Add Outlining Support for strcat
@bpotchik is already working on this.
Since Jun 23, 2025.
Assessment
This issue has not been assessed yet.
Description
What is the feature you'd like to have?
Currently, in the binary I am looking at, there are a number of string operations that are treated as raw hex numbers applied to variable offsets. It would be nice if these showed in a more 'as it would appear in the code' way, of just general string operations.
Is your feature request related to a problem?
There are other similar examples in the binary (macOS, x86_64) I'm looking at, but this is the most self contained one:
005851a0 int64_t SerumGUI::getPath_AppDataBase(int64_t arg1, int64_t* arg2)
005851b5 int64_t rax = *___stack_chk_guard
005851d4 void var_70
005851d4 if (_FSFindFolder(0xffff8005, 0x61737570, 0, &var_70) == 0)
005851dc int64_t rax_2 = _CFURLCreateFromFSRef(0, &var_70)
005851f1 _CFURLGetFileSystemRepresentation(rax_2, 0, arg2, 0x200)
005851f9 _CFRelease(rax_2)
00585201 int64_t rax_3 = _strlen(arg2)
🐛00585210 *(arg2 + rax_3) = 0x6566782e6d6f632f
🐛0058521e *(arg2 + rax_3 + 8) = 0x7364726f63657272
🐛0058522d *(arg2 + rax_3 + 0x10) = 0x2f6d757265732e
00585239 int64_t rax_4 = *___stack_chk_guard
00585240 if (rax_4 != rax)
0058524b ___stack_chk_fail()
0058524b noreturn
0058524a return rax_4
If I right click -> Display As -> Character Constant on those hex constants, it looks a bit more readable:
005851a0 int64_t SerumGUI::getPath_AppDataBase(int64_t arg1, int64_t* arg2)
005851b5 int64_t rax = *___stack_chk_guard
005851d4 void var_70
005851d4 if (_FSFindFolder(0xffff8005, 0x61737570, 0, &var_70) == 0)
005851dc int64_t rax_2 = _CFURLCreateFromFSRef(0, &var_70)
005851f1 _CFURLGetFileSystemRepresentation(rax_2, 0, arg2, 0x200)
005851f9 _CFRelease(rax_2)
00585201 int64_t rax_3 = _strlen(arg2)
- 🐛00585210 *(arg2 + rax_3) = 0x6566782e6d6f632f
- 🐛0058521e *(arg2 + rax_3 + 8) = 0x7364726f63657272
- 🐛0058522d *(arg2 + rax_3 + 0x10) = 0x2f6d757265732e
+ 🐛00585210 *(arg2 + rax_3) = '/com.xfe'
+ 🐛0058521e *(arg2 + rax_3 + 8) = 'rrecords'
+ 🐛0058522d *(arg2 + rax_3 + 0x10) = '.serum/'
00585239 int64_t rax_4 = *___stack_chk_guard
00585240 if (rax_4 != rax)
0058524b ___stack_chk_fail()
0058524b noreturn
0058524a return rax_4
But it would be nicer if it was automatically something more like this (or similar):
005851a0 int64_t SerumGUI::getPath_AppDataBase(int64_t arg1, int64_t* arg2)
005851b5 int64_t rax = *___stack_chk_guard
005851d4 void var_70
005851d4 if (_FSFindFolder(0xffff8005, 0x61737570, 0, &var_70) == 0)
005851dc int64_t rax_2 = _CFURLCreateFromFSRef(0, &var_70)
005851f1 _CFURLGetFileSystemRepresentation(rax_2, 0, arg2, 0x200)
005851f9 _CFRelease(rax_2)
00585201 int64_t rax_3 = _strlen(arg2)
- 🐛00585210 *(arg2 + rax_3) = 0x6566782e6d6f632f
- 🐛0058521e *(arg2 + rax_3 + 8) = 0x7364726f63657272
- 🐛0058522d *(arg2 + rax_3 + 0x10) = 0x2f6d757265732e
+ 🐛00585210 *(arg2 + rax_3) = '/com.xferrecords.serum/'
00585239 int64_t rax_4 = *___stack_chk_guard
00585240 if (rax_4 != rax)
0058524b ___stack_chk_fail()
0058524b noreturn
0058524a return rax_4
Or even better would be:
005851a0 int64_t SerumGUI::getPath_AppDataBase(int64_t arg1, int64_t* arg2)
005851b5 int64_t rax = *___stack_chk_guard
005851d4 void var_70
005851d4 if (_FSFindFolder(0xffff8005, 0x61737570, 0, &var_70) == 0)
005851dc int64_t rax_2 = _CFURLCreateFromFSRef(0, &var_70)
005851f1 _CFURLGetFileSystemRepresentation(rax_2, 0, arg2, 0x200)
005851f9 _CFRelease(rax_2)
- 00585201 int64_t rax_3 = _strlen(arg2)
- 🐛00585210 *(arg2 + rax_3) = 0x6566782e6d6f632f
- 🐛0058521e *(arg2 + rax_3 + 8) = 0x7364726f63657272
- 🐛0058522d *(arg2 + rax_3 + 0x10) = 0x2f6d757265732e
+ 🐛00585210 _strcat(arg2, "/com.xferrecords.serum/")
00585239 int64_t rax_4 = *___stack_chk_guard
00585240 if (rax_4 != rax)
0058524b ___stack_chk_fail()
0058524b noreturn
0058524a return rax_4
- https://www.geeksforgeeks.org/strcat-in-c/
-
char *strcat(char *dest, const char *src);
-
Are any alternative solutions acceptable?
Unsure.
Additional Information:
- This last screenshot shows another thing that would be nice to improve (which maybe is worth opening as a separate issue), where 32 bit shifts are also being used within the string operations
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Vector35/binaryninja-api
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8540 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8516 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Vector35/binaryninja-api#8503 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8446 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8444 ·
All issues in Vector35/binaryninja-api
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
gazebosim/gz-sensors#662 · 1 comment ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
LadybirdBrowser/ladybird#12123 ·