Vector35 / Vector35/binaryninja-api
Possible bug in MediumLevelILFunction::GetLLILSSAToMLILExprMap
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
Version and Platform (required):
- Binary Ninja Version:
dev/5.2.8353
Bug Description:
In mediumlevelil.cpp, in MediumLevelILFunction::GetLLILSSAToMLILExprMap, I see this code:
for (auto& [oldExprIndex, newExprIndices]: m_translationData->mlilToMlilExprMap)
[..]
size_t oldLLILSSADirect = m_translationData->copyingFunction->GetLowLevelILExprIndex(oldExprIndex);
[..]
info.higherToLowerDirect = newDirect && oldExprIndex == oldLLILSSADirect;
I haven't tried to test/reproduce this, but it seems wrong that oldExprIndex (an MLIL expression index) is being compared to both oldLLILSSADirect (an LLIL expression index). I think this is probably supposed to be comparing oldLLILSSADirect to oldLLILSSAIndex.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in mediumlevelil.cpp at MediumLevelILFunction::GetLLILSSAToMLILExprMap and inspect the translation data fields used in the loop, especially oldExprIndex, oldLLILSSADirect, and oldLLILSSAIndex. Confirm whether the comparison mixes MLIL and LLIL expression indices; done means the index comparison is consistent and the relevant behavior is covered by existing validation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- reverse-engineering
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100