Commit graph

3489 commits

Author SHA1 Message Date
pancake
b4e48fb498 Fix #25480 - pcap stream selection support ##bin 2026-08-22 13:08:52 +02:00
pancake
9f345aaaf8 Fix #26431 - Support endian-swapped hex streams in rax2 ##tools 2026-08-22 12:36:05 +02:00
phix33
dbc488df4c Fix esil that writes a destination aliasing its own source ##esil 2026-08-22 05:24:29 +02:00
pancake
da7ed645d6 Add s390 in the test list 2026-08-22 00:34:41 +02:00
pancake
3d9002544e Fix UB in strs and regression in locals 2026-08-22 00:11:16 +02:00
pancake
d54402a3d7 Fix fp local variable and arm32 reg tracking ##analysi 2026-08-21 22:17:04 +02:00
pancake
bc2f45caba Add s390 pseudo parser ##pseudo 2026-08-21 20:23:29 +02:00
pancake
8323266fae Resolve typed JNI table calls in analysis ##analysis 2026-08-21 20:13:08 +02:00
pancake
3957bfe8e3 Fully expand ELF RELR bitmap relocations ##bin 2026-08-21 18:10:59 +02:00
pancake
b81521065a Add support for the android-specific ELF relocations ##bin 2026-08-21 17:59:50 +02:00
pancake
4f0fef3d1b Typed JNI interface tables and indirection ##analysis 2026-08-21 17:38:11 +02:00
phix33
3e2a8f4cfa Fix the x86 mul, div and movbe esil and model the bit counters ##esil 2026-08-21 17:05:57 +02:00
pancake
323fe03d2b JNI types survive deep analysis 2026-08-21 17:05:12 +02:00
pancake
a231a0fd44 Materialize typed JNI native methods during analysis ##analysis 2026-08-21 15:39:55 +02:00
pancake
961e10bc39 Add the new jni analysis plugin ##analysis 2026-08-21 14:26:33 +02:00
pancake
e9dc573b3f
Fix JNI symbol detection for ELF only ##bin 2026-08-21 14:26:23 +02:00
phix33
dfd819cd18 Decode the mips.gnu unaligned word loads and stores ##arch 2026-08-21 14:07:44 +02:00
phix33
faaed48879 Merge the addressed bytes in the mips unaligned loads and stores ##esil 2026-08-21 14:07:44 +02:00
pancake
da8b06b92c Add structured Java and JNI descriptor parsing ##bin 2026-08-21 13:08:41 +02:00
phix33
01cc4a5167 Deduplicate the x86 shift emitters and fix their flag ordering ##esil 2026-08-21 11:17:45 +02:00
phix33
5deee0ae5e Take the x86 shift counts from the right operand ##esil 2026-08-21 11:17:45 +02:00
phix33
2a3b5efc6f Model the x86 rotates through the carry flag ##esil 2026-08-21 11:17:45 +02:00
pancake
5fe07007e1
Port b to task-owned command contexts ##shell 2026-08-21 11:17:17 +02:00
phix33
2134a747c8 Fix the mips.gnu instruction ids and let it decode at 64 bits ##arch 2026-08-21 09:09:45 +02:00
phix33
5d846f0927 Compare and multiply the whole mips64 registers in sltu and multu ##esil 2026-08-21 09:09:45 +02:00
phix33
3b2532b484 Sign-extend the mips 32-bit results and mask the shift counts ##esil 2026-08-21 09:09:45 +02:00
phix33
7ef395ef70 Skip the x86 shift body when the count masks to zero ##esil 2026-08-20 23:28:06 +02:00
phix33
508efc6e0e Zero-extend the 32-bit registers the x86 esil writes by hand ##esil 2026-08-20 23:28:06 +02:00
phix33
787e1a2394 Jump to the right token when the bsf or bsr source is in memory ##esil 2026-08-20 23:28:06 +02:00
pancake
35eeac88b6
Initial support for nvidia ptx sass encode/decode/pseudo ##arch 2026-08-20 23:27:44 +02:00
pancake
94f28e5c43 Fix bic expression for arm64 ##esil 2026-08-20 21:49:40 +02:00
phix33
92dafe14fb Stop afb and afbi from deleting switch cases that share a target ##analysis 2026-08-20 13:48:02 +02:00
phix33
4fc9f91dc2 Fix the x86 adjust flag bit position and adc carry propagation ##esil 2026-08-20 10:01:00 +02:00
phix33
14ffe482e2 Compute the sbb overflow correction before the destination write ##esil 2026-08-20 10:01:00 +02:00
AGhebrea
023c47f2b0
Test no crash on a huge nso decompress 2026-08-20 06:36:56 +02:00
phix33
5eec44d01f Type ppc bcl 20,31 branch-always forms as jumps that set lr ##arch 2026-08-20 06:31:35 +02:00
Priyanshu Kumar
e0a442373b Show the instruction under a typelink that has no format ##disasm
A function type linked at an address has no pf format, and the
disassembly loop skipped the instruction entirely instead of falling
through to disassemble it.
2026-08-20 06:29:42 +02:00
Priyanshu Kumar
3c0735f268 Resolve typedefs before measuring pointer width ##types
A typedef like "typedef char *string" is a pointer with no star in its
name, so r_anal_type_bitsize measured it from the sdb instead of using
the target word size. Resolve the typedef chain first and fail closed
on cycles.
2026-08-20 06:29:25 +02:00
phix33
ec279715f9 Scan the last 20 bytes of a range for ppc64 ELFv1 eager call stubs ##bin 2026-08-20 06:16:58 +02:00
phix33
ee83b0f683 Fix the sbb carry, adjust and overflow flags in the x86 esil ##esil 2026-08-20 06:14:59 +02:00
phix33
4a78dc767a Store to the sbb destination and zero-extend its 32-bit register writes ##esil 2026-08-20 06:14:59 +02:00
pancake
8b4a161977
Recover Swift struct field offsets from type metadata ##bin 2026-08-19 18:15:57 +02:00
Priyanshu Kumar
fcb54e7be5 Drop a stale arg from the float-formal expectation ##analysis
The test recorded `arg int64_t arg2 @ rsi` alongside the DWARF-named formals.
Current master no longer reports it, and does not with this branch's commits
removed either, so the line describes behaviour that changed upstream after
the test was written rather than anything this branch does.

Verified by building master alone at the same fixture and address: the output
is identical apart from that line. The full suite on this branch is 17017 OK
with one failure, `db/formats/dwarf "DWARF mismatch preserves registered type
and stable name"`, which fails on master unchanged.
2026-08-19 18:07:33 +02:00
Priyanshu Kumar
b294be002e Separate a formal's ABI position from its sdb index ##analysis
arg_index counts placed arguments and must stay dense, because
apply_debug_info stops reading at the first missing fcn.%s.arg.%d key.
It was also passed as the formal's ABI position, so the two diverged the
moment a formal was skipped, and every later fallback was handed its
neighbour's register. Count non-result formals separately and pass that
as argno; argc now counts non-result formals too, which is what feeds
the stack-offset math for reverse conventions.

The calling convention tables describe integer slots only, so a float
formal without a location was placed in an integer register it never
occupies, colliding with a located argument sitting there. Skip the
fallback for floating-point and complex types instead.

On bins/elf/dwarf_go_tree that removes four float64 and three complex128
arguments from integer registers, and without the argno fix the removal
shifts twelve later arguments down a slot.

Read DW_AT_variable_parameter through the flag union member the form
parsers actually write, rather than uconstant.

db/anal, db/cmd/dwarf and db/cmd/dwarf2 are 910 OK, 35 BR, 0 XX, 3 SK,
1 FX. The added test is 19/19 with the change and 18 OK, 1 XX without.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 18:07:33 +02:00
Priyanshu Kumar
709b77f7b0 Place formal parameters that DWARF leaves without a location ##analysis
A formal parameter can carry a name and a type but no DW_AT_location,
which happens routinely at -O2 when the parameter is never spilled.
sdb_variable_data() returns NULL without a location, so the argument was
skipped, while the function type is still built from every formal. The
two disagreed on arity: the prototype listed a parameter that no argument
existed for.

Derive the missing storage from the calling convention instead of
discarding the parameter. r_anal_cc_argslot() already answers where the
caller leaves parameter N on entry.

Skip a formal that carries DW_AT_variable_parameter. Go encodes a
function's result slots as formal parameters with that flag set, so
without the check the fallback handed them entry registers they never
occupy, and reflect.maplen(h *hmap) int gained a second argument
named ~r1.

On bins/elf/dwarf_rust_bubble:

  before  void dbg.begin_panic_str_ (int64_t arg1, int64_t arg2, int64_t arg3);
  after   void dbg.begin_panic_str_ (&str msg, int64_t arg2, int64_t arg3);

db/anal, db/cmd/dwarf and db/cmd/dwarf2 are 909 OK, 35 BR, 0 XX with the
change. The new test fails without it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 18:07:33 +02:00
phix33
16b28385c3 Render arm conditional branches as v conditions in the pseudo output ##disasm 2026-08-19 15:03:29 +02:00
phix33
8f2ecdd8f5 Zero-extend every W register the arm64 ESIL writes ##esil 2026-08-19 13:03:59 +02:00
potato
7de7b679bd
Measure typedefs in r_type_get_bitsize ##types 2026-08-19 11:36:35 +02:00
pancake
71423fa7db Fix blockers that restricted pdc.structured ##pseudo 2026-08-19 01:42:42 +02:00
Priyanshu Kumar
798d9cfef1 Zero-extend 32-bit register writes on arm64 ##esil
A write to a `w` register clears the top half of the `x` register it sits
in. ESIL does not do that on its own: naming `w9` stores four bytes and
leaves the rest of `x9` as it was, so

    ar x9=0xffffffff00000001
    ar x10=1
    wx 29010a0b       ; add w9, w9, w10
    aes; ar x9
    before  0xffffffff00000002
    after   0x2

The same held for every `w` destination: the arithmetic helpers, the
loads, the moves. It is appended once where the instruction's ESIL is
finished rather than at each of the sites that spell a destination, and
after the flag assignments so the extension cannot disturb the comparison
state they read. Storing through the 64-bit name clears the top half
without reading it, so `aea` still reports only what is really read.

Five expectations move, all because a 32-bit write now fully defines its
register and the type backtrace can follow it:

- db/anal/types: `mov w0, 1` picks up `int fd`
- db/anal/jmptbl: the three CCCrypt argument registers pick up their
  parameter types, which is what that test is named for
- db/cmd/charset: `arg1` moves from `add x0, sp, 0x28` to the `ldr w0`
  that actually sets the register the call reads, the `add` result being
  consumed by `mov x1, x0` for `arg2`; and `mov w1, 0x63` picks up `arg2`
  for `WriteAddress_DWORD(long, int)`

The full r2r suite is 17001 OK, 1043 BR, 1 XX, 30 SK, 33 FX; the single
failure, db/formats/mangling, fails identically without this change.

The x86-64 counterpart landed as e3d433fb8e.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 00:08:49 +02:00