Hide explicit pointer authentication checks before tail calls
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- cpp
- Domain
- reverse-engineering
Research direction
Reproduce the issue by opening a Mac shared cache, loading MediaLibrary.framework, and navigating to +[MLMediaLibrary initialize]. Read the HLIL output and compare the observed HighBitsNoTBI pattern with llvm/lib/Target/AArch64/AArch64PointerAuth.h, especially the patterns described in the linked LLVM source. Done means explicit pointer-authentication checks before tail calls are detected and suppressed so the HLIL control flow is no longer broken.
Written by the indexing model from the issue text.
Description
Version and Platform (required):
- Binary Ninja Version: 5.0.7284-dev (e7d42d95)
- OS: macOS 15.4.1
- CPU Architecture: arm64
Bug Description:
When PAC is enabled, arm64 functions that end with a tail call rather than returning often explicitly validate lr prior to branching.
19c01be2c 0 ff2303d5 autibsp
19c01be30 0 d0071eca eor x16, x30, x30, lsl #0x1
19c01be34 0 5000f0b6 tbz x16, #0x3e, 0x19c01be3c
19c01be38 0 208e38d4 brk #0xc471
19c01be3c 0 a1450014 b 0x19c02d4c0
This validation ends up in HLIL in an incomplete/broken form:
19c01be34 int64_t x30
19c01be34
19c01be34 if (((x30 ^ x30 << 1) & 0x40000000) == 0)
19c02d4d4 return _objc_msgSend(x0_2, "instrument:", &cfstr_MLMediaLibrary) __tailcall
These patterns make it harder to follow the control flow of the function and should be detected and suppressed.
Steps To Reproduce:
- Open a Mac shared cache
- Load MediaLibrary.framework
- Navigate to
+[MLMediaLibrary initialize]
Additional Information:
There's a few different patterns for these explicit checks that LLVM can emit per https://github.com/llvm/llvm-project/blob/0014b49482c0862c140149c650d653b4e41fa9b4/llvm/lib/Target/AArch64/AArch64PointerAuth.h#L44-L86 The HighBitsNoTBI pattern is what I've seen on Apple platforms.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Vector35/binaryninja-api
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8540 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8516 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Vector35/binaryninja-api#8503 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8446 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8444 ·
All issues in Vector35/binaryninja-api
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
gazebosim/gz-sensors#662 · 1 comment ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
LadybirdBrowser/ladybird#12123 ·