Skip to content

Point relocated ARM xrefs at Thumb entries ##analysis - #26934

Merged
trufae merged 1 commit into
radareorg:masterfrom
phix33:arm-esil-thumb-xref-reloc
Oct 9, 2026
Merged

trufae merged 1 commit into
radareorg:masterfrom
phix33:arm-esil-thumb-xref-reloc

Conversation

@phix33

@phix33 phix33 commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator
  • Mark this if you consider it ready to merge
  • I've added tests (optional)
  • I wrote some lines in the book (optional)

Description

With relocations applied, an ARM PLT stub that loads a Thumb function pointer records its CODE xref one byte past the function entry:

$ r2 -e bin.relocs.apply=true -qc 'aaa; ax~0x3e158~CODE' test/bins/elf/libarm.so
                          fcn.0003e150+8 0x3e158 > CODE:--x > 0x2d589 sym.std::__ndk1::to_string_int_+1
  • Record the xref at 0x2d588 when the instruction reads a relocation slot whose Thumb symbol matches that address exactly. Resolve both the slot and symbol in the loaded address space, including -B.
  • Preserve the raw target for validity checks and function discovery. An odd value or Thumb hint alone is insufficient evidence to change an xref.
  • Let targeted ESIL searches find the xref using either the raw pointer or the function entry.

The libarm/g711 PLT, rebased-load, and raw/even search cases fail without the fix. Controls cover mismatched slot contents, ARM symbols, missing relocation provenance, register branches, and unrelated veneers. The g711 case also checks that subsequent anal.calls analysis keeps the real Thumb function intact.

@trufae
trufae merged commit c75d8ad into radareorg:master Oct 9, 2026
45 checks passed
@trufae

trufae commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

I was expecting a much larger patch! Lgtm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants