Skip to content

Very oldschool x86 signed division by 2 using sar+adc lifts into something unhelpful #8457

Description

@ArcaneNibble

Version and Platform (required):

  • Binary Ninja Version: 5.3.9757 Personal (a99f2380)
  • OS: macOS
  • OS Version: 26.6.1
  • CPU Architecture: ARM64

Bug Description:
I have a target that has been compiled using Borland C++, either version 4.5 or 5.x (from the late 90s). In this compiler, the following code:

int bad_div2(int x) { return x / 2; }

…which computes a signed division by 2, ends up compiling into the following assembly:

	sar       eax,1
	jns	short @3
	adc       eax,0
@3:

After loading this into Binary Ninja, it decompiles into a rather unhelpful:

0040107c    int32_t sub_40107c(int32_t arg1)
0040107c    {
0040107c        int32_t result = arg1 >> 1;
🚫🚫00401082        bool c = /*   bool c = unimplemented  {sar eax, 0x1} */;
00401082        
00401084        if (arg1 >> 1 >= 0)
0040108a            return result;
0040108a        
00401086        return result + 0;
0040107c    }

Steps To Reproduce:
Please provide all steps required to reproduce the behavior:

  1. I am attaching a fully-linked EXE which includes this function at address 0x40107c. (Running the EXE doesn't do anything, it's only useful for looking at the function.)

Expected Behavior:
It'd be really nice if this pattern could be recognized and simplified.

Screenshots/Video Recording:
N/A

Binary:
binjabaddiv.zip

Additional Information:
N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions