Skip to content

[aarch64] Lift more things - #8611

Open
bdash wants to merge 8 commits into
test_aarch64_lifting_fixesfrom
test_aarch64_lift_more_things
Open

bdash wants to merge 8 commits into
test_aarch64_lifting_fixesfrom
test_aarch64_lift_more_things

Conversation

@bdash

@bdash bdash commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This adds lifting of a number of features that were added in recent ARM spec versions and lift cleanly to LLIL. It also adds lifting to intrinsics for a number of features that don't lift cleanly to LLIL, but show up in dyld shared caches in recent iOS versions.

See the individual commits for details on what is covered.

bdash added 8 commits October 1, 2026 09:43
`HINTE` and unallocated `HINT` encodings lifted as unimplemented, though
the architecture defines them to behave as NOPs. They now lift as `Nop`.
The `HINT` case no longer checks for BTI, which exarmo always decodes as
`BTI`.
`CFLT<cc>`, `TFLTZ`, `TFLTNZ` and `FLT.<cond>` are new in the 2026-09
ISA data. Each lifts as an `If` whose true branch is a `Trap` of the
instruction's reason, so the check it performs shows up in the IL.
`CB<cc>`, `CBB<cc>` and `CBH<cc>` lifted as unimplemented, so their
branch conditions were missing from the IL. Each now lifts as an `If`
that jumps to the branch target, sharing the comparison mapping with
`CFLT<cc>`.
`CAST`, `CASPT`, `SWPT`, `LDTADD`, `LDTCLR`, `LDTSET`, `LDTP`, `LDTNP`,
`STTP`, `STTNP`, the exclusives and their variants lifted as
unimplemented. Each differs from its privileged counterpart only in the
permission check, so it now shares that counterpart's lifting.
The Guarded Control Stack instructions and `CHKFEAT` were not lifted.
`GCSSTR` and `GCSSTTR` now lift as stores. The push, pop and stack
switch operations lift as intrinsics, since `GCSPR_EL0` is not a
register the IL can address. `CHKFEAT` lifts as an intrinsic that reads
and writes x16.
`FJCVTZS` was not lifted. It converts with JavaScript's `ToInt32`
semantics, wrapping modulo 2^32, and sets Z only when the conversion is
exact, which `-0.0` and a flushed subnormal are not. A float-to-int
conversion would get both wrong, so it now lifts as ACLE's `__jcvt`
intrinsic producing the result and Z, with N, C and V cleared.
…perands

`FNMADD` and `FNMSUB` were not lifted, as ACLE has no intrinsic for
them. Arm defines them as `FMADD` with the addend negated, and for
`FNMADD` the first factor too. Negation is exact, so they now lift as
`FMADD`'s intrinsic for each precision applied to the negated operands,
which keeps the single rounding.
…min/max instructions

These were not lifted, though each mirrors an instruction that was
already lifted.

`LDTR` and `STTR` and their variants now lift in the same way as `LDUR`
and `STUR`. `LDLAR` and `STLLR`  now lift in the same way as `LDAR` and
`STLR`. `LDAXP` and `STLXP` lift to `__ldaxp` and `__stlxp` in the same
way as `LDXP` and `STXP`.

The LSE `LDSMAX`, `LDSMIN`, `LDUMAX` and `LDUMIN` families and their
`ST` aliases lift in the same way as the other LSE atomics, storing the
signed or unsigned minimum or maximum.
@bdash
bdash added this pull request to stack #8610 October 1, 2026 17:16

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant