Support for variable size structure array in decompiler

オープン
#3,530 コメント 1 件 リアクション 2 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
35/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
c, cpp

調査の方向性

Start with the supplied C reproduction and compare its current HLIL output with the expected indexed structure-array accesses. Trace the decompiler path responsible for structure-member and pointer-array indexing, then add coverage demonstrating the expected output and verify that both the allocation loop and print_persons example decompile correctly.

索引モデルが issue の本文から書いたものです。

説明

Component: Core Effort: Medium Impact: Medium

I've a structure which have a variable sized structure array in it. After importing and setting types it decompiled like this in HLIL:

people people
people.count = 0
people.arr = malloc(0x30)

... (memset )

for (int32_t i = 0; i s<= 3; i = i + 1)
    //expected: people.arr[i].age = i
    people.arr[sx.q(i) * 4] = i
    //expected: people.arr[i].name = "test name"
    *(people.arr + sx.q(i) * 0x10 + 8) = "test name"
    people.count = people.count + 1

print_persons(people: &people)

print_persons

for (int32_t i = 0; i s< 3; i = i + 1)
    printf("Person: %s, Age:%d\n", people->arr[sx.q(i)].name, zx.q(people->arr[sx.q(i)].age))

I guess this is not a bug, but a feature not implemented yet. I could not find an issue for it so creating one for tracking it.

Test code:

typedef struct _person
{
	int age;
	char* name;
}person;

typedef struct _people
{
	int count;
	person* arr;
}people;


void print_persons(people *people)
{
	for (int i = 0; i < 3; i++)
	{
		printf("Person: %s, Age:%d\n", people->arr[i].name, people->arr[i].age);
	}
}

int main()
{
	people people;

	people.count = 0;
	people.arr = malloc(sizeof(person) * 3);

	memset(people.arr, 0, sizeof(person) * 3);

	for (int i = 0; i <= 3; i++)
	{
		people.arr[i].age = i;
		people.arr[i].name = "test name";
		people.count++;
	}

	print_persons(&people);
}
主要言語
C++
スター
1.3k
フォーク
298
平均マージ
5日 5時間
マージ済み PR(30日)
19

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

Vector35/binaryninja-api のほかの issue

Vector35/binaryninja-api の issue をすべて見る

似ている issue

C++ の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。