ghidra-cli/schemas/v1/functions.schema.json
2026-07-28 22:20:39 +00:00

605 lines
16 KiB
JSON

{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "SuccessEnvelope",
"description": "Versioned successful response.",
"type": "object",
"properties": {
"data": {
"description": "Operation-specific result.",
"$ref": "#/$defs/InlineOrArtifact"
},
"kind": {
"type": "string",
"const": "functions"
},
"provenance": {
"description": "Reproducibility and execution context.",
"$ref": "#/$defs/QueryProvenance"
},
"schema_version": {
"type": "integer",
"const": 1
},
"warnings": {
"description": "Deduplicated stable warnings.",
"type": "array",
"items": {
"$ref": "#/$defs/Warning"
}
}
},
"required": [
"schema_version",
"kind",
"provenance",
"data",
"warnings"
],
"$defs": {
"Address": {
"description": "A Ghidra address with an explicit, case-sensitive address space.",
"type": "object",
"properties": {
"offset": {
"description": "Canonical lowercase, `0x`-prefixed, even-width hexadecimal offset.",
"type": "string"
},
"space": {
"description": "Exact Ghidra address-space name.",
"type": "string"
}
},
"required": [
"space",
"offset"
]
},
"AnalysisStoreProvenance": {
"description": "Analysis Store provenance.",
"type": "object",
"properties": {
"path": {
"description": "Tagged absolute store path.",
"$ref": "#/$defs/TaggedPath"
},
"source": {
"description": "Store resolution source.",
"$ref": "#/$defs/StoreSource"
}
},
"required": [
"path",
"source"
]
},
"ArtifactDescriptor": {
"description": "Artifact descriptor returned instead of oversized inline data.",
"type": "object",
"properties": {
"bytes": {
"description": "Exact file bytes including trailing LF.",
"type": "integer",
"format": "uint64",
"minimum": 0
},
"contains": {
"description": "Always `complete_success_response`.",
"type": "string"
},
"media_type": {
"description": "Always `application/json`.",
"type": "string"
},
"path": {
"description": "Tagged absolute Artifact path.",
"$ref": "#/$defs/TaggedPath"
},
"sha256": {
"description": "SHA-256 of exact file bytes.",
"$ref": "#/$defs/Digest"
}
},
"required": [
"path",
"bytes",
"sha256",
"media_type",
"contains"
]
},
"Digest": {
"description": "A lowercase SHA-256 digest.",
"type": "string"
},
"FunctionItem": {
"description": "Minimal version 0.1 Function record.",
"type": "object",
"properties": {
"body_address_count": {
"description": "Number of Addresses in the body.",
"type": "integer",
"format": "uint64",
"minimum": 0
},
"decompilable": {
"description": "Whether the Function is a valid decompilation target.",
"type": "boolean"
},
"entry": {
"description": "Function entry Address.",
"$ref": "#/$defs/Address"
},
"is_external": {
"description": "Whether Ghidra marks the Function external.",
"type": "boolean"
},
"is_thunk": {
"description": "Whether Ghidra marks the Function a thunk.",
"type": "boolean"
},
"location": {
"description": "Memory or external location.",
"$ref": "#/$defs/FunctionLocation"
},
"name": {
"description": "Exact basename.",
"type": "string"
},
"qualified_name": {
"description": "Exact fully-qualified name.",
"type": "string"
},
"thunk_target_entry": {
"description": "Resolved thunk target entry when available.",
"anyOf": [
{
"$ref": "#/$defs/Address"
},
{
"type": "null"
}
]
}
},
"required": [
"name",
"qualified_name",
"entry",
"body_address_count",
"location",
"is_external",
"is_thunk",
"decompilable"
]
},
"FunctionLocation": {
"description": "Function location class used by stable ordering.",
"oneOf": [
{
"description": "Function has a memory Address.",
"type": "string",
"const": "memory"
},
{
"description": "External/imported Function.",
"type": "string",
"const": "external"
}
]
},
"FunctionsData": {
"description": "Function collection data.",
"type": "object",
"properties": {
"items": {
"description": "Function records in documented order.",
"type": "array",
"items": {
"$ref": "#/$defs/FunctionItem"
}
},
"page": {
"description": "Stable page facts.",
"$ref": "#/$defs/PageMetadata"
}
},
"required": [
"page",
"items"
]
},
"InlineOrArtifact": {
"description": "Successful command data emitted inline or represented by a complete Artifact.",
"anyOf": [
{
"description": "Complete command-specific data.",
"$ref": "#/$defs/FunctionsData"
},
{
"description": "Bounded descriptor for the complete stored success response.",
"$ref": "#/$defs/SpilledData"
}
]
},
"Limits": {
"description": "Resource policy selected for one invocation.",
"type": "object",
"properties": {
"analysis_timeout_seconds": {
"description": "Native analysis timeout.",
"$ref": "#/$defs/PositiveU64"
},
"child_watchdog_seconds": {
"description": "Derived process watchdog.",
"$ref": "#/$defs/PositiveU64"
},
"decompile_timeout_seconds": {
"description": "Optional native decompilation timeout.",
"anyOf": [
{
"$ref": "#/$defs/PositiveU64"
},
{
"type": "null"
}
]
},
"max_cpu": {
"description": "Maximum Ghidra analysis CPU count.",
"$ref": "#/$defs/PositiveU64"
},
"max_heap_mib": {
"description": "Maximum Java heap, in MiB.",
"$ref": "#/$defs/PositiveU64"
},
"max_inline_bytes": {
"description": "Maximum serialized successful stdout size.",
"$ref": "#/$defs/PositiveU64"
},
"max_sample_bytes": {
"description": "Maximum accepted Sample size.",
"$ref": "#/$defs/PositiveU64"
}
},
"required": [
"max_heap_mib",
"max_cpu",
"analysis_timeout_seconds",
"child_watchdog_seconds",
"max_sample_bytes",
"max_inline_bytes"
]
},
"PageMetadata": {
"description": "Stable page metadata.",
"type": "object",
"properties": {
"has_more": {
"description": "Whether a subsequent page exists.",
"type": "boolean"
},
"limit": {
"description": "Applied item bound, null only for explicit `--all`.",
"type": [
"integer",
"null"
],
"format": "uint64",
"minimum": 0
},
"offset": {
"description": "Number of items skipped.",
"type": "integer",
"format": "uint64",
"minimum": 0
},
"order": {
"description": "Stable order identifier.",
"type": "string"
},
"returned": {
"description": "Number of returned items.",
"type": "integer",
"format": "uint64",
"minimum": 0
},
"total": {
"description": "Total items in the immutable Analysis.",
"type": "integer",
"format": "uint64",
"minimum": 0
}
},
"required": [
"order",
"offset",
"returned",
"total",
"has_more"
]
},
"PositiveU64": {
"description": "A validated positive integer accepted by resource-limit flags.",
"type": "integer",
"format": "uint64",
"minimum": 1
},
"QueryProvenance": {
"description": "Fixed provenance for every Sample-backed Query.",
"type": "object",
"properties": {
"adapter_protocol_version": {
"description": "Rust/Java protocol version.",
"type": "integer",
"format": "uint32",
"minimum": 0
},
"analysis_profile_sha256": {
"description": "Canonical Analysis Profile identity.",
"$ref": "#/$defs/Digest"
},
"analysis_store": {
"description": "Selected Analysis Store.",
"$ref": "#/$defs/AnalysisStoreProvenance"
},
"ghidr_version": {
"description": "CLI package version.",
"type": "string"
},
"ghidra_version": {
"description": "Ghidra version.",
"type": "string"
},
"java_version": {
"description": "Java major version.",
"type": "string"
},
"limits": {
"description": "Selected and derived resource limits.",
"$ref": "#/$defs/Limits"
},
"sample_sha256": {
"description": "Sample content identity.",
"$ref": "#/$defs/Digest"
},
"sandbox": {
"description": "Selected sandbox policy.",
"$ref": "#/$defs/SandboxProvenance"
},
"source_path": {
"description": "Exact caller-supplied path.",
"$ref": "#/$defs/TaggedPath"
},
"target": {
"description": "Resolved Target Specification and verification.",
"$ref": "#/$defs/TargetProvenance"
}
},
"required": [
"ghidr_version",
"adapter_protocol_version",
"ghidra_version",
"java_version",
"sample_sha256",
"source_path",
"analysis_profile_sha256",
"target",
"analysis_store",
"sandbox",
"limits"
]
},
"SandboxBackend": {
"description": "Sandbox backend.",
"oneOf": [
{
"description": "Bubblewrap namespaces.",
"type": "string",
"const": "bubblewrap"
},
{
"description": "Caller-supplied isolation.",
"type": "string",
"const": "external"
},
{
"description": "Isolation disabled.",
"type": "string",
"const": "off"
}
]
},
"SandboxProvenance": {
"description": "Worker sandbox provenance.",
"type": "object",
"properties": {
"backend": {
"description": "Selected backend.",
"$ref": "#/$defs/SandboxBackend"
},
"verification": {
"description": "Isolation verification state.",
"$ref": "#/$defs/SandboxVerification"
}
},
"required": [
"backend",
"verification"
]
},
"SandboxVerification": {
"description": "Sandbox verification state.",
"oneOf": [
{
"description": "Verified by `ghidr`.",
"type": "string",
"const": "verified"
},
{
"description": "Declared but not verifiable by `ghidr`.",
"type": "string",
"const": "unverified"
},
{
"description": "Explicitly disabled.",
"type": "string",
"const": "disabled"
}
]
},
"SpilledData": {
"description": "Public data shape returned when a complete success exceeds the inline byte budget.",
"type": "object",
"properties": {
"artifact": {
"description": "Immutable complete-success Artifact.",
"$ref": "#/$defs/ArtifactDescriptor"
},
"spilled": {
"description": "Always true for this variant.",
"type": "boolean"
}
},
"required": [
"spilled",
"artifact"
]
},
"StoreSource": {
"description": "Analysis Store resolution source.",
"oneOf": [
{
"description": "Explicit `--store` flag.",
"type": "string",
"const": "cli"
},
{
"description": "`GHIDR_STORE` environment variable.",
"type": "string",
"const": "environment"
},
{
"description": "Explicit `XDG_CACHE_HOME` fallback.",
"type": "string",
"const": "xdg"
},
{
"description": "Home-directory fallback.",
"type": "string",
"const": "home_fallback"
}
]
},
"TaggedPath": {
"description": "A path preserving either UTF-8 text or exact Unix bytes.",
"oneOf": [
{
"description": "An unmodified UTF-8 path.",
"type": "object",
"properties": {
"encoding": {
"type": "string",
"const": "utf8"
},
"value": {
"type": "string"
}
},
"required": [
"encoding",
"value"
]
},
{
"description": "Standard padded Base64 over exact Unix path bytes.",
"type": "object",
"properties": {
"encoding": {
"type": "string",
"const": "unix_bytes_base64"
},
"value": {
"type": "string"
}
},
"required": [
"encoding",
"value"
]
}
]
},
"TargetProvenance": {
"description": "Target Specification provenance.",
"type": "object",
"properties": {
"compiler_specification": {
"description": "Exact compiler-specification identifier.",
"type": "string"
},
"format": {
"description": "Executable format name.",
"type": "string"
},
"loader": {
"description": "Exact loader identifier.",
"type": "string"
},
"processor_language": {
"description": "Exact processor-language identifier.",
"type": "string"
},
"verification": {
"description": "Project integration-test coverage.",
"$ref": "#/$defs/TargetVerification"
}
},
"required": [
"loader",
"format",
"processor_language",
"compiler_specification",
"verification"
]
},
"TargetVerification": {
"description": "Project integration-test coverage for a recognized target.",
"oneOf": [
{
"description": "Covered by version 0.1 real-Ghidra fixtures.",
"type": "string",
"const": "verified"
},
{
"description": "Recognized by Ghidra but outside the tested matrix.",
"type": "string",
"const": "unverified"
}
]
},
"Warning": {
"description": "Stable non-fatal warning.",
"type": "object",
"properties": {
"code": {
"description": "Stable machine identifier.",
"type": "string"
},
"details": {
"description": "Warning-specific context, always an object.",
"type": "object",
"additionalProperties": true
},
"message": {
"description": "Concise human context.",
"type": "string"
}
},
"required": [
"code",
"message",
"details"
]
}
}
}