Lifting assistance with a conditional branch.
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Stale
- Domain
- reverse-engineering
Research direction
No file or test is identified. Start by locating the lifting logic for conditional branches and the handling of pop(), cmp_ne(), set_reg(), and dangling IL statements. Define which obviously dangling statements should trigger a diagnostic, then add coverage showing that the conditional pop is detected and valid lifting remains unaffected.
Written by the indexing model from the issue text.
Description
This is a feature request for sanity checks on some lifting.
I ran across a particular hard to debug instance of this. I am lifting a stack machine which has a conditional branch instruction that is something like:
if pop() != 0:
// true path
else:
// fall through
Originally, I lifted this by creating a cmp_ne(pop(), const(0)) expression. However, this is subtly incorrect -- the stack adjustment from the pop in the conditional will never be be applied as control flow passes to either the true or false branch before its committed. This is extremely hard to detect/debug, because by all appearances this initially looks correct: there is a conditional that does look at the top stack value, its just implemented as a peek() instead of a pop() in effect. The correct lifting for this ended up being something like set_reg(t0, pop()); cmp_ne(reg(t0), const(0)).
The feature request here is when there are some obviously dangling il statements that the user should be notified.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Vector35/binaryninja-api
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8540 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8516 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Vector35/binaryninja-api#8503 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8446 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8444 ·
All issues in Vector35/binaryninja-api
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
gazebosim/gz-sensors#662 · 1 comment ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
LadybirdBrowser/ladybird#12123 ·