MSP430: byte operations sign-extend into registers instead of zero-extending
Los mantenedores suelen responder en 2 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 72/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- rust
- Área
- reverse-engineering
Línea de trabajo
Start in arch/msp430/src/lift.rs and inspect the byte-handling arms, including Instruction::Mov, where the issue identifies il.sx(2, ...) as suspect. Load sx_repro.bin or use the provided printf command, then compare LLIL at offset 0 and the resulting HLIL value against the documented zero-extension behavior. Done means byte register operations produce 0x80 + arg1 rather than 0xff80 + arg1.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Version and Platform (required):
- Binary Ninja Version: 5.0.7648
- Edition: Non-Commercial
- OS: Ubuntu
- OS Version: 24.04
- CPU Architecture: x64
Bug Description:
A byte instruction with a register destination is lifted with a sign-extension. Per slau144 §3.2.5, Figure 3-7 (Byte-Register Operation), the high byte of the destination register is filled with 0h — byte operations zero-extend into registers.
The result is an incorrect constant in HLIL for any byte value with bit 7 set.
Steps To Reproduce:
printf '\x7b\x40\x80\x00\x0f\x5b\x30\x41' > sx_repro.bin or open sx_repro.bin attached and look at sub_0 (if sub_0 does not exist, create a function at 0).
Expected Behavior:
The returned value should be 0x80 + arg1 and not 0xff80 + arg1.
LLIL at offset 0 should not sign-extend.
Confirmed against the mspdebug simulator (v0.22): with r11 = 0xdead and r15 = 0x1234 set beforehand, mov.b #0x80, r11 leaves r11 = 0x0080. The subsequent add r11, r15 gives 0x12b4.
Screenshots/Video Recording:
Binary:
sx_repro.zip
Suspected cause (hypothesis):
The byte arms in arch/msp430/src/lift.rs use il.sx(2, ...) where il.zx(2, ...) is required — e.g. in Instruction::Mov:
OperandWidth::Byte => il
.sx(2, lift_source_operand(inst.source(), size, il))
.build()
This appears in several instruction arms, so the fix is likely needed in more than one place.
- Lenguaje dominante
- C++
- Estrellas
- 1.3k
- Forks
- 297
- Merge medio
- 3 d 11 h
- PR fusionados (30 d)
- 17
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Vector35/binaryninja-api
-
Hexagon lifting issuesAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Vector35/binaryninja-api#8621 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
ARMv7 lifting issuesAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Vector35/binaryninja-api#8617 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Vector35/binaryninja-api#8589 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 88/100
Vector35/binaryninja-api#8540 ·
Los mantenedores suelen responder en 2 días
-
normalize time logs from WARPAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Vector35/binaryninja-api#8446 ·
Los mantenedores suelen responder en 2 días
Todos los issues de Vector35/binaryninja-api
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
espressif/esp-matter#1874 ·
-
cudev: Fix MSVC build failures with 64-bit integers (int64_t/uint64_t) in vec_traits.hppPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
opencv/opencv_contrib#4231 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
MiSTer-devel/Main_MiSTer#1341 ·
Los mantenedores suelen responder en 1 día
-
Wrong macro use under MSVCAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
Los mantenedores suelen responder en 3 días
-
`-static-libstdc++` breaks buildAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
linux-test-project/lcov#552 ·
Los mantenedores suelen responder en 1 día