Vector35 / Vector35/binaryninja-api
IL inlining of jump table dispatch routines
@D0ntPanic is already working on this.
Since Jun 23, 2026.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
Discussed in https://github.com/Vector35/binaryninja-api/discussions/5193
Originally posted by mostthingsweb March 18, 2024
I'm dealing with an ARM binary that has some jump tables in it. The tricky thing is the jump table logic is encapsulated in its own routine (which I've named doJumpTable):
arg1 (r3) is passed as the index into the jump table. lr is used to locate the jump table, which exists right after the bl doJumpTable in the caller.
I have already worked through the disassembly for one of the callers and resolved the possible jump targets, using this article as inspiration: https://www.lodsb.com/reversing-complex-jumptables-in-binary-ninja.
Question: The "Inline during analysis (experimental)" option is disabled for doJumpTable. Any ideas why this might be?
If it were enabled, I would be able to use UIDF to constrain the r3 input and have Binja trace through the possible jumps. But without the ability to inline doJumpTable, Binja doesn't see the jumps. What's the best way to proceed here?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.