offset_sig
Overview
offset_sig is the relocation signature used to recover struct-member offsets across versions.
Field Context
- Related YAML fields:
struct_name,member_name,offset,size,offset_sig(optionaloffset_sig_disp).
Generation Principle
- In this repository, authoring usually follows the struct-offset signature workflow (
.claude/skills/generate-signature-for-structoffset/SKILL.md). - Signature is built near an instruction that encodes/uses the target member offset.
- Volatile bytes are wildcarded (
??) to improve cross-version robustness. - Observed outputs generally use forward anchoring (signature starts at target instruction,
offset_sig_dispomitted/0). - Acceptance goal: unique matching plus reliable offset re-derivation.
Usage Method
- In
preprocess_struct_offset_sig_via_mcp, oldoffset_sigis reused to recover the newoffset. - Flow:
- Load
struct_name,member_name,offset_sig, optionaloffset_sig_disp, optionalsize. - Unique-match
offset_sig->sig_addr. - Compute instruction address:
inst_addr = sig_addr + offset_sig_disp(default 0). - Decode instruction and inspect operand positions (
offb/offo) and candidate sizes. - Extract displacement/immediate candidates; prefer candidates matching old offset when available.
- Emit new YAML with updated
offset, carryingoffset_sigand optional metadata.
- Load
Practical Notes
- Multi-hit
offset_sigis rejected. - Non-zero
offset_sig_dispmeans signature starts before target instruction. offsetmay change across versions;offset_sigshould remain stable enough to re-derive it.- Weak signatures (too short/too wildcarded) reduce long-term reliability.