Very oldschool x86 signed division by 2 using `sar`+`adc` lifts into something unhelpful
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- cpp
- Ambito
- reverse-engineering
Direzione di ricerca
Start with the attached binjabaddiv.zip and inspect the function at 0x40107c in Binary Ninja; compare the lifted SAR/ADC flags and conditional path with signed division by two. Done means this pattern decompiles without an unimplemented carry flag and expresses the intended signed result.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Version and Platform (required):
- Binary Ninja Version: 5.3.9757 Personal (a99f2380)
- OS: macOS
- OS Version: 26.6.1
- CPU Architecture: ARM64
Bug Description:
I have a target that has been compiled using Borland C++, either version 4.5 or 5.x (from the late 90s). In this compiler, the following code:
int bad_div2(int x) { return x / 2; }
…which computes a signed division by 2, ends up compiling into the following assembly:
sar eax,1
jns short @3
adc eax,0
@3:
After loading this into Binary Ninja, it decompiles into a rather unhelpful:
0040107c int32_t sub_40107c(int32_t arg1)
0040107c {
0040107c int32_t result = arg1 >> 1;
🚫🚫00401082 bool c = /* bool c = unimplemented {sar eax, 0x1} */;
00401082
00401084 if (arg1 >> 1 >= 0)
0040108a return result;
0040108a
00401086 return result + 0;
0040107c }
Steps To Reproduce:
Please provide all steps required to reproduce the behavior:
- I am attaching a fully-linked EXE which includes this function at address 0x40107c. (Running the EXE doesn't do anything, it's only useful for looking at the function.)
Expected Behavior:
It'd be really nice if this pattern could be recognized and simplified.
Screenshots/Video Recording:
N/A
Binary:
binjabaddiv.zip
Additional Information:
N/A
- Lingua principale
- C++
- Stelle
- 1.3k
- Fork
- 298
- Merge medio
- 4g 13h
- PR unite (30g)
- 20
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Vector35/binaryninja-api
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 88/100
Vector35/binaryninja-api#8540 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
Vector35/binaryninja-api#8446 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
Vector35/binaryninja-api#8444 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Vector35/binaryninja-api#8441 · 3 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Vector35/binaryninja-api#8404 ·
Tutte le issue di Vector35/binaryninja-api
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
google/libultrahdr#485 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
godotengine/godot#123776 ·
-
bug
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 60/100
-
good first issue
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
-
good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
ros2/common_interfaces#344 ·