Inconsistent behavior of get_var_uses between Medium and High Level IL

Open
#2,739 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
30/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
cpp, python

Research direction

Reproduce the behavior through the MLIL and HLIL get_var_uses entry points shown in the issue, comparing whether each returns instructions or expressions and whether definitions are included. Trace the corresponding API implementation and add coverage for the reported variable-use case; done means HLIL behavior is consistent with MLIL or returns only read uses as documented.

Written by the indexing model from the issue text.

Description

Component: Core Effort: Low Impact: Medium

Binary Ninja Version

Version 2.4.3081-dev Personal

Describe the bug

Split out from a previous conversation in slack. In MLIL, get_var_uses returns instructions where the passed-in argument is on the RHS.

>>> current_mlil.get_var_uses(state_var_mlil)
[<mlil: rax_1 = var_1c>]

However in HLIL, get_var_uses returns expressions instead of instructions, including those expressions which appear in the LHS of that instruction (i.e. writes/definitions).

>>> current_hlil.get_var_uses(state_var_hlil)
[<HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>, <HLIL_VAR: var_1c>]

I was upgrading some old code from using mlil to hlil and was confused when my code using get_var_uses() stopped working because it returned expressions instead of instructions, and returned far more results than expected.

Expected behavior

current_hlil.get_var_uses should return instructions instead of expressions, or at least return only the expressions which are reads/uses

Version and Platform (required):

  • Binary Ninja: Version 2.4.3081-dev Personal
  • OS: Windows
  • Version 10
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Vector35/binaryninja-api

All issues in Vector35/binaryninja-api

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.