Skip to content

Stop treating arm64 sub to a non-sp register as a stack reset ##arch - #26899

Merged
trufae merged 1 commit into
radareorg:masterfrom
phix33:arm64-sub-stack-reset
Oct 4, 2026
Merged

trufae merged 1 commit into
radareorg:masterfrom
phix33:arm64-sub-stack-reset

Conversation

@phix33

@phix33 phix33 commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator
  • Mark this if you consider it ready to merge
  • I've added tests (optional)
  • I wrote some lines in the book (optional)

Description

On arm64 any sub whose destination is not sp is treated as a stack reset, so after sub x0, x0, 1 the tracked depth drops to 0 and every later sp access in the block is read as a stack argument above the frame.

$ r2 -a arm -b 64 -qc 'e anal.vars.stackname=true; wx ff8300d1000400d1e00300f9ff830091c0035fd6; af; afva; afv; ao 1 @ 4~stackop' -
arg int64_t arg1 @ x0
arg int64_t arg_0h @ sp+0x20
stackop: reset

str x0, [sp] writes the local at the bottom of the 0x20 frame; with this PR it is var_20h @ sp+0x0 and sub x0, x0, 1 has no stackop.

  • anop64 no longer sets R_ANAL_STACK_RESET on sub with a non-sp destination, matching add. Only instructions that write sp change the depth.
  • arm.v35 had the same reset on both sub and add; it goes too.
  • Across the 103 arm64 binaries in the testbins, aaa loses 3587 phantom stack args and gains none.

The new case in test/db/anal/arm64 fails without the fix on both the variable and the stackop; its sub sp, sp, 0x20 line keeps master's inc of 32. A second case checks that arm.v35 no longer reports a reset for sub x0, x0, 1 or add x0, x0, 1; it only runs on builds with v35 enabled.

@trufae
trufae merged commit ae051a5 into radareorg:master Oct 4, 2026
50 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants