#pragma once #include #include #include "GuidRenderer.h" #include "ModuleType.h" #include "TypePropagation.h" #include "binaryninjaapi.h" #include "highlevelilinstruction.h" #include "lowlevelilinstruction.h" #include "mediumlevelilinstruction.h" using namespace BinaryNinja; using namespace std; typedef array EFI_GUID; class Resolver { protected: Ref m_view; Ref m_task; size_t m_width; map> m_protocol; map m_user_guids; vector> m_service_usages; vector> m_protocol_usages; vector> m_guid_usages; vector> m_variable_usages; bool parseUserGuidIfExists(const string& filePath); bool parseProtocolMapping(const string& filePath); /*! For backward compatibility, if a user saved a bndb with older version Binary Ninja this function will try to retrieve types from Platform Types if it doesn't find one in BinaryView */ Ref GetTypeFromViewAndPlatform(string type_name); void initProtocolMapping(); public: bool setModuleEntry(EFIModuleType fileType); bool resolveGuidInterface(Ref func, uint64_t addr, int guid_pos, int interface_pos); Resolver(Ref view, Ref task); pair lookupGuid(EFI_GUID guidBytes); pair defineAndLookupGuid(uint64_t addr); string nonConflictingName(const string& basename); static string nonConflictingLocalName(Ref func, const string& basename); /*! Define the structure used at the callsite with type `typeName`, propagate it to the data section. If it's a structure type, define it fields according to the `followFields` parameter. The input `addr` should be a call instruction \param func the function that contains the callsite (it's parent function) \param addr address of the callsite \param typeName the type that need to define \param paramIdx the parameter index that want to define \param followFields whether to define the structure's fields if they are pointers \return False if failed \b Example: \code{.cpp} refs = bv->GetCodeReferencesForType(QualifiedName("EFI_GET_VARIABLE")); for (auto ref : refs) { // ... some checking, need to make sure is a call instruction bool ok = defineTypeAtCallsite(ref.func, ref.addr, "EFI_GUID", 2, false); } \endcode */ bool defineTypeAtCallsite( Ref func, uint64_t addr, string typeName, int paramIdx, bool followFields = false); vector HighLevelILExprsAt(Ref func, Ref arch, uint64_t addr); };