Most of the Windows types reported in issue #3728 were stub entries of the form NAME=type type.NAME=p i.e. opaque atomic pointers with no actual body. rz-ghidra rejects these as 'Invalid atomic type'. Convert them to proper typedef entries backed by either real struct definitions (for well-known types) or forward-declared opaque structs (for architecture-specific ones like CONTEXT and KNONVOLATILE_CONTEXT_POINTERS, whose layout varies across x86/x64/ARM/ARM64 and which the shared types-windows.sdb.txt cannot commit to). Specifically, this commit: * converts the stubs for PSID, LPOLESTR, LPCLSID, PCONTEXT, PKNONVOLATILE_CONTEXT_POINTERS, LPSYSTEM_INFO, LPWIN32_FIND_DATAW, PCACTCTXW, PSID_AND_ATTRIBUTES, PLUID_AND_ATTRIBUTES, PTRACEHANDLE and the duplicate LPMSG/PLUID into proper typedefs; * adds new top-level typedefs for CLSID, OLECHAR, LPCOLESTR (corrected to const OLECHAR *), REFCLSID, LPBC, MSG, PMSG, NPMSG, LPMSG, SYSTEM_INFO, WIN32_FIND_DATAW, PWIN32_FIND_DATAW, OSVERSIONINFOW, POSVERSIONINFOW, LPOSVERSIONINFOW, RTL_OSVERSIONINFOW, PRTL_OSVERSIONINFOW, OSVERSIONINFOEXW (plus its POSVERSIONINFOEXW/LPOSVERSIONINFOEXW siblings), ACTCTXW, PACTCTXW, LUID, PLUID, LUID_AND_ATTRIBUTES and SID_AND_ATTRIBUTES; * adds struct bodies for tagMSG, _OSVERSIONINFOW, _OSVERSIONINFOEXW, _SYSTEM_INFO (with the union flattened to wProcessorArchitecture + wReserved per modern usage), _WIN32_FIND_DATAW, tagACTCTXW, _SID_AND_ATTRIBUTES, _LUID, _LUID_AND_ATTRIBUTES and the empty opaque tags _CONTEXT, _KNONVOLATILE_CONTEXT_POINTERS and _IBindCtx; * fixes a small typo in struct._EVENT_DATA_DESCRIPTOR where the field list said 'Usize' while the per-field entry was 'Size'. Member layouts were taken from the Microsoft Win32 documentation (winnt.h, sysinfoapi.h, winuser.h, evntrace.h, minwinbase.h, winbase.h) and cross-checked with the Wine include/winnt.h, wtypes.idl and guiddef.h headers. Offsets follow the 32-bit Windows ABI used by the rest of this file (this matches the existing _OBJECT_ATTRIBUTES, _FILETIME etc. layouts). Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com> |
||
|---|---|---|
| .builds | ||
| .github | ||
| .woodpecker | ||
| binrz | ||
| dist | ||
| doc | ||
| examples | ||
| librz | ||
| LICENSES | ||
| patches | ||
| subprojects | ||
| sys | ||
| test | ||
| .appveyor.yml | ||
| .clang-format | ||
| .dockerignore | ||
| .git-blame-ignore-revs | ||
| .gitattributes | ||
| .gitignore | ||
| .lgtm.yml | ||
| .prettierignore | ||
| .pylintrc | ||
| .travis.yml | ||
| AGENTS.md | ||
| BUILDING.md | ||
| CODE_OF_CONDUCT.md | ||
| codecov.yml | ||
| CODEOWNERS | ||
| CONTRIBUTING.md | ||
| COPYING | ||
| COPYING.LESSER | ||
| DEVELOPERS.md | ||
| Dockerfile | ||
| Doxyfile | ||
| meson.build | ||
| meson_options.txt | ||
| README.md | ||
| REUSE.toml | ||
| SECURITY.md | ||
| snapcraft.yaml | ||
| travis-extract-var.sh | ||
| travis-script | ||
Rizin
Rizin is a reverse engineering framework, born as a fork of the radare2, with a focus on usability, features and cleanliness.
Rizin is portable and it can be used to analyze binaries, disassemble code, debug programs, as a forensic tool, as a scriptable command-line hexadecimal editor able to open disk files, and much more!
To learn more on Rizin you may want to read the official Rizin book.
How to install
Look at install instructions on our web page.
How to build
Use meson to compile and install Rizin. Please make sure to get an updated
meson (e.g. get it with pip install meson if your system does not provide
one that is at least version 0.55.0).
Clone this repository:
$ git clone https://github.com/rizinorg/rizin
Then compile and install with:
$ meson setup build
$ meson compile -C build
$ sudo meson install -C build
Now you can use rizin:
$ rizin
-- Thank you for using rizin. Have a nice night!
[0x00000000]>
To uninstall rizin, execute sudo ninja -C build uninstall.
Please have a look at BUILDING.md for more information about building Rizin.
Contributing
We very much welcome any kind of contributions, from typos, to documentation, to refactoring, up to completely new features you may think of. Before contributing, we would like you to read the file CONTRIBUTING.md, so that we can all be on the same page.
Tests
Look at test/README.md.
Supported features
Supported Operating Systems
Windows 7 and higher, Apple macOS/iOS/iPadOS, GNU/Linux, [Dragonfly|Net|Free|Open]BSD, Android, QNX, Solaris/Illumos, Haiku, GNU/Darwin, GNU/Hurd.
Supported Architectures
i386, x86-64, ARM/ARM64, RISC-V, PowerPC, MIPS, AVR, SPARC, System Z (S390), SuperH, m68k, m680x, XAP, XCore, CR16, HPPA, ARC, Blackfin, Z80, H8/300, Renesas (V810, V850, RL78), CRIS, XAP, PIC, LM32, 8051, 6502, i4004, i8080, Propeller, Tricore, CHIP-8, LH5801, T8200, GameBoy, SNES, SPC700, MSP430, Xtensa, NIOS II, TMS320 (c54x, c55x, c55+, c64x), Hexagon, DCPU16, LANAI, MCORE, mcs96, RSP, C-SKY(MCore), VAX, AMD Am29000.
There is also support for the following bytecode formats:
Dalvik, EBC, Java, Lua, Python, WebAssembly, Brainfuck, Malbolge
Supported File Formats
ELF, Mach-O, Fatmach-O, PE, PE+, MZ, COFF, OMF, NE, LE, LX, TE, XBE, BIOS/UEFI, Dyldcache, DEX, ART, CGC, ELF, Java class, Android boot image, Plan9 executable, ZIMG, MBN/SBL bootloader, ELF coredump, MDMP (Windows minidump), DMP (Windows pagedump), WASM (WebAssembly binary), Commodore VICE emulator, QNX, Game Boy (Advance), Nintendo DS ROMs and Nintendo 3DS FIRMs.
Tools
Apart from the main tool rizin, there are also other tools tailored for specific purposes and
useful for shell scripting or as separate standalone tools:
rz-bin- provides all kind of information about binary formatsrz-ar- list and extract members from static archives (.a and .lib)rz-asm- a command-line assembler and disassemblersrz-diff- a tool to compare two binaries as raw data or analyzed executablesrz-hash- allows to calculate different hashes or even encrypt datarz-gg- a small "eggs" code generator useful for exploitation purposesrz-find- binary analog offindtool, allowing to search patterns and bit masksrz-sign- tool to create, convert and parse FLIRT signaturesrz-ax- a calculator and number format converterrz-run- a tool that allows to specify running environment and arguments for debugged file
Scripting
We provide a way to interact with Rizin from Python, Haskell, OCaml, Ruby, Rust, and Go languages through rzpipe. Other languages although not currently supported could be easily added.
Community
Our website and blog: https://www.rizin.re/
Join our Mattermost community to discuss Rizin, its development, and general topics related to the project.
We also provide the following partial bridges to other messaging platforms: