NationalSecurityAgency/ghidra
47.5
Weak · 5 August 2026
1947k
lines of production code
Java
primary language
4
measurements over time
What this system is
This system is a comprehensive reverse engineering and binary analysis platform that integrates static disassembly, dynamic debugging, and emulation capabilities. It provides a unified interface for analyzing machine code across multiple architectures, managing debug traces, and inspecting runtime state through various debugger agents. The system also supports advanced analysis techniques including symbolic execution, machine learning-based function detection, and function similarity searching.
How it got here
2019 — processor and framework expansion
134 changes.
This period focused on significantly expanding Ghidra's architecture support by adding new processors such as RISC-V, TriCore, and various microcontrollers, alongside deepening analysis capabilities for existing architectures like x86 and ARM. The work also introduced major new features including a remote server, program diffing, and version tracking, while simultaneously refactoring the underlying framework to support theming, improved database handling, and enhanced build infrastructure.
2020–2021 — Debugger and Trace Analysis Features
85 changes.
This period focused on the comprehensive development of the Ghidra Debugger and Trace Modeling frameworks, introducing deep inspection capabilities such as P-code stepping, memory diffing, and emulation services. The work expanded support for various debugger agents (GDB, LLDB, Dbgeng) and processor architectures, while establishing a robust suite of UI components, automated tests, and documentation for these new features.
2022–2025 — Debugger and analysis expansion
96 changes.
This period focused on significantly expanding the debugger infrastructure, introducing a new service-based architecture, remote debugging capabilities, and advanced features like stack unwinding and taint analysis. Concurrently, the codebase grew to support a wide array of new processor architectures and introduced new analysis tools, including machine learning, symbolic execution, and data graph visualization.
2026 — Debugger and analysis feature expansion
13 changes.
This period focused on significantly expanding Ghidra's debugging capabilities, introducing new plugins for trace visualization, breakpoint management, and function emulation. The release also added support for the Qualcomm Hexagon architecture, Objective-C and Swift source languages, and Jython scripting, alongside server administration and utility scripts.
Features
AARCH64 language support expanded with Apple Silicon, Go, and ilp32 variants
The AARCH64 processor language definitions have been significantly expanded to support multiple compiler and platform variants. This includes a new Apple Silicon variant with specific calling conventions, a dedicated Golang compiler specification with updated register mapping and stack storage logic, and an ilp32 variant for 32-bit data models. Additionally, the configuration now includes support for QEMU launchers and integrates with external tools like IDA-PRO and DWARF for improved binary analysis and debugging capabilities.
Ghidra/Processors/AARCH64/data/languages · high confidence
Add 'Emulate Function' action and dialog
Users can now emulate a function by invoking a new 'Emulate Function' action, which opens a dialog to configure and run emulation. The dialog allows users to specify input variables, view output variables, and monitor the emulation state. The implementation includes a \FunctionEmulationHarness\ to manage the emulation lifecycle, a \DebuggerEmulateFunctionDialog\ for the UI, and supporting classes for input/output tables (\InputsTableModel\, \OutputsTableModel\) and variable row models (\InputRow\, \OutputRow\).
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/emulation, Ghidra/Debug/Debugger/src/screen/java/ghidra/app/plugin/core/debug/service · high confidence
Add 8048 (MCS-48) processor support
Ghidra now includes a new processor implementation for the 8048 (MCS-48) architecture. This update adds the necessary module files, including language specifications (.cspec, .pspec, .ldefs, .slaspec) and manual index, enabling Ghidra to analyze and decompile code for this microcontroller family.
Ghidra/Processors/8048 · high confidence
Add CP1600 processor language support
Added language support for the General Instruments CP1600 processor. This includes new specification files (.cspec, .ldefs, .pspec, .slaspec) that define the 16-bit big-endian architecture, register set (R0-R7), memory organization, and instruction set decoding rules for the Ghidra reverse engineering framework.
Ghidra/Processors/CP1600/data · high confidence
Add Dockerfile and supporting scripts for containerized Ghidra
Introduces a new Dockerfile and associated build scripts (build-docker-image.sh, entrypoint.sh) that enable running Ghidra in various modes (headless, GUI, server, BSIM, PyGhidra) within a containerized environment. The setup configures Java, Python, and necessary dependencies for building and running Ghidra in Docker.
docker · high confidence
Add Intel 8085 language support to Ghidra
Ghidra now supports the Intel 8085 processor architecture. This change introduces the necessary specification files (.cspec, .ldefs, .pspec, .slaspec) to define the processor's registers, memory spaces, instruction set, and calling conventions, enabling Ghidra to analyze and decompile 8085 binaries.
Ghidra/Processors/8085/data · high confidence
Add LLDB debugger agent and Python integration for Ghidra
The LLDB debugger agent module has been added to Ghidra, providing a Python-based bridge between LLDB and Ghidra's Trace RMI system. This includes the core Python package (ghidralldb) with modules for architecture mapping, command handling, and event hooks, alongside a generated XML schema for data serialization. The module also includes comprehensive HTML and XML help documentation covering local, remote, macOS kernel, and Android NDK setup and usage scenarios, enabling users to debug user-space targets on various platforms directly through Ghidra.
Ghidra/Debug/Debugger-agent-lldb · high confidence
Add LLDB debugger support scripts
Introduced new utility scripts for the LLDB debugger agent: a PowerShell script (lldbsetuputils.ps1) and a Bash script (lldbsetuputils.sh) that construct LLDB command-line arguments for various debugging scenarios (user-mode, platform, remote, and pip-install). A corresponding LLDB initialization template (lldbinit\_template) was also added to define the initial connection and synchronization commands. These changes enable Ghidra to launch and configure LLDB-based debugging sessions with proper argument passing and environment setup.
Ghidra/Debug/Debugger-agent-lldb/data/support · high confidence
Add NDS32 processor support
Adds support for the NDS32 processor architecture to Ghidra. This includes language definitions for big and little-endian 32-bit variants, processor and compiler specifications, instruction set definitions, and DWARF register mappings. It also introduces a custom analyzer to recover the global pointer (GP) register value from the \\_SDA\BASE\\ symbol and implements an ELF relocation handler for NDS32-specific relocations (e.g., HI20, LO12S0). Additionally, emulator tests are added to verify the implementation.
Ghidra/Processors/NDS32 · high confidence
Add SampleTablePlugin example plugin
A new example plugin named SampleTablePlugin has been added to the Ghidra Extensions directory. This includes the core Java classes for a table-based plugin that displays function statistics and search results, along with the necessary manifest, properties, and help files to register and display the plugin within the Ghidra environment.
Ghidra/Extensions/SampleTablePlugin · high confidence
Add SleighDevTools extension for external disassembly
The SleighDevTools extension is introduced, providing an 'External Disassembly' field in the listing view. This feature allows Ghidra to invoke external disassemblers (such as the GNU disassembler) to generate disassembly text for supported architectures, with the specific implementation and configuration files for this extension located in the SleighDevTools module.
Ghidra/Extensions/SleighDevTools · high confidence
Add Symbolic Summary Z3 extension for P-Code emulation
The Symbolic Summary Z3 extension is now available as a standalone Ghidra extension. This adds support for P-Code emulation using the Z3 theorem prover, allowing users to perform symbolic execution and generate symbolic summaries. The extension includes the Z3 native libraries and Java bindings (version 4.13.0) for Windows, macOS, and Linux, and provides the necessary infrastructure to integrate with the P-Code debugger for advanced analysis.
Ghidra/Extensions/SymbolicSummaryZ3 · high confidence
Add Wildcard Assembler feature for flexible instruction assembly
Ghidra now includes a Wildcard Assembler feature that allows users to assemble instructions with specific tokens replaced by wildcards. This new API enables scripts and plugins to generate all possible encodings for a given instruction template, returning metadata about each wildcard's bit location and derivation expression. The feature is currently available as an API for Ghidra scripts and plugins, with example scripts provided to demonstrate usage.
Ghidra/Features/WildcardAssembler · high confidence
Add debugger copy and export actions
The debugger plugin now includes a new 'copying' module that provides user-facing actions to copy trace data into Ghidra programs. This includes exporting trace views, and copying memory state (colors), instructions, data, dynamic data, and labels from a trace into the current or a new program via a dedicated dialog.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/copying · high confidence
Add drgn debugger agent for attaching to processes, core dumps, and the Linux kernel
The Ghidra debugger now supports Meta's drgn engine for debugging. Users can attach to a running local process, load a core dump, or debug the local Linux kernel using the new drgn launchers. This integration provides a Python-based debugging experience within Ghidra, allowing users to explore process state, memory, and stack frames via the drgn engine.
Ghidra/Debug/Debugger-agent-drgn · high confidence
Add language support for Motorola 6809, Hitachi 6309, and 6805 microprocessors
Ghidra now supports the Motorola 6809, Hitachi 6309, and 6805 microprocessors. This update introduces new language definitions and SLEIGH specifications that enable the disassembler and decompiler to correctly parse instructions, handle addressing modes, and manage processor state for these architectures. The 6809 and 6309 support includes definitions for register exchange, stack operations, and status flags, while the 6805 support adds specific memory and register mappings for that microcontroller family.
Ghidra/Processors/MC6800/data · high confidence
Add side-by-side memory diff view for trace snapshots
A new DebuggerTraceViewDiffPlugin is introduced, enabling users to compare raw memory states between two points in time within a trace. The plugin provides a side-by-side diff view, allowing users to select two timestamps and navigate through memory differences using previous/next actions.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/diff · high confidence
Add support for exporting and serving data types as Volatility ISF JSON
Ghidra now includes a new ISF (Interface Specification Format) server and export capabilities. Users can export selected data types from the Data Type Manager to ISF JSON files via a new 'Export Data Types (ISF)' action. Additionally, an ISF server can be launched to serve type information over a network, supporting requests for full exports, type lookups, and symbol enumeration. This enables integration with tools like Volatility that consume ISF JSON for debugging and memory analysis.
Ghidra/Debug/Debugger-isf · high confidence
Add support for importing Tenet and Tenet++ debug trace files
Ghidra now includes new \TenetLoader\ and \TenetPlusPlusLoader\ components that allow users to import and analyze debug trace files in the Tenet and Tenet++ formats. These loaders validate file content to ensure they are valid traces before processing, and include corresponding unit tests to verify correct behavior for valid and invalid inputs.
Ghidra/Debug/Debugger-importers · high confidence
Add support for the Tensilica Xtensa processor
Ghidra now supports the Tensilica Xtensa architecture, enabling the analysis of binaries compiled for this processor. This includes a new ELF relocation handler to process Xtensa-specific relocations, emulation state modifiers to handle register window rotation and restoration during execution, and a Pcode userop library for the same emulation logic. The release also includes the necessary language specifications, instruction sets, and pattern files to support Xtensa code analysis.
Ghidra/Processors/Xtensa · high confidence
Add variable value hover plugin
A new VariableValueHoverPlugin and its associated service classes (VariableValueHoverService, VariableValueTable, VariableValueRow, VariableValueUtils) have been added to the debug debugger GUI stack/vars package. This plugin provides a hover service that displays live variable values in a tooltip when hovering over variables in the listings or decompiler during debugging sessions.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/stack/vars · high confidence
Added 65C02 processor support and corrected 6502 instruction semantics
Ghidra now supports the Rockwell 65C02 microcontroller family alongside the standard 6502. This includes new language definitions and SLEIGH specifications for the 65C02, adding support for extended opcodes such as BBR, BBS, BRA, PHX, PLX, PHY, PLY, RMB, and SMB. The update also corrects several 6502 instruction behaviors, including fixes for Zero Page indexed addressing, the BRK opcode, the TSX instruction, and the carry flag handling for CMP, CPX, and CPY instructions.
Ghidra/Processors/6502/data · high confidence
Added AARCH64 relocation and emulation support for ELF, Mach-O, and COFF formats
Ghidra now supports AARCH64 binaries in ELF, Mach-O, and COFF formats. For ELF files, the new AARCH64\_ElfRelocationHandler and AARCH64\_ElfExtension classes handle various relocation types (including PLT thunks and GOT allocations) and program/section header extensions. For Mach-O files, the AARCH64\_MachoRelocationHandler processes relocations like PAGE21 and BRANCH26. For COFF files, the AARCH64\_CoffRelocationHandler handles section and relative relocations. Additionally, the AARCH64EmulateInstructionStateModifier and Aarch64PcodeUseropLibraryFactory provide emulation capabilities for AARCH64 instructions, including TBL/TBX and various integer/float operations. Tests have been added to verify the emulator behavior.
Ghidra/Processors/AARCH64 · high confidence
Added ARM processor support for ELF, COFF, and Mach-O relocation handling
Ghidra now supports importing and relocating ARM and Thumb binaries in ELF, COFF, and Mach-O formats. This includes new handlers for processing ELF relocations (such as R\_ARM\_PC24, R\_ARM\_ABS32, and R\_ARM\_THUMB\_JUMP11/8), COFF relocations for Windows PE, and Mach-O relocations for macOS/iOS binaries. The update also introduces an ARM-specific ELF extension to handle PC bias adjustments and TMode register state for correct Thumb/ARM mode switching during import.
Ghidra/Processors/ARM · high confidence
Added BSim Feature Visualizer plugin for analyzing function features
A new BSim Feature Visualizer plugin has been introduced, providing a table that lists and visualizes BSim features (DATA\_FLOW, CONTROL\_FLOW, COMBINED, DUAL\_FLOW, and COPY\_SIG) for the current function. The plugin displays a table of features with columns for sequence numbers, addresses, base varnodes, and pcode operations. Users can right-click a row to visualize the corresponding control and data flow graphs, and the plugin supports dark theme color customization via a new properties file. The feature also includes help documentation and a table of contents entry for the Ghidra help system.
Ghidra/Features/BSimFeatureVisualizer · high confidence
Added BSim function matching to Version Tracking
The Version Tracking feature now includes a new 'BSim Function Matching' correlator. This new algorithm discovers functional matches by comparing data-flow feature vectors and call graph similarities between source and destination programs. It uses a multi-stage process: generating function nodes, binning them for efficient lookup, selecting high-confidence seeds, and then extending those seeds to find additional matches. The implementation includes new classes for managing function nodes, potential pairs, and neighborhood generation, along with a pre-condition validator to ensure the decompiler is available.
Ghidra/Features/VersionTrackingBSim/src/main/java/ghidra/feature/vt · high confidence
Added BSimElasticPlugin to enable Elasticsearch as a backend for BSim
The BSimElasticPlugin extension has been added to Ghidra, providing support for using Elasticsearch as a backend database for BSim. This plugin includes the necessary Java classes to integrate with Elasticsearch 8.19.7, including a custom tokenizer and script engine for vector comparison. Users can now configure BSim to store and query signatures in an Elasticsearch cluster by specifying the \elastic://\ or \https://\ protocol in the database URL. The plugin also bundles the \lsh\ plugin for Elasticsearch, which must be installed on each node of the cluster.
Ghidra/Extensions/BSimElasticPlugin · high confidence
Added Cypress M8C processor support
Ghidra now supports the Cypress M8C microcontroller family. This change adds the necessary language and processor specification files (including sleigh, compiler spec, and memory maps) to enable decompilation and analysis of M8C binaries.
Ghidra/Processors/M8C · high confidence
Added DATA processor support for raw binary data files
Ghidra now supports loading raw binary data files as data rather than just executable code. This change introduces a new 'DATA' processor with language definitions for both big and little-endian 64-bit data, along with compiler specs for 16, 32, and 64-bit pointer sizes. A new Java helper class (DataLanguageHelper) and a corresponding Ghidra script (LoadDataScript) are added to facilitate loading these data files into the Ghidra project.
Ghidra/Processors/DATA · high confidence
Added DEX constant pool and Pcode injection support for Dalvik analysis
Users can now analyze Android DEX files with improved handling of the DEX constant pool and method/field references. New Java classes (ConstantPoolDex, InjectPayloadDexParameters, InjectPayloadDexRange, PcodeInjectLibraryDex) implement the constant pool mapping and Pcode injection logic required to simulate DEX register stacks and parameter passing. This enables Ghidra to correctly interpret Dalvik bytecode structures, including support for Android 12 and various Android release versions as indicated by the associated SLEIGH specifications.
Ghidra/Processors/Dalvik · high confidence
Added DbViewer diagnostic tool for inspecting Ghidra database files
A new diagnostic application called DbViewer has been added to the DebugUtils feature. This standalone tool allows users to open and inspect Ghidra database files (GBF), displaying their tables and records in a graphical interface. The implementation includes the necessary manifest and certification files to package this utility within the Ghidra distribution.
Ghidra/Features/DebugUtils · high confidence
Added GDB scripts for dynamic debugging of Win32 binaries via Wine
Added new GDB scripts to enable dynamic debugging of 32-bit Windows binaries running under Wine on Linux. This includes \wine32\_info\_proc\_mappings.gdb\ and \getpid-linux-i386.gdb\ to fetch process memory mappings from a remote Wine target, and \remote-proc-mappings.py\ to parse \/proc/{pid}/maps\ data. Additionally, \fallback\_info\_proc\_mappings.gdb\ and \fallback\_maintenance\_info\_sections.gdb\ provide fallbacks for 64-bit address spaces and section information. These scripts allow Ghidra to correctly map memory regions for Wine-based debugging sessions.
Ghidra/Debug/Debugger-agent-gdb/data/scripts · high confidence
Added GnuDisassembler C implementation for binary disassembly
The GnuDisassembler module now includes the core C implementation (disasm\_1.c and gdis.h) that wraps the BFD/libopcodes libraries to perform binary disassembly. This adds the underlying capability to parse and disassemble machine code into human-readable assembly instructions, supporting architecture and machine-type selection.
GPL/GnuDisassembler · high confidence
Added GnuDisassembler and DMG modules with licensing and metadata
The GnuDisassembler and DMG modules have been added to the GPL area. The GnuDisassembler module includes build instructions, test data, and a .gitignore file, while the DMG module includes a README, a server memory configuration file, and a certification manifest detailing the GPL 3 licensed dependencies such as hfsx.jar and llio DLLs. Additionally, a set of modified Nuvola folder icons (closedDescendantsInView, closedFolder, closedFolderArchive, etc.) have been added to the icons directory.
GPL · high confidence
Added HCS12, HC12, and HCS12X processor language support
Ghidra now supports the Freescale HCS12, HC12, and HCS12X microcontroller families. This change introduces the necessary language specification files (.cspec, .pspec, .slaspec, .ldefs, and .opinion) to enable disassembly, decompilation, and debugging for these architectures. The update includes definitions for memory organization, interrupt vectors, and register sets, allowing users to analyze firmware for these specific 8-bit and 24-bit microcontrollers.
Ghidra/Processors/HCS12/data · high confidence
Added HCS12/HCS12X processor support and ELF memory remapping
Ghidra now supports the HCS12, HCS12X, and HC12 processor architectures. This includes new analyzer plugins for calling conventions and disassembly, as well as ELF loader extensions that correctly map memory segments and sections for these architectures, ensuring that non-loaded sections are properly handled during import.
Ghidra/Processors/HCS12 · high confidence
Added HFS+ B-tree and decompressed attribute parsing support for DMG files
Users can now parse HFS+ B-tree structures (header, map, node, and user data records) and read extended attributes such as \com.apple.decmpfs\ from DMG images. This includes new classes for B-tree navigation and constants for compression types and states, enabling deeper inspection of file system metadata within DMG containers.
GPL/DMG · high confidence
Added Intel MCS-96 microcontroller language support
Ghidra now supports the Intel MCS-96 microcontroller family. This update adds the necessary language definition files (.cspec, .ldefs, .pspec, .sinc, .slaspec) and a manual index (.idx) to enable decompilation and analysis of MCS-96 firmware. The configuration defines the processor's 16-bit little-endian architecture, memory map, register set, and instruction set, allowing users to load and reverse-engineer binaries for this specific microcontroller family.
Ghidra/Processors/MCS96/data · high confidence
Added JVM language support in Ghidra
Added support for the Java Virtual Machine (JVM) in Ghidra. This includes new language specification files (JVM.cspec, JVM.pspec, JVM.ldefs, JVM.slaspec) that define the JVM architecture, data organization, and instruction set. The update also adds an ExtensionPoint.manifest to register the JVM processor and a manual index (JVM.idx) for documentation. This enables Ghidra to analyze and decompile Java bytecode.
Ghidra/Processors/JVM/data · high confidence
Added Java debugger launchers for local, attach, and PID-based connections
Users can now launch or attach to Java and Dalvik targets directly from the Ghidra debugger interface. Three new launcher scripts have been added: 'local-java' for launching a local Java process, 'attach-java' for connecting to a remote JVM by host and port, and 'bypid-java' for attaching to a running process by its PID. These launchers support both JVM and Dalvik architectures and allow configuration of classpaths, arguments, and connection timeouts.
Ghidra/Debug/Debugger-jpda/data · high confidence
Added LoongArch processor support with 32-bit and 64-bit variants
Ghidra now supports the LoongArch architecture, introducing new language specifications and instruction sets for both 32-bit (ilp32f, ilp32d) and 64-bit (lp64f, lp64d) variants. This update includes compiler specifications (.cspec) defining data organization and calling conventions, processor specifications (.pspec) for register and program counter definitions, and extensive instruction definitions (.sinc) covering base arithmetic, floating-point operations, and vector extensions (LASX, LBT, LSX). The language definitions (.ldefs) and ELF loader opinions (.opinion) are also added to enable automatic detection and correct parsing of LoongArch binaries.
Ghidra/Processors/Loongarch/data · high confidence
Added MCS-96 processor support
The MCS-96 processor architecture is now supported in Ghidra. This change introduces the necessary language definitions, compiler specifications, and supporting files to enable analysis and decompilation for the MCS-96 microcontroller family.
Ghidra/Processors/MCS96 · high confidence
Added Memory vs. Time visualization for debug traces
Introduced a new 'Memview' plugin and associated UI components (panel, table, provider) that visualize memory events over time. This feature allows users to view and navigate through memory regions, modules, threads, and breakpoints across different points in a debug trace, with support for filtering and zooming.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/memview · high confidence
Added Microsoft Code Analyzer feature with RTTI and exception handling support
The MicrosoftCodeAnalyzer feature was added to Ghidra, introducing new scripts and commands to analyze Windows PE binaries for C++ RTTI (Run-Time Type Information) and exception handling data. This includes the \FixUpRttiAnalysisScript\ and \RunRttiAnalyzerScript\ to process RTTI structures, alongside new background commands like \CreateTypeDescriptorBackgroundCmd\ and \CreateEHCatchHandlerMapBackgroundCmd\ to create and validate data types for type descriptors and catch handlers. The feature also includes utility classes such as \EHDataTypeUtilities\ and models like \TypeDescriptorModel\ to support the analysis of Microsoft-specific debugging and type information.
Ghidra/Features/MicrosoftCodeAnalyzer · high confidence
Added Motorola 68000 and PA-RISC processor support with emulation and analysis
Users can now analyze and emulate code for the Motorola 68000 and PA-RISC architectures. This includes new analysis capabilities for the 68000, such as constant propagation and switch table recovery, alongside emulation support for both the 68000 and PA-RISC processors. The update also introduces a new CPU32 processor variant with full instruction set support and adds test coverage for these processor implementations.
Ghidra/Processors/68000 · high confidence
Added Motorola 68000 processor language support
Added language support for the Motorola 68000 series, including variants for the 68020, 68030, 68040, Coldfire, and CPU32 processors. This includes new compiler specification files (.cspec) defining data organization and calling conventions, processor specifications (.pspec) for emulation, SLEIGH instruction definitions (.sinc), and DWARF register mappings (.dwarf) to enable accurate disassembly and debugging of binaries for these architectures.
Ghidra/Processors/68000/data/languages · high confidence
Added Nested Code Layout for Function Graphs
A new 'Nested Code Layout' is now available for Function Graphs, utilizing the decompiler to visualize code nesting based on conditional logic. This layout introduces options to route edges around vertices to reduce visual clutter and allows users to dim return edges for better clarity. The change includes the necessary provider, layout implementation, and rendering logic to support this new visualization mode.
Ghidra/Features/FunctionGraphDecompilerExtension · high confidence
Added Objective-C and Swift source language support
Ghidra now includes new source language modules for Objective-C and Swift. The Objective-C module provides improved support for binaries written in the Objective-C programming language, including analyzers to discover type metadata and analyze message sends, as well as architecture-specific call fixups for the AArch64 processor. The Swift module is also added to the codebase.
Ghidra/Features/Objective-C, Ghidra/Features/Swift · high confidence
Added P-Code test suite for bit manipulation and arithmetic operations
The SleighDevTools pcodetest framework in the c\_src directory now includes comprehensive C test cases for bit manipulation (get/set/clear/toggle bits) and arithmetic/logical/comparison operations across various integer sizes (1, 2, 4, 8, and long long) as well as float and double types. These new test files provide the reference implementations and expected outcomes used to validate the P-Code generation for these fundamental operations.
_Ghidra/Extensions/SleighDevTools/pcodetest/c\src · high confidence
Added PA-RISC 32-bit big-endian language support
Ghidra now supports the PA-RISC 32-bit big-endian architecture. This change introduces the complete language definition, including the SLEIGH instruction set description, compiler specifications, processor specifications, and pattern matching rules. Users can now analyze 32-bit big-endian PA-RISC binaries, with support for ELF and System Object Model (SOM) file formats, enabling decompilation and disassembly of code for this processor family.
Ghidra/Processors/PA-RISC/data · high confidence
Added R\*-Tree diagnostics plugin for trace memory visualization
A new diagnostic plugin has been added to the Ghidra debugger, introducing an R\*-Tree visualization tool for trace memory. This feature provides a tree view and a graphical plot of the memory space, allowing users to navigate the hierarchical structure of memory regions and inspect their spatial relationships within the trace database.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/internal · high confidence
Added SPARC V9 language support and DWARF register mappings
Ghidra now supports the SPARC V9 architecture with both 32-bit and 64-bit variants, including new language definition files (.ldefs, .pspec, .cspec, .sinc) that define the instruction set, calling conventions, and register windows. Additionally, a new DWARF register mapping file (Sparc.dwarf) has been added to map SPARC registers to standard DWARF numbers, improving debug information compatibility.
Ghidra/Processors/Sparc/data · high confidence
Added SleighDevTools scripts for external disassembly comparison and block disassembly
Two new scripts are now available in the SleighDevTools extension: CompareSleighExternal.java, which compares Sleigh disassembly against external disassembly results, and GNUDisassembleBlockScript.java, which performs block disassembly using the GNU external disassembler. These additions support development and debugging workflows for Sleigh and external disassemblers.
_Ghidra/Extensions/SleighDevTools/ghidra\scripts · high confidence
Added Source Code Lookup plugin for Eclipse integration
A new Source Code Lookup plugin has been added to Ghidra, enabling users to navigate from a symbol in the Ghidra Listing or Decompiler to the corresponding source code in an Eclipse CDT project. This feature requires the Eclipse GhidraDev plugin and the Eclipse CDT plugin to be installed. The plugin communicates with Eclipse via a socket connection to perform symbol lookups, supporting both the Listing and Decompiler views.
Ghidra/Features/SourceCodeLookup · high confidence
Added SuperH SH-1, SH-2, and SH-2A language support
Ghidra now supports the SuperH SH-1, SH-2, and SH-2A processor architectures. This update introduces language specifications and compiler specifications that define the calling conventions, register sets, and data organization for each variant. The SH-2A variant specifically includes support for floating-point registers and FPU state, enabling more accurate decompilation and analysis of binaries targeting these specific SuperH cores.
Ghidra/Processors/SuperH/data/languages · high confidence
Added SuperH4 processor language support for big and little endian 32-bit architectures
Ghidra now supports the SuperH4 (SH4) processor architecture with both big and little endian variants. This change introduces the necessary language definition files (.ldefs), compiler specifications (.cspec), and SLEIGH instruction definitions (.sinc) to enable disassembly, decompilation, and debugging of SuperH4 binaries. The update also includes pattern matching rules for function start detection and manual indexing for the SH-4 software reference.
Ghidra/Processors/SuperH4/data · high confidence
Added SuperH4 processor support
Ghidra now supports the SuperH4 processor architecture. This change introduces the SuperH4 processor module, including language definitions, compiler specifications, and pattern files. It also adds specific ELF relocation handlers for SuperH4, enabling the analysis of ELF binaries for this architecture, and includes emulator tests to verify instruction execution.
(repo-wide) · high confidence
Added TI MSP430 and MSP430X processor support to Ghidra
Added new language and processor support for the Texas Instruments MSP430 and MSP430X 16/32-bit microcontrollers. This includes SLEIGH specifications for instruction decoding, processor specifications defining register maps and volatile memory ranges, compiler specifications for the MSP-ABI, DWARF register mappings, and language definitions. The implementation supports both 16-bit (MSP430) and 32-bit (MSP430X) architectures, enabling Ghidra to analyze firmware for these embedded devices.
_Ghidra/Processors/TI\MSP430/data · high confidence
Added TRICORE instruction set manual indexes
Added index files for the TRICORE processor module, providing page references for instruction set documentation. The new files, tricore.idx and tricore2.idx, map TRICORE assembly mnemonics (such as ADD, CALL, and LOAD) to their corresponding pages in the official Infineon and TriCore architecture manuals, enabling users to quickly locate detailed instruction definitions within the integrated documentation.
Ghidra/Processors/tricore/data/manuals · high confidence
Added Tensilica Xtensa processor language support
Added language support for the Tensilica Xtensa 32-bit processor, including both little-endian and big-endian variants. This introduces new language definitions, compiler specifications, and instruction set definitions that enable Ghidra to parse, disassemble, and decompile code for this architecture. The implementation includes support for custom (CUST) and flexible-length (FLIX) instructions, and adjusts the default calling convention to be compatible with CALL0 in most cases.
Ghidra/Processors/Xtensa/data/languages · high confidence
Added Toy processor analyzer
Introduced a new constant propagation analyzer for the Toy processor, enabling automatic analysis of programs targeting this architecture within Ghidra.
Ghidra/Processors/Toy · high confidence
Added Trace Export Plugin for Debugger
A new TraceExportPlugin has been introduced in the debugger GUI export module, enabling users to export debugger traces as compressed GZT files via a new 'Export Trace' menu action. This adds a concrete export capability to the product, allowing trace data to be saved to disk in a specific format.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/export · high confidence
Added V850 processor language support
Ghidra now supports the Renesas V850 architecture, including the V850E3 variant. This adds the necessary SLEIGH specifications, compiler specs, and instruction definitions to enable decompilation and analysis of V850 binaries.
Ghidra/Processors/V850/data/languages · high confidence
Added bundle\_examples extension with OSGi dynamic modularity demonstrations
A new 'bundle\_examples' extension has been added to Ghidra to demonstrate dynamic modularity (OSGi) features in scripting. This includes example scripts and Java libraries that show how to manage inter-bundle and intra-bundle dependencies, use bundle activators for lifecycle management, and configure package imports via both annotations and manifest files.
_Ghidra/Extensions/bundle\examples · high confidence
Added compile-time validation for database annotation processors
The AnnotationValidator module introduces a new Java annotation processor that performs compile-time validation on database-related annotations. The processor enforces constraints on \@DBAnnotatedField\ and \@DBAnnotatedColumn\ usage, ensuring fields are static, non-final, and correctly typed. It also validates that \@DBAnnotatedObject\ is applied to concrete, non-abstract classes that extend \DBAnnotatedObject\. The module includes the processor implementation, validation logic for fields and columns, and service provider configuration.
Ghidra/Debug/AnnotationValidator · high confidence
Added comprehensive MIPS language definitions and instruction sets
Added new language definition files for the MIPS processor, including \mips.ldefs\ which registers various MIPS variants (32/64-bit, big/little endian, R6, MIPS16e) with their respective compiler specifications and external tool mappings. The update also introduces \MIPS.opinion\ to handle automatic processor identification for ELF, PE, and COFF formats by matching ELF header flags and architecture bits. Additionally, \mips.dwarf\ provides register mappings for debug information, while \mips.sinc\, \mips32.sinc\, and \mips16.sinc\ define the assembly syntax and instruction set for standard, Release 6, and 16-bit modes respectively.
Ghidra/Processors/MIPS/data/languages · high confidence
Added dbgeng debugger agent with full Python implementation and documentation
Introduced the \Debugger-agent-dbgeng\ module, providing a Python-based debugger agent for the Windows Debugger Engine (dbgeng.dll). This includes a complete Python implementation (\src/main/py/src/ghidradbg/\) that interfaces with \pybag\ and \dbgmodel\ to support local, remote, and kernel debugging scenarios. The release also includes comprehensive help documentation (\help/topics/dbgeng/\), a table of contents (\TOC\_Source.xml\), and licensing/manifest files (\Module.manifest\, \certification.manifest\) to support the new debugging capabilities.
Ghidra/Debug/Debugger-agent-dbgeng · high confidence
Added dbgeng support scripts for local, remote, and kernel debugging
Added a new set of Python and shell utility scripts to the \Ghidra/Debug/Debugger-agent-dbgeng/data/support\ directory to facilitate debugging with the dbgeng engine. These include \local-dbgeng.py\ and \local-dbgeng-ext.py\ for attaching to or creating local processes, \remote-dbgeng.py\ for remote debugging, \kernel-dbgeng.py\ for kernel-mode debugging, and \standalone\_listener.py\ for standalone listener operations. The addition also includes \dbgssetuputils.ps1\ and \dbgssetuputils.sh\ for environment setup and pip installation, enabling the debugger agent to connect to the Ghidra Trace RMI service and manage debugging sessions.
Ghidra/Debug/Debugger-agent-dbgeng/data/support · high confidence
Added decompiler module manifest and documentation files
Added the Module.manifest and README.md files to the decompiler feature directory, establishing the module's licensing and documentation structure.
Ghidra/Features/Decompiler · high confidence
Added decompiler-dependent feature module with taint tracking and text search capabilities
Introduced a new 'DecompilerDependent' feature module containing the implementation for Decompiler Taint Tracking and the Decompiler Text Finder. This includes scripts to export PCode facts for external analysis engines, a data type reference finder that supports searching for structure fields by name or offset, and help documentation for the new tools. The module also defines extension points for the taint state and data type reference finding, along with theme properties for highlighting taint paths.
Ghidra/Features/DecompilerDependent · high confidence
Added eBPF processor support for 64-bit big-endian programs
Ghidra now supports analyzing eBPF programs compiled for big-endian architectures. This change introduces the necessary language specifications (cspec, pspec, ldefs, etc.) to enable disassembly, decompilation, and debugging (DWARF mappings) for big-endian eBPF binaries, complementing the existing little-endian support.
Ghidra/Processors/eBPF/data · high confidence
Added help documentation for the Debugger Static Mapping Plugin
Users can now access comprehensive help documentation for the Debugger Static Mapping Plugin. This new HTML help page explains the concept of static mappings, which map dynamic address ranges to static program databases, and details the table columns (Dynamic Address, Static Program, Static Address, Length, Shift, Lifespan) and available actions (Select Rows, Add Mapping, Remove Mapping) for managing these mappings manually.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerStaticMappingPlugin · high confidence
Added help documentation for the Debugger Threads plugin
Users can now view detailed documentation for the Debugger Threads plugin, which explains how to navigate thread contexts, interpret table columns (such as PC, function, state, and timeline plot), and activate threads via double-clicking.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerThreadsPlugin · high confidence
Added help documentation for the Debugger Time Overview plugin
A new help page was added for the Debugger Time Overview plugin, explaining its sidebars for the Dynamic Listing, the Trace Overview bar for event history, and the Trace Selection sidebar for zooming and moving through time spans.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerTimeOverviewPlugin · high confidence
Added help documentation for the Debugger Watches plugin
Added the complete help file for the Debugger Watches plugin, detailing how to monitor variable values using Sleigh expressions, interpret color-coded changes, and utilize table columns like Symbol and Representation. The documentation also covers available actions such as applying data types to listings, adjusting type settings, selecting memory ranges or reads, and enabling edits to modify raw values in the watch table.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerWatchesPlugin · high confidence
Added help documentation for the Dynamic Listing feature
Users can now access comprehensive help documentation for the Dynamic Listing feature, which allows viewing and editing annotated memory contents from a target or trace. The new documentation explains how dynamic listings differ from static ones (e.g., time-based navigation, cloning, and synchronization), how to manage trace tabs, and how to use actions like 'Go To' with various radix modes.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerListingPlugin · high confidence
Added help documentation for the Emulation Service plugin
Added the 'DebuggerEmulationServicePlugin.html' help file, which documents the new emulation capabilities for the Trace Manager. This includes actions for 'Emulate Program' (launching purely emulated traces), 'Add Emulated Thread', and 'Emulate Function' (with a dedicated dialog for harnessing and running functions). The documentation also covers emulator configuration, cache invalidation, and detailed descriptions of the 'Emulate Function' dialog options, including handling of vararg arguments, heap initializations, and input/output tables.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerEmulationServicePlugin · high confidence
Added help documentation for the P-code Stepper plugin
A new help page was added for the Debugger: P-code Stepper plugin, detailing its two-pane interface for viewing p-code operations and unique variables. The documentation explains that p-code stepping is integrated into the emulation framework, allowing users to navigate and inspect machine state at the p-code level. It describes the columns in the unique variables table (Ref, Unique, Bytes, Value, Type, Representation) and the available actions to step forward or backward through the emulation trace.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerPcodeStepperPlugin · high confidence
Added help documentation for the Trace View Diff Plugin
The release includes new help documentation for the Trace View Diff Plugin, which allows users to compare machine state between two points in time. The documentation explains how to use the 'Compare' action to identify memory changes, including how to capture baselines, use emulation for offline comparison, and navigate between differences in the dynamic listing.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerTraceViewDiffPlugin · high confidence
Added help documentation for the Variable Value Hover Plugin
A new help page titled 'Debugger: Variable Hovers' has been added to document the VariableValueHoverPlugin. This plugin provides hover tooltips in the Static Listing, Dynamic Listing, and Decompiler windows, displaying variable values, types, and stack frame information. The documentation explains how the service attempts to unwind the stack to find call records for dynamic variables, and details the various rows (such as Name, Frame, Storage, Type, Instruction, Location, Bytes, Integer, Value, Status, Warnings, and Error) that may appear in the hover tip.
Ghidra/Debug/Debugger/src/main/help/help/topics/VariableValueHoverPlugin · high confidence
Added initial analysis and ELF support for Microchip PIC microcontrollers
This change introduces the foundational components for analyzing Microchip PIC microcontrollers (PIC-12, PIC-16, PIC-17, PIC-18, and PIC-24/30/33 families). The update adds new analyzer classes (e.g., Pic12Analyzer, Pic16Analyzer, Pic18Analyzer, Pic24DInitAnalyzer, PicSwitchAnalyzer) that handle instruction decoding, constant propagation, and switch table resolution for these architectures. Additionally, it introduces ELF extension and relocation handling for PIC30/dsPIC30F processors, enabling the import and analysis of ELF binaries for these devices.
Ghidra/Processors/PIC · high confidence
Added instruction manual indexes for AVR8 and AVR32 architectures
Added new index files (AVR8.idx and AVR32.idx) that map instruction mnemonics to their corresponding pages in the Atmel technical manuals. This enables users to quickly locate documentation for specific instructions when browsing the manual for AVR8 and AVR32 processors.
Ghidra/Processors/Atmel/data/manuals · high confidence
Added language support for Android 12 and 13 DEX files
Ghidra now supports the Dalvik Executable (DEX) format for Android 12 and 13. This update adds specific language definitions and SLEIGH specifications for Android 12 and 13, enabling the disassembly and analysis of DEX files from these Android versions. The changes include new language variants (DEX\_Android12, DEX\_Android13) and corresponding SLEIGH instruction sets that reflect the instruction set changes in those Android releases.
Ghidra/Processors/Dalvik/data · high confidence
Added language support for Atmel AVR32A processor
Added new language definitions and SLEIGH specifications for the Atmel AVR32A processor, including \avr32a.ldefs\, \avr32a.pspec\, \avr32a.cspec\, and \avr32a.opinion\ files. The update also introduces SLEIGH instruction definitions for arithmetic, bit, coprocessor interface, data transfer, and DSP operations, enabling Ghidra to parse, disassemble, and decompile code for this specific 32-bit big-endian architecture.
Ghidra/Processors/Atmel/data/languages · high confidence
Added language support for HC05, HC08, and HCS08 microcontrollers
Added processor specifications, compiler specifications, language definitions, SLEIGH assembly specifications, and manual indexes for the HC05, HC08, and HCS08 microcontroller families. This enables Ghidra to parse, disassemble, and analyze code for these specific 8-bit and 16-bit Motorola/Freescale processors, including variant-specific memory maps and register definitions.
Ghidra/Processors/HCS08/data · high confidence
Added language support for Microchip PIC-12, PIC-16, and PIC-24/30/33/34/35/36/37/38/39/40/41/42/43/44/45/46/47/48/49/50/51/52/53/54/55/56/57/58/59/60/61/62/63/64/65/66/67/68/69/70/71/72/73/74/75/76/77/78/79/80/81/82/83/84/85/86/87/88/89/90/91/92/93/94/95/96/97/98/99/100
Ghidra now supports disassembly, decompilation, and debugging for Microchip PIC-12, PIC-16, PIC-24, dsPIC30, dsPIC33, and dsPIC33C microcontrollers. This includes new language specification files (.cspec, .ldefs, .pspec, .sinc, and .slaspec) that define memory maps, register sets, and instruction sets for these architectures. Users can now load and analyze firmware for these specific PIC families, with support for their unique features such as the PIC-16's PCLATH register handling and the PIC-24's 24-bit instruction set.
Ghidra/Processors/PIC/data · high confidence
Added language support for the Toy processor architecture
Ghidra now supports the 'Toy' processor, a test architecture. This update adds the necessary language definition files (\.ldefs\), compiler specifications (\.cspec\), processor specifications (\.pspec\), and SLEIGH instruction definitions (\.sinc\, \.slaspec\) to enable disassembly and decompilation for 32-bit and 64-bit variants, including big- and little-endian modes, Harvard memory architectures, and word-size variations.
Ghidra/Processors/Toy/data/languages · high confidence
Added machine learning scripts for function finding and search configuration
Two new Ghidra scripts were added to the Machine Learning extension. FindFunctionsRFExampleScript demonstrates how to train a random forest model to identify function starts in a binary, including parameter configuration, model training, and applying the classifier to discover and disassemble new functions. TurnOffFuncStartSearch provides a utility script to disable automatic function start searching and related analysis options, intended for use as a headless analyzer prescript.
_Ghidra/Extensions/MachineLearning/ghidra\scripts · high confidence
Added manual indices for ColdFire instructions
A new index file (68000.idx) has been added to the 68000 processor data directory, providing a searchable mapping of ColdFire-specific instructions (such as BITREV, FF1, and MOV3Q) to their corresponding pages in the ColdFire Family Programmer's Reference Manual. This enhancement allows users to quickly locate documentation for these specific instructions within the tool's help system.
Ghidra/Processors/68000/data/manuals · high confidence
Added old Toy language definitions for version 0.1
Added the old version 0.1 language definitions for the Toy processor, including the \ToyV00BE64\ and \ToyV00LE64\ language files, their corresponding translation files, and supporting files in the \v01stuff\ directory. These files define the 64-bit big-endian and little-endian architectures, register mappings, compiler specifications, and instruction sets for the legacy language version, enabling backward compatibility and language upgrade testing.
Ghidra/Processors/Toy/data/languages/old · high confidence
Added repository governance and development documentation
The repository now includes standard governance and documentation files to guide users and contributors. A new CONTRIBUTING.md file outlines the process for submitting bug reports, feature requests, and patches, including legal and licensing requirements. A comprehensive Developer's Guide (DevGuide.md) has been added, detailing the build environment, common Gradle tasks, and instructions for setting up development and CI environments. Additionally, a .gitattributes file has been introduced to manage line endings and binary file handling across the repository, and a .gitignore file has been updated to exclude build artifacts and IDE-specific files.
(repo-wide) · high confidence
Added sample extension with example plugins and components
Added a new 'sample' extension to the Ghidra distribution, providing a collection of example plugins and components for developers. This includes a 'Hello World' plugin that displays a message, a 'Kitchen Sink' plugin demonstrating services and action enablement, and a 'Show Info' plugin that displays code unit information. The extension also provides a 'Hello World' component provider with a dockable GUI, a 'Sample Graph' plugin for displaying visual graphs, and an 'Entropy Field' factory for displaying entropy calculations in the listing panel. Additionally, a 'Sample String Translation' plugin is included to demonstrate string translation services, and a 'Sample Program Tree' plugin shows how to organize program trees. The extension also contains help documentation and theme properties for icons.
Ghidra/Extensions/sample · high confidence
Added script to generate AVR8 GDT archives
A new script, CreateAVR8GDTArchiveScript, has been added to the Atmel processor directory. This script parses AVR8 header files to extract special memory definitions for each processor variant, creating a corresponding GDT archive file. The script iterates through a predefined list of processor variants, parsing each one individually to avoid conflicting macro definitions, and stores the extracted data types in a new archive.
_Ghidra/Processors/Atmel/ghidra\scripts · high confidence
Added script to parse JNI header files into GDT archives
A new Ghidra script, CreateJNIGDTArchivesScript, was added to the JVM processor scripts directory. This script automates the conversion of Linux and Windows JNI header files into .gdt data type archives, utilizing the CParserUtils to handle parsing and archive generation for both platforms.
_Ghidra/Processors/JVM/ghidra\scripts · high confidence
Added script to update 8051 SFR and BITS symbol sources
A new Ghidra script, Update8051.java, has been added to the 8051 processor support. This script automatically changes the source type of all symbols in the SFR, BITS, and SFR-BITS address spaces to 'imported', ensuring consistent symbol metadata for 8051 programs.
_Ghidra/Processors/8051/ghidra\scripts · medium confidence
Added skeleton template for new Ghidra modules
Added a new 'Skeleton' module to the build system, providing a complete template for creating new Ghidra modules. This includes a sample plugin with a UI provider and action, a program loader, an analyzer, an exporter, and a GFileSystem implementation. The template also includes necessary help files, resource directories for images, and a lib directory for dependencies, giving developers a starting point for building extensions.
GhidraBuild/Skeleton · high confidence
Added support for Infineon TriCore processors (TC172x, TC176x, TC29x)
Ghidra now supports the Infineon TriCore embedded processor architecture. This change adds the necessary language specification files (\.pspec\, \.cspec\, \.dwarf\, \.ldefs\, \.opinion\, and \.sinc\) to enable decompilation, debugging, and analysis for TriCore variants including the TC172x, TC176x, and TC29x. The update includes memory block definitions, register mappings, calling conventions, and instruction set definitions, allowing users to load and analyze TriCore binaries.
Ghidra/Processors/tricore/data/languages · high confidence
Added support for PowerPC e500 core instructions and SPE floating-point operations
Added new SLEIGH language files to support the PowerPC e500 core and its associated features. This includes the e500 processor variant (GP-2272), the Embedded Vector (EVX) instruction set, the Signal Processing Engine (SPE) including its floating-point (SPE\_EFSD, SPE\_EFV, SPE\_FloatMulAdd) and scalar single-precision floating-point (Scalar\_SPFP) instructions, as well as Altivec vector operations. The update also adds the 4xx legacy move assist instructions (dlmzb), load-multiple-word (lmw) and load-swap-word (lswi) instructions, and updates the PowerPC.opinion file to include constraints for PE, COFF, ELF, PEF, and Mach-O formats.
Ghidra/Processors/PowerPC/data/languages · high confidence
Added support for Renesas M16C/60 and M16C/80 16-bit microcontrollers
Ghidra now includes language support for the Renesas M16C/60 and M16C/80 16-bit microcontrollers. This change adds the necessary processor specifications, compiler specifications, language definitions, and instruction set specifications to enable disassembly and decompilation for these architectures.
Ghidra/Processors/M16C · high confidence
Added support for Z180, Z182, and Z8401x microcontrollers
Ghidra now supports the Zilog Z180, Z182, and Z8401x microcontrollers. This update adds new language definitions, processor specifications, and SLEIGH specifications for these variants, enabling the disassembler and decompiler to correctly interpret their instruction sets, memory maps, and special registers.
Ghidra/Processors/Z80/data · high confidence
Added support for the 8048 (MCS-48) microcontroller family
Ghidra now supports the 8048 (MCS-48) microcontroller family, enabling the disassembly and decompilation of code for this architecture. This update includes the necessary language definition, processor specification, and compiler specification files to recognize the 8048 instruction set, memory map, and register context, including support for the DBF context register and external port access.
Ghidra/Processors/8048/data · high confidence
Added support for the National Semiconductor CR16C processor
Users can now analyze and debug firmware for the CR16C architecture in Ghidra. This change introduces the complete language specification, instruction set, and processor definitions for the CR16C variant, including the TBIT instruction and corrected address mapping for the CR16C subconstructor.
Ghidra/Processors/CR16/data · high confidence
Added support for the Qualcomm Hexagon processor
Ghidra now supports the Qualcomm Hexagon V69 processor architecture. This update adds the necessary language and processor specification files, including the compiler specification (defining data types, register sets, and calling conventions), the processor specification (defining registers, control states, and emulation modifiers), the language definition, and the instruction set specifications for both the base Hexagon ISA and the HVX vector extensions. Users can now load, disassemble, and analyze Hexagon binaries.
Ghidra/Processors/Hexagon · high confidence
Added support scripts and utilities for Ghidra operations
Added a collection of shell and batch scripts in the support directory to manage and launch various Ghidra components. This includes headless analysis (analyzeHeadless), the GhidraGo protocol handler (ghidraGo), BSim database interaction (bsim, bsim\_ctl), PDB XML creation (createPdbXmlFiles), storage conversion (convertStorage), jar building (buildGhidraJar), and utilities for cleaning (ghidraClean) and debugging (ghidraDebug). Each component is accompanied by platform-specific launch scripts (e.g., .bat for Windows, shell scripts for Unix) and associated documentation (README files).
Ghidra/RuntimeScripts/support · high confidence
Added support scripts for remote debugging and Python module discovery
New utility scripts have been added to the debugger support directory to facilitate remote debugging and Python package resolution. This includes gmodutils.py for locating Python source paths, raw-python3.py for establishing RMI connections, and setuputils.sh / setuputils.ps1 for managing environment variables, SSH/SCP arguments, and Python module distribution paths on both Linux and Windows targets.
Ghidra/Debug/Debugger-rmi-trace/data/support · high confidence
Added taint analysis state implementations and SARIF writers
The taint analysis subsystem now includes concrete implementations for managing taint state in both the 'angr' and 'emulator' debuggers, along with new classes to export taint results to SARIF format. Specifically, AngrTaintState and EmulatorTaintState handle the construction of queries and the collection of memory/register states for their respective engines. Additionally, new classes (ExtKeyValue, SarifKeyValueWriter, SarifLogicalLocationWriter) have been introduced to map internal taint labels and logical locations into the SARIF output structure, enabling users to export taint analysis results in a standardized format.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/taint · high confidence
Added time overview color services for trace events and breakpoints
The debugger's time overview margin now displays color-coded indicators for trace events and breakpoint hits. New components, including TimeOverviewColorComponent, TimeOverviewColorPlugin, and associated services (TimeTypeOverviewColorService, BreakpointTimeOverviewColorService), render visual markers for thread, module, and memory region lifecycle changes, as well as breakpoint hit locations across the trace timeline. Users can toggle these views and customize the associated colors via a legend dialog.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/timeoverview · high confidence
Added utility for evaluating Sleigh/p-code in the Debugger
A new utility class, DebuggerPcodeUtils, was added to support the evaluation and execution of Sleigh/p-code within the debugger environment. This includes a label-bound p-code parser that resolves symbols from the trace or mapped programs, enabling more robust p-code interpretation and debugging capabilities.
Ghidra/Debug/Debugger/src/main/java/ghidra/pcode · high confidence
Added x64dbg debugger launchers for local and remote (SSH) debugging
New launch scripts (batch, PowerShell, and shell) were added to the debugger-launchers directory to support attaching to and launching the x64dbg debugger. These scripts enable local debugging as well as remote debugging over SSH, including automatic installation of the 'ghidraxdbg' Python package on remote hosts if missing.
Ghidra/Debug/Debugger-agent-x64dbg/data/debugger-launchers · high confidence
Added x64dbg support scripts for local debugging
New support scripts were added to enable local debugging with x64dbg. This includes Python entry points (local-x64dbg.py and local-x64dbg-attach.py) that handle connecting to the Ghidra trace server and attaching to or creating debug sessions, along with PowerShell (x64dbgsetuputils.ps1) and Bash (x64dbgsetuputils.sh) utilities to manage x64dbg installation and configuration.
Ghidra/Debug/Debugger-agent-x64dbg/data/support · high confidence
Added x86 relocation handlers for ELF, COFF, and Mach-O formats
Added new x86 processor module files to support binary loading and analysis. This includes a new X86Analyzer for constant propagation, relocation handlers for 32-bit and 64-bit ELF formats (including support for R\_X86\_64\_IRELATIVE and various GOT/PLT relocations), COFF relocation handlers for x86 and x86-64, and Mach-O relocation constants and handlers. These changes enable Ghidra to correctly process relocations in object files and shared libraries for the x86 architecture.
Ghidra/Processors/x86 · high confidence
Added zoom controls for the memory view
Four new actions—Zoom In (A), Zoom In (T), Zoom Out (A), and Zoom Out (T)—have been added to the memory view (MemviewProvider). These provide toolbar buttons that allow users to incrementally zoom in and out of the address and time dimensions of the memory view.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/memview/actions · high confidence
Adds initial BPF processor support to Ghidra
Users can now analyze Berkeley Packet Filter (BPF) bytecode. This change introduces the BPF processor plugin, including language specifications (cspec, pspec, sinc) and assembly definitions (ldefs, slaspec) that enable Ghidra to parse, disassemble, and understand BPF instructions, registers, and memory spaces.
Ghidra/Processors/BPF · high confidence
Adds language support for 80251, 80390, and CIP-51 microcontrollers
New language specification files (.cspec, .pspec, .sinc, .slaspec) and language definitions (.ldefs) are added for the 80251, 80390, and Silicon Labs CIP-51 processor families. These additions enable Ghidra to parse, disassemble, and decompile code for these specific 8051-variant architectures, including defining memory spaces, register sets, and compiler calling conventions.
Ghidra/Processors/8051/data · high confidence
Automatic static mapping and synchronization for debugger traces
The debugger now automatically maps trace modules, memory regions, and sections to corresponding programs and memory blocks in the Ghidra project. This change introduces a static mapping service that proposes and manages these mappings, allowing users to synchronize static and dynamic listings, transfer selections between them, and view module information in the debugger's modules panel. The system supports automatic mapping based on module names, file paths, and memory offsets, with options to memorize and persist these mappings for future sessions.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/modules · high confidence
BSim feature introduces database support and scripting tools for function similarity analysis
The BSim feature is introduced, enabling Ghidra to connect to and query external databases (H2, PostgreSQL, and Elasticsearch) for function signature matching. This includes new scripts to add programs to an H2 database, compare function signatures between open programs, and compare executables within a database. The feature also ships with pre-configured database schemas, weight files for different executable types, and server configuration files for PostgreSQL.
Ghidra/Features/BSim · high confidence
BSim search plugin and filter types added
The BSim search plugin (BSimSearchPlugin) and its associated GUI components were added to enable searching for similar functions in the BSim database. This includes a new server management system (BSimServerManager) for handling database connections, along with a comprehensive set of filter types (such as Architecture, Compiler, Date, and Function Tag filters) that allow users to refine their search results by various executable and function attributes.
Ghidra/Features/BSim/src/main/java/ghidra/features/bsim · high confidence
Centralized debugger control service plugin
The debugger control and machine-state editing functionality is now provided by a new 'DebuggerControlServicePlugin' that centralizes control across the tool. This plugin implements the 'DebuggerControlService' interface, managing 'ControlMode' per trace and exposing state editors for default, trace-following, and view-following contexts. It also introduces a 'ListenerSet' to manage 'ControlModeChangeListener' notifications, ensuring that mode changes are properly broadcast to interested components.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/control · high confidence
Complete rewrite of the theming system
The internal mechanism for managing application themes has been completely rewritten. This introduces a new, more robust architecture for handling colors, fonts, and icons, allowing for better support of dark mode, look-and-feel specific overrides, and dynamic theme changes. Users will experience more consistent styling across the application, with improved support for system-level theme changes and accessibility features.
Ghidra/Framework/Gui · high confidence
Debugger module restructured with new plugin package and help documentation
The Debugger module has been reorganized into a dedicated plugin package (DebuggerPluginPackage) and includes comprehensive help documentation for various debugger plugins such as Copy Actions, Memory View, Model Objects, Platform Selection, and Static Synchronization. This restructuring supports the broader debugger capabilities by providing clear user guidance and standardized plugin initialization.
Ghidra/Debug/Debugger · high confidence
Enhanced support for Golang binaries and improved DWARF/ELF parsing
Ghidra now supports Golang versions 1.19, 1.20, 1.22, 1.23, and 1.26, including improved handling of GoFuncID, interface types, slices, and GC write barriers. The DWARF importer has been updated to handle explicitly sized base types, packing, and macro info entries, while ELF processing now supports RELR relocations, GNU Hash, and dynamic value relocation tables. Additionally, the Mach-O loader better handles reexports, PRELINK binaries, and encrypted sections, and the Gnu Demangler has been improved to handle function member pointers and cast operators.
Ghidra/Features/Base · medium confidence
Expanded x86 instruction set support for AVX, AVX2, AVX-512, BMI1/2, and ADX
The x86 language specification has been significantly expanded to support a wide range of modern x86 instruction sets. This update adds new SLEIGH definitions for AVX, AVX2, and AVX-512 vector instructions, including arithmetic, logical, and data movement operations. It also introduces support for BMI1 and BMI2 bit-manipulation instructions (such as ANDN, BEXTR, TZCNT) and ADX (ADCX, ADOX) carry-less and carry-adding operations. These changes enable Ghidra to correctly disassemble and decompile code utilizing these extended instruction sets, improving the accuracy of the decompiler for binaries compiled with modern compilers that leverage these CPU features.
Ghidra/Processors/x86/data/languages · high confidence
FileFormats module manifest and supporting scripts added
The FileFormats module now includes a Module.manifest declaring dependencies on updated Java libraries (dex-ir, dex-reader, dexlib2, sevenzipjbinding, and AXMLPrinter2) and native binaries (lzfse). Additionally, the module adds a set of Ghidra scripts for binary analysis and cleanup, including scripts for processing Mach-O bind information, merging programs, resolving references, and cleaning up bad instructions.
Ghidra/Features/FileFormats · high confidence
Function Call Graph introduces a new 'Bow Tie' layout algorithm
The Function Call Graph plugin now supports a 'Bow Tie' layout algorithm, which organizes function nodes into a hierarchical, layered structure. This new layout engine, along with associated graphing classes and animation jobs, enables a more structured visualization of function call relationships, allowing users to better understand the flow of calls from a source function through its incoming and outgoing dependencies.
Ghidra/Features/GraphFunctionCalls · high confidence
Function Graph plugin introduces new layout options and theming support
The Function Graph plugin now supports multiple graph layouts, including a Flow Chart layout that organizes code blocks into a tree structure with orthogonal edge routing, and a Nested Code layout that mimics source code nesting. Users can also customize vertex and edge colors via a new theme properties file, and the plugin registers itself as a layout provider for the graphing system.
Ghidra/Features/FunctionGraph · high confidence
Function ID analyzer and database infrastructure introduced
The Function ID feature now includes a new \FidAnalyzer\ that applies function identification results to programs, allowing users to identify known functions by hashing. This change introduces the core backend infrastructure for the feature, including \FidDB\ for managing function ID database files, \FidQueryService\ for querying across multiple databases, and \ApplyFidEntriesCommand\ to apply the identified labels and bookmarks to the current program. Users will see function names and comments updated based on the FID database matches, with options to control whether to always apply labels or create analysis bookmarks.
Ghidra/Features/FunctionID/src/main/java/ghidra/feature/fid · high confidence
Function ID: New scripts for database management and analysis
The Function ID feature now includes a suite of headless-compatible scripts to manage and analyze function databases. Users can create and attach FID databases, populate them with library data, and perform batch operations such as finding functions by hash or name, collecting failed relocations, and calculating false positive/negative statistics. These scripts enable automated workflows for building and validating Function ID databases in headless mode.
Ghidra/Features/FunctionID · high confidence
GDB debugger agent and Trace RMI integration
The GDB debugger agent is now included in the distribution, providing the Python-based plugin that connects GDB to Ghidra via Trace RMI. This enables users to debug local, remote, and embedded targets by synchronizing state between GDB and Ghidra. The package includes the necessary schema definitions, command handlers, and helper utilities to manage processes, threads, memory, and breakpoints. Documentation and help files are provided to guide users through setup and usage for various connection types, including local, SSH, and QEMU-based debugging.
Ghidra/Debug/Debugger-agent-gdb · high confidence
Ghidra Server initial release with core server components
The Ghidra Server feature is introduced, providing the foundational server infrastructure for remote access to Ghidra repositories. This includes the main server application (GhidraServer), command processing for administrative tasks (CommandProcessor, ServerAdmin), user and repository management (UserManager, RepositoryManager, Repository), and SSL/TLS support for secure RMI connections (GhidraSSLServerSocket). The server supports multiple authentication modes including password files, Kerberos/Active Directory, PKI, and JAAS. Additionally, a serialization filter (data/serial.filter) is added to restrict RMI deserialization to safe classes, addressing security concerns related to remote procedure calls.
Ghidra/Features/GhidraServer · high confidence
Ghidra Server installation and administration scripts added
The Ghidra Server is now supported via a new set of cross-platform scripts (bash and Windows batch) located in the server directory. The \ghidraSvr\ script manages the server lifecycle (start, stop, install, uninstall, status) and handles Java runtime detection, while \svrAdmin\ provides user and repository administration. The \server.conf\ file configures the service wrapper, memory limits, and TLS settings. Additionally, \jaas.conf\ and an example external authentication script are provided to support JAAS-based user authentication modes.
Ghidra/RuntimeScripts/server · high confidence
GhidraDev and Sleigh Editor build infrastructure and Python stubs added
The build system for the GhidraDev Eclipse plugin and the GhidraSleighEditor plugin has been established with new feature, plugin, and launch configuration files, enabling proper Eclipse plugin packaging and runtime debugging. Additionally, a new 'Doclets' build component has been introduced, providing Python type stubs (PEP 561) for the Ghidra API to improve development experience in editors like PyCharm and Visual Studio Code. The Sleigh editor build includes new feature and IDE/UI module definitions for Xtext-based language support.
GhidraBuild · high confidence
GhidraDev plugin adds support for launching and debugging PyGhidra projects
The GhidraDev Eclipse plugin now includes launch shortcuts and delegates for both Java-based Ghidra projects and Python-based PyGhidra projects. Users can now right-click on a project and select 'Run As' or 'Debug As' to launch the corresponding application. For PyGhidra, the plugin configures the Python interpreter, sets up environment variables (including GHIDRA\_INSTALL\_DIR), and supports headless or GUI modes. Debugging PyGhidra projects automatically switches to the Debug perspective and starts the PyDev remote debugger. The plugin also handles user consent for opening network ports required for Ghidra communication.
GhidraBuild/EclipsePlugins/GhidraDev/GhidraDevPlugin · high confidence
Gnu Demangler analyzer introduces configurable options and text simplifications
The GnuDemangler analyzer now supports several new configuration options: applying function signatures and calling conventions, restricting demangling to known compiler patterns, and enabling standard C++ text simplifications (e.g., replacing \std::string\ with its underlying \basic\_string\ template). Users can also set a timeout for the demangling process and choose between the modern and legacy GNU demangler executables. Additionally, the feature includes a script to manually demangle ELF symbols with options, and a VxWorks symbol table finder that integrates demangling. The analyzer also loads a default replacement file to simplify demangled output.
Ghidra/Features/GnuDemangler · high confidence
Initial support for RISC-V processor module
Ghidra now includes a new RISC-V processor module, enabling the analysis of RISC-V binaries. This addition provides ELF relocation handling for RISC-V, supporting various relocation types including PC-relative, GOT, and TLS relocations. The module includes language support for RV32 and RV64 architectures, along with emulation capabilities for instruction state modification. Test coverage is provided for multiple RISC-V configurations (RV32GC, RV64GC, RV64G) with GCC compiler specifications.
Ghidra/Processors/RISCV · high confidence
Introduce DebuggerPlatformServicePlugin for platform selection and management
A new plugin, DebuggerPlatformServicePlugin, has been added to manage the selection and management of debug platforms for the current focus. This plugin implements the DebuggerPlatformService interface, providing methods to retrieve or set the current platform mapper for a given trace and object. It handles the lifecycle of mappers by caching them per trace and firing events when the active platform changes, ensuring that the correct platform interpretation is used for debugging operations.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/platform · high confidence
Introduce LiSA-based abstract interpretation engine for static analysis
Users can now run static analyses based on the Library for Static Analysis (LiSA) from the Software and System Verification (SSV) group at Università Ca' Foscari. This new extension provides an abstract interpretation engine that supports various value, heap, and type domains (such as constant propagation, interval analysis, and taint tracking) via a new plugin and associated scripts. The feature includes configuration options for control flow graph computation, interprocedural analysis, and result serialization, enabling users to perform advanced code analysis directly within Ghidra.
Ghidra/Extensions/Lisa · high confidence
Introduce Trace RMI framework for debugger connections
Adds the Trace RMI plugin, which provides a new architecture for connecting to live debuggers and their targets. This includes a Connections window to manage Trace RMI connections, a Launcher system to automate back-end setup, and a Terminal for direct debugger interaction. The framework supports connecting to back ends via outbound or acceptor modes, managing server/acceptor/connection/target states, and offers a raw Python launcher for development and API exploration.
Ghidra/Debug/Debugger-rmi-trace · high confidence
Introduce a new Pseudo-Terminal (Pty) framework
Added a new pseudo-terminal (pty) framework in the Ghidra/Framework/Pty module. This includes a unified API for opening and managing pseudo-terminals across multiple operating systems, including Linux, macOS, OpenBSD, and Windows (via ConPty). The change introduces core interfaces and implementations such as Pty, PtyFactory, PtyChild, and PtyParent, along with platform-specific factories and session leaders. This provides a consistent way to spawn and control subprocesses with terminal-like behavior, supporting features like window resizing and terminal mode configuration.
Ghidra/Framework/Pty · high confidence
Introduced GhidraGo feature for launching Ghidra via ghidraURL hyperlinks
Added the GhidraGo feature, which enables users to open programs in Ghidra by clicking hyperlinks (ghidra://) in external documents or web pages. This feature includes a command-line interface (CLI) to send URLs to a running Ghidra instance, a plugin to listen for and process these URLs, and platform-specific protocol handler configurations for Windows, Linux, and Mac. The implementation uses file-system based inter-process communication (IPC) to transfer URL data between the external caller and the Ghidra application.
Ghidra/Features/GhidraGo · high confidence
Introduced Program Diff feature for comparing and merging two programs
Added the Program Diff feature, allowing users to compare two programs side-by-side to identify differences in code units, references, comments, and other program elements. The diff view highlights differences in the second program, and users can apply, ignore, or merge specific differences back into the primary program. The feature includes a settings panel to configure which types of differences are detected and applied, and provides navigation between differences. This is a new capability for program analysis and merging.
Ghidra/Features/ProgramDiff · high confidence
Introduced Python-based pcode test build framework
Added a new pcode test framework in the SleighDevTools module that uses Python 3 scripts to build and manage pcode test binaries. The \build\ script and supporting modules (\build.py\, \pcodetest.py\, \defaults.py\) provide a command-line interface to list, build, and configure pcode tests for various architectures (e.g., ARM, AARCH64) using different toolchains (GCC, LLVM, CCS, SDCC). This replaces the previous mechanism for generating and running pcode tests, allowing developers to easily add new tests by defining them in \pcode\_defs.py\ and writing C source files in the \c\_src\ directory.
Ghidra/Extensions/SleighDevTools/pcodetest · high confidence
Introduced new File System Browser plugin components
The File System Browser plugin has been refactored to use a new set of internal classes for managing the file system tree and user interactions. This includes a dedicated action context (FSBActionContext) to handle selection and state, a component provider (FSBComponentProvider) that manages the tree UI and file handlers, and specific node types (FSBNode, FSBFileNode, FSBDirNode, FSBRootNode) that represent files and directories in the browser. Additionally, an extension point (FSBFileHandler) allows other plugins to provide custom actions and behaviors for specific file types within the browser.
Ghidra/Features/Base/src/main/java/ghidra/plugins/fsbrowser · high confidence
Introduces a new theming system with palette and theme property files
Adds gui.palette.theme.properties and gui.theme.properties to define a reusable color palette and UI component styling rules. The palette provides named colors for light and dark modes, while the theme file maps these colors to specific UI elements (tables, trees, buttons) and overrides look-and-feel defaults for better contrast and consistency across different Java Look and Feels.
Ghidra/Framework/Gui/data · high confidence
Introduces new target management service and abstract target implementation
Adds AbstractTarget and DebuggerTargetServicePlugin to the debug service layer. AbstractTarget provides a base implementation for target operations, including address resolution and range finding. DebuggerTargetServicePlugin manages the collection of published targets and notifies listeners of changes, utilizing a ListenerSet for efficient listener management.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/target · medium confidence
Introduction of the Help framework module
The Help framework is now a standalone module, providing a default headless help service and customizing the Java Help system with tailored views for the table of contents, search, and favorites. This change enables the help system to function correctly in headless environments and supports cross-module help lookups.
Ghidra/Framework/Help · high confidence
Jython is now a Ghidra extension
The Jython integration has been converted from a core component into a standalone extension. This change introduces the Jython 2.x scripting engine and interpreter as a modular extension, providing Python-based scripting capabilities for Ghidra. The extension includes a suite of example scripts (such as AddCommentToProgramScriptPy, AskScriptPy, and ghidra\_basics) that demonstrate Python scripting workflows, including user input, data type selection, and program analysis. Additionally, the extension provides Python-based introspection and auto-completion support for Java classes, and includes a custom help system that displays API documentation for Ghidra classes directly within the Python help() function.
Ghidra/Extensions/Jython · high confidence
Loongarch processor support with ELF relocation and analysis
Added support for the Loongarch processor architecture, including an ELF relocation handler for resolving symbols and addresses in Loongarch ELF binaries, and a constant propagation analyzer for Loongarch code. The update also includes test coverage for Loongarch64 and Loongarch64f processor configurations.
Ghidra/Processors/Loongarch · high confidence
MIPS processor support and ELF relocation handling
Added new analysis and symbol handling for MIPS, including the MipsAddressAnalyzer, MipsPreAnalyzer, and MipsSymbolAnalyzer to improve code analysis and symbol resolution. Introduced comprehensive ELF relocation support for MIPS, including the MIPS\_ElfExtension for handling MIPS-specific ELF headers and sections, and new relocation handlers (MIPS\_ElfRelocationHandler, MIPS\_ElfRelocationContext) to process MIPS-specific relocations like R\_MIPS\_GOT16 and R\_MIPS\_GPREL32. Added support for MIPS64 packed relocations and MicroMIPS variants. Also included an emulation state modifier for MIPS to support instruction emulation.
Ghidra/Processors/MIPS · high confidence
Markdown to HTML conversion tool with enhanced styling and link handling
A new Java utility, MarkdownToHtml, has been added to the MarkdownSupport module to convert Markdown files into HTML. This tool integrates several CommonMark extensions, including support for footnotes, GFM tables, and heading anchors. It also applies custom CSS styling to tables, headings (h1-h2), and code blocks, and automatically converts internal Markdown file links (.md) to HTML links (.html) in the output.
GhidraBuild/MarkdownSupport · high confidence
Microsoft demangler feature added with developer scripts and core parsing classes
The MicrosoftDmang feature now includes the core MDMang demangling engine, including classes for character iteration, context management, and symbol parsing. Additionally, three developer scripts are added to the feature: a script to dump parse information for debugging, a script to batch-demangle names from a file, and a script to genericize mangled names. The feature also includes manifest and certification files to support the new component.
Ghidra/Features/MicrosoftDmang · high confidence
Microsoft demangler gains configurable output and apply options
The Microsoft demangler now exposes granular control over how symbols are processed and displayed. Users can configure whether to apply function signatures and calling conventions, restrict demangling to known patterns, and choose how anonymous namespaces and user-defined type tags are rendered in the output.
Ghidra/Features/MicrosoftDemangler · high confidence
New BSim Program Correlator for Version Tracking
A new BSim Program Correlator has been added to the Version Tracking feature. This correlator uses the decompiler to generate confidence scores between potentially matching functions in source and destination programs, utilizing control-flow and data-flow characteristics. The update includes the necessary help documentation and table of contents entries to make this new correlator accessible to users.
Ghidra/Features/CodeCompare, Ghidra/Features/VersionTrackingBSim · medium confidence
New Batch Import dialog and supporting classes
A new Batch Import feature has been added to the Base module, introducing a dedicated dialog (BatchImportDialog) and a suite of supporting classes (BatchInfo, BatchGroup, BatchGroupLoadSpec, BatchImportTableModel, etc.) that enable users to select multiple files and import them in a single operation. The implementation groups files by loader and language, allowing users to configure import settings for each group before execution.
Ghidra/Features/Base/src/main/java/ghidra/plugins/importer · high confidence
New Breakpoint Timeline plugin for visualizing breakpoint hits
A new BreakpointTimelinePlugin has been added to the debugger GUI, providing a visual timeline that displays breakpoint hits across the entire execution of a trace. The plugin includes a timeline panel for visualizing these hits, actions for navigating through snapshots, and controls for zooming and toggling grid outlines. This allows users to see when and where breakpoints were triggered throughout the trace execution.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/breakpoint/timeline · high confidence
New BytePatterns feature for analyzing function start patterns
The BytePatterns module is introduced, providing tools to discover and analyze byte and instruction patterns around function starts and returns. This includes the Function Bit Patterns Explorer plugin for visualizing and filtering these patterns, along with helper scripts (e.g., DumpFunctionPatternInfoScript) to export pattern data from binaries. The feature supports gathering data on first bytes/instructions, pre-bytes/instructions, and return bytes/instructions, allowing users to identify common function entry points across multiple binaries to improve automatic function start detection.
Ghidra/Features/BytePatterns · high confidence
New Data Graph feature for visualizing data object references
A new Data Graph feature has been added to Ghidra, allowing users to visualize a graph of data objects in memory. From any data object in the listing, users can display a graph showing that data object and its referenced objects. The graph includes data vertices that display the contents of data objects and code vertices that represent references to or from code. Users can explore outgoing and incoming references to add new vertices to the graph, with options to expand/collapse sub-data elements, delete vertices, and navigate between referenced locations.
Ghidra/Features/DataGraph · high confidence
New Debugger API service interfaces
The debugger module now exposes a comprehensive set of new service interfaces that define the contract for debugger functionality. These include services for managing trace state and navigation (DebuggerTraceManagerService), controlling the debugger (DebuggerControlService), handling emulation (DebuggerEmulationService), managing breakpoints (DebuggerLogicalBreakpointService), and coordinating static memory mappings (DebuggerStaticMappingService). Additional services are introduced for platform mapping (DebuggerPlatformService), target management (DebuggerTargetService), console logging (DebuggerConsoleService), listing panels (DebuggerListingService), and watch expressions (DebuggerWatchesService). This establishes the core API for the debugger's internal architecture.
Ghidra/Debug/Debugger-api · high confidence
New Debugger Breakpoints UI and Logic
The debugger's breakpoint management has been refactored into a new \DebuggerBreakpointsPlugin\ and associated UI components. This introduces a dedicated GUI for managing logical and trace-level breakpoints, including a table-based provider (\DebuggerBreakpointsProvider\) with custom cell renderers and editors for state and location columns. The change adds support for setting breakpoints via Sleigh conditions and injections, and integrates breakpoint markers into the Decompiler margin. Users can now toggle, enable, disable, and edit breakpoint properties through the new interface.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/breakpoint · high confidence
New Debugger Modules and Static Mapping Management UI
The Debugger plugin now includes dedicated GUI components for managing trace modules, sections, and static mappings. This change introduces new dialogs for adding and reviewing mappings, alongside provider panels that display module and section details (such as base address, name, and length) and allow users to perform manual or automatic mapping operations directly from the debugger interface.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/modules · high confidence
New Debugger Stack Panel with PC, Function, and Module Columns
A new DebuggerStackPanel has been introduced to display the call stack in an object-based trace model. The panel now presents columns for the Program Counter (PC), the associated Function, and the containing Module, allowing users to navigate the stack and view execution context more effectively.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/stack · high confidence
New Debugger Watches plugin and provider implementation
The Debugger Watches plugin has been implemented, introducing a new GUI component for monitoring and editing expressions and register values during debugging sessions. This includes the \DebuggerWatchesPlugin\ and \DebuggerWatchesProvider\ classes, which manage a table-based interface for adding, editing, and displaying watch entries. The implementation supports dynamic expression evaluation, data type representation, and state persistence via \SavedSettings\. Additionally, a new \DebuggerWatchActionContext\ is provided to handle action contexts specific to watch rows, enabling context-sensitive actions on selected watch entries.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/watch · high confidence
New Debugger help documentation
Added new help pages for the Ghidra Debugger, including an overview of the Dynamic Analysis Framework, a 'Getting Started' guide for launching and configuring the debugger on Linux, macOS, and Windows, and a troubleshooting page for common issues.
Ghidra/Debug/Debugger/src/main/help/help/topics/Debugger · high confidence
New Emulation Service Plugin and Integration Utilities
The Debugger now includes a new emulation service plugin that provides actions to emulate programs, functions, and threads within the debugger environment. This change introduces the \DebuggerEmulationServicePlugin\ and supporting classes like \DebuggerEmulationIntegration\ and \ProgramEmulationUtils\ to manage emulation states, handle lazy loading of data from the target, and integrate with the trace model. Users can now launch emulated executions directly from the UI, with the system handling the creation of new traces and managing the emulator's interaction with the target's memory and registers.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/emulation · high confidence
New Emulation framework module with legacy Emulator interface
A new Emulation framework module has been introduced, providing a modernized p-code emulation system alongside a transitional wrapper for the older Emulator interface. The module includes new utility classes for handling ranges and spans (RangeMapSetter, Span, ULongSpan) and introduces the DefaultEmulator as the primary implementation, while marking the previous Emulator interface and its associated helper classes as deprecated. This change allows users to adopt the new PcodeEmulator directly for new emulation tasks, while existing code can continue using the adapted interface during the transition period.
Ghidra/Framework/Emulation · high confidence
New GDB/Lldb setup utilities for debugger integration
Added new shell and PowerShell utility scripts (gdbsetuputils.sh, gdbsetuputils.ps1) and a GDB initialization template (gdbinit\_template) to handle debugger configuration. These scripts automate the process of connecting to the Ghidra trace server, setting up the target architecture and endianness, loading the target image and arguments, and managing GDB/Lldb command-line arguments for both local and remote debugging scenarios.
Ghidra/Debug/Debugger-agent-gdb/data/support · high confidence
New Gradle build scripts and configuration files
The Gradle build system now includes new support scripts and configuration files to organize the build process. A new README.txt explains the structure of the gradle folder, including sub-folders for root project scripts and shared support scripts. A certification.manifest file is added to track required files for certification. Additionally, app\_config\_breakout.txt groups test classes by application configuration to support parallel test execution, and jacoco.excludes.src.txt defines exclusions for code coverage analysis.
gradle · high confidence
New Graph Export Service and Dialog
The GraphServices module now includes a dedicated export workflow. A new 'Graph Export' display provider and its associated non-interactive display allow graphs to be saved to external files. Users can select from multiple export formats including CSV, DIMACS, DOT, GML, GraphML, JSON, Matrix, and Visio via a new export dialog. The module also introduces an \AttributeFilters\ class that dynamically generates filter controls based on graph attributes, and registers help documentation for the new export and display features.
Ghidra/Features/GraphServices · high confidence
New Graph framework module
The Graph framework is introduced as a new module, providing core interfaces for directed graphs (GDirectedGraph, GImplicitDirectedGraph), edges (GEdge, GWeightedEdge), and graph algorithms (GraphAlgorithms). The module includes a factory for creating directed graphs and utility classes for managing graph paths. It also bundles dependencies on the JUNG and JGraphT libraries, along with associated help documentation and image resources.
Ghidra/Framework/Graph · high confidence
New Java Debugger (JPDA) implementation
The Java Debugger (JPDA) module has been refactored to use a new internal manager architecture. This introduces a dedicated event handling system for the Java Debug Interface (JDI), allowing for more robust tracking of VM states, thread events, and breakpoints. Users benefit from improved stability and feature parity when debugging Java and Dalvik (Android) targets, with new help documentation and launchers for local, attach-by-port, and attach-by-PID connections.
Ghidra/Debug/Debugger-jpda · high confidence
New LLDB launchers for remote, local, and kernel debugging
Added new LLDB debugger launchers for various debugging scenarios, including local execution, remote GDB-server connections, SSH-based remote debugging, Android target attachment, and kernel-mode debugging. These scripts enable Ghidra to launch the LLDB debugger for local binaries, connect to remote stubs like gdbserver, or attach to Android and kernel targets over SSH or direct connections.
Ghidra/Debug/Debugger-agent-lldb/data/debugger-launchers · high confidence
New LaunchSupport system for Java detection and launch configuration
The GhidraBuild/LaunchSupport module introduces a new Java detection and launch configuration system. It adds platform-specific Java finders for Windows, Mac, Linux, and OpenBSD, enabling automatic discovery of installed JDKs and JREs. The system supports reading launch.properties to apply environment variables (ENVVARS) and VM arguments (VMARGS), including platform-specific overrides. It also allows users to save and recall the last-used Java home directory, and enforces a 64-bit Java requirement.
GhidraBuild/LaunchSupport · high confidence
New Machine Learning extension for function finding
A new Machine Learning extension has been added to Ghidra, introducing a Random Forest Function Finder plugin. This tool trains machine learning models to identify function starts within a program by analyzing byte patterns and context registers. Users can train models, evaluate their performance via a statistics table, and apply them to disassemble or create functions at predicted addresses. The extension includes support for parallelized model evaluation, alignment-based search optimization, and configurable data gathering parameters such as pre-bytes, initial bytes, and sampling factors.
Ghidra/Extensions/MachineLearning · high confidence
New Model provider for inspecting object-based traces
Added a new Model provider and associated UI components (AbstractQueryTablePanel, AbstractQueryTableModel, DebuggerModelPlugin) that enable users to browse and inspect objects recorded in a trace. This introduces a tree and table-based interface for navigating object hierarchies, with support for filtering, sorting, and default actions on trace objects.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/model · high confidence
New P-Code Stepper plugin for debugging emulation
A new P-Code Stepper plugin has been added to the Debugger, providing a GUI for single-stepping through p-code during emulation. The implementation includes a new \DebuggerPcodeStepperPlugin\ and \DebuggerPcodeStepperProvider\ which display p-code operations, labels, and state in a table. Supporting classes like \PcodeRow\, \OpPcodeRow\, \UniqueRow\, and others have been introduced to handle the display of p-code instructions, unique variable nodes, and control flow (branches, fall-throughs). This feature allows users to inspect and step through the intermediate p-code representation of the emulated program state.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/pcode · high confidence
New Program Graph plugin for visualizing code and data references
A new 'Program Graph' plugin has been added to the Code Browser, enabling users to generate and visualize program control flow, call graphs, and data reference graphs. The plugin supports block flow and code flow graphs for analyzing control flow within functions or the entire program, as well as data reference graphs that show memory location relationships. Users can select graph output destinations, configure options like maximum code lines per block and reference depth, and interact with nodes to navigate the program. Help documentation and table of contents entries have been added to guide users through the new graphing capabilities.
Ghidra/Features/ProgramGraph · high confidence
New ProgressServicePlugin for debugging task monitoring
A new ProgressServicePlugin has been added to the debug service layer, implementing the ProgressService interface to manage task progress monitoring. This introduces a pub-sub model where publishers create task monitors via the service, and subscribers (such as the Debug Console) are notified of task states and progress updates. The implementation includes DefaultCloseableTaskMonitor and DefaultMonitorReceiver classes to handle the lifecycle and state of these monitors.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/progress · high confidence
New Project module and theme management UI
A new 'Project' module has been introduced to the Ghidra framework, containing the core logic for project management and a new theme management system. Users can now create, switch, import, export, and delete GUI themes via the 'Edit \> Theme' menu in the Project Window. The module also includes utilities for handling file drops and displaying domain object information.
Ghidra/Framework/Project · high confidence
New SystemEmulation feature with example scripts and Linux syscall libraries
A new SystemEmulation feature has been added to Ghidra, providing a framework for P-code emulation. This location contains example scripts demonstrating standalone and debugger-integrated emulation, including a 'Desk Check' script for step-by-step inspection. It also includes demo userop libraries for custom operations and system call simulation, alongside concrete implementations for Linux x86 and AMD64 system calls.
Ghidra/Features/SystemEmulation · high confidence
New Taint Analysis module for p-code emulation
A new Taint Analysis module has been added to Ghidra, providing a concrete emulator that tracks data flow and taint states during emulation. This includes a \TaintPcodeEmulator\ and associated factory classes that integrate taint tracking with the p-code execution engine. The module also introduces a GUI column factory to display taint information in the debugger's register view, allowing users to visualize which registers and memory locations are tainted. Additionally, the module includes support for taint-aware file system operations and Linux syscall handling, enabling scripts to mark variables and arrays as tainted for analysis.
Ghidra/Debug/TaintAnalysis · high confidence
New Threads panel in the Debugger plugin
A new Threads panel has been added to the Debugger plugin, providing a dedicated view for managing and inspecting trace threads. This includes a new plugin, provider, and panel implementation that displays thread information such as path, name, program counter (PC), function, and module. The panel supports context-aware actions and integrates with the debugger's coordinate system to track thread states and changes across trace snapshots.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/thread · high confidence
New Time panel for browsing and navigating trace snapshots
A new Time panel has been added to the debugger, providing a table that lists all recorded snapshots in a trace. Users can browse snapshots, view details such as the program counter, function, and module, and navigate to specific points in time using a selection dialog. The panel supports tool-wide configuration of the time radix (number base) for displaying trace times, and allows renaming snapshot descriptions. This feature enables users to inspect and interact with the temporal history of a debugged program.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/time · high confidence
New Trace Call Tree and Variable Viewer plugins for debugging sessions
Users can now view a hierarchical call tree of all functions executed during a trace or live debugging session via the new TraceCallTreePlugin, which displays function names, modules, snapshots, and parameters in a tree table. Additionally, the DebuggerVariableViewerPlugin provides a table of variables with their current values, memory states, and editability for the active trace, allowing users to inspect and modify variable states directly.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/tracecalltree · high confidence
New Trace Tab Panel for Debugger
Introduced a new DebuggerTraceTabPanel component that manages trace tabs in the debugger GUI. This change adds a dedicated tab panel for displaying open traces, including actions to close individual, all, or dead traces, and integrates with the debugger target service to update tabs when targets are published or withdrawn.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/trace · high confidence
New TraceModeling framework for trace-based analysis
The TraceModeling framework is now available, providing a new API for integrating emulators with trace data. This includes utilities for evaluating Sleigh expressions on trace snapshots, tracking memory state (KNOWN/UNKNOWN) during emulation, and managing event queues for domain objects. The framework introduces new components such as TraceEmulationIntegration for linking emulators to traces, state pieces for tracking memory conditions, and a GSpanField UI widget for lifespan selection.
Ghidra/Debug/Framework-TraceModeling · high confidence
New Version Tracking correlators for program and address matching
The Version Tracking feature introduces a suite of new program correlators that automatically identify matching functions and data between source and destination programs. These include exact matches for function bytes, instructions, and mnemonics, as well as correlators for data references, symbol names, and combined function/data references. Additionally, new address correlators (e.g., ExactMatchAddressCorrelator, LinearAddressCorrelator) and correlation classes (e.g., StraightLineCorrelation, VTHashedFunctionAddressCorrelation) are added to map addresses between matched functions. A new base class, AbstractGhidraVersionTrackingScript, is provided to simplify the creation of Version Tracking scripts. These changes enhance the automatic matching capabilities of Version Tracking, allowing for more robust and granular comparison of software components.
Ghidra/Features/VersionTracking/src/main/java/ghidra/feature/vt · high confidence
New abstract base classes for debugger platform mapping
Added new abstract classes AbstractDebuggerPlatformMapper, AbstractDebuggerPlatformOffer, and AbstractDebuggerPlatformOpinion in the debug mapping package. These classes provide a structured foundation for mapping trace data to Ghidra platforms, including methods for retrieving disassembly injections, handling cancellation, and querying platform opinions. The new interface DebuggerPlatformOffer defines how platform mappings are offered and selected based on confidence levels.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/mapping · high confidence
New advanced development class materials and examples
Added new source code examples and documentation for the Ghidra Advanced Development class. This includes a Makefile and C/C++/assembly source files (such as animals.cpp, compilerVsDecompiler.s, createStructure.c, custom.c, dataMutability.c, globalRegVars.c, inline.s, jumpWithinInstruction.c, ldiv.c, noReturn.c, opaque.c, override.c, setRegister.c, sharedReturn.c, switch.s, and write.c) located in the GhidraClass/Advanced/src/Examples directory. Additionally, the LaTeX source for the 'Improving Disassembly and Decompilation' presentation and the HTML slides for the 'Ghidra Advanced Development Class' have been added to the documentation.
GhidraDocs · high confidence
New analysis scripts and processor specifications for PIC, Z80, and x86 architectures
Added a new Ghidra script, CreatePICSwitch.java, to automatically create switch statements for PIC processors when the current instruction modifies the program counter. Added a new processor specification file, z8401x.pspec, for the Z80 architecture, defining registers, context data, and default symbols. Added X86InstructionSkipper.java to identify and skip x86 NOP instructions used by Visual Studio for dynamic code patching. Additionally, added example C++ source files for a Win32 application (WinHelloCPP) and version-tracking exercise files for the Ghidra class documentation.
(repo-wide) · high confidence
New code comparison actions to transfer function and variable names and types
The Code Compare feature now includes new actions in the dual decompiler view that allow users to transfer function and variable names, types, and signatures between matched tokens. Specifically, users can now apply callee function names and signatures, as well as local and global variable names and types, directly from the comparison view. These changes are implemented through new action classes such as ApplyCalleeFunctionNameFromMatchedTokensAction and ApplyGlobalNameFromMatchedTokensAction, which facilitate the synchronization of code elements between the two sides of the comparison.
Ghidra/Features/CodeCompare/src/main/java/ghidra/features/codecompare · high confidence
New column implementations for trace value and path tables
Added a new set of column classes in the debug GUI model to support object-based trace inspection. This includes base classes like AbstractTraceValueObjectAddressColumn and AbstractTraceValueObjectLengthColumn for handling address and length data types. New columns were introduced for displaying trace paths (TracePathStringColumn, TracePathLastKeyColumn, TracePathLastLifespanColumn, TracePathLastLifespanPlotColumn) and trace values (TraceValueKeyColumn, TraceValueLifeColumn, TraceValueLifePlotColumn, TraceValueValColumn). Additionally, an EditableColumn interface and TraceValueObjectEditableAttributeColumn were added to enable in-place editing of trace object attributes.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/model/columns · high confidence
New dbgeng launchers for kernel, local, remote, and SSH debugging
Added new batch, PowerShell, and shell scripts for the dbgeng debugger agent, enabling users to launch or attach to local and remote targets, connect to remote debuggers, open traces, and use connection servers. These launchers support both Windows (bat/ps1) and Unix (sh) environments, with options for kernel debugging, attaching to running processes, and remote execution via SSH, all utilizing the Trace RMI infrastructure.
Ghidra/Debug/Debugger-agent-dbgeng/data/debugger-launchers · high confidence
New debugger GUI components and utilities
The debugger plugin introduces a suite of new GUI components to enhance the debugging experience. This includes abstract dialog classes for map proposals and parameter inputs, a block chooser dialog for memory mapping, and a byte source implementation for memory searching. Additionally, the update provides a location label for displaying trace context, a resources interface for icons and help anchors, search region factories for memory searches, action contexts for snapshots, and mixins for pasting bytes into targets. These changes collectively expand the debugger's interactive capabilities and UI infrastructure.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui · high confidence
New debugger console UI components for logging and progress tracking
Added new Java classes that implement the visual components of the debugger console: a plugin that registers a log4j appender to route debug and agent logs into the console, a provider that manages the console table (displaying icon, message, actions, and time), and specific cell renderers for HTML/progress bars and monitor progress bars. These files establish the UI layer for the central debug console, allowing users to view log entries and interactive actions within the debugger interface rather than in separate pop-ups or the main application window.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/console · high confidence
New debugger launchers for GDB, QEMU, and remote debugging
Adds new debugger launchers for local GDB, QEMU (user and system), remote GDB, SSH-based GDB (including Windows and GDBServer variants), and Wine. These scripts enable debugging on the local machine, via SSH to remote hosts, or through emulators, with automatic installation of the 'ghidragdb' Python package on remote systems when missing.
Ghidra/Debug/Debugger-agent-gdb/data/debugger-launchers · high confidence
New debugger listing components for memory state and cursor highlighting
The debugger listing area now uses a new set of classes to manage background colors and action contexts for trace memory views. A new \CursorBackgroundColorModel\ highlights the current cursor line, while \MemoryStateListingBackgroundColorModel\ visually indicates the state of memory (e.g., unknown, error, or known) in the listing. These models are integrated into the \DebuggerListingPlugin\ and \DebuggerListingProvider\ to provide visual feedback on memory states and cursor position within the debugger's dynamic listings.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/listing · high confidence
New debugger memory views and region management
The debugger now includes dedicated plugins and components for viewing memory bytes and managing memory regions. Users can open a new 'Memory Bytes' view to inspect raw trace memory, with support for dynamic updates and selection tracking. Additionally, a 'Regions' plugin provides a table-based interface to view, add, and delete memory regions, and map them to program blocks. These changes introduce new UI components (e.g., \DebuggerMemoryBytesPlugin\, \DebuggerRegionsPlugin\) and dialogs (\DebuggerAddRegionDialog\) that allow users to interact with trace memory and region mappings directly within the debugger environment.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/memory · high confidence
New debugger scripts for mapping, emulation, and trace population
Added several new Ghidra scripts to the Debugger tool to enhance debugging workflows. AddMapping.java allows users to programmatically map memory regions between a trace and a program. ComputeUnwindInfoScript provides diagnostic information about stack unwinding for the current function. DemoDebuggerScript demonstrates how to launch a target, set breakpoints, and run a trace. ListAllKnownMemoryScript lists all memory addresses known at a specific snapshot. PopulateDemoTrace creates a sample trace database with threads, memory, and symbols for demonstration purposes. RefreshRegistersScript provides a mechanism to refresh register states for debugging.
_Ghidra/Debug/Debugger/ghidra\scripts · high confidence
New generic framework module with utility classes and algorithms
The Ghidra Framework now includes a new 'Generic' module containing shared utility classes and algorithms. This module introduces a 'FilteredIterator' for streamlining data processing, a 'DominantPair' for map/set keying, and a 'CachingPool' for object pooling. It also provides new algorithmic classes including 'CRC64' for checksums, 'Lcs' and 'ReducingLcs' for longest common subsequence calculations, and 'WordDiffer' for text diffing. Additionally, the module includes 'GenericApplicationLayout' for managing application directory structures and 'BasicFactory' for object creation patterns.
Ghidra/Framework/Generic · high confidence
New global control actions for the debugger
The debugger now provides a unified set of global control actions for the target, trace, and emulator. Users can now access standard debugging controls (such as resume, interrupt, step, and kill) directly from the main toolbar and menus, with actions dynamically enabled or disabled based on the current control mode (target, trace, or emulator). This centralizes execution control, making it easier to manage the debugging session without navigating through context-specific menus.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/control · high confidence
New grammar definitions for language and compiler specifications
Added RelaxNG schema files (\.rxg\) that define the structure for Ghidra's language and compiler specification files. These new files (\compiler\_spec.rxg\, \format\_opinions.rxg\, \language\_common.rxg\, \language\_definitions.rxg\, and \processor\_spec.rxg\) establish the validation rules for parsing \.cspec\ and \.pspec\ files, enabling the tool to correctly interpret processor architectures, calling conventions, and data types.
Ghidra/Framework/SoftwareModeling/data/languages · high confidence
New help documentation for the Debugger Memory (Dynamic Bytes) plugin
Added comprehensive help documentation for the Debugger Memory (Dynamic Bytes) plugin. This new page explains the dynamic memory view, which displays recorded memory contents from a target or trace, and details available actions such as creating new memory views, following threads, tracking location, and performing memory reads and edits.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerMemoryBytesPlugin · high confidence
New help documentation for the Registers plugin
A new help page for the Debugger Registers plugin has been added, detailing the register window's features including color-coded state indicators, column descriptions (Favorite, Number, Name, Value, Type, Representation), and available actions such as Go To, Select Registers, Register Type Settings, Enable Edits, and Clone Window.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerRegistersPlugin · high confidence
New help documentation for the Trace Management service plugin
A new help page has been added for the Debugger: Trace Management service plugin. It documents the plugin's role in managing open traces and controlling them via the Listing window's tab panel. The documentation details available actions including opening, saving (and saving as), closing, and managing traces, as well as configuration toggles for saving by default and automatically closing traces on target termination.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerTraceManagerServicePlugin · high confidence
New launch scripts and certification manifest for Ghidra
Added a new certification manifest (certification.manifest) that defines the licensing and IP status for a set of runtime scripts, including ghidraRun, server launchers, and support utilities. Introduced new shell (ghidraRun) and batch (ghidraRun.bat) launch scripts that configure Java heap memory via environment variables (GHIDRA\_MAXMEM, GHIDRA\_GUI\_MAXMEM) and delegate to the respective platform-specific launchers (launch.sh/launch.bat).
Ghidra/RuntimeScripts · high confidence
New listing code comparison view with diff highlighting and options
Users can now compare two listings side-by-side with customizable background colors for byte, mnemonic, and operand differences, as well as unmatched code units. The new ListingCodeComparisonView provides a dual-pane interface that synchronizes scrolling and cursor location between the two listings. It includes actions to toggle ignoring specific types of differences (bytes, constants, registers) and highlights the differing code units in the listing view. The implementation adds several new classes including LinearAddressCorrelation for address mapping, ListingDiffActionManager to handle diff-related actions, and ListingDiffHighlightProvider to render the visual differences.
Ghidra/Features/Base/src/main/java/ghidra/features/base · high confidence
New platform selection interface for debugger traces
A new graphical interface allows users to view and select debugger platform options for a trace. The \DebuggerPlatformPlugin\ now manages a set of toggle actions for each available platform offer, while the \DebuggerSelectPlatformOfferDialog\ presents a sortable, filterable table of these offers, displaying details such as processor, variant, size, endianness, and compiler specification.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/platform · high confidence
New registers management UI for the Debugger
The Debugger now includes a dedicated plugin and provider for viewing and modifying register values. This change introduces a new 'Registers' tab in the debugger interface, allowing users to see a table of available registers, their values, types, and representations. Users can edit register values directly in the table, set favorite registers, and configure data types for registers. The UI includes a dialog for selecting available registers and a filterable table for managing them. This provides a more integrated and user-friendly way to interact with CPU registers during debugging sessions.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/register · high confidence
New scripts for Trace RMI and Terminal services
Added new Ghidra scripts to support Trace RMI and Terminal services. The Trace RMI scripts (ConnectTraceRmiScript, ListenTraceRmiScript) allow users to connect to and listen for Trace RMI connections, while the Terminal scripts (RunBashInTerminalScript, TerminalGhidraScript) enable launching interactive terminal sessions within Ghidra. Additionally, ClearLaunchConfigScript was added to clear launch configuration data.
_Ghidra/Debug/Debugger-rmi-trace/ghidra\scripts · high confidence
New stack unwinding infrastructure for the debugger
The debugger now includes a new stack unwinding framework located in the \ghidra.app.plugin.core.debug.stack\ package. This introduces a \StackUnwinder\ that can traverse the call stack by analyzing register states and memory mappings. The implementation provides multiple frame representations: \AnalysisUnwoundFrame\ for frames derived from static analysis, \ListingUnwoundFrame\ for frames annotated in the trace listing, and \FakeUnwoundFrame\ for evaluating variables without a full stack context. The system also includes helper classes like \SavedRegisterMap\ to track register-to-stack mappings and \StackUnwindWarning\ to report issues such as unknown function purges or missing return paths. This infrastructure enables more robust debugging by allowing the debugger to reconstruct stack frames and evaluate local variables even when dynamic execution state is incomplete.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/stack · high confidence
New table widget utilities for debugger and trace views
The ProposedUtils module now includes a suite of new table widget classes to support debugger and trace views. This includes a GAddressRangeField for selecting address ranges, a CustomToStringCellRenderer for flexible cell rendering, and a set of enumerated column table models (DefaultEnumeratedColumnTableModel, RowWrappedEnumeratedColumnTableModel) that simplify the creation of editable, enum-driven tables. Additional utilities include HexBigIntegerTableCellEditor and HexDefaultGColumnRenderer for hexadecimal display, IconButtonTableCellEditor/Renderer for clickable icons, and SpanTableCellRenderer for visualizing data ranges.
Ghidra/Debug/ProposedUtils · high confidence
New theming infrastructure for the Docking module
The Docking module now supports a comprehensive theming system, introducing new configuration files that define colors, fonts, and icons for UI components such as headers, tabs, buttons, and file choosers. This enables users to customize the visual appearance of the application's docking and data-viewing interfaces through theme properties.
Ghidra/Framework/Docking/data · high confidence
New trace-related plugin events for debugger state changes
Added new plugin event classes to the debugger core, including TraceOpenedPluginEvent, TraceClosedPluginEvent, TraceLocationPluginEvent, TraceSelectionPluginEvent, TraceHighlightPluginEvent, TraceInactiveCoordinatesPluginEvent, TraceActivatedPluginEvent, DebuggerPlatformPluginEvent, and TrackingChangedPluginEvent. These events allow plugins to react to trace lifecycle changes, location/selection updates, and platform mappings.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/event · high confidence
New utility classes for file, jar, and thread management
Added new classes to the Utility framework: a thread pool manager (GThreadPool) and a set of abstractions for handling file and jar resources (Resource, FileResource, JarResource, ResourceFile) along with a custom class loader (GClassLoader) and application layout classes (GhidraApplicationLayout, GhidraJarApplicationLayout) to support dynamic module discovery and loading.
Ghidra/Framework/Utility · high confidence
New x64dbg debugger agent and Python client for remote debugging
The x64dbg debugger agent is now available, providing a Python-based client that connects to the x64dbg debugger via Trace RMI. This enables Ghidra to launch, attach to, and interact with x64dbg sessions locally or over SSH. The release includes the full Python package (arch, commands, hooks, methods, util), the associated XML schema for state synchronization, and comprehensive help documentation covering setup, options, and remote configuration.
Ghidra/Debug/Debugger-agent-x64dbg · high confidence
PDB module adds developer scripts and metadata files
The PDB feature module now includes a suite of developer scripts designed to assist with debugging and analysis of PDB files. These scripts allow users to dump PDB information, mangled symbol names, mangled type names, and all data types to text files. Additionally, a script is provided to apply PDB data to a dummy program for testing purposes. The module also introduces new metadata files, including a module manifest, a certification manifest, and a README, to support the feature's structure and documentation.
Ghidra/Features/PDB · high confidence
PowerPC ELF and COFF relocation support added
Ghidra now supports ELF and COFF relocation processing for PowerPC binaries. This includes new handlers for 32-bit and 64-bit ELF formats, enabling proper resolution of symbols, GOT/PLT entries, and function descriptors (including ELFv2 and ELFv1 ABI variants). Additionally, basic relocation handling for COFF (Windows) binaries is introduced. These changes improve the accuracy of binary analysis for PowerPC targets by correctly applying relocations during the loading phase.
Ghidra/Processors/PowerPC · high confidence
PyGhidra interpreter and script provider implementation
The PyGhidra feature adds an interactive Python interpreter and a script provider for running Python scripts within Ghidra. This includes the Java plugin and script provider classes that integrate the Python environment with Ghidra's API, along with supporting files like help documentation, Eclipse launch configurations, and module manifests.
Ghidra/Features/PyGhidra · high confidence
RISC-V language files restructured and extended with AndeStar V5 support
The RISC-V language definitions have been reorganized and expanded. The default language definitions are now in \riscv.ldefs\ and \riscv.lp64d.slaspec\, while the previous generic variants (RV32I, RV64I, etc.) have been moved to \old/riscv\_deprecated.ldefs\ to indicate they are deprecated. A new AndeStar V5 variant has been added, including \andestar\_v5.ldefs\, \andestar\_v5.slaspec\, and \andestar\_v5.instr.sinc\ which define custom instructions and memory spaces specific to that architecture. Additionally, the core RISC-V specification files (\RV32.pspec\, \RV64.pspec\) and instruction sets (\riscv.instr.sinc\, \riscv.csr.sinc\, \riscv.custom.sinc\) have been updated to support these changes, improving the accuracy of decompilation and disassembly for both standard and custom RISC-V extensions.
Ghidra/Processors/RISCV/data/languages · high confidence
SARIF import and export support added to Ghidra
Users can now import and export Static Analysis Results Interchange Format (SARIF) files. The new 'Sarif' plugin provides a 'Read File' action to load SARIF results into a table for inspection and ingestion into the current program. An exporter is also available to generate SARIF files from the current program, with options to include memory blocks, code, data types, symbols, and other program elements. The module relies on the java-sarif-2.1-modified.jar library.
Ghidra/Features/Sarif · high confidence
Sleigh Editor IDE and UI components added
The Sleigh language editor now includes full IDE and UI support within the Eclipse plugin. This adds semantic highlighting for Sleigh syntax elements (such as variables, tokens, and context fields), hover text for definitions and subtables, content assist proposals, and a document outline view. It also introduces console hyperlinking to allow users to click on error messages in the console to navigate directly to the corresponding source file and line number.
GhidraBuild/EclipsePlugins/GhidraSleighEditor/ghidra.xtext.sleigh.ide, GhidraBuild/EclipsePlugins/GhidraSleighEditor/ghidra.xtext.sleigh.ui · high confidence
SleighEditor grammar and tooling implementation
The SleighEditor plugin is now fully implemented with a complete Xtext-based grammar (Sleigh.xtext) and supporting infrastructure, including value converters for integer, hexadecimal, and binary literals, a custom scope provider for symbol resolution, and a validator that enforces uniqueness for token, context, and variable names. This provides the Eclipse-based editor with syntax highlighting, code completion, and validation for Sleigh specification files.
GhidraBuild/EclipsePlugins/GhidraSleighEditor/ghidra.xtext.sleigh · high confidence
SuperH instruction manual index added
A new index file for the SuperH processor's programming manual has been added, providing a searchable list of instructions (such as add, mov, and cmp) with their corresponding page numbers in the SuperH RISC Engine SH-1/SH-2 Programming Manual.
Ghidra/Processors/SuperH/data/manuals · high confidence
Trace debugger disassembler plugin adds disassembly and patching actions
The Debugger Disassembler Plugin now provides actions to disassemble, assemble, and patch instructions and data within trace views. Users can now use the 'Disassemble' action to generate instructions from raw bytes in a trace, and the 'Patch Instruction' and 'Assemble' actions to modify trace state. The plugin also introduces a pluggable 'DisassemblyInject' framework to configure disassembler context based on trace platform and status registers.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/disassemble · high confidence
TriCore processor module adds ELF relocation handling and emulation support
The TriCore processor module now includes support for ELF relocation handling, allowing Ghidra to process TriCore-specific ELF relocations during binary loading. Additionally, emulation capabilities have been enhanced with new P-code user operations for saving and restoring caller state (FCX, LCX, PCXI, PSW, and various registers) during function calls and returns, ensuring accurate state preservation and restoration in the emulator.
Ghidra/Processors/tricore · high confidence
Version Tracking feature initialization and script examples
The Version Tracking feature module is initialized with core configuration files, including extension points for correlators and a theme properties file defining colors and icons for the UI. Additionally, a collection of example and utility scripts is added to the module, including scripts for auto-tracking, session management, and function comparison, providing users with templates for automating version tracking workflows.
Ghidra/Features/VersionTracking · high confidence
Security
New client-side RMI deserialization filter and authentication framework for Ghidra Server
This change introduces a new client-side Java RMI deserialization filter (\client.rmi.serial.filter\) to restrict the classes allowed during remote object deserialization, addressing potential security vulnerabilities in Ghidra Server communications. Alongside the filter, a new authentication framework is added to \Ghidra/Framework/FileSystem\, including the \ClientAuthenticator\ interface and its implementations (\DefaultClientAuthenticator\, \HeadlessClientAuthenticator\, \PasswordClientAuthenticator\) which handle password and SSH key-based authentication for connecting to the Ghidra Server. The update also includes new utility classes like \ClientUtil\ and \RepositoryServerAdapter\ to manage server connections and state, as well as specific exception classes (\NotConnectedException\, \RepositoryNotFoundException\) to handle connection failures.
Ghidra/Framework/FileSystem · high confidence
Architecture
Restructured build system for GPL modules
The build system for GPL modules has been refactored to use a shared Gradle script (nativeBuildProperties.gradle) that defines common native build settings and platform configurations. New build scripts (build.gradle, buildGdis.gradle, settings.gradle) were added for the DMG, DemanglerGnu, and GnuDisassembler modules, standardizing how native code is compiled and packaged for various operating systems and architectures.
(dependencies) · high confidence
Behavioural changes
6502 processor module restructured with 65c02 variant support
The 6502 processor module has been reorganized to include support for the 65c02 processor variant, alongside the standard 6502. This change introduces new module manifest and certification files that define the structure for both processor types, including specific language specification files (cspec, ldefs, pspec, slaspec) for each. Users will now see the 65c02 variant as a distinct, supported processor option within the 6502 module.
Ghidra/Processors/6502 · medium confidence
8051 processor module structure reorganized
The 8051 processor support has been reorganized into a new module directory structure. This includes the addition of a Module.manifest, README.md, and a certification.manifest that explicitly lists the associated language specification files (cspec, pspec, slaspec, etc.) for the 8051, 80251, 80390, and related variants, along with manual index files.
Ghidra/Processors/8051 · medium confidence
Added SuperH processor support with language specifications and certification
Users can now utilize the SuperH architecture in Ghidra. This change introduces the SuperH processor support, including language specifications (slaspec) for SH-1, SH-2, and SH-2A variants, along with the necessary certification and module manifest files to enable the processor in the tool.
Ghidra/Processors/SuperH · medium confidence
Added default symbol server and debuginfod URLs for DWARF and PDB debugging
Ghidra now includes pre-configured URLs for downloading debug symbols. For DWARF-based binaries, the new DWARF.debuginfod\_urls file lists public debuginfod servers from major Linux distributions (Fedora, Ubuntu, Debian, openSUSE, Arch, CentOS). For Windows PDB files, the new PDB\_SYMBOL\_SERVER\_URLS.pdburl file lists Microsoft, Chromium, and Mozilla symbol servers. These additions allow users to automatically fetch missing debug symbols from the internet, with security warnings about organizational policies.
_Ghidra/Configurations/Public\Release/data · medium confidence
Added help documentation for Debugger Disassembler and Assembler actions
Users can now view help documentation for the Debugger's disassembler and assembler features. This includes details on the 'Disassemble' action, which disassembles linearly up to the next branching instruction, and the 'Assemble' and 'Patch Instruction' actions, which allow users to assemble instructions or patch data at the cursor. The documentation also covers the 'Patch Data' action for encoding data units.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerDisassemblerPlugin · high confidence
Added license files for Apache, BSD, Creative Commons, and other open-source components
The \licenses\ directory now includes text and HTML files for a wide range of open-source licenses, including Apache 2.0, BSD (2- and 3-clause variants for Apple, Google, Oracle, etc.), Creative Commons Attribution 2.5, Bouncy Castle, and GNU GPL with Classpath exception. These files provide the legal text required for compliance with the respective open-source licenses used in the project.
licenses · high confidence
Byte Viewer: New theming, copy formats, and UI refactoring
The Byte Viewer has been refactored to support theme-based colors and fonts, allowing the appearance of the Byte Viewer to adapt to the user's selected theme. Additionally, the 'Copy Special' feature now supports Python byte-string, Python list, and C/Java array formats. The UI has been updated to use GLabel, GComboBox, and GCheckBox components, and the help documentation has been restructured to reflect these changes.
Ghidra/Features/ByteViewer · high confidence
Comprehensive fixes to the Docking framework and UI components
This release addresses a wide range of bugs and behavioral issues within the Ghidra Docking framework. Key improvements include a robust theming system that updates UI colors and fonts dynamically, fixing numerous rendering glitches in tables, trees, and dialogs. The update resolves numerous keybinding conflicts and ensures that global and window-specific key bindings are correctly scoped and applied. Accessibility is enhanced through improved screen reader support, focus management, and keyboard navigation for menus, popups, and table filters. Additionally, the commit fixes memory leaks related to Swing component disposal, corrects dialog parenting and modal state issues, and resolves various edge cases in the Function Graph, Symbol Tree, and File Chooser components.
Ghidra/Framework/Docking · medium confidence
Database framework refactored with new field and buffer classes
The database framework has been refactored to introduce a new set of field types (BinaryCodedField, BooleanField, ByteField, etc.) and buffer classes (ChainedBuffer, DBBuffer, etc.) that provide a more robust and flexible way to store and retrieve data. These changes improve data handling, support for sparse records, and enhance the overall stability and performance of the database layer.
Ghidra/Framework/DB · medium confidence
Debugger theming and extension points for dark mode and UI consistency
The debugger UI now supports dark mode and consistent theming across components like the memory view, time overview, and breakpoint timeline. This is achieved by introducing a new \debugger.theme.properties\ file that maps UI elements to palette colors and fonts, and an \ExtensionPoint.manifest\ that registers debugger-specific extension points (e.g., \AutoMapSpec\, \EmulatorFactory\). These changes ensure that debugger views such as the memory browser, register/watch windows, and breakpoint timeline adapt to the current theme, improving readability and visual consistency.
Ghidra/Debug/Debugger/data · high confidence
Ghidra 12.2 release configuration and build environment updates
The release configuration has been updated to version 12.2, with the release name set to 'DEV'. The build environment now requires Java 25 (min and compiler) and supports Python versions 3.9 through 3.14. Additionally, the minimum supported Gradle version has been raised to 9.1, and new Git attributes and ignore rules have been introduced to manage binary merges and build artifacts.
Ghidra · high confidence
Graph module theming and extension point registration
The Graph framework now supports theme-based styling for visual graphs, with new properties defining colors for vertices, edges, and labels (e.g., green for default edges, blue for selected items) and font attributes. Additionally, an ExtensionPoint.manifest file registers the GraphDisplayProvider, enabling the graph display functionality to be discovered and used by the application.
Ghidra/Framework/Graph/data · medium confidence
Improved ELF relocation handling for AVR8 and AVR32 processors
The ELF loader for Atmel AVR8 and AVR32 processors now uses dedicated relocation handlers (AVR8\_ElfRelocationHandler, AVR32\_ElfRelocationHandler) with specific relocation type enums (AVR8\_ElfRelocationType, AVR32\_ElfRelocationType) to process ELF binaries. This includes support for various relocation types such as PC-relative, constant pool, and dynamic relocations, improving the accuracy of symbol resolution and memory layout for these architectures. Additionally, the ELF extension for AVR8 (AVR8\_ElfExtension) handles code space offset adjustments and symbol evaluation. New emulator-based tests have been added for AVR8 (AVR8\_31, AVR8\_51, AVR8\_6, AVR8\_xmega) and AVR32 processors to validate these changes.
Ghidra/Processors/Atmel · high confidence
Improved ELF relocation handling for TI MSP430 and MSP430X processors
Added new ELF extension and relocation handler classes for TI MSP430 and MSP430X processors, implementing support for various relocation types (ABS, PCREL, EXT) and handling of unresolved symbols. This change improves the accuracy of ELF loading for these architectures by properly applying relocations during analysis. Additionally, CSpec tests were added to catch regressions in analysis based on CSpec prototype configurations.
_Ghidra/Processors/TI\MSP430 · high confidence
Improved debugger performance and trace file support
The debugger now features improved performance through debounced table updates and background task handling. Additionally, the debugger now supports importing and exporting packed Ghidra Trace (GZT) files, allowing users to save and load trace data in a compressed, portable format.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/utils · high confidence
Improved handling of zero-length data types and components
The SoftwareModeling framework now supports zero-length arrays and zero-length structure components, allowing these edge cases to be processed without errors. The \Structure.getComponentAt\ and \Structure.getComponentContaining\ methods have been revised to ignore zero-length components, and a new \DataType.isZeroLength()\ method has been added to the API. This change ensures that data type operations remain stable when encountering or creating zero-length structures, preventing potential null pointer exceptions or unexpected behavior during analysis and editing.
Ghidra/Framework/SoftwareModeling · high confidence
New Emulator tool and reconfigured Debugger tool layout
A new Emulator tool has been introduced, providing a dedicated workspace for emulation tasks, while the existing Debugger tool has been reconfigured to exclude TraceRmi-related plugins and adjust the default layout. The Debugger tool now features a centralized Debug Console and a reorganized split-view with components like the Model, Listing, Decompiler, and Registers, while the Emulator tool includes similar debugging components but excludes TraceRmi launcher and connection plugins.
Ghidra/Debug/Debugger/src/main/resources/defaultTools · high confidence
New default behaviors for memory reading, location tracking, and auto-mapping in the debugger
The debugger now uses new default specifications for automatic memory reading, location tracking, and memory mapping. Users will see updated default behaviors for how the debugger automatically reads memory regions, tracks the current program counter or stack pointer, and maps trace memory to program symbols. These changes streamline the debugging experience by providing more sensible defaults for common debugging workflows, such as automatically loading memory for emulation traces or tracking the program counter by register or stack.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/gui/action · high confidence
New extension points and charset metadata for software modeling and theming
The SoftwareModeling module now registers new extension points (AnnotationHandler, RelocationHandler, LanguageTranslator, Constraint, and DataType) and includes a comprehensive charset\_info.json file that defines properties for various character encodings (such as Big5, CESU-8, etc.), enabling the ByteViewer to decode bytes using any available charset. Additionally, a new softwaremodeling.theme.properties file defines default and dark-mode icons for content handlers and data types, supporting the application's theming system.
Ghidra/Framework/SoftwareModeling/data · high confidence
New help documentation for the Breakpoint Marker Plugin
A new help page for the Debugger Breakpoint Marker Plugin has been added, detailing how breakpoints are visually indicated in the Listings, Function Graph, and Decompiler. The documentation explains the use of background colors and margin markers to show breakpoint states (enabled, disabled, ineffective) and describes the available actions for setting, toggling, enabling, disabling, and clearing breakpoints, including the prompt for user-defined names.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerBreakpointMarkerPlugin · high confidence
New help documentation for the Debugger Console plugin
Added new help documentation for the Debugger Console plugin, detailing its role as a central log for debugger-related messages and plugin-delivered actionable messages. The documentation explains the table structure (Icon, Message, Actions, Time), sorting behavior (actionable messages at the top, then by date), and available actions such as Clear, Select None, and Cancel for background tasks.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerConsolePlugin · high confidence
New help documentation for the Debugger Modules and Sections plugin
Added comprehensive help documentation for the Debugger Modules and Sections plugin, detailing the module and section tables, their columns, and all available actions including Auto-Map, Map Identically, Map Manually, and handling missing modules or programs via the Debug Console.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerModulesPlugin · high confidence
New help documentation for the Debugger Regions plugin
Added comprehensive help documentation for the Debugger Regions plugin, detailing the Memory Regions window and its table columns (Name, Start, End, Length, Read/Write/Execute flags, Key, and Path). The documentation also describes the available actions, including Map Regions, Map Regions to Current Program, Map Region to Current Block, Select Addresses, Select Rows, Add Region, Delete Regions, and Force Full View, explaining their specific behaviors and use cases within the debugger.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerRegionsPlugin · high confidence
New help documentation for the Debugger Stack plugin
A new help page for the Debugger Stack plugin has been added, explaining the stack window's behavior, table columns (Level, PC, Function, Module), and the 'Unwind Stack' action. The documentation details how the plugin displays the current trace's execution stack, how double-clicking a frame activates new coordinates, and how the 'Unwind Stack' action uses Ghidra's program databases to generate frame data units with local variables, parameters, return addresses, saved registers, and slack space.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerStackPlugin · medium confidence
New help documentation for the Debugger Time plugin
Added comprehensive help documentation for the Debugger Time plugin, detailing the Time window's table columns (Snap, Time, Event Thread, PC, Module, Function, Timestamp, Schedule, Description), actions (Rename Snapshot, Go To Time, Hide Scratch, Set Time Radix), and the syntax for time schedules including emulation stepping and p-code operations.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerTimePlugin · high confidence
New platform opinions and disassembly injections for debugger backends
The debugger plugin now includes new platform opinion classes for Dbgeng, Frida, GDB, JDI, and LLDB, each providing specific language and compiler spec mappings for those debuggers. Additionally, new disassembly injection classes are introduced for ARM (handling Thumb mode via CPSR) and for Dbgeng x64 (setting longMode, addrsize, and opsize registers). An override mechanism is also added to allow users to manually select a platform, and the system now supports multiple platform offers simultaneously to improve automatic detection.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/platform · high confidence
Project data tree icons and theme colors updated
The project data tree now uses new icon definitions for version control states (connected/disconnected), content handlers, and file types, with specific overlays for status indicators. Additionally, theme properties have been added to define foreground and background colors for various UI components, including extension panels, plugin details, log viewer, and key bindings, supporting both default and dark mode themes.
Ghidra/Framework/Project/data · high confidence
Public release configuration updated with new module manifest and certification files
The Public\_Release configuration now includes a new Module.manifest and a certification.manifest that explicitly lists the included documentation and resource files, such as ChangeHistory.md, WhatsNew.md, and various data files. This change formalizes the public release package by defining the exact set of files to be distributed, ensuring that key user-facing documents and configuration resources are properly packaged and certified for the public release.
_Ghidra/Configurations/Public\Release · medium confidence
Public release configuration updated with user agreement and default tool settings
The public release configuration now includes a User Agreement and splash screen text clarifying the Apache 2.0 license terms and third-party component notices. The CodeBrowser tool configuration has been updated to include the BSim plugin by default in the package structure, and the layout has been adjusted to reflect recent name changes and a correction to a bad entry in the CodeBrowser tool config.
_Ghidra/Configurations/Public\Release/src/main · medium confidence
Python type stub generation and Javadoc processing refactored
The doclet system for generating Python type stubs and JSON documentation has been restructured. The \JsonDoclet\ was moved to a new \json\ package, and the \typestubs\ package was reorganized with new classes including \DocConverter\, \HtmlConverter\, \JavadocConverter\, and \PythonTypeStubDoclet\. This refactoring improves the generation of \.pyi\ files and Python pre-definitions, ensuring that Python developers using PyGhidra receive accurate type hints and documentation. The changes also include fixes to Javadoc processing to handle HTML tags and Markdown more robustly, and ensure that the generated stubs correctly map Java types to Python equivalents.
GhidraBuild/BuildFiles/Doclets · medium confidence
Refactor emulation data access with new shims
The emulation data access layer has been refactored to use a new set of shims (AbstractPcodeDebuggerAccess, DefaultPcodeDebuggerAccess, TranslatedPcodeDebuggerAccess, etc.) that integrate with the Target interface. This change introduces a more modular approach to handling memory, registers, and properties during emulation, allowing for better separation of concerns between the debugger and the trace. The new structure supports dynamic address translation and property mapping, enhancing the flexibility of the emulation service.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/emulation/data · high confidence
Refactored debugger breakpoint service to use an action-based execution model
The debugger's logical breakpoint service has been refactored to use an action-based execution model. Breakpoint state changes (enable, disable, delete) and placements (for emulated and target breakpoints) are now represented as distinct action items collected in a \BreakpointActionSet\. This set deduplicates and executes these actions asynchronously, improving the handling of breakpoint updates and reducing UI glitches and timing issues.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/breakpoint · medium confidence
Refactored trace saving logic into dedicated task classes
The trace saving functionality has been refactored into specific task classes: AbstractSaveTraceTask, SaveNewTraceTask, SaveTraceAsTask, and SaveTraceTask. This change introduces a more structured approach to saving traces, with each class handling a specific type of save operation (new, as, or existing). The refactoring ensures that trace saving operations are handled consistently and safely, with proper locking and error handling. Users will experience more reliable trace saving operations, with improved error reporting and handling of edge cases such as duplicate file names.
Ghidra/Debug/Debugger/src/main/java/ghidra/app/plugin/core/debug/service/tracemgr · high confidence
Restructure MC6800 processor support and add H6309
The MC6800 processor support has been reorganized into a modular layout, moving 6805 support into the MC6800 directory to better allow extensions. Additionally, the H6309 processor is now supported, with new language specification and manual files added for it.
Ghidra/Processors/MC6800 · medium confidence
SPARC ELF relocation and analysis improvements
SPARC processors now include new analysis and relocation handlers to improve binary processing. The SPARC analyzer checks for the setting of the o7 return link register in the delay slot of calls, allowing Ghidra to correctly identify non-returning calls and fix flow. Additionally, ELF relocation handling has been updated with specific handlers for SPARC and SPARC64, supporting a wider range of relocation types (including 64-bit and TLS relocations) and improving the handling of unresolved symbols and statically linked binaries.
Ghidra/Processors/Sparc · high confidence
Updated AArch64 instruction manual index
The AArch64 processor manual index has been updated to include a comprehensive list of AArch64 instructions (such as abs, adc, add, aesd, etc.) with their corresponding page numbers in the ARM Architecture Reference Manual (DDI 0487H.a). This change ensures that the documentation lookup for AArch64 instructions is current and complete.
Ghidra/Processors/AARCH64/data/manuals, Ghidra/Processors/x86/data/manuals · medium confidence
Updated ARM instruction manual index with new A-profile and AArch64 entries
The ARM processor module now includes an updated index of instruction manuals, adding support for A-profile and AArch64 architecture specifications up to version 9. This update includes the addition of the 'cbz' instruction and other A-profile instructions, ensuring that the documentation references are current with the latest ARM architecture standards.
Ghidra/Processors/ARM/data/manuals · medium confidence
Updated ARM language support with AAPCS and APCS calling conventions
Ghidra's ARM processor now supports the ARM/Thumb v8 architecture with explicit compiler specifications for the ARM/Thumb v8 little and big endian variants, as well as the legacy APCS and Windows-specific calling conventions. The update introduces new \.cspec\ files defining parameter passing rules for the AAPCS (default) and APCS standards, mapping floating-point and integer registers (s0-s31, r0-r12) to function arguments and return values. Additionally, the change adds a DWARF register mapping file to improve debug symbol analysis and a \.gdis\ file to configure GNU external disassembler options for ARM and Thumb modes. These language files enable more accurate decompilation and analysis of ARM binaries by correctly interpreting function calls, register usage, and debug information.
Ghidra/Processors/ARM/data/languages · high confidence
Updated Breakpoints help documentation
The help documentation for the Debugger Breakpoints plugin has been updated to reflect the current state of the feature. The documentation now includes details about the 'Expression' column in the bottom table, which shows the user-defined expression for a breakpoint location. It also clarifies that breakpoints can be placed in the emulator with Sleigh injections or custom conditions, and explains the states of breakpoints (effective, ineffective, inconsistent) and the available actions (Set Breakpoint, Enable, Disable, etc.).
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerBreakpointsPlugin · high confidence
Updated Debugger Control Plugin documentation
The help file for the Debugger Control Plugin has been updated to reflect the new global control actions for the Target, Trace, and Emulator. The documentation now details the different control modes (Target, Trace, Emulator) and their respective actions, including resume, interrupt, step, and kill commands for each mode. It also covers trace navigation and emulation actions, providing users with clear guidance on how to control and modify machine state in each context.
Ghidra/Debug/Debugger/src/main/help/help/topics/DebuggerControlPlugin · high confidence
Updated Eclipse code formatting and project preferences
The default Eclipse code formatter profiles for both C++ (GhidraCDTFormatter) and Java (GhidraEclipseFormatter) have been updated to enforce a consistent coding style across the project. Additionally, the Eclipse project preferences (GhidraSharedPreferences.epf) have been refreshed to align with the new formatting rules and compiler settings.
eclipse · high confidence
Updated GnuDemangler v2.24 to handle function qualifiers and static qualifiers
The GnuDemangler v2.24 implementation was updated to correctly handle type qualifiers when used alongside the 'F' character for functions, and added legacy support for the static qualifier. These changes ensure that mangled symbols containing these specific C++ qualifiers are demangled accurately, preventing potential segmentation faults and improving the completeness of the demangled output.
GPL/DemanglerGnu · high confidence
Updated MIPS processor manual indexes
The index files for the MIPS processor manuals (MIPS.idx, mipsM16.idx, mipsMic.idx, and r4000.idx) have been updated to the latest version. This refreshes the reference manual content and corrects spelling and indexing errors, ensuring that users have access to the most accurate and up-to-date documentation for MIPS instruction sets.
Ghidra/Processors/MIPS/data/manuals · medium confidence
Updated PowerPC and PowerISA instruction indexes
The PowerPC and PowerISA instruction index files have been updated to reflect the latest documentation. The PowerISA index now references the OpenPower Power ISA, Version 3.1 (May 2020), while the PowerPC index references the PowerPC Microprocessor Family Programming Environments Manual, Version 2.3 (March 2005). These updates ensure that instruction lookups in Ghidra's manual search correspond to the correct pages in the respective PDFs.
Ghidra/Processors/PowerPC/data/manuals · medium confidence
Z80 processor module structure and certification updated
The Z80 processor module in Ghidra has been updated with a new directory structure, including the addition of a Module.manifest, README.md, and a certification.manifest file that explicitly lists the supported language specifications (such as z80, z180, z182, and z8401x) and manual indices. This change reflects an update to the module's certification headers and internal organization, ensuring that the necessary files for language parsing and documentation are correctly registered within the module.
Ghidra/Processors/Z80 · medium confidence
Fixes
Added help theme color mappings
A new help.theme.properties file was added to define color mappings for the help system, specifying foreground and background colors for headings, selectors, and code blocks using the application's palette.
Ghidra/Framework/Help/data · medium confidence
Added missing x86 old language v2-v3 translators and corrected old language file parse bug
Added missing language translation files (x86RealV1/V2/V3.lang and .trans) for the x86 processor's old language definitions, enabling proper versioning and migration paths for 16-bit and 32-bit real and protected mode variants. This resolves a parsing bug in the old language files that prevented correct interpretation of x86-16 Protected and SMM mode variants.
Ghidra/Processors/x86/data/languages/old · high confidence
Test coverage
Added MockTarget test double for debugging service tests; Added automated checks for empty PNG images and placeholder tests for debugger opinions; Added automated screenshot generation for the Debugger Memory View plugin; Added automated screenshot tests for the Debugger Model Plugin; Added automated tests for the Debugger Modules and Static Mapping providers; Added certification manifests for test resources; Added comprehensive test coverage for Version Tracking core components; Added debugger integration test programs and screenshot tests; Added emulator tests for V850 and RH850 processors; Added emulator-based unit tests for CR16C processor; Added integration tests for core plugins and UI components; Added screenshot generation for the Debugger Threads plugin; Added screenshot generation tests for Debugger Listing Plugin; Added screenshot tests for Debugger Modules and Static Mapping plugins; Added screenshot tests for Debugger copy-into-program actions; Added screenshot tests for Debugger memory plugins; Added screenshot tests for the Debugger Console Plugin; Added screenshot tests for the Debugger Trace View Diff Plugin; Added screenshot tests for the Debugger Watches plugin; Added screenshot tests for the Pcode Stepper plugin; Added screenshot tests for the debugger platform selection dialog; Added screenshot tests for the debugger registers plugin; Added screenshot tests for the variable value hover feature; Added test accessors for debugger listing and trace manager services; Added test coverage for the P-code stepper provider; Added test for debugger platform opinion mapping; Added test infrastructure for debugger GUI components; Added test resources and unit tests for import and version tracking; Added tests for BSim query functionality; Added tests for DebuggerTraceTabPanel; Added tests for FSBIcons; Added tests for Function ID manager and filtering logic; Added tests for SleighEditor parsing and scope resolution; Added tests for memory search and function comparison models; Added tests for memory search and value selection features; Added tests for project and domain folder change listeners; Added tests for stack unwinding functionality; Added tests for the Debugger Disassembler Plugin; Added tests for the Debugger Threads Provider; Added tests for the Debugger Trace View Diff Plugin; Added tests for the DebuggerStaticMappingService; Added tests for the DebuggerTimeProvider; Added tests for the debug model provider and query functionality; Added tests for the debugger copy plan and UI interactions; Added tests for the debugger emulation service; Added tests for the debugger stack provider; Added tests for the dual decompiler and function comparison plugin; Added unit tests for BSim self-similar correlator; Added unit tests for the Debugger Console Provider; Added unit tests for the Debugger Regions Provider; Added unit tests for the DebuggerPlatformPlugin; Documentation and tests added for the Breakpoint Timeline plugin; Expanded test coverage for JVM processor; Version Tracking test suite refactored with new test harnesses and base classes.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 47.
Lenses
- Code Health 72
- Architecture 100
- Maturity 62
- Readiness 47
- Security 48
- Domain Modelling 100
- Accessibility 39
Changes since last survey
- 300 commits — 243 feature/other, 57 fixes
By area
- (repo) — 148 commits
- Ghidra/Features — 78 commits
- Ghidra/Debug — 19 commits
- Ghidra/Framework — 18 commits
- Ghidra/Processors — 17 commits
- Ghidra/Test — 4 commits
- Ghidra/Extensions — 3 commits
- Ghidra/RuntimeScripts — 3 commits
- GhidraBuild/IDAPro — 2 commits
- (root) — 1 commit
- .github/workflows — 1 commit
- GPL/DMG — 1 commit
- GhidraBuild/BuildFiles — 1 commit
- GhidraBuild/LaunchSupport — 1 commit
- GhidraDocs/GettingStarted.md — 1 commit
- eclipse/GhidraSharedPreferences.epf — 1 commit
- gradle/hasProtobuf.gradle — 1 commit
Notable commits
- fix: 9303: aligning fix with #9188
- fix: Fix IDA 9 XML importer structure member type handling
- fix: Fix IDA v9 XML exporter datatype comment handling
- fix: Fix debugger module indexing startup hang
- fix: Fix for stack trace related to setting row height
- fix: Fix gdb on OpenBSD/amd64 by: * Filtering out registers that are "<unavailable>" when querying gdb for register list. * Force querying gdb for register list on OpenBSD.
- fix: Fix sev.w arm encoding.
- fix: Fixed Decompiler message area not going away when changing functions
- fix: Fixed search highlights for multi-row components
- fix: Fixed table row height not resizing correctly as the font size is changed
- fix: Fixed test focus issue when typing into text fields on FlatLaf
- fix: GP-0: Fix tests and clean up.
- fix: GP-0: Fix tests.
- fix: GP-0: Fix tests.
- fix: GP-0: Fixed potential NPE in ImageCor20Header.java (Closes #2246)
- fix: GP-0: Javadoc fix
- fix: GP-0: Javadoc fixes
- fix: GP-0: More javadoc fixes
- fix: GP-1 Corrected regression to SymbolDB refresh from GP-6634 change
- fix: GP-1 Minor fixes back-ported from GP-6779: project in-use tracking, data type archive address factory
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
NationalSecurityAgency/ghidra was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 5 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7462bcec30b597b0b51f549f0bb39a63a942c577 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.