Hide explicit pointer authentication checks before tail calls

Aperta
#6,702 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
cpp

Direzione di ricerca

Reproduce the issue by opening a Mac shared cache, loading MediaLibrary.framework, and navigating to +[MLMediaLibrary initialize]. Read the HLIL output and compare the observed HighBitsNoTBI pattern with llvm/lib/Target/AArch64/AArch64PointerAuth.h, especially the patterns described in the linked LLVM source. Done means explicit pointer-authentication checks before tail calls are detected and suppressed so the HLIL control flow is no longer broken.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Arch: ARM64 Component: Architecture Component: Core Effort: Medium Impact: Medium

Version and Platform (required):

  • Binary Ninja Version: 5.0.7284-dev (e7d42d95)
  • OS: macOS 15.4.1
  • CPU Architecture: arm64

Bug Description:
When PAC is enabled, arm64 functions that end with a tail call rather than returning often explicitly validate lr prior to branching.

19c01be2c     0  ff2303d5   autibsp 
19c01be30     0  d0071eca   eor     x16, x30, x30, lsl #0x1
19c01be34     0  5000f0b6   tbz     x16, #0x3e, 0x19c01be3c

19c01be38     0  208e38d4   brk     #0xc471

19c01be3c     0  a1450014   b       0x19c02d4c0

This validation ends up in HLIL in an incomplete/broken form:

19c01be34        int64_t x30
19c01be34        
19c01be34        if (((x30 ^ x30 << 1) & 0x40000000) == 0)
19c02d4d4            return _objc_msgSend(x0_2, "instrument:", &cfstr_MLMediaLibrary) __tailcall

These patterns make it harder to follow the control flow of the function and should be detected and suppressed.

Steps To Reproduce:

  1. Open a Mac shared cache
  2. Load MediaLibrary.framework
  3. Navigate to +[MLMediaLibrary initialize]

Additional Information:
There's a few different patterns for these explicit checks that LLVM can emit per https://github.com/llvm/llvm-project/blob/0014b49482c0862c140149c650d653b4e41fa9b4/llvm/lib/Target/AArch64/AArch64PointerAuth.h#L44-L86 The HighBitsNoTBI pattern is what I've seen on Apple platforms.

Lingua principale
C++
Stelle
1.3k
Fork
298
Merge medio
5g 5h
PR unite (30g)
19

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Vector35/binaryninja-api

Tutte le issue di Vector35/binaryninja-api

Issue simili

Altre issue su C++

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.