Vector35 / Vector35/binaryninja-api

self-referential function gets bonus de-references

Open
#8,424 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Due to some improvements to propagating self-referential functions, the user-provided sample of river gulf mounts functionally has its first function go from:

int64_t (*)() sub_100000000()

to:

int64_t (* (* (*)())())() sub_100000000()

when going from 5.3 to 6.0.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the user-provided river gulf mounts functionally sample under versions 5.3 and 6.0, then compare the first function's inferred type. Trace the self-referential function propagation responsible for the added dereferences. Done means the function remains int64_t (*)() rather than gaining the extra nested function-pointer levels.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
reverse-engineering
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.