improper "add negative -> subtract" transformation with floating point
@rssor is already working on this.
Since Jan 12, 2022.
Assessment
This issue has not been assessed yet.
Description
Version and Platform (required):
- Binary Ninja Version: 2.5.3140-dev (Build ID 532595b6)
- OS: macOS
- OS Version: 11.6
Steps To Reproduce:
Please provide all steps required to reproduce the behavior:
-
Open this binary.
-
Notice in HLIL:
00000000 uint64_t _start(float arg1 @ v0)
00000004 data_4000
0000001c return zx.q(int.d(arg1 - 0x41666666))
00000020 uint64_t sub_20(float arg1 @ v0)
00000024 data_4000
0000003c return zx.q(int.d(arg1 f+ 0x41666666))
Expected Behavior:
The functions are identical except for loading a different constant: one is "negative" 0x41666666, one is "positive" 0x41666666. In reality, both constants are used as 32-bit floats, not signed integers.
In the second function, Binary Ninja indicates that floating point addition is being used with f+ 0x41666666. But in the first function, Binary Ninja produces just - 0x41666666. This is wrong in two ways: it doesn't indicate that floating point is being used, and in any case arg1 f+ -0x41666666 (i.e. arg1 f+ 0xbe99999a, i.e. arg1 + -0.300000011921) is not equivalent to arg1 f- 0x41666666 (i.e. arg1 + 14.3999996185).
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Vector35/binaryninja-api
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8540 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8516 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Vector35/binaryninja-api#8503 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8446 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8444 ·
All issues in Vector35/binaryninja-api
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
gazebosim/gz-sensors#662 · 1 comment ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
LadybirdBrowser/ladybird#12123 ·