mirror of https://github.com/geohot/qira
222d6da4f0
This PR introduces bap as a backend for QIRA. The backend is made optional, but is enabled by default. This backend allows one to disassemble instructions for all platforms, supported by LLVM (at the time of writing it is about 25 targets). Also, to some platforms BAP will provide BIL and/or target specific instructions, lifted to first class python values, as opposed to strings. A new instruction class is introduces, that will use BIL if available to infer destinations, as well as to infer registers touched or modified by the instruction. Using, BIL allows us to determine instructions like `pop {r0, pc}` as calls, that, as a consequence, allows us to build a more correct CFG. As a drawback on ARM platform the built CFG is so big, that it takes a considerable amount of time just to draw it. Since BAP can provide a reasonable analysis for all platforms, including those that at the time of writing still doesn't have a BIL support, the static analysis in QIRA will be always turned on. BAP is installed using opam, and BAP Python bindings a downloaded directly from the git repository using pip. As a free bonus, this PR will also fix Travis CI issue. |
||
---|---|---|
.. | ||
__init__.py | ||
arch.py | ||
qira.py | ||
qira_analysis.py | ||
qira_base.py | ||
qira_config.py | ||
qira_log.py | ||
qira_program.py | ||
qira_socat.py | ||
qira_webserver.py | ||
qira_webstatic.py |