From 4d7e55d9139e1fa0ed6a53d21f2b8cfc33b5c2ba Mon Sep 17 00:00:00 2001 From: Xiaoyin Liu Date: Thu, 29 Apr 2021 09:31:08 -0400 Subject: [PATCH] define a set that contains noreturn syscalls hardcode noreturn function list Make LinuxSyscallsScript mark no-return functions This patch makes the script ResolveX86orX64LinuxSyscallsScript.javarecognize syscalls that do not return, and mark these functions asno-return. The list of non-return functions is read fromElfFunctionsThatDoNotReturn. --- .../ResolveX86orX64LinuxSyscallsScript.java | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/Ghidra/Features/Base/ghidra_scripts/ResolveX86orX64LinuxSyscallsScript.java b/Ghidra/Features/Base/ghidra_scripts/ResolveX86orX64LinuxSyscallsScript.java index bd5010b97d..ca0f979b8f 100644 --- a/Ghidra/Features/Base/ghidra_scripts/ResolveX86orX64LinuxSyscallsScript.java +++ b/Ghidra/Features/Base/ghidra_scripts/ResolveX86orX64LinuxSyscallsScript.java @@ -65,6 +65,9 @@ public class ResolveX86orX64LinuxSyscallsScript extends GhidraScript { //native "syscall" instruction private static final String SYSCALL_X64_CALLOTHER = "syscall"; + //a set of names of all syscalls that do not return + private static final Set noreturnSyscalls = Set.of("exit", "exit_group"); + //tests whether an instruction is making a system call private Predicate tester; @@ -179,6 +182,11 @@ public class ResolveX86orX64LinuxSyscallsScript extends GhidraScript { } callee = createFunction(callTarget, funcName); callee.setCallingConvention(callingConvention); + + //check if the function name is one of the non-returning syscalls + if (noreturnSyscalls.contains(funcName)) { + callee.setNoReturn(true); + } } Reference ref = currentProgram.getReferenceManager().addMemoryReference(callSite, callTarget, overrideType, SourceType.USER_DEFINED, Reference.MNEMONIC);