idc
IDC compatibility module
This file contains IDA built-in function declarations and internal bit definitions. Each byte of the program has 32-bit flags (low 8 bits keep the byte value). These 32 bits are used in get_full_flags/get_flags functions.
This file is subject to change without any notice. Future versions of IDA may use other definitions.
Constants
WORDMASKBADADDRBADSELSIZE_MAXMS_VALFF_IVLMS_CLSFF_CODEFF_DATAFF_TAILFF_UNKMS_COMMFF_COMMFF_REFFF_LINEFF_NAMEFF_LABLFF_FLOWFF_ANYNAMEMS_0TYPEFF_0VOIDFF_0NUMHFF_0NUMDFF_0CHARFF_0SEGFF_0OFFFF_0NUMBFF_0NUMOFF_0ENUMFF_0FOPFF_0STROFF_0STKMS_1TYPEFF_1VOIDFF_1NUMHFF_1NUMDFF_1CHARFF_1SEGFF_1OFFFF_1NUMBFF_1NUMOFF_1ENUMFF_1FOPFF_1STROFF_1STKDT_TYPEFF_BYTEFF_WORDFF_DWORDFF_QWORDFF_TBYTEFF_STRLITFF_STRUCTFF_OWORDFF_FLOATFF_DOUBLEFF_PACKREALFF_ALIGNMS_CODEFF_FUNCFF_IMMDFF_JUMPNEF_SEGSNEF_RSCSNEF_NAMENEF_MANNEF_FILLNEF_IMPSNEF_FIRSTNEF_CODENEF_RELOADNEF_FLATIDCHK_OKIDCHK_ARGIDCHK_KEYIDCHK_MAXadd_idc_hotkeydel_idc_hotkeyjumptoauto_waitDBFL_BAKqexitload_and_run_pluginplan_to_apply_idasgncreate_insnSN_CHECKSN_NOCHECKSN_PUBLICSN_NON_PUBLICSN_WEAKSN_NON_WEAKSN_AUTOSN_NON_AUTOSN_NOLISTSN_NOWARNSN_LOCALset_cmtcreate_datacreate_custom_datacreate_aligndel_itemsDELIT_SIMPLEDELIT_EXPANDDELIT_DELNAMESAP_ALLOWDUPSAP_SIGNEDAP_INDEXAP_ARRAYAP_IDXBASEMASKAP_IDXDECAP_IDXHEXAP_IDXOCTAP_IDXBINop_binop_octop_decop_hexop_chrOPND_OUTERop_offsetREF_OFF8REF_OFF16REF_OFF32REF_LOW8REF_LOW16REF_HIGH8REF_HIGH16REF_OFF64REFINFO_RVAREFINFO_PASTENDREFINFO_NOBASEREFINFO_SUBTRACTREFINFO_SIGNEDOPop_segop_numop_fltop_mantoggle_signop_enumop_stkvarE_PREVE_NEXTget_extra_cmtupdate_extra_cmtdel_extra_cmtset_manual_insnget_manual_insnpatch_dbg_bytepatch_bytepatch_wordpatch_dwordpatch_qwordSR_inheritSR_userSR_autoSR_autostartauto_mark_rangeauto_unmarkAU_UNKAU_CODEAU_PROCAU_USEDAU_LIBFAU_FINALOFILE_MAPOFILE_EXEOFILE_IDCOFILE_LSTOFILE_ASMOFILE_DIFGENFLG_MAPSEGGENFLG_MAPNAMEGENFLG_MAPDMNGGENFLG_MAPLOCGENFLG_IDCTYPEGENFLG_ASMTYPEGENFLG_GENHTMLGENFLG_ASMINCCHART_PRINT_NAMESCHART_GEN_GDLCHART_WINGRAPHCHART_NOLIBFUNCSget_root_filenameget_input_file_pathset_root_filenameretrieve_input_file_md5get_full_flagsget_db_byteget_wide_byteread_dbg_memoryget_original_byteget_wide_wordget_wide_dwordget_qwordget_name_eaget_screen_eanext_addrprev_addrnext_not_tailprev_not_tailget_item_headget_item_endGN_VISIBLEGN_COLOREDGN_DEMANGLEDGN_STRICTGN_SHORTGN_LONGGN_LOCALGN_ISRETGN_NOT_ISRETcalc_gtn_flagsGENDSM_FORCE_CODEGENDSM_MULTI_LINEo_voido_rego_memo_phraseo_displo_immo_faro_nearo_idpspec0o_idpspec1o_idpspec2o_idpspec3o_idpspec4o_idpspec5o_trrego_dbrego_crrego_fprego_mmxrego_xmmrego_reglisto_creglisto_crego_fpreglisto_texto_condo_spro_twofpro_shmbmeo_crfo_crbo_dcrGetCommentExget_cmtget_forced_operandBPU_1BBPU_2BBPU_4BSTRWIDTH_1BSTRWIDTH_2BSTRWIDTH_4BSTRWIDTH_MASKSTRLYT_TERMCHRSTRLYT_PASCAL1STRLYT_PASCAL2STRLYT_PASCAL4STRLYT_MASKSTRLYT_SHIFTSTRTYPE_TERMCHRSTRTYPE_CSTRTYPE_C_16STRTYPE_C_32STRTYPE_PASCALSTRTYPE_PASCAL_16STRTYPE_LEN2STRTYPE_LEN2_16STRTYPE_LEN4STRTYPE_LEN4_16STRTYPE_C16find_suspopfind_codefind_datafind_unknownfind_definedfind_immfind_textfind_bytesINF_VERSIONINF_PROCNAMEINF_GENFLAGSINF_LFLAGSINF_DATABASE_CHANGE_COUNTINF_CHANGE_COUNTERINF_FILETYPEFT_EXE_OLDFT_COM_OLDFT_BINFT_DRVFT_WINFT_HEXFT_MEXFT_LXFT_LEFT_NLMFT_COFFFT_PEFT_OMFFT_SRECFT_ZIPFT_OMFLIBFT_ARFT_LOADERFT_ELFFT_W32RUNFT_AOUTFT_PRCFT_EXEFT_COMFT_AIXARFT_MACHOINF_OSTYPEOSTYPE_MSDOSOSTYPE_WINOSTYPE_OS2OSTYPE_NETWINF_APPTYPEAPPT_CONSOLEAPPT_GRAPHICAPPT_PROGRAMAPPT_LIBRARYAPPT_DRIVERAPPT_1THREADAPPT_MTHREADAPPT_16BITAPPT_32BITINF_ASMTYPEINF_SPECSEGSINF_AFINF_AF2INF_BASEADDRINF_START_SSINF_START_CSINF_START_IPINF_START_EAINF_START_SPINF_MAININF_MIN_EAINF_MAX_EAINF_OMIN_EAINF_OMAX_EAINF_LOWOFFINF_LOW_OFFINF_HIGHOFFINF_HIGH_OFFINF_MAXREFINF_PRIVRANGE_START_EAINF_START_PRIVRANGEINF_PRIVRANGE_END_EAINF_END_PRIVRANGEINF_NETDELTAINF_XREFNUMINF_TYPE_XREFNUMINF_TYPE_XREFSINF_REFCMTNUMINF_REFCMTSINF_XREFFLAGINF_XREFSINF_MAX_AUTONAME_LENINF_NAMETYPEINF_SHORT_DEMNAMESINF_SHORT_DNINF_LONG_DEMNAMESINF_LONG_DNINF_DEMNAMESINF_LISTNAMESINF_INDENTINF_CMT_INDENTINF_COMMENTINF_MARGININF_LENXREFINF_OUTFLAGSINF_CMTFLGINF_CMTFLAGINF_LIMITERINF_BORDERINF_BIN_PREFIX_SIZEINF_BINPREFINF_PREFFLAGINF_STRLIT_FLAGSINF_STRLIT_BREAKINF_STRLIT_ZEROESINF_STRTYPEINF_STRLIT_PREFINF_STRLIT_SERNUMINF_DATATYPESINF_CC_IDCOMP_MASKCOMP_UNKCOMP_MSCOMP_BCCOMP_WATCOMCOMP_GNUCOMP_VISAGECOMP_BPINF_CC_CMINF_CC_SIZE_IINF_CC_SIZE_BINF_CC_SIZE_EINF_CC_DEFALIGNINF_CC_SIZE_SINF_CC_SIZE_LINF_CC_SIZE_LLINF_CC_SIZE_LDBLINF_COMPILERINF_MODELINF_SIZEOF_INTINF_SIZEOF_BOOLINF_SIZEOF_ENUMINF_SIZEOF_ALGNINF_SIZEOF_SHORTINF_SIZEOF_LONGINF_SIZEOF_LLONGINF_SIZEOF_LDBLINF_ABIBITSINF_APPCALL_OPTIONSset_processor_typeSETPROC_IDBSETPROC_LOADERSETPROC_LOADER_NON_FATALSETPROC_USERset_target_assemblerask_segask_ynmsgwarningerrorset_ida_stateIDA_STATUS_READYIDA_STATUS_THINKINGIDA_STATUS_WAITINGIDA_STATUS_WORKrefresh_idaview_anywayrefresh_listsset_selectordel_selectorADDSEG_NOSREGADDSEG_OR_DIEADDSEG_NOTRUNCADDSEG_QUIETADDSEG_FILLGAPADDSEG_SPARSEdel_segmSEGMOD_KILLSEGMOD_KEEPSEGMOD_SILENTsaAbssaRelBytesaRelWordsaRelParasaRelPagesaRelDblesaRel4KsaGroupsaRel32BytessaRel64BytessaRelQwordscPrivscPubscPub2scStackscCommonscPub3SEG_NORMSEG_XTRNSEG_CODESEG_DATASEG_IMPSEG_GRPSEG_NULLSEG_UNDFSEG_BSSSEG_ABSSYMSEG_COMMSEG_IMEMSEGATTR_STARTSEGATTR_ENDSEGATTR_ORGBASESEGATTR_ALIGNSEGATTR_COMBSEGATTR_PERMSEGATTR_BITNESSSEGATTR_FLAGSSEGATTR_SELSEGATTR_ESSEGATTR_CSSEGATTR_SSSEGATTR_DSSEGATTR_FSSEGATTR_GSSEGATTR_TYPESEGATTR_COLORSEGATTR_STARTSFL_COMORGSFL_OBOKSFL_HIDDENSFL_DEBUGSFL_LOADERSFL_HIDETYPEMSF_SILENTMSF_NOFIXMSF_LDKEEPMSF_FIXONCEMOVE_SEGM_OKMOVE_SEGM_PARAMMOVE_SEGM_ROOMMOVE_SEGM_IDPMOVE_SEGM_CHUNKMOVE_SEGM_LOADERMOVE_SEGM_ODDMOVE_SEGM_ORPHANMOVE_SEGM_DEBUGMOVE_SEGM_SOURCEFILESMOVE_SEGM_MAPPINGMOVE_SEGM_INVALrebase_programset_storage_typeSTT_VASTT_MMfl_CFfl_CNfl_JFfl_JNfl_FXREF_USERadd_crefdel_crefget_first_cref_fromget_next_cref_fromget_first_cref_toget_next_cref_toget_first_fcref_fromget_next_fcref_fromget_first_fcref_toget_next_fcref_todr_Odr_Wdr_Rdr_Tdr_Iadd_drefdel_drefget_first_dref_fromget_next_dref_fromget_first_dref_toget_next_dref_toadd_funcdel_funcset_func_endFUNCATTR_STARTFUNCATTR_ENDFUNCATTR_FLAGSFUNCATTR_FRAMEFUNCATTR_FRSIZEFUNCATTR_FRREGSFUNCATTR_ARGSIZEFUNCATTR_FPDFUNCATTR_COLORFUNCATTR_OWNERFUNCATTR_REFQTYFUNCATTR_STARTFUNC_NORETFUNC_FARFUNC_LIBFUNC_STATICFUNC_FRAMEFUNC_USERFARFUNC_HIDDENFUNC_THUNKFUNC_BOTTOMBPFUNC_NORET_PENDINGFUNC_SP_READYFUNC_PURGED_OKFUNC_TAILFUNC_LUMINAFUNC_OUTLINEget_fchunk_refereradd_user_stkpntrecalc_spdget_entry_qtyadd_entryget_entry_ordinalget_entryget_entry_namerename_entryget_next_fixup_eaget_prev_fixup_eaFIXUP_OFF8FIXUP_OFF16FIXUP_SEG16FIXUP_PTR32FIXUP_OFF32FIXUP_PTR48FIXUP_HI8FIXUP_HI16FIXUP_LOW8FIXUP_LOW16FIXUP_OFF64FIXUP_CUSTOMFIXUPF_RELFIXUPF_EXTDEFFIXUPF_UNUSEDFIXUPF_CREATEDdel_fixupput_bookmarkget_bookmarkget_bookmark_descENFL_REGEXAR_LONG: Array of longsAR_STR: Array of stringsadd_sourcefileget_sourcefiledel_sourcefileset_source_linnumget_source_linnumdel_source_linnumSizeOfTINFO_GUESSEDTINFO_DEFINITETINFO_DELAYFUNCPT_SILPT_NDCPT_TYPPT_VARPT_PACKMASKPT_HIGHPT_LOWERPT_REPLACEPT_RAWARGSPT_SILENTPT_PAKDEFPT_PAK1PT_PAK2PT_PAK4PT_PAK8PT_PAK16PT_FILEPT_STANDALONEPDF_INCL_DEPSPDF_DEF_FWDPDF_DEF_BASEPDF_HEADER_CMTPRTYPE_1LINEPRTYPE_MULTIPRTYPE_TYPEPRTYPE_PRAGMAPRTYPE_SEMIPRTYPE_CPPPRTYPE_DEFPRTYPE_NOARGSPRTYPE_NOARRSPRTYPE_NORESPRTYPE_RESTOREPRTYPE_NOREGEXPRTYPE_COLOREDPRTYPE_METHODSPRTYPE_1LINCMTadd_hidden_rangedel_hidden_rangeload_debuggerstart_processexit_processsuspend_processget_processesattach_processdetach_processget_thread_qtygetn_threadget_current_threadgetn_thread_nameselect_threadsuspend_threadresume_threadstep_intostep_overrun_tostep_until_retwait_for_next_eventWFNE_ANYWFNE_SUSPWFNE_SILENTWFNE_CONTWFNE_NOWAITNOTASKDBG_ERRORDBG_TIMEOUTPROCESS_STARTEDPROCESS_EXITEDTHREAD_STARTEDTHREAD_EXITEDBREAKPOINTSTEPEXCEPTIONLIB_LOADEDLIB_UNLOADEDINFORMATIONPROCESS_ATTACHEDPROCESS_DETACHEDPROCESS_SUSPENDEDrefresh_debugger_memorytake_memory_snapshotget_process_stateDSTATE_SUSPDSTATE_NOTASKDSTATE_RUNDSTATE_RUN_WAIT_ATTACHDSTATE_RUN_WAIT_END: Get various information about the current debug eventset_debugger_optionsDOPT_SEGM_MSGSDOPT_START_BPTDOPT_THREAD_MSGSDOPT_THREAD_BPTDOPT_BPT_MSGSDOPT_LIB_MSGSDOPT_LIB_BPTDOPT_INFO_MSGSDOPT_INFO_BPTDOPT_REAL_MEMORYDOPT_REDO_STACKDOPT_ENTRY_BPTDOPT_EXCDLGEXCDLG_NEVEREXCDLG_UNKNOWNEXCDLG_ALWAYSDOPT_LOAD_DINFOget_debugger_event_condset_debugger_event_condset_remote_debuggerdefine_exceptionEXC_BREAKEXC_HANDLEget_reg_valueget_bpt_qtyBPTATTR_EABPTATTR_SIZEBPTATTR_TYPEBPT_WRITEBPT_RDWRBPT_SOFTBPT_EXECBPT_DEFAULTBPTATTR_COUNTBPTATTR_FLAGSBPT_BRKBPT_TRACEBPT_UPDMEMBPT_ENABLEDBPT_LOWCNDBPT_TRACEONBPT_TRACE_INSNBPT_TRACE_FUNCBPT_TRACE_BBLKBPTATTR_CONDBPTATTR_PIDBPTATTR_TIDBPLT_ABSBPLT_RELBPLT_SYMadd_bptdel_bptenable_bptcheck_bptBPTCK_NONEBPTCK_NOBPTCK_YESBPTCK_ACTTRACE_STEPTRACE_INSNTRACE_FUNCget_step_trace_optionsset_step_trace_optionsST_OVER_DEBUG_SEGST_OVER_LIB_FUNCST_ALREADY_LOGGEDST_SKIP_LOOPSload_trace_filesave_trace_fileis_valid_trace_filediff_trace_fileget_trace_file_descset_trace_file_descget_tev_qtyget_tev_eaTEV_NONETEV_INSNTEV_CALLTEV_RETTEV_BPTTEV_MEMTEV_EVENTget_tev_typeget_tev_tidget_tev_regget_tev_mem_qtyget_tev_memget_tev_mem_eaget_call_tev_calleeget_ret_tev_returnget_bpt_tev_eaCIC_ITEMCIC_FUNCCIC_SEGMDEFCOLORARGV: The command line arguments passed to IDA via the -S switch.
Functions Overview
has_value(F)byte_value(F): Get byte value from flagsis_loaded(ea): Is the byte initialized?is_code(F)is_data(F)is_tail(F)is_unknown(F)is_head(F)is_flow(F)isExtra(F)isRef(F)hasName(F)hasUserName(F)is_defarg0(F)is_defarg1(F)isDec0(F)isDec1(F)isHex0(F)isHex1(F)isOct0(F)isOct1(F)isBin0(F)isBin1(F)is_off0(F)is_off1(F)is_char0(F)is_char1(F)is_seg0(F)is_seg1(F)is_enum0(F)is_enum1(F)is_manual0(F)is_manual1(F)is_stroff0(F)is_stroff1(F)is_stkvar0(F)is_stkvar1(F)is_byte(F)is_word(F)is_dword(F)is_qword(F)is_oword(F)is_tbyte(F)is_float(F)is_double(F)is_pack_real(F)is_strlit(F)is_struct(F)is_align(F)value_is_string(var)value_is_long(var)value_is_float(var)value_is_func(var)value_is_pvoid(var)value_is_int64(var)to_ea(seg, off): Return value of expression: ((seg<<4) + off)form(format, *args)substr(s, x1, x2)strstr(s1, s2)strlen(s)xtol(s)atoa(ea): Convert address value to a stringltoa(n, radix)atol(s)rotate_left(value, count, nbits, offset): Rotate a value to the left (or right)rotate_dword(x, count)rotate_word(x, count)rotate_byte(x, count)eval_idc(expr): Evaluate an IDC expressionEVAL_FAILURE(code): Check the result of eval_idc() for evaluation failuressave_database(idbname, flags=0): Save current database to the specified idb filevalidate_idb_names(do_repair=0): check consistency of IDB name recordscall_system(command): Execute an OS command.qsleep(milliseconds): qsleep the specified number of millisecondsdelete_all_segments(): Delete all segments, instructions, comments, i.e. everythingplan_and_wait(sEA, eEA, final_pass=True): Perform full analysis of the rangeset_name(ea, name, flags=ida_name.SN_CHECK): Rename an addressmake_array(ea, nitems): Create an array.create_strlit(ea, endea): Create a string.create_byte(ea): Convert the current item to a bytecreate_word(ea): Convert the current item to a word (2 bytes)create_dword(ea): Convert the current item to a double word (4 bytes)create_qword(ea): Convert the current item to a quadro word (8 bytes)create_oword(ea): Convert the current item to an octa word (16 bytes/128 bits)create_yword(ea): Convert the current item to a ymm word (32 bytes/256 bits)create_float(ea): Convert the current item to a floating point (4 bytes)create_double(ea): Convert the current item to a double floating point (8 bytes)create_pack_real(ea): Convert the current item to a packed real (10 or 12 bytes)create_tbyte(ea): Convert the current item to a tbyte (10 or 12 bytes)create_struct(ea, size, strname): Convert the current item to a structure instancedefine_local_var(start, end, location, name): Create a local variableset_array_params(ea, flags, litems, align): Set array representation formatop_plain_offset(ea, n, base): Convert operand to an offsettoggle_bnot(ea, n): Toggle the bitwise not operator for the operandop_stroff(ea, n, strid, delta): Convert operand to an offset in a structureop_offset_high16(ea, n, target): Convert operand to a high offsetMakeVar(ea)split_sreg_range(ea, reg, value, tag=SR_user): Set value of a segment register.AutoMark(ea, qtype): Plan to analyze an addressgen_file(filetype, path, ea1, ea2, flags): Generate an output filegen_flow_graph(outfile, title, ea1, ea2, flags): Generate a flow chart GDL filegen_simple_call_chart(outfile, title, flags): Generate a function call graph GDL fileidadir(): Get IDA directoryget_idb_path(): Get IDB full pathget_bytes(ea, size, use_dbg=False): Return the specified number of bytes of the programread_dbg_byte(ea): Get value of program byte using the debugger memoryread_dbg_word(ea): Get value of program word using the debugger memoryread_dbg_dword(ea): Get value of program double-word using the debugger memoryread_dbg_qword(ea): Get value of program quadro-word using the debugger memorywrite_dbg_memory(ea, data): Write to debugger memory.GetFloat(ea): Get value of a floating point number (4 bytes)GetDouble(ea): Get value of a floating point number (8 bytes)get_name_ea_simple(name): Get linear address of a nameget_segm_by_sel(base): Get segment by segment baseget_curline(): Get the disassembly line at the cursorread_selection_start(): Get start address of the selected rangeread_selection_end(): Get end address of the selected rangeget_sreg(ea, reg): Get value of segment register at the specified addressnext_head(ea, maxea=BADADDR): Get next defined item (instruction or data) in the programprev_head(ea, minea=0): Get previous defined item (instruction or data) in the programget_item_size(ea): Get size of instruction or data item in bytesfunc_contains(func_ea, ea): Does the given function contain the given address?get_name(ea, gtn_flags=0): Get name at the specified addressdemangle_name(name, disable_mask): demangle_name a namegenerate_disasm_line(ea, flags): Get disassembly lineGetDisasm(ea): Get disassembly lineprint_insn_mnem(ea): Get instruction mnemonicsprint_operand(ea, n): Get operand of an instruction or dataget_operand_type(ea, n): Get type of instruction operandget_operand_value(ea, n): Get number used in the operandget_strlit_contents(ea, length=-1, strtype=STRTYPE_C): Get string contentsget_str_type(ea): Get string typeprocess_config_line(directive): Obsolete. Please use ida_idp.process_config_directive().get_inf_attr(attr): Deprecated. Please ida_ida.inf_get_* instead.set_inf_attr(attr, value): Deprecated. Please ida_ida.inf_set_* instead.SetPrcsr(processor)get_processor_name(): Get name of the current processorbatch(batch): Enable/disable batch mode of operationprocess_ui_action(name, flags=0): Invokes an IDA UI action by namesel2para(sel): Get a selector valuefind_selector(val): Find a selector which has the specified valueget_first_seg(): Get first segmentget_next_seg(ea): Get next segmentget_segm_start(ea): Get start address of a segmentget_segm_end(ea): Get end address of a segmentget_segm_name(ea): Get name of a segmentadd_segm_ex(startea, endea, base, use32, align, comb, flags): Create a new segmentAddSeg(startea, endea, base, use32, align, comb)set_segment_bounds(ea, startea, endea, flags): Change segment boundariesset_segm_name(ea, name): Change name of the segmentset_segm_class(ea, segclass): Change class of the segmentset_segm_alignment(ea, alignment): Change alignment of the segmentset_segm_combination(segea, comb): Change combination of the segmentset_segm_addressing(ea, bitness): Change segment addressingselector_by_name(segname): Get segment selector by nameset_default_sreg_value(ea, reg, value): Set default segment register value for a segmentset_segm_type(segea, segtype): Set segment typeget_segm_attr(segea, attr): Get segment attributeset_segm_attr(segea, attr, value): Set segment attributemove_segm(ea, to, flags): Move a segment to a new addressget_xref_type(): Return type of the last xref obtained byfopen(f, mode)fclose(handle)filelength(handle)fseek(handle, offset, origin)ftell(handle)LoadFile(filepath, pos, ea, size): Load file into IDA databaseloadfile(filepath, pos, ea, size)SaveFile(filepath, pos, ea, size): Save from IDA database to filesavefile(filepath, pos, ea, size)fgetc(handle)fputc(byte, handle)fprintf(handle, format, *args)readshort(handle, mostfirst)readlong(handle, mostfirst)writeshort(handle, word, mostfirst)writelong(handle, dword, mostfirst)readstr(handle)writestr(handle, s)get_next_func(ea): Find next functionget_prev_func(ea): Find previous functionget_func_attr(ea, attr): Get a function attributeset_func_attr(ea, attr, value): Set a function attributeget_func_flags(ea): Retrieve function flagsset_func_flags(ea, flags): Change function flagsget_func_name(ea): Retrieve function nameget_func_cmt(ea, repeatable): Retrieve function commentset_func_cmt(ea, cmt, repeatable): Set function commentchoose_func(title): Ask the user to select a functionget_func_off_str(ea): Convert address to 'funcname+offset' stringfind_func_end(ea): Determine a new function boundariesget_frame_id(ea): Get ID of function frame structureget_frame_lvar_size(ea): Get size of local variables in function frameget_frame_regs_size(ea): Get size of saved registers in function frameget_frame_args_size(ea): Get size of arguments in function frame which are purged upon returnget_frame_size(ea): Get full size of function frameset_frame_size(ea, lvsize, frregs, argsize): Make function frameget_spd(ea): Get current delta for the stack pointerget_sp_delta(ea): Get modification of SP made by the instructionget_fchunk_attr(ea, attr): Get a function chunk attributeset_fchunk_attr(ea, attr, value): Set a function chunk attributeget_next_fchunk(ea): Get next function chunkget_prev_fchunk(ea): Get previous function chunkappend_func_tail(funcea, ea1, ea2): Append a function chunk to the functionremove_fchunk(funcea, tailea): Remove a function chunk from the functionset_tail_owner(tailea, funcea): Change the function chunk ownerfirst_func_chunk(funcea): Get the first function chunk of the specified functionnext_func_chunk(funcea, tailea): Get the next function chunk of the specified functionadd_auto_stkpnt(func_ea, ea, delta): Add automatic SP register change pointdel_stkpnt(func_ea, ea): Delete SP register change pointget_min_spd_ea(func_ea): Return the address with the minimal spd (stack pointer delta)get_fixup_target_type(ea): Get fixup target typeget_fixup_target_flags(ea): Get fixup target flagsget_fixup_target_sel(ea): Get fixup target selectorget_fixup_target_off(ea): Get fixup target offsetget_fixup_target_dis(ea): Get fixup target displacementset_fixup(ea, fixuptype, fixupflags, targetsel, targetoff, displ): Set fixup informationget_struc_id(name)get_struc_name(tid)get_struc_cmt(tid)get_struc_size(tid)get_member_qty(sid): Get number of members of a structureget_member_by_idx(sid, idx): Get member ID by member ordinal numberis_member_id(sid): Is a member id?get_member_id(sid, member_offset)get_member_offset(sid, member_name): Get offset of a member of a structure by the member nameget_member_name(sid, member_offset): Get name of a member of a structureget_member_cmt(sid, member_offset, repeatable=True): Get comment of a memberget_member_size(sid, member_offset): Get size of a memberget_member_strid(sid, member_offset): Get structure id of a memberis_union(sid): Is a structure a union?add_struc(index, name, is_union): Define a new structure typedel_struc(sid): Delete a structure typeset_struc_name(sid, name)set_struc_cmt(sid, cmt, repeatable=True)add_struc_member(sid, name, offset, flag, typeid, nbytes, target=-1, tdelta=0, reftype=REF_OFF32): Add structure memberdel_struc_member(sid, member_offset): Delete structure memberset_member_name(sid, member_offset, name): Change structure member nameset_member_type(sid, member_offset, flag, typeid, nitems, target=-1, tdelta=0, reftype=REF_OFF32): Change structure member typeset_member_cmt(sid, member_offset, comment, repeatable): Change structure member commentexpand_struc(sid, offset, delta, recalc=True): Expand or shrink a structure typeget_enum(name): Get enum by nameget_enum_name(enum_id, flags=0): Get name of enumget_enum_cmt(enum_id): Get enum commentget_enum_size(enum_id): Get the number of the members of the enumget_enum_width(enum_id): Get the width of a enum elementget_enum_flag(enum_id): Get flags determining the representation of the enum.get_enum_member_by_name(name): Get a reference to an enum member by its nameget_enum_member_enum(const_id): Get the parent enum of an enum memberget_enum_member(enum_id, value, serial, bmask): Get id of constantget_first_bmask(enum_id): Get first bitmask in the enumget_last_bmask(enum_id): Get last bitmask in the enumget_next_bmask(enum_id, bmask): Get next bitmask in the enumget_prev_bmask(enum_id, bmask): Get prev bitmask in the enumget_bmask_name(enum_id, bmask): Get bitmask name (only for bitfields)get_bmask_cmt(enum_id, bmask, repeatable): Get bitmask comment (only for bitfields)set_bmask_name(enum_id, bmask, name): Set bitmask name (only for bitfields)set_bmask_cmt(enum_id, bmask, cmt, repeatable): Set bitmask comment (only for bitfields)get_first_enum_member(enum_id, bmask=-1): Get first constant in the enumget_last_enum_member(enum_id, bmask=-1): Get last constant in the enumget_next_enum_member(enum_id, value, bmask=-1): Get next constant in the enumget_prev_enum_member(enum_id, value, bmask=-1): Get prev constant in the enumget_enum_member_name(const_id): Get name of a constantget_enum_member_cmt(const_id, repeatable=True): Get comment of a constantget_enum_member_value(const_id): Get value of an enum memberget_enum_member_bmask(const_id): Get bitmask of an enum memberadd_enum(idx, name, flag): Add a new enum typedel_enum(enum_id): Delete an enum typeset_enum_name(enum_id, name): Set name of enum typeset_enum_flag(enum_id, flag): Set enum constant representation flagsset_enum_width(enum_id, nbytes): Set the width of enum base typeis_bf(enum_id): Is enum a bitmask ?set_enum_bf(enum_id, bf): Set or clear the 'bitmask' attribute of an enumset_enum_cmt(enum_id, cmt, repeatable): Set comment for enum typeadd_enum_member(enum_id, name, value, bmask=-1): Add a member of enum - a symbolic constantdel_enum_member(enum_id, value, serial, bmask=-1): Delete a member of enum - a symbolic constantset_enum_member_name(const_id, name): Set name of enum memberset_enum_member_cmt(const_id, cmt, repeatable=False): Set comment for enum membercreate_array(name): Create array.get_array_id(name): Get array array_id, by name.rename_array(array_id, newname): Rename array, by its ID.delete_array(array_id): Delete array, by its ID.set_array_long(array_id, idx, value): Sets the long value of an array element.set_array_string(array_id, idx, value): Sets the string value of an array element.get_array_element(tag, array_id, idx): Get value of array element.del_array_element(tag, array_id, idx): Delete an array element.get_first_index(tag, array_id): Get index of the first existing array element.get_last_index(tag, array_id): Get index of last existing array element.get_next_index(tag, array_id, idx): Get index of the next existing array element.get_prev_index(tag, array_id, idx): Get index of the previous existing array element.set_hash_long(hash_id, key, value): Sets the long value of a hash element.get_hash_long(hash_id, key): Gets the long value of a hash element.set_hash_string(hash_id, key, value): Sets the string value of a hash element.get_hash_string(hash_id, key): Gets the string value of a hash element.del_hash_string(hash_id, key): Delete a hash element.get_first_hash_key(hash_id): Get the first key in the hash.get_last_hash_key(hash_id): Get the last key in the hash.get_next_hash_key(hash_id, key): Get the next key in the hash.get_prev_hash_key(hash_id, key): Get the previous key in the hash.add_default_til(name): Load a type libraryimport_type(idx, type_name): Copy information from type library to databaseget_type(ea): Get type of function/variablesizeof(typestr): Returns the size of the type. It is equivalent to IDC's sizeof().get_tinfo(ea): Get type information of function/variable as 'typeinfo' objectget_local_tinfo(ordinal): Get local type information as 'typeinfo' objectguess_type(ea): Guess type of function/variableapply_type(ea, py_type, flags=TINFO_DEFINITE): Apply the specified type to the addressSetType(ea, newtype): Set type of function/variableparse_decl(inputtype, flags): Parse type declarationparse_decls(inputtype, flags=0): Parse type declarationsprint_decls(ordinals, flags): Print types in a format suitable for use in a header fileget_ordinal_limit(): Get number of local types + 1set_local_type(ordinal, input, flags): Parse one type declaration and store it in the specified slotGetLocalType(ordinal, flags): Retrieve a local type declarationget_numbered_type_name(ordinal): Retrieve a local type nameupdate_hidden_range(ea, visible): Set hidden range stateget_first_module(): Enumerate process modulesget_next_module(base): Enumerate process modulesget_module_name(base): Get process module nameget_module_size(base): Get process module sizeresume_process()send_dbg_command(cmd): Sends a command to the debugger module and returns the output string.get_event_id(): Get ID of debug eventget_event_pid(): Get process ID for debug eventget_event_tid(): Get type ID for debug eventget_event_ea(): Get ea for debug eventis_event_handled(): Is the debug event handled?get_event_module_name(): Get module name for debug eventget_event_module_base(): Get module base for debug eventget_event_module_size(): Get module size for debug eventget_event_exit_code(): Get exit code for debug eventget_event_info(): Get debug event infoget_event_bpt_hea(): Get hardware address for BREAKPOINT eventget_event_exc_code(): Get exception code for EXCEPTION eventget_event_exc_ea(): Get address for EXCEPTION eventcan_exc_continue(): Can it continue after EXCEPTION event?get_event_exc_info(): Get info for EXCEPTION eventset_reg_value(value, name): Set register valueget_bpt_ea(n): Get breakpoint addressget_bpt_attr(ea, bptattr): Get the characteristics of a breakpointset_bpt_attr(address, bptattr, value): modifiable characteristics of a breakpointset_bpt_cond(ea, cnd, is_lowcnd=0): Set breakpoint conditionenable_tracing(trace_level, enable): Enable step tracingclear_trace(filename): Clear the current trace bufferget_color(ea, what): Get item colorset_color(ea, what, color): Set item colorforce_bl_jump(ea): Some ARM compilers in Thumb mode use BL (branch-and-link)force_bl_call(ea): Force BL instruction to be a callset_flag(off, bit, value)here()is_mapped(ea)