Binja incorrectly translating ILP32 tailcall pattern

Offen
#7,930 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Anfängerfreundlichkeit
45/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Veraltet
Tech-Stack
cpp

Rechercherichtung

Start in arch/arm64/il.cpp at LoadStoreOperand and inspect how the AArch64 IL handles the 32-bit load into w17 followed by a jump through x17. Reproduce with the attached binary in Binja, navigate to strtoul in .plt, and confirm the 0x401dcc jump is translated with x17 as a resolved constant rather than an incorrect tag.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

Effort: Low Impact: Low

Bug Description:
Binja incorrectly translating AArch64 ILP32 tailcall pattern as a result of 32-bit load into w17 and jump through x17.

00401dc0    uint32_t strtoul(char const* str, char** endptr, int32_t base)
00401dc0  adrp    x16, getspnam
00401dc4  ldr     w17, [x16, #0x10c]  {strtoul}
00401dc8  add     w16, w16, #0x10c  {strtoul}
❓00401dcc  br      x17

Steps To Reproduce:
Please provide all steps required to reproduce the behavior:

  1. Open the attached binary in Binja 5.3.9025 or later
  2. Navigate to strtoul in .plt
  3. Observe the tag at 0x401dcc on the jump(zx.q(*getaddrinfo))

Expected Behavior:
Translate correctly resulting in x17 being a resolved constant value

Binary:
victory spring enters valuably

Additional Information:

This hack allows the PLT branches to the extern region to work fine, but this isn't a good solution and I think we need to fix this in core.

diff --git a/arch/arm64/il.cpp b/arch/arm64/il.cpp
index f02cdd2d..ab6ff084 100644
--- a/arch/arm64/il.cpp
+++ b/arch/arm64/il.cpp
@@ -905,8 +905,11 @@ static void LoadStoreOperand(LowLevelILFunction& il, bool load,
                            ILSETREG_O(operand1, il.Operand(1, il.Load(load_store_sz, ILREG_O(operand2)))));
                        break;
                case MEM_OFFSET:
-                       if (!load_store_sz)
-                               load_store_sz = REGSZ_O(operand1);
+                       if ((operand1.reg[0] >= REG_W0 && operand1.reg[0] <= REG_WSP) || (operand1.reg[0] >= REG_S0 && operand1.reg[0] <= REG_S31))
+                       {
+                               BNRegisterInfo regInfo = il.GetArchitecture()->GetRegisterInfo(operand1.reg[0]);
+                               operand1.reg[0] = (Register)regInfo.fullWidthRegister;
+                       }

                        // operand1.reg = [operand2.reg + operand2.imm]
                        if (IMM_O(operand2) == 0)
Vorherrschende Sprache
C++
Sterne
1.3k
Forks
298
Ø Merge
5 T. 5 Std.
Gemergte PRs (30 T.)
19

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus Vector35/binaryninja-api

Alle Issues in Vector35/binaryninja-api

Ähnliche Issues

Weitere Issues zu C++

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.