Incomplete decompilation in golang binary

オープン
#7,435 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
35/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
go

調査の方向性

Open the attached asd.exe, navigate to main.main, and inspect Pseudo C and MLIL around 0x004cdbe9 and the branch at 0x004cdc90. Reproduce the incorrect always-false branch and confirm that correcting the analysis allows the remaining main-function code to appear in the decompilation.

索引モデルが issue の本文から書いたものです。

説明

Core: Calling Convention Core: Dataflow Effort: Medium Impact: Medium Language: Go

Version and Platform (required):

  • Binary Ninja Version: 5.2.8286-dev
  • Edition: Non-Commercial
  • OS: Windows
  • OS Version: 10
  • CPU Architecture: x64

Bug Description:
BInary NInja doesn't fully decompile the main function, decompiler output ends at runtime.ncpu_3 = runtime.ncpu_3;, but there is more code. The bug happens because MLIL thinks that branch at 0x004cdc90 is always false

Steps To Reproduce:

  1. Open asd.exe
  2. Go to main.main function
  3. Open Pseudo C and MLIL (or any other lower BNIL)
  4. Go to 0x004cdbe9
  5. See that in MLIL there is more code.

Expected Behavior:
Full decompilation of main function

Binary:
asd.zip

主要言語
C++
スター
1.3k
フォーク
298
平均マージ
5日 5時間
マージ済み PR(30日)
19

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

Vector35/binaryninja-api のほかの issue

Vector35/binaryninja-api の issue をすべて見る

似ている issue

C++ の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。