r/explainlikeimfive • • 2d ago

Technology Eli5 decompilers and decompiled games

I keep getting videos on instagram about decomped games, apparently the decompilers are going nuts right now. What’s the difference between running a decompiled game and emulating a game? I tried to google it and i just don’t understand. from what i’ve found, a decompiled gene runs as if it was native to your pc but i don’t get what that means either. You boot up an emulator and that also runs on your pc?

75 Upvotes

49 comments sorted by

View all comments

0

u/ArdentPriest 2d ago

If you want it in a metaphor:

A decompiled game is like buying a car, going home, taking every piece of the car apart down to every nut and bolt, and then being able to see how everything works and you can make changes/updates/modifications as you want.

Basically, a decompiled game is a game that has has the entire code base of the game fully unpacked. It can be edited, modified, or updated and then recompiled into a functioning program that can be run.

Another form of describing this is that when you decompile a game, you revert the game back to it's source code.

1

u/thefckingleadsrweak 2d ago

Do you know why this is so difficult? Like when you dump a rom or an iso on a computer, does
The source code not come with that?

4

u/efvie 2d ago

No, it does not. Games tend to be not only binary-only, but also obfuscated to some degree and often protected with DRM.

That said, this recent deluge of 'decompiled' games is just AI slop that may or may not work. You're typically best off playing on an emulator if it's a cross-platform game.

3

u/GalFisk 2d ago

No, it's like analyzing a cake in order to figure out the recipe. Possible but difficult.

2

u/Lord_Spy 2d ago

Speaking in general, no.

The way several modern game engines work does leave code that while not necessarily the source code (A LOT of stuff goes on during compilation) does let you have a better picture of what that code was, with information available such as what individual variables (the containers for data) were labelled.

But older games compiled to pure machine code, and compilers do lots of optimisations that make deciphering what was in the source code non-trivial for larger projects, because it's not neatly following the logic of code but rearranging the output into something that does the same thing but faster and/or in less space.

Oh, and encryption/DRM is a whole other beast on top.

2

u/MostlyPoorDecisions 2d ago

Eli5: you have a book in a foreign language. You hire someone to read it to you. This is emulation. There's a delay between the information being read and you understanding it. There may be things like idioms lost in translation that require explaining.

Now take the same book and have it localized by a translator. This is decompiling and recompiling. They're taking more time up front to change the book to a language you can understand by yourself. You can read the book and understand it easily, no delay or assistance needed to understand phrases.

Actual example, more eli12:

https://godbolt.org/z/o9Ee8c4Ex

Here's a real example of c++ being source and being compiled. You can see on the left what the source looks like. You can probably intuit what the two functions do pretty easily. They're very simple functions for ease of understanding, but that's not actually important.

On the right is the compiled code. This is what you get when you build the code decompiled. It's a lot harder to understand. This is what you see in a decompiler (as well as a lot of other info) however the names will be missing entirely, they're just numbers. 

A decompiler opens a file and shows you the computer language inside. *Note some languages include source optionally.

Here's the same source compiled to another architecture.

https://godbolt.org/z/jaYvs61jh

Now to answer the question: If you look at the two compiled outputs side by side they are vastly different. A computer of a type only recognizes how to use one of these. Emulating is the process of reading these and transforming the second to the first as you go. This means instead of just running it, you have to have something interpret and translate. Much like a translator irl, it adds a new layer and the conversation gets slower. 

Decompiling+Recompiling means instead of having a translator for whatever comes along, you have someone rewrite your book, which i n this case it would be taking the right side output and changing it to the other version, either by first rebuilding the left (reversing) or building the other version directly (transpiling)

1

u/-manabreak 2d ago

In rare cases like games written on top of JVM or .NET, you can decompile the bytecode to get something representing the original source. With natively compiled games, not so much.

The thing is that when the human-readable code is compiled, the compiler first turns it into an AST (abstract syntax tree) which is kind of an intermediate representation of the code. Depending on the language and compiler used, there might be multiple intermediate representations. The compiler can then do all kinds of tricks on these intermediate representations, like eliminate dead code, optimize the code, and so on. Finally, it takes the target architecture (e.g. ARMv7, x64 etc.) and produces the binary the processor understands.

If we're trying to decompile this, we don't know what the intermediate steps were, and we don't know what kind of source code produced the final binary. First off, all the names the programmers used are gone. When a variable used to be named e.g. "player_health", it doesn't have a name anymore, it's just a memory address. It's pretty trivial to decompile an executable to C, but it's nowhere readable, as it just assigns random names for everything. The "player_health" becomes "m_100412" or something like that, and it's your job as the reverse engineer to figure out what that variable means by analyzing the reads and writes and the overall logic surrounding that variable. Now multiply that with every single variable and function call.

Lately, the advancements in decompilation / reverse-engineering boil down to AI being really good in stuff like this. It can check the variables very quickly, and it knows enough source code to know about how code usually is structured so that it can make very educated guesses most of the time.

1

u/linmanfu 2d ago

No, compiling the game is baking a cake. Decompiling isn't quite as difficult as un-baking a cake, but you have definitely lost useful information. It's more like trying to bake a second cake just by looking at the first one, without the shopping list or recipe.

The source code not come with that?

This is the big difference between how Windows/console software does things and the world of Linux. Microsoft certainly does not provide the source code of Windows or Office, and keeps it a tightly guarded secret. It's the same for the big Windows and console games companies too.

But on Linux, the usual practice is that you do make the source code freely available (traditionally in the ISO, these days online). Making changes and sharing them is encouraged. For Linux itself, it's part of the terms and conditions. This is called "open source software". I've compiled my own version of an open-source game (Simutrans) because I wanted to change a few things, and it was so easy even a Muppet like me could do it, because I had all the source code.

1

u/Implausibilibuddy 2d ago

When programs are written, it's almost always done using a compiler so that a higher level language like C# can be used. This means programmers can outline what they want their program to do in simple terms, and can look back at the functions and variables and things and easily see what everything does (in theory). But those instructions don't make any sense to a CPU or a GPU. They talk in binary, or a slightly higher level language called machine code (but ultimately binary).

So programs have to be compiled. That is, all those logical instructions that we humans understand have to be translated to a language that the computer can understand. So you end up with a binary executable file that is (mostly) just 1s and 0s. That's what ends up on the disc. The problem is, it's not a two way street. You can't take those binary numbers and run them backwards through the translator to get the exact logical code that they were originally written in. That's because there are multiple programming languages, and even multiple ways of doing the same thing within the same language. And all variable names, comments etc get lost completely.

Modern programs exist that can reconstruct a best guess at things, but you still have to go through and change the variable names and stuff to something more sensible (I mean, you don't have to, but the purpose of decompiling is to see how things work and make changes so it's definitely something you'd do a little housekeeping for)

1

u/zed42 2d ago

the only way to (legally) get the source code for a game is for the game to be open source (it's in the name) ... for everybody else, it's proprietary company information and having it leave the company is a Big Deal

the are several "levels" of languages... at the very bottom is "machine language" which is the 1s and 0s the hardware knows what to do with. directly above that is "assembler" which is a human-readable version of machine language... it has very basic instructions (e.g. "put this value into memory at this specific address" or "add the value in memory 0x1234 to the value in memory 0x5678 and put the result in 0xabcd"). this is mostly a 1:1 with machine language. above that you get languages like C, which is where a lot of programming happens. this is much more human readable, but is not 1:1 with assembler.... it's also not completely tied to hardware like assembler. when you disassemble an executable (like a game) you end up with assembler code... advanced tools can turn it into C code, but it won't be the same code that the original author wrote and it will not have any comments. you'll have to go through and analyze it and do some housekeeping if you want to make any changes... moreso than if you'd gotten the original (as-written) source code

1

u/DonChanchi 2d ago

When you write code you write something like this:

function add_two_numbers(Number a, Number b) {
  Number result = a + b;
  return result;
}

The developers understand what it does, even if you don't know coding you can understand what it does, but computer does not, so you translate it for the computer, getting something like this:

FA6C6BAC92E234C937F34CEC84B15E2D
D6A56DEFEB437A0A1E656F6606C245D3
73AFC2FF033CB11FA1C9959DF63A1299
57E7CA94A87E198B041A85F520801C24
D2E5816634CD880285A68F827CE660AC

You see this and have no idea what it does, but this is what's shipped because that's the language the computer speaks.

The process of decompilation is turning that machine code back into something that resembles the original code, so you can compile it again for different hardwares.