disassemble_function
Decode a native PE x86-64 function from an entry RVA by linear sweep to ret/iret or max_bytes, returning verified instructions for analysis.
Instructions
Disassemble a function starting at an RVA in a native PE (x86-64). Linear sweep from the entry RVA to the first terminal instruction (ret/iret) or max_bytes, whichever comes first — a PR-3.1 boundary heuristic (CFG-accurate bounds arrive with the call-graph in PR-3.2), so the function EXTENT is tagged provenance=inferred while the decoded bytes themselves are verified. Read-only on the binary. Writes a 'function' row into The Model when db_path/game_path is supplied and the binary is catalogued.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| rva | Yes | Entry RVA of the function. | |
| db_path | No | Optional .autopsy.db for writeback. | |
| game_path | No | Optional game dir; default .autopsy DB used if db_path omitted. | |
| max_bytes | No | Safety cap on sweep length (default 4096). | |
| binary_path | Yes | Path to the PE (.exe/.dll). |