Vector35 / Vector35/binaryninja-api

IL inlining of jump table dispatch routines

Open
#5,250 9 comments 0 reactions 1 assignee View on GitHub

@D0ntPanic is already working on this.

Since Jun 23, 2026.

Component: Core Effort: Medium Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Discussed in https://github.com/Vector35/binaryninja-api/discussions/5193

Originally posted by mostthingsweb March 18, 2024
I'm dealing with an ARM binary that has some jump tables in it. The tricky thing is the jump table logic is encapsulated in its own routine (which I've named doJumpTable):

image

arg1 (r3) is passed as the index into the jump table. lr is used to locate the jump table, which exists right after the bl doJumpTable in the caller.

I have already worked through the disassembly for one of the callers and resolved the possible jump targets, using this article as inspiration: https://www.lodsb.com/reversing-complex-jumptables-in-binary-ninja.

Question: The "Inline during analysis (experimental)" option is disabled for doJumpTable. Any ideas why this might be?

If it were enabled, I would be able to use UIDF to constrain the r3 input and have Binja trace through the possible jumps. But without the ability to inline doJumpTable, Binja doesn't see the jumps. What's the best way to proceed here?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.