| java.lang.Object | |
| ↳ | com.pnfsoftware.jeb.core.units.code.asm.analyzer.AbstractAnalyzerExtension<InsnType extends com.pnfsoftware.jeb.core.units.code.IInstruction> |
Extension of the INativeCodeAnalyzer.
| Fields | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| protected INativeCodeAnalyzer<InsnType extends IInstruction> | gca | ||||||||||
| protected BinaryPatternVerifier | paddingVerifier | ||||||||||
| protected BinaryPatternVerifier | prologueVerifier | ||||||||||
| Public Constructors | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| AbstractAnalyzerExtension() | |||||||||||
| Public Methods | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| NativeCodeAnalyzerExtensionResult<Boolean> |
determinePotentialPointers(long address, InsnType insn, List<PointerDescription> values)
The default result (
getResult()) is false. | ||||||||||
| NativeCodeAnalyzerExtensionResult<Integer> |
determineRoutineStackPointerDelta(CFG<InsnType> routine)
The default result (
getResult()) is null. | ||||||||||
| NativeCodeAnalyzerExtensionResult<SwitchInformation> |
determineSwitchInformation(long address, long base, Map<Long, List<InsnType>> inBlocks, Map<Long, List<Long>> dstBlocks)
The default result (
getResult()) is null. | ||||||||||
| NativeCodeAnalyzerExtensionResult<Long> |
getPossiblePaddingSize(long address, long addressMax)
Default implementation checks the patterns stored in
paddingVerifier. | ||||||||||
| NativeCodeAnalyzerExtensionResult<List<EntryPointDescription>> |
getProbableEntryPoints(long address, long addressMax)
Determine the likely entry points in the given memory area.
| ||||||||||
| NativeCodeAnalyzerExtensionResult<EntryPointDescription> |
getPrologueLooking(long address, long addressMax)
Default implementation checks the patterns stored in
prologueVerifier. | ||||||||||
| void |
initialize(INativeCodeAnalyzer<InsnType> analyzer)
Must be called by the GCA.
| ||||||||||
| NativeCodeAnalyzerExtensionResult<Boolean> |
isCandidateSwitchDispatcher(long address, InsnType insn, List<InsnType> insns)
The default result (
getResult()) is false. | ||||||||||
| NativeCodeAnalyzerExtensionResult<Boolean> |
isNonReturningRoutine(INativeMethodItem routine)
Determine if the given routine is non-returning.
| ||||||||||
| NativeCodeAnalyzerExtensionResult<? extends PointerDescription> |
isTrampolineToDynResRoutine(CFG<InsnType> routine)
The default result (
getResult()) is null. | ||||||||||
| NativeCodeAnalyzerExtensionResult<Boolean> |
postprocessImage()
This method is called after the first analysis pass was performed.
| ||||||||||
| NativeCodeAnalyzerExtensionResult<Boolean> |
preprocessImage()
This method is called before the first analysis pass is performed.
| ||||||||||
| NativeCodeAnalyzerExtensionResult<Boolean> |
shouldForceRoutineEnd(long address, InsnType insn)
The default result (
getResult()) is false. | ||||||||||
| Protected Methods | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| void |
initializePaddingPatterns(BinaryPatternVerifier paddingVerifier)
The default implementation does nothing.
| ||||||||||
| void |
initializeProloguePatterns(BinaryPatternVerifier prologueVerifier)
The default implementation does nothing.
| ||||||||||
|
[Expand]
Inherited Methods | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
From class
java.lang.Object
| |||||||||||
From interface
com.pnfsoftware.jeb.core.units.code.asm.analyzer.INativeCodeAnalyzerExtension
| |||||||||||
The default result (getResult()) is false.
getResult(); false to let the
code analyzer proceed with its own (generic) pointer discovery algorithm; true to
instruct it to skip it
The default result (getResult()) is null.
getResult(), null if the
routine failed to determine the stack pointer delta
The default result (getResult()) is null.
| address | base address of the switch instruction |
|---|---|
| base | base address of the basic block to analyze |
| inBlocks | all known basic blocks. The map index is the base address and it must at least contains the switch candidate, but not necessarily all the blocks (and at least a path to the switch candidate). |
| dstBlocks | map that indicates the destination offsets per basic block base address. |
SwitchInformation in getResult()
(might be empty), null if the routine failed
Default implementation checks the patterns stored in paddingVerifier. When alignment
information are present, only unaligned data is considered padding. If nothing is found,
result (getResult()) is 0L.
| address | address to be examined (inclusive) |
|---|---|
| addressMax | end address to be examined (exclusive) |
getResult(); the size of the
padding-like area from address, 0L if it does not look like padding
Determine the likely entry points in the given memory area. It might provide several entry points (with different modes) ordered by their likelihood.
This method is not guaranteed to give the correct result, and should be considered an heuristic. It is intended to be used before the actual disassembly of code; it may provide a hint on the entry point to disassemble with.
getResult(), ordered from the most probable
to the least probable. The list will be empty if none could be determined
Default implementation checks the patterns stored in prologueVerifier. Can be
overridden, but sub-class should call super-method first. If nothing is found, result
(getResult()) is null.
| address | address to be examined (inclusive) |
|---|---|
| addressMax | end address to be examined (exclusive) |
EntryPointDescription in
getResult() if a prologue was found,
possibly at a different address than address parameter, null if no prologue was
found.
Must be called by the GCA. We cannot use @SerCustomInit here, as the GCA may not exist yet (eg, unprocessed unit).
The default result (getResult()) is false.
| address | address of the branching instruction |
|---|---|
| insn | branching instruction |
| insns | list of all instructions in the current basic block |
getResult(); true if the
instruction might correspond to a switch-like statement, false otherwise
Determine if the given routine is non-returning.
getResult(); true if the
routine does not return, false otherwise, null when no determination could be made
The default result (getResult()) is null.
PointerDescription in getResult()
for the target, null if none
This method is called after the first analysis pass was performed.
This method is called before the first analysis pass is performed.
The default result (getResult()) is false.
| insn | parsed instruction at the provided address |
|---|
getResult(); true if the
address should be considered a routine termination, false otherwise
The default implementation does nothing.
The default implementation does nothing.