diff options
| author | blasty <blasty@local> | 2026-07-26 14:51:07 +0200 |
|---|---|---|
| committer | blasty <blasty@local> | 2026-07-26 14:51:07 +0200 |
| commit | 7bdf3741c91f76bfff3f3e054a5cf41b7f476d0b (patch) | |
| tree | 26404f9b55551980505dbc94f9757f7ee7c187e7 /tests/test_thumb_ui.py | |
| parent | TODO: DisasmView removed (diff) | |
| download | ida-tui-7bdf3741c91f76bfff3f3e054a5cf41b7f476d0b.tar.gz ida-tui-7bdf3741c91f76bfff3f3e054a5cf41b7f476d0b.tar.xz ida-tui-7bdf3741c91f76bfff3f3e054a5cf41b7f476d0b.zip | |
arm: switch ARM/Thumb decoding with `t`
`c` could not carve Thumb code. Thumb isn't a property of the bytes — it's a
mode the CPU is in — so a raw image gives IDA nothing to detect: at a Thumb entry
point it decodes 16-bit instructions as 32-bit ARM and produces confident
nonsense. experiments/fibonacci.bin starts with `08 b5` = push {r3,lr}, which
IDA reads as SVCLT 0xBF00.
`t` on the listing switches the mode at the cursor and disassembles in it:
Thumb @ 0x0 (segment set to 32-bit; Thumb needs ARM32) — 10 instructions
0x0 PUSH {R3,LR} 0x2 MOVS R1, #0 0x4 MOV R4, R0 0x6 BL unk_E3C
Setting the T segment register is only half of it. Thumb does not exist in
AArch64, and a headerless blob loaded with -parm comes up 64-bit, so T alone
changes nothing and looks broken — I watched exactly that happen while probing
the API. Asking for Thumb IS asking for ARM32, so set_thumb forces the segment
to 32-bit and says so rather than doing it silently.
It also has to del_items over the range first: the bytes are currently decoded
in the old mode, and leaving that item defined pins the wrong instruction length
so the new mode has nothing to apply to.
Implemented as a `thumb` kind in the existing edit-item flow, so it inherits the
shared reload — same cache bump, same ViewAnchor restore, same status flash. It
switches AND disassembles, because flipping T and leaving the bytes undefined
shows you nothing and reading the code was the point.
tests: new tests/test_thumb_ui.py (8) driving the real Thumb binary — `c` alone
does NOT produce the prologue, `t` does, the instructions are 16-bit wide (in ARM
mode those three rows would be one 4-byte instruction), the run continues, the
status explains the 32-bit forcing, and `t` toggles back. Deletes the .i64 first,
because T and the segment's addressing mode are saved in it and a stale database
would answer the question for us.
209/0 scenarios, 26/0 blob, 8/0 thumb.
Diffstat (limited to 'tests/test_thumb_ui.py')
| -rw-r--r-- | tests/test_thumb_ui.py | 126 |
1 files changed, 126 insertions, 0 deletions
diff --git a/tests/test_thumb_ui.py b/tests/test_thumb_ui.py new file mode 100644 index 0000000..dce1635 --- /dev/null +++ b/tests/test_thumb_ui.py @@ -0,0 +1,126 @@ +#!/usr/bin/env python3 +"""ARM/Thumb decoding switch, against real Thumb code. + +Thumb isn't a property of the bytes — it's a mode the CPU is in — so a raw image +gives IDA no way to know. At a Thumb entry point it decodes 16-bit instructions +as 32-bit ARM and produces confident nonsense, and `c` either fails or carves +garbage. `t` switches the mode. + +Uses experiments/fibonacci.bin (real Thumb), so the encodings are not a guess. +Needs IDA. ~40s. +""" +import asyncio +import os +import sys + +sys.path.insert(0, os.path.dirname(os.path.dirname(os.path.abspath(__file__)))) + +from textual.widgets import Static # noqa: E402 + +from idatui.app import IdaTui, ListingView # noqa: E402 + +PASS = FAIL = 0 +BIN = os.path.join(os.path.dirname(os.path.dirname(os.path.abspath(__file__))), + "experiments", "fibonacci.bin") + + +def check(name, ok, detail=""): + global PASS, FAIL + if ok: + PASS += 1 + print(f" ok {name}") + else: + FAIL += 1 + print(f" FAIL {name} {detail}") + + +async def wait(pred, pilot, t=240.0): + for _ in range(int(t / 0.05)): + await pilot.pause(0.05) + try: + if pred(): + return True + except Exception: # noqa: BLE001 + pass + return False + + +async def run() -> int: + # A fresh database every time: the T flag and the segment's addressing mode + # are SAVED in the .i64, so a previous run would answer the question for us. + for ext in (".i64", ".id0", ".id1", ".id2", ".nam", ".til"): + try: + os.remove(BIN + ext) + except OSError: + pass + + app = IdaTui(open_path=BIN, keepalive=False, load_args="-parm") + async with app.run_test(size=(140, 44)) as pilot: + await wait(lambda: app._func_index is not None + and app._func_index.complete, pilot) + await wait(lambda: app._cur is not None, pilot, 60) + lst = app.query_one(ListingView) + lst.focus() + lst.cursor = lst.model.index_of_ea(0) + lst._scroll_cursor_into_view() + await pilot.pause(0.3) + check("starts undefined at the entry", lst.model.get(lst.cursor).kind == "unknown", + f"{lst.model.get(lst.cursor).text!r}") + + # `c` in the wrong mode: this is the failure being fixed. It must NOT + # quietly carve garbage — either it refuses, or whatever it makes is not + # the Thumb prologue. + m0 = lst.model + await pilot.press("c") + await pilot.pause(2.5) + h = lst.model.get(lst.model.index_of_ea(0)) + check("`c` alone does not produce the Thumb prologue", + h is None or h.kind != "code" or "PUSH" not in h.text.upper(), + f"{h.text if h else None!r}") + + m1 = lst.model + await pilot.press("t") + await wait(lambda: lst.model is not m1 and lst.model is not None, pilot, 60) + await pilot.pause(0.5) + + status = str(app.query_one("#status", Static).render()) + check("the status says it switched to Thumb", "Thumb" in status, status[:90]) + # Thumb doesn't exist in AArch64, and -parm on a headerless blob gives a + # 64-bit segment, so setting T alone would change nothing and look broken. + check("and says it forced the segment to 32-bit", + "32-bit" in status, status[:90]) + + m = lst.model + rows = [m.get(m.index_of_ea(ea)) for ea in (0x0, 0x2, 0x4)] + check("the entry decodes as Thumb", + rows[0] is not None and rows[0].kind == "code" + and "PUSH" in rows[0].text.upper(), + f"{rows[0].text if rows[0] else None!r}") + # 16-bit instructions: the addresses are 2 apart, which is the whole + # point — in ARM mode these would be one 4-byte instruction. + check("instructions are 16-bit wide", + all(r is not None and r.kind == "code" and r.size == 2 for r in rows), + f"{[(hex(r.ea), r.size, r.text) for r in rows if r]}") + check("and it kept disassembling past the first one", + sum(1 for i in range(20) if (m.get(i) or h).kind == "code") > 5, + "expected a run of instructions, not one") + + # Toggling back must be possible — the mode is a guess and guesses get + # revised. + m2 = lst.model + lst.cursor = lst.model.index_of_ea(0) + await pilot.press("t") + await wait(lambda: lst.model is not m2 and lst.model is not None, pilot, 60) + await pilot.pause(0.5) + status = str(app.query_one("#status", Static).render()) + check("`t` toggles back to ARM", "ARM @" in status, status[:80]) + + print(f"\n{PASS} passed, {FAIL} failed") + return 1 if FAIL else 0 + + +if __name__ == "__main__": + if not os.path.isfile(BIN): + print(f"no such binary: {BIN}") + raise SystemExit(2) + raise SystemExit(asyncio.run(run())) |
