No description
Find a file
atipriya 6d45a3c53e Decompiler: fix four defects in the Insert lowering pass
Follow-up to 90359a2b0, addressing code-review findings against the
lowering pass itself.

- LowerInsert tagged only the top-level Or with the original tags, so
  the generated Convert/Shl/And/Const nodes carried no ins_addr and the
  codegen's expression-to-address map had no entry for them. Every
  generated node now carries **expr.tags.

- The width cutoff gated on arch.bits, which refused ordinary 64-bit
  Inserts on 32-bit targets even though they are plain long long
  arithmetic. Those reached the backend as _INSERT across the whole
  32-bit family. The cutoff is now the widest C integer type.

- _lower_residual_inserts discarded walk()'s return value. Handlers for
  nodes that cannot be rewritten in place (LoopNode above all) return a
  fresh node, so a replacement produced at the root was dropped and the
  lowering silently did not happen for it.

- _lower_block built a fresh _PeepholeExprsWalker per block, rebuilding
  the dispatch table each time. It now reuses a cached walker, matching
  AILBlockSimplifier.

Not addressed here: the stack-base and uninitialized-base bail-outs
still let Inserts reach the C backend as _INSERT. Both defer to a
rendering in _handle_Stmt_Assignment that is keyed on the assignment
destination, which an expression-level peephole rule cannot see, so the
fix belongs in the backend rather than in these bail-outs.

Co-Authored-By:

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-20 19:19:51 +00:00
.github Update installation CI run (#6631) 2026-07-17 11:50:28 -07:00
angr Decompiler: fix four defects in the Insert lowering pass 2026-07-20 19:19:51 +00:00
corpus_tests Enable ruff isort rule (#6452) 2026-06-02 14:48:07 -07:00
docs Remove widen() from state api (#6632) 2026-07-17 13:23:53 -07:00
native AIL: Port the AIL VEX lifter to Rust. (#6608) 2026-07-15 01:23:34 -07:00
tests Decompiler: fix four defects in the Insert lowering pass 2026-07-20 19:19:51 +00:00
.dockerignore Oxidizer: Rust pseudocode generation (#6283) 2026-05-19 07:15:07 -07:00
.git-blame-ignore-revs .git-blame-ignore-revs: Fix reference 2025-11-26 17:44:09 -07:00
.gitignore docs: Auto-generate the API reference via autosummary (#6460) 2026-06-04 08:32:27 -07:00
.pre-commit-config.yaml [pre-commit.ci] pre-commit autoupdate (#6618) 2026-07-13 13:39:06 -07:00
.readthedocs.yml docs: Use integrated RTD rust support (#6382) 2026-05-01 23:08:38 -07:00
Cargo.lock AIL: Port the AIL VEX lifter to Rust. (#6608) 2026-07-15 01:23:34 -07:00
Cargo.toml Update to Rust 1.88 (#5561) 2025-06-26 21:00:49 -07:00
COPYRIGHT Update LICENSE and COPYRIGHT. (#5376) 2025-03-27 23:58:21 -07:00
LICENSE Update LICENSE and COPYRIGHT. (#5376) 2025-03-27 23:58:21 -07:00
MANIFEST.in Move pure data to angr-data. (#6530) 2026-06-23 16:00:58 -07:00
pyproject.toml Pin a recent pydantic-ai (#6630) 2026-07-17 11:09:09 -07:00
README.md README: Update some links 2025-10-13 13:57:08 -07:00
rust-toolchain.toml Upgrade rust toolchain to 1.96 (#6552) 2026-06-29 17:13:42 -07:00
SECURITY.md Draft security and reporting advisory (#3072) 2022-01-09 19:49:40 -07:00
setup.py Enable ruff isort rule (#6452) 2026-06-02 14:48:07 -07:00

angr

Latest Release Python Version PyPI Statistics License

angr is a platform-agnostic binary analysis framework. It is brought to you by the Computer Security Lab at UC Santa Barbara, SEFCOM at Arizona State University, their associated CTF team, Shellphish, the open source community, and @rhelmot.

Homepage: https://angr.io

Project repository: https://github.com/angr/angr

Documentation: https://docs.angr.io

API Documentation: https://docs.angr.io/en/latest/api.html

What is angr?

angr is a suite of Python 3 libraries that let you load a binary and do a lot of cool things to it:

  • Disassembly and intermediate-representation lifting
  • Program instrumentation
  • Symbolic execution
  • Control-flow analysis
  • Data-dependency analysis
  • Value-set analysis (VSA)
  • Decompilation

The most common angr operation is loading a binary: p = angr.Project('/bin/bash') If you do this in an enhanced REPL like IPython, you can use tab-autocomplete to browse the top-level-accessible methods and their docstrings.

The short version of "how to install angr" is mkvirtualenv --python=$(which python3) angr && python -m pip install angr.

Example

angr does a lot of binary analysis stuff. To get you started, here's a simple example of using symbolic execution to get a flag in a CTF challenge.

import angr

project = angr.Project("angr-doc/examples/defcamp_r100/r100", auto_load_libs=False)

@project.hook(0x400844)
def print_flag(state):
    print("FLAG SHOULD BE:", state.posix.dumps(0))
    project.terminate_execution()

project.execute()

Quick Start