Commit graph

2899 commits

Author SHA1 Message Date
Anton Kochkov
689bafb7a4
Rewrite the RzNum parser and calculator on tree-sitter (#4326)
Replace the hand-written parser in calc.c with a tree-sitter grammar
(subprojects/rizin-math-parser) and a typed evaluator. The old parser
could only ever produce a ut64 and folded anything it failed to read to
0, which left callers unable to tell a failed expression from one that
evaluated to zero.

Expressions now evaluate to an RzNumValue, a tagged union over ut64,
double, RzBitVector, arbitrary-precision integer and arbitrary-precision
decimal, carrying an RzNumError rather than signalling failure as 0.
Literals keep the width they were written with (5u8, 0xffu128, any width
from 1 to 65536), results that outgrow 64 bits promote to a big number on
their own, and a parse error, division by zero or unresolved identifier
reaches the caller.

rz_num_math() is deprecated. rz_num_math_ut64() keeps its exact behaviour
for callers that want a ut64, and rz_num_math_value() exposes the typed
result. rz_core_math() adds the RzCore-backed form used by the % command,
with rz_core_math_ut64() deprecated alongside it. rz-ax routes through the
typed API, so it prints values at full precision, reports errors on stderr
and exits non-zero. rz_il_lift_num() converts an expression to an
RzILOpPure, so a numeric argument can be lifted instead of pre-evaluated.

Legacy input still works: trailing base suffixes (101b, 35o, 212t), the
trailing-'h' hex form and the k/m/g scale suffixes are all accepted and
warn once, pointing at the 0b/0o/0t prefixes. doc/math.md documents the
language and doc/math-il-lift.md the lift; the grammar, the evaluator,
rz-ax and the % command are covered by unit and db tests.
2026-07-24 02:57:27 +08:00
Farhan Saiyed
fa2db74f86
Change rz_config variables to use Set instead of List (#6623)
* Update rz_config list variables to set variables

* Linking error fix

* Update rz_config_get_options in cautocmpl.c

* Update rz_config_get_options in core/tui/config.c

* Test fix

* Assertion error fix
2026-07-23 15:09:58 +00:00
Farhan Saiyed
78045e8fc6
Fix x-axis address overflow in histogram (#6563) 2026-07-23 15:06:28 +00:00
Florian Märkl
3a22989501
Replace self-jmp in SPARC RzIL (#6632)
To perform the effect in a delay slot, if the branch was not taken, the
IL, which is already lifted as part of the delay slot instruction, would
explicitly jump to itself again, to execute the effect as normal.
This would create erroneous loop edges in the cfg.
It is actually not necessary to perform this jmp since we already have
the lifted effect and can inline it.
2026-07-23 14:57:14 +02:00
MrQuantum1915
6150ac78bc
Fix classification of xrefs as data xrefs(#6612)
While processing xrefs for marking them as data:

1. classify target using `xref_ref_kind` for data section too, previously it was only classified if target was in exec segment. Which caused false positive when the target was in non-exec section. Happens when the immediate value is small and it points in data section.

2. restrict data block from bleeding into other sections. Currently it correctly caps data block  at next "detected" function (or next data) but when the function is not detected yet (like in stripped bins) and the area onward from data ref is empty, the data block bleeds into other sections specifically executable section. This should never happen.
2026-07-21 14:43:58 +00:00
Florian Märkl
9b57c7a8ec
Add exclusions to config saving (#6629)
This will be used for future experimental options that are subject to
frequent change and should not pollute projects.
2026-07-21 13:03:05 +02:00
Dmitry Opokin
cd1ad98598
Enhance milstd1750 analysis (#6557) 2026-07-21 16:53:41 +08:00
Farhan Saiyed
12cf18e7b0
unicode version update (#6595) 2026-07-19 17:54:12 +08:00
Jagath P
1d0320367b
Capstone eBPF disassembly (#6611) 2026-07-19 17:51:24 +08:00
مصطفي محمود كمال الدين
faf4afc0e3
Implement file download from the remote machine in GDB protocol (#6576) 2026-07-18 14:49:31 +08:00
billow
ffacc9e08f
Update capstone-next and support Alpha instruction ID variants (#6621)
* Support Capstone Alpha instruction ID variants
* Update capstone-next to ae11e423
* Fix memory leaks in rz-asm
2026-07-17 00:53:43 +08:00
Florian Märkl
1c4bcf6ef7
Fix and test lm32 disasm and replace unsafe string handling (#6620)
Tests are added for covering all edited lines and bugs fixed that were
discovered from these tests.
2026-07-14 16:12:32 +02:00
Khairul Azhar Kasmiran
5d699e8feb
Allow seek to flag realnames (#6593)
Flags are sorted into the name hashtable with their realnames as well.
Refcounting is used to prevent double-free and similar issues that would
be caused by this.
2026-07-14 16:12:05 +02:00
Florian Märkl
9836b05b05 Rewrite unsafe string handling in i8080 disasm 2026-07-13 19:44:09 +02:00
Florian Märkl
f762b37ca8 Replace sprintf usages in 8051 disassembly 2026-07-13 19:44:09 +02:00
Rot127
d2d6846e58 Speed up rz_bv_set_from functions 2026-07-12 09:35:08 +02:00
Florian Märkl
5353b06952 Replace unsafe string functions in gb plugins
None of these should be exploitable, but we want to get rid of these
unsafe functions.
2026-07-11 15:57:50 +02:00
Florian Märkl
f430f28c02
Make rz_interval_tree_insert return the node (#6613)
There are APIs for which the node is needed, so it makes sense to return
it directly on insertion instead of only the boolean success state.
2026-07-11 14:08:35 +02:00
MrQuantum1915
de80709985
lbrz/core/cmd: fix config print for plugins (#6567) 2026-07-09 22:25:59 +08:00
Farhan Saiyed
d2859bbfdd
Update cconfig.c to make =? behave like =?? (#6546) 2026-07-09 09:58:26 +08:00
wargio
f941f85187 Optimize cmd_0 tests. 2026-07-07 23:14:47 +08:00
wargio
c7dd1a9787 Fix behaviour of pb and ensure buffer is always smaller than block. 2026-07-07 23:14:47 +08:00
NOT XVilka
155ead6822
librz/reg: derive CC with more than four argument registers (#6600)
rz_reg_profile_to_cc() only emitted the first four argument registers
(A0-A3), so architectures that pass more arguments in registers -- the
C6000 EABI uses ten, and x86-64/riscv/ppc all declare more than four --
got a truncated convention. Walk the whole A0-A9 role range, stopping at
the first role the profile leaves undefined, and build the cc string with
RzStrBuf. Covered by a new test_reg unit test.

Co-authored-by agent: Claude/claude-opus-4-8

Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-07-06 03:35:41 +08:00
Khairul Azhar Kasmiran
4897885c5c
Uniquify function flag realnames (#6601) 2026-07-05 22:33:25 +08:00
Naren Sirigere
3c02fa5618
Fix x64 and x86 SEH analysis (#6558) 2026-07-04 15:46:13 +08:00
Khairul Azhar Kasmiran
6249c2e5f2
Fix tn- <flag> (#6589) 2026-07-04 11:51:58 +08:00
Florian Märkl
ff4d6608c0
Add rz_bv_append_inplace() (#6592)
Warning: this also swaps the arguments of the old rz_bv_append() to be
consistend with the new inplace variant.
The reason why the inplace function has the low as the first operand is
that it can be more efficient to append to an existing vector inplace
than to prepend to it. Then, the first argument is being used as the
in-out one in all other inplace functions.
2026-07-03 23:31:30 +08:00
MrQuantum1915
893ff4e380
librz/util/pj: Fix JSON depth limit handling (#6533) 2026-07-02 15:21:36 +08:00
Khairul Azhar Kasmiran
90a2b56509
Fix tn- <hex_number> (#6585) 2026-07-02 11:11:28 +08:00
Naren Sirigere
6dbd1198c8
Recognize objc_msgSendSuper2 and objc rtti information (#6529) 2026-07-02 11:10:20 +08:00
Naren Sirigere
478117db3b
Bump rz-libdemangle to get the dlang demangler (#6566)
Fix check_dlang() to check if the string starts with "_D" followed by any digit
2026-06-28 12:50:08 +08:00
Rot127
39ab034d28
Don't print meta items which are not at the current seek. (#6559)
* Don't print meta items which are not at the current seek.

The old code tried (unsuccessfully) to print _any_ meta item _covering_ the seek (ds->at).

There seems to be several bugs getting triggered with that.
One of them giving the behavior of https://github.com/rizinorg/rizin/issues/6556.

If the current seek is in a _data_ region, the disassembler logic doesn't care.
It just assumes that RzAsmOp.size is equivalent to the size of the objects there.
Even though there are only Meta items.

But since some meta items are like 4K bytes, RzAsmOp.size gets
trimmed down.
Anyways, that completely messes up the size calculation (as can be seen in the issue),
and the navigation.
I couldn't figure out where stuff broke.
But the library closes and I have to leave, so I push that.

That "fix" makes it at least behave somewhat consistently.

* Fix leaks

* Fix and add interactive test
2026-06-27 10:36:12 +00:00
Ashish Kumar
53e8999271
implement shake-128 and shake-256 (#6490) 2026-06-23 11:47:13 +08:00
Dmitry Opokin
9d37b7cdf2
Add MediaTek md1img and GFH firmware image parsers (#5974)
- Introduced md1img.h and md1img.c for parsing MediaTek md1img container format.
- Implemented mtk.h and mtk.c for parsing MediaTek GFH firmware images (md1rom).
- Added plugin support for md1img and mtk formats in bin_md1img.c and bin_mtk.c.
- Updated meson.build to include new source files and plugins.
- Enhanced RzBuffer utility with LZMA alone decompression support.

---------

Co-authored-by: Giovanni <561184+wargio@users.noreply.github.com>
2026-06-22 20:25:48 +00:00
billow
bb3b7cc7b1
Add JSON projection grep (#6522) 2026-06-22 17:17:20 +00:00
Rot127
da228d11cf
Add all call and other xrefs to the abl output (#6269)
* Ensure call targets are only added once for each block.
* Fix abl printing correct xrefs
2026-06-21 13:02:40 +08:00
مصطفي محمود كمال الدين
59d8c998e5 fix positive zero comparing inequal with negative zero, IEEE754 mandates equality 2026-06-21 03:48:49 +08:00
NOT XVilka
c351d5f32a
librz/cons: new "underwater" color theme (#6538)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-20 21:57:01 +08:00
NOT XVilka
06217cd05e
librz/type: fix forward type for enums (#6539)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-20 17:32:06 +08:00
NOT XVilka
2e8d857e63
Fix no-return function propagation (#6449)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-20 05:29:18 +08:00
NOT XVilka
37d11d985a
librz/arch/tms320: add support for the TMS320C54x series (#6534)
* arch/tms320: add TMS320C54x disassembly support

Add a C54x instruction decoder that reuses the shared C55x decode engine
(c55_decode/c55_format) via the C55ArchDesc plug-in interface, rather than
duplicating the matcher/formatter. Disassembly only for now (.lift = NULL).

Engine changes (c55_ir.c/.h):
 - add C55ArchDesc.words_le so the decoder can byte-swap the little-endian
   16-bit instruction words used by the C54x COFF object format;
 - add a self-contained C54x memory-operand renderer (direct @dma, MMR,
   indirect *ARx with all post-modify modes, *ARx(lk) const-index, *(lk)
   ABS16 absolute and circular '%' addressing) and bare-hex immediates;
 - add C55Operand.circular for the '%' suffix and C55Operand.space_join
   for the space-separated second half of a C54x parallel instruction;
 - extend the data-memory operand-field analysis (register, base pointer,
   displacement, direction, referenced size) to the LOAD/STORE op types the
   C54x ld/st family uses, in addition to the C55x MOV form.

The C54x decoder (isa/tms320/c54x/c54x.c) covers the complete documented
instruction set - all 117 mnemonics of the SPRU172 opcode map, in every
documented encoding form:
 - load/store/move, integer and logical ALU ops in every addressing form
   (Smem, #lk, dual-accumulator, Xmem/Ymem, TS/ASM/SHIFT-shifted, the
   shift-by-16 and #lk,16 long-immediate forms, and the two-word
   Smem,SHIFT form whose operation selector lives in the second word);
 - the full multiply/MAC family: Smem, #lk, program-memory, squaring,
   multiply-by-A, signed-unsigned and the dual-operand MAC[R]/MAS[R]
   Xmem,Ymem forms;
 - the parallel (dual-operation) class rendered "op1 .. || op2 .." -
   ST||ADD/SUB/LD/MPY/MAC[R]/MAS[R], ST||LD T and LD||MAC[R]/MAS[R];
 - double/long-word (Lmem) add/subtract, the unary accumulator ops
   (exp/norm/abs/neg/rnd/sat/min/max/rol/ror/sftc/cmpl/...);
 - control flow with the separate delayed (bd/calld/bcd/banzd/fcalad/...)
   variants, conditional return/execute (rc[d]/xc) and the multi-condition
   "tc, c"-style combinable condition fields, repeats (incl. rpt #lk),
   conditional stores, I/O port access, status-bit set/clear and the
   non-linear idle encoding.

Operands resolve to their architectural names - the full memory-mapped
register file (AR0-AR7, the accumulator AL/AH/AG/BL/BH/BG halves, T, TRN,
SP, BK, BRC/RSA/REA, IMR/IFR, PMST, XPC), the ST0/ST1 status bits and the
named condition codes; the memory-mapped-register operand is kept single
word (its long-offset modes are not legal). The analyzer classifies every
instruction (op->type, op->id), resolves branch/call targets and the stack
effect of calls/returns/pushes, and exposes operand details: the register,
base pointer, displacement and access direction of data-memory loads and
stores, and the target register of indirect branches/calls.

All encodings were verified byte-exact against the TI asm500 assembler,
and every decoded instruction re-assembles to an identical encoding (a
full-opcode-space disassemble/reassemble round-trip is stable). A 297-case
disasm test suite and an analysis test suite (opcode classification, branch
and call targets, stack effects, memory-operand fields, data-immediate values, the register
profile, named instruction ids and COFF binary-fixture function discovery)
are added, and the real-world emulateme C54x .text decodes cleanly.

* arch/tms320: add TMS320C54x RzIL lifting

Lift the C54x integer core to RzIL so emulation and IL-based analysis work
for C54x as they already do for C55x/C55x+.

- Register profile: C54x previously fell through to the C64x profile
  (a0-a31, =PC pce1), wrong for the A/B accumulator core. Add a proper
  C54x profile: the two 40-bit accumulators A/B (with the L/H 16-bit and
  G 8-bit guard slices overlapping their parent), AR0-AR7, T/TRN, SP, DP,
  BK, ST0/ST1/PMST, BRC/RSA/REA, IMR/IFR, XPC and a 24-bit PC.

- IL VM config: tms320_c54x_il_config() binds the canonical registers; the
  accumulator slices stay unbound, the lifter expresses them as bit-slices
  of A/B so they never desynchronise.

- Lifter (C55ArchDesc::lift hook, dispatched by c55_lift): the no-shift
  forms of LD/LDU/LDR/LDM, ADD/SUB/AND/OR/XOR, STL/STH/STLM/STM, the mvd*
  memory-to-memory moves, the DLD/DST 32-bit double-word load/store (high
  word at the lower address), PSHM/POPM and RET. Shift/round/saturate
  variants are left unlifted (their shift count is carried only as a
  display string); the engine's generic EA/read/write/post-modify helpers
  are reused for the addressing modes.

Tested via two new RzIL VM blocks in test/db/rzil/tms320: a register/
immediate/memory execute test, and an end-to-end emulation of the
emulateme binary's _decrypt (a UART hex-writer) showing the IL VM emits
the hex digits and advances the write position.

---------

Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-20 05:28:41 +08:00
NOT XVilka
9217b0a86a
librz/arch/sh: add SuperH-3 support via asm.cpu (#6531)
Co-authored-by agent: Claude/Claude-Opus-4.8
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-19 04:37:30 +08:00
NOT XVilka
070c004e0c
rz-find: flush output to avoid undeterminism (#6527)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-18 14:56:02 +08:00
Rot127
110c812219
librz/arch/x86: fix ADC, AND, OR, SBB RzIL lifting (#6524)
* Cast operands for AND and OR instructions to the correct width
* Add missing operand casts for SBB and ADC.
* Add flawed instructions to asm tests

---------

Co-authored-by: Dhruv Maroo <dhruvmaru007@gmail.com>
2026-06-18 11:07:43 +08:00
MrQuantum1915
b9d2a03be3
librz/core/tui: fix panel mode and visual modes cmd format and redundant quotes (#6520)
* Fix and add new gadget search cmds
* Fix some more commands and menus
* Fix /a error message
2026-06-18 11:06:17 +08:00
Khairul Azhar Kasmiran
43cb43ed18
Add reliable http:// test (#6509)
* Add reliable http:// test
* REUSE.toml: Add `test/www/**` entry
* Use `cwd` instead to work around old http.server in Python 3.6
* Move test to `not-windows-any`
* NetBSD: Add `python3` symbolic link
* Prevent test from running on woodpecker
2026-06-18 07:01:00 +08:00
NOT XVilka
f205e231ef
arch/tms320: drop c55x+ global state, populate op->val, lift rptadd/rptsub (#6525)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-18 03:52:09 +08:00
NOT XVilka
e43565fade
librz/core/disasm: dedup symbol name when realname is used (#6518)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-17 11:22:30 +08:00
NOT XVilka
8fde88fd9e
rz-asm: show an error when -m arg is invalid (#6519)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-17 11:22:17 +08:00
NOT XVilka
880c8005f7
librz/arch/x86: uplift scalar FP SSE/SSE2 insns to RzIL (#6517)
Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com>
2026-06-17 11:22:04 +08:00