diff options
| author | user <user@clank> | 2026-08-09 12:59:18 +0200 |
|---|---|---|
| committer | user <user@clank> | 2026-08-09 12:59:18 +0200 |
| commit | 1cf127f5c1cc5d7862385df14b5c49ba028ade7c (patch) | |
| tree | e36114b4c5ce315f2d5b89e633abb40de02ed550 /experiments/bench_pack_trace.py | |
| parent | splash: scale the logo to the pane instead of dropping it (diff) | |
| download | ida-tui-1cf127f5c1cc5d7862385df14b5c49ba028ade7c.tar.gz ida-tui-1cf127f5c1cc5d7862385df14b5c49ba028ade7c.tar.xz ida-tui-1cf127f5c1cc5d7862385df14b5c49ba028ade7c.zip | |
Graph: a second layout engine, triskel's SESE decomposition
`e` in graph mode cycles auto -> native -> triskel, and `auto` prefers
triskel where it is installed and the function is at most 250 blocks.
Why: our layered engine draws wide-and-short pictures with a lot of
crossings on anything branchy. Triskel splits the CFG into Single-Entry
Single-Exit regions first and lays each out on its own, which on the
128-function corpus means fewer crossings on 12 functions, equal on 9,
worse on 3 -- and the wins are the hairballs (sub_5CA0 41 -> 6,
sub_2C90 32 -> 7, sub_2C00 12 -> 0). It also routes loop edges around
the side of the graph the way IDA does, which was a known gap here.
It is not free: ~2x slower at 87 blocks, 10x at 424, hence the cap.
The library needed a fork (~/dev/triskel, branch idatui) before it could
be used from Python at all -- its get_waypoints() threw on every
published version, an empty graph segfaulted the interpreter, and its
spacing constants were pixels baked in at compile time. Making those
settable is what makes this integration cheap: we hand it CELLS, so
its output is integral and two edge lanes can never round onto the same
row. The feared quantisation problem measured out backwards -- cells
claimed by more than one edge: native 131, triskel 35.
Not trusted with degenerate input, all handled before the call:
self-loops and disconnected components make it throw, and one corpus
edge comes back routed through a block, which we detour and re-verify.
A triskel failure is never fatal; it falls back to native.
Two things the second engine flushed out of the existing code:
- the canvas was sized from boxes alone, which is exact only because
native's dummy nodes reserve the space. Triskel routes outside that
bounding box and the edges were being clipped.
- arrowhead placement read e.back, conflating "this is a loop edge"
(style) with "this polyline runs against control flow" (geometry).
Now Edge.flipped, which is also a latent fix for residual-cycle edges
whose succ/pred were being reported backwards.
tests/test_graph.py runs its whole suite once per available engine
(943 checks); new graph_engine scenario covers the live toggle.
Diffstat (limited to 'experiments/bench_pack_trace.py')
0 files changed, 0 insertions, 0 deletions
