Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

x86: bt/bts/btr/btc lift the carry flag with an unmasked bit index

未关闭
#8,375 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
68/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
冷清
技术栈
cpp

调研方向

Start from the x86 lifter paths for register-indexed bt, bts, btr, and btc, comparing the carry-flag test with the existing masked write index. Use the supplied byte sequence and LLIL to reproduce the mismatch, then verify that the carry flag uses the reduced index and matches the hardware results for all four instructions.

由索引模型根据 Issue 内容生成。

描述

For bt/bts/btr/btc with a register bit index, the lifter masks the index
on the memory/register write but not on the carry flag, so the two halves of the
same instruction disagree when the index is >= the operand size.

Intel SDM: for a register destination, the bit offset is taken modulo the operand
size, so bts eax, ecx with ecx = 33 operates on bit 1.

Repro
b802000000 b921000000 0fabc8 c3
mov eax, 2
mov ecx, 33
bts eax, ecx
ret

LLIL:

eax = 2
ecx = 0x21
flag:c = test_bit(eax, ecx)              <-- raw index 33
eax = eax | 1 << modu.d(ecx, 0x20)       <-- index correctly reduced to 1
Expected vs actual

Hardware (executed on x86-64), all with eax = 2, ecx = 33:

instruction CF eax
bt eax, ecx 1 0x2
bts eax, ecx 1 0x2
btr eax, ecx 1 0x0
btc eax, ecx 1 0x0

Binary Ninja reports CF = 0, because test_bit(eax, 33) reads bit 33 of 2
rather than bit 1. The write side is correct. Dataflow constant-folds the wrong
flag value accordingly.

主要语言
C++
星标
1.3k
派生
298
平均合并
4 天 13 小时
30 天内合并 PR
20

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

Vector35/binaryninja-api 的其他 Issue

查看 Vector35/binaryninja-api 的全部 Issue

相似的 Issue

更多 C++ Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。