Skip to content

0.12.0

Choose a tag to compare

@github-actions github-actions released this 31 May 22:11
· 496 commits to main since this release

An ITrace release: every trace now owns its buffer, instruction
tracing folds into the tracer instrument, and data written right
up to a target crash survives instead of being dropped.

ITrace

  • Per-trace buffers. Each trace owns its buffer, created
    before Stalker is armed and announced to Luma via a
    token-keyed start/ack handshake. The ack carries the drain
    verdict: Luma remaps the buffer out-of-process while the agent
    blocks, so an early crash still yields data; on
    task_for_pid denial (cached per target) the agent drains and
    pushes chunks itself. The drain agent keys readers by session
    so concurrent traces stay separate.
  • Folded into the tracer instrument. Function-arm traces and
    thread traces now share one Trace registry; thread traces
    become threadTraces config entries on a find-or-created
    tracer instance. Core no longer exports a standalone itrace.
  • Drain on session crash. The ring buffer can live in shared
    memory mapped into the drain script's address space, so it
    outlives the target. A final chunk is drained before pending
    traces are finalized, so panic events written near the crash
    surface instead of being lost when the periodic drainer is
    cancelled.
  • Empty state for the CFG view. The detail stack pins to the
    top and shows an empty state when no control-flow data is
    available, rather than letting the header collapse and centre
    vertically.

Fixes

  • Live hook updates apply in place. A hook's target never
    moves across an update, so when code and state are unchanged
    the interceptor is reconciled in place rather than
    re-attached. The pristine prologue is snapshotted at first
    attach, so arming a live hook on an itrace_arming change no
    longer relocates the live redirect into the original prologue
    and crashes.
  • disassemble mission tool hardened. Two failure modes are
    fixed: the joined text payload is now pinned to String at
    every binding so it can't drift to a GRDB.SQL value that
    NSJSONSerialization rejects (which previously surfaced as an
    uncaught ObjC exception unwinding through the concurrency
    runtime and crashing the app), and the tool now requires an
    attached node before disassembling so a detached session
    returns the canonical "no attached session" error instead of
    lines decoded as garbage. makeResult also gains an
    isValidJSONObject guard that turns any future non-JSON value
    into a clean MCP error with a key-path + Swift-type
    diagnostic.

Dependencies

  • frida-swift / frida-core refreshed.