Skip to content

arm: Account for Thumb instruction widths in IT lookback - #92

Open
zardus wants to merge 1 commit into
masterfrom
feature/thumb-it-lookback-widths
Open

zardus wants to merge 1 commit into
masterfrom
feature/thumb-it-lookback-widths

Conversation

@zardus

@zardus zardus commented Aug 20, 2026 •

Copy link
Copy Markdown
Member

THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS

Problem

Lifting mixed_width_after at 0x110c6 in the compiler-built Thumb fixture retains ITSTATE after its mixed-width IT group has ended. At optimization level 1, the baseline emits a false conditional exit to Thumb address 0x110c9.

Root cause

The ARM decoder allowed two halfwords per guarded instruction during its backward IT search. It could not prove that a mixed-width group had expired, and an expired 0xbf08 halfword inside LDREX could hide an older active IT candidate.

Fix

Walk forward from each candidate using the actual 16- or 32-bit Thumb instruction widths. Mark the current instruction conditional only when the candidate reaches it, and continue searching after an expired false candidate.

Testing

The dependent PyVEX regression uses a compiler-built Thumb fixture to cover mixed-width expiry, conservative insufficient or disabled lookback, an expired false candidate inside LDREX, and the nine-halfword window edge. Validation: #92 (comment)

session: sharpen

@zardus

zardus commented Aug 20, 2026 •

Copy link
Copy Markdown
Member Author

THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS

Validation record for head 866bb8c991ed59fe37352443fbadbf9bef160d5a against baseline e3062871112afded52ae155757113a5873e9819c.

Coordinated candidate: PyVEX d4abbd0385f59198f4b6d2225bd03aa15c0b4dc9 with VEX 866bb8c991ed59fe37352443fbadbf9bef160d5a; baseline: PyVEX 24e2bd862aaedc14887bd247f1f1130445f94db6 with VEX e3062871112afded52ae155757113a5873e9819c. Tests used CPython 3.12.13 and the built packages.

Rebase: the ARM source blob and the PyVEX regression/workflow blobs are unchanged from the preceding published heads. The PyVEX gitlink now names the VEX rebased commit, preserving the AVX512 baseline.

  • Native build: the combined VEX/PyVEX store build passed, including the rebased ARM decoder and the AVX512 changes in the VEX baseline.
  • Focused regression: pytest --import-mode=append -q tests/test_arm_postprocess.py -k thumb_it_lookback against the baseline produced 1 failed, 3 passed, 2 deselected; the candidate produced 4 passed, 2 deselected. The failing baseline test is test_thumb_it_lookback_mixed_width_group_ends_before_block (ITSTATE remains live). The same compiler-built fixture was used in both runs.
  • Full PyVEX suite: pytest --import-mode=append -q tests passed 91 tests on the candidate.
  • Efficacy at optimization level 1: mixed_width_after changes from one ITSTATE read and one false exit to 0x110c9, to no ITSTATE reads or exits. The older-candidate control retains its exit to 0x110dd; the nine-halfword window-edge control remains unconditional.
  • Fixture: binaries commit 97ce07863c6d80a4145b73201dcb80d2da583332, tests/armel/thumb_it_lookback_widths.bin, 64 bytes, SHA-256 a49c1a151765f87446da09b98d6b11991f054a0a4ccb1d4ed2ea92694ad1f628.
  • Lint/type comparison for the changed Python file: Pylint 10.00 to 10.00; Pyright errors 1 to 1. Configured PyVEX pre-commit hooks, test-input policy, and test-package checks passed.

Workspace gate and limits

./feature.sh test pr-pyvex-568 was interrupted during feature-build. Before interruption, workspace tests reported a manager test fixture error (NOT NULL constraint failed: pr.repo); that test passes on workspace commit f0587f442a330e471c7c3a0b58f27ba418f54cb2, whose fixture supplies the missing PR row. Test-inputs, test-packages, and pre-commit completed successfully.

The remaining suites ran with ./feature.sh test pr-pyvex-568 feature-build mono pyvex pysoot: mono, PyVEX, and PySoot passed. Feature-build failed while preparing sweep tools because Nix reported an invalid Python build-tool store reference. The gate exited 1; this is not a full green workspace gate.

Suites skipped because their repositories were not adopted: archinfo, pypcode, cle, angr, angr-rust, and angr-management. Workspace, test-inputs, test-packages, and pre-commit were not repeated in the resumed command. Decompiler snapshots were not run locally.

This replaces the earlier-head validation. Its corpus, fixture-rebuild, mutant-control, and hosted-CI measurements were not rerun for these heads and are not claimed as current validation.

@zardus

zardus commented Aug 28, 2026 •

Copy link
Copy Markdown
Member Author

THIS MESSAGE WAS GENERATED BY AN AUTOMATED PROCESS

Lift result for mixed_width_after at 0x110c6 in the compiler-built Thumb fixture, at optimization level 1.

Before

vex baseline e306287
{"case": "mixed_width_after", "itstate_reads": 1, "exits": ["0x110c9"], "size": 2, "jumpkind": "Ijk_Ret"}

After

vex head 866bb8c
{"case": "mixed_width_after", "itstate_reads": 0, "exits": [], "size": 2, "jumpkind": "Ijk_Ret"}

To reproduce, read fixture bytes [0:0x14] and construct pyvex.IRSB(data, 0x110c7, pyvex.ARCH_ARM_LE, max_bytes=2, num_inst=1, bytes_offset=0x13, opt_level=1). Count reads at the architecture's itstate offset and list irsb.exit_statements targets. Both builds use the same fixture bytes.

@zardus
zardus force-pushed the feature/thumb-it-lookback-widths branch 2 times, most recently from 02e39d4 to 1f47b55 Compare September 8, 2026 09:38
Walk each possible IT candidate forward using exact Thumb instruction widths before clearing ITSTATE. Continue past expired candidates so halfwords within 32-bit encodings cannot hide an older active IT.
@zardus
zardus force-pushed the feature/thumb-it-lookback-widths branch from 1f47b55 to 866bb8c Compare September 16, 2026 01:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant