Conversation
`HINTE` and unallocated `HINT` encodings lifted as unimplemented, though the architecture defines them to behave as NOPs. They now lift as `Nop`. The `HINT` case no longer checks for BTI, which exarmo always decodes as `BTI`.
`CFLT<cc>`, `TFLTZ`, `TFLTNZ` and `FLT.<cond>` are new in the 2026-09 ISA data. Each lifts as an `If` whose true branch is a `Trap` of the instruction's reason, so the check it performs shows up in the IL.
`CB<cc>`, `CBB<cc>` and `CBH<cc>` lifted as unimplemented, so their branch conditions were missing from the IL. Each now lifts as an `If` that jumps to the branch target, sharing the comparison mapping with `CFLT<cc>`.
`CAST`, `CASPT`, `SWPT`, `LDTADD`, `LDTCLR`, `LDTSET`, `LDTP`, `LDTNP`, `STTP`, `STTNP`, the exclusives and their variants lifted as unimplemented. Each differs from its privileged counterpart only in the permission check, so it now shares that counterpart's lifting.
The Guarded Control Stack instructions and `CHKFEAT` were not lifted. `GCSSTR` and `GCSSTTR` now lift as stores. The push, pop and stack switch operations lift as intrinsics, since `GCSPR_EL0` is not a register the IL can address. `CHKFEAT` lifts as an intrinsic that reads and writes x16.
`FJCVTZS` was not lifted. It converts with JavaScript's `ToInt32` semantics, wrapping modulo 2^32, and sets Z only when the conversion is exact, which `-0.0` and a flushed subnormal are not. A float-to-int conversion would get both wrong, so it now lifts as ACLE's `__jcvt` intrinsic producing the result and Z, with N, C and V cleared.
…perands `FNMADD` and `FNMSUB` were not lifted, as ACLE has no intrinsic for them. Arm defines them as `FMADD` with the addend negated, and for `FNMADD` the first factor too. Negation is exact, so they now lift as `FMADD`'s intrinsic for each precision applied to the negated operands, which keeps the single rounding.
…min/max instructions These were not lifted, though each mirrors an instruction that was already lifted. `LDTR` and `STTR` and their variants now lift in the same way as `LDUR` and `STUR`. `LDLAR` and `STLLR` now lift in the same way as `LDAR` and `STLR`. `LDAXP` and `STLXP` lift to `__ldaxp` and `__stlxp` in the same way as `LDXP` and `STXP`. The LSE `LDSMAX`, `LDSMIN`, `LDUMAX` and `LDUMIN` families and their `ST` aliases lift in the same way as the other LSE atomics, storing the signed or unsigned minimum or maximum.
bdash
added this pull request to stack #8610
October 1, 2026 17:16
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This adds lifting of a number of features that were added in recent ARM spec versions and lift cleanly to LLIL. It also adds lifting to intrinsics for a number of features that don't lift cleanly to LLIL, but show up in dyld shared caches in recent iOS versions.
See the individual commits for details on what is covered.