From 1bf1278ee5798d8c0ae68b34366caec4774f758a Mon Sep 17 00:00:00 2001 From: Dan <46821332+nsadeveloper789@users.noreply.github.com> Date: Thu, 15 Jan 2026 15:13:32 +0000 Subject: [PATCH] GP-6032: Update Watches screenshots and documentation. Fix mentions of Threads window having step schedule. --- .../GhidraClass/Debugger/A4-MachineState.html | 9 +++--- .../GhidraClass/Debugger/A4-MachineState.md | 3 +- .../GhidraClass/Debugger/B2-Emulation.html | 30 +++++++++--------- .../GhidraClass/Debugger/B2-Emulation.md | 8 ++--- .../images/Emulation_WatchesForCmdline.png | Bin 21013 -> 21410 bytes .../images/Emulation_WatchesForCmdlineSet.png | Bin 24030 -> 24331 bytes .../images/State_WatchesInCallSRand.png | Bin 13878 -> 14398 bytes 7 files changed, 26 insertions(+), 24 deletions(-) diff --git a/GhidraDocs/GhidraClass/Debugger/A4-MachineState.html b/GhidraDocs/GhidraClass/Debugger/A4-MachineState.html index a0ca3dd35b..6d9f1ea6ff 100644 --- a/GhidraDocs/GhidraClass/Debugger/A4-MachineState.html +++ b/GhidraDocs/GhidraClass/Debugger/A4-MachineState.html @@ -318,10 +318,9 @@ after a call to rand
Just as the Dynamic Listing is the analog of the Static Listing, the Memory viewer is the analog of the Bytes viewer. To open it, use Windows → Byte Viewer → Memory … in the menus. Its -default configuration should be Auto PC, the same as the Dynamic -Listing’s default. It has all the same additional Debugger features as -the Dynamic Listing. Furthermore, bytes that have changed are displayed -in red text.
+configuration should be Auto PC, the same as the Dynamic Listing’s. It +has all the same additional Debugger features as the Dynamic Listing. +Furthermore, bytes that have changed are displayed in red text.This is a bit quick and dirty, but it works and can be useful. Your @@ -417,6 +416,8 @@ which adds the current selection to the Watches window.
register space.
Double-clicking this cell will go to the address in the Dynamic
diff --git a/GhidraDocs/GhidraClass/Debugger/A4-MachineState.md b/GhidraDocs/GhidraClass/Debugger/A4-MachineState.md
index 0ae58a637e..be73375a2a 100644
--- a/GhidraDocs/GhidraClass/Debugger/A4-MachineState.md
+++ b/GhidraDocs/GhidraClass/Debugger/A4-MachineState.md
@@ -149,7 +149,7 @@ You can also experiment by placing code units in the Dynamic Listing before comm
Just as the Dynamic Listing is the analog of the Static Listing, the Memory viewer is the analog of the Bytes viewer.
To open it, use **Windows → Byte Viewer → Memory ...** in the menus.
-Its default configuration should be Auto PC, the same as the Dynamic Listing's default.
+Its configuration should be Auto PC, the same as the Dynamic Listing's.
It has all the same additional Debugger features as the Dynamic Listing.
Furthermore, bytes that have changed are displayed in red text.
@@ -221,6 +221,7 @@ The context menus for the Listing and Registers windows include a **Watch** acti
The columns are:
* The **Expression** column is the user-defined Sleigh expression.
+* The **Comment** column is a user-defined comment, usually to describe the watch.
* The **Address** column is the address of the resulting value, if applicable.
This may be in `register` space.
Double-clicking this cell will go to the address in the Dynamic Listing.
diff --git a/GhidraDocs/GhidraClass/Debugger/B2-Emulation.html b/GhidraDocs/GhidraClass/Debugger/B2-Emulation.html
index d178d2273d..5fb80166d6 100644
--- a/GhidraDocs/GhidraClass/Debugger/B2-Emulation.html
+++ b/GhidraDocs/GhidraClass/Debugger/B2-Emulation.html
@@ -190,8 +190,8 @@ of the target into the future, without allowing the actual target to
execute. Instead, we will allow an emulator to step forward, while
reading its initial state from the live target. This allows you, e.g.,
to experiment with various patches, or to force execution down a certain
-path. If you devise a patch, you can then apply it the live target and
-allow it to execute for real. Interpolation is similar, but
+path. If you devise a patch, you can then apply it to the live target
+and allow it to execute for real. Interpolation is similar, but
from a snapshot that is in the past. It can help answer the question,
“How did I get here?” It is more limited, because missing state for
snapshots in the past cannot be recovered.
@@ -495,13 +495,13 @@ parser may not actually use the value of
Use the Watches window to set RDI to 1, then click
Resume.
Like before, the emulator will crash, but this time you should see “pc =
-00000000” in red. This probably indicates success. In the Threads
-window, you should see a schedule similar to
-0:t0-{RDI=0x1);t0-16. This tells us we first patched RDI,
-then emulated 16 machine instructions before crashing. When the parser
-function returned, it probably read a stale 0 as the return address, so
-we would expect a decode error at 00000000. Step backward
-once to confirm this hypothesis.
0:t0-{RDI=0x1);t0-16. This
+tells us we first patched RDI, then emulated 16 machine instructions
+before crashing. When the parser function returned, it probably read a
+stale 0 as the return address, so we would expect a decode error at
+00000000. Step backward once to confirm this
+hypothesis.
As you step, you may notice the schedule changes. It is displayed in -the stepper’s subtitle as well as the Threads panel’s subtitle. P-code -stepping is denoted by the portion of the schedule following the dot. +the stepper’s subtitle as well as in the trace tab. P-code stepping is +denoted by the portion of the schedule following the dot. NOTE: You cannot mix instruction steps with p-code op -steps. The instruction steps always precede the p-code ops. If you click -Step Into from the global toolbar in the middle of an -instruction, the trailing p-code op steps will be removed and replaced -with a single instruction step. In most cases, this intuitively +steps. The instruction steps always precede the p-code op steps. If you +click Step Into from the global toolbar in the middle +of an instruction, the trailing p-code op steps will be removed and +replaced with a single instruction step. In most cases, this intuitively “finishes” the partial instruction.
wU_Y{!QD9b%uE=3z;sA>aIP)c(ca4V+KE
zvl}4cdX2s$2Ji{N7Dm)%eCoJwf;^Uv7lhAuME^Uzd5UtN(%b8 #;-hR-Fkf>ZaSR~PhG