From 410da1176d13bd8e58cf92787bd36428550590f4 Mon Sep 17 00:00:00 2001 From: Henny Sipma Date: Thu, 1 Oct 2026 21:35:50 -0700 Subject: [PATCH 1/3] CHB:CMD: add option to save asm instructions --- CodeHawk/CHB/bchcmdline/bCHXBinaryAnalyzer.ml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/CodeHawk/CHB/bchcmdline/bCHXBinaryAnalyzer.ml b/CodeHawk/CHB/bchcmdline/bCHXBinaryAnalyzer.ml index b5b7209d..b6d7f1aa 100644 --- a/CodeHawk/CHB/bchcmdline/bCHXBinaryAnalyzer.ml +++ b/CodeHawk/CHB/bchcmdline/bCHXBinaryAnalyzer.ml @@ -117,6 +117,7 @@ let add_print_datasection (s: string) = let save_asm_cfg_info = ref false (* save functions list with cfg info in xml *) let save_asm_callgraph = ref false (* save callgraph edges based on disassembly *) +let save_asm_instructions = ref false (* save list of assembly instructions in xml *) let set_datablocks = ref false (* only supported for arm *) let construct_all_functions = ref false @@ -229,6 +230,8 @@ let speclist = "save list of functions with cfg info to xml file (may be slow)"); ("-save_asm_callgraph", Arg.Unit (fun () -> save_asm_callgraph := true), "save list of callgraph edges based on disassembly only in xml"); + ("-save_asm_instructions", Arg.Unit (fun () -> save_asm_instructions := true), + "save list of assembly instructions in functions in xml"); ("-print_datasection", Arg.String (fun s -> add_print_datasection s), "print the data sections as part of the assembly listing"); ("-construct_all_functions", @@ -630,6 +633,11 @@ let main () = end); save_system_info (); pr_timing [STR "system_info saved"]; + (if !save_asm_instructions then + begin + save_arm_assembly_instructions (); + pr_timing [STR "arm-assembly-instructions saved"] + end); save_arm_dictionary (); pr_timing [STR "dictionary saved"]; save_global_memory_map (); From 854493483645629726fa943f5b2a9437d12797de Mon Sep 17 00:00:00 2001 From: Henny Sipma Date: Thu, 1 Oct 2026 21:36:20 -0700 Subject: [PATCH 2/3] CHB:ARM: add support for SXTAB instruction --- CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml | 3 ++- .../CHB/bchlibarm32/bCHARMOpcodeRecords.ml | 10 +++++++- CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli | 7 +++++- .../bCHDisassembleARMInstruction.ml | 9 ++++++++ .../CHB/bchlibarm32/bCHFnARMDictionary.ml | 23 +++++++++++++++++++ .../CHB/bchlibarm32/bCHTranslateARMToCHIF.ml | 19 +++++++++++++++ .../bCHDisassembleARMInstructionTest.ml | 4 +++- 7 files changed, 71 insertions(+), 4 deletions(-) diff --git a/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml b/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml index 092a92ed..6b796556 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml @@ -4,7 +4,7 @@ ------------------------------------------------------------------------------ The MIT License (MIT) - Copyright (c) 2021-2024 Aarno Labs, LLC + Copyright (c) 2021-2026 Aarno Labs, LLC Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal @@ -311,6 +311,7 @@ object (self) (ctags c, [di dt; oi vd; oi vn; oi vm]) | SignedBitFieldExtract (c, rd, rn) -> (ctags c, [oi rd; oi rn]) | SignedDivide (c, rd, rn, rm) -> (ctags c, [oi rd; oi rn; oi rm]) + | SignedExtendAddByte (c, rd, rn, rm) -> (ctags c, [oi rd; oi rn; oi rm]) | SignedExtendByte (c, rd, rm, tw) -> (ctags c, [oi rd; oi rm; setb tw]) | SignedExtendHalfword (c, rd, rm, tw) -> (ctags c, [oi rd; oi rm; setb tw]) diff --git a/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml b/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml index 401c7e43..c4ac8a8e 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml @@ -4,7 +4,7 @@ ------------------------------------------------------------------------------ The MIT License (MIT) - Copyright (c) 2021-2025 Aarno Labs, LLC + Copyright (c) 2021-2026 Aarno Labs, LLC Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal @@ -824,6 +824,14 @@ let get_record (opc:arm_opcode_t): 'a opcode_record_t = ccode = Some c; ida_asm = (fun f -> f#opscc "SBFX" c [rd; rn]) } + | SignedExtendAddByte (c, rd, rn, rm) -> { + mnemonic = "SXTAB"; + operands = [rd; rn; rm]; + flags_set = []; + flags_used = []; + ccode = Some c; + ida_asm = (fun f -> f#opscc "SXTAB" c [rd; rn; rm]) + } | SignedExtendByte (c, rd, rm, tw) -> { mnemonic = "SXTB"; operands = [rd; rm]; diff --git a/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli b/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli index 46bd0a27..0073d8d0 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli +++ b/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli @@ -4,7 +4,7 @@ ------------------------------------------------------------------------------ The MIT License (MIT) - Copyright (c) 2021-2025 Aarno Labs, LLC + Copyright (c) 2021-2026 Aarno Labs, LLC Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal @@ -735,6 +735,11 @@ type arm_opcode_t = * arm_operand_int (* rd: destination *) * arm_operand_int (* rm: dividend *) * arm_operand_int (* rn: divisor *) + | SignedExtendAddByte of + arm_opcode_cc_t (* condition *) + * arm_operand_int (* rd: destination *) + * arm_operand_int (* rn: first operand *) + * arm_operand_int (* rm: second operand *) | SignedExtendByte of arm_opcode_cc_t (* condition *) * arm_operand_int (* rd: destination *) diff --git a/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml b/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml index 7f6dc583..ab5f198e 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml @@ -1342,6 +1342,15 @@ let parse_media_type (instrbytes: doubleword_int) (cond: int) = (* SXTB , {, } *) SignedExtendByte (c, rd, rm, false) + (* <3>< 10>ro000111 *) (* SXTAB - A1 *) + | 10 when (b 9 5) = 3 && (b 9 8) = 0 -> + let rd = arm_register_op (get_arm_reg ry) WR in + let rn = arm_register_op (get_arm_reg rx) RD in + let rotation = (b 11 10) lsl 3 in + let rm = mk_arm_rotated_register_op (get_arm_reg rz) rotation RD in + (* SXTAB , , {, } *) + SignedExtendAddByte (c, rd, rn, rm) + (* <3>< 11><15><15>0011 *) (* REV - A1 *) | 11 when (rx = 15) && (b 11 8) = 15 && (b 7 5) = 1 -> let rd = arm_register_op (get_arm_reg ry) WR in diff --git a/CodeHawk/CHB/bchlibarm32/bCHFnARMDictionary.ml b/CodeHawk/CHB/bchlibarm32/bCHFnARMDictionary.ml index d061d342..a1c6abec 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHFnARMDictionary.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHFnARMDictionary.ml @@ -3434,6 +3434,29 @@ object (self) let (tags, args) = add_optional_instr_condition tagstring args c in (tags, args) + | SignedExtendAddByte (c, rd, rn, rm) -> + let vrd_r = rd#to_variable floc in + let xrn_r = rn#to_expr floc in + let xxrn_r = TR.tmap rewrite_expr xrn_r in + let xrm_r = rm#to_expr floc in + let xxrm_r = TR.tmap rewrite_expr xrm_r in + let rdefs = + (get_rdef_r xrn_r) + :: (get_rdef_r xrm_r) + :: ((get_all_rdefs_r xxrn_r) @ (get_all_rdefs_r xxrm_r)) in + let uses = [get_def_use_r vrd_r] in + let useshigh = [get_def_use_high_r vrd_r] in + let (tagstring, args) = + mk_instrx_data_r + ~vars_r:[vrd_r] + ~xprs_r:[xrn_r; xrm_r; xxrn_r; xxrm_r] + ~rdefs + ~uses + ~useshigh + () in + let (tags, args) = add_optional_instr_condition tagstring args c in + (tags, args) + | SignedExtendByte (c, rd, rm, _) -> let vrd_r = rd#to_variable floc in let xrm_r = rm#to_expr floc in diff --git a/CodeHawk/CHB/bchlibarm32/bCHTranslateARMToCHIF.ml b/CodeHawk/CHB/bchlibarm32/bCHTranslateARMToCHIF.ml index 62f83000..62139892 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHTranslateARMToCHIF.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHTranslateARMToCHIF.ml @@ -2808,6 +2808,25 @@ let translate_arm_instruction | ACCAlways -> default cmds | _ -> make_conditional_commands c cmds) + | SignedExtendAddByte (c, rd, rn, rm) -> + let vrd = floc#env#mk_register_variable rd#to_register in + let lhs_r = TR.tmap fst (rd#to_lhs floc) in + let xrn_r = rn#to_expr floc in + let xrm_r = rm#to_expr floc in + let cmds = floc#get_abstract_commands_r lhs_r in + let usevars = get_register_vars [rn; rm] in + let usehigh = get_use_high_vars_r [xrn_r; xrm_r] in + let defcmds = + floc#get_vardef_commands + ~defs:[vrd] + ~use:usevars + ~usehigh + ctxtiaddr in + let cmds = defcmds @ cmds in + (match c with + | ACCAlways -> default cmds + | _ -> make_conditional_commands c cmds) + | SignedExtendByte (c, rd, rm, _) -> let vrd = floc#env#mk_register_variable rd#to_register in let lhs_r = TR.tmap fst (rd#to_lhs floc) in diff --git a/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml b/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml index 7395fc64..53e97142 100644 --- a/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml +++ b/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml @@ -5,7 +5,7 @@ ------------------------------------------------------------------------------ The MIT License (MIT) - Copyright (c) 2022-2024 Aarno Labs LLC + Copyright (c) 2022-2026 Aarno Labs LLC Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal @@ -141,6 +141,8 @@ let arm_basic () = ("STRH", "b007cde1", "STRH R0, [SP,#0x70]"); ("SUB", "45df4de2", "SUB SP, SP, #0x114"); ("SUBS", "062052e0", "SUBS R2, R2, R6"); + ("SXTAB", "7330a2e6", "SXTAB R3, R2, R3"); + ("SXTB", "7430afe6", "SXTB R3, R4"); ("TST", "020c12e3", "TST R2, #0x200"); ("UBFX", "50ede2e7", "UBFX LR, R0, #26, #3"); ("UDF", "fedeffe7", "UDF #0xfdee"); From f5d5d75daf903a5706c0c07fe65894d13c0f1794 Mon Sep 17 00:00:00 2001 From: Henny Sipma Date: Thu, 1 Oct 2026 23:15:16 -0700 Subject: [PATCH 3/3] CHB:ARM: add support for VFMA/VFMS instructions --- CodeHawk/CHB/bchlib/bCHVersion.ml | 4 +- CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml | 2 + .../CHB/bchlibarm32/bCHARMOpcodeRecords.ml | 8 ++++ CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli | 6 +++ .../bCHDisassembleARMInstruction.ml | 48 +++++++++++++++++++ .../bCHDisassembleARMInstructionTest.ml | 2 + 6 files changed, 68 insertions(+), 2 deletions(-) diff --git a/CodeHawk/CHB/bchlib/bCHVersion.ml b/CodeHawk/CHB/bchlib/bCHVersion.ml index 59556f6e..f0fe0c57 100644 --- a/CodeHawk/CHB/bchlib/bCHVersion.ml +++ b/CodeHawk/CHB/bchlib/bCHVersion.ml @@ -95,8 +95,8 @@ end let version = new version_info_t - ~version:"0.6.0_20260930" - ~date:"2026-09-30" + ~version:"0.6.0_20261001" + ~date:"2026-10-01" ~licensee: None ~maxfilesize: None () diff --git a/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml b/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml index 6b796556..af3d2a7a 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHARMDictionary.ml @@ -429,6 +429,8 @@ object (self) (ctags c, [di dt; oi dst; oi src1; oi src2; oi imm]) | VectorFusedMultiplyAccumulate (c, dt, dst, src1, src2) -> (ctags c, [di dt; oi dst; oi src1; oi src2]) + | VectorFusedMultiplySubtract (c, dt, dst, src1, src2) -> + (ctags c, [di dt; oi dst; oi src1; oi src2]) | VectorLoadMultipleIncrementAfter (wb, c, rn, rl, mem) -> (ctags c, [setb wb; oi rn; oi rl; oi mem]) | VectorLoadFour (wb, c, sz, rl, rn, mem, rm) -> diff --git a/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml b/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml index c4ac8a8e..fb3a5211 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHARMOpcodeRecords.ml @@ -1383,6 +1383,14 @@ let get_record (opc:arm_opcode_t): 'a opcode_record_t = ccode = Some c; ida_asm = (fun f -> f#opscc ~dt "VFMA" c [dst; src1; src2]) } + | VectorFusedMultiplySubtract (c, dt, dst, src1, src2) -> { + mnemonic = "VFMS"; + operands = [dst; src1; src2]; + flags_set = []; + flags_used = []; + ccode = Some c; + ida_asm = (fun f -> f#opscc ~dt "VFMS" c [dst; src1; src2]) + } | VectorLoadFour (_wb, c, dt, rl, rn, mem, rm) -> { mnemonic = "VLD4"; operands = [rl; rn; mem; rm]; diff --git a/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli b/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli index 0073d8d0..582e4447 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli +++ b/CodeHawk/CHB/bchlibarm32/bCHARMTypes.mli @@ -1119,6 +1119,12 @@ type arm_opcode_t = * arm_operand_int (* destination *) * arm_operand_int (* source 1 *) * arm_operand_int (* source 2 *) + | VectorFusedMultiplySubtract of + arm_opcode_cc_t (* condition *) + * vfp_datatype_t (* data type *) + * arm_operand_int (* destination *) + * arm_operand_int (* source 1 *) + * arm_operand_int (* source 2 *) | VectorLoadMultipleIncrementAfter of bool (* writeback *) * arm_opcode_cc_t (* condition *) diff --git a/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml b/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml index ab5f198e..a5fe5bea 100644 --- a/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml +++ b/CodeHawk/CHB/bchlibarm32/bCHDisassembleARMInstruction.ml @@ -2343,6 +2343,30 @@ let parse_misc_7_type (* VDUP.
, *) VectorDuplicate (c, VfpSize esize, 1, elements, d WR, rt RD) + (* <7>01D10101sN0M0 *) (* VFMA - A2 *) + | (1, 2, 0, 0) when (b 11 9) = 5 -> + let sz = bv 8 in + let dp = sz = 1 in + let dbit = bv 22 in + let nbit = bv 7 in + let mbit = bv 5 in + let vn = b 19 16 in + let vd = b 15 12 in + let vm = b 3 0 in + let (dreg, nreg, mreg) = + if dp then + (prefix_bit dbit vd, prefix_bit nbit vn, prefix_bit mbit vm) + else + (postfix_bit dbit vd, postfix_bit nbit vn, postfix_bit mbit vm) in + let (dt, xtype) = + if dp then (VfpFloat 64, XDouble) else (VfpFloat 32, XSingle) in + let vd = arm_extension_register_op xtype dreg in + let vn = arm_extension_register_op xtype nreg in + let vm = arm_extension_register_op xtype mreg in + (* VFMA.F64
, , *) + (* VFMA.F32 , , *) + VectorFusedMultiplyAccumulate (c, dt, vd WR, vn RD, vm RD) + (* <14><14>< 1><10>< 1>< 0> *) (* VMSR - A1 *) | (1, 2, 0, 1) when (bv 22) = 1 @@ -2355,6 +2379,30 @@ let parse_misc_7_type (* VMSR FPSCR, *) VMoveToSystemRegister (c, dst WR, rt RD) + (* <7>01D10101sN1M0 *) (* VFMS - A2 *) + | (1, 2, 1, 0) when (b 11 9) = 5 -> + let sz = bv 8 in + let dp = sz = 1 in + let dbit = bv 22 in + let nbit = bv 7 in + let mbit = bv 5 in + let vn = b 19 16 in + let vd = b 15 12 in + let vm = b 3 0 in + let (dreg, nreg, mreg) = + if dp then + (prefix_bit dbit vd, prefix_bit nbit vn, prefix_bit mbit vm) + else + (postfix_bit dbit vd, postfix_bit nbit vn, postfix_bit mbit vm) in + let (dt, xtype) = + if dp then (VfpFloat 64, XDouble) else (VfpFloat 32, XSingle) in + let vd = arm_extension_register_op xtype dreg in + let vn = arm_extension_register_op xtype nreg in + let vm = arm_extension_register_op xtype mreg in + (* VFMS.F64
, , *) + (* VFMS.F32 , , *) + VectorFusedMultiplySubtract (c, dt, vd WR, vn RD, vm RD) + (* <14>1D11<4H>101s< 0><4L> *) (* VMOV (immediate) - A2 *) | (1, 3, 0, 0) when (b 11 9) = 5 && (b 7 4) = 0 -> let d = bv 22 in diff --git a/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml b/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml index 53e97142..f7ef3cc3 100644 --- a/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml +++ b/CodeHawk/CHT/CHB_tests/bchlibarm32_tests/txbchlibarm32/bCHDisassembleARMInstructionTest.ml @@ -210,6 +210,8 @@ let arm_vector () = ("VDUP.32-scalar", "622cfcf3", "VDUP.32 Q9, D18[1]"); ("VEOR-Q", "746106f3", "VEOR Q3, Q3, Q10"); ("VEXT", "462cf0f2", "VEXT.8 Q9, Q0, Q3, #0xc"); + ("VFMA.F64", "007ba8ee", "VFMA.F64 D7, D8, D0"); + ("VFMS.F64", "e20be1ee", "VFMS.F64 D16, D17, D18"); ("VLD1.8", "0d0760f4", "VLD1.8 {D16}, [R0]!"); ("VLD1.32", "8f2a23f4", "VLD1.32 {D2,D3}, [R3]"); ("VMOV.I8", "584ec0f2", "VMOV.I8 Q10, #8");