mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
GP-6032: Update Watches screenshots and documentation. Fix mentions of Threads window having step schedule.
This commit is contained in:
@@ -190,8 +190,8 @@ of the target into the future, without allowing the actual target to
|
||||
execute. Instead, we will allow an emulator to step forward, while
|
||||
reading its initial state from the live target. This allows you, e.g.,
|
||||
to experiment with various patches, or to force execution down a certain
|
||||
path. If you devise a patch, you can then apply it the live target and
|
||||
allow it to execute for real. <em>Interpolation</em> is similar, but
|
||||
path. If you devise a patch, you can then apply it to the live target
|
||||
and allow it to execute for real. <em>Interpolation</em> is similar, but
|
||||
from a snapshot that is in the past. It can help answer the question,
|
||||
“How did I get here?” It is more limited, because missing state for
|
||||
snapshots in the past cannot be recovered.</p>
|
||||
@@ -495,13 +495,13 @@ parser may not actually <em>use</em> the value of
|
||||
<p>Use the Watches window to set <code>RDI</code> to 1, then click <img
|
||||
src="images/resume.png" alt="resume button" /> <strong>Resume</strong>.
|
||||
Like before, the emulator will crash, but this time you should see “pc =
|
||||
00000000” in red. This probably indicates success. In the Threads
|
||||
window, you should see a schedule similar to
|
||||
<code>0:t0-{RDI=0x1);t0-16</code>. This tells us we first patched RDI,
|
||||
then emulated 16 machine instructions before crashing. When the parser
|
||||
function returned, it probably read a stale 0 as the return address, so
|
||||
we would expect a decode error at <code>00000000</code>. Step backward
|
||||
once to confirm this hypothesis.</p>
|
||||
00000000” in red. This probably indicates success. In the trace tab, you
|
||||
should see a schedule similar to <code>0:t0-{RDI=0x1);t0-16</code>. This
|
||||
tells us we first patched RDI, then emulated 16 machine instructions
|
||||
before crashing. When the parser function returned, it probably read a
|
||||
stale 0 as the return address, so we would expect a decode error at
|
||||
<code>00000000</code>. Step backward once to confirm this
|
||||
hypothesis.</p>
|
||||
</section>
|
||||
<section id="stubbing-external-calls" class="level3">
|
||||
<h3>Stubbing External Calls</h3>
|
||||
@@ -803,13 +803,13 @@ is ephemeral.</li>
|
||||
according to the assigned type.</li>
|
||||
</ul>
|
||||
<p>As you step, you may notice the schedule changes. It is displayed in
|
||||
the stepper’s subtitle as well as the Threads panel’s subtitle. P-code
|
||||
stepping is denoted by the portion of the schedule following the dot.
|
||||
the stepper’s subtitle as well as in the trace tab. P-code stepping is
|
||||
denoted by the portion of the schedule following the dot.
|
||||
<strong>NOTE</strong>: You cannot mix instruction steps with p-code op
|
||||
steps. The instruction steps always precede the p-code ops. If you click
|
||||
<strong>Step Into</strong> from the global toolbar in the middle of an
|
||||
instruction, the trailing p-code op steps will be removed and replaced
|
||||
with a single instruction step. In most cases, this intuitively
|
||||
steps. The instruction steps always precede the p-code op steps. If you
|
||||
click <strong>Step Into</strong> from the global toolbar in the middle
|
||||
of an instruction, the trailing p-code op steps will be removed and
|
||||
replaced with a single instruction step. In most cases, this intuitively
|
||||
“finishes” the partial instruction.</p>
|
||||
</section>
|
||||
</section>
|
||||
|
||||
Reference in New Issue
Block a user