* Added support for functions
* Added unit-test for propagators
* Updated documentation
* Updated documentation and increase of patch version
* Prevent newlines in YML files
* First draft of new function-centric configuration
* Fixed unit-tests
* Distinguish src_par_slice and snk_par_slice
* Cleanup
* Updated popup dialogs
* Remove empty aliases
* Fix adding functions to new categories
* Add tree items without tab refresh
* Added context menu and remove functionality
* Always fix functions
* Updated documentation
* Rename propagator to fixer
* Updated documentation
* Quotes in log messages
* Try to restore path instruction using instruction address
* Changing log outputs
* Improved upwards propagation of checkbox states
* Update analysis without waiting
* Run re-analysis after function type signature fixes in non-UI thread
* Include Path for type checking only
* Support for installation with uv
* Minor change in the installation instructions
* Fix functions outside UI thread
* Use proper session ID in logger
- Implement proper per-BinaryView plugin context
- Refactoring of the Model-View-Controller architecture
- Replace Binja BackgroundTaskThreads with standard Threads
- Allow parallel task (e.g. analyze paths with AI while still slicing)
- Improve UI responsiveness
- Various other improvements
If the slicer enters a function due to following an output parameter, the corresponding parameter is added to the set of known pointers in that function.
Improved tracking of **pointers**:
- Backward slice memory version at each variable use-site
- Use HLIL for call parameters
Improved **flow graphs**:
- Support the marking of function output parameters
- Added call sites
**Other** improvements:
- Additional `libc` source/sink functions
- Setting to fix source/sink function types
- Command-line argument to save `.bndb` containing the identified paths
- Added unit-tests `function_out_params-XX.c`
- When the slicer enters a function, it now understands whether it followed the function's return value or entered due to following a pointer parameter. In the first case, the slicer proceeds at all possible return instructions of the callee. In the second case, the slicer proceeds at the instruction writing the output parameter.
- Few other improvements with respect to pointer tracking
- Added unit-tests for object-oriented programming in C++
- Support for tracking virtual functions via VTables (requires Binja to correctly identify code x-refs of function pointers in VTables)
- Refactoring of the slicing core with proper call stack tracking, enabling more accurate inter-procedural variable slicing
- Switching to Binary Ninja's internal FlowGraph API for call graph visualization
- Several small improvements, e.g. with respect to pointer analysis
* Added helper to get the instructions corresponding to function parameters
* Select MLIL Function as Source
* Fix code x-refs
* Select HLIL and LLIL function as source
* Always slice parameters for MLIL Function sources
* Cleanaups
* Always use all code x-refs for manual sources
* Bug fix in logging path diffs
* Synthetic calls have no basic block
* Only consider sources/sinks from libc for unit tests
* Updated documentation
* Patch version update
* Fix expansion of paths
* Using BinaryBase and CarryBase
* Using ConstBase and UnaryBase
* Support misc instructions
* Remove non-SSA instructions
* Merge cases
* Support store instructions
* Enable log output in unittests
* Tests for MLIL instruction handlers
* Line break
* Testing MLIL_STORE_STRUCT
* Testing MLIL_STORE_STRUCT
* Testing MLIL_STORE_STRUCT
* Added instruction handler
* Struct tests
* Integreate assembler
* Unit test for MLIL_JUMP
* Added handlers
* Added handlers
* Create function
* Using ConstBase and UnaryBase
* Support misc instructions
* Added test case for call instructions
* Added handlers
* Create function
* Tests for MLIL instruction handlers
* Testing MLIL_STORE_STRUCT
* Integreate assembler
* Added test case for call instructions
* Cleanups
* Cleanup
* Added unittest for struct
* Using BinaryBase and CarryBase
* Using ConstBase and UnaryBase
* Support misc instructions
* Remove non-SSA instructions
* Merge cases
* Support store instructions
* Enable log output in unittests
* Tests for MLIL instruction handlers
* Line break
* Testing MLIL_STORE_STRUCT
* Testing MLIL_STORE_STRUCT
* Testing MLIL_STORE_STRUCT
* Added instruction handler
* Struct tests
* Integreate assembler
* Unit test for MLIL_JUMP
* Added handlers
* Added handlers
* Create function
* Using ConstBase and UnaryBase
* Support misc instructions
* Added test case for call instructions
* Added handlers
* Create function
* Tests for MLIL instruction handlers
* Testing MLIL_STORE_STRUCT
* Integreate assembler
* Added test case for call instructions
* Cleanups
* Cleanup
* Added unittest for struct
* Improvements
* Improvements
* Improved method to determine caller sites
* Added handler for MLIL_Separate_Param_List
* Remove testing individual instructions
* Minor version update
* Select test binaries by EXT environment variable
* Improved function slicing
* Restructure function handling
* Test to manually select MLIL instruction as source
* Slice manually selected MLIL instructions
* Changed name
* Temporary changes
* Use merged call graphs and add debug info to exported paths
* Test to manually select MLIL call instructions as source
* Cleanup
* Popup view
* Cleanups
* Reordering context menu
* Make backward/forward slices more explicit
* Change to SSA form
* Select sinks manually
* Restructuring to add save functionality
* Fix par_slice
* Add function manually
* Function synopsis
* Bug fix
* Editable function synopsis
* Editable category
* Allow manual source/sink selection on all ILs
* Catch exception
* Ignore .yml.bak files
* Updated usage instructions
* Updated usage instructions
* Bug fix
* User feedback when adding source/sink
* Parse returns None in case of failure
* Improved user feedback
* Fixing function signatures for imports
* Bug fix
* Added contributor
* Added symbol names used by xcode
* Fixing code x-ref issue
* Fixes for PE files
* Improved function slicing
* Only log source/sink info if we process it
* Store all instructions at the code x-refs address
* Restructure function handling
* Pass canceled callable to MediumLevelILBackwardSlicer
* Pass canceled callable to MediumLevelILBackwardSlicer
* Improved cancellation
* 151 failed to find code references in macho binaries (#160)
* Added contributor
* Added symbol names used by xcode
* Fixing code x-ref issue
* Fixes for PE files
* Improved function slicing
* Only log source/sink info if we process it
* Store all instructions at the code x-refs address
* Restructure function handling
* Moved to class method
* Handle no founds found
* Improved function slicing
* Restructure function handling
* Pass canceled callable to MediumLevelILBackwardSlicer
* Improved cancellation
* Fixing follow_params
* Remove uneeded function follow_params
* Version update
* Added contributor
* Added symbol names used by xcode
* Fixing code x-ref issue
* Fixes for PE files
* Improved function slicing
* Only log source/sink info if we process it
* Store all instructions at the code x-refs address
* Restructure function handling
* Moved to class method
* Handle no founds found
* Add dependency extraction and plugin JSON update functionality
* Update minimum binary ninja version to 5336
* Update minimum binary ninja version to 5747
* Add dependency extraction and plugin JSON update functionality
* Clean some resources
* Fixed some dependencies
* Update to new description
* Prepare version for new release
* Add release badge
* Added installinstructions to pass validation
* Add link
* Add requirements.txt generation and remove dependencies from plugin.json
* Update README and plugin.json with new logo and improved long description
* Replaced other images too
* Minor cleanups
* Minor cleanups
* Refactor README processing to keep only the first section and remove others; update long description in plugin.json for clarity.
* Update networkx dependency to use the default extra in pyproject.toml and requirements.txt
---------
Co-authored-by: wizche <sergio.paganoni@gmail.com>
- Improved handling of `MediumLevelILVarAliased` instructions
- Added helper function for SsaVariables
- Improved unit-tests with respect to pointer analysis
- Paths can be saved/loaded to/from the .bndb
- Paths can be deleted
- Paths can be exported to JSON or YAML files (UI and headless mode)
- Paths can be imported from JSON or YAML files