ida_auto
Functions that work with the autoanalyzer queue.
The autoanalyzer works when IDA is not busy processing the user keystrokes.
It has several queues, each queue having its own priority. The analyzer stops
when all queues are empty.
A queue contains addresses or address ranges. The addresses are kept sorted by
their values. The analyzer will process all addresses from the first queue,
then switch to the second queue and so on. There are no limitations on the
size of the queues.
This file also contains functions that deal with the IDA status indicator and
the autoanalysis indicator. You may use these functions to change the
indicator value.
Constants
cvar
AU_NONE: placeholder, not used
AU_UNK: 0: convert to unexplored
AU_CODE: 1: convert to instruction
AU_WEAK: 2: convert to instruction (ida decision)
AU_PROC: 3: convert to procedure start
AU_TAIL: 4: add a procedure tail
AU_FCHUNK: 5: find func chunks
AU_USED: 6: reanalyze
AU_USD2: 7: reanalyze, second pass
AU_TYPE: 8: apply type information
AU_LIBF: 9: apply signature to address
AU_LBF2: 10: the same, second pass
AU_LBF3: 11: the same, third pass
AU_CHLB: 12: load signature file (file name is kept separately)
AU_FINAL: 13: final pass
st_Ready: READY: IDA is doing nothing.
st_Think: THINKING: Autoanalysis on, the user may press keys.
st_Waiting: WAITING: Waiting for the user input.
st_Work: BUSY: IDA is busy.
Classes Overview
Functions Overview
get_auto_state() -> atype_t: Get current state of autoanalyzer. If auto_state == AU_NONE, IDA is currently not running the analysis (it could be temporarily interrupted to perform the user's requests, for example).
set_auto_state(new_state: atype_t) -> atype_t: Set current state of autoanalyzer.
get_auto_display(auto_display: auto_display_t) -> bool: Get structure which holds the autoanalysis indicator contents.
show_auto(*args) -> None: Change autoanalysis indicator value.
show_addr(ea: ida_idaapi.ea_t) -> None: Show an address on the autoanalysis indicator. The address is displayed in the form " @:12345678".
set_ida_state(st: idastate_t) -> idastate_t: Change IDA status indicator value
may_create_stkvars() -> bool: Is it allowed to create stack variables automatically?. This function should be used by IDP modules before creating stack vars.
may_trace_sp() -> bool: Is it allowed to trace stack pointer automatically?. This function should be used by IDP modules before tracing sp.
auto_mark_range(start: ida_idaapi.ea_t, end: ida_idaapi.ea_t, type: atype_t) -> None: Put range of addresses into a queue. 'start' may be higher than 'end', the kernel will swap them in this case. 'end' doesn't belong to the range.
auto_mark(ea: ida_idaapi.ea_t, type: atype_t) -> None: Put single address into a queue. Queues keep addresses sorted.
auto_unmark(start: ida_idaapi.ea_t, end: ida_idaapi.ea_t, type: atype_t) -> None: Remove range of addresses from a queue. 'start' may be higher than 'end', the kernel will swap them in this case. 'end' doesn't belong to the range.
plan_ea(ea: ida_idaapi.ea_t) -> None: Plan to perform reanalysis.
plan_range(sEA: ida_idaapi.ea_t, eEA: ida_idaapi.ea_t) -> None: Plan to perform reanalysis.
auto_make_code(ea: ida_idaapi.ea_t) -> None: Plan to make code.
auto_make_proc(ea: ida_idaapi.ea_t) -> None: Plan to make code&function.
auto_postpone_analysis(ea: ida_idaapi.ea_t) -> bool: Plan to reanalyze on the second pass The typical usage of this function in emu.cpp is: if ( !auto_postpone_analysis(ea) ) op_offset(ea, 0, ...); (we make an offset only on the second pass)
reanalyze_callers(ea: ida_idaapi.ea_t, noret: bool) -> None: Plan to reanalyze callers of the specified address. This function will add to AU_USED queue all instructions that call (not jump to) the specified address.
revert_ida_decisions(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> None: Delete all analysis info that IDA generated for for the given range.
auto_apply_type(caller: ida_idaapi.ea_t, callee: ida_idaapi.ea_t) -> None: Plan to apply the callee's type to the calling point.
auto_apply_tail(tail_ea: ida_idaapi.ea_t, parent_ea: ida_idaapi.ea_t) -> None: Plan to apply the tail_ea chunk to the parent
plan_and_wait(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t, final_pass: bool = True) -> int: Analyze the specified range. Try to create instructions where possible. Make the final pass over the specified range if specified. This function doesn't return until the range is analyzed.
auto_wait() -> bool: Process everything in the queues and return true.
auto_wait_range(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> ssize_t: Process everything in the specified range and return true.
auto_make_step(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> bool: Analyze one address in the specified range and return true.
auto_cancel(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> None: Remove an address range (ea1..ea2) from queues AU_CODE, AU_PROC, AU_USED. To remove an address range from other queues use auto_unmark() function. 'ea1' may be higher than 'ea2', the kernel will swap them in this case. 'ea2' doesn't belong to the range.
auto_is_ok() -> bool: Are all queues empty? (i.e. has autoanalysis finished?).
peek_auto_queue(low_ea: ida_idaapi.ea_t, type: atype_t) -> ida_idaapi.ea_t: Peek into a queue 'type' for an address not lower than 'low_ea'. Do not remove address from the queue.
auto_get(type: atype_t *, lowEA: ida_idaapi.ea_t, highEA: ida_idaapi.ea_t) -> ida_idaapi.ea_t: Retrieve an address from queues regarding their priority. Returns BADADDR if no addresses not lower than 'lowEA' and less than 'highEA' are found in the queues. Otherwise *type will have queue type.
auto_recreate_insn(ea: ida_idaapi.ea_t) -> int: Try to create instruction
is_auto_enabled() -> bool: Get autoanalyzer state.
enable_auto(enable: bool) -> bool: Temporarily enable/disable autoanalyzer. Not user-facing, but rather because IDA sometimes need to turn AA on/off regardless of inf.s_genflags:INFFL_AUTO
1---2name: classes-overview-143description: The autoanalyzer works when IDA is not busy processing the user keystrokes. It has several queues, each queue having its own priority. The analyzer stops when all queues are empty.4---5# ida_auto67Functions that work with the autoanalyzer queue.89The autoanalyzer works when IDA is not busy processing the user keystrokes.10It has several queues, each queue having its own priority. The analyzer stops11when all queues are empty.1213A queue contains addresses or address ranges. The addresses are kept sorted by14their values. The analyzer will process all addresses from the first queue,15then switch to the second queue and so on. There are no limitations on the16size of the queues.1718This file also contains functions that deal with the IDA status indicator and19the autoanalysis indicator. You may use these functions to change the20indicator value.2122## Constants2324- `cvar`25- `AU_NONE`: placeholder, not used26- `AU_UNK`: 0: convert to unexplored27- `AU_CODE`: 1: convert to instruction28- `AU_WEAK`: 2: convert to instruction (ida decision)29- `AU_PROC`: 3: convert to procedure start30- `AU_TAIL`: 4: add a procedure tail31- `AU_FCHUNK`: 5: find func chunks32- `AU_USED`: 6: reanalyze33- `AU_USD2`: 7: reanalyze, second pass34- `AU_TYPE`: 8: apply type information35- `AU_LIBF`: 9: apply signature to address36- `AU_LBF2`: 10: the same, second pass37- `AU_LBF3`: 11: the same, third pass38- `AU_CHLB`: 12: load signature file (file name is kept separately)39- `AU_FINAL`: 13: final pass40- `st_Ready`: READY: IDA is doing nothing.41- `st_Think`: THINKING: Autoanalysis on, the user may press keys.42- `st_Waiting`: WAITING: Waiting for the user input.43- `st_Work`: BUSY: IDA is busy.4445## Classes Overview4647- `auto_display_t`4849## Functions Overview5051- `get_auto_state() -> atype_t`: Get current state of autoanalyzer. If auto_state == AU_NONE, IDA is currently not running the analysis (it could be temporarily interrupted to perform the user's requests, for example).52- `set_auto_state(new_state: atype_t) -> atype_t`: Set current state of autoanalyzer.53- `get_auto_display(auto_display: auto_display_t) -> bool`: Get structure which holds the autoanalysis indicator contents.54- `show_auto(*args) -> None`: Change autoanalysis indicator value.55- `show_addr(ea: ida_idaapi.ea_t) -> None`: Show an address on the autoanalysis indicator. The address is displayed in the form " @:12345678".56- `set_ida_state(st: idastate_t) -> idastate_t`: Change IDA status indicator value57- `may_create_stkvars() -> bool`: Is it allowed to create stack variables automatically?. This function should be used by IDP modules before creating stack vars.58- `may_trace_sp() -> bool`: Is it allowed to trace stack pointer automatically?. This function should be used by IDP modules before tracing sp.59- `auto_mark_range(start: ida_idaapi.ea_t, end: ida_idaapi.ea_t, type: atype_t) -> None`: Put range of addresses into a queue. 'start' may be higher than 'end', the kernel will swap them in this case. 'end' doesn't belong to the range.60- `auto_mark(ea: ida_idaapi.ea_t, type: atype_t) -> None`: Put single address into a queue. Queues keep addresses sorted.61- `auto_unmark(start: ida_idaapi.ea_t, end: ida_idaapi.ea_t, type: atype_t) -> None`: Remove range of addresses from a queue. 'start' may be higher than 'end', the kernel will swap them in this case. 'end' doesn't belong to the range.62- `plan_ea(ea: ida_idaapi.ea_t) -> None`: Plan to perform reanalysis.63- `plan_range(sEA: ida_idaapi.ea_t, eEA: ida_idaapi.ea_t) -> None`: Plan to perform reanalysis.64- `auto_make_code(ea: ida_idaapi.ea_t) -> None`: Plan to make code.65- `auto_make_proc(ea: ida_idaapi.ea_t) -> None`: Plan to make code&function.66- `auto_postpone_analysis(ea: ida_idaapi.ea_t) -> bool`: Plan to reanalyze on the second pass The typical usage of this function in emu.cpp is: if ( !auto_postpone_analysis(ea) ) op_offset(ea, 0, ...); (we make an offset only on the second pass)67- `reanalyze_callers(ea: ida_idaapi.ea_t, noret: bool) -> None`: Plan to reanalyze callers of the specified address. This function will add to AU_USED queue all instructions that call (not jump to) the specified address.68- `revert_ida_decisions(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> None`: Delete all analysis info that IDA generated for for the given range.69- `auto_apply_type(caller: ida_idaapi.ea_t, callee: ida_idaapi.ea_t) -> None`: Plan to apply the callee's type to the calling point.70- `auto_apply_tail(tail_ea: ida_idaapi.ea_t, parent_ea: ida_idaapi.ea_t) -> None`: Plan to apply the tail_ea chunk to the parent71- `plan_and_wait(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t, final_pass: bool = True) -> int`: Analyze the specified range. Try to create instructions where possible. Make the final pass over the specified range if specified. This function doesn't return until the range is analyzed.72- `auto_wait() -> bool`: Process everything in the queues and return true.73- `auto_wait_range(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> ssize_t`: Process everything in the specified range and return true.74- `auto_make_step(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> bool`: Analyze one address in the specified range and return true.75- `auto_cancel(ea1: ida_idaapi.ea_t, ea2: ida_idaapi.ea_t) -> None`: Remove an address range (ea1..ea2) from queues AU_CODE, AU_PROC, AU_USED. To remove an address range from other queues use auto_unmark() function. 'ea1' may be higher than 'ea2', the kernel will swap them in this case. 'ea2' doesn't belong to the range.76- `auto_is_ok() -> bool`: Are all queues empty? (i.e. has autoanalysis finished?).77- `peek_auto_queue(low_ea: ida_idaapi.ea_t, type: atype_t) -> ida_idaapi.ea_t`: Peek into a queue 'type' for an address not lower than 'low_ea'. Do not remove address from the queue.78- `auto_get(type: atype_t *, lowEA: ida_idaapi.ea_t, highEA: ida_idaapi.ea_t) -> ida_idaapi.ea_t`: Retrieve an address from queues regarding their priority. Returns BADADDR if no addresses not lower than 'lowEA' and less than 'highEA' are found in the queues. Otherwise *type will have queue type.79- `auto_recreate_insn(ea: ida_idaapi.ea_t) -> int`: Try to create instruction80- `is_auto_enabled() -> bool`: Get autoanalyzer state.81- `enable_auto(enable: bool) -> bool`: Temporarily enable/disable autoanalyzer. Not user-facing, but rather because IDA sometimes need to turn AA on/off regardless of inf.s_genflags:INFFL_AUTO