Broken navigation with nested anonymous structures
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 52/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- cpp
- Domain
- reverse-engineering
Research direction
Start by reproducing the nested anonymous-structure and union examples in the types view, then inspect the HLIL/MLIL tokens and their typeNames as described. Trace how double-click navigation resolves those tokens, including data variables, and consider the issue done when inner fields navigate to their definitions.
Written by the indexing model from the issue text.
Description
Version and Platform (required):
- Binary Ninja Version: 6.1.10668-dev
- Edition: Ultimate
- OS: macOS
- OS Version: 27.0
- CPU Architecture: M5
Bug Description:
Trying to navigate to a field nested in one or more anonymous structures fails to navigate.
Steps To Reproduce:
Structure:
struct foo {
int pad;
struct {
int bar;
} inner;
};
Code (x86 Windows):
int32_t sub_0(struct foo* arg1)
mov eax, dword [esp+0x4]
mov eax, dword [eax+0x4]
retn
HLIL:
return arg1->inner.bar
Trying to double click bar fails to navigate to the field. Looking at the token itself:
>>> current_il_instruction.tokens[-1].typeNames
['bar']
The token doesn't have valid type information for figuring out how to navigate to it.
Making it a union instead:
union foo_u
{
struct
{
int32_t a;
int32_t b;
} bar;
};
Function type:
int32_t sub_0(union foo_u* arg1)
HLIL (broken):
return arg1->bar.__offset(0x4).d
MLIL:
eax = eax_1->bar.b
Double clicking b in MLIL also fails to navigate. The token for this:
>>> current_il_instruction.tokens[-1].typeNames
['foo_u', 'bar', 'b']
These two types also fail to navigate when made into data variables.
Expected Behavior:
Double clicking the inner field of these structures should navigate to that field in the types view.
- Dominant language
- C++
- Stars
- 1.3k
- Forks
- 298
- Avg merge
- 5d 5h
- Merged PRs (30d)
- 19
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Vector35/binaryninja-api
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8540 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Vector35/binaryninja-api#8516 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Vector35/binaryninja-api#8503 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8446 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Vector35/binaryninja-api#8444 ·
All issues in Vector35/binaryninja-api
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
gazebosim/gz-sensors#662 · 1 comment ·
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
comp-datalake
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
ClickHouse/ClickHouse#121222 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
LadybirdBrowser/ladybird#12123 ·