From fa72d644be96d4e2a4e98f8061bd80266827ad51 Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Thu, 7 Feb 2019 08:19:29 +0100 Subject: Dataflow: use AssignblkNode in SSADefUse --- miasm2/analysis/data_flow.py | 44 +++++++++++++++++++------------------------- 1 file changed, 19 insertions(+), 25 deletions(-) (limited to 'miasm2/analysis/data_flow.py') diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index 4bf64e25..a08acbd9 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -528,33 +528,28 @@ class SSADefUse(DiGraph): """ def add_var_def(self, node, src): - lbl, index, dst = node - index2dst = self._links.setdefault(lbl, {}) - dst2src = index2dst.setdefault(index, {}) - dst2src[dst] = src + index2dst = self._links.setdefault(node.label, {}) + dst2src = index2dst.setdefault(node.index, {}) + dst2src[node.var] = src def add_def_node(self, def_nodes, node, src): - lbl, index, dst = node - if dst.is_id(): - def_nodes[dst] = node + if node.var.is_id(): + def_nodes[node.var] = node def add_use_node(self, use_nodes, node, src): - lbl, index, dst = node sources = set() - if dst.is_mem(): - sources.update(dst.ptr.get_r(mem_read=True)) + if node.var.is_mem(): + sources.update(node.var.ptr.get_r(mem_read=True)) sources.update(src.get_r(mem_read=True)) for source in sources: if not source.is_mem(): use_nodes.setdefault(source, set()).add(node) def get_node_target(self, node): - lbl, index, reg = node - return self._links[lbl][index][reg] + return self._links[node.label][node.index][node.var] def set_node_target(self, node, src): - lbl, index, reg = node - self._links[lbl][index][reg] = src + self._links[node.label][node.index][node.var] = src @classmethod def from_ssa(cls, ssa): @@ -575,7 +570,7 @@ class SSADefUse(DiGraph): continue for index, assignblk in enumerate(block): for dst, src in assignblk.iteritems(): - node = lbl, index, dst + node = AssignblkNode(lbl, index, dst) graph.add_var_def(node, src) graph.add_def_node(def_nodes, node, src) graph.add_use_node(use_nodes, node, src) @@ -713,16 +708,15 @@ class PropagateExpr(object): to_replace = {} node_to_reg = {} for node in defuse.nodes(): - lbl, index, reg = node src = defuse.get_node_target(node) if expr_has_call(src): continue if src.is_op('Phi'): continue - if reg.is_mem(): + if node.var.is_mem(): continue - to_replace[reg] = src - node_to_reg[node] = reg + to_replace[node.var] = src + node_to_reg[node] = node.var modified = False for node, reg in node_to_reg.iteritems(): @@ -730,14 +724,14 @@ class PropagateExpr(object): if not self.propagation_allowed(ssa, to_replace, node, successor): continue - loc_a, index_a, reg_a = node - loc_b, index_b, reg_b = successor - block = ssa.graph.blocks[loc_b] + node_a = node + node_b = successor + block = ssa.graph.blocks[node_b.label] - replace = {reg_a: to_replace[reg_a]} + replace = {node_a.var: to_replace[node_a.var]} # Replace assignblks = list(block) - assignblk = block[index_b] + assignblk = block[node_b.index] out = {} for dst, src in assignblk.iteritems(): if src.is_op('Phi'): @@ -765,7 +759,7 @@ class PropagateExpr(object): modified = True out[new_dst] = new_src out = AssignBlock(out, assignblk.instr) - assignblks[index_b] = out + assignblks[node_b.index] = out new_block = IRBlock(block.loc_key, assignblks) ssa.graph.blocks[block.loc_key] = new_block return modified -- cgit 1.4.1 From f89a9e302e087dbb34de2dff47bc236a0ece36c6 Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Thu, 7 Feb 2019 20:28:58 +0100 Subject: Propagation: Don't propagate immutable registers --- miasm2/analysis/data_flow.py | 2 ++ 1 file changed, 2 insertions(+) (limited to 'miasm2/analysis/data_flow.py') diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index a08acbd9..53033d7e 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -708,6 +708,8 @@ class PropagateExpr(object): to_replace = {} node_to_reg = {} for node in defuse.nodes(): + if node.var in ssa.immutable_ids: + continue src = defuse.get_node_target(node) if expr_has_call(src): continue -- cgit 1.4.1 From db44ff49a2997d7916971d36f0f86cd8a530cf7c Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Mon, 4 Feb 2019 21:04:27 +0100 Subject: IR: add simplifier --- example/disasm/full.py | 164 ++++------------------- example/ida/graph_ir.py | 123 +++++------------ miasm2/analysis/data_flow.py | 156 +++++++++++++++++++--- miasm2/analysis/simplifier.py | 303 ++++++++++++++++++++++++++++++++++++++++++ miasm2/analysis/ssa.py | 9 +- test/analysis/unssa.py | 52 +++----- 6 files changed, 516 insertions(+), 291 deletions(-) create mode 100644 miasm2/analysis/simplifier.py (limited to 'miasm2/analysis/data_flow.py') diff --git a/example/disasm/full.py b/example/disasm/full.py index 42d50216..19036882 100644 --- a/example/disasm/full.py +++ b/example/disasm/full.py @@ -6,17 +6,13 @@ from miasm2.analysis.binary import Container from miasm2.core.asmblock import log_asmblock, AsmCFG from miasm2.core.interval import interval from miasm2.analysis.machine import Machine -from miasm2.analysis.data_flow import dead_simp, DiGraphDefUse, \ - ReachingDefinitions, merge_blocks, remove_empty_assignblks, \ - PropagateExpr, replace_stack_vars, load_from_int, \ - del_unused_edges +from miasm2.analysis.data_flow import dead_simp, \ + DiGraphDefUse, ReachingDefinitions, \ + replace_stack_vars, load_from_int, del_unused_edges from miasm2.expression.simplifications import expr_simp from miasm2.analysis.ssa import SSADiGraph -from miasm2.analysis.outofssa import UnSSADiGraph -from miasm2.analysis.data_flow import DiGraphLivenessSSA from miasm2.ir.ir import AssignBlock, IRBlock - - +from miasm2.analysis.simplifier import IRCFGSimplifierCommon, IRCFGSimplifierSSA log = logging.getLogger("dis") console_handler = logging.StreamHandler() @@ -207,7 +203,6 @@ open('lines.dot', 'w').write('\n'.join([str(l) for l in all_lines])) log.info('total lines %s' % total_l) - if args.propagexpr: args.gen_ir = True @@ -240,6 +235,9 @@ if args.gen_ir: ir_arch.blocks = {} ir_arch_a.blocks = {} + + head = list(entry_points)[0] + for ad, asmcfg in all_funcs_blocks.items(): log.info("generating IR... %x" % ad) for block in asmcfg.blocks: @@ -257,8 +255,9 @@ if args.gen_ir: print block if args.simplify > 0: - log.info("dead simp...") - dead_simp(ir_arch_a, ircfg_a) + log.info("Simplify...") + ircfg_simplifier = IRCFGSimplifierCommon(ir_arch_a) + ircfg_simplifier.simplify(ircfg_a, head) log.info("ok...") if args.defuse: @@ -270,30 +269,14 @@ if args.gen_ir: out = ircfg_a.dot() open('graph_irflow.dot', 'w').write(out) - if args.simplify > 1: - - ircfg_a.simplify(expr_simp) - modified = True - while modified: - modified = False - modified |= dead_simp(ir_arch_a, ircfg_a) - modified |= remove_empty_assignblks(ircfg_a) - - open('graph_irflow_reduced.dot', 'w').write(ircfg_a.dot()) - if args.ssa and not args.propagexpr: if len(entry_points) != 1: raise RuntimeError("Your graph should have only one head") - head = list(entry_points)[0] ssa = SSADiGraph(ircfg_a) ssa.transform(head) - open("ssa.dot", "wb").write(ircfg_a.dot()) - - - if args.propagexpr: class IRAOutRegs(ira): def get_out_regs(self, block): @@ -324,8 +307,6 @@ if args.propagexpr: - ir_arch_a = IRAOutRegs(mdis.loc_db) - def is_addr_ro_variable(bs, addr, size): """ Return True if address at @addr is a read-only variable. @@ -341,118 +322,21 @@ if args.propagexpr: return False return True + ir_arch_a = IRAOutRegs(mdis.loc_db) - ir_arch_a.ssa_var = {} - index = 0 - modified = True - ssa_forbidden_regs = set([ - ir_arch_a.pc, - ir_arch_a.IRDst, - ir_arch_a.arch.regs.exception_flags - ]) - head = list(entry_points)[0] - heads = set([head]) - all_ssa_vars = {} + class CustomIRCFGSimplifierSSA(IRCFGSimplifierSSA): + def do_simplify(self, ssa, head): + modified = super(CustomIRCFGSimplifierSSA, self).do_simplify(ssa, head) + if args.loadint: + modified |= load_from_int(ssa.graph, bs, is_addr_ro_variable) + if args.stack2var: + modified |= replace_stack_vars(self.ir_arch, ssa) + return modified - propagate_expr = PropagateExpr() - ssa_variable_to_expr = {} - while modified: - ssa = SSADiGraph(ircfg_a) - ssa.immutable_ids.update(ssa_forbidden_regs) - ssa.ssa_variable_to_expr.update(all_ssa_vars) - ssa.transform(head) - all_ssa_vars.update(ssa.ssa_variable_to_expr) - - if args.verbose > 3: - open("ssa_%d.dot" % index, "wb").write(ircfg_a.dot()) - - ir_arch_a.ssa_var.update(ssa.ssa_variable_to_expr) - if args.verbose > 3: - open("ssa_orig.dot", "wb").write(ircfg_a.dot()) - - while modified: - log.debug('Loop %d', index) - index += 1 - modified = False - if args.verbose > 3: - open('tmp_before_%d.dot' % index, 'w').write(ircfg_a.dot()) - modified |= propagate_expr.propagate(ssa, head) - if args.verbose > 3: - open('tmp_adter_%d.dot' % index, 'w').write(ircfg_a.dot()) - modified |= ircfg_a.simplify(expr_simp) - if args.verbose > 3: - open('tmp_simp_%d.dot' % index, 'w').write(ircfg_a.dot()) - simp_modified = True - while simp_modified: - index += 1 - if args.verbose > 3: - open('tmp_before_%d.dot' % index, 'w').write(ircfg_a.dot()) - simp_modified = False - log.info("dead simp...") - simp_modified |= dead_simp(ir_arch_a, ircfg_a) - log.info("ok...") - - index += 1 - if args.verbose > 3: - open('tmp_after_%d.dot' % index, 'w').write(ircfg_a.dot()) - simp_modified |= remove_empty_assignblks(ircfg_a) - simp_modified |= del_unused_edges(ircfg_a, heads) - simp_modified |= merge_blocks(ircfg_a, heads) - - if args.loadint: - simp_modified |= load_from_int(ircfg_a, bs, is_addr_ro_variable) - modified |= simp_modified - index += 1 - if args.verbose > 3: - open('stack_%d.dot' % index, 'w').write(ircfg_a.dot()) - if args.stack2var: - modified |= replace_stack_vars(ir_arch_a, ssa) - - if args.verbose > 3: - open('final_pre.dot', 'w').write(ircfg_a.dot()) - - if args.verbose > 3: - open('final_merge.dot', 'w').write(ircfg_a.dot()) - ssa = SSADiGraph(ircfg_a) - ssa.immutable_ids.update(ssa_forbidden_regs) - ssa.ssa_variable_to_expr.update(all_ssa_vars) - ssa.transform(head) - print '*'*80, "Remove phi" - if args.verbose > 3: - open('final_ssa.dot', 'w').write(ircfg_a.dot()) - - cfg_liveness = DiGraphLivenessSSA(ircfg_a) - cfg_liveness.init_var_info(ir_arch_a) - cfg_liveness.compute_liveness() - - unssa = UnSSADiGraph(ssa, head, cfg_liveness) - - if args.verbose > 3: - open('final_no_phi.dot', 'w').write(ircfg_a.dot()) - - modified = True - while modified: - log.debug('Loop %d', index) - index += 1 - modified = False - modified |= ircfg_a.simplify(expr_simp) - if args.verbose > 3: - open('tmp_simp_%d.dot' % index, 'w').write(ircfg_a.dot()) - simp_modified = True - while simp_modified: - index += 1 - if args.verbose > 3: - open('tmp_before_%d.dot' % index, 'w').write(ircfg_a.dot()) - simp_modified = False - simp_modified |= dead_simp(ir_arch_a, ircfg_a) - index += 1 - if args.verbose > 3: - open('tmp_after_%d.dot' % index, 'w').write(ircfg_a.dot()) - simp_modified |= remove_empty_assignblks(ircfg_a) - simp_modified |= merge_blocks(ircfg_a, heads) - modified |= simp_modified - index += 1 - - open('final.dot', 'w').write(ircfg_a.dot()) + head = list(entry_points)[0] + ir_arch_a = IRAOutRegs(mdis.loc_db) + simplifier = CustomIRCFGSimplifierSSA(ir_arch_a) + ircfg = simplifier.simplify(ircfg_a, head) + open('final.dot', 'w').write(ircfg.dot()) diff --git a/example/ida/graph_ir.py b/example/ida/graph_ir.py index f9c61c2c..8026174d 100644 --- a/example/ida/graph_ir.py +++ b/example/ida/graph_ir.py @@ -10,16 +10,9 @@ from miasm2.core.asmblock import is_int from miasm2.core.bin_stream_ida import bin_stream_ida from miasm2.expression.simplifications import expr_simp from miasm2.ir.ir import IRBlock, AssignBlock - -from miasm2.analysis.ssa import SSADiGraph, UnSSADiGraph - -from miasm2.analysis.data_flow import dead_simp, \ - merge_blocks, remove_empty_assignblks, \ - PropagateExpr, load_from_int, \ - DiGraphLivenessSSA - - +from miasm2.analysis.data_flow import load_from_int from utils import guess_machine, expr2colorstr +from miasm2.analysis.simplifier import IRCFGSimplifierCommon, IRCFGSimplifierSSA @@ -251,15 +244,11 @@ def build_graph(start_addr, type_graph, simplify=False, dontmodstack=True, loadi title = "Miasm IR graph" + head = list(entry_points)[0] + if simplify: - dead_simp(ir_arch, ircfg) - ircfg.simplify(expr_simp) - modified = True - while modified: - modified = False - modified |= dead_simp(ir_arch, ircfg) - modified |= remove_empty_assignblks(ircfg) - modified |= merge_blocks(ircfg, entry_points) + ircfg_simplifier = IRCFGSimplifierCommon(ir_arch) + ircfg_simplifier.simplify(ircfg, head) title += " (simplified)" if type_graph == TYPE_GRAPH_IR: @@ -267,8 +256,6 @@ def build_graph(start_addr, type_graph, simplify=False, dontmodstack=True, loadi graph.Show() return - head = list(entry_points)[0] - class IRAOutRegs(ira): def get_out_regs(self, block): @@ -299,86 +286,38 @@ def build_graph(start_addr, type_graph, simplify=False, dontmodstack=True, loadi new_irblock = IRBlock(irblock.loc_key, assignblks) ircfg.blocks[loc] = new_irblock - ir_arch = IRAOutRegs(mdis.loc_db) - ir_arch.ssa_var = {} - modified = True - ssa_forbidden_regs = set([ - ir_arch.pc, - ir_arch.IRDst, - ir_arch.arch.regs.exception_flags - ]) - head = list(entry_points)[0] - heads = set([head]) - all_ssa_vars = {} - - propagate_expr = PropagateExpr() + class CustomIRCFGSimplifierSSA(IRCFGSimplifierSSA): + def do_simplify(self, ssa, head): + modified = super(CustomIRCFGSimplifierSSA, self).do_simplify(ssa, head) + if loadint: + modified |= load_from_int(ssa.graph, bs, is_addr_ro_variable) + return modified - ssa = SSADiGraph(ircfg) - ssa.immutable_ids.update(ssa_forbidden_regs) - ssa.ssa_variable_to_expr.update(all_ssa_vars) - ssa.transform(head) - all_ssa_vars.update(ssa.ssa_variable_to_expr) + def simplify(self, ircfg, head): + ssa = self.ircfg_to_ssa(ircfg, head) + ssa = self.do_simplify_loop(ssa, head) - ir_arch.ssa_var.update(ssa.ssa_variable_to_expr) + if type_graph == TYPE_GRAPH_IRSSA: + ret = ssa.graph + elif type_graph == TYPE_GRAPH_IRSSAUNSSA: + ircfg = self.ssa_to_unssa(ssa, head) + ircfg_simplifier = IRCFGSimplifierCommon(self.ir_arch) + ircfg_simplifier.simplify(ircfg, head) + ret = ircfg + else: + raise ValueError("Unknown option") + return ret - if simplify: - while modified: - ssa = SSADiGraph(ircfg) - ssa.immutable_ids.update(ssa_forbidden_regs) - ssa.ssa_variable_to_expr.update(all_ssa_vars) - ssa.transform(head) - all_ssa_vars.update(ssa.ssa_variable_to_expr) - - ir_arch.ssa_var.update(ssa.ssa_variable_to_expr) - - while modified: - modified = False - modified |= propagate_expr.propagate(ssa, head) - modified |= ircfg.simplify(expr_simp) - simp_modified = True - while simp_modified: - simp_modified = False - simp_modified |= dead_simp(ir_arch, ircfg) - simp_modified |= remove_empty_assignblks(ircfg) - simp_modified |= load_from_int(ircfg, bs, is_addr_ro_variable) - modified |= simp_modified - - - ssa = SSADiGraph(ircfg) - ssa.immutable_ids.update(ssa_forbidden_regs) - ssa.ssa_variable_to_expr.update(all_ssa_vars) - ssa.transform(head) - all_ssa_vars.update(ssa.ssa_variable_to_expr) - - if type_graph == TYPE_GRAPH_IRSSA: - graph = GraphMiasmIR(ssa.graph, title, None) - graph.Show() - return + head = list(entry_points)[0] + simplifier = CustomIRCFGSimplifierSSA(ir_arch) + ircfg = simplifier.simplify(ircfg, head) + open('final.dot', 'w').write(ircfg.dot()) - if type_graph == TYPE_GRAPH_IRSSAUNSSA: - - cfg_liveness = DiGraphLivenessSSA(ssa.graph) - cfg_liveness.init_var_info(ir_arch) - cfg_liveness.compute_liveness() - - UnSSADiGraph(ssa, head, cfg_liveness) - if simplify: - modified = True - while modified: - modified = False - modified |= ssa.graph.simplify(expr_simp) - simp_modified = True - while simp_modified: - simp_modified = False - simp_modified |= dead_simp(ir_arch, ssa.graph) - simp_modified |= remove_empty_assignblks(ssa.graph) - simp_modified |= merge_blocks(ssa.graph, heads) - modified |= simp_modified - graph = GraphMiasmIR(ssa.graph, title, None) - graph.Show() + graph = GraphMiasmIR(ircfg, title, None) + graph.Show() def function_graph_ir(): # Get settings diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index 53033d7e..fb09a6cb 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -11,6 +11,7 @@ from miasm2.expression.expression_helper import possible_values from miasm2.analysis.ssa import get_phi_sources_parent_block, \ irblock_has_phi + class ReachingDefinitions(dict): """ Computes for each assignblock the set of reaching definitions. @@ -510,17 +511,19 @@ def remove_empty_assignblks(ircfg): modified = False for loc_key, block in ircfg.blocks.iteritems(): irs = [] + block_modified = False for assignblk in block: if len(assignblk): irs.append(assignblk) else: - modified = True - ircfg.blocks[loc_key] = IRBlock(loc_key, irs) - + block_modified = True + if block_modified: + new_irblock = IRBlock(loc_key, irs) + ircfg.blocks[loc_key] = new_irblock + modified = True return modified - class SSADefUse(DiGraph): """ Generate DefUse information from SSA transformation @@ -635,17 +638,16 @@ def expr_has_call(expr): return expr_test_visit(expr, expr_has_call_test) -class PropagateExpr(object): - - def assignblk_is_propagation_barrier(self, assignblk): - for dst, src in assignblk.iteritems(): - if expr_has_call(src): - return True - if dst.is_mem(): - return True - return False +class PropagateThroughExprId(object): + """ + Propagate expressions though ExprId + """ def has_propagation_barrier(self, assignblks): + """ + Return True if propagation cannot cross the @assignblks + @assignblks: list of AssignBlock to check + """ for assignblk in assignblks: for dst, src in assignblk.iteritems(): if expr_has_call(src): @@ -655,13 +657,19 @@ class PropagateExpr(object): return False def is_mem_written(self, ssa, node, successor): + """ + Return True if memory is written at least once between @node and + @successor + + @node: Location of the block to start with + @successor: Location of last block + """ loc_a, index_a, reg_a = node loc_b, index_b, reg_b = successor block_b = ssa.graph.blocks[loc_b] nodes_to_do = self.compute_reachable_nodes_from_a_to_b(ssa.graph, loc_a, loc_b) - if loc_a == loc_b: # src is dst assert nodes_to_do == set([loc_a]) @@ -703,7 +711,7 @@ class PropagateExpr(object): return False return True - def propagate(self, ssa, head): + def get_candidates(self, ssa, head, max_expr_depth): defuse = SSADefUse.from_ssa(ssa) to_replace = {} node_to_reg = {} @@ -717,9 +725,20 @@ class PropagateExpr(object): continue if node.var.is_mem(): continue + if max_expr_depth is not None and len(str(src)) > max_expr_depth: + continue to_replace[node.var] = src node_to_reg[node] = node.var + return node_to_reg, to_replace, defuse + def propagate(self, ssa, head, max_expr_depth=None): + """ + Do expression propagation + @ssa: SSADiGraph instance + @head: the head location of the graph + @max_expr_depth: the maximum allowed depth of an expression + """ + node_to_reg, to_replace, defuse = self.get_candidates(ssa, head, max_expr_depth) modified = False for node, reg in node_to_reg.iteritems(): for successor in defuse.successors(node): @@ -741,8 +760,7 @@ class PropagateExpr(object): continue if src.is_mem(): - ptr = src.ptr - ptr = ptr.replace_expr(replace) + ptr = src.ptr.replace_expr(replace) new_src = ExprMem(ptr, src.size) else: new_src = src.replace_expr(replace) @@ -750,8 +768,7 @@ class PropagateExpr(object): if dst.is_id(): new_dst = dst elif dst.is_mem(): - ptr = dst.ptr - ptr = ptr.replace_expr(replace) + ptr = dst.ptr.replace_expr(replace) new_dst = ExprMem(ptr, dst.size) else: new_dst = dst.replace_expr(replace) @@ -764,6 +781,105 @@ class PropagateExpr(object): assignblks[node_b.index] = out new_block = IRBlock(block.loc_key, assignblks) ssa.graph.blocks[block.loc_key] = new_block + + return modified + + + +class PropagateExprIntThroughExprId(PropagateThroughExprId): + """ + Propagate ExprInt though ExprId: classic constant propagation + This is a sub family of PropagateThroughExprId. + It reduces leaves in expressions of a program. + """ + + def get_candidates(self, ssa, head, max_expr_depth): + defuse = SSADefUse.from_ssa(ssa) + + to_replace = {} + node_to_reg = {} + for node in defuse.nodes(): + src = defuse.get_node_target(node) + if not src.is_int(): + continue + if expr_has_call(src): + continue + if node.var.is_mem(): + continue + to_replace[node.var] = src + node_to_reg[node] = node.var + return node_to_reg, to_replace, defuse + + def propagation_allowed(self, ssa, to_replace, node_a, node_b): + """ + Propagating ExprInt is always ok + """ + return True + + +class PropagateThroughExprMem(object): + """ + Propagate through ExprMem in very simple cases: + - if no memory write between source and target + - if source does not contain any memory reference + """ + + def propagate(self, ssa, head, max_expr_depth=None): + ircfg = ssa.graph + todo = set() + modified = False + for block in ircfg.blocks.itervalues(): + for i, assignblk in enumerate(block): + for dst, src in assignblk.iteritems(): + if not dst.is_mem(): + continue + if expr_has_mem(src): + continue + todo.add((block.loc_key, i + 1, dst, src)) + ptr = dst.ptr + for size in xrange(8, dst.size, 8): + todo.add((block.loc_key, i + 1, ExprMem(ptr, size), src[:size])) + + while todo: + loc_key, index, mem_dst, mem_src = todo.pop() + block = ircfg.blocks[loc_key] + assignblks = list(block) + block_modified = False + for i in xrange(index, len(block)): + assignblk = block[i] + write_mem = False + assignblk_modified = False + out = dict(assignblk) + out_new = {} + for dst, src in out.iteritems(): + if dst.is_mem(): + write_mem = True + if dst != mem_dst and mem_dst in dst: + dst = dst.replace_expr({mem_dst:mem_src}) + if mem_dst in src: + src = src.replace_expr({mem_dst:mem_src}) + out_new[dst] = src + if out != out_new: + assignblk_modified = True + + if assignblk_modified: + assignblks[i] = AssignBlock(out_new, assignblk.instr) + block_modified = True + if write_mem: + break + else: + # If no memory written, we may propagate to sons + # if son has only parent + for successor in ircfg.successors(loc_key): + predecessors = ircfg.predecessors(successor) + if len(predecessors) != 1: + continue + todo.add((successor, 0, mem_dst, mem_src)) + + if block_modified: + modified = True + new_block = IRBlock(block.loc_key, assignblks) + ircfg.blocks[block.loc_key] = new_block return modified @@ -971,7 +1087,7 @@ def load_from_int(ir_arch, bs, is_addr_ro_variable): """ modified = False - for label, block in ir_arch.blocks.iteritems(): + for block in ir_arch.blocks.itervalues(): assignblks = list() for assignblk in block: out = {} diff --git a/miasm2/analysis/simplifier.py b/miasm2/analysis/simplifier.py new file mode 100644 index 00000000..ca8e74fb --- /dev/null +++ b/miasm2/analysis/simplifier.py @@ -0,0 +1,303 @@ +""" +Apply simplification passes to an IR cfg +""" + +import logging +from functools import wraps +from miasm2.analysis.ssa import SSADiGraph +from miasm2.analysis.outofssa import UnSSADiGraph +from miasm2.analysis.data_flow import DiGraphLivenessSSA +from miasm2.expression.simplifications import expr_simp +from miasm2.analysis.data_flow import dead_simp, \ + merge_blocks, remove_empty_assignblks, \ + PropagateExprIntThroughExprId, PropagateThroughExprId, \ + PropagateThroughExprMem, del_unused_edges + + +log = logging.getLogger("simplifier") +console_handler = logging.StreamHandler() +console_handler.setFormatter(logging.Formatter("%(levelname)-5s: %(message)s")) +log.addHandler(console_handler) +log.setLevel(logging.WARNING) + + +def fix_point(func): + @wraps(func) + def ret_func(self, ircfg, head): + log.debug('[%s]: start', func.func_name) + has_been_modified = False + modified = True + while modified: + modified = func(self, ircfg, head) + has_been_modified |= modified + log.debug( + '[%s]: stop %r', + func.func_name, + has_been_modified + ) + return has_been_modified + return ret_func + + +class IRCFGSimplifier(object): + """ + Simplify an IRCFG + This class applies passes until reaching a fix point + """ + + def __init__(self, ir_arch): + self.ir_arch = ir_arch + self.init_passes() + + def init_passes(self): + """ + Init the array of simplification passes + """ + self.passes = [] + + @fix_point + def simplify(self, ircfg, head): + """ + Apply passes until reaching a fix point + Return True if the graph has been modified + + @ircfg: IRCFG instance to simplify + @head: Location instance of the ircfg head + """ + modified = False + for simplify_pass in self.passes: + modified |= simplify_pass(ircfg, head) + return modified + + def __call__(self, ircfg, head): + return self.simplify(ircfg, head) + + +class IRCFGSimplifierCommon(IRCFGSimplifier): + """ + Simplify an IRCFG + This class applies following passes until reaching a fix point: + - simplify_ircfg + - do_dead_simp_ircfg + """ + def __init__(self, ir_arch, expr_simp=expr_simp): + self.expr_simp = expr_simp + super(IRCFGSimplifierCommon, self).__init__(ir_arch) + + def init_passes(self): + self.passes = [ + self.simplify_ircfg, + self.do_dead_simp_ircfg, + ] + + @fix_point + def simplify_ircfg(self, ircfg, _head): + """ + Apply self.expr_simp on the @ircfg until reaching fix point + Return True if the graph has been modified + + @ircfg: IRCFG instance to simplify + """ + modified = ircfg.simplify(self.expr_simp) + return modified + + @fix_point + def do_dead_simp_ircfg(self, ircfg, head): + """ + Apply: + - dead_simp + - remove_empty_assignblks + - merge_blocks + on the @ircfg until reaching fix point + Return True if the graph has been modified + + @ircfg: IRCFG instance to simplify + @head: Location instance of the ircfg head + """ + modified = dead_simp(self.ir_arch, ircfg) + modified |= remove_empty_assignblks(ircfg) + modified |= merge_blocks(ircfg, set([head])) + return modified + + +class IRCFGSimplifierSSA(IRCFGSimplifierCommon): + """ + Simplify an IRCFG. + The IRCF is first transformed in SSA, then apply transformations passes + and apply out-of-ssa. Final passes of IRcfgSimplifier are applied + + This class apply following pass until reaching a fix point: + - do_propagate_int + - do_propagate_mem + - do_propagate_expr + - do_dead_simp_ssa + """ + + def __init__(self, ir_arch, expr_simp=expr_simp): + super(IRCFGSimplifierSSA, self).__init__(ir_arch, expr_simp) + + self.ir_arch.ssa_var = {} + self.all_ssa_vars = {} + + self.ssa_forbidden_regs = self.get_forbidden_regs() + + self.propag_int = PropagateExprIntThroughExprId() + self.propag_expr = PropagateThroughExprId() + self.propag_mem = PropagateThroughExprMem() + + def get_forbidden_regs(self): + """ + Return a set of immutable register during SSA transformation + """ + regs = set( + [ + self.ir_arch.pc, + self.ir_arch.IRDst, + self.ir_arch.arch.regs.exception_flags + ] + ) + return regs + + def init_passes(self): + """ + Init the array of simplification passes + """ + self.passes = [ + self.simplify_ssa, + self.do_propagate_int, + self.do_propagate_mem, + self.do_propagate_expr, + self.do_dead_simp_ssa, + ] + + def ircfg_to_ssa(self, ircfg, head): + """ + Apply the SSA transformation to @ircfg using it's @head + + @ircfg: IRCFG instance to simplify + @head: Location instance of the ircfg head + """ + ssa = SSADiGraph(ircfg) + ssa.immutable_ids.update(self.ssa_forbidden_regs) + ssa.ssa_variable_to_expr.update(self.all_ssa_vars) + ssa.transform(head) + self.all_ssa_vars.update(ssa.ssa_variable_to_expr) + self.ir_arch.ssa_var.update(ssa.ssa_variable_to_expr) + return ssa + + def ssa_to_unssa(self, ssa, head): + """ + Apply the out-of-ssa transformation to @ssa using it's @head + + @ssa: SSADiGraph instance + @head: Location instance of the graph head + """ + cfg_liveness = DiGraphLivenessSSA(ssa.graph) + cfg_liveness.init_var_info(self.ir_arch) + cfg_liveness.compute_liveness() + + UnSSADiGraph(ssa, head, cfg_liveness) + return ssa.graph + + @fix_point + def simplify_ssa(self, ssa, _head): + """ + Apply self.expr_simp on the @ssa.graph until reaching fix point + Return True if the graph has been modified + + @ssa: SSADiGraph instance + """ + modified = ssa.graph.simplify(self.expr_simp) + return modified + + @fix_point + def do_propagate_int(self, ssa, head): + """ + Constant propagation in the @ssa graph + @head: Location instance of the graph head + """ + modified = self.propag_int.propagate(ssa, head) + modified |= ssa.graph.simplify(self.expr_simp) + modified |= del_unused_edges(ssa.graph, set([head])) + return modified + + @fix_point + def do_propagate_mem(self, ssa, head): + """ + Propagation of expression based on ExprInt/ExprId in the @ssa graph + @head: Location instance of the graph head + """ + modified = self.propag_mem.propagate(ssa, head) + modified |= ssa.graph.simplify(self.expr_simp) + modified |= del_unused_edges(ssa.graph, set([head])) + return modified + + @fix_point + def do_propagate_expr(self, ssa, head): + """ + Expressions propagation through ExprId in the @ssa graph + @head: Location instance of the graph head + """ + modified = self.propag_expr.propagate(ssa, head) + modified |= ssa.graph.simplify(self.expr_simp) + modified |= del_unused_edges(ssa.graph, set([head])) + return modified + + @fix_point + def do_dead_simp_ssa(self, ssa, head): + """ + Apply: + - dead_simp + - remove_empty_assignblks + - del_unused_edges + - merge_blocks + on the @ircfg until reaching fix point + Return True if the graph has been modified + + @ircfg: IRCFG instance to simplify + @head: Location instance of the ircfg head + """ + modified = dead_simp(self.ir_arch, ssa.graph) + modified |= remove_empty_assignblks(ssa.graph) + modified |= del_unused_edges(ssa.graph, set([head])) + modified |= merge_blocks(ssa.graph, set([head])) + return modified + + def do_simplify(self, ssa, head): + """ + Apply passes until reaching a fix point + Return True if the graph has been modified + """ + return super(IRCFGSimplifierSSA, self).simplify(ssa, head) + + def do_simplify_loop(self, ssa, head): + """ + Apply do_simplify until reaching a fix point + SSA is updated between each do_simplify + Return True if the graph has been modified + """ + modified = True + while modified: + modified = self.do_simplify(ssa, head) + # Update ssa structs + ssa = self.ircfg_to_ssa(ssa.graph, head) + return ssa + + def simplify(self, ircfg, head): + """ + Apply SSA transformation to @ircfg + Apply passes until reaching a fix point + Apply out-of-ssa transformation + Apply post simplification passes + + Updated simplified IRCFG instance and return it + + @ircfg: IRCFG instance to simplify + @head: Location instance of the ircfg head + """ + ssa = self.ircfg_to_ssa(ircfg, head) + ssa = self.do_simplify_loop(ssa, head) + ircfg = self.ssa_to_unssa(ssa, head) + ircfg_simplifier = IRCFGSimplifierCommon(self.ir_arch) + ircfg_simplifier.simplify(ircfg, head) + return ircfg diff --git a/miasm2/analysis/ssa.py b/miasm2/analysis/ssa.py index 5e1a872b..036d92ca 100644 --- a/miasm2/analysis/ssa.py +++ b/miasm2/analysis/ssa.py @@ -595,10 +595,11 @@ class SSADiGraph(SSA): # Replace non modified node used in phi with new variable self.ircfg.simplify(lambda expr:expr.replace_expr(var_to_newname)) - irblock = self.ircfg.blocks[head] - assignblks = list(irblock) - assignblks[0:0] = [AssignBlock(newname_to_var, assignblks[0].instr)] - self.ircfg.blocks[head] = IRBlock(head, assignblks) + if newname_to_var: + irblock = self.ircfg.blocks[head] + assignblks = list(irblock) + assignblks[0:0] = [AssignBlock(newname_to_var, assignblks[0].instr)] + self.ircfg.blocks[head] = IRBlock(head, assignblks) # Updt structure for loc_key in self._phinodes: diff --git a/test/analysis/unssa.py b/test/analysis/unssa.py index ae9566ee..a796f3b6 100644 --- a/test/analysis/unssa.py +++ b/test/analysis/unssa.py @@ -1,14 +1,10 @@ """ Test cases for dead code elimination""" -from pdb import pm -from pprint import pprint as pp from miasm2.expression.expression import ExprId, ExprInt, ExprAssign, ExprMem, \ - ExprCond, ExprOp, ExprLoc + ExprCond, ExprLoc from miasm2.core.locationdb import LocationDB -from miasm2.analysis.data_flow import DiGraphLivenessSSA, dead_simp, PropagateExpr +from miasm2.analysis.simplifier import IRCFGSimplifierSSA from miasm2.ir.analysis import ira from miasm2.ir.ir import IRCFG, IRBlock, AssignBlock -from miasm2.analysis.ssa import SSADiGraph -from miasm2.analysis.outofssa import UnSSADiGraph loc_db = LocationDB() @@ -595,6 +591,18 @@ def add_out_reg_end(ir_arch_a, ircfg_a): ir_arch_a = IRAOutRegs(loc_db) +class CustomIRCFGSimplifierSSA(IRCFGSimplifierSSA): + def get_forbidden_regs(self): + """ + Return a set of immutable register during SSA transformation + """ + regs = set( + [ + self.ir_arch.pc, + self.ir_arch.IRDst, + ] + ) + return regs for test_nb, ircfg in enumerate( [ @@ -620,34 +628,8 @@ for test_nb, ircfg in enumerate( # SSA head = LBL0 - ssa = SSADiGraph(ircfg) - ssa.transform(head) - - ir_arch_a.ssa_var = ssa.ssa_variable_to_expr - dead_simp(ir_arch_a, ssa.graph) - - open("ssa_%d.dot" % test_nb, "wb").write(ssa.graph.dot()) - - - - # Un SSA - ir_arch_a.ssa_var = ssa.ssa_variable_to_expr - - propagate_expr = PropagateExpr() - modified = True - while modified: - modified = False - modified |= propagate_expr.propagate(ssa, head) - - open('tmp_%d.dot' % test_nb, 'w').write(ssa.graph.dot()) - - cfg_liveness = DiGraphLivenessSSA(ssa.graph) - cfg_liveness.init_var_info(ir_arch_a) - cfg_liveness.compute_liveness() - - open('liveness_%d.dot' % test_nb, 'w').write(cfg_liveness.dot()) - - unssa = UnSSADiGraph(ssa, head, cfg_liveness) - open('final_%d.dot' % test_nb, 'w').write(unssa.ssa.graph.dot()) + simplifier = CustomIRCFGSimplifierSSA(ir_arch_a) + ircfg = simplifier(ircfg, head) + open('final_%d.dot' % test_nb, 'w').write(ircfg.dot()) # XXX TODO: add real regression test -- cgit 1.4.1 From a5c34babbf50a22718e1910b36cf2f6a0b2f991d Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Thu, 7 Feb 2019 16:53:12 +0100 Subject: Use AssignblkNode --- miasm2/analysis/data_flow.py | 49 ++++++++++++++++++++++---------------------- 1 file changed, 25 insertions(+), 24 deletions(-) (limited to 'miasm2/analysis/data_flow.py') diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index fb09a6cb..c965e463 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -656,42 +656,40 @@ class PropagateThroughExprId(object): return True return False - def is_mem_written(self, ssa, node, successor): + def is_mem_written(self, ssa, node_a, node_b): """ - Return True if memory is written at least once between @node and - @successor + Return True if memory is written at least once between @node_a and + @node_b - @node: Location of the block to start with - @successor: Location of last block + @node: AssignblkNode representing the start position + @successor: AssignblkNode representing the end position """ - loc_a, index_a, reg_a = node - loc_b, index_b, reg_b = successor - block_b = ssa.graph.blocks[loc_b] - nodes_to_do = self.compute_reachable_nodes_from_a_to_b(ssa.graph, loc_a, loc_b) + block_b = ssa.graph.blocks[node_b.label] + nodes_to_do = self.compute_reachable_nodes_from_a_to_b(ssa.graph, node_a.label, node_b.label) - if loc_a == loc_b: + if node_a.label == node_b.label: # src is dst - assert nodes_to_do == set([loc_a]) - if self.has_propagation_barrier(block_b.assignblks[index_a:index_b]): + assert nodes_to_do == set([node_a.label]) + if self.has_propagation_barrier(block_b.assignblks[node_a.index:node_b.index]): return True else: - # Check everyone but loc_a and loc_b - for loc in nodes_to_do - set([loc_a, loc_b]): + # Check everyone but node_a.label and node_b.label + for loc in nodes_to_do - set([node_a.label, node_b.label]): block = ssa.graph.blocks[loc] if self.has_propagation_barrier(block.assignblks): return True - # Check loc_a partially - block_a = ssa.graph.blocks[loc_a] - if self.has_propagation_barrier(block_a.assignblks[index_a:]): + # Check node_a.label partially + block_a = ssa.graph.blocks[node_a.label] + if self.has_propagation_barrier(block_a.assignblks[node_a.index:]): return True - if nodes_to_do.intersection(ssa.graph.successors(loc_b)): - # There is a path from loc_b to loc_b => Check loc_b fully + if nodes_to_do.intersection(ssa.graph.successors(node_b.label)): + # There is a path from node_b.label to node_b.label => Check node_b.label fully if self.has_propagation_barrier(block_b.assignblks): return True else: - # Check loc_b partially - if self.has_propagation_barrier(block_b.assignblks[:index_b]): + # Check node_b.label partially + if self.has_propagation_barrier(block_b.assignblks[:node_b.index]): return True return False @@ -702,10 +700,13 @@ class PropagateThroughExprId(object): def propagation_allowed(self, ssa, to_replace, node_a, node_b): """ - Return True if we can replace @node source into @node_b + Return True if we can replace @node_a source present in @to_replace into + @node_b + + @node_a: AssignblkNode position + @node_b: AssignblkNode position """ - loc_a, index_a, reg_a = node_a - if not expr_has_mem(to_replace[reg_a]): + if not expr_has_mem(to_replace[node_a.var]): return True if self.is_mem_written(ssa, node_a, node_b): return False -- cgit 1.4.1 From 2d7b38576c49bd4b2e23e0a45faa0287b7042e77 Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Fri, 8 Feb 2019 10:50:30 +0100 Subject: Data flow: propagate phi with identical sources --- miasm2/analysis/data_flow.py | 50 +++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 47 insertions(+), 3 deletions(-) (limited to 'miasm2/analysis/data_flow.py') diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index c965e463..e6c330f6 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -712,7 +712,47 @@ class PropagateThroughExprId(object): return False return True + + def get_var_definitions(self, ssa): + """ + Return a dictionary linking variable to its assignment location + @ssa: SSADiGraph instance + """ + ircfg = ssa.graph + def_dct = {} + for node in ircfg.nodes(): + for index, assignblk in enumerate(ircfg.blocks[node]): + for dst, src in assignblk.iteritems(): + if not dst.is_id(): + continue + if dst in ssa.immutable_ids: + continue + assert dst not in def_dct + def_dct[dst] = node, index + return def_dct + + def phi_has_identical_sources(self, ssa, def_dct, var): + """ + If phi operation has identical source values, return it; else None + @ssa: SSADiGraph instance + @def_dct: dictionary linking variable to its assignment location + @var: Phi destination variable + """ + loc_key, index = def_dct[var] + sources = ssa.graph.blocks[loc_key][index][var] + assert sources.is_op('Phi') + sources_values = set() + for src in sources.args: + assert src in def_dct + loc_key, index = def_dct[src] + value = ssa.graph.blocks[loc_key][index][src] + sources_values.add(value) + if len(sources_values) != 1: + return None + return list(sources_values)[0] + def get_candidates(self, ssa, head, max_expr_depth): + def_dct = self.get_var_definitions(ssa) defuse = SSADefUse.from_ssa(ssa) to_replace = {} node_to_reg = {} @@ -720,13 +760,17 @@ class PropagateThroughExprId(object): if node.var in ssa.immutable_ids: continue src = defuse.get_node_target(node) - if expr_has_call(src): + if max_expr_depth is not None and len(str(src)) > max_expr_depth: continue - if src.is_op('Phi'): + if expr_has_call(src): continue if node.var.is_mem(): continue - if max_expr_depth is not None and len(str(src)) > max_expr_depth: + if src.is_op('Phi'): + ret = self.phi_has_identical_sources(ssa, def_dct, node.var) + if ret: + to_replace[node.var] = ret + node_to_reg[node] = node.var continue to_replace[node.var] = src node_to_reg[node] = node.var -- cgit 1.4.1 From 087f9f0998563914745f5b8b26e1c7b63e3ab84c Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Fri, 8 Feb 2019 17:50:34 +0100 Subject: Merge blocks: don't create predecessors for heads --- miasm2/analysis/data_flow.py | 39 +++++++++++++++++++++++++++++---------- test/ir/reduce_graph.py | 41 +++++++++++++++++++++++++++++++++++------ 2 files changed, 64 insertions(+), 16 deletions(-) (limited to 'miasm2/analysis/data_flow.py') diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index e6c330f6..446d09be 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -292,6 +292,7 @@ def _test_merge_next_block(ircfg, loc_key): return None if son not in ircfg.blocks: return None + return son @@ -329,14 +330,16 @@ def _do_merge_blocks(ircfg, loc_key, son_loc_key): ircfg.blocks[loc_key] = new_block -def _test_jmp_only(ircfg, loc_key): +def _test_jmp_only(ircfg, loc_key, heads): """ If irblock at @loc_key sets only IRDst to an ExprLoc, return the corresponding loc_key target. + Avoid creating predecssors for heads LocKeys None in other cases. @ircfg: IRCFG instance @loc_key: LocKey instance of the candidate irblock + @heads: LocKey heads of the graph """ @@ -348,11 +351,20 @@ def _test_jmp_only(ircfg, loc_key): items = dict(irblock.assignblks[0]).items() if len(items) != 1: return None + if len(ircfg.successors(loc_key)) != 1: + return None + # Don't create predecessors on heads dst, src = items[0] assert dst.is_id("IRDst") if not src.is_loc(): return None - return src.loc_key + dst = src.loc_key + if loc_key in heads: + predecessors = set(ircfg.predecessors(dst)) + predecessors.difference_update(set([loc_key])) + if predecessors: + return None + return dst def _relink_block_node(ircfg, loc_key, son_loc_key, replace_dct): @@ -397,7 +409,6 @@ def _remove_to_son(ircfg, loc_key, son_loc_key): # Unlink block destinations ircfg.del_edge(loc_key, son_loc_key) - del ircfg.blocks[loc_key] replace_dct = { ExprLoc(loc_key, ircfg.IRDst.size):ExprLoc(son_loc_key, ircfg.IRDst.size) @@ -405,6 +416,9 @@ def _remove_to_son(ircfg, loc_key, son_loc_key): _relink_block_node(ircfg, loc_key, son_loc_key, replace_dct) + ircfg.del_node(loc_key) + del ircfg.blocks[loc_key] + return True @@ -434,7 +448,6 @@ def _remove_to_parent(ircfg, loc_key, son_loc_key): ircfg.blocks[son_loc_key] = new_irblock - del ircfg.blocks[son_loc_key] ircfg.add_irblock(new_irblock) replace_dct = { @@ -443,10 +456,14 @@ def _remove_to_parent(ircfg, loc_key, son_loc_key): _relink_block_node(ircfg, son_loc_key, loc_key, replace_dct) + + ircfg.del_node(son_loc_key) + del ircfg.blocks[son_loc_key] + return True -def merge_blocks(ircfg, loc_key_entries): +def merge_blocks(ircfg, heads): """ This function modifies @ircfg to apply the following transformations: - group an irblock with its son if the irblock has one and only one son and @@ -458,10 +475,12 @@ def merge_blocks(ircfg, loc_key_entries): IRDst with a given label, this irblock is dropped and its son becomes the head. References are fixed + This function avoid creating predecessors on heads + Return True if at least an irblock has been modified @ircfg: IRCFG instance - @loc_key_entries: loc_key to keep + @heads: loc_key to keep """ modified = False @@ -471,15 +490,15 @@ def merge_blocks(ircfg, loc_key_entries): # Test merge block son = _test_merge_next_block(ircfg, loc_key) - if son is not None and son not in loc_key_entries: + if son is not None and son not in heads: _do_merge_blocks(ircfg, loc_key, son) todo.add(loc_key) modified = True continue # Test jmp only block - son = _test_jmp_only(ircfg, loc_key) - if son is not None and loc_key not in loc_key_entries: + son = _test_jmp_only(ircfg, loc_key, heads) + if son is not None and loc_key not in heads: ret = _remove_to_son(ircfg, loc_key, son) modified |= ret if ret: @@ -488,7 +507,7 @@ def merge_blocks(ircfg, loc_key_entries): # Test head jmp only block if (son is not None and - son not in loc_key_entries and + son not in heads and son in ircfg.blocks): # jmp only test done previously ret = _remove_to_parent(ircfg, loc_key, son) diff --git a/test/ir/reduce_graph.py b/test/ir/reduce_graph.py index 29a3501f..75ff3410 100644 --- a/test/ir/reduce_graph.py +++ b/test/ir/reduce_graph.py @@ -319,19 +319,29 @@ G4_RES = IRA.new_ircfg() G4_RES_IRB0 = gen_irblock( LBL0, + [ + [ + ExprAssign(IRDst, ExprLoc(LBL1, 32)), + ] + ] +) + + +G4_RES_IRB1 = gen_irblock( + LBL1, [ [ ExprAssign(A, C), ], [ ExprAssign(D, A), - ExprAssign(IRDst, ExprLoc(LBL0, 32)), + ExprAssign(IRDst, ExprLoc(LBL1, 32)), ] ] ) -for irb in [G4_RES_IRB0 ]: +for irb in [G4_RES_IRB0, G4_RES_IRB1 ]: G4_RES.add_irblock(irb) @@ -389,15 +399,25 @@ for irb in [G5_IRB0, G5_IRB1, G5_IRB2, G5_IRB3]: # Result G5_RES = IRA.new_ircfg() + G5_RES_IRB0 = gen_irblock( LBL0, + [ + [ + ExprAssign(IRDst, ExprLoc(LBL1, 32)), + ] + ] +) + +G5_RES_IRB1 = gen_irblock( + LBL1, [ [ ExprAssign(A, C), ], [ ExprAssign(D, A), - ExprAssign(IRDst, ExprCond(C, ExprLoc(LBL0, 32), ExprLoc(LBL3, 32))), + ExprAssign(IRDst, ExprCond(C, ExprLoc(LBL1, 32), ExprLoc(LBL3, 32))), ] ] ) @@ -413,7 +433,7 @@ G5_RES_IRB3 = gen_irblock( ] ) -for irb in [G5_RES_IRB0, G5_RES_IRB3 ]: +for irb in [G5_RES_IRB0, G5_RES_IRB1, G5_RES_IRB3 ]: G5_RES.add_irblock(irb) @@ -603,16 +623,25 @@ G8_RES = IRA.new_ircfg() G8_RES_IRB0 = gen_irblock( LBL0, + [ + [ + ExprAssign(IRDst, ExprLoc(LBL1, 32)), + ] + ] +) + +G8_RES_IRB1 = gen_irblock( + LBL1, [ [ ExprAssign(A, C), - ExprAssign(IRDst, ExprLoc(LBL0, 32)), + ExprAssign(IRDst, ExprLoc(LBL1, 32)), ] ] ) -for irb in [G8_RES_IRB0]: +for irb in [G8_RES_IRB0, G8_RES_IRB1]: G8_RES.add_irblock(irb) -- cgit 1.4.1 From 79a2ab0f9c54abdd586c3cd65268ba37743ff800 Mon Sep 17 00:00:00 2001 From: Fabrice Desclaux Date: Tue, 12 Feb 2019 07:19:38 +0100 Subject: Fix has_call test --- miasm2/analysis/data_flow.py | 24 +++--------------------- 1 file changed, 3 insertions(+), 21 deletions(-) (limited to 'miasm2/analysis/data_flow.py') diff --git a/miasm2/analysis/data_flow.py b/miasm2/analysis/data_flow.py index 446d09be..dc72d06a 100644 --- a/miasm2/analysis/data_flow.py +++ b/miasm2/analysis/data_flow.py @@ -639,24 +639,6 @@ def expr_has_mem(expr): return expr_test_visit(expr, expr_has_mem_test) -def expr_has_call_test(expr, result): - if result: - # Don't analyse if we already found a candidate - return False - if expr.is_op() and expr.op.startswith("call"): - result.add(expr) - return False - return True - - -def expr_has_call(expr): - """ - Return True if expr contains at least one "call" operator - @expr: Expr instance - """ - return expr_test_visit(expr, expr_has_call_test) - - class PropagateThroughExprId(object): """ Propagate expressions though ExprId @@ -669,7 +651,7 @@ class PropagateThroughExprId(object): """ for assignblk in assignblks: for dst, src in assignblk.iteritems(): - if expr_has_call(src): + if src.is_function_call(): return True if dst.is_mem(): return True @@ -781,7 +763,7 @@ class PropagateThroughExprId(object): src = defuse.get_node_target(node) if max_expr_depth is not None and len(str(src)) > max_expr_depth: continue - if expr_has_call(src): + if src.is_function_call(): continue if node.var.is_mem(): continue @@ -866,7 +848,7 @@ class PropagateExprIntThroughExprId(PropagateThroughExprId): src = defuse.get_node_target(node) if not src.is_int(): continue - if expr_has_call(src): + if src.is_function_call(): continue if node.var.is_mem(): continue -- cgit 1.4.1