Python

Utilities

lief.is_dex(*args) → bool
lief.is_dex(raw: collections.abc.Sequence[int]) → bool

Overloaded function.

  1. is_dex(path: str) -> bool

Check if the file given in parameter is a DEX

  1. is_dex(raw: collections.abc.Sequence[int]) -> bool

Check if the raw data given in parameter is a DEX

lief.DEX.version(*args) → int
lief.DEX.version(raw: collections.abc.Sequence[int]) → int

Overloaded function.

  1. version(file: str) -> int

Return the DEX version of the file given in parameter

  1. version(raw: collections.abc.Sequence[int]) -> int

Return the DEX version of the raw data given in parameter


Parser

lief.DEX.parse(*args) → lief.DEX.File | None
lief.DEX.parse(raw: collections.abc.Sequence[int], name: str = '') → lief._lief.DEX.File | None
lief.DEX.parse(obj: str | io.IOBase | os.PathLike | bytes | list[int], name: str = '') → lief._lief.DEX.File | None

Overloaded function.

  1. parse(filename: str) -> Optional[lief._lief.DEX.File]

Parse the given filename and return a File object

  1. parse(raw: collections.abc.Sequence[int], name: str = '') -> Optional[lief._lief.DEX.File]

Parse the given raw data and return a File object

  1. parse(obj: Union[str | io.IOBase | os.PathLike | bytes | list[int]], name: str = '') -> Optional[lief._lief.DEX.File]


File

class lief.DEX.File

Bases: Object

DEX File representation

property classes → lief.DEX.File.it_classes

Iterator over Dex Class

property dex2dex_json_info → str
property fields → lief.DEX.File.it_fields

Iterator over Dex Field

get_class(self, classname: str) → lief._lief.DEX.Class | None
get_class(self, classname: int) → lief._lief.DEX.Class | None
has_class(self, classname: str) → bool

Check if a class with a name given in parameter exists

property header → lief.DEX.Header

Dex File Header

property location → str

Original location of the dex file

property map → lief.DEX.MapList

Dex MapList

property methods → lief.DEX.File.it_methods

Iterator over Dex Method

property name → str

Name of the dex file

property prototypes → lief.DEX.File.it_prototypes

Iterator over Dex Prototype

raw(self, deoptimize: bool = True) → list[int]

Original raw file

save(self, output: str = '', deoptimize: bool = True) → str

Save the original file into the file given in first parameter

property strings → lief.DEX.File.it_strings

Iterator over Dex strings

property types → lief.DEX.File.it_types

Iterator over Dex Type

property version → int

Dex version



Method

class lief.DEX.Method

Bases: Object

DEX Method representation

property access_flags → list[lief.DEX.ACCESS_FLAGS]

List of ACCESS_FLAGS

property bytecode → list[int]

Dalvik Bytecode as a list of bytes

property cls → lief.DEX.Class | None

Class associated with this method

property code_info → lief.DEX.CodeInfo

CodeInfo associated with this method

property code_offset → int

Offset to the Dalvik Bytecode

has(self, flag: lief._lief.DEX.ACCESS_FLAGS) → bool

Check if the given ACCESS_FLAGS is present

property has_class → bool

True if a class is associated with this method

property index → int

Original DEX file index of the method

insert_dex2dex_info(self, pc: int, index: int) → None

Insert de-optimization information

property is_virtual → bool

True if the method is a virtual (not private, static, final, constructor)

property name → str

Method’s name

property prototype → lief.DEX.Prototype | None

Prototype of this method


Field

class lief.DEX.Field

Bases: Object

DEX Field representation

property access_flags → list[lief.DEX.ACCESS_FLAGS]

List of ACCESS_FLAGS

property cls → lief.DEX.Class | None

Class associated with this field

has(self, flag: lief._lief.DEX.ACCESS_FLAGS) → bool

Check if the given ACCESS_FLAGS is present

property has_class → bool

True if a class is associated with this field

property index → int

Original DEX file index of the field

property is_static → bool

True if the field is static

property name → str

Field’s name

property type → lief.DEX.Type | None

Type of this field


Class

class lief.DEX.Class

Bases: Object

DEX Class representation

property access_flags → list[lief.DEX.ACCESS_FLAGS]

List of ACCESS_FLAGS

property dex2dex_info → dict[lief.DEX.Method, dict[int, int]]

De-optimize information

property fields → lief.DEX.Class.it_fields

Iterator over Field in this class

property fullname → str

Mangled class name (e.g. Lcom/example/android/MyActivity;)

get_field(self, name: str) → lief._lief.DEX.Class.it_named_fields

Iterator over Field (s) having the given name

get_method(self, name: str) → lief._lief.DEX.Class.it_named_methods

Iterator over Method (s) having the given name

has(self, flag: lief._lief.DEX.ACCESS_FLAGS) → bool

Check if the given ACCESS_FLAGS is present

property has_parent → bool

True if the current class extends another one

property index → int

Original index in the DEX class pool

property methods → lief.DEX.Class.it_methods

Iterator over Method implemented in this class

property name → str

Class name (e.g. MyActivity)

property package_name → str

Package Name (e.g. com.example.android)

property parent → lief.DEX.Class | None

Class parent class

property pretty_name → str

Demangled class name (e.g. com.example.android.MyActivity)

property source_filename → str

Original filename


Code Info

class lief.DEX.CodeInfo

Bases: Object

DEX CodeInfo representation

property nb_registers → int

Number of registers used by the method


Prototype

class lief.DEX.Prototype

Bases: Object

DEX Prototype representation

property parameters_type → lief.DEX.Prototype.it_params

Iterator over parameters Type

property return_type → lief.DEX.Type | None

Type returned


Type

class lief.DEX.Type

Bases: Object

DEX Type representation

class PRIMITIVES(*values)

Bases: Enum

BOOLEAN = 2
BYTE = 3
CHAR = 5
DOUBLE = 9
FLOAT = 8
INT = 6
LONG = 7
SHORT = 4
VOID_T = 1
class TYPES(*values)

Bases: Enum

ARRAY = 3
CLASS = 2
PRIMITIVE = 1
UNKNOWN = 0
property dim → int

If the current type is an array, return its dimension otherwise 0

pretty_name(primitive: lief.DEX.Type.PRIMITIVES) → str = <nanobind.nb_func object>
property type → lief.DEX.Type.TYPES

TYPES of this object

property underlying_array_type → lief.DEX.Type

Underlying type of the array

property value → object

Depending on the TYPES, return Class or PRIMITIVES or array


MapList

class lief.DEX.MapList

Bases: Object

DEX MapList representation

get(self, type: lief._lief.DEX.MapItem.TYPES) → lief._lief.DEX.MapItem

Return the MapItem from the given TYPES

has(self, type: lief._lief.DEX.MapItem.TYPES) → bool

Check if the given TYPES is present

property items → lief.DEX.MapList.it_items_t

Iterator over MapItem


MapItem

class lief.DEX.MapItem

Bases: Object

DEX MapItem representation

class TYPES(*values)

Bases: Enum

ANNOTATION = 8196
ANNOTATIONS_DIRECTORY = 8198
ANNOTATION_SET = 4099
ANNOTATION_SET_REF_LIST = 4098
CALL_SITE_ID = 7
CLASS_DATA = 8192
CLASS_DEF = 6
CODE = 8193
DEBUG_INFO = 8195
ENCODED_ARRAY = 8197
FIELD_ID = 4
HEADER = 0
MAP_LIST = 4096
METHOD_HANDLE = 8
METHOD_ID = 5
PROTO_ID = 3
STRING_DATA = 8194
STRING_ID = 1
TYPE_ID = 2
TYPE_LIST = 4097
from_value(arg: int) → lief.DEX.MapItem.TYPES = <nanobind.nb_func object>
property offset → int

Offset from the start of the file to the items in question

property size → int

Count of the number of items to be found at the indicated offset

property type → lief.DEX.MapItem.TYPES

TYPES of the item


Enums

Access Flags

class lief.DEX.ACCESS_FLAGS(*values)

Bases: Enum

ABSTRACT = 1024
ANNOTATION = 8192
BRIDGE = 64
CONSTRUCTOR = 65536
DECLARED_SYNCHRONIZED = 131072
ENUM = 16384
FINAL = 16
INTERFACE = 512
NATIVE = 256
PRIVATE = 2
PROTECTED = 4
PUBLIC = 1
STATIC = 8
STRICT = 2048
SYNCHRONIZED = 32
SYNTHETIC = 4096
TRANSIENT = 128
UNKNOWN = 0
VARARGS = 128
VOLATILE = 64