No description
Find a file
Anton Kochkov 13ebcbc2c7 arch/tms320: named instruction IDs (TMS320C55_INS_*) from the disassembler
Gives the C55x / C55x+ disassembler a Capstone-style per-instruction
identifier and threads it through to analysis, so the analyzers dispatch
on named operations instead of raw opcode bytes.

What lands
==========

* librz/arch/isa/tms320/tms320c55x_insn.{c,h} -- a shared TMS320C55InsID enum
  (TMS320C55_INS_AADD, TMS320C55_INS_B, TMS320C55_INS_CALL, ...) covering
  C55x and C55x+, plus tms320c55x_insn_name(), tms320c55x_insn_id_from_syntax()
  and tms320c55x_insn_optype(). The prefix is TMS320C55_ / tms320c55x_
  rather than TMS320_ / tms320_ because the other TMS320 families (C54x,
  C64x, C28x) have substantially different instruction sets; the enum,
  the file and these helpers are C55x/C55x+ specific.

* insn_head_t gains an .id field; every head entry in c55x/table.h is
  tagged with its TMS320C55InsID. The disassembler resolves the decoded
  instruction ID from the emitted mnemonic (so multi-form leading bytes
  such as 0x95 -> intr/trap, 0x48 -> ret/reti/rpt, 0x50 -> sftl/popboth
  resolve to the exact instruction, which a static byte->head map cannot).
  tms320_dasm_t gains an insn_id field and tms320_dasm_insn_id() accessor.

* tms320_c55x_insn_id_decode() / tms320_c55x_plus_insn_id_decode() let the
  analyzers resolve the named ID for a byte sequence via a cached decoder
  instance.

* The C55x analyzer's dispatch is rewritten from switch(opcode_byte) to
  switch(TMS320C55InsID). Both analyzers set op->id to the named ID, the
  same way the Capstone-based plugins (e.g. c64x) populate op->id.

* The C55x+ analyzer keeps its byte-level dispatch for control flow,
  stack deltas and operands, but takes the final arithmetic/logical/move/
  multiply/stack type from tms320c55x_insn_optype(op->id). A leading byte on
  C55x+ encodes several instructions (selected by operand bits), so the
  byte switch alone cannot tell ADD from SUB, AND from OR/XOR, or AMOV
  from ASUB; the decoded id can.

Bugs fixed
==========

Driving dispatch / typing from the decoded id fixes a number of latent
mis-classifications the raw-byte switch had masked, verified against the
TI dis55 reference disassembler and the C55x+ documentation:

  - 0x50 0x66 (psh Tx) was typed SHL; now a stack push (corrects
    sym._main's computed stackframe in the rel.stripped.coff test).
  - 0x48 0x05 (reti) was typed REP; now RET.
  - 0x95 0x0F / 0x8F (intr vs trap) distinguished by the decoder.
  - C55x+ 0x7B: byte1 bit7 selects LD (mov) vs add/sub, and within
    add/sub byte2 bit7 selects sub; was always typed add/mov by nibble.
    (TI SWPU104 Table 7-2, opcode 01111011.)
  - C55x+ 0xD2 mar(XDAa op k24): address-register modify, now LEA like
    AADD / AMOV; was typed SUB. (Table 7-2, opcode 11010010.)
  - 57 further C55x+ arith/logical/move/stack contradictions found by
    cross-referencing a Motorola Droid (Wrigley3G) C55x+ baseband dump
    against the decoder are resolved by the optype override.

* DELAY is a memory-delay MOVE per TI SWPU104 sec.6.7.1 (Memory Delay,
  grouped under Move Operations): it copies Smem to Smem+1. Both
  analyzers now mark it as a memory access (width 2, write) and drop the
  spurious FAMILY_CPU (CPU is already the default family).

Tests
=====

New checks assert op->id carries the right TMS320C55_INS_* value on each
CPU, plus regression tests for every byte/decoded-id mismatch fixed above
(c55x: 0x50/0x48/0x95/0xb6; c55x+: 0x7b/0xd2). The c55x opcode-
classification and stackframe expectations are updated to the corrected
output.

Cross-reference
===============

  TI SPRU374    'TMS320C55x DSP Mnemonic Instruction Set Reference Guide'
  TI SWPU086    'TMS320C55x+ DSP Algebraic Instruction Set Reference Guide'
  TI SWPU104    'TMS320C55x+ DSP Mnemonic Instruction Set Reference Guide'
2026-05-28 17:44:54 +08:00
.builds NetBSD: Upgrade to Python 3.10 (#5686) 2025-12-27 00:02:58 +08:00
.github Apply patches/fix_zydis_amalgamated_riscv32_build to subproject 2026-05-11 11:54:02 +08:00
.woodpecker Run tests on woodpecker but be verbose. 2024-09-23 14:24:41 +08:00
binrz fix: remove windows debugger compilation warnings (#6140) 2026-04-05 16:27:46 +08:00
dist ci: fix macOS package creation 2026-02-01 20:29:59 +08:00
doc add RISC-V 32-bit env to CI (#6109) 2026-04-14 15:39:39 +08:00
examples Rename rz_list_first() / rz_list_last() to rz_list_first_val() / rz_list_last_val() (#5654) 2025-12-20 17:08:59 +08:00
librz arch/tms320: named instruction IDs (TMS320C55_INS_*) from the disassembler 2026-05-28 17:44:54 +08:00
LICENSES Move SDB into RzUtil 2022-07-19 08:45:20 +02:00
patches Apply patches/fix_zydis_amalgamated_riscv32_build to subproject 2026-05-11 11:54:02 +08:00
subprojects Bump demangler to latest commit + fix useless code (#6381) 2026-05-18 23:20:19 +08:00
sys add RISC-V 32-bit env to CI (#6109) 2026-04-14 15:39:39 +08:00
test arch/tms320: named instruction IDs (TMS320C55_INS_*) from the disassembler 2026-05-28 17:44:54 +08:00
.appveyor.yml log.level help: Don't show 0:DEBUG on Release builds (#6319) 2026-05-07 22:33:46 +08:00
.clang-format Remove Language from .clang-format to reuse config for C & Cpp 2025-11-22 12:33:15 +08:00
.dockerignore Drop libuv dependency 2022-08-06 13:20:52 +02:00
.git-blame-ignore-revs linter: update clang-format entries in .git-blame-ignore-revs (#5453) 2025-10-12 12:07:13 +08:00
.gitattributes Move remaining things from shlr/ to meson subprojects (#2126) 2021-12-22 09:20:39 +08:00
.gitignore hash: add jenkins non-cryptographic hash (#6121) 2026-04-02 01:42:23 +08:00
.lgtm.yml Make LGTM use Meson 2021-01-28 11:57:28 +01:00
.prettierignore Move remaining things from shlr/ to meson subprojects (#2126) 2021-12-22 09:20:39 +08:00
.pylintrc Add leak check in CI (#5553) 2025-12-04 11:02:01 +00:00
.travis.yml Fix endianness issues on s390x (#5940) 2026-02-19 23:13:18 +08:00
AGENTS.md Add AGENTS.md with requirement to disclose agent authorship and flag PRs with detected AI usage. (#6025) 2026-03-13 15:00:14 +00:00
BUILDING.md doc: fix various typos and documentation issues (#5771) 2026-01-10 21:33:54 +08:00
CODE_OF_CONDUCT.md Create CODE_OF_CONDUCT.md (#93) 2020-11-24 06:50:10 +02:00
codecov.yml refactor: remove unused mpc subproject (#6091) 2026-03-25 20:30:15 +08:00
CODEOWNERS Simplify CODEOWNERS (#6040) 2026-03-15 15:52:16 +00:00
CONTRIBUTING.md Forbid usage of AI tools for good-first-issues. (#5829) 2026-01-23 13:06:24 +08:00
COPYING Honor FSF filename license rules (LICENSE->COPYING) 2013-03-30 00:54:05 +01:00
COPYING.LESSER Honor FSF filename license rules (LICENSE->COPYING) 2013-03-30 00:54:05 +01:00
DEVELOPERS.md Document allowed macro usage. (#6060) 2026-03-22 11:46:14 +00:00
Dockerfile docker: update to Debian 11 (Bullseye) (#5277) 2025-07-18 12:27:28 +08:00
Doxyfile Move remaining things from shlr/ to meson subprojects (#2126) 2021-12-22 09:20:39 +08:00
meson.build librz/arch: check if M680X HSC12X/RS08 is present in Capstone (#6318) 2026-05-06 11:53:40 +08:00
meson_options.txt blake2 hash support (#5995) 2026-03-06 22:17:59 +08:00
README.md rz-ar: add archive extraction utility (#6036) 2026-03-18 03:51:18 +08:00
REUSE.toml refactor: remove unused mpc subproject (#6091) 2026-03-25 20:30:15 +08:00
SECURITY.md Add AI tool guidelines (#5474) 2025-10-21 20:53:17 +08:00
snapcraft.yaml Bump version to v0.9.0 2025-04-23 16:49:14 +08:00
travis-extract-var.sh SPDX Copyright text for all files based on history 2021-03-05 19:39:15 +08:00
travis-script Use meson setup <dir> instead of meson <dir> 2023-04-26 20:01:47 +08:00

Rizin logo

Rizin

Rizin is a reverse engineering framework, born as a fork of the radare2, with a focus on usability, features and cleanliness.

Rizin is portable and it can be used to analyze binaries, disassemble code, debug programs, as a forensic tool, as a scriptable command-line hexadecimal editor able to open disk files, and much more!

To learn more on Rizin you may want to read the official Rizin book.

How to install

Look at install instructions on our web page.

How to build

Use meson to compile and install Rizin. Please make sure to get an updated meson (e.g. get it with pip install meson if your system does not provide one that is at least version 0.55.0).

Clone this repository:

$ git clone https://github.com/rizinorg/rizin

Then compile and install with:

$ meson setup build
$ meson compile -C build
$ sudo meson install -C build

Now you can use rizin:

$ rizin
 -- Thank you for using rizin. Have a nice night!
[0x00000000]>

To uninstall rizin, execute sudo ninja -C build uninstall.

Please have a look at BUILDING.md for more information about building Rizin.

Contributing

We very much welcome any kind of contributions, from typos, to documentation, to refactoring, up to completely new features you may think of. Before contributing, we would like you to read the file CONTRIBUTING.md, so that we can all be on the same page.

Tests

Look at test/README.md.

Supported features

Supported Operating Systems

Windows 7 and higher, Apple macOS/iOS/iPadOS, GNU/Linux, [Dragonfly|Net|Free|Open]BSD, Android, QNX, Solaris/Illumos, Haiku, GNU/Darwin, GNU/Hurd.

Supported Architectures

i386, x86-64, ARM/ARM64, RISC-V, PowerPC, MIPS, AVR, SPARC, System Z (S390), SuperH, m68k, m680x, XAP, XCore, CR16, HPPA, ARC, Blackfin, Z80, H8/300, Renesas (V810, V850, RL78), CRIS, XAP, PIC, LM32, 8051, 6502, i4004, i8080, Propeller, Tricore, CHIP-8, LH5801, T8200, GameBoy, SNES, SPC700, MSP430, Xtensa, NIOS II, TMS320 (c54x, c55x, c55+, c64x), Hexagon, DCPU16, LANAI, MCORE, mcs96, RSP, C-SKY(MCore), VAX, AMD Am29000.

There is also support for the following bytecode formats:

Dalvik, EBC, Java, Lua, Python, WebAssembly, Brainfuck, Malbolge

Supported File Formats

ELF, Mach-O, Fatmach-O, PE, PE+, MZ, COFF, OMF, NE, LE, LX, TE, XBE, BIOS/UEFI, Dyldcache, DEX, ART, CGC, ELF, Java class, Android boot image, Plan9 executable, ZIMG, MBN/SBL bootloader, ELF coredump, MDMP (Windows minidump), DMP (Windows pagedump), WASM (WebAssembly binary), Commodore VICE emulator, QNX, Game Boy (Advance), Nintendo DS ROMs and Nintendo 3DS FIRMs.

Tools

Apart from the main tool rizin, there are also other tools tailored for specific purposes and useful for shell scripting or as separate standalone tools:

  • rz-bin - provides all kind of information about binary formats
  • rz-ar - list and extract members from static archives (.a and .lib)
  • rz-asm - a command-line assembler and disassemblers
  • rz-diff - a tool to compare two binaries as raw data or analyzed executables
  • rz-hash - allows to calculate different hashes or even encrypt data
  • rz-gg - a small "eggs" code generator useful for exploitation purposes
  • rz-find - binary analog of find tool, allowing to search patterns and bit masks
  • rz-sign - tool to create, convert and parse FLIRT signatures
  • rz-ax - a calculator and number format converter
  • rz-run - a tool that allows to specify running environment and arguments for debugged file

Scripting

We provide a way to interact with Rizin from Python, Haskell, OCaml, Ruby, Rust, and Go languages through rzpipe. Other languages although not currently supported could be easily added.

Community

Our website and blog: https://www.rizin.re/

Join our Mattermost community to discuss Rizin, its development, and general topics related to the project.

We also provide the following partial bridges to other messaging platforms: