2018-02-04 11:42:42 +00:00
|
|
|
/* radare - LGPL - Copyright 2010-2018 - pancake, nibble */
|
2010-03-12 02:05:20 +00:00
|
|
|
|
|
|
|
#include <r_anal.h>
|
|
|
|
#include <r_util.h>
|
|
|
|
#include <r_list.h>
|
|
|
|
|
2016-02-15 16:49:17 +00:00
|
|
|
#define SDB_VARUSED_FMT "qzdq"
|
|
|
|
struct VarUsedType {
|
|
|
|
ut64 fcn_addr;
|
|
|
|
char *type;
|
|
|
|
ut32 scope;
|
|
|
|
st64 delta;
|
|
|
|
};
|
|
|
|
|
2014-03-26 13:47:30 +00:00
|
|
|
R_API RAnalOp *r_anal_op_new () {
|
|
|
|
RAnalOp *op = R_NEW0 (RAnalOp);
|
2016-11-03 15:22:56 +00:00
|
|
|
if (op) {
|
|
|
|
op->addr = UT64_MAX;
|
|
|
|
op->jump = UT64_MAX;
|
|
|
|
op->fail = UT64_MAX;
|
|
|
|
op->ptr = UT64_MAX;
|
|
|
|
op->val = UT64_MAX;
|
|
|
|
r_strbuf_init (&op->esil);
|
|
|
|
}
|
2011-02-24 13:06:49 +00:00
|
|
|
return op;
|
2010-03-12 02:05:20 +00:00
|
|
|
}
|
|
|
|
|
2011-02-24 13:06:49 +00:00
|
|
|
R_API RList *r_anal_op_list_new() {
|
2010-03-12 02:05:20 +00:00
|
|
|
RList *list = r_list_new ();
|
2017-08-09 17:21:53 +00:00
|
|
|
if (list) {
|
|
|
|
list->free = &r_anal_op_free;
|
2016-06-17 12:26:24 +00:00
|
|
|
}
|
2010-03-12 02:05:20 +00:00
|
|
|
return list;
|
|
|
|
}
|
|
|
|
|
2016-05-24 10:32:45 +00:00
|
|
|
R_API bool r_anal_op_fini(RAnalOp *op) {
|
2016-05-29 22:38:35 +00:00
|
|
|
if (!op) {
|
2016-05-24 10:32:45 +00:00
|
|
|
return false;
|
|
|
|
}
|
2016-02-15 16:49:17 +00:00
|
|
|
r_anal_var_free (op->var);
|
2016-10-26 21:40:17 +00:00
|
|
|
op->var = NULL;
|
2013-12-01 22:33:07 +00:00
|
|
|
r_anal_value_free (op->src[0]);
|
|
|
|
r_anal_value_free (op->src[1]);
|
|
|
|
r_anal_value_free (op->src[2]);
|
2016-10-26 21:40:17 +00:00
|
|
|
op->src[0] = NULL;
|
|
|
|
op->src[1] = NULL;
|
|
|
|
op->src[2] = NULL;
|
2013-12-01 22:33:07 +00:00
|
|
|
r_anal_value_free (op->dst);
|
2016-10-26 21:40:17 +00:00
|
|
|
op->dst = NULL;
|
2017-03-10 19:05:28 +00:00
|
|
|
r_strbuf_fini (&op->opex);
|
2016-04-03 22:52:45 +00:00
|
|
|
r_strbuf_fini (&op->esil);
|
2014-03-26 13:47:30 +00:00
|
|
|
r_anal_switch_op_free (op->switch_op);
|
2018-02-04 11:42:42 +00:00
|
|
|
op->switch_op = NULL;
|
2016-04-03 22:36:18 +00:00
|
|
|
R_FREE (op->mnemonic);
|
2016-05-24 10:32:45 +00:00
|
|
|
return true;
|
2011-11-13 23:21:25 +00:00
|
|
|
}
|
|
|
|
|
2011-02-24 13:06:49 +00:00
|
|
|
R_API void r_anal_op_free(void *_op) {
|
2016-08-24 20:02:38 +00:00
|
|
|
if (!_op) {
|
|
|
|
return;
|
|
|
|
}
|
2011-11-13 23:21:25 +00:00
|
|
|
r_anal_op_fini (_op);
|
2016-04-03 22:36:18 +00:00
|
|
|
memset (_op, 0, sizeof (RAnalOp));
|
2011-11-13 23:21:25 +00:00
|
|
|
free (_op);
|
2010-03-12 02:05:20 +00:00
|
|
|
}
|
|
|
|
|
2016-02-15 16:49:17 +00:00
|
|
|
static RAnalVar *get_used_var(RAnal *anal, RAnalOp *op) {
|
2018-04-25 02:28:41 +00:00
|
|
|
char *inst_key = r_str_newf ("inst.0x%"PFMT64x".vars", op->addr);
|
|
|
|
char *var_def = sdb_get (anal->sdb_fcns, inst_key, 0);
|
2016-02-15 16:49:17 +00:00
|
|
|
struct VarUsedType vut;
|
2018-04-25 02:28:41 +00:00
|
|
|
RAnalVar *res = NULL;
|
|
|
|
if (sdb_fmt_tobin (var_def, SDB_VARUSED_FMT, &vut) == 4) {
|
|
|
|
res = r_anal_var_get (anal, vut.fcn_addr, vut.type[0], vut.scope, vut.delta);
|
|
|
|
sdb_fmt_free (&vut, SDB_VARUSED_FMT);
|
2016-02-24 05:41:36 +00:00
|
|
|
}
|
2018-04-25 02:28:41 +00:00
|
|
|
free (inst_key);
|
|
|
|
free (var_def);
|
2016-02-15 16:49:17 +00:00
|
|
|
return res;
|
|
|
|
}
|
|
|
|
|
2018-03-15 11:31:01 +00:00
|
|
|
R_API int r_anal_op(RAnal *anal, RAnalOp *op, ut64 addr, const ut8 *data, int len, int mask) {
|
2016-11-22 14:43:20 +00:00
|
|
|
//len will end up in memcmp so check for negative
|
2016-06-17 13:52:57 +00:00
|
|
|
if (!anal || len < 0) {
|
|
|
|
return -1;
|
|
|
|
}
|
2018-03-15 11:31:01 +00:00
|
|
|
|
|
|
|
anal->decode = mask & R_ANAL_OP_MASK_ESIL ? true : false;
|
2018-05-26 09:42:14 +00:00
|
|
|
anal->fillval = mask & R_ANAL_OP_MASK_VAL ? true : false;
|
2018-03-15 11:31:01 +00:00
|
|
|
|
2015-10-14 00:11:53 +00:00
|
|
|
if (anal->pcalign) {
|
|
|
|
if (addr % anal->pcalign) {
|
|
|
|
memset (op, 0, sizeof (RAnalOp));
|
|
|
|
op->type = R_ANAL_OP_TYPE_ILL;
|
|
|
|
op->addr = addr;
|
|
|
|
op->size = 1;
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
}
|
2016-06-17 16:38:25 +00:00
|
|
|
memset (op, 0, sizeof (RAnalOp));
|
2016-11-03 15:22:56 +00:00
|
|
|
if (len > 0 && anal->cur && anal->cur->op) {
|
2017-02-07 22:51:44 +00:00
|
|
|
//use core binding to set asm.bits correctly based on the addr
|
|
|
|
//this is because of the hassle of arm/thumb
|
2017-02-08 21:18:56 +00:00
|
|
|
if (anal && anal->coreb.archbits) {
|
|
|
|
anal->coreb.archbits (anal->coreb.core, addr);
|
|
|
|
}
|
2017-08-09 17:21:53 +00:00
|
|
|
int ret = anal->cur->op (anal, op, addr, data, len);
|
|
|
|
if (ret < 1) {
|
|
|
|
op->type = R_ANAL_OP_TYPE_ILL;
|
|
|
|
}
|
2014-11-06 15:01:00 +00:00
|
|
|
op->addr = addr;
|
2016-11-23 10:31:24 +00:00
|
|
|
/* consider at least 1 byte to be part of the opcode */
|
|
|
|
if (op->nopcode < 1) {
|
|
|
|
op->nopcode = 1;
|
|
|
|
}
|
2016-06-28 21:14:16 +00:00
|
|
|
//free the previous var in op->var
|
2017-08-09 17:21:53 +00:00
|
|
|
RAnalVar *tmp = get_used_var (anal, op);
|
2016-06-27 21:26:13 +00:00
|
|
|
if (tmp) {
|
|
|
|
r_anal_var_free (op->var);
|
|
|
|
op->var = tmp;
|
|
|
|
}
|
2017-08-09 17:21:53 +00:00
|
|
|
return ret;
|
2013-07-04 01:34:28 +00:00
|
|
|
}
|
2017-08-09 17:21:53 +00:00
|
|
|
if (!memcmp (data, "\xff\xff\xff\xff", R_MIN (4, len))) {
|
|
|
|
op->type = R_ANAL_OP_TYPE_ILL;
|
|
|
|
return R_MIN (2, len); // HACK
|
|
|
|
}
|
|
|
|
op->type = R_ANAL_OP_TYPE_MOV;
|
|
|
|
return R_MIN (2, len); // HACK
|
2010-03-12 02:05:20 +00:00
|
|
|
}
|
2010-06-21 09:55:48 +00:00
|
|
|
|
2017-02-07 22:51:44 +00:00
|
|
|
R_API RAnalOp *r_anal_op_copy(RAnalOp *op) {
|
2016-05-24 10:32:45 +00:00
|
|
|
RAnalOp *nop = R_NEW0 (RAnalOp);
|
2017-02-07 22:51:44 +00:00
|
|
|
if (!nop) {
|
|
|
|
return NULL;
|
|
|
|
}
|
2014-03-26 13:47:30 +00:00
|
|
|
*nop = *op;
|
2015-07-21 04:06:00 +00:00
|
|
|
if (op->mnemonic) {
|
|
|
|
nop->mnemonic = strdup (op->mnemonic);
|
|
|
|
if (!nop->mnemonic) {
|
|
|
|
free (nop);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
nop->mnemonic = NULL;
|
2015-06-17 10:36:08 +00:00
|
|
|
}
|
2011-03-28 08:24:01 +00:00
|
|
|
nop->src[0] = r_anal_value_copy (op->src[0]);
|
|
|
|
nop->src[1] = r_anal_value_copy (op->src[1]);
|
|
|
|
nop->src[2] = r_anal_value_copy (op->src[2]);
|
|
|
|
nop->dst = r_anal_value_copy (op->dst);
|
2013-12-10 02:35:59 +00:00
|
|
|
r_strbuf_init (&nop->esil);
|
|
|
|
r_strbuf_set (&nop->esil, r_strbuf_get (&op->esil));
|
2011-03-28 08:24:01 +00:00
|
|
|
return nop;
|
|
|
|
}
|
|
|
|
|
2011-02-02 23:20:39 +00:00
|
|
|
// TODO: return RAnalException *
|
2017-01-19 20:44:48 +00:00
|
|
|
R_API int r_anal_op_execute(RAnal *anal, RAnalOp *op) {
|
2011-03-28 08:24:01 +00:00
|
|
|
while (op) {
|
2016-05-24 10:32:45 +00:00
|
|
|
if (op->delay > 0) {
|
2011-03-28 08:24:01 +00:00
|
|
|
anal->queued = r_anal_op_copy (op);
|
2015-09-14 09:31:54 +00:00
|
|
|
return false;
|
2011-03-28 08:24:01 +00:00
|
|
|
}
|
|
|
|
switch (op->type) {
|
|
|
|
case R_ANAL_OP_TYPE_JMP:
|
|
|
|
case R_ANAL_OP_TYPE_UJMP:
|
2016-09-22 11:42:06 +00:00
|
|
|
case R_ANAL_OP_TYPE_RJMP:
|
|
|
|
case R_ANAL_OP_TYPE_IJMP:
|
|
|
|
case R_ANAL_OP_TYPE_IRJMP:
|
2011-03-28 08:24:01 +00:00
|
|
|
case R_ANAL_OP_TYPE_CALL:
|
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_ADD:
|
|
|
|
// dst = src[0] + src[1] + src[2]
|
2012-07-17 08:00:23 +00:00
|
|
|
r_anal_value_set_ut64 (anal, op->dst,
|
2016-06-17 12:26:24 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[0]) +
|
|
|
|
r_anal_value_to_ut64 (anal, op->src[1]) +
|
2011-03-28 08:24:01 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[2]));
|
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_SUB:
|
|
|
|
// dst = src[0] + src[1] + src[2]
|
2012-07-17 08:00:23 +00:00
|
|
|
r_anal_value_set_ut64 (anal, op->dst,
|
2016-06-17 12:26:24 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[0]) -
|
|
|
|
r_anal_value_to_ut64 (anal, op->src[1]) -
|
2011-03-28 08:24:01 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[2]));
|
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_DIV:
|
|
|
|
{
|
|
|
|
ut64 div = r_anal_value_to_ut64 (anal, op->src[1]);
|
|
|
|
if (div == 0) {
|
|
|
|
eprintf ("r_anal_op_execute: division by zero\n");
|
|
|
|
eprintf ("TODO: throw RAnalException\n");
|
2012-07-17 08:00:23 +00:00
|
|
|
} else r_anal_value_set_ut64 (anal, op->dst,
|
2011-03-28 08:24:01 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[0])/div);
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_MUL:
|
2012-07-17 08:00:23 +00:00
|
|
|
r_anal_value_set_ut64 (anal, op->dst,
|
2011-03-28 08:24:01 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[0])*
|
|
|
|
r_anal_value_to_ut64 (anal, op->src[1]));
|
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_MOV:
|
|
|
|
// dst = src[0]
|
2012-07-17 08:00:23 +00:00
|
|
|
r_anal_value_set_ut64 (anal, op->dst,
|
2011-03-28 08:24:01 +00:00
|
|
|
r_anal_value_to_ut64 (anal, op->src[0]));
|
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_NOP:
|
|
|
|
// do nothing
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
op = op->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (anal->queued) {
|
|
|
|
anal->queued->delay--;
|
|
|
|
if (anal->queued->delay == 0) {
|
|
|
|
r_anal_op_execute (anal, anal->queued);
|
|
|
|
r_anal_op_free (anal->queued);
|
|
|
|
anal->queued = NULL;
|
|
|
|
}
|
2011-02-02 23:20:39 +00:00
|
|
|
}
|
2015-09-14 09:31:54 +00:00
|
|
|
return true;
|
2011-02-02 23:20:39 +00:00
|
|
|
}
|
|
|
|
|
2018-05-29 04:51:31 +00:00
|
|
|
R_API bool r_anal_op_nonlinear(int t) {
|
|
|
|
switch (t) {
|
|
|
|
//call
|
|
|
|
case R_ANAL_OP_TYPE_CALL:
|
|
|
|
case R_ANAL_OP_TYPE_RCALL:
|
|
|
|
case R_ANAL_OP_TYPE_ICALL:
|
|
|
|
case R_ANAL_OP_TYPE_UCALL:
|
|
|
|
case R_ANAL_OP_TYPE_IRCALL:
|
|
|
|
case R_ANAL_OP_TYPE_UCCALL:
|
|
|
|
// jmp
|
|
|
|
case R_ANAL_OP_TYPE_JMP:
|
|
|
|
case R_ANAL_OP_TYPE_MJMP:
|
|
|
|
case R_ANAL_OP_TYPE_UJMP:
|
|
|
|
case R_ANAL_OP_TYPE_CJMP:
|
|
|
|
case R_ANAL_OP_TYPE_UCJMP:
|
|
|
|
case R_ANAL_OP_TYPE_RJMP:
|
|
|
|
case R_ANAL_OP_TYPE_IJMP:
|
|
|
|
case R_ANAL_OP_TYPE_IRJMP:
|
|
|
|
// trap| ill| unk
|
|
|
|
case R_ANAL_OP_TYPE_TRAP:
|
|
|
|
case R_ANAL_OP_TYPE_ILL:
|
|
|
|
case R_ANAL_OP_TYPE_UNK:
|
|
|
|
return true;
|
|
|
|
default:
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-06-05 19:43:32 +00:00
|
|
|
R_API bool r_anal_op_ismemref(int t) {
|
|
|
|
switch (t) {
|
|
|
|
case R_ANAL_OP_TYPE_LOAD:
|
|
|
|
case R_ANAL_OP_TYPE_MOV:
|
|
|
|
case R_ANAL_OP_TYPE_STORE:
|
|
|
|
case R_ANAL_OP_TYPE_LEA:
|
|
|
|
case R_ANAL_OP_TYPE_CMP:
|
|
|
|
return true;
|
|
|
|
default:
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-03 23:46:59 +00:00
|
|
|
R_API const char *r_anal_optype_to_string(int t) {
|
2016-11-22 22:59:04 +00:00
|
|
|
t &= R_ANAL_OP_TYPE_MASK; // ignore the modifier bits... we dont want this!
|
2012-11-08 08:49:27 +00:00
|
|
|
switch (t) {
|
2015-03-03 23:46:59 +00:00
|
|
|
case R_ANAL_OP_TYPE_IO : return "io";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_ACMP : return "acmp";
|
|
|
|
case R_ANAL_OP_TYPE_ADD : return "add";
|
2018-01-08 10:21:48 +00:00
|
|
|
case R_ANAL_OP_TYPE_SYNC : return "sync";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_AND : return "and";
|
2012-11-08 08:49:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_CALL : return "call";
|
2014-02-25 23:03:42 +00:00
|
|
|
case R_ANAL_OP_TYPE_CCALL : return "ccall";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_CJMP : return "cjmp";
|
2016-05-29 22:38:35 +00:00
|
|
|
case R_ANAL_OP_TYPE_MJMP : return "mjmp";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_CMP : return "cmp";
|
2014-02-25 23:03:42 +00:00
|
|
|
case R_ANAL_OP_TYPE_CRET : return "cret";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_DIV : return "div";
|
2012-11-08 08:49:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_ILL : return "ill";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_JMP : return "jmp";
|
|
|
|
case R_ANAL_OP_TYPE_LEA : return "lea";
|
|
|
|
case R_ANAL_OP_TYPE_LEAVE : return "leave";
|
|
|
|
case R_ANAL_OP_TYPE_LOAD : return "load";
|
2016-12-14 23:14:33 +00:00
|
|
|
case R_ANAL_OP_TYPE_NEW : return "new";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_MOD : return "mod";
|
2015-10-18 20:14:06 +00:00
|
|
|
case R_ANAL_OP_TYPE_CMOV : return "cmov";
|
2012-11-08 08:49:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_MOV : return "mov";
|
|
|
|
case R_ANAL_OP_TYPE_MUL : return "mul";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_NOP : return "nop";
|
|
|
|
case R_ANAL_OP_TYPE_NOT : return "not";
|
|
|
|
case R_ANAL_OP_TYPE_NULL : return "null";
|
|
|
|
case R_ANAL_OP_TYPE_OR : return "or";
|
|
|
|
case R_ANAL_OP_TYPE_POP : return "pop";
|
|
|
|
case R_ANAL_OP_TYPE_PUSH : return "push";
|
|
|
|
case R_ANAL_OP_TYPE_REP : return "rep";
|
|
|
|
case R_ANAL_OP_TYPE_RET : return "ret";
|
|
|
|
case R_ANAL_OP_TYPE_ROL : return "rol";
|
|
|
|
case R_ANAL_OP_TYPE_ROR : return "ror";
|
|
|
|
case R_ANAL_OP_TYPE_SAL : return "sal";
|
2014-10-15 23:51:48 +00:00
|
|
|
case R_ANAL_OP_TYPE_SAR : return "sar";
|
2012-11-08 08:49:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_SHL : return "shl";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_SHR : return "shr";
|
2012-11-08 08:49:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_STORE : return "store";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_SUB : return "sub";
|
|
|
|
case R_ANAL_OP_TYPE_SWI : return "swi";
|
2015-03-08 21:09:59 +00:00
|
|
|
case R_ANAL_OP_TYPE_SWITCH: return "switch";
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_TRAP : return "trap";
|
|
|
|
case R_ANAL_OP_TYPE_UCALL : return "ucall";
|
2016-09-22 11:42:06 +00:00
|
|
|
case R_ANAL_OP_TYPE_RCALL : return "ucall"; // needs to be changed
|
|
|
|
case R_ANAL_OP_TYPE_ICALL : return "ucall"; // needs to be changed
|
|
|
|
case R_ANAL_OP_TYPE_IRCALL: return "ucall"; // needs to be changed
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_UCCALL: return "uccall";
|
|
|
|
case R_ANAL_OP_TYPE_UCJMP : return "ucjmp";
|
|
|
|
case R_ANAL_OP_TYPE_UJMP : return "ujmp";
|
2016-09-22 11:42:06 +00:00
|
|
|
case R_ANAL_OP_TYPE_RJMP : return "ujmp"; // needs to be changed
|
|
|
|
case R_ANAL_OP_TYPE_IJMP : return "ujmp"; // needs to be changed
|
|
|
|
case R_ANAL_OP_TYPE_IRJMP : return "ujmp"; // needs to be changed
|
2015-01-15 00:31:21 +00:00
|
|
|
case R_ANAL_OP_TYPE_UNK : return "unk";
|
|
|
|
case R_ANAL_OP_TYPE_UPUSH : return "upush";
|
|
|
|
case R_ANAL_OP_TYPE_XCHG : return "xchg";
|
|
|
|
case R_ANAL_OP_TYPE_XOR : return "xor";
|
2015-03-08 21:09:59 +00:00
|
|
|
case R_ANAL_OP_TYPE_CASE : return "case";
|
2015-10-15 00:22:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_CPL : return "cpl";
|
2015-10-15 18:02:36 +00:00
|
|
|
case R_ANAL_OP_TYPE_CRYPTO: return "crypto";
|
2012-11-08 08:49:27 +00:00
|
|
|
}
|
|
|
|
return "undefined";
|
|
|
|
}
|
|
|
|
|
2013-06-09 01:25:32 +00:00
|
|
|
R_API const char *r_anal_op_to_esil_string(RAnal *anal, RAnalOp *op) {
|
2013-12-10 02:35:59 +00:00
|
|
|
return r_strbuf_get (&op->esil);
|
2013-06-09 01:25:32 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// TODO: use esil here?
|
2011-02-24 13:06:49 +00:00
|
|
|
R_API char *r_anal_op_to_string(RAnal *anal, RAnalOp *op) {
|
2016-06-17 12:26:24 +00:00
|
|
|
RAnalBlock *bb;
|
2012-07-19 02:54:22 +00:00
|
|
|
RAnalFunction *f;
|
2017-08-09 17:21:53 +00:00
|
|
|
char *cstr, ret[128];
|
2010-06-21 09:55:48 +00:00
|
|
|
char *r0 = r_anal_value_to_string (op->dst);
|
|
|
|
char *a0 = r_anal_value_to_string (op->src[0]);
|
|
|
|
char *a1 = r_anal_value_to_string (op->src[1]);
|
2016-02-22 22:21:29 +00:00
|
|
|
if (!r0) r0 = strdup ("?");
|
|
|
|
if (!a0) a0 = strdup ("?");
|
|
|
|
if (!a1) a1 = strdup ("?");
|
2010-06-21 09:55:48 +00:00
|
|
|
|
|
|
|
switch (op->type) {
|
|
|
|
case R_ANAL_OP_TYPE_MOV:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s = %s", r0, a0);
|
2010-06-21 09:55:48 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_CJMP:
|
2016-06-17 12:26:24 +00:00
|
|
|
if ((bb = r_anal_bb_from_offset (anal, op->addr))) {
|
2011-02-28 12:07:41 +00:00
|
|
|
cstr = r_anal_cond_to_string (bb->cond);
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "if (%s) goto 0x%"PFMT64x, cstr, op->jump);
|
2011-02-28 12:07:41 +00:00
|
|
|
free (cstr);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "if (%s) goto 0x%"PFMT64x, "?", op->jump);
|
2011-02-28 12:07:41 +00:00
|
|
|
}
|
2010-06-21 09:55:48 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_JMP:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "goto 0x%"PFMT64x, op->jump);
|
2010-06-21 09:55:48 +00:00
|
|
|
break;
|
2011-03-01 18:16:29 +00:00
|
|
|
case R_ANAL_OP_TYPE_UJMP:
|
2016-09-22 11:42:06 +00:00
|
|
|
case R_ANAL_OP_TYPE_RJMP:
|
|
|
|
case R_ANAL_OP_TYPE_IJMP:
|
|
|
|
case R_ANAL_OP_TYPE_IRJMP:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "goto %s", r0);
|
2011-03-01 18:16:29 +00:00
|
|
|
break;
|
2011-02-27 02:39:27 +00:00
|
|
|
case R_ANAL_OP_TYPE_PUSH:
|
|
|
|
case R_ANAL_OP_TYPE_UPUSH:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "push %s", a0);
|
2011-02-27 02:39:27 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_POP:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "pop %s", r0);
|
2011-02-27 02:39:27 +00:00
|
|
|
break;
|
2011-02-28 16:27:08 +00:00
|
|
|
case R_ANAL_OP_TYPE_UCALL:
|
2016-09-22 11:42:06 +00:00
|
|
|
case R_ANAL_OP_TYPE_RCALL:
|
|
|
|
case R_ANAL_OP_TYPE_ICALL:
|
|
|
|
case R_ANAL_OP_TYPE_IRCALL:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s()", r0);
|
2011-02-28 16:27:08 +00:00
|
|
|
break;
|
2010-06-21 09:55:48 +00:00
|
|
|
case R_ANAL_OP_TYPE_CALL:
|
2014-09-26 13:40:17 +00:00
|
|
|
f = r_anal_get_fcn_in (anal, op->jump, R_ANAL_FCN_TYPE_NULL);
|
2017-08-09 17:21:53 +00:00
|
|
|
if (f) {
|
|
|
|
snprintf (ret, sizeof (ret), "%s()", f->name);
|
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "0x%"PFMT64x"()", op->jump);
|
|
|
|
}
|
2010-06-21 09:55:48 +00:00
|
|
|
break;
|
2014-02-25 23:03:42 +00:00
|
|
|
case R_ANAL_OP_TYPE_CCALL:
|
2014-09-26 13:40:17 +00:00
|
|
|
f = r_anal_get_fcn_in (anal, op->jump, R_ANAL_FCN_TYPE_NULL);
|
2016-06-17 12:26:24 +00:00
|
|
|
if ((bb = r_anal_bb_from_offset (anal, op->addr))) {
|
2014-02-25 23:03:42 +00:00
|
|
|
cstr = r_anal_cond_to_string (bb->cond);
|
|
|
|
if (f) snprintf (ret, sizeof (ret), "if (%s) %s()", cstr, f->name);
|
|
|
|
else snprintf (ret, sizeof (ret), "if (%s) 0x%"PFMT64x"()", cstr, op->jump);
|
|
|
|
free (cstr);
|
|
|
|
} else {
|
|
|
|
if (f) snprintf (ret, sizeof (ret), "if (unk) %s()", f->name);
|
|
|
|
else snprintf (ret, sizeof (ret), "if (unk) 0x%"PFMT64x"()", op->jump);
|
|
|
|
}
|
|
|
|
break;
|
2011-02-27 15:17:05 +00:00
|
|
|
case R_ANAL_OP_TYPE_ADD:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s += %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "%s = %s + %s", r0, a0, a1);
|
|
|
|
}
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
2010-06-21 09:55:48 +00:00
|
|
|
case R_ANAL_OP_TYPE_SUB:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s -= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "%s = %s - %s", r0, a0, a1);
|
|
|
|
}
|
2010-06-21 09:55:48 +00:00
|
|
|
break;
|
2011-02-27 15:17:05 +00:00
|
|
|
case R_ANAL_OP_TYPE_MUL:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s *= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "%s = %s * %s", r0, a0, a1);
|
|
|
|
}
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_DIV:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s /= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else snprintf (ret, sizeof (ret), "%s = %s / %s", r0, a0, a1);
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_AND:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s &= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else snprintf (ret, sizeof (ret), "%s = %s & %s", r0, a0, a1);
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_OR:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s |= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else snprintf (ret, sizeof (ret), "%s = %s | %s", r0, a0, a1);
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_XOR:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s ^= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else snprintf (ret, sizeof (ret), "%s = %s ^ %s", r0, a0, a1);
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
2011-03-01 18:16:29 +00:00
|
|
|
case R_ANAL_OP_TYPE_LEA:
|
2011-08-18 15:03:45 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s -> %s", r0, a0);
|
2011-03-01 18:16:29 +00:00
|
|
|
break;
|
2011-02-28 12:07:41 +00:00
|
|
|
case R_ANAL_OP_TYPE_CMP:
|
2011-08-18 15:03:45 +00:00
|
|
|
memcpy (ret, ";", 2);
|
2011-02-28 12:07:41 +00:00
|
|
|
break;
|
2011-02-27 15:17:05 +00:00
|
|
|
case R_ANAL_OP_TYPE_NOP:
|
2011-07-06 07:40:23 +00:00
|
|
|
memcpy (ret, "nop", 4);
|
2011-02-27 15:17:05 +00:00
|
|
|
break;
|
2011-02-28 12:07:41 +00:00
|
|
|
case R_ANAL_OP_TYPE_RET:
|
2011-07-06 07:40:23 +00:00
|
|
|
memcpy (ret, "ret", 4);
|
2011-02-28 12:07:41 +00:00
|
|
|
break;
|
2014-02-25 23:03:42 +00:00
|
|
|
case R_ANAL_OP_TYPE_CRET:
|
2016-06-17 12:26:24 +00:00
|
|
|
if ((bb = r_anal_bb_from_offset (anal, op->addr))) {
|
2014-02-25 23:03:42 +00:00
|
|
|
cstr = r_anal_cond_to_string (bb->cond);
|
|
|
|
snprintf (ret, sizeof (ret), "if (%s) ret", cstr);
|
|
|
|
free (cstr);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
strcpy (ret, "if (unk) ret");
|
2014-02-25 23:03:42 +00:00
|
|
|
}
|
|
|
|
break;
|
2011-03-01 18:16:29 +00:00
|
|
|
case R_ANAL_OP_TYPE_LEAVE:
|
2011-07-06 07:40:23 +00:00
|
|
|
memcpy (ret, "leave", 6);
|
2011-03-01 18:16:29 +00:00
|
|
|
break;
|
2014-01-02 05:09:46 +00:00
|
|
|
case R_ANAL_OP_TYPE_MOD:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2014-03-18 01:21:52 +00:00
|
|
|
snprintf (ret, sizeof (ret), "%s %%= %s", r0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "%s = %s %% %s", r0, a0, a1);
|
|
|
|
}
|
2014-01-02 05:09:46 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_XCHG:
|
2016-06-17 12:26:24 +00:00
|
|
|
if (!a1 || !strcmp (a0, a1)) {
|
2014-01-02 05:09:46 +00:00
|
|
|
snprintf (ret, sizeof (ret), "tmp = %s; %s = %s; %s = tmp", r0, r0, a0, a0);
|
2016-06-17 12:26:24 +00:00
|
|
|
} else {
|
|
|
|
snprintf (ret, sizeof (ret), "%s = %s ^ %s", r0, a0, a1);
|
|
|
|
}
|
2014-01-02 05:09:46 +00:00
|
|
|
break;
|
|
|
|
case R_ANAL_OP_TYPE_ROL:
|
|
|
|
case R_ANAL_OP_TYPE_ROR:
|
|
|
|
case R_ANAL_OP_TYPE_SWITCH:
|
2014-08-11 02:52:53 +00:00
|
|
|
case R_ANAL_OP_TYPE_CASE:
|
2014-01-02 05:09:46 +00:00
|
|
|
eprintf ("Command not implemented.\n");
|
2014-01-04 04:03:24 +00:00
|
|
|
free (r0);
|
|
|
|
free (a0);
|
|
|
|
free (a1);
|
|
|
|
return NULL;
|
2010-06-21 09:55:48 +00:00
|
|
|
default:
|
2011-08-18 15:03:45 +00:00
|
|
|
free (r0);
|
|
|
|
free (a0);
|
|
|
|
free (a1);
|
|
|
|
return NULL;
|
2010-06-21 09:55:48 +00:00
|
|
|
}
|
|
|
|
free (r0);
|
|
|
|
free (a0);
|
|
|
|
free (a1);
|
2011-08-18 15:03:45 +00:00
|
|
|
return strdup (ret);
|
2010-06-21 09:55:48 +00:00
|
|
|
}
|
2014-09-22 11:45:36 +00:00
|
|
|
|
2016-06-15 23:43:41 +00:00
|
|
|
R_API const char *r_anal_stackop_tostring(int s) {
|
2014-09-22 11:45:36 +00:00
|
|
|
switch (s) {
|
|
|
|
case R_ANAL_STACK_NULL:
|
|
|
|
return "null";
|
|
|
|
case R_ANAL_STACK_NOP:
|
|
|
|
return "nop";
|
|
|
|
case R_ANAL_STACK_INC:
|
|
|
|
return "inc";
|
|
|
|
case R_ANAL_STACK_GET:
|
|
|
|
return "get";
|
|
|
|
case R_ANAL_STACK_SET:
|
|
|
|
return "set";
|
2016-05-11 10:59:32 +00:00
|
|
|
case R_ANAL_STACK_RESET:
|
|
|
|
return "reset";
|
2014-09-22 11:45:36 +00:00
|
|
|
}
|
|
|
|
return "unk";
|
|
|
|
}
|
2014-12-01 23:36:42 +00:00
|
|
|
|
2016-06-15 23:43:41 +00:00
|
|
|
R_API const char *r_anal_op_family_to_string(int n) {
|
2014-12-01 23:36:42 +00:00
|
|
|
static char num[32];
|
|
|
|
switch (n) {
|
2015-10-03 11:52:52 +00:00
|
|
|
case R_ANAL_OP_FAMILY_UNKNOWN: return "unk";
|
2014-12-01 23:36:42 +00:00
|
|
|
case R_ANAL_OP_FAMILY_CPU: return "cpu";
|
|
|
|
case R_ANAL_OP_FAMILY_FPU: return "fpu";
|
|
|
|
case R_ANAL_OP_FAMILY_MMX: return "mmx";
|
2017-05-21 22:56:24 +00:00
|
|
|
case R_ANAL_OP_FAMILY_SSE: return "sse";
|
2014-12-01 23:36:42 +00:00
|
|
|
case R_ANAL_OP_FAMILY_PRIV: return "priv";
|
2016-06-15 23:43:41 +00:00
|
|
|
case R_ANAL_OP_FAMILY_VIRT: return "virt";
|
2014-12-01 23:36:42 +00:00
|
|
|
default:
|
2015-03-08 21:44:00 +00:00
|
|
|
snprintf (num, sizeof (num), "%d", n);
|
2014-12-01 23:36:42 +00:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
return num;
|
|
|
|
}
|
2016-06-15 23:43:41 +00:00
|
|
|
|
|
|
|
R_API int r_anal_op_family_from_string(const char *f) {
|
2016-12-12 13:47:42 +00:00
|
|
|
// TODO: use array of strings or so ..
|
2016-06-15 23:43:41 +00:00
|
|
|
if (!strcmp (f, "cpu")) return R_ANAL_OP_FAMILY_CPU;
|
|
|
|
if (!strcmp (f, "fpu")) return R_ANAL_OP_FAMILY_FPU;
|
|
|
|
if (!strcmp (f, "mmx")) return R_ANAL_OP_FAMILY_MMX;
|
2017-05-21 22:56:24 +00:00
|
|
|
if (!strcmp (f, "sse")) return R_ANAL_OP_FAMILY_SSE;
|
2016-06-15 23:43:41 +00:00
|
|
|
if (!strcmp (f, "priv")) return R_ANAL_OP_FAMILY_PRIV;
|
|
|
|
if (!strcmp (f, "virt")) return R_ANAL_OP_FAMILY_VIRT;
|
|
|
|
return R_ANAL_OP_FAMILY_UNKNOWN;
|
|
|
|
}
|
2016-12-12 13:47:42 +00:00
|
|
|
|
|
|
|
/* apply hint to op, return the number of hints applied */
|
|
|
|
R_API int r_anal_op_hint(RAnalOp *op, RAnalHint *hint) {
|
|
|
|
int changes = 0;
|
|
|
|
if (hint) {
|
|
|
|
if (hint->jump != UT64_MAX) {
|
|
|
|
changes++;
|
|
|
|
op->jump = hint->jump;
|
|
|
|
}
|
|
|
|
if (hint->fail != UT64_MAX) {
|
|
|
|
changes++;
|
|
|
|
op->fail = hint->fail;
|
|
|
|
}
|
|
|
|
if (hint->opcode) {
|
|
|
|
changes++;
|
|
|
|
/* XXX: this is not correct */
|
|
|
|
free (op->mnemonic);
|
|
|
|
op->mnemonic = strdup (hint->opcode);
|
|
|
|
}
|
|
|
|
if (hint->esil) {
|
|
|
|
changes++;
|
|
|
|
r_strbuf_set (&op->esil, hint->esil);
|
|
|
|
}
|
|
|
|
if (hint->size) {
|
|
|
|
changes++;
|
|
|
|
op->size = hint->size;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return changes;
|
|
|
|
}
|