IL String Rendering Ignores Types for Read-Only Sections
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- cpp
调研方向
No source files, tests, or entry points are named. Reproduce the issue with an ELF .rodata section or read-only segment, change a string variable to an int or struct, and compare the IL rendering; review related issue 2971. Done means explicitly non-string types no longer render as strings while valid string rendering remains available.
由索引模型根据 Issue 内容生成。
描述
Version and Platform (required):
- Binary Ninja Version: 3.0.3233-stable, 3.0.3255-dev
- OS: Manjaro Linux
- OS Version: Up to date
Bug Description:
Ascii string rendering in IL ignores type information for data variables in ReadOnlyDataSectionSematics sections, or a segment with read but not write segment flags if no sections are defined. Any reference to an address which contains a valid ascii string, regardless of whether or not that address has been identified to be of type const char[]/char[]/const char */char *, or of some other non string type such as an int, or a struct (with or without a char[] as its first member), will result in the rendering of the string in the IL. See image below for an example. This behavior is primarily a problem with structures in a readOnly section which happen to have a char[] (or otherwise valid ascii) for their first field.
It's also clear that binary ninja does know the correct type for that address, as demonstrated in the image: the struct member accesses are displayed as expected.
This appears to be related to a similar issue, where string rendering is completely disabled when the addresses being referenced reside in a read-write section at the time the view is initialized and loaded. I am still tracking that down though, and will file a separate issue.
Steps To Reproduce:
Please provide all steps required to reproduce the behavior:
- Open a binary and ensure that there is a section containing ascii strings mapped with ReadOnlyDataSectionSemantics (ELF's .rodata is fine)
- Locate a reference to an address of one of these strings, such that the IL is rendering the string
- Change the type of the string var to something else, for example an int or struct
- Observe that the string is still rendered in the IL
Expected Behavior:
Strings should not be rendered in IL if the types of the underlying variable at the "string" address has been explicitly set to not be a string. I think the behavior to default to string rendering when it seems plausible is fine and in fact very useful, but it needs to be overrideable in cases where it was incorrect (for example in the case of the struct with a char[] as its first member).
Screenshots:
Correct IL, displayed only when world resides in a read/write section

Incorrect IL, displayed when world resides in a read-only section

Definition of the data variable world

Manually redefinition of world to explicitly not have a char[] as it's first member, no change in IL behavior

Additional Information:
I'd like to share an example in the form of an x86 ELF bndb file, where I've manually set the .data section to have ReadOnlyDataSectionSemantics for the sake of demonastration; see the first few lines of the main function, just after the call to srand.
- How can I share it here, github does not allow for the uploading of bndb files in issues.
Possibly related to https://github.com/Vector35/binaryninja-api/issues/2971
- 主要语言
- C++
- 星标
- 1.3k
- 派生
- 298
- 平均合并
- 5 天 5 小时
- 30 天内合并 PR
- 19
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Vector35/binaryninja-api 的其他 Issue
-
难度 1/5 1-3 小时 新手友好度 88/100
Vector35/binaryninja-api#8540 ·
-
难度 2/5 1-3 小时 新手友好度 88/100
Vector35/binaryninja-api#8516 ·
-
难度 1/5 1 小时以内 新手友好度 92/100
Vector35/binaryninja-api#8503 ·
-
难度 1/5 1 小时以内 新手友好度 88/100
Vector35/binaryninja-api#8446 ·
-
难度 1/5 1 小时以内 新手友好度 88/100
Vector35/binaryninja-api#8444 ·
查看 Vector35/binaryninja-api 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 86/100
-
Sensor initialization takes very long when `--initial-sim-time` is set to current UNIX timestamp 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
gazebosim/gz-sensors#662 · 1 条评论 ·
-
enhancement
难度 2/5 1-3 小时 新手友好度 76/100
-
comp-datalake
难度 2/5 1-3 小时 新手友好度 88/100
ClickHouse/ClickHouse#121222 ·
-
难度 2/5 1-3 小时 新手友好度 68/100
LadybirdBrowser/ladybird#12123 ·