aboutsummaryrefslogtreecommitdiff
path: root/tools/ghidra/ExportAiVmHandler1Callees.java
diff options
context:
space:
mode:
authorValentin Popov <valentin@popov.link>2026-07-18 20:01:46 +0300
committerValentin Popov <valentin@popov.link>2026-07-18 20:01:46 +0300
commit545d661b2b7af61c1b46cd7aebf52ece59b113fa (patch)
tree5ca0a9f9dc3c62abd78066573bd7ec34b9ac47c3 /tools/ghidra/ExportAiVmHandler1Callees.java
parent9dcf6d456e0c2e06d45be001874ac72d7911703e (diff)
downloadfparkan-545d661b2b7af61c1b46cd7aebf52ece59b113fa.tar.xz
fparkan-545d661b2b7af61c1b46cd7aebf52ece59b113fa.zip
docs(ai): recover numeric handler contract
Diffstat (limited to 'tools/ghidra/ExportAiVmHandler1Callees.java')
-rw-r--r--tools/ghidra/ExportAiVmHandler1Callees.java25
1 files changed, 25 insertions, 0 deletions
diff --git a/tools/ghidra/ExportAiVmHandler1Callees.java b/tools/ghidra/ExportAiVmHandler1Callees.java
new file mode 100644
index 0000000..f59e619
--- /dev/null
+++ b/tools/ghidra/ExportAiVmHandler1Callees.java
@@ -0,0 +1,25 @@
+// Emits the two direct callees recovered from AI VM Handler(1).
+// Run through Ghidra headless analysis; the original PE remains read only.
+import ghidra.app.decompiler.DecompInterface;
+import ghidra.app.script.GhidraScript;
+import ghidra.program.model.address.Address;
+import ghidra.program.model.listing.Function;
+
+public class ExportAiVmHandler1Callees extends GhidraScript {
+ private static final long[] ADDRESSES = { 0x10002d30L, 0x10013190L };
+
+ @Override
+ public void run() throws Exception {
+ DecompInterface decompiler = new DecompInterface();
+ decompiler.openProgram(currentProgram);
+ for (long value : ADDRESSES) {
+ Address address = currentProgram.getAddressFactory().getDefaultAddressSpace()
+ .getAddress(value);
+ Function function = currentProgram.getFunctionManager().getFunctionAt(address);
+ println("===== AI VM Handler(1) callee " + address + " =====");
+ if (function == null) { println("missing"); continue; }
+ println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC());
+ }
+ decompiler.dispose();
+ }
+}