Vector35 / Vector35/binaryninja-api
Support for variable size structure array in decompiler
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
I've a structure which have a variable sized structure array in it. After importing and setting types it decompiled like this in HLIL:
people people
people.count = 0
people.arr = malloc(0x30)
... (memset )
for (int32_t i = 0; i s<= 3; i = i + 1)
//expected: people.arr[i].age = i
people.arr[sx.q(i) * 4] = i
//expected: people.arr[i].name = "test name"
*(people.arr + sx.q(i) * 0x10 + 8) = "test name"
people.count = people.count + 1
print_persons(people: &people)
print_persons
for (int32_t i = 0; i s< 3; i = i + 1)
printf("Person: %s, Age:%d\n", people->arr[sx.q(i)].name, zx.q(people->arr[sx.q(i)].age))
I guess this is not a bug, but a feature not implemented yet. I could not find an issue for it so creating one for tracking it.
Test code:
typedef struct _person
{
int age;
char* name;
}person;
typedef struct _people
{
int count;
person* arr;
}people;
void print_persons(people *people)
{
for (int i = 0; i < 3; i++)
{
printf("Person: %s, Age:%d\n", people->arr[i].name, people->arr[i].age);
}
}
int main()
{
people people;
people.count = 0;
people.arr = malloc(sizeof(person) * 3);
memset(people.arr, 0, sizeof(person) * 3);
for (int i = 0; i <= 3; i++)
{
people.arr[i].age = i;
people.arr[i].name = "test name";
people.count++;
}
print_persons(&people);
}
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the supplied C reproduction and compare its current HLIL output with the expected indexed structure-array accesses. Trace the decompiler path responsible for structure-member and pointer-array indexing, then add coverage demonstrating the expected output and verify that both the allocation loop and print_persons example decompile correctly.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, cpp
- Domain
- compilers, reverse-engineering
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100