1 /* disasm.c where all the _work_ gets done in the Netwide Disassembler
3 * The Netwide Assembler is copyright (C) 1996 Simon Tatham and
4 * Julian Hall. All rights reserved. The software is
5 * redistributable under the license given in the file "LICENSE"
6 * distributed in the NASM archive.
8 * initial version 27/iii/95 by Simon Tatham
26 * Flags that go into the `segment' field of `insn' structures
29 #define SEG_RELATIVE 1
36 #define SEG_SIGNED 128
45 uint8_t osize; /* Operand size */
46 uint8_t asize; /* Address size */
47 uint8_t osp; /* Operand size prefix present */
48 uint8_t asp; /* Address size prefix present */
49 uint8_t rep; /* Rep prefix present */
50 uint8_t seg; /* Segment override prefix present */
51 uint8_t lock; /* Lock prefix present */
52 uint8_t rex; /* Rex prefix present */
55 #define getu8(x) (*(uint8_t *)(x))
57 /* Littleendian CPU which can handle unaligned references */
58 #define getu16(x) (*(uint16_t *)(x))
59 #define getu32(x) (*(uint32_t *)(x))
60 #define getu64(x) (*(uint64_t *)(x))
62 static uint16_t getu16(uint8_t *data)
64 return (uint16_t)data[0] + ((uint16_t)data[1] << 8);
66 static uint32_t getu32(uint8_t *data)
68 return (uint32_t)getu16(data) + ((uint32_t)getu16(data+2) << 16);
70 static uint64_t getu64(uint8_t *data)
72 return (uint64_t)getu32(data) + ((uint64_t)getu32(data+4) << 32);
76 #define gets8(x) ((int8_t)getu8(x))
77 #define gets16(x) ((int16_t)getu16(x))
78 #define gets32(x) ((int32_t)getu32(x))
79 #define gets64(x) ((int64_t)getu64(x))
81 /* Important: regval must already have been adjusted for rex extensions */
82 static enum reg_enum whichreg(int32_t regflags, int regval, int rex)
84 if (!(regflags & (REGISTER|REGMEM)))
85 return 0; /* Registers not permissible?! */
89 if (!(REG_AL & ~regflags))
91 if (!(REG_AX & ~regflags))
93 if (!(REG_EAX & ~regflags))
95 if (!(REG_RAX & ~regflags))
97 if (!(REG_DL & ~regflags))
99 if (!(REG_DX & ~regflags))
101 if (!(REG_EDX & ~regflags))
103 if (!(REG_RDX & ~regflags))
105 if (!(REG_CL & ~regflags))
107 if (!(REG_CX & ~regflags))
109 if (!(REG_ECX & ~regflags))
111 if (!(REG_RCX & ~regflags))
113 if (!(FPU0 & ~regflags))
115 if (!(REG_CS & ~regflags))
116 return (regval == 1) ? R_CS : 0;
117 if (!(REG_DESS & ~regflags))
118 return (regval == 0 || regval == 2
119 || regval == 3 ? rd_sreg[regval] : 0);
120 if (!(REG_FSGS & ~regflags))
121 return (regval == 4 || regval == 5 ? rd_sreg[regval] : 0);
122 if (!(REG_SEG67 & ~regflags))
123 return (regval == 6 || regval == 7 ? rd_sreg[regval] : 0);
125 /* All the entries below look up regval in an 16-entry array */
126 if (regval < 0 || regval > 15)
129 if (!(REG8 & ~regflags)) {
131 return rd_reg8_rex[regval];
133 return rd_reg8[regval];
135 if (!(REG16 & ~regflags))
136 return rd_reg16[regval];
137 if (!(REG32 & ~regflags))
138 return rd_reg32[regval];
139 if (!(REG64 & ~regflags))
140 return rd_reg64[regval];
141 if (!(REG_SREG & ~regflags))
142 return rd_sreg[regval & 7]; /* Ignore REX */
143 if (!(REG_CREG & ~regflags))
144 return rd_creg[regval];
145 if (!(REG_DREG & ~regflags))
146 return rd_dreg[regval];
147 if (!(REG_TREG & ~regflags)) {
149 return 0; /* TR registers are ill-defined with rex */
150 return rd_treg[regval];
152 if (!(FPUREG & ~regflags))
153 return rd_fpureg[regval & 7]; /* Ignore REX */
154 if (!(MMXREG & ~regflags))
155 return rd_mmxreg[regval & 7]; /* Ignore REX */
156 if (!(XMMREG & ~regflags))
157 return rd_xmmreg[regval];
162 static const char *whichcond(int condval)
164 static int conds[] = {
165 C_O, C_NO, C_C, C_NC, C_Z, C_NZ, C_NA, C_A,
166 C_S, C_NS, C_PE, C_PO, C_L, C_NL, C_NG, C_G
168 return conditions[conds[condval]];
172 * Process a DREX suffix
174 static uint8_t *do_drex(uint8_t *data, insn *ins)
176 uint8_t drex = *data++;
177 operand *dst = &ins->oprs[ins->drexdst];
179 if ((drex & 8) != ((ins->rex & REX_OC) ? 8 : 0))
180 return NULL; /* OC0 mismatch */
181 ins->rex = (ins->rex & ~7) | (drex & 7);
183 dst->segment = SEG_RMREG;
184 dst->basereg = drex >> 4;
190 * Process an effective address (ModRM) specification.
192 static uint8_t *do_ea(uint8_t *data, int modrm, int asize,
193 int segsize, operand * op, insn *ins)
195 int mod, rm, scale, index, base;
199 mod = (modrm >> 6) & 03;
202 if (mod != 3 && rm == 4 && asize != 16)
205 if (ins->rex & REX_D) {
206 data = do_drex(data, ins);
212 if (mod == 3) { /* pure register version */
213 op->basereg = rm+(rex & REX_B ? 8 : 0);
214 op->segment |= SEG_RMREG;
223 * <mod> specifies the displacement size (none, byte or
224 * word), and <rm> specifies the register combination.
225 * Exception: mod=0,rm=6 does not specify [BP] as one might
226 * expect, but instead specifies [disp16].
228 op->indexreg = op->basereg = -1;
229 op->scale = 1; /* always, in 16 bits */
260 if (rm == 6 && mod == 0) { /* special case */
264 mod = 2; /* fake disp16 */
268 op->segment |= SEG_NODISP;
271 op->segment |= SEG_DISP8;
272 op->offset = (int8_t)*data++;
275 op->segment |= SEG_DISP16;
276 op->offset = *data++;
277 op->offset |= ((unsigned)*data++) << 8;
283 * Once again, <mod> specifies displacement size (this time
284 * none, byte or *dword*), while <rm> specifies the base
285 * register. Again, [EBP] is missing, replaced by a pure
286 * disp32 (this time that's mod=0,rm=*5*) in 32-bit mode,
287 * and RIP-relative addressing in 64-bit mode.
290 * indicates not a single base register, but instead the
291 * presence of a SIB byte...
293 int a64 = asize == 64;
298 op->basereg = rd_reg64[rm | ((rex & REX_B) ? 8 : 0)];
300 op->basereg = rd_reg32[rm | ((rex & REX_B) ? 8 : 0)];
302 if (rm == 5 && mod == 0) {
304 op->eaflags |= EAF_REL;
305 op->segment |= SEG_RELATIVE;
306 mod = 2; /* fake disp32 */
310 op->disp_size = asize;
313 mod = 2; /* fake disp32 */
316 if (rm == 4) { /* process SIB */
317 scale = (sib >> 6) & 03;
318 index = (sib >> 3) & 07;
321 op->scale = 1 << scale;
324 op->indexreg = -1; /* ESP/RSP/R12 cannot be an index */
326 op->indexreg = rd_reg64[index | ((rex & REX_X) ? 8 : 0)];
328 op->indexreg = rd_reg32[index | ((rex & REX_X) ? 8 : 0)];
330 if (base == 5 && mod == 0) {
332 mod = 2; /* Fake disp32 */
334 op->basereg = rd_reg64[base | ((rex & REX_B) ? 8 : 0)];
336 op->basereg = rd_reg32[base | ((rex & REX_B) ? 8 : 0)];
344 op->segment |= SEG_NODISP;
347 op->segment |= SEG_DISP8;
348 op->offset = gets8(data);
352 op->segment |= SEG_DISP32;
353 op->offset = getu32(data);
362 * Determine whether the instruction template in t corresponds to the data
363 * stream in data. Return the number of bytes matched if so.
365 #define case4(x) case (x): case (x)+1: case (x)+2: case (x)+3
367 static int matches(const struct itemplate *t, uint8_t *data,
368 const struct prefix_info *prefix, int segsize, insn *ins)
370 uint8_t *r = (uint8_t *)(t->code);
371 uint8_t *origdata = data;
372 bool a_used = false, o_used = false;
373 enum prefixes drep = 0;
374 uint8_t lock = prefix->lock;
375 int osize = prefix->osize;
376 int asize = prefix->asize;
379 int s_field_for = -1; /* No 144/154 series code encountered */
381 for (i = 0; i < MAX_OPERANDS; i++) {
382 ins->oprs[i].segment = ins->oprs[i].disp_size =
383 (segsize == 64 ? SEG_64BIT : segsize == 32 ? SEG_32BIT : 0);
386 ins->rex = prefix->rex;
387 memset(ins->prefixes, 0, sizeof ins->prefixes);
389 if (t->flags & (segsize == 64 ? IF_NOLONG : IF_LONG))
392 if (prefix->rep == 0xF2)
394 else if (prefix->rep == 0xF3)
397 while ((c = *r++) != 0) {
398 opx = &ins->oprs[c & 3];
412 ins->oprs[0].basereg = 0;
415 ins->oprs[0].basereg = 2;
418 ins->oprs[0].basereg = 3;
428 ins->oprs[0].basereg = 4;
431 ins->oprs[0].basereg = 5;
441 ins->oprs[0].basereg = 0;
444 ins->oprs[0].basereg = 1;
447 ins->oprs[0].basereg = 2;
450 ins->oprs[0].basereg = 3;
460 ins->oprs[0].basereg = 4;
463 ins->oprs[0].basereg = 5;
472 int t = *r++, d = *data++;
473 if (d < t || d > t + 7)
476 opx->basereg = (d-t)+
477 (ins->rex & REX_B ? 8 : 0);
478 opx->segment |= SEG_RMREG;
484 opx->offset = (int8_t)*data++;
485 opx->segment |= SEG_SIGNED;
489 opx->offset = *data++;
493 opx->offset = *data++;
497 opx->offset = getu16(data);
503 opx->offset = getu32(data);
506 opx->offset = getu16(data);
509 if (segsize != asize)
510 opx->disp_size = asize;
514 opx->offset = getu32(data);
521 opx->offset = getu16(data);
527 opx->offset = getu32(data);
533 opx->offset = getu64(data);
541 opx->offset = gets8(data++);
542 opx->segment |= SEG_RELATIVE;
546 opx->offset = getu64(data);
551 opx->offset = gets16(data);
553 opx->segment |= SEG_RELATIVE;
554 opx->segment &= ~SEG_32BIT;
558 opx->segment |= SEG_RELATIVE;
560 opx->offset = getu16(data);
562 opx->segment &= ~(SEG_32BIT|SEG_64BIT);
563 } else if (osize == 32) {
564 opx->offset = getu32(data);
566 opx->segment &= ~SEG_64BIT;
567 opx->segment |= SEG_32BIT;
569 if (segsize != osize) {
571 (opx->type & ~SIZE_MASK)
572 | ((osize == 16) ? BITS16 : BITS32);
577 opx->offset = getu32(data);
579 opx->segment |= SEG_32BIT | SEG_RELATIVE;
588 opx->segment |= SEG_RMREG;
589 data = do_ea(data, modrm, asize, segsize,
590 &ins->oprs[(c >> 3) & 3], ins);
593 opx->basereg = ((modrm >> 3)&7)+
594 (ins->rex & REX_R ? 8 : 0);
599 if (s_field_for == (c & 3)) {
600 opx->offset = gets8(data);
603 opx->offset = getu16(data);
610 s_field_for = (*data & 0x02) ? c & 3 : -1;
611 if ((*data++ & ~0x02) != *r++)
616 if (s_field_for == (c & 3)) {
617 opx->offset = gets8(data);
620 opx->offset = getu32(data);
627 ins->drexdst = c & 3;
631 ins->rex |= REX_D|REX_OC;
632 ins->drexdst = c & 3;
641 data = do_drex(data, ins);
656 if (((modrm >> 3) & 07) != (c & 07))
657 return false; /* spare field doesn't match up */
658 data = do_ea(data, modrm, asize, segsize,
659 &ins->oprs[(c >> 3) & 07], ins);
680 if (asize != segsize)
694 if (prefix->rex & REX_B)
699 if (prefix->rex & REX_X)
704 if (prefix->rex & REX_R)
709 if (prefix->rex & REX_W)
728 if (osize != (segsize == 16) ? 16 : 32)
735 ins->rex |= REX_W; /* 64-bit only instruction */
741 if (!(ins->rex & (REX_P|REX_W)) || osize != 64)
748 int t = *r++, d = *data++;
749 if (d < t || d > t + 15)
752 ins->condition = d - t;
762 if (prefix->rep != 0xF2)
768 if (prefix->rep != 0xF3)
811 return false; /* Unknown code */
815 /* REX cannot be combined with DREX */
816 if ((ins->rex & REX_D) && (prefix->rex))
820 * Check for unused rep or a/o prefixes.
822 for (i = 0; i < t->operands; i++) {
823 if (ins->oprs[i].segment != SEG_RMREG)
828 if (ins->prefixes[PPS_LREP])
830 ins->prefixes[PPS_LREP] = P_LOCK;
833 if (ins->prefixes[PPS_LREP])
835 ins->prefixes[PPS_LREP] = drep;
838 if (osize != ((segsize == 16) ? 16 : 32)) {
839 enum prefixes pfx = 0;
853 if (ins->prefixes[PPS_OSIZE])
855 ins->prefixes[PPS_OSIZE] = pfx;
858 if (!a_used && asize != segsize) {
859 if (ins->prefixes[PPS_ASIZE])
861 ins->prefixes[PPS_ASIZE] = asize == 16 ? P_A16 : P_A32;
864 /* Fix: check for redundant REX prefixes */
866 return data - origdata;
869 int32_t disasm(uint8_t *data, char *output, int outbufsize, int segsize,
870 int32_t offset, int autosync, uint32_t prefer)
872 const struct itemplate * const *p, * const *best_p;
873 const struct disasm_index *ix;
875 int length, best_length = 0;
877 int i, slen, colon, n;
881 uint32_t goodness, best;
883 struct prefix_info prefix;
886 memset(&ins, 0, sizeof ins);
891 memset(&prefix, 0, sizeof prefix);
892 prefix.asize = segsize;
893 prefix.osize = (segsize == 64) ? 32 : segsize;
897 for (end_prefix = false; !end_prefix; ) {
901 prefix.rep = *data++;
904 prefix.lock = *data++;
907 segover = "cs", prefix.seg = *data++;
910 segover = "ss", prefix.seg = *data++;
913 segover = "ds", prefix.seg = *data++;
916 segover = "es", prefix.seg = *data++;
919 segover = "fs", prefix.seg = *data++;
922 segover = "gs", prefix.seg = *data++;
925 prefix.osize = (segsize == 16) ? 32 : 16;
926 prefix.osp = *data++;
929 prefix.asize = (segsize == 32) ? 16 : 32;
930 prefix.asp = *data++;
933 if (segsize == 64 && (*data & 0xf0) == REX_P) {
934 prefix.rex = *data++;
935 if (prefix.rex & REX_W)
944 best = -1; /* Worst possible */
950 while (ix->n == -1) {
951 ix = (const struct disasm_index *)ix->p + *dp++;
954 p = (const struct itemplate * const *)ix->p;
955 for (n = ix->n; n; n--, p++) {
956 if ((length = matches(*p, data, &prefix, segsize, &tmp_ins))) {
959 * Final check to make sure the types of r/m match up.
960 * XXX: Need to make sure this is actually correct.
962 for (i = 0; i < (*p)->operands; i++) {
963 if (!((*p)->opd[i] & SAME_AS) &&
965 /* If it's a mem-only EA but we have a
967 ((tmp_ins.oprs[i].segment & SEG_RMREG) &&
968 !(MEMORY & ~(*p)->opd[i])) ||
969 /* If it's a reg-only EA but we have a memory
971 (!(tmp_ins.oprs[i].segment & SEG_RMREG) &&
972 !(REG_EA & ~(*p)->opd[i]) &&
973 !((*p)->opd[i] & REG_SMASK)) ||
974 /* Register type mismatch (eg FS vs REG_DESS):
976 ((((*p)->opd[i] & (REGISTER | FPUREG)) ||
977 (tmp_ins.oprs[i].segment & SEG_RMREG)) &&
978 !whichreg((*p)->opd[i],
979 tmp_ins.oprs[i].basereg, tmp_ins.rex))
987 * Note: we always prefer instructions which incorporate
988 * prefixes in the instructions themselves. This is to allow
989 * e.g. PAUSE to be preferred to REP NOP, and deal with
990 * MMX/SSE instructions where prefixes are used to select
991 * between MMX and SSE register sets or outright opcode
996 goodness = ((*p)->flags & IF_PFMASK) ^ prefer;
998 for (i = 0; i < MAXPREFIX; i++)
999 if (tmp_ins.prefixes[i])
1001 if (nprefix < best_pref ||
1002 (nprefix == best_pref && goodness < best)) {
1003 /* This is the best one found so far */
1006 best_pref = nprefix;
1007 best_length = length;
1015 return 0; /* no instruction was matched */
1017 /* Pick the best match */
1019 length = best_length;
1023 /* TODO: snprintf returns the value that the string would have if
1024 * the buffer were long enough, and not the actual length of
1025 * the returned string, so each instance of using the return
1026 * value of snprintf should actually be checked to assure that
1027 * the return value is "sane." Maybe a macro wrapper could
1028 * be used for that purpose.
1030 for (i = 0; i < MAXPREFIX; i++)
1031 switch (ins.prefixes[i]) {
1033 slen += snprintf(output + slen, outbufsize - slen, "lock ");
1036 slen += snprintf(output + slen, outbufsize - slen, "rep ");
1039 slen += snprintf(output + slen, outbufsize - slen, "repe ");
1042 slen += snprintf(output + slen, outbufsize - slen, "repne ");
1045 slen += snprintf(output + slen, outbufsize - slen, "a16 ");
1048 slen += snprintf(output + slen, outbufsize - slen, "a32 ");
1051 slen += snprintf(output + slen, outbufsize - slen, "a64 ");
1054 slen += snprintf(output + slen, outbufsize - slen, "o16 ");
1057 slen += snprintf(output + slen, outbufsize - slen, "o32 ");
1060 slen += snprintf(output + slen, outbufsize - slen, "o64 ");
1066 for (i = 0; i < (int)elements(ico); i++)
1067 if ((*p)->opcode == ico[i]) {
1069 snprintf(output + slen, outbufsize - slen, "%s%s", icn[i],
1070 whichcond(ins.condition));
1073 if (i >= (int)elements(ico))
1075 snprintf(output + slen, outbufsize - slen, "%s",
1076 insn_names[(*p)->opcode]);
1078 length += data - origdata; /* fix up for prefixes */
1079 for (i = 0; i < (*p)->operands; i++) {
1080 opflags_t t = (*p)->opd[i];
1081 const operand *o = &ins.oprs[i];
1085 o = &ins.oprs[t & ~SAME_AS];
1086 t = (*p)->opd[t & ~SAME_AS];
1089 output[slen++] = (colon ? ':' : i == 0 ? ' ' : ',');
1092 if (o->segment & SEG_RELATIVE) {
1093 offs += offset + length;
1095 * sort out wraparound
1097 if (!(o->segment & (SEG_32BIT|SEG_64BIT)))
1100 * add sync marker, if autosync is on
1111 if ((t & (REGISTER | FPUREG)) ||
1112 (o->segment & SEG_RMREG)) {
1114 reg = whichreg(t, o->basereg, ins.rex);
1116 slen += snprintf(output + slen, outbufsize - slen, "to ");
1117 slen += snprintf(output + slen, outbufsize - slen, "%s",
1118 reg_names[reg - EXPR_REG_START]);
1119 } else if (!(UNITY & ~t)) {
1120 output[slen++] = '1';
1121 } else if (t & IMMEDIATE) {
1124 snprintf(output + slen, outbufsize - slen, "byte ");
1125 if (o->segment & SEG_SIGNED) {
1128 output[slen++] = '-';
1130 output[slen++] = '+';
1132 } else if (t & BITS16) {
1134 snprintf(output + slen, outbufsize - slen, "word ");
1135 } else if (t & BITS32) {
1137 snprintf(output + slen, outbufsize - slen, "dword ");
1138 } else if (t & BITS64) {
1140 snprintf(output + slen, outbufsize - slen, "qword ");
1141 } else if (t & NEAR) {
1143 snprintf(output + slen, outbufsize - slen, "near ");
1144 } else if (t & SHORT) {
1146 snprintf(output + slen, outbufsize - slen, "short ");
1149 snprintf(output + slen, outbufsize - slen, "0x%"PRIx64"",
1151 } else if (!(MEM_OFFS & ~t)) {
1153 snprintf(output + slen, outbufsize - slen,
1154 "[%s%s%s0x%"PRIx64"]",
1155 (segover ? segover : ""),
1156 (segover ? ":" : ""),
1157 (o->disp_size == 64 ? "qword " :
1158 o->disp_size == 32 ? "dword " :
1159 o->disp_size == 16 ? "word " : ""), offs);
1161 } else if (!(REGMEM & ~t)) {
1162 int started = false;
1165 snprintf(output + slen, outbufsize - slen, "byte ");
1168 snprintf(output + slen, outbufsize - slen, "word ");
1171 snprintf(output + slen, outbufsize - slen, "dword ");
1174 snprintf(output + slen, outbufsize - slen, "qword ");
1177 snprintf(output + slen, outbufsize - slen, "tword ");
1180 snprintf(output + slen, outbufsize - slen, "oword ");
1182 slen += snprintf(output + slen, outbufsize - slen, "far ");
1185 snprintf(output + slen, outbufsize - slen, "near ");
1186 output[slen++] = '[';
1188 slen += snprintf(output + slen, outbufsize - slen, "%s",
1189 (o->disp_size == 64 ? "qword " :
1190 o->disp_size == 32 ? "dword " :
1191 o->disp_size == 16 ? "word " :
1193 if (o->eaflags & EAF_REL)
1194 slen += snprintf(output + slen, outbufsize - slen, "rel ");
1197 snprintf(output + slen, outbufsize - slen, "%s:",
1201 if (o->basereg != -1) {
1202 slen += snprintf(output + slen, outbufsize - slen, "%s",
1203 reg_names[(o->basereg -
1207 if (o->indexreg != -1) {
1209 output[slen++] = '+';
1210 slen += snprintf(output + slen, outbufsize - slen, "%s",
1211 reg_names[(o->indexreg -
1215 snprintf(output + slen, outbufsize - slen, "*%d",
1221 if (o->segment & SEG_DISP8) {
1223 uint8_t offset = offs;
1224 if ((int8_t)offset < 0) {
1231 snprintf(output + slen, outbufsize - slen, "%s0x%"PRIx8"",
1233 } else if (o->segment & SEG_DISP16) {
1235 uint16_t offset = offs;
1236 if ((int16_t)offset < 0 && started) {
1240 prefix = started ? "+" : "";
1243 snprintf(output + slen, outbufsize - slen,
1244 "%s0x%"PRIx16"", prefix, offset);
1245 } else if (o->segment & SEG_DISP32) {
1246 if (prefix.asize == 64) {
1248 uint64_t offset = (int64_t)(int32_t)offs;
1249 if ((int32_t)offs < 0 && started) {
1253 prefix = started ? "+" : "";
1256 snprintf(output + slen, outbufsize - slen,
1257 "%s0x%"PRIx64"", prefix, offset);
1260 uint32_t offset = offs;
1261 if ((int32_t) offset < 0 && started) {
1265 prefix = started ? "+" : "";
1268 snprintf(output + slen, outbufsize - slen,
1269 "%s0x%"PRIx32"", prefix, offset);
1272 output[slen++] = ']';
1275 snprintf(output + slen, outbufsize - slen, "<operand%d>",
1279 output[slen] = '\0';
1280 if (segover) { /* unused segment override */
1282 int count = slen + 1;
1284 p[count + 3] = p[count];
1285 strncpy(output, segover, 2);
1291 int32_t eatbyte(uint8_t *data, char *output, int outbufsize)
1293 snprintf(output, outbufsize, "db 0x%02X", *data);