cfg
This module generates the control flow graph of the disassembled code
- cfg_edge(src:address, dest:address, conditional:symbol, indirect:symbol, type:symbol)
This predicate specifies a CFG edge between two locations in the binary.
Uses:
arch.conditional
,arch.jump
,block_information
,code_in_refined_block
,conditional_return
,direct_call
,direct_jump
,function_inference.in_function
,loaded_section
,may_fallthrough
,no_return_call_propagated
,nop_block
,pc_load_call
,plt_block
,refined_block
,refined_block_control_instruction
,refined_block_last_instruction
,resolved_transfer
,unconditional_return
Used by:
cfg_edge_to_top
Recursive:
cfg_edge
- cfg_edge_to_top(src:address, conditional:symbol, type:symbol)
This predicate specifies CFG edges from
src
to a Top proxy block to model calls or jumps whose destination is unknown. This is optimistic, if at least one target of a jump/call is known, the edge to the proxy block will not be generated.
- cfg_edge_to_symbol(src:address, Symbol:symbol, conditional:symbol, indirect:symbol, type:symbol)
This predicate specifies CFG edges whose destination is an external symbol.
- jump_table(Src:address, Memory:address)
The jump at address
Src
might access the jump table entry at addressMemory
.Uses:
code_in_block
,data_access
,data_access_pattern
,indirect_jump
Recursive:
resolved_transfer
,+disconnected6
,data_limit_after_access
,jump_table
,symbol_score
,discarded_data_object
,symbolic_expr_attribute
,split_block
,labeled_data_candidate
,data_limit
,code_in_split_block
,symbolic_operand
,best_func_symbol
,code_in_refined_block
,after_address_in_data
,refined_block
,inferred_special_symbol
,got_reference
,data_object
,address_array_aux
,symbolic_operand_attribute
,+disconnected3
,preferred_data_access
,string_candidate
,moved_displacement_candidate
,+disconnected2
,address_array
,discarded_jump_table_entry
,data_object_point
,moved_label
,moved_data_label
,symbol_minus_symbol_candidate
,function_inference.function_entry
,data_object_conflict
,relative_jump_table_entry
,base_relative_symbolic_operand
,data_object_candidate
,string_candidate_refined
,value_reg_address_before
,moved_label_candidate
,+disconnected1
,block_needs_merging
,data_access_limit
,symbolic_data
,boundary_sym_expr
,symbolic_operand_point
,symbolic_expr
,moved_pc_relative_candidate
,block_needs_splitting_at
,labeled_ea
,label_conflict
,data_object_total_points
,next_address_in_data
,code_pointer_in_data
,inferred_main_function
,symbolic_expr_symbol_minus_symbol
,main_function
,symbol_minus_symbol_from_relocation
,symbol_minus_symbol
,next_data_limit
,best_symexpr_symbol
- resolved_transfer(EA:address, Dest:address, Type:symbol)
This predicate represents known targets of indirect jumps or calls.
EA
is the address of the jump or call instruction andDest
is the destination address. Type can be “branch” or “call”.
Uses:
arch.call
,arch.jump
,code_in_block
,data_access_pattern_candidate_refined
,defined_symbol
,indirect_call
,indirect_jump
,instruction
,jump_table_candidate_refined
,jump_table_start
,op_regdirect_contains_reg
,plt_entry
,reg_call
,reg_def_use.def_used
,reg_jump
,split_load_candidate
,symbolic_expr_from_relocation
,value_reg
Used by:
cfg_edge
,cfg_edge_to_top
Recursive:
resolved_transfer
,+disconnected6
,data_limit_after_access
,jump_table
,symbol_score
,discarded_data_object
,symbolic_expr_attribute
,split_block
,labeled_data_candidate
,data_limit
,code_in_split_block
,symbolic_operand
,best_func_symbol
,code_in_refined_block
,after_address_in_data
,refined_block
,inferred_special_symbol
,got_reference
,data_object
,address_array_aux
,symbolic_operand_attribute
,+disconnected3
,preferred_data_access
,string_candidate
,moved_displacement_candidate
,+disconnected2
,address_array
,discarded_jump_table_entry
,data_object_point
,moved_label
,moved_data_label
,symbol_minus_symbol_candidate
,function_inference.function_entry
,data_object_conflict
,relative_jump_table_entry
,base_relative_symbolic_operand
,data_object_candidate
,string_candidate_refined
,value_reg_address_before
,moved_label_candidate
,+disconnected1
,block_needs_merging
,data_access_limit
,symbolic_data
,boundary_sym_expr
,symbolic_operand_point
,symbolic_expr
,moved_pc_relative_candidate
,block_needs_splitting_at
,labeled_ea
,label_conflict
,data_object_total_points
,next_address_in_data
,code_pointer_in_data
,inferred_main_function
,symbolic_expr_symbol_minus_symbol
,main_function
,symbol_minus_symbol_from_relocation
,symbol_minus_symbol
,next_data_limit
,best_symexpr_symbol
- resolved_transfer_to_symbol(EA:address, Symbol:symbol, Type:symbol)
This predicates represent known targets of indirect jumps or calls that refer to external symbols. It is similar to
resolved_transfer
but its target is not an address but a symbol. ‘Type’ can be “branch” or “call”.
- pointer_to_external_symbol(DataPointer:address, Symbol:symbol)
Auxiliary predicate of
resolved_transfer_to_symbol
that captures a pointer at address ‘DataPointer’ that refers to the external symbol ‘Symbol’.