08[MachO] Avoid leaking MachoObjCProcessorMark Rowe
This would leak if parsing of CFStrings was enabled while parsing of Objective-C metadata was disabled. It would also leak if exceptions were thrown or early returns were taken in the ~500 lines between where the object was allocated and it was deleted.
2025-07-08[ObjC] Avoid leaking SymbolQueueMark Rowe
`SymbolQueue`'s lifetime was being managed via `new` / `delete`. This was error-prone in the face of code that can a) throw exceptions, or b) return early. Typically the solution would be to move to `std::unique_ptr` and call it a day, but nothing is ever easy. The `SymbolQueue`s created by `ObjCProcessor` are intended to live for the duration of `ProcessObjCData` and `ProcessCFStrings` methods. Since they are used multiple levels down the call tree, the active `SymbolQueue` is stored as a member variable on `ObjCProcessor`. Switching to `std::unique_ptr` would ensure that the `SymbolQueue` is destroyed, but would leave a dangling pointer in the member variable. To address this I'm introducing a `ScopedSingleton` class that provides a thread-local singleton whose lifetime is controlled by a guard object. `ProcessObjCData` / `ProcessCFStrings` call `ScopedSymbolQueue::Make` and store the returned guard object in a local. Code that accesses the symbol queue uses `ScopedSymbolQueue::Get` to retrieve the current instance. The guard object ensures the `SymbolQueue` is deleted and the `current` pointer is cleared no matter how the scope is exited. A better longer-term design is to introduce a class for processing the Objective-C runtime metadata and a class for processing constants such as `CFString`s. These could directly own the symbol queue so it would be accessible to any member functions that define symbols. This is a more involved refactoring than I have time for right now.
2025-07-08[RTTI] Fix leak of BackgroundTaskMark Rowe
2025-07-09Fix command palette focus stealing when clicking elsewhere.Brian Potchik
When clicking outside the command palette, focus is now properly transferred to the clicked widget instead of being restored to the previously focused widget. Escape key still restores focus as expected.
2025-07-08Parse sections containing Objective-C constantsMark Rowe
This adds support for the `__objc_arrayobj`, `_objc_dictobj`, `__objc_intobj`, `__objc_floatobj`, `__objc_doubleobj` and `__objc_dateobj` sections that contain Objective-C constants. These are emitted by Apple's versions of Clang for `const` literals, amongst other things.
2025-07-08Add wrapping support for long inline string annotationsAlexander Khosrowshahi
2025-07-08Update variablelist.h for variable placement infoAlexander Khosrowshahi
2025-07-08Various improvements for guided disassembly mode.Brian Potchik
2025-07-08remove spurious freestring from coreversion initializerJordan Wiens
2025-07-07[ObjC] Fix handling of relative method selectors with MSVCMark Rowe
The order that the operands to `+` are evaluated in is unspecified. Clang happens to evaluate them left to right and gives the expected answer. MSVC picks the opposite order and so the value it computes is off by 4. This was resulting in missing method names when arm64 binaries containing Objective-C are analyzed on Windows.
2025-07-07Add IL view type change UI context notificationRusty Wagner
2025-07-07KernelCache rewritekat
2025-07-06[WARP] Fix tag type creation marking the view as modifiedMason Reed
2025-07-06[Rust] Add `FileMetadata::forget_undo_actions`Mason Reed
Need this for WARP, see next commit
2025-07-06[Rust] Make `ReportCollection::add_*` optionally take a viewMason Reed
To allow for creating reports outside the context of a view
2025-07-06[WARP] Recover register variables and re-add tags to matched functionsMason Reed
2025-07-06[Rust] Fix typo for `MediumLevelILFunction::live_instruction_for_variable` paramMason Reed
2025-07-06[Rust] Fix MLIL function expression index usage in place of instruction indexMason Reed
Discovered when poking at variable values in WARP
2025-07-05Fix ELF loader image base calculation to include memory-only PT_LOAD segments.Brian Potchik
2025-07-04[Rust] Fix double precision expression low level IL definitionMason Reed
2025-07-04[WARP] Fix possible skipped instructions when multiple IL expressions are ↵Mason Reed
appended for a given instruction
2025-07-04[RTTI] Fix vtables straddling section boundaries causing a OOB exceptionMason Reed
This fixes an issue with certain shared cache binaries where a VFT was placed at the tail of the const data section
2025-07-04[SharedCache] Enqueue pointer sweep on image/region loadMason Reed
This is enabled as is, there might need to be some restrictions later on, does not seem to have an unreasonable impact analysis time
2025-07-04EFI Resolver user guide documentationBrandon Miller
2025-07-03[Rust] Fix clippy + rustfmt complaintsMark Rowe
The clippy complaint was a real issue: the doc comment intended for the commented-out `unresolved_indirect_branches` was being interpreted as the start of the doc comment for the following function.
2025-07-04[WARP] Remove warning about missing sections for Raw viewMason Reed
2025-07-04[Rust] Fix some grammar in README.mdMason Reed
2025-07-04[Rust] Add missing `ADD_OVERFLOW`, `TEST_BIT` and `LLIL_REG_STACK_FREE_REG` ↵Mason Reed
low level IL expressions
2025-07-03Fix compilation with newer clang/gcc versionsJosh Ferrell
2025-07-03Fix C++ deprecation warnings in nlohmann and rapidjsonJosh Ferrell
2025-07-03Bump current core ABI versionAlexander Khosrowshahi
2025-07-03Add get_files_by_path_in_project and get_path_in_project to C++ and python APIsAlexander Khosrowshahi
2025-07-03Change 'Path' to 'Path on disk' in triage summaryAlexander Khosrowshahi
2025-07-03Add GetPathInProject() to core APIAlexander Khosrowshahi
2025-07-03Add API to get all type field references at the same time to avoid ↵Rusty Wagner
duplicating work
2025-07-03Reduce number of refreshes and memory usage of cross references widget.Rusty Wagner
* Generates IL for cross references only when visible instead of all at once. * Releases memory for IL after the cross references retrieves the tokens. * Much faster algorithm for updating IL when functions change. * Don't refresh cross references at all if the widget isn't visible. Retreiving the new set of cross references is deferred until the widget becomes visible again. * Don't redo the query for the list of cross references when anything in the entire UI changes, even the window layout. Only recompute the list when an event for a new cross reference selection comes in.
2025-07-03Expose Add/RemoveDataReference and ensure BinaryViews use this API instead ↵Peter LaFosse
of the _user_ variant
2025-07-03api: indirect branch inlining supportRyan Snyder
2025-07-03arm/thumb: signal that returns can switch archRyan Snyder
2025-07-03[Rust] Add simple binary view tags testMason Reed
2025-07-03Temporarily disable tags for WARP functions tag types are not thread safeMason Reed
Another set of bugs caused by undo and main thread actions, when will it end