diff --git a/WEEK04/WEEK04-BN.md b/WEEK04/WEEK04-BN.md index fb6addc..75c0ea6 100644 --- a/WEEK04/WEEK04-BN.md +++ b/WEEK04/WEEK04-BN.md @@ -619,7 +619,18 @@ main | `0x10000da0` | `time_us_64` | `uint64_t time_us_64(void)` | | `0x100033e0` | `strlen` | `size_t strlen(const char*)` | -> **A `void` return type may not stick.** Binary Ninja treats `void` as low-confidence, and its analysis can override it with an inferred type — most often `int32_t` on this 32-bit target. It is most visible on `_reset_handler` (a hand-written assembly entry that never returns normally), but it can happen to **any** function whose return type Binary Ninja thinks it can infer. If a header shows a different return type right after you set `void`, that is the analysis winning, not a mistake in what you typed — leave it. It does not affect the rest of the lesson. +> **A `void` return type may not stick — here is the fix.** Binary Ninja treats `void` as low-confidence, and its analysis can override it with an inferred type — most often `int32_t` on this 32-bit target. It is most visible on `_reset_handler` (a hand-written assembly entry that never returns normally), but it can happen to **any** function whose return type Binary Ninja thinks it can infer. +> +> Setting the full signature with `Y` reproduces the unwanted `int32_t`, and `fn.return_type = ...` fails too. What works is the **return-value** setter: +> +> ```python +> from binaryninja import ReturnValue, Type +> fn = bv.get_function_at(0x1000015c) +> if fn is not None: +> fn.return_value = ReturnValue(Type.void()) +> ``` +> +> That holds `_reset_handler` at `void` even after reanalysis (verified live). Setting the signature and the return type both failing while `return_value` succeeds looks like a bug or inconsistency in this build (BN 6.0.10601). If it still will not stick, leave it — it does not affect the rest of the lesson. > **`__wrap_printf` is the real symbol.** `printf` in our source compiles to the SDK's `__wrap_printf` (which forwards to `__wrap_vprintf`). Rename it `printf` if you prefer the lesson's shorthand, but `__wrap_printf` is what the ELF says. > diff --git a/WEEK04/WEEK04-BN.pdf b/WEEK04/WEEK04-BN.pdf index 9ea5791..c4019d8 100644 Binary files a/WEEK04/WEEK04-BN.pdf and b/WEEK04/WEEK04-BN.pdf differ