Vector35 / Vector35/binaryninja-api

Callee-saved regs are not eliminated well when concatenated with LLIL_SPLIT_REG

Open
#2,595 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Core: MLIL Effort: Medium Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Binary Ninja Version

2.4.2950-dev Personal

Describe the bug

binja-hexagon lifts allocframe by pushing LLIL_SPLIT_REG(LR, FP) onto the stack. And, it doesn't use LLIL_PUSH but manipulates SP directly. This confuses binja, and it cannot elide LR:FP from MLIL or HLIL.

00000028      int32_t FP
00000028      int32_t FP_1
00000028      int32_t LR
00000028      int32_t LR_1
00000028      LR_1:FP_1 = LR:FP
00000028      return 0x100

To Reproduce
Steps to reproduce the behavior:

  1. Install https://github.com/google/binja-hexagon/ plugin
  2. Open https://github.com/google/binja-hexagon/blob/main/test_binaries/prebuilt/bn_llil_test_app in binja
  3. Navigate to test_allocframe function

Expected behavior

I want the HLIL to look like:

00000028      return 0x100

Version and Platform (required):

  • Binary Ninja: 2.4.2950-dev Personal
  • OS: Debian Linux
  • Version Buster

Additional context

Split from https://github.com/google/binja-hexagon/issues/3

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Install the binja-hexagon plugin, open its prebuilt bn_llil_test_app, and navigate to the test_allocframe function as described. Inspect how LLIL_SPLIT_REG(LR, FP), direct SP manipulation, and the resulting MLIL/HLIL are handled. Done means the redundant LR:FP assignment is eliminated and HLIL shows only return 0x100.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.