Vector35 / Vector35/binaryninja-api
Unrecovered Switch Statement
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Description
Version and Platform (required):
- Binary Ninja Version: 5.1.8104 stable and 5.2.8587 dev
- Edition: Commercial
- OS: MacOS
- OS Version: 26.01
- CPU Architecture: M2
Bug Description:
There's a specific switch table format that I've been seeing in a couple of binaries that I'm reverse engineering. It looks like:
int value;
if (value > 10) { goto base_case; }
else {
goto table[-value];
}
The jump table is being indexed from the end of the table rather than the beginning of the table. Binary Ninja is not picking up on this and fails to decompile to a switch statement.
I have included a minimal binary that reproduces the problem. My example binary doesn't show any error of failure to reconstruct control flow like I was seeing in the example binary but still fails to get the control flow correct.
Steps To Reproduce:
Load example binary in Binary Ninja and decompile function func.
Expected Behavior:
I expected a switch statement to be present in the decompilation.
Screenshots/Video Recording:
This is the failure case. The lookup into table should be a switch control flow block.
Manually setting the set of values arg1 can have leads to correct decompilation.
Binary:
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Load jump.zip in Binary Ninja and decompile function func to reproduce the missed switch recovery. Compare the recovered control flow with the expected switch behavior for the reverse-indexed jump table; done means the decompilation represents the lookup as a switch control-flow block.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- compilers, reverse-engineering
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100