ida_dbg
Contains functions to control the debugging of a process.
See Debugger functions for a complete explanation of these functions. These functions are inlined for the kernel. They are not inlined for the user-interfaces.
Constants
dbg_nulldbg_process_startdbg_process_exitdbg_process_attachdbg_process_detachdbg_thread_startdbg_thread_exitdbg_library_loaddbg_library_unloaddbg_informationdbg_exceptiondbg_suspend_process: The process is now suspended.dbg_bpt: A user defined breakpoint was reached.dbg_trace: A step occurred (one instruction was executed). This event notification is only generated if step tracing is enabled.dbg_request_error: An error occurred during the processing of a request.dbg_step_intodbg_step_overdbg_run_todbg_step_until_retdbg_bpt_changed: Breakpoint has been changed.dbg_started_loading_bpts: Started loading breakpoint info from idb.dbg_finished_loading_bpts: Finished loading breakpoint info from idb.dbg_last: The last debugger notification code.BPTEV_ADDED: Breakpoint has been added.BPTEV_REMOVED: Breakpoint has been removed.BPTEV_CHANGED: Breakpoint has been modified.DSTATE_SUSP: process is suspended and will not continueDSTATE_NOTASK: no process is currently debuggedDSTATE_RUN: process is runningDBGINV_MEMORY: invalidate cached memory contentsDBGINV_MEMCFG: invalidate cached process segmentationDBGINV_REGS: invalidate cached register valuesDBGINV_ALL: invalidate everythingDBGINV_REDRAW: refresh the screenDBGINV_NONE: invalidate nothingMOVBPT_OK: moved okMOVBPT_NOT_FOUND: source bpt not foundMOVBPT_DEST_BUSY: destination location is busy (we already have such a bpt)MOVBPT_BAD_TYPE: BPLT_ABS is not supported.BPLT_ABS: absolute address: eaBPLT_REL: relative address: module_path, offsetBPLT_SYM: symbolic: symbol_name, offsetBPLT_SRC: source level: filename, linenoBPT_BRK: suspend execution upon hitBPT_TRACE: add trace information upon hitBPT_UPDMEM: refresh the memory layout and contents before evaluating bpt conditionBPT_ENABLED: enabled?BPT_LOWCND: condition is calculated at low level (on the server side)BPT_TRACEON: enable tracing when the breakpoint is reachedBPT_TRACE_INSN: instruction tracingBPT_TRACE_FUNC: function tracingBPT_TRACE_BBLK: basic block tracingBPT_TRACE_TYPES: trace insns, functions, and basic blocks. if any of BPT_TRACE_TYPES bits are set but BPT_TRACEON is clear, then turn off tracing for the specified trace typesBPT_ELANG_MASKBPT_ELANG_SHIFT: index of the extlang (scripting language) of the conditionBKPT_BADBPT: failed to write the bpt to the process memory (at least one location)BKPT_LISTBPT: include in bpt list (user-defined bpt)BKPT_TRACE: trace bpt; should not be deleted when the process gets suspendedBKPT_ACTIVE: active?BKPT_PARTIAL: partially active? (some locations were not written yet)BKPT_CNDREADY: condition has been compiledBKPT_FAKEPEND: fake pending bpt: it is inactive but another bpt of the same type is active at the same address(es)BKPT_PAGE: written to the process as a page bpt. Available only after writing the bpt to the process.BPTCK_NONE: breakpoint does not existBPTCK_NO: breakpoint is disabledBPTCK_YES: breakpoint is enabledBPTCK_ACT: breakpoint is active (written to the process)ST_OVER_DEBUG_SEG: step tracing will be disabled when IP is in a debugger segmentST_OVER_LIB_FUNC: step tracing will be disabled when IP is in a library functionST_ALREADY_LOGGED: step tracing will be disabled when IP is already loggedST_SKIP_LOOPS: step tracing will try to skip loops already recordedST_DIFFERENTIAL: tracing: log only new instructions (not previously logged)ST_OPTIONS_MASK: mask of available options, to ensure compatibility with newer IDA versionsST_OPTIONS_DEFAULTIT_LOG_SAME_IP: specific options for instruction tracing (see set_insn_trace_options())FT_LOG_RET: specific options for function tracing (see set_func_trace_options())BT_LOG_INSTS: specific options for basic block tracing (see set_bblk_trace_options())tev_none: no eventtev_insn: an instruction tracetev_call: a function call tracetev_ret: a function return tracetev_bpt: write, read/write, execution tracetev_mem: memory layout changedtev_event: debug event occurredtev_max: first unused event typeSAVE_ALL_VALUESSAVE_DIFFSAVE_NONEDEC_NOTASK: process does not existDEC_ERROR: errorDEC_TIMEOUT: timeoutWFNE_ANY: return the first event (even if it doesn't suspend the process)WFNE_SUSP: wait until the process gets suspendedWFNE_SILENT: 1: be silent, 0:display modal boxes if necessaryWFNE_CONT: continue from the suspended stateWFNE_NOWAIT: do not wait for any event, immediately return DEC_TIMEOUT (to be used with WFNE_CONT)WFNE_USEC: timeout is specified in microseconds (minimum non-zero timeout is 40000us)DOPT_SEGM_MSGS: log debugger segments modificationsDOPT_START_BPT: break on process startDOPT_THREAD_MSGS: log thread starts/exitsDOPT_THREAD_BPT: break on thread start/exitDOPT_BPT_MSGS: log breakpointsDOPT_LIB_MSGS: log library loads/unloadsDOPT_LIB_BPT: break on library load/unloadDOPT_INFO_MSGS: log debugging info eventsDOPT_INFO_BPT: break on debugging informationDOPT_REAL_MEMORY: do not hide breakpoint instructionsDOPT_REDO_STACK: reconstruct the stackDOPT_ENTRY_BPT: break on program entry pointDOPT_EXCDLG: exception dialogs:EXCDLG_NEVER: never display exception dialogsEXCDLG_UNKNOWN: display for unknown exceptionsEXCDLG_ALWAYS: always displayDOPT_LOAD_DINFO: automatically load debug files (pdb)DOPT_END_BPT: evaluate event condition on process endDOPT_TEMP_HWBPT: when possible use hardware bpts for temp bptsDOPT_FAST_STEP: prevent debugger memory refreshes when single-steppingDOPT_DISABLE_ASLR: disable ASLRSRCIT_NONE: unknownSRCIT_MODULE: moduleSRCIT_FUNC: functionSRCIT_STMT: a statement (if/while/for...)SRCIT_EXPR: an expression (a+b*c)SRCIT_STTVAR: static variable/codeSRCIT_LOCVAR: a stack, register, or register-relative local variable or parameterSRCDBG_PROV_VERSIONmove_bpt_to_grp
Classes Overview
bpt_vec_ttev_reg_values_ttevinforeg_vec_tmemreg_infos_tbptaddrs_tbpt_location_tbpt_ttev_info_tmemreg_info_ttev_reg_value_ttev_info_reg_teval_ctx_tDBG_Hooks
Functions Overview
run_to(*args) -> bool: Execute the process until the given address is reached. If no process is active, a new process is started. Technically, the debugger sets up a temporary breakpoint at the given address, and continues (or starts) the execution of the whole process. So, all threads continue their execution! sq{Type, Asynchronous function - available as Request, Notification, dbg_run_to}request_run_to(*args) -> bool: Post a run_to() request.run_requests() -> bool: Execute requests until all requests are processed or an asynchronous function is called. sq{Type, Synchronous function, Notification, none (synchronous function)}get_running_request() -> ui_notification_t: Get the current running request. sq{Type, Synchronous function, Notification, none (synchronous function)}is_request_running() -> bool: Is a request currently running?get_running_notification() -> dbg_notification_t: Get the notification associated (if any) with the current running request. sq{Type, Synchronous function, Notification, none (synchronous function)}clear_requests_queue() -> None: Clear the queue of waiting requests. sq{Type, Synchronous function, Notification, none (synchronous function)}get_process_state() -> int: Return the state of the currently debugged process. sq{Type, Synchronous function, Notification, none (synchronous function)}is_valid_dstate(state: int) -> boolset_process_state(newstate: int, p_thid: thid_t *, dbginv: int) -> int: Set new state for the debugged process. Notifies the IDA kernel about the change of the debugged process state. For example, a debugger module could call this function when it knows that the process is suspended for a short period of time. Some IDA API calls can be made only when the process is suspended. The process state is usually restored before returning control to the caller. You must know that it is ok to change the process state, doing it at arbitrary moments may crash the application or IDA. sq{Type, Synchronous function, Notification, none (synchronous function)}invalidate_dbg_state(dbginv: int) -> int: Invalidate cached debugger information. sq{Type, Synchronous function, Notification, none (synchronous function)}start_process(path: str = None, args: str = None, sdir: str = None) -> int: Start a process in the debugger. sq{Type, Asynchronous function - available as Request, Notification, dbg_process_start}request_start_process(path: str = None, args: str = None, sdir: str = None) -> int: Post a start_process() request.suspend_process() -> bool: Suspend the process in the debugger. sq{ Type,request_suspend_process() -> bool: Post a suspend_process() request.continue_process() -> bool: Continue the execution of the process in the debugger. sq{Type, Synchronous function - available as Request, Notification, none (synchronous function)}request_continue_process() -> bool: Post a continue_process() request.continue_backwards() -> bool: Continue the execution of the process in the debugger backwards. Can only be used with debuggers that support time-travel debugging. sq{Type, Synchronous function - available as Request, Notification, none (synchronous function)}request_continue_backwards() -> bool: Post a continue_backwards() request.exit_process() -> bool: Terminate the debugging of the current process. sq{Type, Asynchronous function - available as Request, Notification, dbg_process_exit}request_exit_process() -> bool: Post an exit_process() request.get_processes(proclist: procinfo_vec_t) -> ssize_t: Take a snapshot of running processes and return their description. sq{Type, Synchronous function, Notification, none (synchronous function)}attach_process(*args) -> int: Attach the debugger to a running process. sq{Type, Asynchronous function - available as Request, Notification, dbg_process_attach}request_attach_process(pid: pid_t, event_id: int) -> int: Post an attach_process() request.detach_process() -> bool: Detach the debugger from the debugged process. sq{Type, Asynchronous function - available as Request, Notification, dbg_process_detach}request_detach_process() -> bool: Post a detach_process() request.is_debugger_busy() -> bool: Is the debugger busy?. Some debuggers do not accept any commands while the debugged application is running. For such a debugger, it is unsafe to do anything with the database (even simple queries like get_byte may lead to undesired consequences). Returns: true if the debugged application is running under such a debuggerget_thread_qty() -> int: Get number of threads. sq{Type, Synchronous function, Notification, none (synchronous function)}getn_thread(n: int) -> thid_t: Get the ID of a thread. sq{Type, Synchronous function, Notification, none (synchronous function)}get_current_thread() -> thid_t: Get current thread ID. sq{Type, Synchronous function, Notification, none (synchronous function)}getn_thread_name(n: int) -> str: Get the NAME of a thread sq{Type, Synchronous function, Notification, none (synchronous function)}select_thread(tid: thid_t) -> bool: Select the given thread as the current debugged thread. All thread related execution functions will work on this thread. The process must be suspended to select a new thread. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_select_thread(tid: thid_t) -> bool: Post a select_thread() request.suspend_thread(tid: thid_t) -> int: Suspend thread. Suspending a thread may deadlock the whole application if the suspended was owning some synchronization objects. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_suspend_thread(tid: thid_t) -> int: Post a suspend_thread() request.resume_thread(tid: thid_t) -> int: Resume thread. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_resume_thread(tid: thid_t) -> int: Post a resume_thread() request.get_first_module(modinfo: modinfo_t) -> boolget_next_module(modinfo: modinfo_t) -> boolstep_into() -> bool: Execute one instruction in the current thread. Other threads are kept suspended. sq{Type, Asynchronous function - available as Request, Notification, dbg_step_into}request_step_into() -> bool: Post a step_into() request.step_over() -> bool: Execute one instruction in the current thread, but without entering into functions. Others threads keep suspended. sq{Type, Asynchronous function - available as Request, Notification, dbg_step_over}request_step_over() -> bool: Post a step_over() request.step_into_backwards() -> bool: Execute one instruction backwards in the current thread. Other threads are kept suspended. sq{Type, Asynchronous function - available as Request, Notification, dbg_step_into}request_step_into_backwards() -> bool: Post a step_into_backwards() request.step_over_backwards() -> bool: Execute one instruction backwards in the current thread, but without entering into functions. Other threads are kept suspended. sq{Type, Asynchronous function - available as Request, Notification, dbg_step_over}request_step_over_backwards() -> bool: Post a step_over_backwards() request.run_to_backwards(*args) -> bool: Execute the process backwards until the given address is reached. Technically, the debugger sets up a temporary breakpoint at the given address, and continues (or starts) the execution of the whole process. sq{Type, Asynchronous function - available as Request, Notification, dbg_run_to}request_run_to_backwards(*args) -> bool: Post a run_to_backwards() request.step_until_ret() -> bool: Execute instructions in the current thread until a function return instruction is executed (aka "step out"). Other threads are kept suspended. sq{Type, Asynchronous function - available as Request, Notification, dbg_step_until_ret}request_step_until_ret() -> bool: Post a step_until_ret() request.set_resume_mode(tid: thid_t, mode: resume_mode_t) -> bool: How to resume the application. Set resume mode but do not resume process.request_set_resume_mode(tid: thid_t, mode: resume_mode_t) -> bool: Post a set_resume_mode() request.get_dbg_reg_info(regname: str, ri: register_info_t) -> bool: Get register information sq{Type, Synchronous function, Notification, none (synchronous function)}get_sp_val() -> uint64 *: Get value of the SP register for the current thread. Requires a suspended debugger.get_ip_val() -> uint64 *: Get value of the IP (program counter) register for the current thread. Requires a suspended debugger.is_reg_integer(regname: str) -> bool: Does a register contain an integer value? sq{Type, Synchronous function, Notification, none (synchronous function)}is_reg_float(regname: str) -> bool: Does a register contain a floating point value? sq{Type, Synchronous function, Notification, none (synchronous function)}is_reg_custom(regname: str) -> bool: Does a register contain a value of a custom data type? sq{Type, Synchronous function, Notification, none (synchronous function)}set_bptloc_string(s: str) -> intget_bptloc_string(i: int) -> strget_bpt_qty() -> int: Get number of breakpoints. sq{Type, Synchronous function, Notification, none (synchronous function)}getn_bpt(n: int, bpt: bpt_t) -> bool: Get the characteristics of a breakpoint. sq{Type, Synchronous function, Notification, none (synchronous function)}get_bpt(ea: ida_idaapi.ea_t, bpt: bpt_t) -> bool: Get the characteristics of a breakpoint. sq{Type, Synchronous function, Notification, none (synchronous function)}exist_bpt(ea: ida_idaapi.ea_t) -> bool: Does a breakpoint exist at the given location?add_bpt(*args) -> bool: This function has the following signatures:request_add_bpt(*args) -> bool: This function has the following signatures:del_bpt(*args) -> bool: This function has the following signatures:request_del_bpt(*args) -> bool: This function has the following signatures:update_bpt(bpt: bpt_t) -> bool: Update modifiable characteristics of an existing breakpoint. To update the breakpoint location, use change_bptlocs() sq{Type, Synchronous function, Notification, none (synchronous function)}find_bpt(bptloc: bpt_location_t, bpt: bpt_t) -> bool: Find a breakpoint by location. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}enable_bpt(*args) -> booldisable_bpt(*args) -> boolrequest_enable_bpt(*args) -> boolrequest_disable_bpt(*args) -> boolcheck_bpt(ea: ida_idaapi.ea_t) -> int: Check the breakpoint at the specified address.set_trace_size(size: int) -> bool: Specify the new size of the circular buffer. sq{Type, Synchronous function, Notification, none (synchronous function)}clear_trace() -> None: Clear all events in the trace buffer. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_clear_trace() -> None: Post a clear_trace() request.is_step_trace_enabled() -> bool: Get current state of step tracing. sq{Type, Synchronous function, Notification, none (synchronous function)}enable_step_trace(enable: int = 1) -> booldisable_step_trace() -> boolrequest_enable_step_trace(enable: int = 1) -> boolrequest_disable_step_trace() -> boolget_step_trace_options() -> int: Get current step tracing options. sq{Type, Synchronous function, Notification, none (synchronous function)}set_step_trace_options(options: int) -> None: Modify step tracing options. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_set_step_trace_options(options: int) -> None: Post a set_step_trace_options() request.is_insn_trace_enabled() -> bool: Get current state of instruction tracing. sq{Type, Synchronous function, Notification, none (synchronous function)}enable_insn_trace(enable: bool = True) -> booldisable_insn_trace() -> boolrequest_enable_insn_trace(enable: bool = True) -> boolrequest_disable_insn_trace() -> boolget_insn_trace_options() -> int: Get current instruction tracing options. Also see IT_LOG_SAME_IP sq{Type, Synchronous function, Notification, none (synchronous function)}set_insn_trace_options(options: int) -> None: Modify instruction tracing options. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_set_insn_trace_options(options: int) -> None: Post a set_insn_trace_options() request.is_func_trace_enabled() -> bool: Get current state of functions tracing. sq{Type, Synchronous function, Notification, none (synchronous function)}enable_func_trace(enable: bool = True) -> booldisable_func_trace() -> boolrequest_enable_func_trace(enable: bool = True) -> boolrequest_disable_func_trace() -> boolget_func_trace_options() -> int: Get current function tracing options. Also see FT_LOG_RET sq{Type, Synchronous function, Notification, none (synchronous function)}set_func_trace_options(options: int) -> None: Modify function tracing options. sq{Type, Synchronous function - available as request, Notification, none (synchronous function)}request_set_func_trace_options(options: int) -> None: Post a set_func_trace_options() request.enable_bblk_trace(enable: bool = True) -> booldisable_bblk_trace() -> boolrequest_enable_bblk_trace(enable: bool = True) -> boolrequest_disable_bblk_trace() -> boolis_bblk_trace_enabled() -> boolget_bblk_trace_options() -> int: Get current basic block tracing options. Also see BT_LOG_INSTS sq{Type, Synchronous function, Notification, none (synchronous function)}set_bblk_trace_options(options: int) -> None: Modify basic block tracing options (see BT_LOG_INSTS)request_set_bblk_trace_options(options: int) -> None: Post a set_bblk_trace_options() request.get_tev_qty() -> int: Get number of trace events available in trace buffer. sq{Type, Synchronous function, Notification, none (synchronous function)}get_tev_info(n: int, tev_info: tev_info_t) -> bool: Get main information about a trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_insn_tev_reg_val(n: int, regname: str, regval: regval_t) -> bool: Read a register value from an instruction trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_insn_tev_reg_mem(n: int, memmap: memreg_infos_t) -> bool: Read the memory pointed by register values from an instruction trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_insn_tev_reg_result(n: int, regname: str, regval: regval_t) -> bool: Read the resulting register value from an instruction trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_call_tev_callee(n: int) -> ida_idaapi.ea_t: Get the called function from a function call trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_ret_tev_return(n: int) -> ida_idaapi.ea_t: Get the return address from a function return trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_bpt_tev_ea(n: int) -> ida_idaapi.ea_t: Get the address associated to a read, read/write or execution trace event. sq{Type, Synchronous function, Notification, none (synchronous function)}get_tev_memory_info(n: int, mi: meminfo_vec_t) -> bool: Get the memory layout, if any, for the specified tev object. sq{Type, Synchronous function, Notification, none (synchronous function)}get_tev_event(n: int, d: debug_event_t) -> bool: Get the corresponding debug event, if any, for the specified tev object. sq{Type, Synchronous function, Notification, none (synchronous function)}get_trace_base_address() -> ida_idaapi.ea_t: Get the base address of the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}set_trace_base_address(ea: ida_idaapi.ea_t) -> None: Set the base address of the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_thread(tid: thid_t) -> None: Add a thread to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_del_thread(tid: thid_t) -> None: Delete a thread from the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_tev(type: tev_type_t, tid: thid_t, address: ida_idaapi.ea_t) -> None: Add a new trace element to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_many_tevs(new_tevs: tevinforeg_vec_t) -> bool: Add many new trace elements to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_insn_tev(tid: thid_t, ea: ida_idaapi.ea_t, save: save_reg_values_t = SAVE_DIFF) -> bool: Add a new instruction trace element to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_bpt_tev(tid: thid_t, ea: ida_idaapi.ea_t, bp: ida_idaapi.ea_t) -> bool: Add a new breakpoint trace element to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_call_tev(tid: thid_t, caller: ida_idaapi.ea_t, callee: ida_idaapi.ea_t) -> None: Add a new call trace element to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_ret_tev(tid: thid_t, ret_insn: ida_idaapi.ea_t, return_to: ida_idaapi.ea_t) -> None: Add a new return trace element to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}dbg_add_debug_event(event: debug_event_t) -> None: Add a new debug event to the current trace. sq{Type, Synchronous function, Notification, none (synchronous function)}load_trace_file(filename: str) -> str: Load a recorded trace file in the 'Tracing' window. If the call succeeds and 'buf' is not null, the description of the trace stored in the binary trace file will be returned in 'buf'save_trace_file(filename: str, description: str) -> bool: Save the current trace in the specified file.is_valid_trace_file(filename: str) -> bool: Is the specified file a valid trace file for the current database?set_trace_file_desc(filename: str, description: str) -> bool: Change the description of the specified trace file.get_trace_file_desc(filename: str) -> str: Get the file header of the specified trace file.choose_trace_file() -> str: Show the choose trace dialog.diff_trace_file(NONNULL_filename: str) -> bool: Show difference between the current trace and the one from 'filename'.graph_trace() -> bool: Show the trace callgraph.set_highlight_trace_options(hilight: bool, color: bgcolor_t, diff: bgcolor_t) -> None: Set highlight trace parameters.set_trace_platform(platform: str) -> None: Set platform name of current trace.get_trace_platform() -> str: Get platform name of current trace.set_trace_dynamic_register_set(idaregs: dynamic_register_set_t &) -> None: Set dynamic register set of current trace.get_trace_dynamic_register_set(idaregs: dynamic_register_set_t *) -> None: Get dynamic register set of current trace.wait_for_next_event(wfne: int, timeout: int) -> dbg_event_code_t: Wait for the next event.get_debug_event() -> debug_event_t const *: Get the current debugger event.set_debugger_options(options: uint) -> uint: Set debugger options. Replaces debugger options with the specification combination Debugger optionsset_remote_debugger(host: str, _pass: str, port: int = -1) -> None: Set remote debugging options. Should be used before starting the debugger.get_process_options2() -> qstring *, qstring *, launch_env_t *, qstring *, qstring *, qstring *, int *retrieve_exceptions() -> excvec_t *: Retrieve the exception information. You may freely modify the returned vector and add/edit/delete exceptions You must call store_exceptions() after any modifications Note: exceptions with code zero, multiple exception codes or names are prohibitedstore_exceptions() -> bool: Update the exception information stored in the debugger module by invoking its dbg->set_exception_info callbackdefine_exception(code: uint, name: str, desc: str, flags: int) -> str: Convenience function: define new exception code.create_source_viewer(out_ccv: TWidget **, parent: TWidget *, custview: TWidget *, sf: source_file_ptr, lines: strvec_t *, lnnum: int, colnum: int, flags: int) -> source_view_t *: Create a source code view.get_dbg_byte(ea: ida_idaapi.ea_t) -> uint32 *: Get one byte of the debugged process memory.put_dbg_byte(ea: ida_idaapi.ea_t, x: int) -> bool: Change one byte of the debugged process memory.invalidate_dbgmem_config() -> None: Invalidate the debugged process memory configuration. Call this function if the debugged process might have changed its memory layout (allocated more memory, for example)invalidate_dbgmem_contents(ea: ida_idaapi.ea_t, size: asize_t) -> None: Invalidate the debugged process memory contents. Call this function each time the process has been stopped or the process memory is modified. If ea == BADADDR, then the whole memory contents will be invalidatedis_debugger_on() -> bool: Is the debugger currently running?is_debugger_memory(ea: ida_idaapi.ea_t) -> bool: Is the address mapped to debugger memory?get_tev_ea(n: int) -> ida_idaapi.ea_tget_tev_type(n: int) -> intget_tev_tid(n: int) -> intbring_debugger_to_front() -> Noneset_manual_regions(ranges: meminfo_vec_t) -> Noneedit_manual_regions() -> Noneenable_manual_regions(enable: bool) -> Nonehandle_debug_event(ev: debug_event_t, rqflags: int) -> intadd_virt_module(mod: modinfo_t) -> booldel_virt_module(base: ea_t const) -> boolinternal_ioctl(fn: int, buf: void const *, poutbuf: void **, poutsize: ssize_t *) -> intget_dbg_memory_info(ranges: meminfo_vec_t) -> intset_bpt_group(bpt: bpt_t, grp_name: str) -> bool: Move a bpt into a folder in the breakpoint dirtree if the folder didn't exists, it will be created sq{Type, Synchronous function, Notification, none (synchronous function)}set_bptloc_group(bptloc: bpt_location_t, grp_name: str) -> bool: Move a bpt into a folder in the breakpoint dirtree based on the bpt_location find_bpt is called to retrieve the bpt and then set_bpt_group if the folder didn't exists, it will be created sq{Type, Synchronous function, Notification, none (synchronous function)}get_bpt_group(bptloc: bpt_location_t) -> str: Retrieve the absolute path to the folder of the bpt based on the bpt_location find_bpt is called to retrieve the bpt sq{Type, Synchronous function, Notification, none (synchronous function)}rename_bptgrp(old_name: str, new_name: str) -> bool: Rename a folder of bpt dirtree sq{Type, Synchronous function, Notification, none (synchronous function)}del_bptgrp(name: str) -> bool: Delete a folder, bpt that were part of this folder are moved to the root folder sq{Type, Synchronous function, Notification, none (synchronous function)}get_grp_bpts(bpts: bpt_vec_t, grp_name: str) -> ssize_t: Retrieve a copy the bpts stored in a folder sq{Type, Synchronous function, Notification, none (synchronous function)}enable_bptgrp(bptgrp_name: str, enable: bool = True) -> int: Enable (or disable) all bpts in a folder sq{Type, Synchronous function, Notification, none (synchronous function)}get_local_vars(prov: srcinfo_provider_t *, ea: ida_idaapi.ea_t, out: source_items_t *) -> boolsrcdbg_request_step_into() -> boolsrcdbg_request_step_over() -> boolsrcdbg_request_step_until_ret() -> boolhide_all_bpts() -> intread_dbg_memory(ea: ida_idaapi.ea_t, buffer: void *, size: size_t) -> ssize_tget_module_info(ea: ida_idaapi.ea_t, modinfo: modinfo_t) -> booldbg_bin_search(start_ea: ida_idaapi.ea_t, end_ea: ida_idaapi.ea_t, data: compiled_binpat_vec_t const &, srch_flags: int) -> strload_debugger(dbgname: str, use_remote: bool) -> boolcollect_stack_trace(tid: thid_t, trace: call_stack_t) -> boolget_global_var(prov: srcinfo_provider_t *, ea: ida_idaapi.ea_t, name: str, out: source_item_ptr *) -> boolget_local_var(prov: srcinfo_provider_t *, ea: ida_idaapi.ea_t, name: str, out: source_item_ptr *) -> boolget_srcinfo_provider(name: str) -> srcinfo_provider_t *get_current_source_file() -> strget_current_source_line() -> intadd_path_mapping(src: str, dst: str) -> Nonesrcdbg_step_into() -> boolsrcdbg_step_over() -> boolsrcdbg_step_until_ret() -> boolset_debugger_event_cond(NONNULL_evcond: str) -> Noneget_debugger_event_cond() -> strset_process_options(*args) -> None: Set process options. Any of the arguments may be nullptr, which means 'do not modify'get_process_options() -> qstring *, qstring *, qstring *, qstring *, qstring *, int *: Get process options. Any of the arguments may be nullptrget_manual_regions(*args): Returns the manual memory regionsdbg_is_loaded(): Checks if a debugger is loadedrefresh_debugger_memory(): Refreshes the debugger memorylist_bptgrps() -> List[str]: Retrieve the list of absolute path of all folders of bpt dirtree.internal_get_sreg_base(tid: int, sreg_value: int): Get the sreg base, for the given thread.write_dbg_memory(*args) -> ssize_tdbg_can_query(): This function can be used to check if the debugger can be queried:set_reg_val(*args) -> bool: Set a register value by namerequest_set_reg_val(regname: str, o: PyObject *) -> PyObject *: Post a set_reg_val() request.get_reg_val(*args): Get a register value.get_reg_vals(tid: int, clsmask: int = -1) -> ida_idd.regvals_t: Fetch live registers values for the threadget_tev_reg_val(tev, reg)get_tev_reg_mem_qty(tev)get_tev_reg_mem(tev, idx)get_tev_reg_mem_ea(tev, idx)send_dbg_command(command): Send a direct command to the debugger backend, and