Skip to main content

resq-bin

Version: v0.1.16 · License: Apache-2.0 · Crate: crates.io · API docs: docs.rs
Crates.io License Binary and machine-code analyzer for the ResQ platform. Provides deep inspection of ELF, Mach-O, and PE object files with interactive TUI exploration, Capstone-powered disassembly with objdump fallback, symbol and section analysis, and a persistent CRC32-based cache for fast repeated analysis of large binaries.

Capabilities

  • Multi-format binary parsing — ELF, Mach-O, PE, and WASM via the object crate.
  • Dual disassembly backends — Capstone for high-quality instruction decoding (x86_64, AArch64), with automatic fallback to llvm-objdump/objdump for missing functions.
  • Interactive TUI — Three-pane terminal interface (Targets, Functions, Disassembly) with regex search, function filtering, and keyboard navigation.
  • CLI output modes — Human-readable plain text and structured JSON for CI pipelines and tooling integration.
  • Smart caching — Persistent analysis cache keyed on file path, size, modification time, and analysis options. Falls back to CRC32 content hashing when mtime is unavailable.
  • Batch analysis — Recursive directory scanning with extension filtering for analyzing entire build output trees.
  • Read-only operation — Never mutates inspected binaries.

Architecture

Installation

System Requirements

  • Rust: Latest stable toolchain.
  • Capstone: The capstone crate bundles its own copy; no system library required.
  • objdump (optional): llvm-objdump or objdump on PATH enables the fallback disassembly backend. Analysis works without it, but some functions may lack disassembly when Capstone cannot decode them.

CLI Reference

Arguments

When none of --tui, --plain, or --json is specified, the output mode is determined automatically: TUI if stdout is a terminal, plain text otherwise.

Usage Examples

Single file — interactive TUI (default on a terminal)

Single file — plain text report

Output:

Single file — JSON output (for CI)

Directory scan — recursive with extension filter

Batch analysis — metadata only (fast)

Force TUI with a non-default config

Rebuild cache after recompilation

TUI Mode

The interactive TUI provides a three-pane layout for exploring binary analysis results.

Layout

Keyboard Shortcuts

Cache System

resq-bin maintains a persistent cache of analysis results to avoid redundant heavy disassembly work on unchanged binaries.

Cache Location

The default cache directory is .cache/resq/bin-explorer relative to the working directory. This can be overridden with the cache_dir key in the configuration file.

Cache Key Computation

Each cache entry is keyed by a CRC32 hash of a fingerprint string that includes:
  1. Protocol version (v5) — cache is automatically invalidated on schema changes.
  2. Canonical file path — absolute path to the binary.
  3. File size — byte length from filesystem metadata.
  4. Analysis options — disassembly enabled/disabled, max functions, max symbols, max instructions per function.
  5. Modification time — nanosecond-precision mtime when available.
  6. Content CRC32 — full file content hash as a fallback when mtime is unavailable (e.g., some network filesystems).

Cache Behavior

Cache Storage Format

Each entry is stored as a JSON file named {crc32_hex}.json containing the full BinaryReport structure.

Configuration File

resq-bin reads an optional TOML configuration file. By default it looks for .resq-bin-explorer.toml in the current directory, or you can specify a path with --config.

Format

CLI flags always take precedence over configuration file values.

JSON Output Format

The --json flag emits a single JSON object with three top-level fields:

Field Reference

Source Layout

License

Licensed under the Apache License, Version 2.0. See LICENSE for details.

Modules

Click through to each module for the full rustdoc-rendered API surface (types, traits, functions, methods).