3 ms·
Oh yeah - absolutely. This isn't even just a PowerPC thing - it happens more generally, because usually if you're forwarding both arguments and return values fo
by jchw 12d ago
Oh yeah - absolutely. This isn't even just a PowerPC thing - it happens more generally, because usually if you're forwarding both arguments and return values for a function that has the same calling conventions, you don't really have to do much adaptation, everything was already set up for you. It hit me a ton on x86 when I first started my journey into trying to reverse engineer. It still occasionally hits me, especially when I'm relying too hard on decompiler output and not paying enough attention.
There are plenty of examples where two very semantically different source codes can have the same output, which is really counter-intuitive when combined with the difficulty that often comes with trying to find a single source code that does match.
This is just another reason why debug information is such a godsend; having symbol names for C++ code will usually give you most of the function signature, and type information will give you the rest. That greatly enriches the disassembly, and the automated decompilation output, and no doubt constrains the number of possible source codes that could match both the output and the debug information, somewhat alleviating this issue.
- StilesCrisis 12d agoYup. Unfortunately the project I'm working on does not have any debug info. There are not even lingering __FILE__ strings anywhere. Just picking out the TU bounds has been a chore! It's a huge benefit that things like the OS and SDK are known and predictable. This got me a foothold. Otherwise I would have gotten nowhere. I'm still impressed that this decomp has macros (fully lost in the assembly) and nearly-100% meaningful variable names and struct layouts. That's not easy!
- jchw 12d agoHow in the world are you finding reasonable TU boundaries, without debug info? I've always been puzzled by this in particular.
- StilesCrisis 12d agoFloat constants are stored as data which is deduplicated on a per-TU basis. So if my TU has 1.0 and 0.0 in it, every function in that TU which uses those numbers will load from the same address. The next TU will get its own dedicated 1.0 and 0.0 constants.
- jchw 12d agoThat is pretty clever. In a particularly C++ heavy program I was able to find decent splits by starting around where the vtables were stored and searching from there, which was helpful since they also often pointed into the relevant part of the .text section. The repeating floats thing definitely seems to ring true though. For old MSVC it seems like it will emit floats even if they aren't directly referenced, if they happen to be referenced by inline functions that are not used. That adds another challenge if you want to get really close to the actual original source: figuring out what those inline functions actually are instead of just dropping a dummy that references them and is never used :) But I'd say that's extra credit, if you ever got to the point where that was the only remaining debt...
- StilesCrisis 12d agoFor sure, actually mirroring the shape of inlined code properly rather than just emitting code N times is already extra credit as far as I'm concerned. I've got enough loose ends without chasing that sort of thing!