View8 is a static analysis tool designed to decompile serialized V8 bytecode objects (JSC files) into high-level readable code. To parse and disassemble these serialized objects, View8 utilizes a patched compiled V8 binary. As a result, View8 produces a textual output similar to JavaScript.
- Python 3.x
- Disassembler binary. You'll have to build this yourself. See the instructions below.
For compiled disassembler binaries, visit the original repo's releases page.
input_file: The input file name.output_file: The output file name.--path,-p: Path to disassembler binary (optional).--disassembled,-d: Indicate if the input file is already disassembled (optional).--export_format,-e: Specify the export format(s). Options arev8_opcode,translated, anddecompiled. Multiple options can be combined (optional, default:decompiled).--nested,-n: Export nested format (optional).
To decompile a V8 bytecode file and export the decompiled code:
python view8.py input_file output_fileBy default, view8 detects the V8 bytecode version of the input file (using VersionDetector.exe) and automatically searches for a compatible disassembler binary in the Bin folder. This can be changed by specifing a different disassembler binary, use the --path (or -p) option:
python view8.py input_file output_file --path /path/to/disassemblerTo skip the disassembling process and provide an already disassembled file as the input, use the --disassembled (or -d) flag:
python view8.py input_file output_file --disassembledTo export code with nested function definition, use the --nested (or -n) flag:
python view8.py input_file output_file --nestedSpecify the export format(s) using the --export_format (or -e) option. You can combine multiple formats:
v8_opcodetranslateddecompiled
For example, to export both V8 opcodes and decompiled code side by side:
python view8.py input_file output_file -e v8_opcode decompiledBy default, the format used is decompiled.
The V8 bytecode version is stored as a hash at the beginning of the file. Below are the options available for VersionDetector.exe:
-h: Retrieves a version and returns its hash.-d: Retrieves a hash (little-endian) and returns its corresponding version using brute force.-f: Retrieves a file and returns its version.
See Building V8 for Electron Apps with Leap Tiering.
Guide/disassembler/patch based on v8dasm and https://github.com/v8/v8/tree/10.6.194.26.
-
Check out your v8 version: https://v8.dev/docs/source-code
-
Apply the patch:
git apply -3 v8.patch
It's expected that a few merge conflicts occur for different versions, resolve them manually.
-
Create a build configuration:
python tools/dev/v8gen.py x64.release
-
Edit the build flags in
out.gn/x64.release/args.gn:dcheck_always_on = false is_component_build = false is_debug = false target_cpu = "x64" use_custom_libcxx = false v8_monolithic = true v8_use_external_startup_data = false v8_static_library = true v8_enable_disassembler = true v8_enable_object_print = true
- For Node: add
v8_enable_pointer_compression = false
- For Node: add
-
Build the static library:
ninja -C out.gn/x64.release v8_monolith
-
Compile the disassembler:
-
For Node:
clang++ v8dasm.cpp -g -std=c++20 -Iinclude -Lout.gn/x64.release/obj -lv8_libbase -lv8_libplatform -lv8_monolith -o v8dasm
-
For Electron:
clang++ v8dasm.cpp -g -std=c++20 -Iinclude -Lout.gn/x64.release/obj -lv8_libbase -lv8_libplatform -lv8_monolith -o v8dasm -DV8_COMPRESS_POINTERS -DV8_ENABLE_SANDBOX
-