Vector35 / Vector35/binaryninja-api

Phantom stack variables generated when creating a struct field

Open
#5,389 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Core: HLIL Effort: Medium IL Optimization Impact: Low
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Version and Platform (required):

  • Binary Ninja Version: 4.1.5260-dev, 7f6bb9ee
  • OS: macos
  • OS Version: 14.4
  • CPU Architecture: arm64

Internal binary major dine favor.

Possibly related to #5386.

struct Link __packed
{
    __offset(0x0), __offset(0x0).d
    uint32_t channel_id;
    uint32_t n_channels;
    int32_t baud_rate;
    int64_t field_10;
    int64_t field_18;
    int64_t field_20;
    int64_t field_28;
    uint32_t protocol_id;
};

or

struct Link __packed
{
    __padding char _0[4];
    uint32_t channel_id;
    uint32_t n_channels;
    int32_t baud_rate;
    int64_t field_10;
    int64_t field_18;
    int64_t field_20;
    int64_t field_28;
    uint32_t protocol_id;
};

The code is not recognizing that this is an array of structures (function arg struct Link* links), probably related to #5376

00062280                              DjiLogger_UserLogOutput(level: "linker", fmt: &(*nullptr->ident.signature)[3], "[%s:%d) config list channel id:%…", "DjiCommand_Init", 0x9e, zx.q(*(links->__offset(0x0).q + sx.q(ix) * 0x34 + 0x30)))
000622d8                              T_DjiReturnCode err_1 = DjiLinker_Init(link: links->__offset(0x0).q + sx.q(ix) * 0x34, linker: &(*mgr)->linkers[sx.q(ix)])
000622e8                              if (err_1 != 0)
00062318                                  DjiLogger_UserLogOutput(level: "linker", fmt: nullptr, "[%s:%d) init linker error:0x%08l…", "DjiCommand_Init", 0xa1, err_1)
0006231c                                  err = err_1
00062320                                  break

but I want to point something else. Replacing that 4-byte padding at the beginning of the struct with a 4-byte int

struct Link __packed
{
    uint32_t field_0;
    uint32_t channel_id;
    uint32_t n_channels;
    int32_t baud_rate;
    int64_t field_10;
    int64_t field_18;
    int64_t field_20;
    int64_t field_28;
    uint32_t protocol_id;
};

changes the code to

00062228                                  void* x2_1
00062228                                  x2_1.d = links->field_0
00062228                                  x2_1:4.d = links->channel_id
00062280                                  DjiLogger_UserLogOutput(level: "linker", fmt: &(*nullptr->ident.signature)[3], "[%s:%d) config list channel id:%…", "DjiCommand_Init", 0x9e, zx.q(*(x2_1 + sx.q(ix) * 0x34 + 0x30)))
00062288                                  void* x2_2
00062288                                  x2_2.d = links->field_0
00062288                                  x2_2:4.d = links->channel_id
000622d8                                  T_DjiReturnCode err_1 = DjiLinker_Init(link: x2_2 + sx.q(ix) * 0x34, linker: &(*mgr)->linkers[sx.q(ix)])

Why the extra phantom stack variables?

IDA Pro doesn't recognize array access but no extra variables are created

      DjiLogger_Output(
        "linker",
        3LL,
        "[%s:%d) config list channel id:%d",
        "DjiCommand_Init",
        158LL,
        *(unsigned __int8 *)(*(_QWORD *)&links->field_0 + 0x34LL * i + 0x30));// link->protocol_id
      v11 = DjiLinker_Init((struct Link *)(*(_QWORD *)&links->field_0 + 0x34LL * i), &(*mgr)->linkers[i]);

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the reported decompilation on Binary Ninja 4.1.5260-dev on macOS arm64 using the shown packed Link structures and function argument. Compare the generated output with the versions shown for padding versus a field, then determine what behavior should be considered done; the issue names no repository file or test entry point.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.