
Reverse engineering NVIDIA SASS instruction dictionary, kernel audits and pattern recognition across GPU architectures.
Reverse engineering NVIDIA SASS from controlled kernels to production audits.
Article 1 · Article 2 · Knowledge base · Pattern library · SM120 instruction glossary · Encoding notes · Start here · Project structure · Tensor-core chapters · Contributing
SASS King is a systematic reverse-engineering project for NVIDIA SASS, the native GPU instruction set emitted inside compiled CUDA binaries. The project starts with SM120 / SM120a consumer Blackwell hardware and expands toward a full cross-architecture ISA and pattern library over time.
The goal is practical: help a kernel engineer open a SASS dump, recognize compiler patterns, identify performance-relevant structures, and connect the binary back to source-level optimization decisions.
The project has completed its initial Phase 3 pattern library: 29 reusable SASS signatures are now formalized under patterns/, with knowledge/FINDINGS.md kept as the full evidence trail. The next major step is Phase 4: applying those patterns to real production kernels.
| If you want to... | Start here | Then read |
|---|---|---|
| Understand the project in 10 minutes | docs/README.md | docs/START_HERE.md, then docs/PROJECT_STRUCTURE.md |
| Reproduce the evidence | corpus/README.md | one chapter conclusion*.md, then its .sass dump |
| Find the source of truth | knowledge/FINDINGS.md | knowledge/SASS_INSTRUCTIONS_SM120.md, knowledge/encoding/README.md |
| Recognize a pattern in a new dump | patterns/README.md | the matching patterns/NN-*.md page |
| Start a production audit | production/README.md | matching PATTERN-NN pages and source evidence |
| Contribute a correction or dump | CONTRIBUTING.md | docs/START_HERE.md |
The repository is organized as an evidence pipeline:
corpus/ controlled kernels and raw SASS evidence
knowledge/ project-wide findings, instruction notes, and encoding notes
patterns/ reusable Phase 3 audit signatures
production/ Phase 4 real-kernel audits
The last broad public SASS reverse-engineering work comparable in spirit was Jia et al. on Volta and Turing in 2018. Ampere, Hopper, and Blackwell have changed the instruction mix substantially: async copy paths, tensor-core families, matrix load/store instructions, sparse and scaled MMA forms, and new uniform-register flows.
SASS King fills that gap by combining controlled micro-kernels, raw SASS reading, runtime probes, and production-kernel audits.
| Area | Status | Where |
|---|---|---|
| SM120 teaching kernels | Complete through kernels 01-12 | corpus/basics/01_vector_add/ to corpus/math_and_spills/12_register_spill/ |
| Tensor-core studies | Complete through Kernel 25 | corpus/tensor_cores/ |
| Global findings | Active source of truth | knowledge/FINDINGS.md |
| SM120 instruction glossary | Active, evidence-backed | knowledge/SASS_INSTRUCTIONS_SM120.md |
| Encoding pilots | Started with LDSM, STSM, QMMA | knowledge/encoding/ |
| denvdis cross-validation | Initial pass complete; deeper control-code gaps remain | knowledge/DENVDIS_INTEGRATION.md |
| Pattern library | Initial Phase 3 library complete | patterns/ |
| Production audits | Next phase | production/ |
The formal pattern library is the main output of Phase 3. It turns the chapter-local evidence into reusable audit signatures, so an audit can cite a named pattern instead of rewriting the full research trail every time.
Phase 3 is considered complete because:
knowledge/FINDINGS.md;patterns/README.md;| Pattern family | Examples | Where |
|---|---|---|
| Tensor-core compute | HMMA, QMMA, OMMA accumulator chains; sparse metadata; narrow fragments | patterns/02-* to patterns/04-*, patterns/10-*, patterns/21-* |
| Matrix memory and epilogues | LDSM, STSM, async copy pipelines, REDG reduction epilogues | patterns/05-*, patterns/06-*, patterns/07-*, patterns/28-* |
| Control flow | divergence/reconvergence, loop back-edges, predicated exits, cold traps, local CALLs | patterns/08-*, patterns/14-*, patterns/16-*, patterns/26-*, patterns/29-* |
| Memory and registers | vectorized global memory, spills, shared-memory staging, descriptors, uniform-register flow | patterns/09-*, patterns/11-*, patterns/17-*, patterns/19-*, patterns/20-* |
| Arithmetic and scheduling | FFMA fusion, constants, MUFU slowpaths, scoreboards, lifetime recycling | patterns/12-*, patterns/18-*, patterns/22-*, patterns/23-*, patterns/24-* |
| Warp collectives | warp reductions, shuffle/vote/match/sync primitives | patterns/01-*, patterns/25-* |
Each pattern page includes:
Use patterns/README.md as the audit-facing index. Use knowledge/FINDINGS.md when you need the longer research context behind a pattern.
Phase 3 does not claim that every NVIDIA SASS behavior is decoded. It establishes a reusable SM120 / SM120a pattern layer good enough to begin manual production audits. Runtime layout decode, full control-code bit placement, automated cubin reporting, and cross-architecture replay remain future work.