0.12.0
An ITrace release: every trace now owns its buffer, instruction
tracing folds into the tracer instrument, and data written right
up to a target crash survives instead of being dropped.
ITrace
- Per-trace buffers. Each trace owns its buffer, created
before Stalker is armed and announced to Luma via a
token-keyed start/ack handshake. The ack carries the drain
verdict: Luma remaps the buffer out-of-process while the agent
blocks, so an early crash still yields data; on
task_for_piddenial (cached per target) the agent drains and
pushes chunks itself. The drain agent keys readers by session
so concurrent traces stay separate. - Folded into the tracer instrument. Function-arm traces and
thread traces now share oneTraceregistry; thread traces
becomethreadTracesconfig entries on a find-or-created
tracer instance. Core no longer exports a standalone itrace. - Drain on session crash. The ring buffer can live in shared
memory mapped into the drain script's address space, so it
outlives the target. A final chunk is drained before pending
traces are finalized, so panic events written near the crash
surface instead of being lost when the periodic drainer is
cancelled. - Empty state for the CFG view. The detail stack pins to the
top and shows an empty state when no control-flow data is
available, rather than letting the header collapse and centre
vertically.
Fixes
- Live hook updates apply in place. A hook's target never
moves across an update, so when code and state are unchanged
the interceptor is reconciled in place rather than
re-attached. The pristine prologue is snapshotted at first
attach, so arming a live hook on anitrace_armingchange no
longer relocates the live redirect into the original prologue
and crashes. disassemblemission tool hardened. Two failure modes are
fixed: the joinedtextpayload is now pinned toStringat
every binding so it can't drift to aGRDB.SQLvalue that
NSJSONSerializationrejects (which previously surfaced as an
uncaught ObjC exception unwinding through the concurrency
runtime and crashing the app), and the tool now requires an
attached node before disassembling so a detached session
returns the canonical "no attached session" error instead of
lines decoded as garbage.makeResultalso gains an
isValidJSONObjectguard that turns any future non-JSON value
into a clean MCP error with a key-path + Swift-type
diagnostic.
Dependencies
- frida-swift / frida-core refreshed.