From 781c5eff4218d7ffdc9905f652ca08ce10953e43 Mon Sep 17 00:00:00 2001 From: blasty Date: Sun, 26 Jul 2026 20:49:30 +0200 Subject: arm: find Thumb entry points from a vector table (Shift+T) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit An ARM function pointer carries the mode in bit 0: odd means Thumb. A Cortex-M vector table is therefore a list of Thumb entry points, and IDA won't follow them on a headerless image because nothing tells it those words are pointers at all. Shift+T scans forward from the cursor and marks them. 0 functions -> 3 Thumb entries found, 3 disassembled A word only counts when it is odd, lands in a loaded segment, and its target is executable and not already data. The even words in a vector table — the initial stack pointer — fail the first test, which is the point: marking a data word as code corrupts the listing, so a false positive costs more than a miss. The fixture includes an even in-range word and an odd OUT-of-range word to keep that honest. A note on how this started: I recommended this feature, then probed experiments/fibonacci.bin for the signal and found ZERO odd in-range pointers — it's a flat code blob, not a firmware image. Rather than build a detector I couldn't test, I wrote experiments/cortexm.bin: a real vector table pointing at small self-contained Thumb handlers. The first version of that fixture aimed its handlers into the middle of copied code, so two "entries" were really inside one function — the tool was right and the fixture was wrong, which is worth stating because I nearly filed it as a bug. Function creation goes through one _idatui_add_func helper now, shared with define_func_run: add_func(ea) alone fails on freshly-marked code (IDA can't find the end), and the scan hit exactly the same wall `p` did. Status precedence, fixed properly this time. An action's result kept being overwritten by the reload it triggered — cursor moved, filter re-applied, functions re-counted. I patched that at FIVE separate call sites before admitting it's one problem. _status(text, priority=True) now marks a result: it holds the bar for 8s or until the next keypress, and routine chatter can't outrank it. The per-site special cases are gone. tests: +4 thumb (20) — a bare vector table gives IDA nothing, scanning finds exactly the three handlers, the non-pointer words are ignored, and the result survives both the reload and the reindex. 209/0 scenarios, 30/0 blob, 30/0 project UI. --- docs/PROJECTS.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) (limited to 'docs') diff --git a/docs/PROJECTS.md b/docs/PROJECTS.md index eae860b..fe6c2a8 100644 --- a/docs/PROJECTS.md +++ b/docs/PROJECTS.md @@ -335,6 +335,20 @@ Worth knowing: a correctly-chosen 32-bit ARM database also lets IDA's own auto-analysis find Thumb functions — `experiments/fibonacci.bin` yields 54 functions on load with `arm:ARMv7-A` and none with `arm`. +### Thumb entry points from a vector table + +`Shift+T` scans forward from the cursor for **odd pointers** — an ARM function +pointer carries the mode in bit 0, so a Cortex-M vector table is a list of Thumb +entry points. IDA won't follow them on a headerless image, because nothing tells +it those words are pointers at all: + + 3 Thumb entries found, 3 disassembled + +A word only counts when it is odd, lands inside a loaded segment, and its target +is executable and not already data. The even words in a vector table (the initial +stack pointer) fail the first test, which is the point — marking a data word as +code corrupts the listing, so a false positive costs more than a miss. + ### When analysis finds nothing Zero functions is what a raw image described wrongly looks like — right file, -- cgit v1.3.1-sl0p