Vector35 / Vector35/binaryninja-api
Partially overwritten variables are broken
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
Binary Ninja Version
2.4.2871-dev
Describe the bug
HLIL dead store elimination kills variables which are only partially overwritten. For example, this MLIL from x86_64:
rax = var_10
rax.ax = 0
rax_1 = rax + 4
lifts to this HLIL:
int32_t rax
rax.w = 0
... (rax + 4) ...
Where the high half of RAX, which was var_10, is eliminated and lost. Ideally, I'd think that should look more like rax = var_10 & 0xffff0000.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing HLIL dead store elimination for the MLIL sequence shown, focusing on how a partial write such as rax.ax = 0 is handled after rax = var_10. Compare the resulting HLIL with the reported loss of the high half and verify that the preserved value is represented as described in the issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- reverse-engineering
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100