Very oldschool x86 signed division by 2 using `sar`+`adc` lifts into something unhelpful
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- cpp
- Domain
- reverse-engineering
Research direction
Start with the attached binjabaddiv.zip and inspect the function at 0x40107c in Binary Ninja; compare the lifted SAR/ADC flags and conditional path with signed division by two. Done means this pattern decompiles without an unimplemented carry flag and expresses the intended signed result.
Written by the indexing model from the issue text.
Description
Version and Platform (required):
- Binary Ninja Version: 5.3.9757 Personal (a99f2380)
- OS: macOS
- OS Version: 26.6.1
- CPU Architecture: ARM64
Bug Description:
I have a target that has been compiled using Borland C++, either version 4.5 or 5.x (from the late 90s). In this compiler, the following code:
int bad_div2(int x) { return x / 2; }
…which computes a signed division by 2, ends up compiling into the following assembly:
sar eax,1
jns short @3
adc eax,0
@3:
After loading this into Binary Ninja, it decompiles into a rather unhelpful:
0040107c int32_t sub_40107c(int32_t arg1)
0040107c {
0040107c int32_t result = arg1 >> 1;
🚫🚫00401082 bool c = /* bool c = unimplemented {sar eax, 0x1} */;
00401082
00401084 if (arg1 >> 1 >= 0)
0040108a return result;
0040108a
00401086 return result + 0;
0040107c }
Steps To Reproduce:
Please provide all steps required to reproduce the behavior:
- I am attaching a fully-linked EXE which includes this function at address 0x40107c. (Running the EXE doesn't do anything, it's only useful for looking at the function.)
Expected Behavior:
It'd be really nice if this pattern could be recognized and simplified.
Screenshots/Video Recording:
N/A
Binary:
binjabaddiv.zip
Additional Information:
N/A
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Vector35/binaryninja-api
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8540 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8516 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Vector35/binaryninja-api#8503 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8446 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8444 ·
All issues in Vector35/binaryninja-api
Similar issues
-
Website Doc Typo Open
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
Difficulty 1/5 1-3 hours Newbie friendliness 92/100
autowarefoundation/autoware_universe#13413 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
-
automated-analysis bug memory-safety
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100