-
Notifications
You must be signed in to change notification settings - Fork 113
/
bridgemain.h
1176 lines (1083 loc) · 40.7 KB
/
bridgemain.h
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
#ifndef _BRIDGEMAIN_H_
#define _BRIDGEMAIN_H_
#include <windows.h>
#ifndef __cplusplus
#include <stdbool.h>
#endif
//default structure alignments forced
#ifdef _WIN64
#pragma pack(push, 16)
#else //x86
#pragma pack(push, 8)
#endif //_WIN64
#ifdef _WIN64
typedef unsigned long long duint;
typedef signed long long dsint;
#else
typedef unsigned long duint;
typedef signed long dsint;
#endif //_WIN64
#ifndef BRIDGE_IMPEXP
#ifdef BUILD_BRIDGE
#define BRIDGE_IMPEXP __declspec(dllexport)
#else
#define BRIDGE_IMPEXP __declspec(dllimport)
#endif //BUILD_BRIDGE
#endif //BRIDGE_IMPEXP
#ifdef __cplusplus
extern "C"
{
#endif
//Bridge defines
#define MAX_SETTING_SIZE 65536
#define DBG_VERSION 25
//Bridge functions
BRIDGE_IMPEXP const wchar_t* BridgeInit();
BRIDGE_IMPEXP const wchar_t* BridgeStart();
BRIDGE_IMPEXP void* BridgeAlloc(size_t size);
BRIDGE_IMPEXP void BridgeFree(void* ptr);
BRIDGE_IMPEXP bool BridgeSettingGet(const char* section, const char* key, char* value);
BRIDGE_IMPEXP bool BridgeSettingGetUint(const char* section, const char* key, duint* value);
BRIDGE_IMPEXP bool BridgeSettingSet(const char* section, const char* key, const char* value);
BRIDGE_IMPEXP bool BridgeSettingSetUint(const char* section, const char* key, duint value);
BRIDGE_IMPEXP bool BridgeSettingFlush();
BRIDGE_IMPEXP bool BridgeSettingRead(int* errorLine);
BRIDGE_IMPEXP int BridgeGetDbgVersion();
#ifdef __cplusplus
}
#endif
//list structure (and C++ wrapper)
#include "bridgelist.h"
#include "bridgegraph.h"
#ifdef __cplusplus
extern "C"
{
#endif
//Debugger defines
#define MAX_LABEL_SIZE 256
#define MAX_COMMENT_SIZE 512
#define MAX_MODULE_SIZE 256
#define MAX_IMPORT_SIZE 65536
#define MAX_BREAKPOINT_SIZE 256
#define MAX_CONDITIONAL_EXPR_SIZE 256
#define MAX_CONDITIONAL_TEXT_SIZE 256
#define MAX_SCRIPT_LINE_SIZE 2048
#define MAX_THREAD_NAME_SIZE 256
#define MAX_WATCH_NAME_SIZE 256
#define MAX_STRING_SIZE 512
#define MAX_ERROR_SIZE 512
#define RIGHTS_STRING_SIZE (sizeof("ERWCG") + 1)
#define MAX_SECTION_SIZE 10
#define MAX_COMMAND_LINE_SIZE 256
#define MAX_MNEMONIC_SIZE 64
#define PAGE_SIZE 0x1000
//Debugger enums
typedef enum
{
initialized,
paused,
running,
stopped
} DBGSTATE;
typedef enum
{
SEG_DEFAULT,
SEG_ES,
SEG_DS,
SEG_FS,
SEG_GS,
SEG_CS,
SEG_SS
} SEGMENTREG;
typedef enum
{
flagmodule = 0x1,
flaglabel = 0x2,
flagcomment = 0x4,
flagbookmark = 0x8,
flagfunction = 0x10,
flagloop = 0x20,
flagargs = 0x40,
flagNoFuncOffset = 0x80
} ADDRINFOFLAGS;
typedef enum
{
bp_none = 0,
bp_normal = 1,
bp_hardware = 2,
bp_memory = 4,
bp_dll = 8,
bp_exception = 16
} BPXTYPE;
typedef enum
{
FUNC_NONE,
FUNC_BEGIN,
FUNC_MIDDLE,
FUNC_END,
FUNC_SINGLE
} FUNCTYPE;
typedef enum
{
LOOP_NONE,
LOOP_BEGIN,
LOOP_MIDDLE,
LOOP_ENTRY,
LOOP_END,
LOOP_SINGLE
} LOOPTYPE;
//order by most important type last
typedef enum
{
XREF_NONE,
XREF_DATA,
XREF_JMP,
XREF_CALL
} XREFTYPE;
typedef enum
{
ARG_NONE,
ARG_BEGIN,
ARG_MIDDLE,
ARG_END,
ARG_SINGLE
} ARGTYPE;
typedef enum
{
DBG_SCRIPT_LOAD, // param1=const char* filename, param2=unused
DBG_SCRIPT_UNLOAD, // param1=unused, param2=unused
DBG_SCRIPT_RUN, // param1=int destline, param2=unused
DBG_SCRIPT_STEP, // param1=unused, param2=unused
DBG_SCRIPT_BPTOGGLE, // param1=int line, param2=unused
DBG_SCRIPT_BPGET, // param1=int line, param2=unused
DBG_SCRIPT_CMDEXEC, // param1=const char* command, param2=unused
DBG_SCRIPT_ABORT, // param1=unused, param2=unused
DBG_SCRIPT_GETLINETYPE, // param1=int line, param2=unused
DBG_SCRIPT_SETIP, // param1=int line, param2=unused
DBG_SCRIPT_GETBRANCHINFO, // param1=int line, param2=SCRIPTBRANCH* info
DBG_SYMBOL_ENUM, // param1=SYMBOLCBINFO* cbInfo, param2=unused
DBG_ASSEMBLE_AT, // param1=duint addr, param2=const char* instruction
DBG_MODBASE_FROM_NAME, // param1=const char* modname, param2=unused
DBG_DISASM_AT, // param1=duint addr, param2=DISASM_INSTR* instr
DBG_STACK_COMMENT_GET, // param1=duint addr, param2=STACK_COMMENT* comment
DBG_GET_THREAD_LIST, // param1=THREADALLINFO* list, param2=unused
DBG_SETTINGS_UPDATED, // param1=unused, param2=unused
DBG_DISASM_FAST_AT, // param1=duint addr, param2=BASIC_INSTRUCTION_INFO* basicinfo
DBG_MENU_ENTRY_CLICKED, // param1=int hEntry, param2=unused
DBG_FUNCTION_GET, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_FUNCTION_OVERLAPS, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_FUNCTION_ADD, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_FUNCTION_DEL, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_LOOP_GET, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_LOOP_OVERLAPS, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_LOOP_ADD, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_LOOP_DEL, // param1=FUNCTION_LOOP_INFO* info, param2=unused
DBG_IS_RUN_LOCKED, // param1=unused, param2=unused
DBG_IS_BP_DISABLED, // param1=duint addr, param2=unused
DBG_SET_AUTO_COMMENT_AT, // param1=duint addr, param2=const char* text
DBG_DELETE_AUTO_COMMENT_RANGE, // param1=duint start, param2=duint end
DBG_SET_AUTO_LABEL_AT, // param1=duint addr, param2=const char* text
DBG_DELETE_AUTO_LABEL_RANGE, // param1=duint start, param2=duint end
DBG_SET_AUTO_BOOKMARK_AT, // param1=duint addr, param2=const char* text
DBG_DELETE_AUTO_BOOKMARK_RANGE, // param1=duint start, param2=duint end
DBG_SET_AUTO_FUNCTION_AT, // param1=duint addr, param2=const char* text
DBG_DELETE_AUTO_FUNCTION_RANGE, // param1=duint start, param2=duint end
DBG_GET_STRING_AT, // param1=duint addr, param2=unused
DBG_GET_FUNCTIONS, // param1=unused, param2=unused
DBG_WIN_EVENT, // param1=MSG* message, param2=long* result
DBG_WIN_EVENT_GLOBAL, // param1=MSG* message, param2=unused
DBG_INITIALIZE_LOCKS, // param1=unused, param2=unused
DBG_DEINITIALIZE_LOCKS, // param1=unused, param2=unused
DBG_GET_TIME_WASTED_COUNTER, // param1=unused, param2=unused
DBG_SYMBOL_ENUM_FROMCACHE, // param1=SYMBOLCBINFO* cbInfo, param2=unused
DBG_DELETE_COMMENT_RANGE, // param1=duint start, param2=duint end
DBG_DELETE_LABEL_RANGE, // param1=duint start, param2=duint end
DBG_DELETE_BOOKMARK_RANGE, // param1=duint start, param2=duint end
DBG_GET_XREF_COUNT_AT, // param1=duint addr, param2=unused
DBG_GET_XREF_TYPE_AT, // param1=duint addr, param2=unused
DBG_XREF_ADD, // param1=duint addr, param2=duint from
DBG_XREF_DEL_ALL, // param1=duint addr, param2=unused
DBG_XREF_GET, // param1=duint addr, param2=XREF_INFO* info
DBG_GET_ENCODE_TYPE_BUFFER, // param1=duint addr, param2=unused
DBG_ENCODE_TYPE_GET, // param1=duint addr, param2=duint size
DBG_DELETE_ENCODE_TYPE_RANGE, // param1=duint start, param2=duint end
DBG_ENCODE_SIZE_GET, // param1=duint addr, param2=duint codesize
DBG_DELETE_ENCODE_TYPE_SEG, // param1=duint addr, param2=unused
DBG_RELEASE_ENCODE_TYPE_BUFFER, // param1=void* buffer, param2=unused
DBG_ARGUMENT_GET, // param1=FUNCTION* info, param2=unused
DBG_ARGUMENT_OVERLAPS, // param1=FUNCTION* info, param2=unused
DBG_ARGUMENT_ADD, // param1=FUNCTION* info, param2=unused
DBG_ARGUMENT_DEL, // param1=FUNCTION* info, param2=unused
DBG_GET_WATCH_LIST, // param1=ListOf(WATCHINFO), param2=unused
DBG_SELCHANGED, // param1=hWindow, param2=VA
DBG_GET_PROCESS_HANDLE, // param1=unused, param2=unused
DBG_GET_THREAD_HANDLE, // param1=unused, param2=unused
DBG_GET_PROCESS_ID, // param1=unused, param2=unused
DBG_GET_THREAD_ID, // param1=unused, param2=unused
DBG_GET_PEB_ADDRESS, // param1=DWORD ProcessId, param2=unused
DBG_GET_TEB_ADDRESS, // param1=DWORD ThreadId, param2=unused
DBG_ANALYZE_FUNCTION, // param1=BridgeCFGraphList* graph, param2=duint entry
} DBGMSG;
typedef enum
{
linecommand,
linebranch,
linelabel,
linecomment,
lineempty,
} SCRIPTLINETYPE;
typedef enum
{
scriptnobranch,
scriptjmp,
scriptjnejnz,
scriptjejz,
scriptjbjl,
scriptjajg,
scriptjbejle,
scriptjaejge,
scriptcall
} SCRIPTBRANCHTYPE;
typedef enum
{
instr_normal,
instr_branch,
instr_stack
} DISASM_INSTRTYPE;
typedef enum
{
arg_normal,
arg_memory
} DISASM_ARGTYPE;
typedef enum
{
str_none,
str_ascii,
str_unicode
} STRING_TYPE;
typedef enum
{
_PriorityIdle = -15,
_PriorityAboveNormal = 1,
_PriorityBelowNormal = -1,
_PriorityHighest = 2,
_PriorityLowest = -2,
_PriorityNormal = 0,
_PriorityTimeCritical = 15,
_PriorityUnknown = 0x7FFFFFFF
} THREADPRIORITY;
typedef enum
{
_Executive = 0,
_FreePage = 1,
_PageIn = 2,
_PoolAllocation = 3,
_DelayExecution = 4,
_Suspended = 5,
_UserRequest = 6,
_WrExecutive = 7,
_WrFreePage = 8,
_WrPageIn = 9,
_WrPoolAllocation = 10,
_WrDelayExecution = 11,
_WrSuspended = 12,
_WrUserRequest = 13,
_WrEventPair = 14,
_WrQueue = 15,
_WrLpcReceive = 16,
_WrLpcReply = 17,
_WrVirtualMemory = 18,
_WrPageOut = 19,
_WrRendezvous = 20,
_Spare2 = 21,
_Spare3 = 22,
_Spare4 = 23,
_Spare5 = 24,
_WrCalloutStack = 25,
_WrKernel = 26,
_WrResource = 27,
_WrPushLock = 28,
_WrMutex = 29,
_WrQuantumEnd = 30,
_WrDispatchInt = 31,
_WrPreempted = 32,
_WrYieldExecution = 33,
_WrFastMutex = 34,
_WrGuardedMutex = 35,
_WrRundown = 36,
} THREADWAITREASON;
typedef enum
{
size_byte = 1,
size_word = 2,
size_dword = 4,
size_qword = 8
} MEMORY_SIZE;
typedef enum
{
enc_unknown, //must be 0
enc_byte, //1 byte
enc_word, //2 bytes
enc_dword, //4 bytes
enc_fword, //6 bytes
enc_qword, //8 bytes
enc_tbyte, //10 bytes
enc_oword, //16 bytes
enc_mmword, //8 bytes
enc_xmmword, //16 bytes
enc_ymmword, //32 bytes
enc_zmmword, //64 bytes avx512 not supported
enc_real4, //4 byte float
enc_real8, //8 byte double
enc_real10, //10 byte decimal
enc_ascii, //ascii sequence
enc_unicode, //unicode sequence
enc_code, //start of code
enc_junk, //junk code
enc_middle //middle of data
} ENCODETYPE;
typedef enum
{
TYPE_UINT, // unsigned integer
TYPE_INT, // signed integer
TYPE_FLOAT,// single precision floating point value
TYPE_ASCII, // ascii string
TYPE_UNICODE, // unicode string
TYPE_INVALID // invalid watch expression or data type
} WATCHVARTYPE;
typedef enum
{
MODE_DISABLED, // watchdog is disabled
MODE_ISTRUE, // alert if expression is not 0
MODE_ISFALSE, // alert if expression is 0
MODE_CHANGED, // alert if expression is changed
MODE_UNCHANGED // alert if expression is not changed
} WATCHDOGMODE;
//Debugger typedefs
typedef MEMORY_SIZE VALUE_SIZE;
typedef struct SYMBOLINFO_ SYMBOLINFO;
typedef struct DBGFUNCTIONS_ DBGFUNCTIONS;
typedef void (*CBSYMBOLENUM)(SYMBOLINFO* symbol, void* user);
//Debugger structs
typedef struct
{
MEMORY_BASIC_INFORMATION mbi;
char info[MAX_MODULE_SIZE];
} MEMPAGE;
typedef struct
{
int count;
MEMPAGE* page;
} MEMMAP;
typedef struct
{
BPXTYPE type;
duint addr;
bool enabled;
bool singleshoot;
bool active;
char name[MAX_BREAKPOINT_SIZE];
char mod[MAX_MODULE_SIZE];
unsigned short slot;
// extended part
unsigned int hitCount;
bool fastResume;
bool silent;
char breakCondition[MAX_CONDITIONAL_EXPR_SIZE];
char logText[MAX_CONDITIONAL_TEXT_SIZE];
char logCondition[MAX_CONDITIONAL_EXPR_SIZE];
char commandText[MAX_CONDITIONAL_TEXT_SIZE];
char commandCondition[MAX_CONDITIONAL_EXPR_SIZE];
} BRIDGEBP;
typedef struct
{
int count;
BRIDGEBP* bp;
} BPMAP;
typedef struct
{
char WatchName[MAX_WATCH_NAME_SIZE];
char Expression[MAX_CONDITIONAL_EXPR_SIZE];
unsigned int window;
unsigned int id;
WATCHVARTYPE varType;
WATCHDOGMODE watchdogMode;
duint value;
bool watchdogTriggered;
} WATCHINFO;
typedef struct
{
duint start; //OUT
duint end; //OUT
duint instrcount; //OUT
} FUNCTION;
typedef struct
{
int depth; //IN
duint start; //OUT
duint end; //OUT
duint instrcount; //OUT
} LOOP;
#ifndef _NO_ADDRINFO
typedef struct
{
int flags; //ADDRINFOFLAGS (IN)
char module[MAX_MODULE_SIZE]; //module the address is in
char label[MAX_LABEL_SIZE];
char comment[MAX_COMMENT_SIZE];
bool isbookmark;
FUNCTION function;
LOOP loop;
FUNCTION args;
} ADDRINFO;
#endif
struct SYMBOLINFO_
{
duint addr;
char* decoratedSymbol;
char* undecoratedSymbol;
bool isImported;
};
typedef struct
{
duint base;
char name[MAX_MODULE_SIZE];
} SYMBOLMODULEINFO;
typedef struct
{
duint base;
CBSYMBOLENUM cbSymbolEnum;
void* user;
} SYMBOLCBINFO;
typedef struct
{
bool c;
bool p;
bool a;
bool z;
bool s;
bool t;
bool i;
bool d;
bool o;
} FLAGS;
typedef struct
{
bool FZ;
bool PM;
bool UM;
bool OM;
bool ZM;
bool IM;
bool DM;
bool DAZ;
bool PE;
bool UE;
bool OE;
bool ZE;
bool DE;
bool IE;
unsigned short RC;
} MXCSRFIELDS;
typedef struct
{
bool B;
bool C3;
bool C2;
bool C1;
bool C0;
bool IR;
bool SF;
bool P;
bool U;
bool O;
bool Z;
bool D;
bool I;
unsigned short TOP;
} X87STATUSWORDFIELDS;
typedef struct
{
bool IC;
bool IEM;
bool PM;
bool UM;
bool OM;
bool ZM;
bool DM;
bool IM;
unsigned short RC;
unsigned short PC;
} X87CONTROLWORDFIELDS;
typedef struct DECLSPEC_ALIGN(16) _XMMREGISTER
{
ULONGLONG Low;
LONGLONG High;
} XMMREGISTER;
typedef struct
{
XMMREGISTER Low; //XMM/SSE part
XMMREGISTER High; //AVX part
} YMMREGISTER;
typedef struct
{
BYTE data[10];
int st_value;
int tag;
} X87FPUREGISTER;
typedef struct
{
WORD ControlWord;
WORD StatusWord;
WORD TagWord;
DWORD ErrorOffset;
DWORD ErrorSelector;
DWORD DataOffset;
DWORD DataSelector;
DWORD Cr0NpxState;
} X87FPU;
typedef struct
{
ULONG_PTR cax;
ULONG_PTR ccx;
ULONG_PTR cdx;
ULONG_PTR cbx;
ULONG_PTR csp;
ULONG_PTR cbp;
ULONG_PTR csi;
ULONG_PTR cdi;
#ifdef _WIN64
ULONG_PTR r8;
ULONG_PTR r9;
ULONG_PTR r10;
ULONG_PTR r11;
ULONG_PTR r12;
ULONG_PTR r13;
ULONG_PTR r14;
ULONG_PTR r15;
#endif //_WIN64
ULONG_PTR cip;
ULONG_PTR eflags;
unsigned short gs;
unsigned short fs;
unsigned short es;
unsigned short ds;
unsigned short cs;
unsigned short ss;
ULONG_PTR dr0;
ULONG_PTR dr1;
ULONG_PTR dr2;
ULONG_PTR dr3;
ULONG_PTR dr6;
ULONG_PTR dr7;
BYTE RegisterArea[80];
X87FPU x87fpu;
DWORD MxCsr;
#ifdef _WIN64
XMMREGISTER XmmRegisters[16];
YMMREGISTER YmmRegisters[16];
#else // x86
XMMREGISTER XmmRegisters[8];
YMMREGISTER YmmRegisters[8];
#endif
} REGISTERCONTEXT;
typedef struct
{
DWORD code;
char name[128];
} LASTERROR;
typedef struct
{
REGISTERCONTEXT regcontext;
FLAGS flags;
X87FPUREGISTER x87FPURegisters[8];
unsigned long long mmx[8];
MXCSRFIELDS MxCsrFields;
X87STATUSWORDFIELDS x87StatusWordFields;
X87CONTROLWORDFIELDS x87ControlWordFields;
LASTERROR lastError;
} REGDUMP;
typedef struct
{
DISASM_ARGTYPE type; //normal/memory
SEGMENTREG segment;
char mnemonic[64];
duint constant; //constant in the instruction (imm/disp)
duint value; //equal to constant or equal to the register value
duint memvalue; //memsize:[value]
} DISASM_ARG;
typedef struct
{
char instruction[64];
DISASM_INSTRTYPE type;
int argcount;
int instr_size;
DISASM_ARG arg[3];
} DISASM_INSTR;
typedef struct
{
char color[8]; //hex color-code
char comment[MAX_COMMENT_SIZE];
} STACK_COMMENT;
typedef struct
{
int ThreadNumber;
HANDLE Handle;
DWORD ThreadId;
duint ThreadStartAddress;
duint ThreadLocalBase;
char threadName[MAX_THREAD_NAME_SIZE];
} THREADINFO;
typedef struct
{
THREADINFO BasicInfo;
duint ThreadCip;
DWORD SuspendCount;
THREADPRIORITY Priority;
THREADWAITREASON WaitReason;
DWORD LastError;
FILETIME UserTime;
FILETIME KernelTime;
FILETIME CreationTime;
ULONG64 Cycles; // Windows Vista or greater
} THREADALLINFO;
typedef struct
{
int count;
THREADALLINFO* list;
int CurrentThread;
} THREADLIST;
typedef struct
{
duint value; //displacement / addrvalue (rip-relative)
MEMORY_SIZE size; //byte/word/dword/qword
char mnemonic[MAX_MNEMONIC_SIZE];
} MEMORY_INFO;
typedef struct
{
duint value;
VALUE_SIZE size;
} VALUE_INFO;
//definitions for BASIC_INSTRUCTION_INFO.type
#define TYPE_VALUE 1
#define TYPE_MEMORY 2
#define TYPE_ADDR 4
typedef struct
{
DWORD type; //value|memory|addr
VALUE_INFO value; //immediat
MEMORY_INFO memory;
duint addr; //addrvalue (jumps + calls)
bool branch; //jumps/calls
bool call; //instruction is a call
int size;
char instruction[MAX_MNEMONIC_SIZE * 4];
} BASIC_INSTRUCTION_INFO;
typedef struct
{
SCRIPTBRANCHTYPE type;
int dest;
char branchlabel[256];
} SCRIPTBRANCH;
typedef struct
{
duint addr;
duint start;
duint end;
bool manual;
int depth;
} FUNCTION_LOOP_INFO;
typedef struct
{
duint addr;
XREFTYPE type;
} XREF_RECORD;
typedef struct
{
duint refcount;
XREF_RECORD* references;
} XREF_INFO;
//Debugger functions
BRIDGE_IMPEXP const char* DbgInit();
BRIDGE_IMPEXP void DbgExit();
BRIDGE_IMPEXP bool DbgMemRead(duint va, void* dest, duint size);
BRIDGE_IMPEXP bool DbgMemWrite(duint va, const void* src, duint size);
BRIDGE_IMPEXP duint DbgMemGetPageSize(duint base);
BRIDGE_IMPEXP duint DbgMemFindBaseAddr(duint addr, duint* size);
BRIDGE_IMPEXP bool DbgCmdExec(const char* cmd);
BRIDGE_IMPEXP bool DbgCmdExecDirect(const char* cmd);
BRIDGE_IMPEXP bool DbgMemMap(MEMMAP* memmap);
BRIDGE_IMPEXP bool DbgIsValidExpression(const char* expression);
BRIDGE_IMPEXP bool DbgIsDebugging();
BRIDGE_IMPEXP bool DbgIsJumpGoingToExecute(duint addr);
BRIDGE_IMPEXP bool DbgGetLabelAt(duint addr, SEGMENTREG segment, char* text);
BRIDGE_IMPEXP bool DbgSetLabelAt(duint addr, const char* text);
BRIDGE_IMPEXP void DbgClearLabelRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgGetCommentAt(duint addr, char* text);
BRIDGE_IMPEXP bool DbgSetCommentAt(duint addr, const char* text);
BRIDGE_IMPEXP void DbgClearCommentRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgGetBookmarkAt(duint addr);
BRIDGE_IMPEXP bool DbgSetBookmarkAt(duint addr, bool isbookmark);
BRIDGE_IMPEXP void DbgClearBookmarkRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgGetModuleAt(duint addr, char* text);
BRIDGE_IMPEXP BPXTYPE DbgGetBpxTypeAt(duint addr);
BRIDGE_IMPEXP duint DbgValFromString(const char* string);
BRIDGE_IMPEXP bool DbgGetRegDump(REGDUMP* regdump);
BRIDGE_IMPEXP bool DbgValToString(const char* string, duint value);
BRIDGE_IMPEXP bool DbgMemIsValidReadPtr(duint addr);
BRIDGE_IMPEXP int DbgGetBpList(BPXTYPE type, BPMAP* list);
BRIDGE_IMPEXP FUNCTYPE DbgGetFunctionTypeAt(duint addr);
BRIDGE_IMPEXP LOOPTYPE DbgGetLoopTypeAt(duint addr, int depth);
BRIDGE_IMPEXP duint DbgGetBranchDestination(duint addr);
BRIDGE_IMPEXP void DbgScriptLoad(const char* filename);
BRIDGE_IMPEXP void DbgScriptUnload();
BRIDGE_IMPEXP void DbgScriptRun(int destline);
BRIDGE_IMPEXP void DbgScriptStep();
BRIDGE_IMPEXP bool DbgScriptBpToggle(int line);
BRIDGE_IMPEXP bool DbgScriptBpGet(int line);
BRIDGE_IMPEXP bool DbgScriptCmdExec(const char* command);
BRIDGE_IMPEXP void DbgScriptAbort();
BRIDGE_IMPEXP SCRIPTLINETYPE DbgScriptGetLineType(int line);
BRIDGE_IMPEXP void DbgScriptSetIp(int line);
BRIDGE_IMPEXP bool DbgScriptGetBranchInfo(int line, SCRIPTBRANCH* info);
BRIDGE_IMPEXP void DbgSymbolEnum(duint base, CBSYMBOLENUM cbSymbolEnum, void* user);
BRIDGE_IMPEXP void DbgSymbolEnumFromCache(duint base, CBSYMBOLENUM cbSymbolEnum, void* user);
BRIDGE_IMPEXP bool DbgAssembleAt(duint addr, const char* instruction);
BRIDGE_IMPEXP duint DbgModBaseFromName(const char* name);
BRIDGE_IMPEXP void DbgDisasmAt(duint addr, DISASM_INSTR* instr);
BRIDGE_IMPEXP bool DbgStackCommentGet(duint addr, STACK_COMMENT* comment);
BRIDGE_IMPEXP void DbgGetThreadList(THREADLIST* list);
BRIDGE_IMPEXP void DbgSettingsUpdated();
BRIDGE_IMPEXP void DbgDisasmFastAt(duint addr, BASIC_INSTRUCTION_INFO* basicinfo);
BRIDGE_IMPEXP void DbgMenuEntryClicked(int hEntry);
BRIDGE_IMPEXP bool DbgFunctionGet(duint addr, duint* start, duint* end);
BRIDGE_IMPEXP bool DbgFunctionOverlaps(duint start, duint end);
BRIDGE_IMPEXP bool DbgFunctionAdd(duint start, duint end);
BRIDGE_IMPEXP bool DbgFunctionDel(duint addr);
BRIDGE_IMPEXP bool DbgArgumentGet(duint addr, duint* start, duint* end);
BRIDGE_IMPEXP bool DbgArgumentOverlaps(duint start, duint end);
BRIDGE_IMPEXP bool DbgArgumentAdd(duint start, duint end);
BRIDGE_IMPEXP bool DbgArgumentDel(duint addr);
BRIDGE_IMPEXP bool DbgLoopGet(int depth, duint addr, duint* start, duint* end);
BRIDGE_IMPEXP bool DbgLoopOverlaps(int depth, duint start, duint end);
BRIDGE_IMPEXP bool DbgLoopAdd(duint start, duint end);
BRIDGE_IMPEXP bool DbgLoopDel(int depth, duint addr);
BRIDGE_IMPEXP bool DbgXrefAdd(duint addr, duint from);
BRIDGE_IMPEXP bool DbgXrefDelAll(duint addr);
BRIDGE_IMPEXP bool DbgXrefGet(duint addr, XREF_INFO* info);
BRIDGE_IMPEXP size_t DbgGetXrefCountAt(duint addr);
BRIDGE_IMPEXP XREFTYPE DbgGetXrefTypeAt(duint addr);
BRIDGE_IMPEXP bool DbgIsRunLocked();
BRIDGE_IMPEXP bool DbgIsBpDisabled(duint addr);
BRIDGE_IMPEXP bool DbgSetAutoCommentAt(duint addr, const char* text);
BRIDGE_IMPEXP void DbgClearAutoCommentRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgSetAutoLabelAt(duint addr, const char* text);
BRIDGE_IMPEXP void DbgClearAutoLabelRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgSetAutoBookmarkAt(duint addr);
BRIDGE_IMPEXP void DbgClearAutoBookmarkRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgSetAutoFunctionAt(duint start, duint end);
BRIDGE_IMPEXP void DbgClearAutoFunctionRange(duint start, duint end);
BRIDGE_IMPEXP bool DbgGetStringAt(duint addr, char* text);
BRIDGE_IMPEXP const DBGFUNCTIONS* DbgFunctions();
BRIDGE_IMPEXP bool DbgWinEvent(MSG* message, long* result);
BRIDGE_IMPEXP bool DbgWinEventGlobal(MSG* message);
BRIDGE_IMPEXP bool DbgIsRunning();
BRIDGE_IMPEXP duint DbgGetTimeWastedCounter();
BRIDGE_IMPEXP ARGTYPE DbgGetArgTypeAt(duint addr);
BRIDGE_IMPEXP void* DbgGetEncodeTypeBuffer(duint addr, duint* size);
BRIDGE_IMPEXP void DbgReleaseEncodeTypeBuffer(void* buffer);
BRIDGE_IMPEXP ENCODETYPE DbgGetEncodeTypeAt(duint addr, duint size);
BRIDGE_IMPEXP duint DbgGetEncodeSizeAt(duint addr, duint codesize);
BRIDGE_IMPEXP bool DbgSetEncodeType(duint addr, duint size, ENCODETYPE type);
BRIDGE_IMPEXP void DbgDelEncodeTypeRange(duint start, duint end);
BRIDGE_IMPEXP void DbgDelEncodeTypeSegment(duint start);
BRIDGE_IMPEXP bool DbgGetWatchList(ListOf(WATCHINFO) list);
BRIDGE_IMPEXP void DbgSelChanged(int hWindow, duint VA);
BRIDGE_IMPEXP HANDLE DbgGetProcessHandle();
BRIDGE_IMPEXP HANDLE DbgGetThreadHandle();
BRIDGE_IMPEXP DWORD DbgGetProcessId();
BRIDGE_IMPEXP DWORD DbgGetThreadId();
BRIDGE_IMPEXP duint DbgGetPebAddress(DWORD ProcessId);
BRIDGE_IMPEXP duint DbgGetTebAddress(DWORD ThreadId);
BRIDGE_IMPEXP bool DbgAnalyzeFunction(duint entry, BridgeCFGraphList* graph);
//Gui defines
#define GUI_PLUGIN_MENU 0
#define GUI_DISASM_MENU 1
#define GUI_DUMP_MENU 2
#define GUI_STACK_MENU 3
#define GUI_DISASSEMBLY 0
#define GUI_DUMP 1
#define GUI_STACK 2
#define GUI_GRAPH 3
#define GUI_MEMMAP 4
#define GUI_SYMMOD 5
#define GUI_MAX_LINE_SIZE 65536
#define GUI_MAX_DISASSEMBLY_SIZE 2048
//Gui enums
typedef enum
{
GUI_DISASSEMBLE_AT, // param1=(duint)va, param2=(duint)cip
GUI_SET_DEBUG_STATE, // param1=(DBGSTATE)state, param2=unused
GUI_ADD_MSG_TO_LOG, // param1=(const char*)msg, param2=unused
GUI_CLEAR_LOG, // param1=unused, param2=unused
GUI_UPDATE_REGISTER_VIEW, // param1=unused, param2=unused
GUI_UPDATE_DISASSEMBLY_VIEW, // param1=unused, param2=unused
GUI_UPDATE_BREAKPOINTS_VIEW, // param1=unused, param2=unused
GUI_UPDATE_WINDOW_TITLE, // param1=(const char*)file, param2=unused
GUI_GET_WINDOW_HANDLE, // param1=unused, param2=unused
GUI_DUMP_AT, // param1=(duint)va param2=unused
GUI_SCRIPT_ADD, // param1=int count, param2=const char** lines
GUI_SCRIPT_CLEAR, // param1=unused, param2=unused
GUI_SCRIPT_SETIP, // param1=int line, param2=unused
GUI_SCRIPT_ERROR, // param1=int line, param2=const char* message
GUI_SCRIPT_SETTITLE, // param1=const char* title, param2=unused
GUI_SCRIPT_SETINFOLINE, // param1=int line, param2=const char* info
GUI_SCRIPT_MESSAGE, // param1=const char* message, param2=unused
GUI_SCRIPT_MSGYN, // param1=const char* message, param2=unused
GUI_SYMBOL_LOG_ADD, // param1(const char*)msg, param2=unused
GUI_SYMBOL_LOG_CLEAR, // param1=unused, param2=unused
GUI_SYMBOL_SET_PROGRESS, // param1=int percent param2=unused
GUI_SYMBOL_UPDATE_MODULE_LIST, // param1=int count, param2=SYMBOLMODULEINFO* modules
GUI_REF_ADDCOLUMN, // param1=int width, param2=(const char*)title
GUI_REF_SETROWCOUNT, // param1=int rows, param2=unused
GUI_REF_GETROWCOUNT, // param1=unused, param2=unused
GUI_REF_DELETEALLCOLUMNS, // param1=unused, param2=unused
GUI_REF_SETCELLCONTENT, // param1=(CELLINFO*)info, param2=unused
GUI_REF_GETCELLCONTENT, // param1=int row, param2=int col
GUI_REF_RELOADDATA, // param1=unused, param2=unused
GUI_REF_SETSINGLESELECTION, // param1=int index, param2=bool scroll
GUI_REF_SETPROGRESS, // param1=int progress, param2=unused
GUI_REF_SETCURRENTTASKPROGRESS, // param1=int progress, param2=const char* taskTitle
GUI_REF_SETSEARCHSTARTCOL, // param1=int col param2=unused
GUI_STACK_DUMP_AT, // param1=duint addr, param2=duint csp
GUI_UPDATE_DUMP_VIEW, // param1=unused, param2=unused
GUI_UPDATE_THREAD_VIEW, // param1=unused, param2=unused
GUI_ADD_RECENT_FILE, // param1=(const char*)file, param2=unused
GUI_SET_LAST_EXCEPTION, // param1=unsigned int code, param2=unused
GUI_GET_DISASSEMBLY, // param1=duint addr, param2=char* text
GUI_MENU_ADD, // param1=int hMenu, param2=const char* title
GUI_MENU_ADD_ENTRY, // param1=int hMenu, param2=const char* title
GUI_MENU_ADD_SEPARATOR, // param1=int hMenu, param2=unused
GUI_MENU_CLEAR, // param1=int hMenu, param2=unused
GUI_SELECTION_GET, // param1=int hWindow, param2=SELECTIONDATA* selection
GUI_SELECTION_SET, // param1=int hWindow, param2=const SELECTIONDATA* selection
GUI_GETLINE_WINDOW, // param1=const char* title, param2=char* text
GUI_AUTOCOMPLETE_ADDCMD, // param1=const char* cmd, param2=ununsed
GUI_AUTOCOMPLETE_DELCMD, // param1=const char* cmd, param2=ununsed
GUI_AUTOCOMPLETE_CLEARALL, // param1=unused, param2=unused
GUI_SCRIPT_ENABLEHIGHLIGHTING, // param1=bool enable, param2=unused
GUI_ADD_MSG_TO_STATUSBAR, // param1=const char* msg, param2=unused
GUI_UPDATE_SIDEBAR, // param1=unused, param2=unused
GUI_REPAINT_TABLE_VIEW, // param1=unused, param2=unused
GUI_UPDATE_PATCHES, // param1=unused, param2=unused
GUI_UPDATE_CALLSTACK, // param1=unused, param2=unused
GUI_UPDATE_SEHCHAIN, // param1=unused, param2=unused
GUI_SYMBOL_REFRESH_CURRENT, // param1=unused, param2=unused
GUI_UPDATE_MEMORY_VIEW, // param1=unused, param2=unused
GUI_REF_INITIALIZE, // param1=const char* name, param2=unused
GUI_LOAD_SOURCE_FILE, // param1=const char* path, param2=line
GUI_MENU_SET_ICON, // param1=int hMenu, param2=ICONINFO*
GUI_MENU_SET_ENTRY_ICON, // param1=int hEntry, param2=ICONINFO*
GUI_SHOW_CPU, // param1=unused, param2=unused
GUI_ADD_QWIDGET_TAB, // param1=QWidget*, param2=unused
GUI_SHOW_QWIDGET_TAB, // param1=QWidget*, param2=unused
GUI_CLOSE_QWIDGET_TAB, // param1=QWidget*, param2=unused
GUI_EXECUTE_ON_GUI_THREAD, // param1=GUICALLBACK, param2=unused
GUI_UPDATE_TIME_WASTED_COUNTER, // param1=unused, param2=unused
GUI_SET_GLOBAL_NOTES, // param1=const char* text, param2=unused
GUI_GET_GLOBAL_NOTES, // param1=char** text, param2=unused
GUI_SET_DEBUGGEE_NOTES, // param1=const char* text, param2=unused
GUI_GET_DEBUGGEE_NOTES, // param1=char** text, param2=unused
GUI_DUMP_AT_N, // param1=int index, param2=duint va
GUI_DISPLAY_WARNING, // param1=const char *text, param2=unused
GUI_REGISTER_SCRIPT_LANG, // param1=SCRIPTTYPEINFO* info, param2=unused
GUI_UNREGISTER_SCRIPT_LANG, // param1=int id, param2=unused
GUI_UPDATE_ARGUMENT_VIEW, // param1=unused, param2=unused
GUI_FOCUS_VIEW, // param1=int hWindow, param2=unused
GUI_UPDATE_WATCH_VIEW, // param1=unused, param2=unused
GUI_LOAD_GRAPH, // param1=BridgeCFGraphList* param2=unused
GUI_GRAPH_AT, // param1=duint addr param2=unused
GUI_UPDATE_GRAPH_VIEW, // param1=unused, param2=unused
GUI_SET_LOG_ENABLED, // param1=bool isEnabled param2=unused
GUI_ADD_FAVOURITE_TOOL, // param1=const char* name param2=const char* description
GUI_ADD_FAVOURITE_COMMAND, // param1=const char* command param2=const char* shortcut
GUI_SET_FAVOURITE_TOOL_SHORTCUT,// param1=const char* name param2=const char* shortcut
GUI_FOLD_DISASSEMBLY, // param1=duint startAddress param2=duint length
GUI_SELECT_IN_MEMORY_MAP, // param1=duint addr, param2=unused
GUI_GET_ACTIVE_VIEW, // param1=ACTIVEVIEW*, param2=unused
GUI_MENU_SET_ENTRY_CHECKED, // param1=int hEntry, param2=bool checked
GUI_ADD_INFO_LINE, // param1=const char* infoline, param2=unused
GUI_PROCESS_EVENTS, // param1=unused, param2=unused
GUI_TYPE_ADDNODE, // param1=void* parent, param2=TYPEDESCRIPTOR* type
GUI_TYPE_CLEAR, // param1=unused, param2=unused
GUI_UPDATE_TYPE_WIDGET, // param1=unused, param2=unused
GUI_CLOSE_APPLICATION, // param1=unused, param2=unused
GUI_MENU_SET_VISIBLE, // param1=int hMenu, param2=bool visible
GUI_MENU_SET_ENTRY_VISIBLE, // param1=int hEntry, param2=bool visible
GUI_MENU_SET_NAME, // param1=int hMenu, param2=const char* name
GUI_MENU_SET_ENTRY_NAME, // param1=int hEntry, param2=const char* name
GUI_FLUSH_LOG, // param1=unused, param2=unused