Repository navigation
feat(ida): add read-only GUI and headless MCP providers - #754
Merged
Merged
Conversation
2 of 9 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #747.
Reuse an existing
mrexodia/ida-pro-mcpregistration as REA'sidadeep-analysis provider. An analyst connects to REA once, opens the original binary, and uses existing REA function/string tools. The attached profile reads the current GUI database; the headless profile opens and releases its own database automatically.Problem and expected behavior
REA previously had no IDA provider, so agents had to configure and manage a second MCP surface. Existing IDA users should keep their upstream installation and select IDA through the same CLI/MCP contracts as other deep providers.
Change and scope
src/ida/boundaries for registration parsing, pinned SDK transport, upstream producer normalization, analysis operations, protected workspaces, and database ownership/cleanup.REA_IDA_MCP_CONFIG; doctor validates registration without launching IDA.Contract and boundary impact
src/ida/; generic live-cache policy and function Evidence presentation in the application layer.idawith--provider,REA_ANALYSIS_PROVIDER, oropen_binary.provider_id. Existing named output schemas remain canonical; direct callers are unavailable in the modern profile because code xrefs do not prove call edges..idb/.i64files. Headless REA and upstream share native filesystem paths. Real workflows cover Windows; other engine/platform combinations are explicitly unverified.force_headless, a unique requested session ID, verified worker ownership, explicit database arguments, andidb_close(save: false). Unconfirmed open/release retains the workspace and reports incomplete cleanup. Attached close releases the connection/proxy and leaves the GUI database open. Detached upstream workers do not have a REA Job Object containment claim.docs/product-catalog.json), package, or installation impact: regenerate provider/configuration catalog and related metadata; update README, architecture, testing guide, and bundled skill. No new runtime dependencies, engine installation, activation changes, or vendored upstream server.Evidence and regression coverage
idawas not a registered deep candidate. Real upstream observations established the legacy call-site/interior-address semantics and the modern explicit-database lifecycle. Packaged Windows testing caught forward-slash workspace paths at the native boundary; normalization now occurs on the actual host.{"name":"open_binary","arguments":{"path":"/samples/program.exe","provider_id":"ida"}} {"name":"analyze_function","arguments":{"procedure":"rea_fixture_add"}} {"name":"search_strings","arguments":{"pattern":"license"}} {"name":"close_binary","arguments":{}}Sanitized response excerpt (omitted fields remain present in the actual response):
{ "evidence": { "provider": {"id":"ida","name":"IDA Pro MCP adapter","version":"1"}, "analysis_profile": { "parameters": { "version_scope":"rea-ida-adapter", "engine_version":null, "mode":"headless", "cache_policy":"live" } } }, "result": { "procedure": { "name":"rea_fixture_add", "address":"0x1000", "body":{"available":false,"reason":"IDA MCP does not report complete function body ranges."} } } }Validation performed
npm run check:changed— typecheck/lint and 2,390 affected tests passed; one unrelated test skipped after integration with the fixed main snapshot.npm run test:focused -- <IDA conformance, SDK HTTP boundary, Ghidra/function Evidence, product catalog, direct-analysis filesystem tests>— 42 tests passed.npx vitest run src/ida/IdaSessionClient.test.ts --maxWorkers=1— 15 tests passed, including rejected document selection before provider startup.npm run docs:check,npm run knip,npm run jscpd,npm run scan:todos, andnpx oxfmt --check .— passed.node scripts/verify-real-ida.mjs --target <local-input> --procedure <function>— real Windows GUI through its existing legacy stdio proxy; production CLI/MCP contract validation and parity, all admitted operations, original-input preservation, and GUI still open after close.c133c3853faa111a9b00ee615c013b720d0c4acd, IDA 9.3 build 260213, a benign x64 PE fixture, protected workspace, owned database release, and workspace removal. Fixture never executed.Compatibility, safety, and release
analyze_functionEvidence provenance now preserves its actual provider instead of a workflow wrapper; consumers should use the returned provider/profile rather than assumingrea-workflow.0700/Windows private DACL reused; transport authentication redacted from SDK diagnostics; ambient environment not persisted; no GUI/mutation/Python forwarding. Cleanup uncertainty remains visible rather than guessing ownership or deleting working files.Review checklist
type(scope): outcome.