Commit graph

1897 commits

Author SHA1 Message Date
Anton Kochkov
2cbe8fe0f0
Update capstone-v5 to 5.0.1 (#3777) 2023-08-23 16:00:11 +08:00
Peiwei Hu
8b792f5a81
Fix: overflow of core->block in the handler of plf command (#3762) 2023-08-18 10:01:41 +08:00
Giovanni
305a2cb3ae
Add SM3 hash (#3769) 2023-08-17 21:59:06 +08:00
Pavel I
061c56f4c4 RzStrBuf: remove weakref related code 2023-08-15 09:00:22 +08:00
blarn
e3617f7981
Expand pc commands to accept size argument (#3738) 2023-08-10 22:55:25 +08:00
Peiwei Hu
d71f4a2128
Add new command plf to print the RzIL of the function (#3724)
+ expose API rz_core_analysis_bytes_il
+ add new command `plf`
+ add test test/db/cmd/cmd_plf
2023-08-05 22:27:54 +08:00
billow
48b0880562
Fix tricore jumps/calls syntax #3664 (#3708)
* Fix tricore jump address set
* Fix tricore sub jumps
* Add TRICORE asm pattern
2023-08-04 10:44:07 +08:00
Rot127
cebe0b5081 Add test for custom bf coloring. 2023-08-04 08:18:51 +08:00
Gleb Popov
f3667b0963 Introduce rz_core_analysis_cc_init_by_path() that allows specifying a path to cc data. 2023-08-03 15:35:25 +08:00
Gleb Popov
30ba928f54 test/unit/test_analysis_var: Use types DB from the build dir. 2023-08-03 15:35:25 +08:00
Anton Kochkov
45f1153d41
unit: test_str compiler warnings fixes (#3716) 2023-08-02 20:46:04 +08:00
Giovanni
1272933338
fix -M and bin.demangle (#3709) 2023-08-01 19:27:42 +08:00
Riccardo Schirone
bd5268f9aa
core: fix output of pC commands (#3692) 2023-08-01 18:32:24 +08:00
frmdstryr
c9fe729ce0
Make rz_core_analysis_var_display work with stack vars when debugging (#3687) 2023-07-28 01:40:22 +08:00
Hertatijanto Hartono
d1fd135df3 Reopening file should not be identified as an error 2023-07-25 11:02:11 +08:00
Anton Kochkov
ba84a920ad Improve parsing C syntax up to C23 2023-07-23 19:04:05 +08:00
Anton Kochkov
fd8086bcc8
Show realname in fl.t table output (#3682) 2023-07-23 13:46:26 +08:00
svr
832e5b0d36
Rewrite LE plugin (#3666)
* Apply relocations, jump tables are detected correctly now
* Use virtual files for patching and relocation targets
* Create continous sections where possible instead of a section per page
* Support for DOS extender bound LE executables
* Support page compression of type 1 (iterated) and 5 (compressed)
* Add support for 16 bit relocations
* Fix numerous issues, leaks, UB, etc
2023-07-22 21:39:30 +08:00
Anton Kochkov
07747e2ba8
Update rz-libdemangle (#3680) 2023-07-21 13:01:23 +08:00
Anton Kochkov
47701f65b4
Fix fl. commands and add tests (#3678) 2023-07-20 21:17:14 +08:00
Anton Kochkov
f1006f97c2
arm: use cortexm cpu instead of cortex (#3674) 2023-07-20 16:20:04 +08:00
Anton Kochkov
d581fc2528
test: remove duplicate dbg.fds.count test (#3673) 2023-07-20 13:33:20 +08:00
Heersin
c0850845f1
RzIL: asm tests for ARM32 VFP and NEON (#3662) 2023-07-20 11:30:17 +08:00
Parth Bansal
0ed81d522b
Add p=r command to display entropy edges (#3671) 2023-07-20 11:21:50 +08:00
Florian Märkl
aa2c54f128
Add support for PT_OPENBSD_NOBTCFI detection (#3663)
OpenBSD enables arm64 BTI or Intel IBT by default, except when the
binary was linked with -Wl,-z,nobtcfi in order to opt-out. In this case,
a PT_OPENBSD_NOBTCFI segment will exist, which we can indicate in the
bin info.
See also https://undeadly.org/cgi?action=article;sid=20230714121907

Original Commit: 4551bf03461595a9645051347ad026974227ac6d

Co-authored-by: pancake <pancake@nopcode.org>
2023-07-18 08:26:21 +08:00
Giovanni
8f2eb45b84
Add bin.demangle.flags to allow users to simplify or not mangled strings (#3659) 2023-07-17 23:31:09 +08:00
wargio
99c5f833c5 Mark as broken the ARM 16 test which fails to disassemble. 2023-07-16 13:22:47 +08:00
wargio
3578cbb4fc Improve sparc analysis and fix tests. 2023-07-16 13:22:47 +08:00
billow
e456c60e20 Fix tests for capstone v3/v4/v5
Co-authored-by: wargio <wargio@libero.it>
2023-07-16 13:22:47 +08:00
yossizap
0cf4cd75b3 Update capstone instruction ids 2023-07-16 13:22:47 +08:00
Anton Kochkov
f29171ceb1
Remove rzk and gprobe IO plugins (#3654) 2023-07-12 00:21:43 +08:00
Anton Kochkov
8e41d975bf
Easier API for creating global variable (#3655) 2023-07-11 20:53:34 +08:00
Heersin
803aa3951e
ARMv7 NEON and VFP for rzil (#3528)
* Export float basic op to op_builder header

* Basic vmov with note and question

* Add vmov for immediate

* Add vmov for NEON and VFP

* Add vmsr, vmrs. shared instruction of vfp and neon done

* Add vector logical operations for arm32 il

* Add vmvn for arm32 il

* Solve op builder for rzil float

* Add vector compare instructions (vceq/vcge/vcle/vcgt/vclt, and abs version)

* Rename vcmp to vec_cmp to avoid conflict with VCMP instruction

* Add vtst of NEON instruction set

* Fix FEQ

* Discard unecessary changes

* Add vldn for multiple n-elements

* Add vldn for single-lane and all-lane

* Add vstn

* Add vcvt for float-integer and float-float

* Check codeql warning

* Add vdup

* Fix according to reviewer

* Add vext

* Add vzip

* Fix reg_bits shadowing

* Add vuzp

* Init some eff as EMPTY for loop-seq

* Add vswap

* Add vadd and vsub

* Add vmul for float point in vfp

* Fix test_validate_forder

* Fix reg binding by add missing reg(fpscr)

* Fix memory broken caused by misuse of REG_VAL and others

* Add vldr and vstr

* Fix some bug in rzil float

* Fix a format typo bug in rzfloat

* Add rzil emulateme test for vfp

* Fix fpscr in db arm32 related tests

* Add extra argument info in vfp test

* Remove duplicated macro of float
2023-07-09 00:43:18 +08:00
Riccardo Schirone
40a01ef36f
Show even sections with 0 size/vsize (#3640) 2023-07-07 11:45:39 +08:00
Riccardo Schirone
194eabae1c
Fix /wi by removing wrong fallthrough (#3636)
/wi was falling through the switch case and it was not accepting the
input correctly. Fix this by breaking at the end of the '/w' case so
that the search can begin.
2023-07-04 17:09:28 +08:00
Giovanni
8efdb3d3a3
Refactoring debug plugin and cleanup output (#3634) 2023-07-04 10:42:41 +08:00
Anton Kochkov
8c1ce710e1
Remove type links and use global vars (#3618) 2023-07-03 02:02:12 +08:00
Florian Märkl
54640cb01c Fix rz_buf_read_at() after negative addr
rz_buf_read_at() with a negative addr on a ref (slice) buffer broke all
subsequent calls to rz_buf_read_at(). This is fixed by making sure to
always reset to the initial seek.
This bug was detected through xnu kernelcaches, where we may also skip
any obviously invalid read.
2023-07-01 22:28:28 +08:00
Giovanni
5badfe10f6
Always search for preludes if is not x86. (#3615) 2023-06-30 13:20:37 +08:00
Anton Kochkov
b5a936585a Rename analop to analysis_op and aop 2023-06-26 08:40:47 +08:00
Florian Märkl
ebe4263323 Implement chained fixups patching for binds
For bind chained fixups (pointing to imports parsed in the previous
commit) we reuse the patching code for classic relocs as the logic is
more generic here than for local chained fixups.
2023-06-25 19:39:56 +08:00
Florian Märkl
b6f984e445 Parse and use dyld chained fixup imports
The LC_DYLD_CHAINED_FIXUPS load command references a new kind of imports
table that is used for binding chained fixups. A similar table may be
reconstructed from the legacy BIND_OPCODE_THREADED info. We now display
these new imports in `ii` instead of the classic undefined symbols and
use them to assign names to relocs.

Objective-C superclass resolution for chained fixups is also changed to
first check for relocs and then for a non-zero address read from memory
instead of ignoring relocs entirely when there is a non-zero value in
memory (this did not work for chained fixups as those already have
non-zero values before patching).
2023-06-25 19:39:56 +08:00
Florian Märkl
f4796c5e66 Populate Mach-O relocs from chained fixups
Chained fixups are essentially a new kind of relocs, so it makes sense
to also represent them as RzBinRelocs. Currently the results are
sometimes less meaningful than the reloc info that was parsed before
from indirectsyms in such cases, as chained imports are not parsed yet
and thus the target symbols of bind relocs are not yet known, hence the
temporarily BROKEN tests.
2023-06-25 19:39:56 +08:00
Florian Märkl
6452be6c20
Make rz-pipe tests invariant to local user config (#3601) 2023-06-23 18:19:45 +02:00
Florian Märkl
4fd9cd7cc1
Extend Mach-O platform recognition (#3599)
Some identical code from both mach-o 32 and 64 has been moved to
mach0_common.c to avoid duplicate compilation.
rz_mach0_platform_to_string() now recognizes all known platforms and the
information is shown as the subsys in the i command.
The "os" value was previously unreliably and ios sometimes showed as
"ios" and sometimes as "darwin" depending on the binary. Now the os is
"darwin" for all platforms. ios-* syscall files have thus been removed
as only darwin-* ones will be used.
2023-06-23 13:28:41 +00:00
swedenspy
655ea987cc
MD2 - hash implementation added according to RFC 1319 (#3585) 2023-06-18 23:01:57 +08:00
Giovanni
27dc5c8650
Remove old string detection methods. (#3584)
* Remove old string detection methods.
* Allow changing encoding based on `bin.str.enc`
* Cleanup for optimization regarding RzAnalysisData and its kind
* Allow changing endianness.
2023-06-18 18:12:59 +08:00
borzacchiello
d9a5cf3d28
Python 3.10 Support (#3577)
* Extract major and minor from python version string instead of converting it to double

The patch fixes 3.10 version extraction (3.10 == 3.1)

* update latest python magic version to 3491 in get_code_object

* opcodes for python3.10

* PYC: do not search for strings in code

* PYC python 3.10 tests

* Fixed typo in "pyc 3.9 sections" test

* pyc: refactored string search

* pyc: removed parse_version_major_minor

use "magic_int_within" to check python version
2023-06-16 08:28:17 +08:00
Dhruv Maroo
5f14d0e0b5 Fix analysis tests 2023-06-14 11:04:34 +08:00
Dhruv Maroo
2f6f2cfdce Fix ROR and update instruction asm tests 2023-06-14 11:04:34 +08:00