v0.3.0
Changes since upstream 0.2.2 (10019ba),
including the electricazimuth integration in
a6a4103,
selected nonsleepr and encounter changes, and subsequent work in this repository.
Added
ghidra pcode at ADDRESSandpcode function TARGET [--high]expose raw
instruction PCode and decompiler high PCode, including operands, outputs,
address spaces, and register names.ghidra analyzer list|set|runlists analyzer settings, enables or disables a
named analyzer, and explicitly re-runs analysis. Changing a setting with
analyzer set NAME true|falsedoes not itself start analysis.ghidra type import-c CODE [--category PATH](aliasestype importand
type parse-c) parses C declarations, including structs, unions, enums,
typedefs, and function definitions. Results include type names, paths, sizes,
categories, and parser messages. Category placement applies to the parsed
types without moving unrelated existing types with the same name.- Explicit import controls:
--loader,--language(alias--processor),
--compiler-spec(alias--cspec), and repeatable
--loader-option NAME=VALUE. Raw binary options--base-address,
--block-name,--file-offset, and--lengthimplyBinaryLoaderwhen no
loader is specified. Explicit loader imports stop any running project bridge,
import throughanalyzeHeadless, and reopen the imported program. ghidra disasm-at ADDRESS [--count N]creates instructions at an unanalyzed
address and reports both Ghidra'sokresult and whether an instruction
actuallylandedat the target.ghidra clear START:END [--to-data | --disasm-at ADDRESS]clears overlapping
code units, optionally re-disassembling at a specified address in the same
request.ghidra function set-noreturn TARGET [--value true|false]controls a
function's no-return flag.function getandfunction listnow include
no_return.- Function-scoped tag commands:
function tag add|remove TARGET TAG_NAMEand
function tag list TARGET, complementing the top-leveltagcommands and
function tag filters introduced in 0.2.2. ghidra script run -reads Java source from stdin and stages it for the same
compilation and execution path used by script files.ghidra comment set ADDRESS --stdinand--text-file PATHaccept comment
text without exposing it to shell argument expansion.ghidra type apply ADDRESS TYPE --force(alias--clear-conflicting) clears
overlapping instructions or data before applying a type. Replacing a function
entry point reports a warning that its code was cleared.ghidra program saveflushes pending edits by stopping the bridge, reopening
the same program, and checking its function count. This works around the
headless harness's lifetime transaction, which prevents an in-place save.
Changed
- Temporarily paused macOS CI jobs and release builds while decompiler and
fixture symbol failures are investigated. CI and release binaries now target
Linux and Windows. - Updated the GitHub Release action and use the tagged version's changelog
section as release notes. crates.io publishing requires the repository
variablePUBLISH_CRATES_IO=trueand a configuredCARGO_REGISTRY_TOKEN. function create ADDRESS [NAME]attempts disassembly first when the target
has no instruction.find calls TARGETnow returns calls made by the target function, scanning
its entire body. Rows usecall_site,callee,callee_address, andtype
instead of the previous incoming-calladdress/callerfields.patch nop --count Nstops at the first missing instruction after a
successful patch and reports the actual count and patched instructions.
A missing instruction at the starting address still fails; reaching a gap
later no longer rolls back the preceding patches.- Separated Rust CLI workflows, bridge transport, headless import, and bridge
diagnostics into dedicated modules. Split the Java bridge into runtime,
scheduling, program-session, and command components; startup anddoctor
compile the same complete source bundle. Handlers resolve the current
program and per-job monitor through the shared session. - Rust library APIs now carry import/export limits in
BridgeClient::list_imports/list_exportsand analysis/loader settings in
bridge::import_oneshotviaOneShotImportOptions. cargo test-runshares a closed, analyzed fixture across test executables
within one invocation, giving each suite an independent project copy.
Fixture creation uses file locks and atomic publication; setup failures are
cached for that run. Prerequisite checks run once per suite, and fixture
import avoids starting a throwaway bridge. Plaincargo testretains a
fixture local to each test executable.- Integration tests build a host-native fixture from Rust source, use isolated
temporary projects, and derive test addresses from the imported program.
CI no longer reuses mutable Ghidra project caches. Integration jobs use
cargo test-run, include tag and fixture coverage, and release validation
runs the full test set. Added regression coverage for cancellation followed
by another job, program switching, and persistence after a failed mutation. - Reorganized agent guidance under
docs/skills/SKILL.md, with runtime and
recovery guidance indocs/runtime.mdand implementation documentation beside
its modules. Replaced the old.claude-specific guidance and separated future
plans from the command reference. - Updated Cargo dependencies and adapted output formatting, hashing, HTTP/TLS,
and ZIP extraction to their current APIs. - Package metadata now points to
toratako/ghidra-cliand liststoratako
alongside original author Alexander Kiselev. Recorded incorporated upstream
contributions inLICENSE.
Fixed
- Fresh imports no longer run auto-analysis twice.
import --no-analyzenow
also disables analysis in the one-shot importer; imports through an existing
bridge still run analysis when requested. - Failed headless imports include recent stdout and stderr in their
diagnostics, including errors that Ghidra reports on stdout. - Program switching resolves the project's file path rather than comparing
internal program names.--program,program open,analyze, and the
current-program marker now distinguish copied programs with identical names,
including files in project subfolders. - Failed nested mutation transactions no longer roll back earlier successful
commands in the headless session. Partial changes from the failed request can
remain; this does not provide atomic rollback per request. Standalone
transactions retain commit/rollback behavior. - Clean bridge shutdown persists pending edits.
program closenow reports
that closing did not save them to disk; useprogram saveorstopto flush
edits before closing. - Java scripts load from the exact OSGi bundle registered for their directory,
preventing broader registered script paths from shadowing it. Removed a
reflective class-name literal that made the OSGi analyzer add an unwireable
package import and break bridge startup. symbol rename, top-levelrename, andsymbol deletereject ambiguous
names unless scoped with--address/--filteror explicitly applied to all
matches with--all.symbol delete --filternow scopes the deletion.
function rename OLD NEW --address ADDRESShonors the exact entry address
and rejects anOLDname mismatch.type createrejects C declarations and other non-identifier names instead
of silently creating an empty struct named after the entire input. Use
type import-cfor declarations ortype add-fieldto populate an empty struct.function createandtype applyerrors include structured details about
owning functions, missing instructions, overlapping code units, and conflicting
data types/ranges. Error detail is printed as JSON on stderr with-vvor
--json.- Address-field filters accept quoted hexadecimal values with or without a
0x/0Xprefix.memory readand patch operations resolve overlay-qualified
addresses;clearparses ranges such asrom1::5512:551dand inherits the
start address's space for an unqualified end address. xref toresolves external import names and their local thunk targets,
collecting references to all matching addresses without duplicate rows.strings refs PATTERNsearches matching defined string values and returns
their references instead of treating the pattern as an address.graph callersrecognizes parameter and indirection references as well as
direct calls.graph callers/calleeshonor--limitduring recursive
traversal, avoiding an exhaustive walk before truncating the output;
--limit 0remains unlimited.dump imports|exportsandquery imports|exportspass row limits to the
bridge, including the unlimited--limit 0case.patch bytesandpatch noptemporarily enable writes to read-only memory
blocks and restore the original permission afterward.analyzer set NAME true|falseaccepts an explicit boolean and displays
--helpwithout panicking. Missing or invalid values produce argument errors.- Socket read timeouts report
Timeout:with exit code 75 (EX_TEMPFAIL),
distinct from bridge failures with exit code 1. A client timeout does not
cancel the server-side job; inspectghidra jobsbefore retrying.
Removed
- The legacy
typeargument alias for the bridge'scomment_setrequest.
Direct protocol clients must sendcomment_type; the CLI continues to expose
--comment-type.