You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
find instruction PATTERN searches existing Ghidra instruction text with
case-insensitive literal matching, optional --case-sensitive, and inclusive --start/--end bounds. It supports the usual query options and cancellation;
it neither disassembles undefined bytes nor requires cross-references.
disasm TARGET --end END lists existing instructions whose start addresses
lie in the inclusive range. It rejects --instructions together with --end,
reversed ranges, and bounds in different address spaces. Range queries honor --limit (including zero), filtering, sorting, offsets, and counts.
Explicit --format c and --format asm render decompiled C and instruction
text, including addresses, bytes, mnemonics, and operands for disassembly.
Output defaults remain human-readable on TTY and compact JSON on non-TTY.
Results containing rows without the required code fields, including after --fields projection, retain a single JSON document.
doctor --runtime creates a disposable project, starts and pings the real
Ghidra bridge, verifies clean shutdown, and removes the project. It reports
Ghidra's settings/cache paths and retains the diagnostic project if shutdown
fails. Without --runtime, JVM startup is explicitly reported as not_checked.
Changed
program list reports Ghidra's recorded analysis-completion flag instead of
estimating it from the function count. Missing or unreadable flags are null.
Import analysis, analyze, and analyzer run record successful completion;
a cancelled first analysis does not create a completed flag.
Function, symbol, type, string and comment lists push a single contains filter
and safe offset/limit into Ghidra, including query/dump aliases, reducing JSON
generation and transfer. Supported filter fields are name for functions,
symbols, and types, value for strings, and text for comments. Sort, count,
projection and other filters stay in Rust. Default limits, unlimited requests,
page counts and batch output retain their semantics. Restart running bridges
after upgrading; there is no old-bridge query fallback. Java/Rust Unicode
lowercasing differences can still miss contains matches or shift page results;
see query execution.
batch writes attempted results to stdout even on partial failure, preserving
nonzero exit codes and stop policies. Stderr no longer carries detail.results.
find calls TARGET searches the selected program for incoming call sites; function calls TARGET retains outgoing calls. Resolved thunks and import
pointers are followed without treating ordinary data references as calls.
Incoming rows include caller, caller_address, and via alongside the call
site and callee; unresolved function-pointer calls are not inferred.
doctor checks storage create/write/rename/delete operations and loopback TCP
bind/connect, with resolved paths and configuration sources in its report.
Bridge lifecycle operations use persistent OS-backed .starting locks. Save
and stop every running bridge with the old CLI before upgrading: old and new lock
protocols cannot coordinate. The new CLI also refuses to stop a legacy bridge
that cannot confirm its final save through shutdown_wait.
See upgrade instructions.
Recovery never deletes Ghidra project locks or force-terminates a discovery PID.
Shutdown uses one total timeout across lock acquisition, connection, response,
and process exit. Timeout errors retain exit code 75 and preserve discovery
and the live process instead of force-terminating it. Status checks no longer
remove discovery files; a live recorded PID prevents cleanup or replacement
startup even when its port is unreachable. .starting files persist after
lock release and must not be deleted.
Rust library list APIs (BridgeClient::list_functions, list_strings, symbol_list, type_list, and comment_list) now require an offset argument. OneShotImportOptions gains program for the saved file name, and BridgeClient::find_calls now requests incoming calls; use function_calls
for outgoing calls. Added function_disasm and symbol_get_by_name adapters,
plus find_string_with_limit, find_bytes_with_limit, and find_interesting_with_limit; the existing search adapters remain available.
Moved the RE agent skill from docs/skills/SKILL.md to docs/skills/ghidra-cli/SKILL.md, with
task-specific references for exploration, refinement, low-level analysis,
programs, scripting, and batch workflows.
Credited hitori-chan's downstream work in LICENSE for the instruction search,
bounded disassembly, and C/assembly output feature inspiration.
Fixed
Explicit-offset type add-field --size rejects sizes Ghidra cannot honor
before changing the structure, matching append behavior.
Symbol deletion rejects generated dynamic labels and the global namespace
before mutation, checks each deletion result, and reports deleted, failed,
and not_attempted targets on partial failure. Successful receipts include the
deleted symbol snapshots. Save failures retain those details. Target-selection
filters no longer erase deletion receipts in standalone or batch output.
find crypto uses correct SHA-256 and MD5 round constants in both little- and
big-endian word order. SHA-512 constants are no longer mislabeled as SHA-256.
graph callers and find calls share call-site validation and thunk/pointer
traversal. Argument references and non-call instructions are not callers.
diff functions --format uses the shared output formats and flag precedence;
unknown formats fail during argument parsing.
setup --version resolves release numbers to official Ghidra_VERSION_build
tags. config set java_home PATH now saves the configured JDK.
script run - uses the JDK parser to require exactly one top-level public
class, accepting modifiers and ignoring apparent declarations in comments,
strings, and nested classes. Invalid syntax reports its line and column before
execution; compilation and loading still use Ghidra's script bundle.
status counts project files in subfolders consistently with program list.
Function lookup errors recommend an executable help command instead of an
invalid bare-word filter.
Search and list output share one query limit plan. find bytes, raw-memory find string, and find interesting no longer truncate at 100/50 matches,
so counts, filters, sorts and offsets can use the complete result set.
Long searches check cancellation. Commands without bridge-side limits now
honor default_limit with omitted query options or --fields alone, including
in batches; explicit --limit 0 remains unlimited.
function disasm lists only the selected function's instructions, including
disjoint body ranges and when selected by an interior address. It honors query
limits, filtering, sorting, pagination, and counts without a hidden ten-instruction
cap or spillover into neighboring functions. A distinct function_disasm
bridge request prevents older bridges from silently returning a partial body.
disasm-at and incomplete clear --disasm-at now fail with retained
diagnostics, so batch --on-error stop stops before dependent edits. Successful
clearing is still saved and reported as a partial change when redisassembly fails.
strings refs applies counts, field selection, filters, sorting, and pagination
to reference rows instead of its response envelope.
Symbol lookup prefers exact names over bare hexadecimal addresses; rename/delete
use name-only lookup so names such as dead remain editable. Explicit 0x/0X
addresses remain available to symbol get. Mutations use the distinct symbol_get_by_name bridge request so older bridges fail before editing.
program list includes nested project folders and correctly identifies the
current program among files sharing the same name.
project info honors the global project and configured default when its name
is omitted, and recognizes empty reservations created by project create.
--projects-dir takes precedence over GHIDRA_PROJECT_DIR without changing
environment variables or saved configuration, including per-line batch overrides.
Script artifact examples use JSONL for minimum-row checks. Help documents .jsonl/.ndjson support and marks CSV row counting as WIP.
Table, CSV, and TSV columns include keys from every output row, so fields
present only in later rows are no longer silently dropped. Missing cells stay
empty; existing column order and CSV/TSV escaping are preserved.
CLI tests without Ghidra cover reservation deletion and preservation of project
files when Ghidra is unavailable; real project deletion runs in Ghidra integration tests.
Windows import tests normalize Ghidra's /C:/... executable paths before
comparing them with native filesystem paths.
Project deletion holds the CLI lifecycle lock through removal and acquires
Ghidra's project lock, refusing deletion while an external Ghidra owner is active.
Deleting .gpr/.rep artifacts now requires a working Ghidra/JDK installation;
missing prerequisites preserve project files. Empty reservations can still be
deleted without Ghidra, and unrelated files in the bare project directory remain.
Stop, restart, and project deletion report final save failures and retain the
JVM/program for recovery. Successful shutdown waits for accepted jobs and saving.
Import rejects unsupported loader option names before loading or saving a
program, reporting import_status: not_started. --compiler-spec now requires --language, and an explicit --program must be a single nonempty file name.
Program metadata, status, operation responses, and artifact manifests use the
saved project file name. program info and summary also expose its path;
internal Ghidra names and original executable paths remain unchanged.
Filesystem error details include io_kind even when a library wrapper hides
the native error code. os_error remains null when that code is unavailable.
Import applies --program to the actual saved file in every route and rejects
an existing explicit name. Responses select the saved file, including automatic
suffixes when no name was specified. One-shot imports confirm a structured save
receipt and successful process exit before starting the persistent bridge.
Startup and configuration I/O errors identify their operation and path. Import
errors retain saved/analysis checkpoints and recovery arguments so a later
bridge failure does not invite repeating an already saved import.
Unsupported memory write/memory search fail with patch bytes/find bytes
alternatives. Function rename rejects --filter/--all; ambiguous function
names return candidates and require an address.
GZF export ends and saves its transaction before packing, stages output beside
the destination, and atomically replaces an existing file only on success.
Fallback fixed-width type aliases retain their widths across target ABIs. Type/field
applicability, size, memory-range, and field-layout checks precede destructive
edits. Struct, enum, and typedef creation report the actual registered name and
path, including conflict suffixes. type add-field --size is honored when
appending, or rejected before mutation if Ghidra cannot represent that size;
existing field settings are preserved.
Symbol edits revalidate selected IDs and metadata before changing any target;
address selectors accept equivalent hex spellings while retaining address spaces.
patch bytes validates that the complete range is mapped and initialized
before clearing code. Patches spanning multiple memory blocks restore every
affected block's write permission.
comment get and comment list return comments at interior addresses of
instructions and data, instead of requiring a code-unit start address.
find bytes rejects empty or incomplete hexadecimal patterns. find function
treats glob punctuation other than * literally. Raw-memory find string
results retain the match in long printable runs and add a truncated flag
indicating printable bytes outside the returned window.
DOT graph output escapes identifiers and labels, preserving address-space
separators instead of replacing them with underscores.
Configured output format is honored after explicit flags. Default limits apply
after client filtering, sorting, and offset, except for counts or explicit zero.
Batch query lines inherit the batch selection despite environment defaults.
Compatibility restart preserves the actual selected program file path and
propagates stop failures instead of starting a replacement JVM.
Configuration updates use locked atomic replacement and preserve config
symlinks and unrelated settings, including concurrent updates on Windows. init preserves existing configuration; invalid output-format values and
dangling config symlinks fail without replacing the previous file. Setup
validates private staging before publication, reuses valid installations,
refuses incomplete existing destinations, and saves absolute paths.
Unavailable file logging no longer prevents commands from running. The CLI
reports logging setup failures only when verbose diagnostics are requested
without --quiet.
Job cancellation is isolated, completed history retains metadata only, and
shutdown remains responsive with a full queue. Pcode work uses the active
cancellation monitor. Artifact hash failures return errors.
CI unit coverage includes both library and binary targets. Ghidra integration
and release test jobs initialize and verify the runtime with doctor --runtime
before parallel JVM startup, and infrastructure coverage includes import/bootstrap recovery.
Shutdown deadline tests no longer hang waiting for mock TCP servers.
Removed
Removed diff programs, BridgeClient::diff_programs, and the diff_programs
bridge request. The command returned the current program's statistics without
comparing the requested programs. diff functions remains available.
Removed the unused --detach flags from import and analysis; commands wait
for completion.
Removed the bridge's find_calls request. Direct protocol clients must use find_calls_to for incoming calls or function_calls for outgoing calls.