Added
- Add
internal_program_nametoprogram infoso Ghidra's internal Program
name remains visible when it differs from the selected project file name. - Add
namespace rename,namespace move, andnamespace deletefor local
namespaces and classes. Deletion requires an empty namespace unless
--recursiveis explicit, and reports every removed symbol, including
descendant functions and variables. Namespace mutations accept--where
to disambiguate exact paths by ID. - Add repeated
--bind-type NAME PATHtofunction set-signatureand
function call-signature setto select exact data types for names in a
declaration without registering alias types. - Support standalone
ghidra.jarfiles generated by the official default
buildGhidraJar, selected withGHIDRA_JARorconfig set ghidra_jar.
Preserve directory installation detection, and use the selected runtime for
imports, project operations, bridge startup, and doctor checks. - Add
type archive inspect,type archive import, andtype archive exportfor
inspecting and transferring Ghidra data type archives. Explicit root selection
includes dependencies; imports reject definition, provenance, and ABI conflicts
atomically, and exports publish a validated new archive without overwriting files. - Add
decompile --with-addressesto relate C lines to native instruction
positions, with a structured JSON mapping, human-readable address gutters,
and inline address comments in C output. - Add
find function-candidatesto find unowned instruction starts backed by
effective CALL references. Candidates retain call-site evidence and distinct
call counts; destination bounds and scan completion support focused recovery
without disassembling code or creating functions. - Add
find virtual-callers FUNCTION --vtable ADDRESS --entries N --abi itanium|msvc
to search indirect calls through explicit absolute-pointer table slots. Optional
--within FUNCTIONrestricts the caller scope; results distinguish traced table
addresses, recovered types, and offset-only candidates, with incomplete-scan
diagnostics and no changes to references or types. - Add
function set-thunk FUNCTION --target FUNCTIONandfunction clear-thunk
to edit a function's direct forwarding relationship, with before/after
signatures, ABI storage, and direct/final targets. Clearing exposes the
function's own saved definition without copying the destination's signature. - Add
job result IDto recover completed bridge responses after a disconnect
or timeout, including structured failures and cancellation results. Bounded
in-memory retention ends with the bridge; unknown outcomes include a recovery
command without adding identifiers to normal command output. - Add
memory read-vtable TARGET --entries N --abi itanium|msvcfor explicit table
slots and ABI metadata, including LLVM relative32 encoding, and
find address-tablesfor Ghidra's native table candidates. - Add
function var infer-structto read Ghidra's structure recovery candidate
for one variable without registering a type or editing the program. Optional
bounded LOAD/STORE evidence retains native instruction locations. - Add
type uses TYPEto find registered types in applied data and database
function signatures, following typedefs, pointers, and arrays. Results retain
declaration paths, ABI and thunk provenance, and scan completion. - Add
type uses TYPE --kind variablefor decompiler parameters and locals,
andtype field uses TYPEfor semantic field accesses. Both support function
scope and report incomplete scans; field results distinguish read, write,
address-taking and unclassified uses with instruction evidence.
Removed
- Remove
ghidra-cli setup. Install Ghidra and a compatible full JDK separately;
select the installation through automatic detection,GHIDRA_INSTALL_DIR, or
config set ghidra_install_dir, and verify it withdoctor --runtime.
Changed
-
Reserve namespace/class rename and deletion for
namespacecommands;
symbol renameandsymbol deletereject these targets before editing any
selected symbol. Individual label/function moves remainsymbol set-namespace. -
Flatten
xref create memorytoxref create, retaining ordinary-memory
reference validation and explicit operand/type selection. -
Consolidate memory block attribute edits into
memory block set BLOCK_START
with--name,--permissions, and--volatile true|false. Multiple attributes
change atomically; omitted attributes are preserved. Block creation also takes
an explicit boolean for--volatile(default false). -
Move function tag operations from
tagtofunction tag. Keep shared
program-level definitions separate from function attachments through
createandattach; remove the top-level command. -
Move calling-convention discovery to
program list-calling-conventions [NAME],
matching its compiler-specification scope and supporting explicit program operands. -
Rename
memory maptomemory block list, grouping block queries and edits.
Preserve list output and query options; remove the old command. -
Move
type applytolisting define-data, preserving its arguments, data
definition behavior, and result fields. -
Include the current class/namespace, calling convention, and parameter type
when rejecting an automaticthisedit, with guidance for correcting class
membership through namespace operations. -
Use client-generated UUIDs as job IDs, available before the response arrives.
-
Extend current-memory pointer output with decoded targets, normalized code
entries, qualified symbols/functions, and direct/final thunk destinations. -
Use
initializedconsistently in memory map, info, and block edit receipts. -
Rename
program stats'ssectionsfield tomemory_blocks, counting all
Program memory blocks, including overlays and uninitialized blocks. -
Accept decimal and
0x-prefixed hexadecimal integer arguments consistently;
leading zeroes remain decimal, and each argument retains its sign and range
constraints. Addresses and byte patterns retain their separate syntax. -
Use
--wherefor target selection in symbolrename,delete,
set-namespace, andset-primary, and function variableget/set;
result queries keep--filter/-f. -
Use
xref from TARGET --whole-functionto inspect the containing function. -
Use named
--start,--end, and--valueoptions for processor context
operations;getdefaults its end to the start, whilesetandclear
require both endpoints. -
Make program management targets positional; export takes a program name and
--export-format, and rebase takes--base. Settings and memory operations
use named options for values, sizes, permissions, and categories. -
Select tags and equates before their function/address associations. Use
--text,--file, or--stdinfor notes and--codefor inline C declarations.
Comment and reference kinds use--type; no-return edits require--value. -
Accept repeated
--member NAME VALUEfor enum creation and
--loader-option NAME VALUEfor import. Select enum members with--member. -
Separate script artifact existence checks (
--expect PATH) from minimum row
counts (--expect-rows PATH MIN_ROWS), preserving literal artifact paths. -
Separate field inclusion and exclusion with
--fieldsand--exclude-fields.
Use--skipfor query pagination,--formatfor response format, and-o
only for output destinations.
Fixed
- Exclude stale call targets and inactive CALL overrides from
graph callers,
graph callees, andgraph callsby checking the instruction's effective flow.
Keep computed-call targets and symbolic external relocation calls visible. - Parse nested function-pointer parameters in function and call-site signatures,
and resolve existing type names with shared ambiguity checks and candidate paths. - Preserve Unicode JAR paths and headless arguments when launching standalone
Ghidra on Windows, including project paths outside the system code page. - Restrict named function targets to actual function names so entry aliases and
internal labels cannot redirect function edits or deletion. - Include nested structure/array strings in string listing, searches, and
reference queries, and continue exact byte/text searches across address-space
boundaries after matching the final address. - Include namespaces, classes, and variable symbols in symbol listings.
- Exclude equates and union-field annotations from decompiled local variables.
- Sort boolean fields and preserve integer precision when sorting numeric fields.
- Allow local project listing and information queries without a working Ghidra
installation or creating the project directory. - Bind program selection to each queued operation so concurrent clients cannot
redirect commands issued with--program, including guarded edits and import
follow-up requests. Batches retain each project's selection across nested rows
using the actual operation responses.