Vector35 / Vector35/binaryninja-api

Unrecovered Switch Statement

Open
#7,594 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Version and Platform (required):

  • Binary Ninja Version: 5.1.8104 stable and 5.2.8587 dev
  • Edition: Commercial
  • OS: MacOS
  • OS Version: 26.01
  • CPU Architecture: M2

Bug Description:
There's a specific switch table format that I've been seeing in a couple of binaries that I'm reverse engineering. It looks like:

int value;
if (value > 10) { goto base_case; }
else {
    goto table[-value];
}

The jump table is being indexed from the end of the table rather than the beginning of the table. Binary Ninja is not picking up on this and fails to decompile to a switch statement.

I have included a minimal binary that reproduces the problem. My example binary doesn't show any error of failure to reconstruct control flow like I was seeing in the example binary but still fails to get the control flow correct.

Steps To Reproduce:
Load example binary in Binary Ninja and decompile function func.

Expected Behavior:
I expected a switch statement to be present in the decompilation.

Screenshots/Video Recording:
This is the failure case. The lookup into table should be a switch control flow block.

Image

Manually setting the set of values arg1 can have leads to correct decompilation.

Image

Binary:

jump.zip

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Load jump.zip in Binary Ninja and decompile function func to reproduce the missed switch recovery. Compare the recovered control flow with the expected switch behavior for the reverse-indexed jump table; done means the decompilation represents the lookup as a switch control-flow block.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
compilers, reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.