Dead Code Detection
Detection Workflow
- Build call graph: Use
disasm to build control flow, identify all functions, map function call relationships
- Identify entry points: Find main/entry functions, locate exported functions, identify callback registrations, map interrupt handlers
- Trace reachability: Perform forward reachability analysis from entry points, mark all reachable functions and blocks, identify unreachable code
- Analyze dead code: Categorize dead code types, assess security implications, identify potential vulnerabilities, estimate size reduction
Key Patterns
- Unreachable functions: functions with no callers, functions only called from dead code, functions after infinite loops, functions after exit() calls
- Unreachable blocks: basic blocks after return statements, code after unconditional jumps, blocks with no incoming edges, code guarded by always-false conditions
- Unused data: global variables never referenced, string constants never used, data sections with no references, debug symbols in production builds
- Conditional dead code: code in always-false branches, debug-only code in release builds, platform-specific code for other platforms, feature flags permanently disabled
Output Format
Report with: id, type, subtype, severity, confidence, location, dead_code_type, reason, callers, references, size_estimate, security_implications, potential_vulnerabilities, recommendation.
Severity Guidelines
- MEDIUM: Dead code containing security vulnerabilities
- LOW: Dead code with no security impact
See Also
patterns.md - Detailed detection patterns and exploitation scenarios
examples.md - Example analysis cases and code samples
references.md - CWE references and mitigation strategies
1---2name: detecting-dead-code3description: Identifies unreachable functions, unused variables, and abandoned code in binary programs. Use when optimizing binary size, analyzing code coverage, or investigating abandoned functionality.4---5
6# Dead Code Detection
7
8## Detection Workflow
9
101. **Build call graph**: Use `disasm` to build control flow, identify all functions, map function call relationships
112. **Identify entry points**: Find main/entry functions, locate exported functions, identify callback registrations, map interrupt handlers
123. **Trace reachability**: Perform forward reachability analysis from entry points, mark all reachable functions and blocks, identify unreachable code
134. **Analyze dead code**: Categorize dead code types, assess security implications, identify potential vulnerabilities, estimate size reduction
14
15## Key Patterns
16
17- Unreachable functions: functions with no callers, functions only called from dead code, functions after infinite loops, functions after exit() calls
18- Unreachable blocks: basic blocks after return statements, code after unconditional jumps, blocks with no incoming edges, code guarded by always-false conditions
19- Unused data: global variables never referenced, string constants never used, data sections with no references, debug symbols in production builds
20- Conditional dead code: code in always-false branches, debug-only code in release builds, platform-specific code for other platforms, feature flags permanently disabled
21
22## Output Format
23
24Report with: id, type, subtype, severity, confidence, location, dead_code_type, reason, callers, references, size_estimate, security_implications, potential_vulnerabilities, recommendation.
25
26## Severity Guidelines
27
28- **MEDIUM**: Dead code containing security vulnerabilities
29- **LOW**: Dead code with no security impact
30
31## See Also
32
33- `patterns.md` - Detailed detection patterns and exploitation scenarios
34- `examples.md` - Example analysis cases and code samples
35- `references.md` - CWE references and mitigation strategies