Headless Ghidra Function Substitution — P4
P4 consumes the current selected batch, applies enriched metadata, runs the approved Ghidra decompilation path, and records per-function substitution artifacts.
Required ghidra-agent-cli Commands
ghidra-agent-cli ghidra apply-renamesghidra-agent-cli ghidra verify-renamesghidra-agent-cli ghidra apply-signaturesghidra-agent-cli ghidra verify-signaturesghidra-agent-cli ghidra decompileghidra-agent-cli ghidra rebuild-projectghidra-agent-cli substitute addghidra-agent-cli substitute validateghidra-agent-cli gate check --phase P4
Locking and Ghidra invocation are handled internally by the CLI. The public workflow surface is the CLI plus the YAML outputs below. When substitution/next-batch.yaml is ready, process only functions with clear P3 names and signatures.
Inputs
artifacts/<target-id>/baseline/*.yamlartifacts/<target-id>/runtime/fixtures/artifacts/<target-id>/runtime/hotpaths/call-chain.yamlartifacts/<target-id>/third-party/identified.yamlartifacts/<target-id>/third-party/pristine/<library>@<version>/artifacts/<target-id>/third-party/compat/<library>@<version>/if neededartifacts/<target-id>/metadata/renames.yamlartifacts/<target-id>/metadata/signatures.yamlartifacts/<target-id>/substitution/next-batch.yaml
Outputs
artifacts/<target-id>/substitution/functions/<fn_id>/capture.yamlartifacts/<target-id>/substitution/functions/<fn_id>/substitution.yaml- Additional per-function YAML such as blocked, injected, or follow-up records when the workflow records them
Exit Expectations
- Function-level I/O fixtures and capture YAML are recorded before coding a substitute.
- Each substituted function has a
substitution.yamlwith provenance, fixtures, and status. - P4 gate material is available under
substitution/functions/<fn_id>/.
Constraints
- Use Ghidra as the only decompilation backend.
- Acquire the Ghidra queue/lock before mutating or reading shared Ghidra state when the backend requires it.
- Do not modify artifacts for functions outside the active batch.
- Do not bypass
ghidra-agent-clifor supported apply/verify/decompile, substitution, fixture, or gate actions. - Do not modify pristine third-party source; place local adaptation changes under
third-party/compat/. - Do not create or run a new Ghidra script if the CLI lacks a capability; pause and ask the user first.
Next Step
- P4 gate passes for the batch → return to P3 for another round or finish.