diff options
| author | Jordan Wiens <jordan@psifertex.com> | 2020-04-28 04:17:12 -0400 |
|---|---|---|
| committer | Jordan Wiens <jordan@psifertex.com> | 2020-04-28 04:22:32 -0400 |
| commit | 40071b015d7ba28842d64bb783168914d058b8d8 (patch) | |
| tree | a9e7bdb02e4e4841bdae2f1eece2d1a2dab3a591 /docs/dev/bnil-llil.md | |
| parent | 966fd878a020263af0a7a190cd981a75bfeec45d (diff) | |
adding BNIL overview
Diffstat (limited to 'docs/dev/bnil-llil.md')
| -rw-r--r-- | docs/dev/bnil-llil.md | 10 |
1 files changed, 6 insertions, 4 deletions
diff --git a/docs/dev/bnil-llil.md b/docs/dev/bnil-llil.md index 60beb3db..608c5e82 100644 --- a/docs/dev/bnil-llil.md +++ b/docs/dev/bnil-llil.md @@ -1,6 +1,8 @@ # Binary Ninja Intermediate Language Series, Part 1: Low Level IL -The Binary Ninja Intermediate Language (BNIL) is a semantic representation of the assembly language instructions for a native architecture in Binary Ninja. BNIL is actually a family of intermediate languages that work together to provide functionality at different abstraction layers. This developer guide is intended to cover some of the mechanics of the LLIL to distinguish it from the other ILs in the BNIL family. +Make sure to checkout the [BNIL overview](bnil-overview.md) first if you haven't already. Or feel free to skip to [part 2](bnil-mlil.md) which covers MLIL. This developer guide is intended to cover some of the mechanics of the LLIL to distinguish it from the other ILs in the BNIL family. + +If you've already read the introduction, let's get right into the details of LLIL!  @@ -131,7 +133,7 @@ For the above instruction, we have a few operations we can perform: 'rsp' ``` -* **size** - returns the size of the operation in bytes (in this case we have an 8 byte assigment) +* **size** - returns the size of the operation in bytes (in this case we have an 8 byte assignment) ``` >>> instr.size @@ -182,7 +184,7 @@ Reading and writing memory is accomplished through the following instructions. ### Control Flow & Conditionals -Control flow transfering- and comparison instructions are straightforward enough, but one instruction that deserves more attention is the `if` instruction. To understand the `if` instruction we need to first understand the concept of labels. +Control flow transferring- and comparison instructions are straightforward enough, but one instruction that deserves more attention is the `if` instruction. To understand the `if` instruction we need to first understand the concept of labels. Labels function much like they do in C code. They can be put anywhere in the emitted IL and serve as a destination for the `if` and `goto` instructions. Labels are required because one assembly language instruction can translate to multiple IL instructions, and you need to be able to branch to any of the emitted IL instructions. Let's consider the following x86 instruction `cmove` (Conditional move if equal flag is set): @@ -199,7 +201,7 @@ To translate this instruction to IL we have to first create true and false label 2 @ 00000002 goto 3 ``` -As you can see from the above code, labels are really just used internaly and aren't explicitly marked. In addition to `if` and `goto`, the `jump_to` IL instruction is the only other instruction that operates on labels. The rest of the IL control flow instructions operate on addresses rather than labels, much like actual assembly language instructions. Note that an architecture plugin author should not be emitting `jump_to` IL instructions as those are generated by the analysis automatically. +As you can see from the above code, labels are really just used internally and aren't explicitly marked. In addition to `if` and `goto`, the `jump_to` IL instruction is the only other instruction that operates on labels. The rest of the IL control flow instructions operate on addresses rather than labels, much like actual assembly language instructions. Note that an architecture plugin author should not be emitting `jump_to` IL instructions as those are generated by the analysis automatically. * **`LLIL_JUMP`** - Branch execution to the result of the IL operation. * **`LLIL_JUMP_TO`** - Jump table construct, contains an expression and list of possible targets. |
