Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
193 changes: 103 additions & 90 deletions CHANGELOG.md

Large diffs are not rendered by default.

53 changes: 32 additions & 21 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "gobin"
version = "0.5.0"
version = "0.5.1"
edition = "2024"
rust-version = "1.88"
description = "Static analysis library for Go compiled binaries - identification and metadata extraction"
Expand Down Expand Up @@ -28,7 +28,7 @@ indexing_slicing = "deny"
[dependencies]
# We only parse single ELF / Mach-O / PE executables (the three formats
# dispatched in `formats.rs`), so drop goblin's default `te` (UEFI Terse
# Executable) feature — not a Go output format. (`archive` cannot be
# Executable) feature - not a Go output format. (`archive` cannot be
# dropped: goblin's `mach32`/`mach64` features hard-require it.) PE
# resource/import/cert/TLS *parsing* is disabled separately at the call
# site via `ParseOptions`. `endian_fd` + `std` stay for sliced reads.
Expand Down
12 changes: 6 additions & 6 deletions benches/extract.rs
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ fn path_of(name: &str) -> &'static str {
/// Read a fixture once per process and hand out a shared borrow.
///
/// Benchmarks measure gobin, not the filesystem, so the read must not land
/// inside the timed region — and it must not be re-counted by the allocation
/// inside the timed region - and it must not be re-counted by the allocation
/// profiler on every iteration either.
fn fixture(path: &str) -> &'static [u8] {
static CACHE: OnceLock<std::sync::Mutex<Vec<(String, &'static [u8])>>> = OnceLock::new();
Expand All @@ -98,7 +98,7 @@ fn parse(bencher: Bencher, name: &str) {
bencher.bench(|| black_box(GoBinary::parse(black_box(data))).is_some());
}

/// Function enumeration with names and source files resolved — the most
/// Function enumeration with names and source files resolved - the most
/// commonly consumed surface.
#[divan::bench(args = FIXTURES)]
fn functions(bencher: Bencher, name: &str) {
Expand All @@ -123,7 +123,7 @@ fn all_types(bencher: Bencher, name: &str) {
bencher.bench(|| black_box(bin.all_types().len()));
}

/// Go string-literal recovery — a full pointer-aligned sweep of the image.
/// Go string-literal recovery - a full pointer-aligned sweep of the image.
#[divan::bench(args = FIXTURES)]
fn strings(bencher: Bencher, name: &str) {
let data = fixture(path_of(name));
Expand All @@ -139,7 +139,7 @@ fn itabs(bencher: Bencher, name: &str) {
bencher.bench(|| black_box(bin.itab_pairs().count()));
}

/// Inline-tree decoding over every function — the heaviest pclntab surface.
/// Inline-tree decoding over every function - the heaviest pclntab surface.
#[divan::bench(args = FIXTURES)]
fn inline_trees(bencher: Bencher, name: &str) {
let data = fixture(path_of(name));
Expand Down Expand Up @@ -194,15 +194,15 @@ fn init_order(bencher: Bencher, name: &str) {
bencher.bench(|| black_box(bin.init_order().len()));
}

/// `//go:embed` payload recovery — a symbol-independent structural search.
/// `//go:embed` payload recovery - a symbol-independent structural search.
#[divan::bench(args = FIXTURES)]
fn embeds(bencher: Bencher, name: &str) {
let data = fixture(path_of(name));
let bin = GoBinary::parse(data).expect("fixture parses");
bencher.bench(|| black_box(bin.embedded_assets().len()));
}

/// A full metadata sweep — the shape of an actual triage run.
/// A full metadata sweep - the shape of an actual triage run.
#[divan::bench(args = FIXTURES)]
fn full_sweep(bencher: Bencher, name: &str) {
let data = fixture(path_of(name));
Expand Down
8 changes: 4 additions & 4 deletions src/detection.rs
Original file line number Diff line number Diff line change
Expand Up @@ -38,11 +38,11 @@ use crate::structures::PclntabVersion;
/// Consumers persist this enum into long-lived schemas (database columns,
/// structured logs). The contract:
///
/// - **Variants** — append-only. New tiers appear as new variants; existing
/// - **Variants** - append-only. New tiers appear as new variants; existing
/// variants are never renamed or removed.
/// - **`Display` strings** (and [`Self::as_str`]) — fixed forever once
/// - **`Display` strings** (and [`Self::as_str`]) - fixed forever once
/// shipped. Treat them as serialization keys.
/// - **`Debug` strings** — *not* a stability surface. Use `Display` /
/// - **`Debug` strings** - *not* a stability surface. Use `Display` /
/// `as_str` for anything that lands in a database column.
#[derive(Debug, Clone, Copy, PartialEq, Eq, PartialOrd, Ord)]
pub enum Confidence {
Expand Down Expand Up @@ -132,7 +132,7 @@ pub enum ConfidenceSignal {
/// ELF `.note.go.buildid` (or `Go\0\0` note marker) was present.
BuildidNotePresent,
/// A Go type-metadata section was present. These names are unique to the
/// Go linker, so any of them is structural proof on its own — useful on
/// Go linker, so any of them is structural proof on its own - useful on
/// stripped binaries where `.gopclntab` was renamed away.
TypeSectionPresent {
/// Which section matched, in its ELF spelling (`".typelink"`,
Expand Down
Loading
Loading