From 1584baabb16d8678a2a4d693c5d69f5c3e4d5230 Mon Sep 17 00:00:00 2001 From: dragonmacher <48328597+dragonmacher@users.noreply.github.com> Date: Tue, 30 Jun 2026 15:57:09 -0400 Subject: [PATCH] GP-6987 - Instruction Pattern Searcher - Added new actions --- .../Base/data/ExtensionPoint.manifest | 1 + .../ghidra_scripts/YaraGhidraGUIScript.java | 6 +- .../Search/Search_Instruction_Patterns.htm | 14 +- .../images/SearchInstructionPatterns.png | Bin 30829 -> 35588 bytes ...rchInstructionPatternsInstructionTable.png | Bin 16677 -> 17125 bytes ...ructionPatternsInstructionTableToolbar.png | Bin 3376 -> 3798 bytes .../SearchInstructionPatternsPreviewTable.png | Bin 7872 -> 8565 bytes .../SearchInstructionsManualSearchDialog.png | Bin 7353 -> 8558 bytes .../InstructionSearchApi.java | 84 +++-- .../InstructionSearchPlugin.java | 9 +- .../model/InstructionSearchData.java | 340 +++++++++--------- .../model/MaskContainer.java | 56 +-- .../ui/InstructionSearchDialog.java | 169 ++++----- .../ui/InstructionSearchMainPanel.java | 19 +- .../ui/InstructionTable.java | 165 ++++++--- .../ui/InstructionTableCellRenderer.java | 2 +- .../ui/SearchInstructionsTask.java | 21 +- .../util/table/AddressPreviewTableModel.java | 51 +-- .../util/table/GhidraTableCellRenderer.java | 6 +- .../screenshot/GhidraScreenShotGenerator.java | 38 +- .../InstructionSearchTest.java | 19 +- .../FileFormats/data/ExtensionPoint.manifest | 1 - .../screenshot/AbstractSearchScreenShots.java | 11 +- .../InstructionPatternSearchScreenShots.java | 26 +- 24 files changed, 553 insertions(+), 485 deletions(-) diff --git a/Ghidra/Features/Base/data/ExtensionPoint.manifest b/Ghidra/Features/Base/data/ExtensionPoint.manifest index 711f68ce96..75640c0c6f 100644 --- a/Ghidra/Features/Base/data/ExtensionPoint.manifest +++ b/Ghidra/Features/Base/data/ExtensionPoint.manifest @@ -3,6 +3,7 @@ Demangler Exporter FieldFactory FieldMouseHandler +FileSystem StringHandler Loader SourceLanguage diff --git a/Ghidra/Features/Base/ghidra_scripts/YaraGhidraGUIScript.java b/Ghidra/Features/Base/ghidra_scripts/YaraGhidraGUIScript.java index 1ab0709218..bdec784ef7 100644 --- a/Ghidra/Features/Base/ghidra_scripts/YaraGhidraGUIScript.java +++ b/Ghidra/Features/Base/ghidra_scripts/YaraGhidraGUIScript.java @@ -4,9 +4,9 @@ * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at - * + * * http://www.apache.org/licenses/LICENSE-2.0 - * + * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. @@ -101,7 +101,7 @@ public class YaraGhidraGUIScript extends GhidraScript { state.getTool().showDialog(dialog); // Finally, load whatever instructions are selected in the listing. - dialog.loadInstructions(plugin); + dialog.loadInstructions(); } /********************************************************************************************* diff --git a/Ghidra/Features/Base/src/main/help/help/topics/Search/Search_Instruction_Patterns.htm b/Ghidra/Features/Base/src/main/help/help/topics/Search/Search_Instruction_Patterns.htm index 6c01549e03..681a8fdbfd 100644 --- a/Ghidra/Features/Base/src/main/help/help/topics/Search/Search_Instruction_Patterns.htm +++ b/Ghidra/Features/Base/src/main/help/help/topics/Search/Search_Instruction_Patterns.htm @@ -38,8 +38,9 @@ on an item in the table to mask it from the final search string.
Color-coding is used to indicate the code
- unit type. Instructions are displayed in
- blue, data items are tan.
@@ -52,10 +53,12 @@These tools provide ways to manipulate the Instruction Table and are discussed in detail below:
+-
- [
+] Clears - all masks.
- [
+ +] Deletes all items from the table.
- [
] Clears all masks.
- [
@@ -240,5 +243,8 @@] Masks all data (non-instructions).
Provided by: InstructionSearchPlugin
+
+
+