ida_idd
Contains definition of the interface to IDD modules.
The interface consists of structures describing the target debugged processor and a debugging API.
Constants
IDD_INTERFACE_VERSION: The IDD interface version number.NO_THREAD: No thread. in PROCESS_STARTED this value can be used to specify that the main thread has not been created. It will be initialized later by a THREAD_STARTED event.DEF_ADDRSIZEREGISTER_READONLY: the user can't modify the current value of this registerREGISTER_IP: instruction pointerREGISTER_SP: stack pointerREGISTER_FP: frame pointerREGISTER_ADDRESS: may contain an addressREGISTER_CS: code segmentREGISTER_SS: stack segmentREGISTER_NOLF: displays this register without returning to the next line, allowing the next register to be displayed to its right (on the same line)REGISTER_CUSTFMT: register should be displayed using a custom data format. the format name is in bit_strings[0]; the corresponding regval_t will use bytevec_tNO_EVENT: Not an interesting event. This event can be used if the debugger module needs to return an event but there are no valid events.PROCESS_STARTED: New process has been started.PROCESS_EXITED: Process has been stopped.THREAD_STARTED: New thread has been started.THREAD_EXITED: Thread has been stopped.BREAKPOINT: Breakpoint has been reached. IDA will complain about unknown breakpoints, they should be reported as exceptions.STEP: One instruction has been executed. Spurious events of this kind are silently ignored by IDA.EXCEPTION: Exception.LIB_LOADED: New library has been loaded.LIB_UNLOADED: Library has been unloaded.INFORMATION: User-defined information. This event can be used to return empty information This will cause IDA to call get_debug_event() immediately once more.PROCESS_ATTACHED: Successfully attached to running process.PROCESS_DETACHED: Successfully detached from process.PROCESS_SUSPENDED: Process has been suspended. This event can be used by the debugger module to signal if the process spontaneously gets suspended (not because of an exception, breakpoint, or single step). IDA will silently switch to the 'suspended process' mode without displaying any messages.TRACE_FULL: The trace buffer of the tracer module is full and IDA needs to read it before continuingSTATUS_MASK: additional info about process stateBITNESS_CHANGED: Debugger detected the process bitness changing.cvarBPT_WRITE: Write access.BPT_READ: Read access.BPT_RDWR: Read/write access.BPT_SOFT: Software breakpoint.BPT_EXEC: Execute instruction.BPT_DEFAULT: Choose bpt type automatically.EXC_BREAK: break on the exceptionEXC_HANDLE: should be handled by the debugger?EXC_MSG: instead of a warning, log the exception to the output windowEXC_SILENT: do not warn or log to the output windowRVT_FLOAT: floating pointRVT_INT: integerRVT_UNAVAILABLE: unavailable; other values mean custom data typeRESMOD_NONE: no stepping, run freelyRESMOD_INTO: step into call (the most typical single stepping)RESMOD_OVER: step over callRESMOD_OUT: step out of the current function (run until return)RESMOD_SRCINTO: until control reaches a different source lineRESMOD_SRCOVER: next source line in the current stack frameRESMOD_SRCOUT: next source line in the previous stack frameRESMOD_USER: step out to the user codeRESMOD_HANDLE: step into the exception handlerRESMOD_BACKINTO: step backwards into call (in time-travel debugging)RESMOD_MAXSTEP_TRACE: lowest level trace. trace buffers are not maintainedINSN_TRACE: instruction tracingFUNC_TRACE: function tracingBBLK_TRACE: basic block tracingDRC_EVENTS: success, there are pending eventsDRC_CRC: success, but the input file crc does not matchDRC_OK: successDRC_NONE: reaction to the event not implementedDRC_FAILED: failed or falseDRC_NETERR: network errorDRC_NOFILE: file not foundDRC_IDBSEG: use idb segmentationDRC_NOPROC: the process does not exist anymoreDRC_NOCHG: no changesDRC_ERROR: unclassified error, may be complemented by errbufDEBUGGER_ID_X86_IA32_WIN32_USER: Userland win32 processes (win32 debugging APIs)DEBUGGER_ID_X86_IA32_LINUX_USER: Userland linux processes (ptrace())DEBUGGER_ID_X86_IA32_MACOSX_USER: Userland MAC OS X processes.DEBUGGER_ID_ARM_IPHONE_USER: iPhone 1.xDEBUGGER_ID_X86_IA32_BOCHS: BochsDbg.exe 32.DEBUGGER_ID_6811_EMULATOR: MC6812 emulator (beta)DEBUGGER_ID_GDB_USER: GDB remote.DEBUGGER_ID_WINDBG: WinDBG using Microsoft Debug engine.DEBUGGER_ID_X86_DOSBOX_EMULATOR: Dosbox MS-DOS emulator.DEBUGGER_ID_ARM_LINUX_USER: Userland arm linux.DEBUGGER_ID_TRACE_REPLAYER: Fake debugger to replay recorded traces.DEBUGGER_ID_X86_PIN_TRACER: PIN Tracer module.DEBUGGER_ID_DALVIK_USER: Dalvik.DEBUGGER_ID_XNU_USER: XNU Kernel.DEBUGGER_ID_ARM_MACOS_USER: Userland arm MAC OS.DBG_FLAG_REMOTE: Remote debugger (requires remote host name unless DBG_FLAG_NOHOST)DBG_FLAG_NOHOST: Remote debugger with does not require network params (host/port/pass). (a unique device connected to the machine)DBG_FLAG_FAKE_ATTACH: PROCESS_ATTACHED is a fake event and does not suspend the executionDBG_FLAG_HWDATBPT_ONE: Hardware data breakpoints are one byte size by defaultDBG_FLAG_CAN_CONT_BPT: Debugger knows to continue from a bpt. This flag also means that the debugger module hides breakpoints from ida upon read_memoryDBG_FLAG_NEEDPORT: Remote debugger requires port number (to be used with DBG_FLAG_NOHOST)DBG_FLAG_DONT_DISTURB: Debugger can handle only get_debug_event(), request_pause(), exit_process() when the debugged process is running. The kernel may also call service functions (file I/O, map_address, etc)DBG_FLAG_SAFE: The debugger is safe (probably because it just emulates the application without really running it)DBG_FLAG_CLEAN_EXIT: IDA must suspend the application and remove all breakpoints before terminating the application. Usually this is not required because the application memory disappears upon termination.DBG_FLAG_USE_SREGS: Take segment register values into account (non flat memory)DBG_FLAG_NOSTARTDIR: Debugger module doesn't use startup directory.DBG_FLAG_NOPARAMETERS: Debugger module doesn't use commandline parameters.DBG_FLAG_NOPASSWORD: Remote debugger doesn't use password.DBG_FLAG_CONNSTRING: Display "Connection string" instead of "Hostname" and hide the "Port" field.DBG_FLAG_SMALLBLKS: If set, IDA uses 256-byte blocks for caching memory contents. Otherwise, 1024-byte blocks are usedDBG_FLAG_MANMEMINFO: If set, manual memory region manipulation commands will be available. Use this bit for debugger modules that cannot return memory layout informationDBG_FLAG_EXITSHOTOK: IDA may take a memory snapshot at PROCESS_EXITED event.DBG_FLAG_VIRTHREADS: Thread IDs may be shuffled after each debug event. (to be used for virtual threads that represent cpus for windbg kmode)DBG_FLAG_LOWCNDS: Low level breakpoint conditions are supported.DBG_FLAG_DEBTHREAD: Supports creation of a separate thread in ida for the debugger (the debthread). Most debugger functions will be called from debthread (exceptions are marked below) The debugger module may directly call only THREAD_SAFE functions. To call other functions please use execute_sync(). The debthread significantly increases debugging speed, especially if debug events occur frequently.DBG_FLAG_DEBUG_DLL: Can debug standalone DLLs. For example, Bochs debugger can debug any snippet of codeDBG_FLAG_FAKE_MEMORY: get_memory_info()/read_memory()/write_memory() work with the idb. (there is no real process to read from, as for the replayer module) the kernel will not call these functions if this flag is set. however, third party plugins may call them, they must be implemented.DBG_FLAG_ANYSIZE_HWBPT: The debugger supports arbitrary size hardware breakpoints.DBG_FLAG_TRACER_MODULE: The module is a tracer, not a full featured debugger module.DBG_FLAG_PREFER_SWBPTS: Prefer to use software breakpoints.DBG_FLAG_LAZY_WATCHPTS: Watchpoints are triggered before the offending instruction is executed. The debugger must temporarily disable the watchpoint and single-step before resuming.DBG_FLAG_FAST_STEP: Do not refresh memory layout info after single stepping.DBG_FLAG_ADD_ENVS: The debugger supports launching processes with environment variables.DBG_FLAG_MERGE_ENVS: The debugger supports merge or replace setting for environment variables (only makes sense if DBG_FLAG_ADD_ENVS is set)DBG_FLAG_DISABLE_ASLR: The debugger support ASLR disabling (Address space layout randomization)DBG_FLAG_TTD: The debugger is a time travel debugger and supports continuing backwards.DBG_FLAG_FULL_INSTR_BPT: Setting a breakpoint in the middle of an instruction will also break.DBG_HAS_GET_PROCESSES: supports ev_get_processesDBG_HAS_ATTACH_PROCESS: supports ev_attach_processDBG_HAS_DETACH_PROCESS: supports ev_detach_processDBG_HAS_REQUEST_PAUSE: supports ev_request_pauseDBG_HAS_SET_EXCEPTION_INFO: supports ev_set_exception_infoDBG_HAS_THREAD_SUSPEND: supports ev_thread_suspendDBG_HAS_THREAD_CONTINUE: supports ev_thread_continueDBG_HAS_SET_RESUME_MODE: supports ev_set_resume_mode. Cannot be set inside the debugger_t::init_debugger()DBG_HAS_THREAD_GET_SREG_BASE: supports ev_thread_get_sreg_baseDBG_HAS_CHECK_BPT: supports ev_check_bptDBG_HAS_OPEN_FILE: supports ev_open_file, ev_close_file, ev_read_file, ev_write_fileDBG_HAS_UPDATE_CALL_STACK: supports ev_update_call_stackDBG_HAS_APPCALL: supports ev_appcall, ev_cleanup_appcallDBG_HAS_REXEC: supports ev_rexecDBG_HAS_MAP_ADDRESS: supports ev_map_address. Avoid using this bit, especially together with DBG_FLAG_DEBTHREAD because it may cause big slow downsDBG_RESMOD_STEP_INTO: RESMOD_INTO is availableDBG_RESMOD_STEP_OVER: RESMOD_OVER is availableDBG_RESMOD_STEP_OUT: RESMOD_OUT is availableDBG_RESMOD_STEP_SRCINTO: RESMOD_SRCINTO is availableDBG_RESMOD_STEP_SRCOVER: RESMOD_SRCOVER is availableDBG_RESMOD_STEP_SRCOUT: RESMOD_SRCOUT is availableDBG_RESMOD_STEP_USER: RESMOD_USER is availableDBG_RESMOD_STEP_HANDLE: RESMOD_HANDLE is availableDBG_RESMOD_STEP_BACKINTO: RESMOD_BACKINTO is availableDBG_PROC_IS_DLL: database contains a dll (not exe)DBG_PROC_IS_GUI: using gui version of idaDBG_PROC_32BIT: application is 32-bitDBG_PROC_64BIT: application is 64-bitDBG_NO_TRACE: do not trace the application (mac/linux)DBG_HIDE_WINDOW: application should be hidden on startup (windows)DBG_SUSPENDED: application should be suspended on startup (mac)DBG_NO_ASLR: disable ASLR (linux)BPT_OK: breakpoint can be setBPT_INTERNAL_ERR: interr occurred when verifying breakpointBPT_BAD_TYPE: bpt type is not supportedBPT_BAD_ALIGN: alignment is invalidBPT_BAD_ADDR: ea is invalidBPT_BAD_LEN: bpt len is invalidBPT_TOO_MANY: reached max number of supported breakpointsBPT_READ_ERROR: failed to read memory at bpt eaBPT_WRITE_ERROR: failed to write memory at bpt eaBPT_SKIP: update_bpts(): do not process bptBPT_PAGE_OK: update_bpts(): ok, added a page bptAPPCALL_MANUAL: Only set up the appcall, do not run. debugger_t::cleanup_appcall will not be generated by ida!APPCALL_DEBEV: Return debug event information.APPCALL_TIMEOUT: Appcall with timeout. If timed out, errbuf will contain "timeout". See SET_APPCALL_TIMEOUT and GET_APPCALL_TIMEOUTRQ_MASKING: masking step handler: unless errors, tmpbpt handlers won't be generated should be used only with request_internal_step()RQ_SUSPEND: suspending step handler: suspends the app handle_debug_event: suspends the appRQ_NOSUSP: running step handler: continues the appRQ_IGNWERR: ignore breakpoint write failuresRQ_SILENT: all: no dialog boxesRQ_VERBOSE: all: display dialog boxesRQ_SWSCREEN: handle_debug_event: switch screensRQ__NOTHRRF: handle_debug_event: do not refresh threadsRQ_PROCEXIT: snapshots: the process is exitingRQ_IDAIDLE: handle_debug_event: ida is idleRQ_SUSPRUN: handle_debug_event: suspend at PROCESS_STARTEDRQ_RESUME: handle_debug_event: resume applicationRQ_RESMOD: resume_mode_tRQ_RESMOD_SHIFTNO_PROCESS: No process.NO_THREAD: No thread. in PROCESS_STARTED this value can be used to specify that the main thread has not been created. It will be initialized later by a THREAD_STARTED event.dbg_can_queryAppcall
Classes Overview
excvec_tprocinfo_vec_tcall_stack_info_vec_tmeminfo_vec_template_tregvals_tprocess_info_tdebapp_attrs_tregister_info_tmemory_info_tmeminfo_vec_tscattered_segm_tlaunch_env_tmodinfo_tbptaddr_texcinfo_tdebug_event_texception_info_tregval_tcall_stack_info_tcall_stack_tthread_name_tdebugger_tdyn_register_info_arrayAppcall_array__: This class is used with Appcall.array() methodAppcall_callable__: Helper class to issue appcalls using a natural syntax:Appcall_consts__: Helper class used by Appcall.Consts attributeAppcall__
Functions Overview
set_debug_event_code(ev: debug_event_t, id: event_id_t) -> Noneget_debug_event_name(dev: debug_event_t) -> str: get debug event namedbg_appcall(retval: idc_value_t *, func_ea: ida_idaapi.ea_t, tid: thid_t, ptif: tinfo_t, argv: idc_value_t *, argnum: size_t) -> error_t: Call a function from the debugged application.cleanup_appcall(tid: thid_t) -> error_t: Cleanup after manual appcall.cpu2ieee(ieee_out: fpvalue_t *, cpu_fpval: void const *, size: int) -> int: Convert a floating point number in CPU native format to IDA's internal format.ieee2cpu(cpu_fpval_out: void *, ieee: fpvalue_t const &, size: int) -> int: Convert a floating point number in IDA's internal format to CPU native format.get_dbg() -> debugger_t *dbg_get_registers(): This function returns the register definition from the currently loaded debugger.dbg_get_thread_sreg_base(tid, sreg_value): Returns the segment register base valuedbg_read_memory(ea, sz): Reads from the debugee's memory at the specified eadbg_write_memory(ea, buffer): Writes a buffer to the debugee's memorydbg_get_name(): This function returns the current debugger's name.dbg_get_memory_info(): This function returns the memory configuration of a debugged process.appcall(func_ea: ida_idaapi.ea_t, tid: thid_t, _type_or_none: bytevec_t const &, _fields: bytevec_t const &, arg_list: PyObject *) -> PyObject *get_event_module_name(ev: debug_event_t) -> strget_event_module_base(ev: debug_event_t) -> ida_idaapi.ea_tget_event_module_size(ev: debug_event_t) -> asize_tget_event_exc_info(ev: debug_event_t) -> strget_event_info(ev: debug_event_t) -> strget_event_bpt_hea(ev: debug_event_t) -> ida_idaapi.ea_tget_event_exc_code(ev: debug_event_t) -> uintget_event_exc_ea(ev: debug_event_t) -> ida_idaapi.ea_tcan_exc_continue(ev: debug_event_t) -> bool