Vector35 / Vector35/binaryninja-api
Analysis falters with x86 code that has pattern "push addr; ret" in a lot of functions
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
While analyzing 9b7ccaa2ae6a5b96e3110ebcbc4311f6.dll_.zip, I observe we bail out on a lot of functions relying on analysis.limits.maxFunctionUpdateCount. A closer look at the code reveals the following pattern at the end of almost all functions:
We actually handle such a case when it occurs on individual functions. However, since every function has it, the analysis falters and do not handle it gracefully. If I force the analysis of the function, the analysis will get into an infinite loop
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce the issue with the linked 9b7ccaa2ae6a5b96e3110ebcbc4311f6.dll_.zip and inspect handling of analysis.limits.maxFunctionUpdateCount. Compare the behavior with the existing individual-function handling for the “push addr; ret” pattern. Done means analysis completes without widespread bailouts or an infinite loop.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- reverse-engineering
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100