Skip to content

Avoid creating functions at jump table entries in shared cache - #8002

Open
plafosse wants to merge 2 commits into
devfrom
fix/shared-cache-jump-table-functions
Open

plafosse wants to merge 2 commits into
devfrom
fix/shared-cache-jump-table-functions

Conversation

@plafosse

@plafosse plafosse commented Mar 9, 2026

Copy link
Copy Markdown
Member

Summary

  • When processing shared cache Mach-O function tables, Binary Ninja was creating functions at addresses that turn out to be jump table entries rather than real function starts, producing spurious sub_ functions.
  • Adds a HeuristicIsAFunction check before calling AddFunctionForAnalysis. On aarch64, if the first instruction at the candidate address disassembles as udf, the entry is skipped — udf is used as padding/data in jump tables and is never a valid function prologue.
  • This heuristic is admittedly a bit rough and could produce false negatives in unusual cases, but it directly addresses the reported symptom.

Fix #7992

Comment thread view/sharedcache/core/MachOProcessor.cpp Outdated
@plafosse plafosse added this to the Jotunheim milestone Mar 24, 2026
Extract MachoView::IsValidFunctionStart logic into a shared inline function and reuse it in the shared cache MachOProcessor to skip creating functions at jump table entries (udf/trap instructions).
@plafosse
plafosse force-pushed the fix/shared-cache-jump-table-functions branch from 3cc4a96 to 7ad9550 Compare March 27, 2026 16:06
@plafosse plafosse modified the milestones: Jotunheim, Krypton Apr 7, 2026
@plafosse plafosse modified the milestones: Krypton, L Aug 20, 2026
@plafosse
plafosse requested a review from bdash August 20, 2026 14:34
Comment thread view/macho/machoview.h Outdated
Comment thread view/sharedcache/core/MachOProcessor.cpp Outdated
@plafosse
plafosse requested a review from bdash September 28, 2026 13:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Functions are being created for jump tables in code sections

2 participants