> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/core/decompiler/specification.md).

# Specification

IDA Decompilers come in 15 different flavors:

* [x86 decompiler](#x86-decompiler) (32-bit code)
* [x64 decompiler](#x64-decompiler) (64-bit code)
* [ARM decompiler](#arm-decompiler) (32-bit code)
* [ARM64 decompiler](#arm64-decompiler) (64-bit code)
* [PowerPC decompiler](#powerpc-decompiler) (32-bit code)
* [PowerPC64 decompiler](#powerpc64-decompiler) (64-bit code)
* [MIPS decompiler](#mips-decompiler) (O32, O64, N32, EABI32, P32/nanoMIPS)
* [MIPS64 decompiler](#mips64-decompiler) (N64 ABI)
* [RISC-V decompiler](#risc-v-decompiler) (32-bit code)
* [RISC-V 64 decompiler](#risc-v-64-decompiler) (64-bit code)
* [Hexagon decompiler](#hexagon-decompiler) (QDSP6)
* [ARC decompiler](#arc-decompiler) (32-bit code)
* [V850 decompiler](#v850-decompiler) (32-bit code)
* [Infineon TriCore decompiler](#tricore-decompiler) (32-bit code)
* [Android DEX decompiler](#android-dex-decompiler) (bytecode)

Currently the decompiler can handle compiler-generated code. Manually crafted code may be decompiled too but the results are usually worse than for compiler code.

## Decompiler summaries

### x86 decompiler

Decompiles 32-bit x86 code, common in Windows and Linux desktop software, legacy applications, and malware analysis. Supports x86 floating-point instructions, including FPU stack analysis and the `_TBYTE` extended-precision type. C++ exception handling is not reconstructed for x86 binaries, unlike the x64 decompiler's MSVC exception support.

### x64 decompiler

The 64-bit counterpart to the x86 decompiler. Common for modern Windows and Linux servers, desktop software, and 64-bit malware samples. It is the only decompiler variant with built-in C++ exception-handling reconstruction, via the [`eh34` plugin](/ida-9.5/core/decompiler/concepts/exception-handler.md), for MSVC-compiled binaries.

### ARM decompiler

Decompiles 32-bit ARM code, one of Hex-Rays's earliest supported architectures, common in mobile devices, embedded systems, and IoT products. Handles ARM's extensive use of conditional instructions and reconstructs switch statements, with a tunable optimization to drop unreachable cases from large switches. Supports both big-endian and little-endian ARM binaries.

### ARM64 decompiler

Handles floating-point and NEON vector instructions for 64-bit ARM (ARM64/AArch64) code, and can optionally show ARMv8.3 Pointer Authentication instructions as intrinsic function calls. Common for modern iOS and Android apps, and increasingly for ARM64 Windows and macOS binaries.

### PowerPC decompiler

Decompiles 32-bit PowerPC code, common in embedded, automotive, and networking hardware, as well as older game consoles. Vector, DFP, VSX, and SPE instruction extensions are not supported.

### PowerPC64 decompiler

The 64-bit counterpart to the PowerPC decompiler, used for 64-bit PowerPC systems such as servers, network appliances, and some embedded platforms. Shares the same instruction-set limitations as its 32-bit counterpart: Vector, DFP, VSX, and SPE extensions are not supported.

### MIPS decompiler

Common in routers, embedded Linux devices, and other network hardware, the MIPS decompiler handles MIPS's branch delay slots transparently. It supports five 32-bit ABI variants (O32, O64, N32, EABI32, and P32/nanoMIPS), with nanoMIPS included.

### MIPS64 decompiler

The 64-bit counterpart to the MIPS decompiler, with support for Cavium OCTEON custom instructions used in advanced network equipment such as routers and telecom gear. Only the N64 ABI and 64-bit floating-point registers are supported.

### RISC-V decompiler

Common in low-power IoT chips such as the Espressif ESP32-C3 and ESP32-C6, the 32-bit RISC-V decompiler supports T-Head custom instructions used in Xuantie and Allwinner processors, plus vector extension instructions.

### RISC-V 64 decompiler

The 64-bit counterpart to the RISC-V decompiler, sharing the same T-Head custom instruction and vector extension support.

### Hexagon decompiler

Decompiles Qualcomm Hexagon (QDSP6) code into plain C pseudocode, turning baseband and DSP firmware from Snapdragon modem, audio, sensor, compute, and NPU subsystems into readable code instead of VLIW assembly.

### ARC decompiler

Used in embedded devices such as SSD controllers and Wi-Fi chipsets, and formerly the core of Intel's Management Engine (ME). Covers every ARC variant IDA recognizes: the classic 32-bit ISA, 32/16-bit ARCompact, and ARCv2, handling delay slots, conditional instructions, and zero-overhead loops out of the box.

### V850 decompiler

Decompiles Renesas V850 (also known as NEC850/RH850) code, extensively used in automotive ECUs and industrial control systems. Covers both the modern RH850 ABI and the legacy GCC V850 ABI, and recognizes compiler-specific prolog/epilog helpers and `callt`-invoked helper calls.

### TriCore decompiler

Decompiles TriCore firmware, common in automotive and industrial microcontrollers. Supports code built with the GNU, HighTec, and Tasking toolchains.

### Android DEX decompiler

Decompiles Android DEX bytecode into readable Java code, including try/catch reconstruction and annotation handling. Adds a class tree/class view for navigating the APK. Bytecode and native `.so` libraries can be analyzed in the same database. A decompiler API is available for automation.

## Current Constraints

Below are the most important limitations of our decompilers (all processors):

* exception handling is not supported (except MSVC x64 C++ exceptions)
* type recovery is not performed
* global program analysis is not performed
* execution timings are not preserved
* memory access patterns are not preserved

Limitations specific to PPC:

* Vector/DFP/VSX/SPE instructions are not supported

Limitations specific to MIPS:

* O32, O64, N32, EABI32, P32(nanoMIPS) are supported
* only 32-bit FPR in O32,EABI32 and 64-bit FPR in N32,O64 are supported

Limitations specific to MIPS64:

* only N64 ABI is supported
* only 64-bit FPR are supported


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/core/decompiler/specification.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
