* arch/tms320: add TMS320C54x disassembly support Add a C54x instruction decoder that reuses the shared C55x decode engine (c55_decode/c55_format) via the C55ArchDesc plug-in interface, rather than duplicating the matcher/formatter. Disassembly only for now (.lift = NULL). Engine changes (c55_ir.c/.h): - add C55ArchDesc.words_le so the decoder can byte-swap the little-endian 16-bit instruction words used by the C54x COFF object format; - add a self-contained C54x memory-operand renderer (direct @dma, MMR, indirect *ARx with all post-modify modes, *ARx(lk) const-index, *(lk) ABS16 absolute and circular '%' addressing) and bare-hex immediates; - add C55Operand.circular for the '%' suffix and C55Operand.space_join for the space-separated second half of a C54x parallel instruction; - extend the data-memory operand-field analysis (register, base pointer, displacement, direction, referenced size) to the LOAD/STORE op types the C54x ld/st family uses, in addition to the C55x MOV form. The C54x decoder (isa/tms320/c54x/c54x.c) covers the complete documented instruction set - all 117 mnemonics of the SPRU172 opcode map, in every documented encoding form: - load/store/move, integer and logical ALU ops in every addressing form (Smem, #lk, dual-accumulator, Xmem/Ymem, TS/ASM/SHIFT-shifted, the shift-by-16 and #lk,16 long-immediate forms, and the two-word Smem,SHIFT form whose operation selector lives in the second word); - the full multiply/MAC family: Smem, #lk, program-memory, squaring, multiply-by-A, signed-unsigned and the dual-operand MAC[R]/MAS[R] Xmem,Ymem forms; - the parallel (dual-operation) class rendered "op1 .. || op2 .." - ST||ADD/SUB/LD/MPY/MAC[R]/MAS[R], ST||LD T and LD||MAC[R]/MAS[R]; - double/long-word (Lmem) add/subtract, the unary accumulator ops (exp/norm/abs/neg/rnd/sat/min/max/rol/ror/sftc/cmpl/...); - control flow with the separate delayed (bd/calld/bcd/banzd/fcalad/...) variants, conditional return/execute (rc[d]/xc) and the multi-condition "tc, c"-style combinable condition fields, repeats (incl. rpt #lk), conditional stores, I/O port access, status-bit set/clear and the non-linear idle encoding. Operands resolve to their architectural names - the full memory-mapped register file (AR0-AR7, the accumulator AL/AH/AG/BL/BH/BG halves, T, TRN, SP, BK, BRC/RSA/REA, IMR/IFR, PMST, XPC), the ST0/ST1 status bits and the named condition codes; the memory-mapped-register operand is kept single word (its long-offset modes are not legal). The analyzer classifies every instruction (op->type, op->id), resolves branch/call targets and the stack effect of calls/returns/pushes, and exposes operand details: the register, base pointer, displacement and access direction of data-memory loads and stores, and the target register of indirect branches/calls. All encodings were verified byte-exact against the TI asm500 assembler, and every decoded instruction re-assembles to an identical encoding (a full-opcode-space disassemble/reassemble round-trip is stable). A 297-case disasm test suite and an analysis test suite (opcode classification, branch and call targets, stack effects, memory-operand fields, data-immediate values, the register profile, named instruction ids and COFF binary-fixture function discovery) are added, and the real-world emulateme C54x .text decodes cleanly. * arch/tms320: add TMS320C54x RzIL lifting Lift the C54x integer core to RzIL so emulation and IL-based analysis work for C54x as they already do for C55x/C55x+. - Register profile: C54x previously fell through to the C64x profile (a0-a31, =PC pce1), wrong for the A/B accumulator core. Add a proper C54x profile: the two 40-bit accumulators A/B (with the L/H 16-bit and G 8-bit guard slices overlapping their parent), AR0-AR7, T/TRN, SP, DP, BK, ST0/ST1/PMST, BRC/RSA/REA, IMR/IFR, XPC and a 24-bit PC. - IL VM config: tms320_c54x_il_config() binds the canonical registers; the accumulator slices stay unbound, the lifter expresses them as bit-slices of A/B so they never desynchronise. - Lifter (C55ArchDesc::lift hook, dispatched by c55_lift): the no-shift forms of LD/LDU/LDR/LDM, ADD/SUB/AND/OR/XOR, STL/STH/STLM/STM, the mvd* memory-to-memory moves, the DLD/DST 32-bit double-word load/store (high word at the lower address), PSHM/POPM and RET. Shift/round/saturate variants are left unlifted (their shift count is carried only as a display string); the engine's generic EA/read/write/post-modify helpers are reused for the addressing modes. Tested via two new RzIL VM blocks in test/db/rzil/tms320: a register/ immediate/memory execute test, and an end-to-end emulation of the emulateme binary's _decrypt (a UART hex-writer) showing the IL VM emits the hex digits and advances the write position. --------- Co-authored-by: Anton Kochkov <anton.kochkov@gmail.com> |
||
|---|---|---|
| .builds | ||
| .github | ||
| .woodpecker | ||
| binrz | ||
| dist | ||
| doc | ||
| examples | ||
| librz | ||
| LICENSES | ||
| patches | ||
| subprojects | ||
| sys | ||
| test | ||
| .appveyor.yml | ||
| .clang-format | ||
| .dockerignore | ||
| .git-blame-ignore-revs | ||
| .gitattributes | ||
| .gitignore | ||
| .lgtm.yml | ||
| .prettierignore | ||
| .pylintrc | ||
| .travis.yml | ||
| AGENTS.md | ||
| BUILDING.md | ||
| CODE_OF_CONDUCT.md | ||
| codecov.yml | ||
| CODEOWNERS | ||
| CONTRIBUTING.md | ||
| COPYING | ||
| COPYING.LESSER | ||
| DEVELOPERS.md | ||
| Dockerfile | ||
| Doxyfile | ||
| meson.build | ||
| meson_options.txt | ||
| README.md | ||
| REUSE.toml | ||
| SECURITY.md | ||
| snapcraft.yaml | ||
| travis-extract-var.sh | ||
| travis-script | ||
Rizin
Rizin is a reverse engineering framework, born as a fork of the radare2, with a focus on usability, features and cleanliness.
Rizin is portable and it can be used to analyze binaries, disassemble code, debug programs, as a forensic tool, as a scriptable command-line hexadecimal editor able to open disk files, and much more!
To learn more on Rizin you may want to read the official Rizin book.
How to install
Look at install instructions on our web page.
How to build
Use meson to compile and install Rizin. Please make sure to get an updated
meson (e.g. get it with pip install meson if your system does not provide
one that is at least version 0.55.0).
Clone this repository:
$ git clone https://github.com/rizinorg/rizin
Then compile and install with:
$ meson setup build
$ meson compile -C build
$ sudo meson install -C build
Now you can use rizin:
$ rizin
-- Thank you for using rizin. Have a nice night!
[0x00000000]>
To uninstall rizin, execute sudo ninja -C build uninstall.
Please have a look at BUILDING.md for more information about building Rizin.
Contributing
We very much welcome any kind of contributions, from typos, to documentation, to refactoring, up to completely new features you may think of. Before contributing, we would like you to read the file CONTRIBUTING.md, so that we can all be on the same page.
Tests
Look at test/README.md.
Supported features
Supported Operating Systems
Windows 7 and higher, Apple macOS/iOS/iPadOS, GNU/Linux, [Dragonfly|Net|Free|Open]BSD, Android, QNX, Solaris/Illumos, Haiku, GNU/Darwin, GNU/Hurd.
Supported Architectures
i386, x86-64, ARM/ARM64, RISC-V, PowerPC, MIPS, AVR, SPARC, System Z (S390), SuperH, m68k, m680x, XAP, XCore, CR16, HPPA, ARC, Blackfin, Z80, H8/300, Renesas (V810, V850, RL78), CRIS, XAP, PIC, LM32, 8051, 6502, i4004, i8080, Propeller, Tricore, CHIP-8, LH5801, T8200, GameBoy, SNES, SPC700, MSP430, Xtensa, NIOS II, TMS320 (c54x, c55x, c55+, c64x), Hexagon, DCPU16, LANAI, MCORE, mcs96, RSP, C-SKY(MCore), VAX, AMD Am29000.
There is also support for the following bytecode formats:
Dalvik, EBC, Java, Lua, Python, WebAssembly, Brainfuck, Malbolge
Supported File Formats
ELF, Mach-O, Fatmach-O, PE, PE+, MZ, COFF, OMF, NE, LE, LX, TE, XBE, BIOS/UEFI, Dyldcache, DEX, ART, CGC, ELF, Java class, Android boot image, Plan9 executable, ZIMG, MBN/SBL bootloader, ELF coredump, MDMP (Windows minidump), DMP (Windows pagedump), WASM (WebAssembly binary), Commodore VICE emulator, QNX, Game Boy (Advance), Nintendo DS ROMs and Nintendo 3DS FIRMs.
Tools
Apart from the main tool rizin, there are also other tools tailored for specific purposes and
useful for shell scripting or as separate standalone tools:
rz-bin- provides all kind of information about binary formatsrz-ar- list and extract members from static archives (.a and .lib)rz-asm- a command-line assembler and disassemblersrz-diff- a tool to compare two binaries as raw data or analyzed executablesrz-hash- allows to calculate different hashes or even encrypt datarz-gg- a small "eggs" code generator useful for exploitation purposesrz-find- binary analog offindtool, allowing to search patterns and bit masksrz-sign- tool to create, convert and parse FLIRT signaturesrz-ax- a calculator and number format converterrz-run- a tool that allows to specify running environment and arguments for debugged file
Scripting
We provide a way to interact with Rizin from Python, Haskell, OCaml, Ruby, Rust, and Go languages through rzpipe. Other languages although not currently supported could be easily added.
Community
Our website and blog: https://www.rizin.re/
Join our Mattermost community to discuss Rizin, its development, and general topics related to the project.
We also provide the following partial bridges to other messaging platforms: