[New Features]:- Added the setting SMALL_INTEGERS to use 32-bit integers on 5.3/5.4[Improvements]:- Reduced obfuscation time by up to 30% for large scripts- Optimized serialization of constants to reduce file size- Optimized LPH_ENCFUNC on Luau platforms to be ~15% faster- Optimized deserialization on Luau platforms to be ~10% faster- Improvements to default anti-tamper and USE_DEBUG_LIBRARY[Bug Fixes]:- Fixed an error on platforms with 32-bit integers- Fixed an error when using Luraph in parallel Luau- Fixed anti-tamper crashing on the Lune runtime- Fixed issues where expressions involving nil would break- Fixed a compiler bug when swapping/shifting variables in assignments
[Improvements]:- Optimized LPH_ENCFUNC decryption to be 20-50x faster for large functions- ENABLE_COMPATIBILITY_MODE is now only usable with TARGET_VERSION="Roblox"- Compiler will now throw errors for ambiguous syntax on versions pre-5.4- FiveM target version now only guarantees support for Lua 5.4- Improvements to default anti-tamper and USE_DEBUG_LIBRARY- Optimized VM Compression to be up to 50% smaller- Optimized code generation of assignment statements[Bug Fixes]:- Fixed issues parsing goto labels and type casts on Luau- Fixed bug parsing digit separators with exponents (e.g. 1e+_1)- Fixed bug with overflow in \u escape sequences
[New Features]:- Implemented a completely new output generation structure that should significantly improve security[Improvements]:- Improved internal code generation used in some security features- Optimized generation of bytecode to lower file size- Tweaked certain security intensity to lower file size[Bug Fixes]:- Fixed bug where a specific usage of LPH_ENCSTR would cause errors- Fixed bug with Luau's string interpolation that would corrupt strings- Fixed some random *extremely* rare errors with code generation
[New Features]:- Added macro "LPH_LINE" (not a function) that evaluates to the current line (similar to __LINE__ in C)- Added support for read/write specifiers that can be in Luau's table type annotations- Added support for Luau's user-defined type function syntax[Improvements & Changes]:- Optimized internal VM structures to use up to 60% less memory on large files- Optimized Luraph's deserialization process to perform up to 3x faster on large files- Reduced memory and performance overhead when calling a protected function- Optimized certain bytecode security passes to reduce bloat and lower output size- Optimized the output of an internal feature used in Luraph's code generation- Optimized the internal algorithms used for LPH_ENCFUNC- Significantly reduced obfuscation time on very large files[Bug Fixes]:- Fixed crashing on World of Warcraft when not using the Static Environment setting- Fixed issue with continue closing upvalues too early inside of repeat-until loops- Fixed an extremely rare issue involving integer overflow in code generation- Fixed a bug that would break parsing certain table indexer type annotations- Fixed issue with constant values assigned to _ENV locals being optimized away- HARDCODE_GLOBALS should now be usable on the Roblox version
[New Features]:- Added "Warcraft 3" target version that should be used instead of Lua 5.3- Added OPTIMIZATION_LEVEL "Level 3" setting which includes behavior-changing optimizations- Level 3 optimization will automatically localize unassigned globals (such as math) when STATIC_ENVIRONMENT is enabled- Level 3 optimization will automatically localize certain unassigned imports (such as math.abs) when STATIC_ENVIRONMENT is enabled- Level 3 optimization will evaluate certain constant function calls (such as math library functions) when STATIC_ENVIRONMENT is enabled[Improvements & Changes]:- Added internal support for 32-bit Lua platforms (need dedicated target versions)- Significantly improved performance of accessing upvalues that aren't reassigned- Table assignment now uses program order (similar to Luau)[Bug Fixes]:- Fixed extremely rare LPH_NUMENC edge cases
[New Features]:- Added "Garry's Mod" target version that should be used instead of LuaJIT- Added support for leading bar and ampersand in Luau types- Added support for Luau's function attribute syntax[Improvements & Changes]:- Removed artificial line & file length limitations- Optimized certain obfuscation algorithms internally- STATIC_ENVIRONMENT can now be used independently for all versions- Improved generation of junk instructions- NaN/Infinity passed to LPH_NUMENC throws an error- Zero-length strings passed to LPH_STRENC throws an error- Optimized VM Compression to use Garry's Mod's util.Decompress function[Bug Fixes]:- Fixed a division-by-zero error on World of Warcraft- Fixed traceback lines not being properly matched on some platforms- Fixed an uncommon issue that could cause a an error while compiling- Fixed an uncommon issue that cause improper code generation on some platforms- Fixed an issue with upvaule handling on a specific fork of Lua
[Improvements & Changes]:- Optimized local declaration generation for smaller file size- Optimized opaque predicate generation for smaller file size- Removed multiple unnecessary/redundant things that caused spikes in file size- WoW scripts will now always use the bit library- LPH_NO_VIRTUALIZE can be used inside of LPH_JIT[Bug Fixes]:- Fixed certain table indexes being corrupted in LPH_NO_VIRTUALIZE- Fixed errors when enabling Use Debug Library on certain platforms- Fixed incorrect chunk name when using VM Compression- Fixed bug where upvalues may not be closed when returning
[Improvements & Changes]:- Optimized bytecode serialization to significantly reduce file size in large files- Improved optimizations that remove unnecessary VM code generation- LuaJIT versions will now always use the bit library[Bug Fixes]:- Fixed issues where LPH_ENCFUNC would corrupt stack when called in a certain way- Fixed issues where LPH_JIT would generate syntax errors or incorrect opcodes- Fixed issues when using goto statements inside of for-loops- Fixed issues with LPH_ENCFUNC on platforms with _ENV
[Improvements & Changes]:- Allowed goto statements to be used on any version to make it easier for developers to write code generation- Constants defined in virtualized code will NOT be inlined to LPH_NO_VIRTUALIZE functions for security reasons[Bug Fixes]:- Fixed a certain security module generating thousands of unnecessary instructions- Fixed issue with _ENV when combined with LPH_NO_VIRTUALIZE- Fixed issue that caused obfuscations to hang and not complete- Fixed issue that caused obfuscations to error when generating the VM- Fixed LPH_ENCSTR erroring when 'Use Debug Library" was enabled
[Bug Fixes]:- Fixed _ENV not working correctly inside of LPH_NO_VIRTUALIZE- Fixed CLOSE generation when jumping over break statements with goto- Fixed <const> attributed variables able to be assigned to[New Features]:- Added support for FiveM's safe navigation operations (?., ?[])- Added support for FiveM's table unpacking syntax (local ... in t)- Added a setting dependency system so that certain settings are only usable when others are selected- Added "OPTIMIZATION_LEVEL" setting for all platforms (level 2 by default)- Added "ENABLE_FFI_LIBRARY" setting for LuaJIT platforms (disabled by default)- Added "HARDCODE_GLOBALS" setting on non-ENV platforms to improve global semantics- Added "STATIC_ENVIRONMENT" setting to disable usage of getfenv/setfenv (requires global hardcoding)- Added "VM_COMPRESSION" setting to significantly lower file size (requires load/loadstring)- Added automatic inlining of constant local/upvalues to the compiler (requires level 2 optimization)- Added "Roblox" target version that should be used when developing for Roblox- Added macro "LPH_ENCFUNC" which encrypts a passed function to prevent deobfuscation[Improvements & Changes]:- Optimized assignment code generation to be smaller and faster- Optimized SETLIST on Luau, Lua 5.3, and Lua 5.4- Optimized mutable upvalue access in LPH_NO_VIRTUALIZE- Optimized readonly upvalue access in LPH_NO_VIRTUALIZE- Optimized LPH_JIT/LPH_JIT_MAX generation to produce smaller and faster chunks- Improved randomization of opcode generation to break signatures- Significantly optimized numeric and generic for-loops- Removed the coroutine library requirement from the VM (still required on Luau)[Incompatibilities]:- Removed "GMod" version option (use LuaJIT with FFI DISABLED instead)- <close> now throws an error as it is not supported by Luraph's compiler- Removed "VM_ENCRYPTION" option (R.I.P. <3)[Highlights]:- Using STATIC_ENVIRONMENT will prevent environment deoptimization on Roblox/Luau- When used correctly, LPH_ENCFUNC can make your functions nearly impossible to deobfuscate
- fixed assigning to macros on versions with _ENV- fixed issues with LPH_JIT and LPH_JIT_MAX- fixed constant folding inside of while loop conditions- banned local/variable names starting with LPH_*- banned assignment of macros inside of obfuscation- further improved macro validation and semantics
- removed the Universal version option (R.I.P. <3)- removed the Luau Handicapped version option (R.I.P. x2)- added a new setting 'ENABLE_COMPATIBILITY_MODE'- added support for proper _ENV behavior on Lua 5.2 - 5.4- added floor division operator (//) support to Luau- fixed an issue with parsing Luau's type syntax- fixed issues with missing/incorrect line information- disabled LPH_NO_UPVALUES on incorrect versions- improved macro validation and error messages- enforced recursion limits on script parsing (similar to Luau)- improved the performance of xor for platforms without native support- improved LPH_JIT security and performance- improved performance of string deserialization (scripts with lots of strings should be WAY faster!)- adjusted serialization of certain script constants to increase security
- enabled support for certain non-ambiguous syntax in all Lua versions (e.g. compound operators now compile on all versions)- disabled support for certain ambiguous syntax features on Universal- fixed assignment order in Luau- added support for Luau's string interpolation syntax- added support for bitwise compound operations- added support for compound operations in FiveM- added support for C-style comments in FiveM- added support for set constructors in FiveM- removed 'CS:GO' version option- many misc. performance/security improvements
- fixed syntax errors when concatenating numbers inside of LPH_NO_VIRTUALIZE- fixed issues with goto labels breaking inside of LPH_NO_VIRTUALIZE- fixed goto labels not being minified in obfuscation output
- fixed an issue that could cause upvalues to not be preserved when going out of scope- fixed an issue that could cause newlines in long strings to be omitted
- optimizations to instruction and constant decoding that should lower file size & memory usage- fixed bug with identifying luau handicapped platforms while on universal target version- fixed missing line information in vararg statements- rewrote internal communication to fix obfuscation jobs getting stuck [!]- fixed ast security causing integer overflow- fixed crash with luau platforms mishandling safeenv- fixed ffi type issues on cs:go target version
- improved TrollVM™️ constant encryption- fixed crashes on gamesense- fixed false positives on luaGuard- fixed nil value errors when using LPH_NO_VIRTUALIZE- fixed ffi initialization error on Garry's Mod
- added TrollVM™️ for HUGE improvements to anti-dump and anti-tamper- added 'World of Warcraft' target version for WoW scripts (Universal now also supports WoW)- added testing library to catch almost all issues on lua5.x, luajit 2.1, and luau- improved constant encryption to make dumping constants much more difficult- optimized the deserializer to improve loading performance on large scripts- optimized VM Encryption to improve loading performance on large scripts- optimized LPH_NO_VIRTUALIZE to reduce call overhead- fixed 0 (integer) becoming 0.0 (double) on Universal- fixed LPH_NO_VIRTUALIZE breaking local assignments under certain conditions- fixed incompatibilities with function calls with extreme amounts of arguments- fixed LPH_NUMENC being allowed inside of LPH_NO_VIRTUALIZE functions- fixed certain issues when using the LL/ULL number suffix on LuaJIT platforms- fixed incorrect results when constant folding certain exponent expressions- fixed 'attempt to call a nil value' error when using LPH_NO_UPVALUES- fixed incorrect parsing of overflowing 0x/0b numbers on Luau (now truncated to 2^64)- fixed line information being improperly generated on certain function calls- fixed certain rare issues caused by VM Encryption- fixed crashes on certain 3rd-party Roblox software- fixed bug with code generation of 'repeat until false' loops- fixed compiler error with break/continue inside 'repeat until true' loops- fixed memory leaks (memory usage should now generally be slightly lower, and much lower on larger files)- removed 'LPH_HOOK_FIX' as an alias for 'LPH_NO_UPVALUES'- removed 'LPH_JIT_ULTRA' as an alias for 'LPH_NO_VIRTUALIZE'
- fixed LPH_NO_UPVALUES erroring when used more than once- major optimizations to the obfuscation process- fixed luraph "tainting" the environment in World of Warcraft
- fixed obfuscated code flooding error messages when using VM Encryption- fixed bugs with constant folding edge cases on certain versions- added support for 'continue' when targeting GMod- added LPH_NUMENC/ENCNUM for securely encrypting numbers
- renamed 'LPH_HOOK_FIX' to 'LPH_NO_UPVALUES' (old version kept as an alias, may be removed at any time)- renamed 'LPH_JIT_ULTRA' to 'LPH_NO_VIRTUALIZE' (old version kept as an alias, may be removed at any time)- fixed syntax errors on some branches of g-mod- fixed errors parsing certain identifiers specific to Lua JIT
- bug fixes and performance improvements- added support for Luau's if-else expressions- ambiguous syntax errors will no longer be caught on all versions- generic for-loops are limited to 10 iteration variables
- fixed issues with C-style operators on G-Mod scripts- optimized conditions to be calculated faster- added support for __iter and generic iteration from Luau- bug fixes and performance improvements- fixed 'unable to allocate registers' error
- added 'LPH_HOOK_FIX' macro to fix issues with hookfunction (too many upvalues error)- fixed LL/ULL/i syntax error on CS:GO and GMod versions- fixed rare bugs with compound operators- fixed bug with [[]]-style strings in LPH_JIT_ULTRA- fixed issues with GMod target version
- improved default anti-tamper and anti-beautify detections when no settings are enabled- added new 'GMod' target version for scripts used on Garry's Mod- added 'LPH_OBFUSCATED' - a boolean that returns true if the script is currently obfuscated (nil if unobfuscated)- added Use Debug Library setting support for Synapse v3- added Use Debug Library setting option support for FiveM- fixed issue where certain internal tables would leak causing certain script to crash (getgc(true))- fixed issue where extremely large strings could freeze certain platforms while decoding- fixed issue with LPH_JIT_ULTRA that would cause syntax errors- fixed issue with LPH_CRASH that had a rare chance of causing an overflow error- fixed 'attempt to index a nil value' internal error on FiveM- fixed break/continue outside of loops causing obfuscations to become stuck on the website
- minor improvements to VM Encryption security- fixed issue that would cause obfuscations to take an extremely long time to complete or never finish- removed VM Compression completely as it is no longer useful (use VM Encryption instead)- fixed issues with \u escapes- fixed issues with the Use Debug Library feature that would cause errors on ScriptWare
- added LPH_JIT_ULTRA: works like LPH_JIT except it will completely disable virtualization for specified code (the raw code of whatever is inside it is exposed but there is no performance loss or bugs from obfuscation)- fixed issues with LPH_JIT/LPH_JIT_MAX- rewrote Luraph's VM Compression feature to just be VM Compression (this setting no longer provides any useful security additions)- added VM Encryption, which is a replacement for old VM Compression that adds an extreme layer of security over your scripts to prevent tampering- rewrote Luraph's anti-dump and anti-tamper to work better and more effectively on all platforms (including Luau!)
- fixed issue with SELF where the instruction would corrupt itself in certain situations- fixed issue with Disable Line Information and Use Debug Library erroring- fixed issue with VM Compression randomly erroring- added support for LuaJIT's LL, ULL, and i number syntax (requires ffi and LuaJIT target version)
- fixed minor issue with tamper detection on Luau-based platforms- fixed ..= not being recognized as a compound operator- fixed issues with repeat/until loops that use continue- fixed issues with _ENV- fixed issues with LPH_CRASH
- removed the 'Use Experimental Compiler' option as Luraph's compiler is now always used- changed how version targeting works to better support all Lua versions- fixed support for FiveM's '``' hashing syntax- fixed constant folding issues with bitwise operators- fixed issues with corrupted string characters when using Luraph's compiler- fixed issues with closing upvalues in loops that use break/continue- fixed a bug with empty statements (;) at the start of files- fixed issues with LPH_JIT- rewrote Luraph's bytecode obfuscation to provide more security and better control flow optimization- added new internal features to crash disassembly tools and decompilers- optimized conditions generated by Luraph's compiler to be faster and smaller than vanilla Lua- fixed issues with certain complex assignment cases in Luraph's compiler- fixed issue with the \z escape corrupting line information- added new integrity checking to Luraph's anti-dumping features- added support for Lua 5.4's increased \u escape limit- fixed certain issues with goto and continue- removed legacy code from pre-v13 and optimized codebase
- heavily optimized Luraph's VM making it 15-20% faster on average (can perform up to 2x faster with the new settings)- made error handling a separate option as it increases performance, lowers file size, and fixes some rare issues on some platforms- made bug fixes for __gc related issues a separate option as it heavily increases performance- fixed issues with control flow generation due to a bug with Lua 5.2 that was fixed in 5.3- increased performance of constant decryption, which speeds up load time- fixed a rare parsing issue with return statements in the experimental compiler- added support for FiveM's '``' string hash syntax- fixed LPH_CRASH causing obfuscations to fail- added LPH_JIT and LPH_JIT_MAX, macros that heavily optimize the input function for up to 2x faster performance with a cost of larger file size (see documentation for more information). LPH_JIT_MAX is a more intense version of LPH_JIT that comes with a slight security cost but an even higher performance increase
- fixed issues with using the _ENV global on 5.2+- fixed issues with the experimental compiler- fixed rare issues with vm generation- fixed garbage collection bug- multiple performance improvements to increase both loading and runtime speeds- added new constant protection to make automatic constant dumping extremely difficult without running the whole script- added support for old vararg (arg)
- Added TAILCALL support to the VM! All the infinitely recursing scripts should now work amazingly!- Fixed an issue with certain required instructions being folded- Fixed an internal issue causing the VM to randomly error
- fixed an issue with the debug library feature causing errors on 5.3- fixed overflowing integers in the experimental compiler- fixed multiple bugs with constant folding integers in the compiler- optimized the deserializer to cut loading time by 80%+ on large scripts
- fixed issue with obfuscation processes hanging while using the compiler- fixed 0 turning into -0 in some cases- fixed issue with a brand new security feature causing syntax errors
- fix an issue with large tables and unicode strings in the compiler- improve randomization to protect against signatures- fix an issue with error formatting- made conditions slightly more optimized with the experimental compiler
- misc fixes to boost speed of obfuscation jobs- fix issues with compatibility of debug lib and certain luau handicapped scripting engines- fix issues with constant virtualization not processing certain numbers properly- internally handle vm constructs in a way that allows easier support of more lua based scripting engines- made target version take more advantage of scripting engine specific features and optimizations- fix goto causing undefined behavior in areas where it should've errored in the custom compiler- fixed issue that possibly made obfuscation jobs hang under specific cases- fix issue that caused syntax error with binops & compound assignments in the script- improvements to our internal backend communications to highly reduce cpu footprint under load
- hopefully finally fixed the dreaded `0b` error- added a mitigation to fix a yielding bug with scripting software- fixed a couple issues with bitwise operators- fixed a couple misc bugs in our AST based security- made target version more accurately use version specific features
- added LuaJIT as an option for the target version setting- fixed random jit issue in LuaJIT causing errors- added constant folding to the experimental compiler setting- improved detection of beautifiers and dumpers in the tamper detection setting- added new randomization methods for VM generation- improved constant virtualization
- immensely refactored and changed the structures of Luraph scripts, improving security by a lot- enhanced randomization of VM generation- improved the VM compression feature, adding new security checks- enforced the 'return script results' option automatically into all scripts- fixed LPH_ENCSTR/LPH_STRENC macros- added the LPH_CRASH macro, a safe & secure way to crash the VM over infinite loops- fixed issues with upvalue closure (fixes common 'setfenv' error and other rarer issues)- fixed memory management to fix __gc issues and memory leak issues (Luraph is the only obfuscator to have these fixes!)- reworked certain opcodes for performance gains- added virtualized constant protection to improve security against constant dumping- added the 'use debug library' option to enhance security against tampering with scripts (environment must be compatible)- fixed nearly every single Luraph bug ever and added an overkill test suite to prevent future bugs- added the 'platform lock' option which takes advantage of certain environments/versions to provide enhanced security and protection- remove ilI variable names and replace with minified ones (RIP <3)- removed the 'custom variable names' option as it is no longer valid- added new bytecode security features to further break disassembly and decompiler tools- optimized line info serialization for lower file sizes- added 'intense vm structure' option, which replaces Luraph's outdated #{...} security in favor for a new implementation- greatly improved Luraph's codebase, meaning fewer bugs and faster updates- added 'use experimental compiler' option which utilizes a custom compiler to process scripts. This is an experimental feature and may contain some bugs. Using this option will allow support for all versions of Lua 5.1 - 5.4 and Luau (unlocking native support for feature like continue, goto, bitwise operators, integers, and more!)
- changed the ways internal VM structures work to improve performance by a lot- fixed an issue with a performance improvement that made boolean constants break comparison operators
- optimized VM instructions, making them up to 2x faster- moved some **minimal** security features out of the VM to increase performance- changed some syntactic garbage in the scripts- use bit.bxor if defined in the environment
- did some stuff that i dont even remember since i've been working on this update little by little over the span of 2 months- implemented a better framework for future upcoming macros- made error messages format much better than they were before- made a new encryption algorithm for the instruction and string encryption in luraph- fixed issues with gc leak of stack elements above the stack top- removed old debug flags, and increased the intensity of multiple matured bytecode security features- added tons of randomization to the string encryption macro to completely prevent attack vectors used on other obfuscators
- fixed the `table index is nil` error- fixed LPH_ENCSTR incorrect decryption results- added a new algorithm for the LPH_ENCSTR macro* this update is small because it is late at night. be on the lookout for another update on friday *
* i lost half of the changelog *- made dumpmeme more secure- fixed deserializer bug that everyone was getting- scrambled constant order to harden against constant dumping
- updated VM structure to increase security and speed. this update also lowers file size.- changed magic numbers and strings in the VM to break tools that may harm the security of Luraph.- updated the sanity check on VM compression.- changed areas of luraph to break signatures that have been built against it- made it harder for the VM's code to be simplified- added metamorphic code to the VM
- fixed deserializer errors. there will soon be a fix to phase out all normal signed integer math out of luraph's serializer in order to stop any of these bugs from ever happening. biginteger here we come !
- fixed vararg issues- cleaned up code and added misc performance increases- added support and base for future macros (suggest these to me in tickets or DMs)- added LPH_ENCSTR("String") to encrypt strings with more intensive security- fixed some complex JMP related issues- cleaned up and optimized a ton of code in the obfuscation process (times should be faster on intensive scripts)
- hopefully finally fixed SETLIST in a way that there is no edge cases where it may break- optimized RETURN. this should provide a noticable difference- optimized CALL
- finally fixed bytecode editing glitches- fixed some areas where security could be accidentally not applied in some areas- fixed and enabled dumpmeme globally (report any performance issues)- finally reenabled scrambled eggs because the underlying bug breaking it was fixed
- added a new algorithm to compress luraph bytecode (infinite yield is no longer 2mb with vm compression off, more like 1mb, even less with vm compression on)- improved performance of certain vm instructions- misc bug fixes
- made obfuscation a LOT faster- fixed vm compression and made it a lot more effective- removed all form of extended SETLIST from the VM due to the fact it'll never be used... vanilla lua 5.1.5 compiler will never use extended setlist- made that weird SETLIST issue defcon told me about only be relevant 0.0001% of the time... if anyone realisticly runs into that issue now then someone's doing something super retarded and can just change their shit to work better (lua limits don't allow me to fix the issue 100%, well at least i think, this fix required me being a bit creative)- changed the bytecode format to make it have a bit less characters- encrypted registers for opcode redirection- added some bamboozling to vmfuncs- removed a ton of unused functions internally from scrapped features- subsequent updates will be coming out to improve this update and continue to make luraph more secure.
- fixed CLOSE (i still stand by the fact that luraph is better than all others because none of them have this fix, nor the stack corruption bug luraph has a proper fix for)- fixed some bloating in the bytecode (could possibly make scripts faster due to less junk instructions being executed)
- actually fixed env so getfenv/setfenv on luraphd functions will work properly. unfortunately at this time getfenv/setfenv while specifying a number for the level is still broken and will probably never be fixed as it'll be nearly impossible to properly fix
- blah blah old v9.0-9.2 changelog LOST- fixed some debugging tools so that i can more easily debug issues like this- fixed it where scrambledeggs would lose instructions (LOL ?)
- added option D - allowing you to use stuff like modulescripts on robloxreenabled bytecode editing - this feature is like half broken so i cant wait for tickets