Skip to content

Commit 8f788dc

Browse files
committed
Fix branch override lifting for tail calls and cross-width targets
Match LLIL_TAILCALL exits for unresolved and indirect branches, preserving MIPS delay-slot effects without adding return-address setup. Use the destination architecture's address size for explicit replacement targets to prevent truncation during value analysis.
1 parent b305cc6 commit 8f788dc

1 file changed

Lines changed: 7 additions & 5 deletions

File tree

‎defaultarch.cpp‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -995,7 +995,9 @@ static bool ApplyLiftedBranchOverrides(LowLevelILFunction& dest, LowLevelILFunct
995995
break;
996996
case IndirectBranch:
997997
case UnresolvedBranch:
998-
match = (exit.operation == LLIL_JUMP) || (exit.operation == LLIL_JUMP_TO);
998+
// Architectures may recognize an indirect jump as a tail call during the initial lift.
999+
match = (exit.operation == LLIL_JUMP) || (exit.operation == LLIL_JUMP_TO)
1000+
|| (exit.operation == LLIL_TAILCALL);
9991001
break;
10001002
case ExceptionBranch:
10011003
match = (exit.operation == LLIL_TRAP) || (exit.operation == LLIL_NORET);
@@ -1098,9 +1100,12 @@ static bool ApplyLiftedBranchOverrides(LowLevelILFunction& dest, LowLevelILFunct
10981100
if ((oldTarget.operation != LLIL_CONST) && (oldTarget.operation != LLIL_CONST_PTR))
10991101
dest.AddInstruction(dest.SetRegister(oldTarget.size, allocateTemporary(), copyExpr(oldTarget), 0, loc));
11001102
}
1103+
Ref<Architecture> targetArch = value.target
1104+
? (value.targetArch ? value.targetArch : location.arch)
1105+
: (replacement->second.second ? replacement->second.second : location.arch);
11011106
ExprId target = BN_INVALID_EXPR;
11021107
if (needsTarget)
1103-
target = value.target ? dest.ConstPointer(location.arch->GetAddressSize(), *value.target, loc)
1108+
target = value.target ? dest.ConstPointer(targetArch->GetAddressSize(), *value.target, loc)
11041109
: copyExpr(*exit->target);
11051110
if (originalNop && (value.type == FunctionReturn) && !value.target)
11061111
{
@@ -1140,9 +1145,6 @@ static bool ApplyLiftedBranchOverrides(LowLevelILFunction& dest, LowLevelILFunct
11401145
dest.SetExprAttributes(setup, ILAllowDeadStoreElimination);
11411146
dest.AddInstruction(setup);
11421147
}
1143-
Ref<Architecture> targetArch = value.target
1144-
? (value.targetArch ? value.targetArch : location.arch)
1145-
: (replacement->second.second ? replacement->second.second : location.arch);
11461148
ExprId transfer;
11471149
switch (value.type)
11481150
{

0 commit comments

Comments
 (0)