Vector35 / Vector35/binaryninja-api

Cleanup ARM64 PAC

Open
#6,895 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Arch: ARM64 Effort: Low Impact: Medium
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

We originally implemented handling for ARM64 PAC instructions prior to adding an instruction attribute for them.

Since we have it, we should go back and re-implement them as the un-authenticated instructions with the attribute set. (And probably changing disassembly)

This requires modifying the get instruction info due to basic block breaks, and requires doing some small forward analysis cross-instruction (but the patterns are known and within the arch window)

Whomever implements this, see Snyder. He Has Thoughts.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the ARM64 PAC handling and the get instruction info logic mentioned in the issue, then review how disassembly and basic-block breaks are represented. Consult Snyder for the expected instruction patterns and guidance on the cross-instruction analysis. Done means PAC instructions use the unauthenticated form with the attribute set and disassembly is updated.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.