Vector35 / Vector35/binaryninja-api

`return` keyword in the end of `void` function for tail calls

Open
#4,130 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Effort: Low Impact: Low
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Version and Platform (required):

  • Binary Ninja Version: 3.4.4151-dev
  • OS: Windows 11, x64

Bug Description:

I think that functions that have void return value should not have return keyword in their end. It makes me think that it will return something. It doesn't happen when last function call is not tail call.

void __fastcall destory_wsa_ctx(struct wsa_ctx* wsa)
004065d4  WSACleanup()
004065e0  release_close_mtx(&wsa->mutex)
004065e8  my_heap_free2(&wsa->some_buffer)
004065f0  my_heap_free2(&wsa->rec_buf)
004065f8  return my_virt_free(wsa->domain) __tailcall
void __fastcall destory_wsa_ctx(struct wsa_ctx* wsa)

004065d1  56                 push    esi {__saved_esi}
004065d2  8bf1               mov     esi, ecx
004065d4  ff1524934100       call    dword [WSACleanup]
004065da  8d8ed8010000       lea     ecx, [esi+0x1d8] {wsa_ctx::mutex}
004065e0  e876da0000         call    release_close_mtx
004065e5  8d4e30             lea     ecx, [esi+0x30] {wsa_ctx::some_buffer}
004065e8  e894daffff         call    my_heap_free2
004065ed  8d4e10             lea     ecx, [esi+0x10] {wsa_ctx::rec_buf}
004065f0  e88cdaffff         call    my_heap_free2
004065f5  8b0e               mov     ecx, dword [esi {wsa_ctx::domain}]
004065f7  5e                 pop     esi {__saved_esi}
004065f8  e920090000         jmp     my_virt_free

my_virt_free is also a function that have void return value.

void __fastcall my_virt_free(void* addr)
00406f25  VirtualFree(addr, nullptr, MEM_RELEASE)
00406f1d  6800800000         push    0x8000 {var_4}
00406f22  6a00               push    0x0 {var_8}
00406f24  51                 push    ecx {var_c}
00406f25  ff1518924100       call    dword [VirtualFree]
00406f2b  c3                 retn     {__return_addr}

Expected Behavior:
I expect it to not show return keyword.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file or test is named. Start by locating the decompiler logic that renders tail calls and void-returning functions, then trace the example where destory_wsa_ctx tail-calls my_virt_free. Done means a void tail call is displayed without a return keyword while non-void tail calls retain it, with coverage for this case.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, cpp
Domain
compilers, reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.