Constant propagation misses values that only become known after stack de-aliasing
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Ambito
- reverse-engineering
Direzione di ricerca
Start by opening the reported .bndb and inspecting HLIL at 0x3b698fde alongside MLIL around the partial write at 0x3b76597e. Compare propagation with and without that instruction, then trace the stack de-aliasing and constant-propagation stages involved. Done means the known value of rdi_1 is propagated and the resulting expression is simplified without manually setting the value.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Version and Platform (required):
- Binary Ninja Version: 5.4.9793-dev Ultimate, 12373795
- OS: macOS 26.5.1
- CPU Architecture: arm64
Steps To Reproduce:
- Download
nova guard works curiouslyand open the included .bndb. - Go to
0x3b698fdein HLIL:
40 @ 3b698fde r9.b = *(arg4 + 4 + rdi_1 + 0x6f3b9513)
- Hover over
rdi_1and note that it reports to have a constant value of-0x6f3b9513, yet the constant is not propagated and the resulting expression is not simplified.
Additional Information:
If I explicitly set the value of rdi_1 to -0x6f3b9513 prior to 0x3b698fde then it is propagated and simplified as expected:
35 @ 3b698fde ASSERT(rdi_1, ConstantValue: 0xffffffff90c46aed)
36 @ 3b698fde r9.b = *(arg4 + 4)
It also simplifies other uses of rdi_1 later in the function.
This appears to be a consequence of the value of rdi being most recently modified via a partial field access:
3b76597e and dil, byte [rsp+rdi-0x6f3b9515 {var_8+0x2}]
which ends up in MLIL as:
8 @ 3b76597e rdi.dil = 0x17 & var_8:2.b
If I NOP the instruction at 0x3b76597e, then the value of rdi is constant propagated. It looks like the partial write is not resolved until after the constant propagation has been performed. This means the value of rdi is not known when constant propagation is performed, and so it is left as a variable.
- Lingua principale
- C++
- Stelle
- 1.3k
- Fork
- 298
- Merge medio
- 5g 5h
- PR unite (30g)
- 19
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Vector35/binaryninja-api
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
Vector35/binaryninja-api#8540 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
Vector35/binaryninja-api#8516 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
Vector35/binaryninja-api#8503 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
Vector35/binaryninja-api#8446 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
Vector35/binaryninja-api#8444 ·
Tutte le issue di Vector35/binaryninja-api
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
gazebosim/gz-sensors#662 · 1 commento ·
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
-
comp-datalake
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
ClickHouse/ClickHouse#121222 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
LadybirdBrowser/ladybird#12123 ·