26 Commits

Author SHA1 Message Date
kyle-elliott-tob 504ba56170 fix: resolve code review findings for PR #749
Remove unused template parameter P from ExecuteLiftedFunction. The P
parameter was never used in the function body (even before this PR, the
old code hardcoded uint32_t). Now that PC width is dynamically determined
from the LLVM function type, P is clearly vestigial. Updated all three
call sites to match.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 09:18:18 -05:00
Duncan Ogilvie 4689097a21 Add standalone GitHub Actions 2025-11-05 20:46:01 -05:00
Duncan Ogilvie ef5aa7a9b5 Add more functionality to remill-lift to make debugging easier 2025-11-05 20:46:01 -05:00
Duncan Ogilvie 92cbd7a182 Fix compilation on Windows (clang-cl) 2025-11-05 20:46:01 -05:00
Duncan Ogilvie 50ac24a35d Improve test failure output for lift-and-compare 2025-11-05 20:46:01 -05:00
Duncan Ogilvie 4bc1b54d6d Switch back to C++17 2025-11-05 20:46:01 -05:00
Duncan Ogilvie ddef25db7c Add support for LLVM 15-21 2025-11-05 20:46:01 -05:00
cctv130 b6fc70f0f4 CMake: update to C++20, clean up properties, optimize fetch content (#721)
- Enable C++20 on both Windows and Linux
- Remove unnecessary set_property calls to silence LOCATION warnings
- Replace duplicate -fPIC flags with INTERFACE_POSITION_INDEPENDENT_CODE
- Set FETCHCONTENT_BASE_DIR to speed up sleigh and ghidra-fork downloads/builds
- fixed: Does not match the generator used previously: Unix Makefiles,use ninja instead
2025-09-05 17:55:23 -04:00
cctv130 e272b48e84 fix: windows clang build (#719)
* Update settings.cmake

Fix the issue where debugging on Windows in VSCode doesn’t work

* fix: windows clang build

The following flags are not supported in non-MSVC environments
/EHsc /wd4141 /wd4146 /wd4180 /wd4244 /wd4258 /wd4267 /wd4291
/wd4345 /wd4351 /wd4355 /wd4456 /wd4457 /wd4458 /wd4459 /wd4503
/wd4624 /wd4722 /wd4800 /wd4100 /wd4127 /wd4512 /wd4505 /wd4610
/wd4510 /wd4702 /wd4245 /wd4706 /wd4310 /wd4701 /wd4703 /wd4389
/wd4611 /wd4805 /wd4204 /wd4577 /wd4091 /wd4592 /wd4324

Update cmake_minimum_required(VERSION 3.21) to remove CMake warning.
2025-08-18 17:42:31 -04:00
2over12 0183248218 llvm 17 fixes (#688)
* llvm 17 fix

* more instances

* more fixes

* add inline

* bump ci

* bump cxx common

* add 17 case

* bump xcode version

* macos 13

* xcode 15

* bump docker to llvm 17

* change actual matrix value

* opaque pointers are the default now

* actually remove the option

* debug size

* install tree

* fix install

* fix install?

* get tree after

* build dir?

* tree above

* accumulate

* bug?

* try to remove intermediate packaging

* fix opt

* only inline

* give up on function inlining

* llvm 17

* remove debug tasks

* Update scripts/build.sh

Co-authored-by: William Tan <1284324+Ninja3047@users.noreply.github.com>

* Revert "Update scripts/build.sh"

This reverts commit 6c727a539d.

* debug

* try clear out old build

* retest

* try to save more space

* up

* Clear space and don't use cxx-common docker image (#689)

* Clear space and don't use cxx-common docker image

* Run on all PRs

* Fix perms

* Remove some unnecessary apt commands

* Install LLVM version as root

* Allow writing to external target

* Build before running tests

* Install with sudo

* Simplify with container volume mounts

---------

Co-authored-by: William Tan <1284324+Ninja3047@users.noreply.github.com>
Co-authored-by: Eric Kilmer <eric.d.kilmer@gmail.com>
2023-10-12 16:37:45 -04:00
2over12 7182636a68 fix remill lift (#687) 2023-09-26 13:17:25 -04:00
James Olds 047c628a84 update link to empirehacking slack (#675) 2023-07-06 10:54:47 -04:00
Alex Cameron 031305d519 Get Remill building with LLVM 16 (#665)
* Get Remill building with LLVM 16

* Update scripts and README

* Refactor `MoveConstantIntoModule` check to reduce duplication

* Remove hack since we don't plan to clone functions across contexts

* Remove call to deprecated LLVM function

* Add LLVM 16 to CI

* Bump cxx-common version

* Fix scripts to work with new `cxx-common`

* Don't add unsupported `readnone` attribute with LLVM 16

* Use `memory(none)` with LLVM 16 instead of `readnone`

* Add LLVM 16 to docker lifter entrypoint
2023-04-28 10:29:34 +10:00
Alex Cameron fb018c96e9 PowerPC Support (#645)
* Add skeleton for PPC

* Copyright notices

* Fill in some details for the PPC arch

* Start building a (wrong) PPC runtime

* Begin populating state structure

* First pass for EIS state structure

* Map registers to Sleigh register names

* More fixes

* add optional param

* Create handle unsupported and invalid instruction isels

* Correct typo

* Get a basic `remill-lift` invocation running without failure

* Fix capitalisation

* Set vle context reg

* Fix SleighDecoder signatures

* Set VLE context register in the Sleigh engine in addition to our
internal context reg mapping

* Capitalize reg names

* Add the flag registers for XER and CR

* Rename bitflag structures in PPC state

* PPC Sleigh patches (#643)

* Modified sleigh patch script to generate patches for multiple .sinc files

* update README with new examples of sleigh patch script invocation

* add ppc register definition

* add ppc sleigh patches

* fix issue with remill_insn_size definition

* regenerate sleigh patches for PPC

* update CMakeLists.txt to include PPC patches

* Add TEA signal as a register in the PPC state

* Uppercase the stack pointer register name

* Fix PPC instruction sizes

* initial PPC tests

* remove duplicate tests

* fix tests for e_stmvgprw/e_ldmvgprw

* add tests for loading/storing from special registers

* add tests with internal conditionals in pcode

* fix for pc reg and addr width not being the same... I suspect this issue is going to come up elsewhere

* add heuristic for flow from normal intrainstruction flow

* rework tests to allow testing for different sized registers

* add tests for overflow and record add

* fix bug with log printout

* add intrafunction control flow lifting

* handle edge case where there is no pcode op at the zero index

* Fix another inconsistency with mismatching address and PC reg size

* Allocate unique ptrs in the entry block

* Fix `INT_LEFT` and `INT_RIGHT` impl where shift exceeds bit width

* fix supiece lift?

* Add PPC emulate instruction to hyper call

* fix for pc reg and addr width not being the same... I suspect this issue is going to come up elsewhere

* add heuristic for flow from normal intrainstruction flow

* add intrafunction control flow lifting

* handle edge case where there is no pcode op at the zero index

* Fix another inconsistency with mismatching address and PC reg size

* fix supiece lift?

* Allocate unique ptrs in the entry block

* Fix `INT_LEFT` and `INT_RIGHT` impl where shift exceeds bit width

* fix int2float semantics

should use appropriate sized float based on the output size

* add tests for lifting int2float

* fix INT_{LEFT,RIGHT} semantics

should be `ICmpSGE` instead of `ICmpSGT`

* add cr0-7 registers

* fix formatting

* fix conditional branch test

* add test for compare

* re-enable rotate left word immediate and mask test

* genericize TestSpecOutput

* explicit instruction data size

* add test for syscall/callother (disabled)

* add tests for store/load word

* add test to convert from float to int

* specify intrinsic arg type, fixes null deref

* Add PPC emulate instruction to hyper call

* add headers + formatting

* remove old comment

* Map CRALL register

* Add basic LLVM data layout that specifies 32-bit addresses

* Remove unused variables

* convert auto* to auto when possible

* RegisterPrecondition -> RegisterCondition

* fix variable name

* convert any to variant

* use std::move

* bump to c++20, use concepts

* set arch in constructor since class isn't generic anyways

* formatting

* make type aliases

* bump cxx-common

* add comment

* clang format

* throw exception if register not found

* use const ref

* use shorthand for lambda capture values

* Add more detail to data layout to include proper stack alignment

* Compare to the correct size for SUBPIECE impl

* Add Sleigh message to error

* throw exception in else case

* throw runtime error if register value has incorrect type

* use reference instead of value

* get rid of unnecessary type alias

* formatting

* Propagate VLE context reg value into Sleigh

* Remove unnecessary whitespace

* Remove stale TODO and NOTE comments

* add additional parameter to test runner to specify decoding context

* drop llvm 14, bump macos version

* bump cxx-common, fix ci.yml mac build

* add test for unconditional relative negative branch

* add missing space to pcode debug log

* fix bug due to unordered_map, iteration order matters

* add error log in case we aren't able to adjust PC value

* use helper for getting register reference

* Revert "add optional param"

This reverts commit 51ed49f8cf.

* Remove remaining LLVM 14 compatibility code and configuration

* Add padding between CR and XER flags

* Use `enum class`

* Remove void cast

* Remove unnecessary variable

* Use initialiser lists where appropriate

* Remove redundant `else`

* Prefer `CHECK` over `assert`

* Polish PowerPC function initialisation with lambda

* zero out xer_so to fix tests

* log error when we see claim_eq with no usages

* Collapse namespace blocks

* Remove unnecessary `this->`

* Use `auto` where appropriate

* Remove unnecessary `else`

* Use `emplace` over `insert` for `std::map`

Co-authored-by: lkorenc <lukas.korencik@trailofbits.com>

* Use `constexpr` for VLE reg name

* Use module verification util

* Add `VerifyFunction` util and use where applicable

* Extract lambda to improve readability of flow categorisation

* Use type alias for context values

* Introduce type alias for block exit

* Create type alias for optional branch taken

* Refactor `PcodeCFGBuilder`

* Use lambda to avoid conditional mutation

* Extract duplicated bit-shift code generation into helper

* Simplify flow with ternary

* Add `GetBlock` helper

* Rename variables

* Move statement for clarity

* Create helpers for working with Sleigh context register values

* Convert loop to `std::copy`

* Add a comment explaining the use of set to de-duplicate and sort

* Refactor `IntraProcTransferCollector`

* Expose static method to easily use `IntraProcTransferCollector`

* Rename PPC related variables to include address width

* add docs to intrainstructionindex

* remove llvm 14 ifdefs

* don't log error if no claim_eqs were used

* update comments

* Cleanup exit visitors

---------

Co-authored-by: 2over12 <ian.smith@trailofbits.com>
Co-authored-by: William Tan <1284324+Ninja3047@users.noreply.github.com>
Co-authored-by: lkorenc <lukas.korencik@trailofbits.com>
2023-02-02 10:05:28 -05:00
Alex Cameron d5c5035728 Get Remill building with LLVM 15 (#631)
* Get Remill building with LLVM 15

* Add missing header for x86 lift test

* Fix `enableOpaquePointers` calls

* Define a non-extern `__remill_state` in each Instructions module

* Remove `__remill_state` variables in tests

* Update build script to support LLVM 15

* Build with LLVM 15 in CI

* Bump CXX Common version

* Update Docker script

* Add comment explaining the definition of the state variable

* Correct wording
2022-10-30 16:42:23 -04:00
William Tan 1cb4bb6001 remove thirdparty interfaces + remove llvm jank 2022-08-29 13:11:12 -04:00
2over12 854c73e06a Ian/instruction carry lifter (#615)
* add lifter field

* arch has intrinsics

* use insn lifter in trace lifter

* limit default lifters to ops only

* init lifters

* pass arch in tests

* fix bug in swap

* stop using archbase decode in sleigh arches
2022-08-12 11:57:45 -04:00
2over12 eef338df00 Ian/sleigh support rebased (#607)
* cmake: Bring in SLEIGH as a dependency

* sleigh: Boilerplate for adding a new arch

* sleigh: Begin passing instruction sequences into SLEIGH

* cmake: Rename target to be X86 specific

* sleigh: Copy over more X86 runtime code and get things running

* sleigh: Begin populating operands in the returned instruction

* sleigh: Set instruction category for a few opcodes

* sleigh: Initial attempt at generating LLVM IR for P-Code

* sleigh: Implement enough opcodes to run the `sleigh-lift` example

* sleigh: Get things building with an up-to-date Remill tree

* sleigh: Use the new SLA helpers

* sleigh: Clear operands between invalid lifts

* added thumb2

* stub out thumb

* need to refactor to relift the instruction

* factored lifter out of handler:

* allow lifters to decide wether to use sleigh

* relift bytes

* fixed both lifter contexts

* hey a copy lifted :)

* need to refactor to use parameterptrs to unify interface to memory

* refactored to use parameter abstraction

* lift at correct location

* add control flow to pc and next

* add categories mostly

* fix direct semantics add cbranch

* track cbranch metavar also lift returns

* cmake: Fix SleighArch.h path

* sleigh: Support more binary ops

* sleigh: Implement ZEXT

* sleigh: Support SEXT op

* sleigh: Implement 2COMP and INT_NEGATE

* mutex around parsing sleigh specs

* fixed typos in custom image

* added handling for exceptions, need to fix issue with xml parsing

* sleigh: Support boolean binops

* sleigh: Support float binary ops

* sleigh: Support a few more float pcode ops that require LLVM intrinsics

* sleigh: Add entries for ops that require overflow intrinsics

* sleigh: Implement more float unary ops

* sleigh: Reduce duplication in ops that require float intrinsics

* expose mutex

* fix fallthough and format of control flow resolution

* sleigh: Support CARRY, SCARRY and SBORROW

* Remove duplicate THUMB2 arch in enum

* Remove duplicate THUMB2 entry in archnames array

* Implement STORE op

* Fix incorrect index

* Support PIECE and SUBPIECE ops

* Support remaining set of PCode ops in the base set. Now to do the
pseudo ops.

* Implement additional ops

* Partially implement a few pseudo ops + a few missing from the docs

* Fix the variadic op condition

* Include <mutex> to build on Linux

* stop lying about insn categories/functions

* set function insns with mnemonic

* fix fallthrough for ind calls

* More virtualization, fewer pimples

* switch back to x86 normal

* Fix off-by-eight issue with ADR in AArch32

* Get rid of mutex in sleigh, make a globally-available remill locker for handling sleigh issues

* CHange allow 32 bit shift to true, not sure if valid but oh well

* Use the node size when creating constants

* fix memory

* store memory state back

* fix calling intrinsic table

* fix comp sizes

* load pspec data

* add pspec names

* add differential test

* fix tests start pretty printer

* add runner

* added really slow memory

* add comparison of memory state

* do reset

* fix uninitialized module

* fixed lift crash

* add amd64 runtime

* unfix fs, gs, and pc

* added whitelist file

* fix memory to update state with uninitialized reads

* better pc handling

* add main.py

* x86 compiles

* fixup patch generation

* add replacements for mem locs and constant varnodes, now need to handle special branches

* added replacement for direct branches

* add context clears

* add handler for claim_eq

* comment out clears for now

* added ambiguity check

* handle duplicate names in same constructor

* mantain sleigh invariant of 1 or 0 in flag

* added uint8t memory intrinsics

* extend shift value when needed

* handle cmovs

* update patch generation

* removed deprecated load

* fix for returned type

* builds

* add logging

* add comment on why not compute GEPAccessors in Arch.cpp

* enable opaque pointers

* fix memory state update

* add mem_16 impls

* not preserve 1 bit width

* fix CR changes

* fix L and R for shift operands bigger than target

* revert use after move

* more CR fixes

* remove lookahead... lets try this again

* rework to create internal function that is inlined to allow for early return control flow

* terminate conditionally

* avoid large iteration counts for .REP insns

* fix patch for rep insns

* handle inst_start in patches

* handle inserting insn_size constructor outside of macros

* hint size of insn_size

* refactor bool functions to make more sense

* just use ;

* remove delete of operands when fail to lift

* remove copy and paste

* remove unused deps

* add patch file to sleigh list

* prep git user

* refer to checkout

* maybe shell type?

* fix layout

* fix format again

* fix

* update dockerfile

* fix gitwatcher to point to current project:

* Revert "fix gitwatcher to point to current project:"

This reverts commit 711da11e6f.

* fix ninja builds

* disable sleigh tests

* remove duplicates

* refactor

* fix non reset context in sleigh lifter

* remove debugging prints

* wrote CI runner

* add handwritten test infra

* refactor to allow sharing JIT test running between differential tester and hand written tests

* allow for internal ownership of semantics module

* handwritten test framework

* fix hand written tests

* pc rel testruns

* add pc rel regression

* fix script for pc rel

* fix names for priors to ignore whitespace

* fix action ops

* add xor to repl ops

* add xors to patch

* add arm patch to build

* fix test for semantics

* allow cross platform tests to run

* add running diff tester

* 2 underscores?

* run tests on macos too

* fix command

* fix whitelist path

* remove unused test data

* install python deps for differential tests

* update script to git patches

* update patches to git format

* attempt to fixup patches

* update ref for sleigh

* install test depends docker

* point docker to correct dir

* install pydeps in macos too

* initialize address field

* exports, also tag master on sleigh

* add comments and whitelist undefined value OF in shifts

* add of accessor to whitelist impl

* change variables to non alloca and remove dead code

* remove dead code:

* replace dump with print

* code quality

* make non null into ref

* type alias

* remove allocas from unit tests

* Address copypasta comment.

* Address PR comment.

* Address PR comment.

* fix build

* unify diff modules into single structure

* remove extra newline

* lock sleigh to specific commit

* remove new lines

* remove useless fenv headers

* caps

* copyright notices

* update more copyright

* fix reviews

* early returns out of accessors

* early return

* auto

* return getarchbyname

* insert register rather than modify reference

* just return

* only log in the assembly logger

* prefer functional style

* remove commented code

* move defaults to header

* that's not how arch switches work in pcode

* informative names

* simplify control flow in fill

* early return

* fix early exit condition

* refactor register default into function

* make one liner

* early return

* unary instead of unop

* construct pair with {}

* move cbranch into binops instead of integer binops

* refactor float ops into getter

* factor out float type

* early return

* separate out callother handling

* do pointer extensions cleaner

* braces

* add private headers to lifters

* refactor redirecting control flow out of instruction

* use constant check function

* remove has_value

* structure for preconditions

* return success when applying eq claim

* expose arch base and move shared functionality into x86 base

* dedup x86 code

* dedup aarch32

* remove needless assignment, also remove else after an if that returns

Co-authored-by: Alex Cameron <asc@tetsuo.sh>
Co-authored-by: Artem Dinaburg <artem@trailofbits.com>
Co-authored-by: Peter Goodman <peter.goodman@gmail.com>
2022-07-28 08:46:32 -04:00
Alex Cameron 752ddf3ec0 Enable opaque pointers in each spot where we make an LLVM context 2022-06-24 14:01:40 +10:00
Alex Cameron fd82a20a20 WIP to support opaque pointers 2022-05-31 12:40:11 +10:00
Lukas Korencik df7e433600 bin:lift: Reflect change in IntrinsicTable ctors. 2022-04-14 19:49:38 +02:00
Lukas Korencik 3c06d00d69 bin:lift: Reflect changes in remill API. 2022-04-11 18:42:42 +02:00
Peter Goodman d5928a0faa llvm 13 support (#577)
* llvm 13 support

* Add llvm 13

* Update build script

* Update build script

* Modify remill-lift docker entrypoint
2022-02-16 19:13:17 -05:00
Peter Goodman 28e48fec22 Removes some deprecated functions, and removes the basic block functi… (#569)
* Removes some deprecated functions, and removes the basic block function cloning apis, in favor of apis on Arch

* More tweaks for removing unnecessary APIs

* Goodbye dse

* Fix issue

* Tweaks

* Remove some annoying logs
2021-12-17 14:20:13 -05:00
Peter Goodman f5c630a1d3 Fix some cmake issues that I caused, and add some options (#547)
* Fix some cmake issues that I caused, and add some options

* Rename some cmake variables. Use them more.
2021-10-06 01:10:03 -04:00
Peter Goodman 3808e9951d Refactor and add sparc (#454)
* Refactors the code to improve directory layout, use more std::string_view in place of std::string, deletes some deprecated functions, deprecates some other functions for eventual deletion, and includes semantics for sparcv8 (sparc32) and sparcv9 (sparc64)

* Update new dir layout with llvm 11 support

* Whoops missing files

* Drop llvm 800 from workflow

* Minor fix

* Move where the install directives are in CMake

* Minor fixes

* Rename tools/ to bin/.

* Minor tweaks

* Should fix issues
2020-10-28 15:11:42 -04:00