Attesor: AI-Powered Reverse Engineering of Rosetta 2 for Linux VM

Attesor is a GitHub repository containing a reverse-engineering project focused on Apple's Rosetta 2 binary translation system. The project aims to understand and document how Rosetta 2 enables x86_64 applications to run on ARM64 Apple Silicon hardware, with potential implications for Linux virtualization.
Project Background
The project documents Apple's architecture transitions: 1994 (Motorola 68000 to PowerPC), 2006 (PowerPC to Intel x86_64), and 2020 (Intel x86_64 to Apple Silicon ARM64). Rosetta 2 is Apple's third-generation binary translation solution, following the original Rosetta (2006-2011) that enabled PowerPC applications on Intel Macs.
Rosetta 2 Architecture
According to the source material, Rosetta 2 operates as a translation layer between x86_64 user applications and the ARM64 macOS kernel. The architecture includes:
- Translator (AOT/JIT): Handles both ahead-of-time and just-in-time translation
- Runtime Library: Provides runtime support functions
- System Call Translation: Converts x86_64 syscalls to ARM64 equivalents
Key Technologies
- Ahead-of-Time (AOT) Translation: Translates x86_64 binaries to ARM64 at install time, storing translated code in a cache
- Just-in-Time (JIT) Translation: Translates code blocks on-demand during execution, handling dynamically loaded code
- Instruction Set Translation: Maps x86_64 to ARM64 instructions, SSE/AVX to NEON vector instructions, and x86_64 flags to ARM64 condition codes
- System Call Translation: Manages different calling conventions and register state across syscall boundaries
Implementation Details
Rosetta 2 is located at /Library/Apple/usr/libexec/oah/ (where "oah" stands for "Old Architecture Hardware"), containing:
rosetta- Main translator binaryrosettad- Rosetta daemonlibrosetta.*- Runtime libraries
On Apple Silicon Macs, Rosetta 2 is not installed by default. Installation is triggered either by the first launch prompt of an Intel application or via the command line with softwareupdate --install-rosetta.
Project Structure
The repository contains multiple files including:
ExportDecomp.javaandexport_decomp.pyfor export and decompilationrosetta_decomp.candrosettad_decomp.cfor decompiled componentsrosetta_function_map.hand various refactored C filesrosetta.TODO.mddocumenting remaining work
The project represents an ongoing effort to document Rosetta 2's internals, which could inform development of similar translation layers for Linux virtualization environments.
📖 Read the full source: HN AI Agents
👀 See Also

Open-source 31-agent product development system for Claude with 12,000+ lines of content
An open-source Claude Skill provides 31 specialized AI agents and 20 strategic frameworks covering all company departments from product to compliance. The MIT-licensed system includes 62 files with 12,000+ lines of actionable content, country-specific compliance for multiple regions, and a smart-loading system that routes requests efficiently.

Claude Code v2.1.217: Subagent Depth Cap, Emoji Autocomplete, and Critical Fixes
Claude Code v2.1.217 caps concurrent subagents at 20, adds emoji autocomplete, fixes memory leak in MCP tool outputs, and resolves Windows auto-update issues.

SuperHQ: Run AI coding agents in isolated microVM sandboxes
SuperHQ is an open source Rust/GPUI app that runs AI coding agents (Claude Code, OpenAI Codex, Pi) in isolated microVM sandboxes. Each agent gets a full Debian VM, mounts project dirs read-only, and never sees host API keys — they're injected via an auth gateway proxy.

Cloudflare's vinext: A Next.js-compatible framework built with AI on Vite
Cloudflare engineers rebuilt Next.js API surface on Vite using AI in one week, creating vinext - a drop-in replacement that builds 4x faster and produces 57% smaller bundles. It deploys to Cloudflare Workers with a single command.