Skip to content

AArch64 lifting issues #8618

Description

@xusheng6

Binary files and instruction addresses (ZIP available for upload separately):

  • kat-aarch64.o: 0x400358, 0x401db0; SHA-256 16de40ff0f7ee4c526831624f1af4aea30b044ebf59fc799494d35d026f718a1

1: AArch64 register shifts

Binary instruction: kat-aarch64.o / md5 at 0x400358; bytes 6d25ca1a.

Disassembly: lsr w13, w11, w10.

Current lifted LLIL (relevant lines):

w13 = w11 u>> w10

Expected LLIL (semantic sketch):

w13 = w11 u>> (w10 & 0x1f)

Out-of-range counts can occur in rotate idioms even though the ISA ignores their upper bits.

Code: arch/arm64/il.cpp:2743

2: AArch64 fmov d0, x9

Binary instruction: kat-aarch64.o / bitcount_probe at 0x401db0; bytes 2001679e.

Disassembly: fmov d0, x9.

Current lifted LLIL (relevant lines):

d0 = float.d(x9)

Expected LLIL (semantic sketch):

d0 = x9  // copy the 64 raw bits

fmov transfers the 64 raw bits without numeric conversion. A direct LLIL register assignment expresses that transfer; no bitcast is needed. Here float.d(x9) is an LLIL_INT_TO_FLOAT expression; the emulator does not implement that operation and stops as unimplemented before writing d0. If it performed the numeric conversion indicated by this LLIL, the result would also have the wrong bits.

Code: arch/arm64/il.cpp:2162

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions