Vector35 / Vector35/binaryninja-api

Overriding system call type does not work

Open
#6,635 1 comment 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Core Effort: Medium Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Repro steps:

  1. Open quick forest swims softly
  2. Go to 0x14000107c
  3. Right click -> Override call Type
  4. Type in void calltarget(uint64_t num @ rax), and press OK
  5. Observe the HLIL does not change

Image

I am not sure whether this is related to #5583 and/or https://github.com/Vector35/binaryninja-api/issues/6458

P.S.: this does not look like a regression to me, tested a few earlier versions and they all behave in the same way

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue by opening quick forest swims softly, navigating to 0x14000107c, and using Override call Type with the provided signature. Inspect why the HLIL does not change and compare the behavior with issues #5583 and #6458. Done means the overridden system call type is reflected in the HLIL.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.