`create_auto_var` replaces the type of a user-defined variable while `is_var_user_defined` stays true

Open
#8,541 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
38/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
cpp

Research direction

Start by reproducing the supplied script around create_user_var, create_auto_var, Variable.type, Function.get_variable_type, and is_var_user_defined after analysis settles. Trace the variable-type update and user-defined-state entry points; done means the chosen precedence or state semantics are implemented consistently and covered by a regression test for both update orders.

Written by the indexing model from the issue text.

Description

The following issue was identified, triaged and written by Claude Fable 5.1, I have read through it to make sure the information is coherent and useful.


Version and Platform (required):

  • Binary Ninja Version: 6.1.10594-dev
  • Edition: Ultimate
  • OS: macOS
  • OS Version: 26.5.1
  • CPU Architecture: arm64

Bug Description:
Calling create_auto_var on a variable that already has a user-defined type replaces the type that reads back from Variable.type / Function.get_variable_type with the auto one, while is_var_user_defined still reports True for the variable. The same happens in the other order: a user type set after an auto type wins, and a further auto type set after that wins again. It is not clear to me whether an auto type is meant to override a user one, but the combination of a variable reporting itself as user-defined and returning the auto type looks wrong either way. In practice an analysis activity that types variables with CreateAutoVariable undoes a user's manual retype of the same variable on every re-analysis.

Steps To Reproduce:
Observed on dyld shared cache and a Mach-O with a plugin workflow, and reproduced from a script with the analysis settled. f is a function, v one of its MLIL variables with no user type, T1/T2/T3 distinct pointer types.

f.create_user_var(v, T1, v.name); bv.update_analysis_and_wait()
v.type                     # T1, f.is_var_user_defined(v) is True
f.create_auto_var(v, T2, v.name); bv.update_analysis_and_wait()
v.type                     # T2, f.is_var_user_defined(v) is still True

Reverse order on a second variable:

f.create_auto_var(w, T1, w.name)   # T1, user-defined False
f.create_user_var(w, T2, w.name)   # T2, user-defined True
f.create_auto_var(w, T3, w.name)   # T3, user-defined still True

Expected Behavior:
Either the user type keeps precedence and create_auto_var on a user-defined variable is a no-op for the reported type, or the variable stops reporting itself as user-defined once an auto type has replaced its type. Which of the two is intended is the question.

Additional Information:
Setting the auto type with confidence 255 or 250 makes no difference. Workaround in use: check is_var_user_defined before every auto retype.

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Vector35/binaryninja-api

All issues in Vector35/binaryninja-api

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.