WARP doesn't save varargs status of functions

Open
#7,929 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
cpp

Research direction

Start by reproducing the WARP Include Function, Create, and Load File flow described in the issue, then trace where the exported printf signature is serialized and reapplied. Done means a signature declared as void printf(char* format, ...); is restored with its varargs intact and the reported calling-convention analysis behavior is preserved.

Written by the indexing model from the issue text.

Description

Component: WARP Impact: Low

Version and Platform (required):

  • Binary Ninja Version: 5.3.9003-dev
  • Edition: Ultimate
  • OS: macOS
  • OS Version: 26.2
  • CPU Architecture: aarch64

Bug Description:
When I used WARP to save signatures for printf, and then used those signatures to match printf in a new file, the varargs portion of the arguments to printf was not applied. Notably, it gave printf the signature void printf(char* format); missing the varargs. The varargs are a critical part of the type signature, as they indicate to analysis that the remaining arguments (at least in my architecture's case) are passed via the stack and not registers.

Steps To Reproduce:

  1. Open a stripped binary containing printf
  2. Navigate to printf
  3. Name and type printf as void printf(char* format, ...);
  4. Use WARP > Include Function to mark printf for export
  5. WARP > Create > From Current View and set included functions to Selected
  6. WARP > Load File on the generated signatures you just saved
  7. Re-open stripped binary
  8. Observe printf is detected but now has the signature void printf(char* format); with no varargs

Expected Behavior:
I expected the function signature I specified to be saved as-is and for the varargs to be reapplied.

Additional Information:
Signatures were generated for a binary using a custom arch plugin which can be provided if requested

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Vector35/binaryninja-api

All issues in Vector35/binaryninja-api

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.