From ac359f8bcbbb64c9c89a821bb65879178815ce37 Mon Sep 17 00:00:00 2001 From: Brian Potchik Date: Thu, 21 May 2026 11:10:34 -0400 Subject: Accept lone '?' as full-byte wildcard in FlexHex search. --- python/binaryview.py | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) (limited to 'python/binaryview.py') diff --git a/python/binaryview.py b/python/binaryview.py index 77afd54a..039c94ee 100644 --- a/python/binaryview.py +++ b/python/binaryview.py @@ -10090,11 +10090,13 @@ to a the type "tagRECT" found in the typelibrary "winX64common" limit: Optional[int] = None, progress_callback: Optional[ProgressFuncType] = None, match_callback: Optional[DataMatchCallbackType] = None) -> QueueGenerator: r""" Searches for matches of the specified ``pattern`` within this BinaryView with an optionally provided address range specified by ``start`` and ``end``. - This is the API used by the advanced binary search UI option. The search pattern can be interpreted in various ways: + This is the API used by the advanced binary search UI option. The pattern is interpreted as one of: - - specified as a string of hexadecimal digits where whitespace is ignored, and the '?' character acts as a wildcard - - a regular expression suitable for working with bytes - - or if the ``raw`` option is enabled, the pattern is interpreted as a raw string, and any special characters are escaped and interpreted literally + - ``"FlexHex"``: a sequence of byte tokens drawn from ``[0-9a-fA-F?]``, where ``??`` (or a whitespace-separated lone ``?``) is a full-byte wildcard and ``?X`` / ``X?`` matches a single nibble. Whitespace between byte tokens is optional, but a lone ``?`` must be whitespace-separated (so ``c3 ? 55`` is valid; ``c3?55`` is not). + - ``"Regex"``: a byte-level regular expression. + - ``"Raw String"``: a literal string match. Used when ``raw=True``, or as a fallback when the pattern is neither valid FlexHex nor a valid regex. + + Use :py:meth:`detect_search_mode` to check which mode would be selected for a given pattern. :param pattern: The pattern to search for. :type pattern: :py:class:`str` @@ -10122,6 +10124,8 @@ to a the type "tagRECT" found in the typelibrary "winX64common" >>> bytes(list(bv.search("50 ?4"))[0][1]).hex() '5004' + >>> bytes(list(bv.search("E8 ? ? ? ?"))[0][1]).hex() # call with 4-byte wildcard operand + 'e83e380000' >>> bytes(list(bv.search("[\x20-\x25][\x60-\x67]"))[0][1]).hex() '2062' """ @@ -10176,6 +10180,12 @@ to a the type "tagRECT" found in the typelibrary "winX64common" """ Detects the search mode that would be used by :py:meth:`search` for the given pattern. + The mode is one of: + + - ``"FlexHex"``: a sequence of byte tokens drawn from ``[0-9a-fA-F?]``, where ``??`` (or a whitespace-separated lone ``?``) is a full-byte wildcard and ``?X`` / ``X?`` matches a single nibble. Whitespace between byte tokens is optional, but a lone ``?`` must be whitespace-separated (so ``c3 ? 55`` is valid; ``c3?55`` is not). + - ``"Regex"``: a byte-level regular expression. + - ``"Raw String"``: a literal string match. Returned when ``raw=True``, or as a fallback when the pattern is neither valid FlexHex nor a valid regex. + :param str pattern: The search pattern to analyze. :param bool raw: Whether to interpret the pattern as a raw string (default: False). :return: The detected search mode: ``"FlexHex"``, ``"Regex"``, or ``"Raw String"``. -- cgit v1.3.1