Skip to content

Broken navigation with nested anonymous structures #8558

Description

@D0ntPanic

Version and Platform (required):

  • Binary Ninja Version: 6.1.10668-dev
  • Edition: Ultimate
  • OS: macOS
  • OS Version: 27.0
  • CPU Architecture: M5

Bug Description:
Trying to navigate to a field nested in one or more anonymous structures fails to navigate.

Steps To Reproduce:

Structure:
struct foo {
    int pad;
    struct {
        int bar;
    } inner;
};

Code (x86 Windows):
int32_t sub_0(struct foo* arg1)
mov     eax, dword [esp+0x4]
mov     eax, dword [eax+0x4]
retn

HLIL:
return arg1->inner.bar

Trying to double click bar fails to navigate to the field. Looking at the token itself:

>>> current_il_instruction.tokens[-1].typeNames
['bar']

The token doesn't have valid type information for figuring out how to navigate to it.

Making it a union instead:

union foo_u
{
    struct
    {
        int32_t a;
        int32_t b;
    } bar;
};

Function type:
int32_t sub_0(union foo_u* arg1)

HLIL (broken):
return arg1->bar.__offset(0x4).d

MLIL:
eax = eax_1->bar.b

Double clicking b in MLIL also fails to navigate. The token for this:

>>> current_il_instruction.tokens[-1].typeNames
['foo_u', 'bar', 'b']

These two types also fail to navigate when made into data variables.

Expected Behavior:
Double clicking the inner field of these structures should navigate to that field in the types view.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions