From 545d661b2b7af61c1b46cd7aebf52ece59b113fa Mon Sep 17 00:00:00 2001 From: Valentin Popov Date: Sat, 18 Jul 2026 21:01:46 +0400 Subject: docs(ai): recover numeric handler contract --- tools/ghidra/ExportAiVmHandler1.java | 23 +++++++++++++++++++++++ tools/ghidra/ExportAiVmHandler1Callees.java | 25 +++++++++++++++++++++++++ 2 files changed, 48 insertions(+) create mode 100644 tools/ghidra/ExportAiVmHandler1.java create mode 100644 tools/ghidra/ExportAiVmHandler1Callees.java (limited to 'tools') diff --git a/tools/ghidra/ExportAiVmHandler1.java b/tools/ghidra/ExportAiVmHandler1.java new file mode 100644 index 0000000..e58c1e9 --- /dev/null +++ b/tools/ghidra/ExportAiVmHandler1.java @@ -0,0 +1,23 @@ +// Emits Handler(1), the second function in the AI DLL's verified 73-entry VM table. +// Run through Ghidra headless analysis; the original PE remains read only. +import ghidra.app.decompiler.DecompInterface; +import ghidra.app.script.GhidraScript; +import ghidra.program.model.address.Address; +import ghidra.program.model.listing.Function; + +public class ExportAiVmHandler1 extends GhidraScript { + private static final long ADDRESS = 0x10007fd0L; + + @Override + public void run() throws Exception { + Address address = currentProgram.getAddressFactory().getDefaultAddressSpace() + .getAddress(ADDRESS); + Function function = currentProgram.getFunctionManager().getFunctionAt(address); + println("===== AI VM Handler(1) ====="); + if (function == null) { println("missing"); return; } + DecompInterface decompiler = new DecompInterface(); + decompiler.openProgram(currentProgram); + println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC()); + decompiler.dispose(); + } +} diff --git a/tools/ghidra/ExportAiVmHandler1Callees.java b/tools/ghidra/ExportAiVmHandler1Callees.java new file mode 100644 index 0000000..f59e619 --- /dev/null +++ b/tools/ghidra/ExportAiVmHandler1Callees.java @@ -0,0 +1,25 @@ +// Emits the two direct callees recovered from AI VM Handler(1). +// Run through Ghidra headless analysis; the original PE remains read only. +import ghidra.app.decompiler.DecompInterface; +import ghidra.app.script.GhidraScript; +import ghidra.program.model.address.Address; +import ghidra.program.model.listing.Function; + +public class ExportAiVmHandler1Callees extends GhidraScript { + private static final long[] ADDRESSES = { 0x10002d30L, 0x10013190L }; + + @Override + public void run() throws Exception { + DecompInterface decompiler = new DecompInterface(); + decompiler.openProgram(currentProgram); + for (long value : ADDRESSES) { + Address address = currentProgram.getAddressFactory().getDefaultAddressSpace() + .getAddress(value); + Function function = currentProgram.getFunctionManager().getFunctionAt(address); + println("===== AI VM Handler(1) callee " + address + " ====="); + if (function == null) { println("missing"); continue; } + println(decompiler.decompileFunction(function, 60, monitor).getDecompiledFunction().getC()); + } + decompiler.dispose(); + } +} -- cgit v1.2.3