Skip to content

v0.9.0

Latest

Choose a tag to compare

@github-actions github-actions released this 24 Sep 01:10
· 38 commits to master since this release

Added

  • Add internal_program_name to program info so Ghidra's internal Program
    name remains visible when it differs from the selected project file name.
  • Add namespace rename, namespace move, and namespace delete for local
    namespaces and classes. Deletion requires an empty namespace unless
    --recursive is explicit, and reports every removed symbol, including
    descendant functions and variables. Namespace mutations accept --where
    to disambiguate exact paths by ID.
  • Add repeated --bind-type NAME PATH to function set-signature and
    function call-signature set to select exact data types for names in a
    declaration without registering alias types.
  • Support standalone ghidra.jar files generated by the official default
    buildGhidraJar, selected with GHIDRA_JAR or config set ghidra_jar.
    Preserve directory installation detection, and use the selected runtime for
    imports, project operations, bridge startup, and doctor checks.
  • Add type archive inspect, type archive import, and type archive export for
    inspecting and transferring Ghidra data type archives. Explicit root selection
    includes dependencies; imports reject definition, provenance, and ABI conflicts
    atomically, and exports publish a validated new archive without overwriting files.
  • Add decompile --with-addresses to relate C lines to native instruction
    positions, with a structured JSON mapping, human-readable address gutters,
    and inline address comments in C output.
  • Add find function-candidates to find unowned instruction starts backed by
    effective CALL references. Candidates retain call-site evidence and distinct
    call counts; destination bounds and scan completion support focused recovery
    without disassembling code or creating functions.
  • Add find virtual-callers FUNCTION --vtable ADDRESS --entries N --abi itanium|msvc
    to search indirect calls through explicit absolute-pointer table slots. Optional
    --within FUNCTION restricts the caller scope; results distinguish traced table
    addresses, recovered types, and offset-only candidates, with incomplete-scan
    diagnostics and no changes to references or types.
  • Add function set-thunk FUNCTION --target FUNCTION and function clear-thunk
    to edit a function's direct forwarding relationship, with before/after
    signatures, ABI storage, and direct/final targets. Clearing exposes the
    function's own saved definition without copying the destination's signature.
  • Add job result ID to recover completed bridge responses after a disconnect
    or timeout, including structured failures and cancellation results. Bounded
    in-memory retention ends with the bridge; unknown outcomes include a recovery
    command without adding identifiers to normal command output.
  • Add memory read-vtable TARGET --entries N --abi itanium|msvc for explicit table
    slots and ABI metadata, including LLVM relative32 encoding, and
    find address-tables for Ghidra's native table candidates.
  • Add function var infer-struct to read Ghidra's structure recovery candidate
    for one variable without registering a type or editing the program. Optional
    bounded LOAD/STORE evidence retains native instruction locations.
  • Add type uses TYPE to find registered types in applied data and database
    function signatures, following typedefs, pointers, and arrays. Results retain
    declaration paths, ABI and thunk provenance, and scan completion.
  • Add type uses TYPE --kind variable for decompiler parameters and locals,
    and type field uses TYPE for semantic field accesses. Both support function
    scope and report incomplete scans; field results distinguish read, write,
    address-taking and unclassified uses with instruction evidence.

Removed

  • Remove ghidra-cli setup. Install Ghidra and a compatible full JDK separately;
    select the installation through automatic detection, GHIDRA_INSTALL_DIR, or
    config set ghidra_install_dir, and verify it with doctor --runtime.

Changed

  • Reserve namespace/class rename and deletion for namespace commands;
    symbol rename and symbol delete reject these targets before editing any
    selected symbol. Individual label/function moves remain symbol set-namespace.

  • Flatten xref create memory to xref create, retaining ordinary-memory
    reference validation and explicit operand/type selection.

  • Consolidate memory block attribute edits into memory block set BLOCK_START
    with --name, --permissions, and --volatile true|false. Multiple attributes
    change atomically; omitted attributes are preserved. Block creation also takes
    an explicit boolean for --volatile (default false).

  • Move function tag operations from tag to function tag. Keep shared
    program-level definitions separate from function attachments through
    create and attach; remove the top-level command.

  • Move calling-convention discovery to program list-calling-conventions [NAME],
    matching its compiler-specification scope and supporting explicit program operands.

  • Rename memory map to memory block list, grouping block queries and edits.
    Preserve list output and query options; remove the old command.

  • Move type apply to listing define-data, preserving its arguments, data
    definition behavior, and result fields.

  • Include the current class/namespace, calling convention, and parameter type
    when rejecting an automatic this edit, with guidance for correcting class
    membership through namespace operations.

  • Use client-generated UUIDs as job IDs, available before the response arrives.

  • Extend current-memory pointer output with decoded targets, normalized code
    entries, qualified symbols/functions, and direct/final thunk destinations.

  • Use initialized consistently in memory map, info, and block edit receipts.

  • Rename program stats's sections field to memory_blocks, counting all
    Program memory blocks, including overlays and uninitialized blocks.

  • Accept decimal and 0x-prefixed hexadecimal integer arguments consistently;
    leading zeroes remain decimal, and each argument retains its sign and range
    constraints. Addresses and byte patterns retain their separate syntax.

  • Use --where for target selection in symbol rename, delete,
    set-namespace, and set-primary, and function variable get/set;
    result queries keep --filter/-f.

  • Use xref from TARGET --whole-function to inspect the containing function.

  • Use named --start, --end, and --value options for processor context
    operations; get defaults its end to the start, while set and clear
    require both endpoints.

  • Make program management targets positional; export takes a program name and
    --export-format, and rebase takes --base. Settings and memory operations
    use named options for values, sizes, permissions, and categories.

  • Select tags and equates before their function/address associations. Use
    --text, --file, or --stdin for notes and --code for inline C declarations.
    Comment and reference kinds use --type; no-return edits require --value.

  • Accept repeated --member NAME VALUE for enum creation and
    --loader-option NAME VALUE for import. Select enum members with --member.

  • Separate script artifact existence checks (--expect PATH) from minimum row
    counts (--expect-rows PATH MIN_ROWS), preserving literal artifact paths.

  • Separate field inclusion and exclusion with --fields and --exclude-fields.
    Use --skip for query pagination, --format for response format, and -o
    only for output destinations.

Fixed

  • Exclude stale call targets and inactive CALL overrides from graph callers,
    graph callees, and graph calls by checking the instruction's effective flow.
    Keep computed-call targets and symbolic external relocation calls visible.
  • Parse nested function-pointer parameters in function and call-site signatures,
    and resolve existing type names with shared ambiguity checks and candidate paths.
  • Preserve Unicode JAR paths and headless arguments when launching standalone
    Ghidra on Windows, including project paths outside the system code page.
  • Restrict named function targets to actual function names so entry aliases and
    internal labels cannot redirect function edits or deletion.
  • Include nested structure/array strings in string listing, searches, and
    reference queries, and continue exact byte/text searches across address-space
    boundaries after matching the final address.
  • Include namespaces, classes, and variable symbols in symbol listings.
  • Exclude equates and union-field annotations from decompiled local variables.
  • Sort boolean fields and preserve integer precision when sorting numeric fields.
  • Allow local project listing and information queries without a working Ghidra
    installation or creating the project directory.
  • Bind program selection to each queued operation so concurrent clients cannot
    redirect commands issued with --program, including guarded edits and import
    follow-up requests. Batches retain each project's selection across nested rows
    using the actual operation responses.