Updates
v4.1 ➞ v4.2


Pack

  • Pack is a new transform that encrypts the compiled code of the chosen functions and decrypts it in place at run time; tigress_post performs the at-rest encryption.
  • --PackCiphers chooses the cipher(s): xtea, xor, rc4, feistel, or des.
  • --PackLevels sets how many nested encryption layers each region gets.
  • --PackWhen chooses when a region is decrypted: once at startup or on each call.
  • --PackRepack re-encrypts a region when it returns (with --PackWhen=call).
  • --PackKeySource chooses where the key comes from: literal, folded, or plugin.
  • --PackKeyCodecs encodes the stored key (add, xor, poly1, polyn, lineargf2, bitperm, feistel, or the bit/nibble/byte splits).
  • --PackKeyComposeCodecs composes several key codecs into a chain.
  • --PackDecryptorName names the generated decryptor function.
  • --PackSpecFile names the JSON region spec that tigress_post reads.
  • --PackSections packs whole linker sections instead of individual functions.
  • --PackTrace traces each decrypt and re-encrypt.
  • See Pack.

Machine models

  • --DumpMachineModel prints a built-in target machine model as JSON (current or all) and exits.
  • --LoadMachineModel loads the target machine model from a JSON file, overriding the one chosen from --Environment.
  • --MakeMachineModelGenerator writes a small C program that prints a target's machine model as JSON for --LoadMachineModel.
  • See top-level.

Driver and installation

  • --DriverTrace traces the driver's steps: environment resolution, argument classification, preprocessing, and the backend command.
  • --MakeTestFiles writes the installation test files into a directory you name.
  • --MakeTigressDotH writes tigress.h to the current directory.
  • See top-level.

EncodeData

  • --EncodeDataComposeCodecs composes codecs into nested encodings, one chain chosen per variable.
  • --EncodeDataPolyDegree sets the degree of the polyn codec's permutation polynomial.
  • --EncodeDataCodecs gains many codecs: automatic, polyn, addshare/xorshare/addxorshare, lineargf2, bitperm, feistel, split_bits/split_nibbles/split_bytes, bignum, bcd, rational, and montgomery.
  • See EncodeData.

EncodeArithmetic

  • --EncodeArithmeticList prints the rewrite-pattern catalog (deity mode).
  • --EncodeArithmeticKinds gains generated: MBA encodings computed on the fly.
  • See EncodeArithmetic.

Optimize

  • --OptimizeLoopUnrollCount sets the unroll factor for loopUnroll.
  • --OptimizeKinds gains deadCodeElim, gotos, and loopUnroll.
  • See Optimize.

Inline

  • --InlineOptimizeKinds gains deadCodeElim and loopUnroll.
  • See Inline.

Checksum

  • --ChecksumHashFunctionsFile now generates a JSON file of hash functions instead of a C file compiled into a .so.
  • See Checksum.

Plugins

  • --InitPluginsContainerPrefix names container ADTs you supply (e.g. a Set prefix for the Set_* types and functions).
  • --InitPluginsKeyPrefix sets the prefix for user-supplied crypto-key plugin functions used by Pack's --PackKeySource=plugin.
  • See Plugins.

Fixed Bugs

  • #179. Fixed a bug where functions embedded with EncodeExternal that used unsigned char were given a signed char instead, so embedded cryptographic hashes such as SHA-256 and MD5 computed the wrong digest.
  • #186. Fixed a bug where a 128-bit integer constant was written as a plain decimal literal that the C compiler silently truncated to 64 bits, which could make an EncodeData program using the rnc codec compute a wrong value and loop forever.
  • #195. Fixed a crash where applying EncodeArithmetic a second time to already-encoded code aborted obfuscation with an uncaught error.
  • #198. Fixed a bug where the Checksum transform ignored TIGRESS_CHECKSUM_INSERT markers when checkers were requested with where = annotations, so no checkers were inserted and the hash-functions file was never written, making a later tigress_post run fail.
  • #199. Fixed a crash where a Checksum segment checker on a statically-linked Linux ELF binary hashed memory past the program text, across an unmapped region, and dereferenced an unmapped page.
  • #202. Fixed a bug where Virtualize output failed to compile on 32-bit targets with an "assignment to expression with array type" error.
  • #203. Fixed a crash where the Jit transform aborted with an internal error on 32-bit x86 Linux targets, which are now supported.
  • #204. Fixed a bug where Virtualize with computed-goto dispatch produced output that failed to compile on 32-bit targets with an "assignment to expression with array type" error.
  • #205. Fixed a bug where CleanUp with --CleanUpKinds=compress on a 32-bit target produced source that would not compile because a generated struct was run together with a following preprocessor directive.
  • #206. Fixed a bug where AntiBranchAnalysis branch functions (--AntiBranchAnalysisKinds=branchFuns) crashed at run time on 32-bit ARM and produced code that did not assemble on 32-bit x86.
  • #209. Fixed a bug where SelfModify with the arithmetic or comparison kinds produced binaries that crashed on 32-bit x86 (i386).
  • #211. Fixed a crash where JitDynamic aborted with an internal error on 32-bit targets.
  • #212. Fixed a bug where the Measure transform with --MeasureKind=time produced a binary that crashed on 32-bit x86 (i386).
  • #226. Fixed a bug where the Jit transform computed wrong results for floating-point arithmetic on 32-bit targets.