| Age | Commit message (Collapse) | Author |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Create a cache variable of the same name as the previous normal variable
that users can set to a specific path for user plugin installation
destination.
This is primarily to help with CI builds to make it easier to find where
the final plugin is located before uploading as a release.
|
|
TypeBuilder.handle creates an immutable_type gets the handle and then deletes the object to which the handle belonged to.
This was fundamentally a UAF. immutable_copy is an error prone api as its very easy to misuse. We should consider a re-architecture of this API. `TypeBuilder.immutable_copy().<anything>` or `Type.mutable_copy().<anything>` should be considered sketchy and immutable_copy().handle is just a straight up UAF. Prior to this commit the following would cause a crash:
current_data_variable.type = PointerBuilder.create(FunctionType.create())
|
|
instead of accept the whole dialog
|
|
documentation.
|
|
This change allows architecture plugins to override the LiftFunction
callback to iterate a function's basic block list and lift entire
functions at once. This is required for architectures such as TMS320
C6x, which have non-traditional "delay slots" in that branches, loads,
and other instructions take multiple cycles to complete, and branch
instructions can reside within the delay slots of other branches.
|
|
|
|
|
|
|
|
Closes #7851.
|
|
|
|
1. A section's `flags` are masked with `SECTION_TYPE` before being
compared. This prevents misclassifying a section when its low bits
are shared with other section types.
2. `__mod_init_func` and `__init_offsets` are identified by section type
flags, rather than by name. There's no documented reason why these
were being matched by name.
3. A fallback is added to detect `__got` sections by name. This is
necessary as some kext bundles that have their `__got` sections as
`S_REGULAR` rather than `S_NON_LAZY_SYMBOL_POINTERS`. This fixes
https://github.com/Vector35/binaryninja-api/issues/7891.
Thanks to @WHW0x455 for these fixes.
|
|
copy_expr_to
|
|
|
|
|
|
|
|
|
|
|
|
|
|
This fixes the incorrect type hint and the other instance of the
function. It also looks like type parsing could have the same issue, so
I've updated that as well.
|
|
associated coreversion usage
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Introduces a Pythonic get_metadata() method to BinaryView, Function, Project,
TypeArchive, and TypeLibrary classes. This method behaves like dict.get(),
returning a default value (None by default) when a key doesn't exist, instead
of raising a KeyError.
Additionally, updates query_metadata() in TypeArchive and TypeLibrary to raise
KeyError when a key is not found, making them consistent with BinaryView,
Function, and Project. Previously these two classes returned None on missing
keys. This breaking change is documented in the method docstrings.
This provides a more consistent and Pythonic API for querying metadata across
all metadata-supporting classes.
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
|
|
This introduces two new dataclasses SegmentInfo and SectionInfo which hold information about their respective objects. These are used for specifying information to a BinaryView while class Segment and Section are still the objects used after registration. Additionally I've created two helper functions in Segment/Section which return the respective Info structure which could be useful if you wanted to modify existing Segments/Sections
Currently these two APIs are only used by the add_segments/add_sections APIs but maybe more useful in the future.
|
|
inlining during analysis
Previously the address of the instruction in the function being inlined
was used as the new instruction's address when copying it during
inlining. Now there is an additional option: use the address of the
call instruction that is being replaced as the new instruction's
address.
This new mode is useful when inlining thunks or stub functions, but care
must be taken if using it beyond that.
The benefit is that it ensures that when a function contains multiple
calls to the same stub function, each inlined copy ends up with distinct
addresses. This ensures that call type adjustments and other overrides
that are stored on the function and keyed by address can be applied
independently to each callsite that was inlined.
The trade-off is that if the function being inlined contains non-trivial
logic, all of the inlined instructions sharing an address will limit
what type of adjustments can be applied to them.
The Objective-C and shared cache workflows are updated to take advantage
of this new mode when they enable inlining of stub functions. This will
make it possible for multiple calls to the same runtime function within
a single function to have separate call type adjustments applied in the
future.
|
|
|
|
- Allow extern functions to show up in a MSVC vtable
- Fix https://github.com/Vector35/binaryninja-api/issues/7871
- Share code between itanium and msvc vft analysis, it is the same logic basically
|
|
|
|
|
|
|
|
System Python on macOS is still 3.9, so match/case doesn't exist.
|
|
generation
|
|
|
|
|
|
|
|
|
|
Assign the `session_id` span field before calling into the relocation handler so logs get scoped to the specific view.
|
|
|
|
Would be really nice if we consolidated this somewhere so this does not keep happening
|