[{"data":1,"prerenderedAt":45},["ShallowReactive",2],{"publications-liblisa-oopsla24":3,"papers-liblisa-oopsla24-08-bibliography":32},{"id":4,"title":5,"authors":6,"awards":7,"bibtex":8,"body":9,"date":20,"description":15,"extension":21,"link":22,"meta":23,"navigation":24,"path":25,"pdf":26,"seo":27,"slug":28,"stem":29,"venue":30,"__hash__":31},"publications\u002Fpublications\u002Fliblisa-oopsla24.md","libLISA: Instruction Discovery and Analysis on x86-64","Jos Craaijo, Freek Verbeek, Binoy Ravindran",null,"@article{craaijo2024liblisa,\n  author = {Craaijo, Jos and Verbeek, Freek and Ravindran, Binoy},\n  title = {libLISA: Instruction Discovery and Analysis on x86-64},\n  year = {2024},\n  issue_date = {October 2024},\n  publisher = {Association for Computing Machinery},\n  address = {New York, NY, USA},\n  volume = {8},\n  number = {OOPSLA2},\n  url = {https:\u002F\u002Fdoi.org\u002F10.1145\u002F3689723},\n  doi = {10.1145\u002F3689723},\n  journal = {Proc. ACM Program. Lang.},\n  month = oct,\n  articleno = {283},\n  numpages = {29},\n  keywords = {instruction semantics, instruction enumeration, synthesis}\n}\n",{"type":10,"value":11,"toc":16},"minimark",[12],[13,14,15],"p",{},"Even though heavily researched, a full formal model of the x86-64 instruction set is still not available. We present libLISA, a tool for automated discovery and analysis of the ISA of a CPU. This produces the most extensive formal x86-64 model to date, with over 118000 different instruction groups. The process requires as little human specification as possible: specifically, we do not rely on a human-written (dis)assembler to dictate which instructions are executable on a given CPU, or what their in- and outputs are. The generated model is CPU-specific: behavior that is “undefined” is synthesized for the current machine. Producing models for five different x86-64 machines, we mutually compare them, discover undocumented instructions, and generate instruction sequences that are CPU-specific. Experimental evaluation shows that we enumerate virtually all instructions within scope, that the instructions’ semantics are correct w.r.t. existing work, and that we improve existing work by exposing bugs in their handwritten models.",{"title":17,"searchDepth":18,"depth":18,"links":19},"",2,[],"2024-10-20","md","https:\u002F\u002F2024.splashcon.org\u002Ftrack\u002Fsplash-2024-oopsla#event-overview",{},true,"\u002Fpublications\u002Fliblisa-oopsla24","\u002Ffiles\u002Fliblisa2024.pdf",{"title":5,"description":15},"liblisa-oopsla24","publications\u002Fliblisa-oopsla24","OOPSLA'24","d-2xqRiGEx9J763VU4sUFN1PvG_NX8MmqYk4AdsbW9Y",{"id":33,"title":34,"body":7,"date":7,"description":7,"extension":35,"html":36,"meta":37,"navigation":24,"next":7,"path":38,"previous":39,"seo":42,"slug":7,"stem":43,"__hash__":44},"papers\u002Fpublications\u002Fliblisa-oopsla24\u002F08-bibliography.html","Acknowledgements, Data-availabilty and References","html","\u003Cstyle>\u002F* Alignment *\u002F\nmtable.right-align mtd,\nmtable mtd.right-align,\nmtable.left-align mtd.right-align,\nmtable.aligned mtd:nth-child(odd) {\n  justify-items: end;\n  text-align: right;\n}\nmtable.cases mtd,\nmtable.left-align mtd,\nmtable mtd.left-align,\nmtable.aligned mtd:nth-child(even),\nmath:is(:not([display])) > mtable.multiline-equation mtd {\n  justify-items: start;\n  text-align: left;\n}\nmtable.cases mtd,\nmtable.aligned mtd,\nmtable mtd.flushed,\nmtable mtd.left-flush {\n  padding-left: 0;\n}\nmtable.cases mtd,\nmtable.aligned mtd,\nmtable mtd.flushed,\nmtable mtd.right-flush {\n  padding-right: 0;\n}\n\n\u002F* Tables *\u002F\nmtable {\n  math-style: inherit;\n}\nmtd {\n  math-depth: auto-add;\n  math-style: compact;\n  math-shift: compact;\n}\n\n\u002F* Equations *\u002F\nmtable.multiline-equation mtd {\n  math-depth: inherit;\n  math-style: inherit;\n  math-shift: inherit;\n  padding: 0;\n}\nmath > mtable.multiline-equation mtr:not(:last-child) mtd {\n  padding-bottom: 0.5em;\n}\n\n\u002F* Fractions *\u002F\nmfrac {\n  padding-inline: 0;\n  margin-inline: 0.1em;\n}\n\n\u002F* Accents *\u002F\nmover[accent=\"true\" i] > :first-child {\n  font-feature-settings: \"dtls\";\n}\nmover.dotted[accent=\"true\" i] > :first-child {\n  font-feature-settings: \"dtls\" 0;\n}\n\n\u002F* Other rules for scriptlevel, displaystyle and math-shift *\u002F\nmunder > :nth-child(2),\nmunderover > :nth-child(2) {\n  math-shift: compact\n}\nmunder[accentunder=\"true\" i] > :not(:first-child),\nmover[accent=\"true\" i] > :not(:first-child) {\n  math-depth: inherit;\n  math-style: inherit;\n  math-shift: inherit;\n}\u003C\u002Fstyle>\u003Cdiv id=\"previous-page\" style=\"display: none\">\u003Ca href=\"07-discussion#loc-1\">Discussion\u003C\u002Fa>\u003C\u002Fdiv>\u003Cdiv id=\"next-page\" style=\"display: none\">\u003C\u002Fdiv>\u003Ch2 id=\"loc-1\">7 Acknowledgements, Data-availabilty and References\u003C\u002Fh2>\u003Ch3>7.1 Acknowledgements\u003C\u002Fh3>\u003Cp>We thank the anonymous reviewers for their insightful comments, which have greatly improved the paper.\u003C\u002Fp>\u003Cp>This work is supported by the Defense Advanced Research Projects Agency (DARPA) and Naval Information Warfare Center Pacific (NIWC Pacific) under Contract No. N66001-21-C-4028.\u003C\u002Fp>\u003Ch3>7.2 Data-availability statement\u003C\u002Fh3>\u003Cp>The analysis results are available in an easily browsable format on \u003Ca href=\"https:\u002F\u002Fexplore.liblisa.nl\u002F\">https:\u002F\u002Fexplore.liblisa.nl\u002F\u003C\u002Fa>. The \u003Cspan style=\"font-variant-caps: small-caps\">libLISA\u003C\u002Fspan> implementation is available under the AGPLv3 open source license on \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fliblisa\">https:\u002F\u002Fgithub.com\u002Fliblisa\u003C\u002Fa>. A self-contained reproduction package is available on Zenodo \u003Cspan id=\"loc-2\">[\u003C\u002Fspan>\u003Ca href=\"#loc-30\" role=\"doc-biblioref\">29\u003C\u002Fa>].\u003C\u002Fp>\u003Ch3>7.3 References\u003C\u002Fh3>\u003Csection role=\"doc-bibliography\">\u003Cul style=\"list-style-type: none\">\u003Cli id=\"loc-3\">\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[1]\u003C\u002Fa>\u003C\u002Fspan> S. Dasgupta, D. Park, T. Kasampalis, V. S. Adve, and G. Roşu, “A Complete Formal Semantics of X86-64 User-Level Instruction Set Architecture,” in \u003Cem>Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation\u003C\u002Fem>, in PLDI '19. Phoenix, AZ, USA: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2019, pp. 1133–1148. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F3314221.3314601\">10.1145\u002F3314221.3314601\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-4\">\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[2]\u003C\u002Fa>\u003C\u002Fspan> S. Heule, E. Schkufza, R. Sharma, and A. Aiken, “Stratified synthesis: automatically learning the x86-64 instruction set,” in \u003Cem>Proceedings of the 37th ACM SIGPLAN Conference on Programming Language Design and Implementation\u003C\u002Fem>, in PLDI '16. Santa Barbara, CA, USA: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2016, pp. 237–250. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2908080.2908121\">10.1145\u002F2908080.2908121\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-5\">\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[3]\u003C\u002Fa>\u003C\u002Fspan> X. Leroy, “Formal verification of a realistic compiler,” \u003Cem>Commun. ACM\u003C\u002Fem>, vol. 52, no. 7, pp. 107–115, Jul. 2009, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F1538788.1538814\">10.1145\u002F1538788.1538814\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-6\">\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[4]\u003C\u002Fa>\u003C\u002Fspan> S. Goel, W. A. Hunt, M. Kaufmann, and S. Ghosh, “Simulation and Formal Verification of x86 Machine-Code Programs that make System Calls,” in \u003Cem>Proceedings of the 14th Conference on Formal Methods in Computer-Aided Design\u003C\u002Fem>, in FMCAD '14. Lausanne, Switzerland: FMCAD Inc,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2014, pp. 91–98. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1109\u002FFMCAD.2014.6987600\">10.1109\u002FFMCAD.2014.6987600\u003C\u002Fa>.\u003C\u002Fli>\u003Cli>\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[5]\u003C\u002Fa>\u003C\u002Fspan> N. Hasabnis and R. Sekar, “Extracting instruction semantics via symbolic execution of code generators,” in \u003Cem>Proceedings of the 2016 24th ACM SIGSOFT International Symposium on Foundations of Software Engineering\u003C\u002Fem>, in FSE 2016. Seattle, WA, USA: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2016, pp. 301–313. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2950290.2950335\">10.1145\u002F2950290.2950335\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-7\">\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[6]\u003C\u002Fa>\u003C\u002Fspan> P. Godefroid and A. Taly, “Automated synthesis of symbolic instruction encodings from I\u002FO samples,” in \u003Cem>Proceedings of the 33rd ACM SIGPLAN Conference on Programming Language Design and Implementation\u003C\u002Fem>, in PLDI '12. Beijing, China: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2012, pp. 441–452. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2254064.2254116\">10.1145\u002F2254064.2254116\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-8\">\u003Cspan class=\"prefix\">\u003Ca href=\"01-introduction#loc-1\" role=\"doc-backlink\">[7]\u003C\u002Fa>\u003C\u002Fspan> J. Lim and T. Reps, “TSL: A System for Generating Abstract Interpreters and its Application to Machine-Code Analysis,” \u003Cem>ACM Trans. Program. Lang. Syst.\u003C\u002Fem>, vol. 35, no. 1, Apr. 2013, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2450136.2450139\">10.1145\u002F2450136.2450139\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-9\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-2\" role=\"doc-backlink\">[8]\u003C\u002Fa>\u003C\u002Fspan> C. Domas, “Breaking the x86 ISA.” [Online]. Available: \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fxoreaxeaxeax\u002Fsandsifter\">https:\u002F\u002Fgithub.com\u002Fxoreaxeaxeax\u002Fsandsifter\u003C\u002Fa>\u003C\u002Fli>\u003Cli id=\"loc-10\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-3\" role=\"doc-backlink\">[9]\u003C\u002Fa>\u003C\u002Fspan> X. Li, Z. Wu, Q. Wei, and H. Wu, “UISFuzz: An Efficient Fuzzing Method for CPU Undocumented Instruction Searching,” \u003Cem>IEEE Access\u003C\u002Fem>, vol. 7, no. , pp. 149224–149236, 2019, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1109\u002FACCESS.2019.2946444\">10.1109\u002FACCESS.2019.2946444\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-11\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-4\" role=\"doc-backlink\">[10]\u003C\u002Fa>\u003C\u002Fspan> R. Dofferhoff, M. Göebel, K. Rietveld, and E. van der Kouwe, “iScanU: A Portable Scanner for Undocumented Instructions on RISC Processors,” in \u003Cem>2020 50th Annual IEEE\u002FIFIP International Conference on Dependable Systems and Networks\u003C\u002Fem>, in DSN 2020, .\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2020, pp. 306–317. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1109\u002FDSN48063.2020.00047\">10.1109\u002FDSN48063.2020.00047\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-12\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-5\" role=\"doc-backlink\">[11]\u003C\u002Fa>\u003C\u002Fspan> D. Kwan, K. Shtoyk, K. Serebryany, M. L. Lifantsev, and P. Hochschild, “SiliFuzz: fuzzing CPUs by proxy,” \u003Cem>Google Research\u003C\u002Fem>, 2021, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.48550\u002FarXiv.2110.11519\">10.48550\u002FarXiv.2110.11519\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-13\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-6\" role=\"doc-backlink\">[12]\u003C\u002Fa>\u003C\u002Fspan> L. Martignoni, R. Paleari, G. F. Roglia, and D. Bruschi, “Testing CPU emulators,” in \u003Cem>Proceedings of the Eighteenth International Symposium on Software Testing and Analysis\u003C\u002Fem>, in ISSTA '09. Chicago, IL, USA: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2009, pp. 261–272. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F1572272.1572303\">10.1145\u002F1572272.1572303\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-14\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-7\" role=\"doc-backlink\">[13]\u003C\u002Fa>\u003C\u002Fspan> F. Solt, K. Ceesay-Seitz, and K. Razavi, “Cascade: CPU Fuzzing via Intricate Program Generation,” in \u003Cem>33rd USENIX Security Symposium (USENIX Security 24)\u003C\u002Fem>, Philadelphia, PA: USENIX Association, Aug. 2024, pp. 5341–5358.\u003C\u002Fli>\u003Cli id=\"loc-15\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-9\" role=\"doc-backlink\">[14]\u003C\u002Fa>\u003C\u002Fspan> G. Morrisett, G. Tan, J. Tassarotti, J.-B. Tristan, and E. Gan, “RockSalt: better, faster, stronger SFI for the x86,” in \u003Cem>Proceedings of the 33rd ACM SIGPLAN Conference on Programming Language Design and Implementation\u003C\u002Fem>, in PLDI '12. Beijing, China: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2012, pp. 395–404. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2254064.2254111\">10.1145\u002F2254064.2254111\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-16\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-10\" role=\"doc-backlink\">[15]\u003C\u002Fa>\u003C\u002Fspan> E. Schkufza, R. Sharma, and A. Aiken, “Stochastic superoptimization,” in \u003Cem>Proceedings of the Eighteenth International Conference on Architectural Support for Programming Languages and Operating Systems\u003C\u002Fem>, in ASPLOS '13. Houston, Texas, USA: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2013, pp. 305–316. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2451116.2451150\">10.1145\u002F2451116.2451150\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-17\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-11\" role=\"doc-backlink\">[16]\u003C\u002Fa>\u003C\u002Fspan> C. Barrett, A. Stump, C. Tinelli, and others, “The SMT-LIB Standard: Version 2.0,” in \u003Cem>Proceedings of the 8th international workshop on satisfiability modulo theories (Edinburgh, UK)\u003C\u002Fem>,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2010, p. 14.\u003C\u002Fli>\u003Cli id=\"loc-18\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-13\" role=\"doc-backlink\">[17]\u003C\u002Fa>\u003C\u002Fspan> A. Armstrong \u003Cem>et al.\u003C\u002Fem>, “ISA semantics for ARMv8-a, RISC-v, and CHERI-MIPS,” \u003Cem>Proc. ACM Program. Lang.\u003C\u002Fem>, vol. 3, no. POPL, Jan. 2019, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F3290384\">10.1145\u002F3290384\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-19\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-14\" role=\"doc-backlink\">[18]\u003C\u002Fa>\u003C\u002Fspan> A. Reid, “Trustworthy specifications of ARM® v8-A and v8-M system level architecture,” in \u003Cem>Proceedings of the 16th Conference on Formal Methods in Computer-Aided Design\u003C\u002Fem>, in FMCAD '16. Mountain View, California: FMCAD Inc,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2016, pp. 161–168. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1109\u002FFMCAD.2016.7886675\">10.1109\u002FFMCAD.2016.7886675\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-20\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-15\" role=\"doc-backlink\">[19]\u003C\u002Fa>\u003C\u002Fspan> P. Sewell, S. Sarkar, S. Owens, F. Z. Nardelli, and M. O. Myreen, “x86-TSO: a rigorous and usable programmer's model for x86 multiprocessors,” \u003Cem>Commun. ACM\u003C\u002Fem>, vol. 53, no. 7, pp. 89–97, Jul. 2010, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F1785414.1785443\">10.1145\u002F1785414.1785443\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-21\">\u003Cspan class=\"prefix\">\u003Ca href=\"03-related-work#loc-15\" role=\"doc-backlink\">[20]\u003C\u002Fa>\u003C\u002Fspan> J. Ševčík, V. Vafeiadis, F. Zappa Nardelli, S. Jagannathan, and P. Sewell, “CompCertTSO: A Verified Compiler for Relaxed-Memory Concurrency,” \u003Cem>J. ACM\u003C\u002Fem>, vol. 60, no. 3, Jun. 2013, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2487241.2487248\">10.1145\u002F2487241.2487248\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-22\">\u003Cspan class=\"prefix\">\u003Ca href=\"04-approach#loc-3\" role=\"doc-backlink\">[21]\u003C\u002Fa>\u003C\u002Fspan> A. Barrington, S. Feldman, and D. Dechev, “A scalable multi-producer multi-consumer wait-free ring buffer,” in \u003Cem>Proceedings of the 30th Annual ACM Symposium on Applied Computing\u003C\u002Fem>, in SAC '15. Salamanca, Spain: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2015, pp. 1321–1328. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F2695664.2695924\">10.1145\u002F2695664.2695924\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-23\">\u003Cspan class=\"prefix\">\u003Ca href=\"04-approach#loc-9\" role=\"doc-backlink\">[22]\u003C\u002Fa>\u003C\u002Fspan> N. Jay and B. P. Miller, “Structured random differential testing of instruction decoders,” in \u003Cem>2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER)\u003C\u002Fem>,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2018, pp. 84–94. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1109\u002FSANER.2018.8330199\">10.1109\u002FSANER.2018.8330199\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-24\">\u003Cspan class=\"prefix\">\u003Ca href=\"04-approach#loc-11\" role=\"doc-backlink\">[23]\u003C\u002Fa>\u003C\u002Fspan> A. Solar-Lezama, L. Tancau, R. Bodik, S. Seshia, and V. Saraswat, “Combinatorial sketching for finite programs,” in \u003Cem>Proceedings of the 12th International Conference on Architectural Support for Programming Languages and Operating Systems\u003C\u002Fem>, in ASPLOS XII. San Jose, California, USA: Association for Computing Machinery,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2006, pp. 404–415. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F1168857.1168907\">10.1145\u002F1168857.1168907\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-25\">\u003Cspan class=\"prefix\">\u003Ca href=\"04-approach#loc-11\" role=\"doc-backlink\">[24]\u003C\u002Fa>\u003C\u002Fspan> R. Alur, R. Singh, D. Fisman, and A. Solar-Lezama, “Search-Based Program Synthesis,” \u003Cem>Commun. ACM\u003C\u002Fem>, vol. 61, no. 12, pp. 84–93, Nov. 2018, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1145\u002F3208071\">10.1145\u002F3208071\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-26\">\u003Cspan class=\"prefix\">\u003Ca href=\"04-approach#loc-12\" role=\"doc-backlink\">[25]\u003C\u002Fa>\u003C\u002Fspan> R. Alur, A. Radhakrishna, and A. Udupa, “Scaling Enumerative Program Synthesis via Divide and Conquer,” in \u003Cem>Tools and Algorithms for the Construction and Analysis of Systems\u003C\u002Fem>, A. Legay and T. Margaria, Eds., in TACAS 2017. Berlin, Heidelberg: Springer Berlin Heidelberg,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2017, pp. 319–336. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1007\u002F978-3-662-54577-5_18\">10.1007\u002F978-3-662-54577-5_18\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-27\">\u003Cspan class=\"prefix\">\u003Ca href=\"05-results#loc-6\" role=\"doc-backlink\">[26]\u003C\u002Fa>\u003C\u002Fspan> L. de Moura and N. Bjørner, “Z3: An Efficient SMT Solver,” in \u003Cem>Tools and Algorithms for the Construction and Analysis of Systems\u003C\u002Fem>, C. R. Ramakrishnan and J. Rehof, Eds., in TACAS 2008. Berlin, Heidelberg: Springer Berlin Heidelberg,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2008, pp. 337–340. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1007\u002F978-3-540-78800-3_24\">10.1007\u002F978-3-540-78800-3_24\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-28\">\u003Cspan class=\"prefix\">\u003Ca href=\"05-results#loc-7\" role=\"doc-backlink\">[27]\u003C\u002Fa>\u003C\u002Fspan> G. Roșu and T. F. Șerbănută, “An overview of the K semantic framework,” \u003Cem>The Journal of Logic and Algebraic Programming\u003C\u002Fem>, vol. 79, no. 6, pp. 397–434, 2010, doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002Fhttps:\u002F\u002Fdoi.org\u002F10.1016\u002Fj.jlap.2010.03.012\">https:\u002F\u002Fdoi.org\u002F10.1016\u002Fj.jlap.2010.03.012\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-29\">\u003Cspan class=\"prefix\">\u003Ca href=\"07-discussion#loc-2\" role=\"doc-backlink\">[28]\u003C\u002Fa>\u003C\u002Fspan> D. Brumley, I. Jager, T. Avgerinos, and E. J. Schwartz, “BAP: A Binary Analysis Platform,” in \u003Cem>Computer Aided Verification\u003C\u002Fem>, G. Gopalakrishnan and S. Qadeer, Eds., Berlin, Heidelberg: Springer Berlin Heidelberg,\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2011, pp. 463–469. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.1007\u002F978-3-642-22110-1_37\">10.1007\u002F978-3-642-22110-1_37\u003C\u002Fa>.\u003C\u002Fli>\u003Cli id=\"loc-30\">\u003Cspan class=\"prefix\">\u003Ca href=\"#loc-2\" role=\"doc-backlink\">[29]\u003C\u002Fa>\u003C\u002Fspan> J. Craaijo, F. Verbeek, and B. Ravindran, “Reproduction package (Docker container) for the OOPSLA 2024 Article ``libLISA: Instruction Discovery and Analysis on x86-64'',”\u003Cspan style=\"white-space: pre-wrap\">  \u003C\u002Fspan>2024. doi: \u003Ca href=\"https:\u002F\u002Fdoi.org\u002F10.5281\u002Fzenodo.13380062\">10.5281\u002Fzenodo.13380062\u003C\u002Fa>.\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fsection>",{},"\u002Fpublications\u002Fliblisa-oopsla24\u002F08-bibliography",{"url":40,"title":41},"07-discussion","Discussion",{"title":34},"publications\u002Fliblisa-oopsla24\u002F08-bibliography","N2XTOxDDeSdQIJbNaW6hTQRWulRL_rrBrF680DF0pOk",1787004871381]