Coverage Report

Created: 2026-03-03 06:14

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/capstonenext/Mapping.c
Line
Count
Source
1
/* Capstone Disassembly Engine */
2
/* By Nguyen Anh Quynh <aquynh@gmail.com>, 2013-2019 */
3
/*    Rot127 <unisono@quyllur.org>, 2022-2023 */
4
5
#include "Mapping.h"
6
#include "capstone/capstone.h"
7
#include "cs_priv.h"
8
#include "utils.h"
9
10
// Create a cache to map LLVM instruction IDs to capstone instruction IDs, if
11
// the architecture needs this.
12
cs_err populate_insn_map_cache(cs_struct *handle)
13
27.2k
{
14
27.2k
  unsigned int i;
15
16
  // If this architecture doesn't use instruction mapping, do nothing
17
27.2k
  if (!handle->insn_map || handle->insn_map_size <= 0)
18
26.0k
    return CS_ERR_OK;
19
20
  // Since the instruction map is assumed to be stored in ascending
21
  // order, we can get the maximum LLVM instruction id just by looking at
22
  // the last element.
23
1.20k
  unsigned int cache_elements =
24
1.20k
    handle->insn_map[handle->insn_map_size - 1].id + 1;
25
26
  // This should not be initialized yet.
27
1.20k
  CS_ASSERT(!handle->insn_cache);
28
29
1.20k
  unsigned short *cache = cs_mem_calloc(cache_elements, sizeof(*cache));
30
1.20k
  if (!cache) {
31
0
    handle->errnum = CS_ERR_MEM;
32
0
    return CS_ERR_MEM;
33
0
  }
34
1.20k
  handle->insn_cache = cache;
35
36
6.58M
  for (i = 1; i < handle->insn_map_size; ++i)
37
6.58M
    handle->insn_cache[handle->insn_map[i].id] = i;
38
39
1.20k
  return CS_ERR_OK;
40
1.20k
}
41
42
const insn_map *lookup_insn_map(cs_struct *handle, unsigned short id)
43
47.1k
{
44
  // If this is getting called, we need the cache to already be populated
45
  // (this should be done when populate_insn_map_cache() gets called).
46
47.1k
  CS_ASSERT(handle->insn_cache);
47
47.1k
  CS_ASSERT(handle->insn_map_size);
48
49
47.1k
  unsigned short highest_id =
50
47.1k
    handle->insn_map[handle->insn_map_size - 1].id;
51
47.1k
  if (id > highest_id)
52
0
    return NULL;
53
54
47.1k
  unsigned short i = handle->insn_cache[id];
55
56
47.1k
  return &handle->insn_map[i];
57
47.1k
}
58
59
// Gives the id for the given @name if it is saved in @map.
60
// Returns the id or -1 if not found.
61
int name2id(const name_map *map, int max, const char *name)
62
36.5k
{
63
36.5k
  CS_ASSERT_RET_VAL(map && name, -1);
64
36.5k
  int i;
65
66
5.19M
  for (i = 0; i < max; i++) {
67
5.19M
    if (!map[i].name) {
68
1.13k
      return -1;
69
1.13k
    }
70
5.19M
    if (!strcmp(map[i].name, name)) {
71
33.7k
      return map[i].id;
72
33.7k
    }
73
5.19M
  }
74
75
  // nothing match
76
1.59k
  return -1;
77
36.5k
}
78
79
// Gives the name for the given @id if it is saved in @map.
80
// Returns the name or NULL if not found.
81
const char *id2name(const name_map *map, int max, const unsigned int id)
82
1.25M
{
83
1.25M
  int i;
84
85
51.6M
  for (i = 0; i < max; i++) {
86
51.6M
    if (map[i].id == id) {
87
1.25M
      return map[i].name;
88
1.25M
    }
89
51.6M
  }
90
91
  // nothing match
92
5.85k
  return NULL;
93
1.25M
}
94
95
/// Adds a register to the implicit write register list.
96
/// It will not add the same register twice.
97
void map_add_implicit_write(MCInst *MI, uint32_t Reg)
98
188k
{
99
188k
  if (!MI->flat_insn->detail)
100
0
    return;
101
102
188k
  uint16_t *regs_write = MI->flat_insn->detail->regs_write;
103
189k
  for (int i = 0; i < MAX_IMPL_W_REGS; ++i) {
104
189k
    if (i == MI->flat_insn->detail->regs_write_count) {
105
181k
      regs_write[i] = Reg;
106
181k
      MI->flat_insn->detail->regs_write_count++;
107
181k
      return;
108
181k
    }
109
7.86k
    if (regs_write[i] == Reg)
110
7.08k
      return;
111
7.86k
  }
112
188k
}
113
114
/// Adds a register to the implicit read register list.
115
/// It will not add the same register twice.
116
void map_add_implicit_read(MCInst *MI, uint32_t Reg)
117
77.1k
{
118
77.1k
  if (!MI->flat_insn->detail)
119
0
    return;
120
121
77.1k
  uint16_t *regs_read = MI->flat_insn->detail->regs_read;
122
80.5k
  for (int i = 0; i < MAX_IMPL_R_REGS; ++i) {
123
80.5k
    if (i == MI->flat_insn->detail->regs_read_count) {
124
69.9k
      regs_read[i] = Reg;
125
69.9k
      MI->flat_insn->detail->regs_read_count++;
126
69.9k
      return;
127
69.9k
    }
128
10.5k
    if (regs_read[i] == Reg)
129
7.12k
      return;
130
10.5k
  }
131
77.1k
}
132
133
/// Removes a register from the implicit write register list.
134
void map_remove_implicit_write(MCInst *MI, uint32_t Reg)
135
13.5k
{
136
13.5k
  if (!MI->flat_insn->detail)
137
0
    return;
138
139
13.5k
  uint16_t *regs_write = MI->flat_insn->detail->regs_write;
140
13.5k
  bool shorten_list = false;
141
14.9k
  for (int i = 0; i < MAX_IMPL_W_REGS; ++i) {
142
14.9k
    if (shorten_list) {
143
1.40k
      regs_write[i - 1] = regs_write[i];
144
1.40k
    }
145
14.9k
    if (i >= MI->flat_insn->detail->regs_write_count)
146
13.5k
      return;
147
148
1.40k
    if (regs_write[i] == Reg) {
149
1.40k
      MI->flat_insn->detail->regs_write_count--;
150
      // The register should exist only once in the list.
151
1.40k
      CS_ASSERT_RET(!shorten_list);
152
1.40k
      shorten_list = true;
153
1.40k
    }
154
1.40k
  }
155
13.5k
}
156
157
/// Copies the implicit read registers of @imap to @MI->flat_insn.
158
/// Already present registers will be preserved.
159
void map_implicit_reads(MCInst *MI, const insn_map *imap)
160
830k
{
161
830k
#ifndef CAPSTONE_DIET
162
830k
  if (!MI->flat_insn->detail)
163
0
    return;
164
165
830k
  cs_detail *detail = MI->flat_insn->detail;
166
830k
  unsigned Opcode = MCInst_getOpcode(MI);
167
830k
  unsigned i = 0;
168
830k
  uint16_t reg = imap[Opcode].regs_use[i];
169
883k
  while (reg != 0) {
170
52.8k
    if (i >= MAX_IMPL_R_REGS ||
171
52.8k
        detail->regs_read_count >= MAX_IMPL_R_REGS) {
172
0
      printf("ERROR: Too many implicit read register defined in "
173
0
             "instruction mapping.\n");
174
0
      return;
175
0
    }
176
52.8k
    detail->regs_read[detail->regs_read_count++] = reg;
177
52.8k
    if (i + 1 < MAX_IMPL_R_REGS) {
178
      // Select next one
179
52.8k
      reg = imap[Opcode].regs_use[++i];
180
52.8k
    }
181
52.8k
  }
182
830k
#endif // CAPSTONE_DIET
183
830k
}
184
185
/// Copies the implicit write registers of @imap to @MI->flat_insn.
186
/// Already present registers will be preserved.
187
void map_implicit_writes(MCInst *MI, const insn_map *imap)
188
830k
{
189
830k
#ifndef CAPSTONE_DIET
190
830k
  if (!MI->flat_insn->detail)
191
0
    return;
192
193
830k
  cs_detail *detail = MI->flat_insn->detail;
194
830k
  unsigned Opcode = MCInst_getOpcode(MI);
195
830k
  unsigned i = 0;
196
830k
  uint16_t reg = imap[Opcode].regs_mod[i];
197
958k
  while (reg != 0) {
198
128k
    if (i >= MAX_IMPL_W_REGS ||
199
128k
        detail->regs_write_count >= MAX_IMPL_W_REGS) {
200
0
      printf("ERROR: Too many implicit write register defined in "
201
0
             "instruction mapping.\n");
202
0
      return;
203
0
    }
204
128k
    detail->regs_write[detail->regs_write_count++] = reg;
205
128k
    if (i + 1 < MAX_IMPL_W_REGS) {
206
      // Select next one
207
128k
      reg = imap[Opcode].regs_mod[++i];
208
128k
    }
209
128k
  }
210
830k
#endif // CAPSTONE_DIET
211
830k
}
212
213
/// Adds a given group to @MI->flat_insn.
214
/// A group is never added twice.
215
void add_group(MCInst *MI, unsigned /* arch_group */ group)
216
59.6k
{
217
59.6k
#ifndef CAPSTONE_DIET
218
59.6k
  if (!MI->flat_insn->detail)
219
0
    return;
220
221
59.6k
  cs_detail *detail = MI->flat_insn->detail;
222
59.6k
  if (detail->groups_count >= MAX_NUM_GROUPS) {
223
0
    printf("ERROR: Too many groups defined.\n");
224
0
    return;
225
0
  }
226
121k
  for (int i = 0; i < detail->groups_count; ++i) {
227
62.2k
    if (detail->groups[i] == group) {
228
388
      return;
229
388
    }
230
62.2k
  }
231
59.2k
  detail->groups[detail->groups_count++] = group;
232
59.2k
#endif // CAPSTONE_DIET
233
59.2k
}
234
235
/// Copies the groups from @imap to @MI->flat_insn.
236
/// Already present groups will be preserved.
237
void map_groups(MCInst *MI, const insn_map *imap)
238
830k
{
239
830k
#ifndef CAPSTONE_DIET
240
830k
  if (!MI->flat_insn->detail)
241
0
    return;
242
243
830k
  cs_detail *detail = MI->flat_insn->detail;
244
830k
  unsigned Opcode = MCInst_getOpcode(MI);
245
830k
  unsigned i = 0;
246
830k
  uint16_t group = imap[Opcode].groups[i];
247
1.77M
  while (group != 0) {
248
945k
    if (detail->groups_count >= MAX_NUM_GROUPS) {
249
0
      printf("ERROR: Too many groups defined in instruction mapping.\n");
250
0
      return;
251
0
    }
252
945k
    detail->groups[detail->groups_count++] = group;
253
945k
    group = imap[Opcode].groups[++i];
254
945k
  }
255
830k
#endif // CAPSTONE_DIET
256
830k
}
257
258
/// Returns the pointer to the supllementary information in
259
/// the instruction mapping table @imap or NULL in case of failure.
260
const void *map_get_suppl_info(MCInst *MI, const insn_map *imap)
261
618k
{
262
618k
#ifndef CAPSTONE_DIET
263
618k
  if (!MI->flat_insn->detail)
264
0
    return NULL;
265
266
618k
  unsigned Opcode = MCInst_getOpcode(MI);
267
618k
  return &imap[Opcode].suppl_info;
268
#else
269
  return NULL;
270
#endif // CAPSTONE_DIET
271
618k
}
272
273
// Search for the CS instruction id for the given @MC_Opcode in @imap.
274
// return -1 if none is found.
275
unsigned int find_cs_id(unsigned MC_Opcode, const insn_map *imap,
276
      unsigned imap_size)
277
830k
{
278
  // binary searching since the IDs are sorted in order
279
830k
  unsigned int left, right, m;
280
830k
  unsigned int max = imap_size;
281
282
830k
  right = max - 1;
283
284
830k
  if (MC_Opcode < imap[0].id || MC_Opcode > imap[right].id)
285
    // not found
286
0
    return -1;
287
288
830k
  left = 0;
289
290
9.38M
  while (left <= right) {
291
9.38M
    m = (left + right) / 2;
292
9.38M
    if (MC_Opcode == imap[m].id) {
293
830k
      return m;
294
830k
    }
295
296
8.55M
    if (MC_Opcode < imap[m].id)
297
3.10M
      right = m - 1;
298
5.45M
    else
299
5.45M
      left = m + 1;
300
8.55M
  }
301
302
0
  return -1;
303
830k
}
304
305
/// Sets the Capstone instruction id which maps to the @MI opcode.
306
/// If no mapping is found the function returns and prints an error.
307
void map_cs_id(MCInst *MI, const insn_map *imap, unsigned int imap_size)
308
830k
{
309
830k
  unsigned int i = find_cs_id(MCInst_getOpcode(MI), imap, imap_size);
310
830k
  if (i != -1) {
311
830k
    MI->flat_insn->id = imap[i].mapid;
312
830k
    return;
313
830k
  }
314
0
  printf("ERROR: Could not find CS id for MCInst opcode: %d\n",
315
0
         MCInst_getOpcode(MI));
316
0
  return;
317
830k
}
318
319
/// Returns the operand type information from the
320
/// mapping table for instruction operands.
321
/// Only usable by `auto-sync` archs!
322
const cs_op_type mapping_get_op_type(MCInst *MI, unsigned OpNum,
323
             const map_insn_ops *insn_ops_map,
324
             size_t map_size)
325
6.70M
{
326
6.70M
  assert(MI);
327
6.70M
  assert(MI->Opcode < map_size);
328
6.70M
  assert(OpNum < sizeof(insn_ops_map[MI->Opcode].ops) /
329
6.70M
             sizeof(insn_ops_map[MI->Opcode].ops[0]));
330
331
6.70M
  return insn_ops_map[MI->Opcode].ops[OpNum].type;
332
6.70M
}
333
334
/// Returns the operand access flags from the
335
/// mapping table for instruction operands.
336
/// Only usable by `auto-sync` archs!
337
const cs_ac_type mapping_get_op_access(MCInst *MI, unsigned OpNum,
338
               const map_insn_ops *insn_ops_map,
339
               size_t map_size)
340
2.47M
{
341
2.47M
  assert(MI);
342
2.47M
  assert(MI->Opcode < map_size);
343
2.47M
  assert(OpNum < sizeof(insn_ops_map[MI->Opcode].ops) /
344
2.47M
             sizeof(insn_ops_map[MI->Opcode].ops[0]));
345
346
2.47M
  cs_ac_type access = insn_ops_map[MI->Opcode].ops[OpNum].access;
347
2.47M
  if (MCInst_opIsTied(MI, OpNum) || MCInst_opIsTying(MI, OpNum))
348
202k
    access |= (access == CS_AC_READ) ? CS_AC_WRITE : CS_AC_READ;
349
2.47M
  return access;
350
2.47M
}
351
352
/// Returns the operand at detail->arch.operands[op_count + offset]
353
/// Or NULL if detail is not set or the offset would be out of bounds.
354
#define DEFINE_get_detail_op(arch, ARCH, ARCH_UPPER) \
355
  cs_##arch##_op *ARCH##_get_detail_op(MCInst *MI, int offset) \
356
9.79M
  { \
357
9.79M
    if (!MI->flat_insn->detail) \
358
9.79M
      return NULL; \
359
9.79M
    int OpIdx = MI->flat_insn->detail->arch.op_count + offset; \
360
9.79M
    if (OpIdx < 0 || OpIdx >= NUM_##ARCH_UPPER##_OPS) { \
361
3.71k
      return NULL; \
362
3.71k
    } \
363
9.79M
    return &MI->flat_insn->detail->arch.operands[OpIdx]; \
364
9.79M
  }
365
366
5.41M
DEFINE_get_detail_op(arm, ARM, ARM);
367
171k
DEFINE_get_detail_op(ppc, PPC, PPC);
368
0
DEFINE_get_detail_op(tricore, TriCore, TRICORE);
369
2.91M
DEFINE_get_detail_op(aarch64, AArch64, AARCH64);
370
0
DEFINE_get_detail_op(alpha, Alpha, ALPHA);
371
0
DEFINE_get_detail_op(hppa, HPPA, HPPA);
372
0
DEFINE_get_detail_op(loongarch, LoongArch, LOONGARCH);
373
533k
DEFINE_get_detail_op(mips, Mips, MIPS);
374
0
DEFINE_get_detail_op(riscv, RISCV, RISCV);
375
528k
DEFINE_get_detail_op(systemz, SystemZ, SYSTEMZ);
376
73.7k
DEFINE_get_detail_op(xtensa, Xtensa, XTENSA);
377
0
DEFINE_get_detail_op(bpf, BPF, BPF);
378
0
DEFINE_get_detail_op(arc, ARC, ARC);
379
159k
DEFINE_get_detail_op(sparc, Sparc, SPARC);
380
381
/// Returns the operand at detail->arch.operands[index]
382
/// Or NULL if detail is not set or the index would be out of bounds.
383
#define DEFINE_get_detail_op_at(arch, ARCH, ARCH_UPPER) \
384
  cs_##arch##_op *ARCH##_get_detail_op_at(MCInst *MI, int index) \
385
38.9k
  { \
386
38.9k
    if (!MI->flat_insn->detail) \
387
38.9k
      return NULL; \
388
38.9k
    if (index < 0 || index >= NUM_##ARCH_UPPER##_OPS) { \
389
0
      return NULL; \
390
0
    } \
391
38.9k
    return &MI->flat_insn->detail->arch.operands[index]; \
392
38.9k
  }
393
394
0
DEFINE_get_detail_op_at(arm, ARM, ARM);
395
0
DEFINE_get_detail_op_at(ppc, PPC, PPC);
396
0
DEFINE_get_detail_op_at(tricore, TriCore, TRICORE);
397
0
DEFINE_get_detail_op_at(aarch64, AArch64, AARCH64);
398
0
DEFINE_get_detail_op_at(alpha, Alpha, ALPHA);
399
0
DEFINE_get_detail_op_at(hppa, HPPA, HPPA);
400
0
DEFINE_get_detail_op_at(loongarch, LoongArch, LOONGARCH);
401
0
DEFINE_get_detail_op_at(mips, Mips, MIPS);
402
38.9k
DEFINE_get_detail_op_at(riscv, RISCV, RISCV);
403
0
DEFINE_get_detail_op_at(systemz, SystemZ, SYSTEMZ);
404
0
DEFINE_get_detail_op_at(xtensa, Xtensa, XTENSA);
405
0
DEFINE_get_detail_op_at(bpf, BPF, BPF);
406
0
DEFINE_get_detail_op_at(arc, ARC, ARC);
407
0
DEFINE_get_detail_op_at(sparc, Sparc, SPARC);
408
409
/// Returns true if for this architecture the
410
/// alias operands should be filled.
411
/// TODO: Replace this with a proper option.
412
///       So it can be toggled between disas() calls.
413
bool map_use_alias_details(const MCInst *MI)
414
1.43M
{
415
1.43M
  assert(MI);
416
1.43M
  return (MI->csh->detail_opt & CS_OPT_ON) &&
417
1.43M
         !(MI->csh->detail_opt & CS_OPT_DETAIL_REAL);
418
1.43M
}
419
420
/// Sets the setDetailOps flag to @p Val.
421
/// If detail == NULLit refuses to set the flag to true.
422
void map_set_fill_detail_ops(MCInst *MI, bool Val)
423
1.39M
{
424
1.39M
  CS_ASSERT_RET(MI);
425
1.39M
  if (!detail_is_set(MI)) {
426
0
    MI->fillDetailOps = false;
427
0
    return;
428
0
  }
429
430
1.39M
  MI->fillDetailOps = Val;
431
1.39M
}
432
433
/// Sets the instruction alias flags and the given alias id.
434
void map_set_is_alias_insn(MCInst *MI, bool Val, uint64_t Alias)
435
0
{
436
0
  CS_ASSERT_RET(MI);
437
0
  MI->isAliasInstr = Val;
438
0
  MI->flat_insn->is_alias = Val;
439
0
  MI->flat_insn->alias_id = Alias;
440
0
}
441
442
static inline bool char_ends_mnem(const char c, cs_arch arch)
443
173k
{
444
173k
  switch (arch) {
445
145k
  default:
446
145k
    return (!c || c == ' ' || c == '\t' || c == '.');
447
15.1k
  case CS_ARCH_PPC:
448
15.1k
    return (!c || c == ' ' || c == '\t');
449
12.2k
  case CS_ARCH_SPARC:
450
12.2k
    return (!c || c == ' ' || c == '\t' || c == ',');
451
173k
  }
452
173k
}
453
454
/// Sets an alternative id for some instruction.
455
/// Or -1 if it fails.
456
/// You must add (<ARCH>_INS_ALIAS_BEGIN + 1) to the id to get the real id.
457
void map_set_alias_id(MCInst *MI, const SStream *O,
458
          const name_map *alias_mnem_id_map, int map_size)
459
794k
{
460
794k
  if (!MCInst_isAlias(MI))
461
758k
    return;
462
463
36.5k
  char alias_mnem[16] = { 0 };
464
36.5k
  int i = 0, j = 0;
465
36.5k
  const char *asm_str_buf = O->buffer;
466
  // Skip spaces and tabs
467
59.4k
  while (is_blank_char(asm_str_buf[i])) {
468
22.9k
    if (!asm_str_buf[i]) {
469
0
      MI->flat_insn->alias_id = -1;
470
0
      return;
471
0
    }
472
22.9k
    ++i;
473
22.9k
  }
474
173k
  for (; j < sizeof(alias_mnem) - 1; ++j, ++i) {
475
173k
    if (char_ends_mnem(asm_str_buf[i], MI->csh->arch))
476
36.5k
      break;
477
136k
    alias_mnem[j] = asm_str_buf[i];
478
136k
  }
479
480
36.5k
  MI->flat_insn->alias_id =
481
36.5k
    name2id(alias_mnem_id_map, map_size, alias_mnem);
482
36.5k
}
483
484
/// Does a binary search over the given map and searches for @id.
485
/// If @id exists in @map, it sets @found to true and returns
486
/// the value for the @id.
487
/// Otherwise, @found is set to false and it returns UINT64_MAX.
488
///
489
/// Of course it assumes the map is sorted.
490
uint64_t enum_map_bin_search(const cs_enum_id_map *map, size_t map_len,
491
           const char *id, bool *found)
492
0
{
493
0
  size_t l = 0;
494
0
  size_t r = map_len;
495
0
  size_t id_len = strlen(id);
496
497
0
  while (l <= r) {
498
0
    size_t m = (l + r) / 2;
499
0
    size_t j = 0;
500
0
    size_t i = 0;
501
0
    size_t entry_len = strlen(map[m].str);
502
503
0
    while (j < entry_len && i < id_len && id[i] == map[m].str[j]) {
504
0
      ++j, ++i;
505
0
    }
506
0
    if (i == id_len && j == entry_len) {
507
0
      *found = true;
508
0
      return map[m].val;
509
0
    }
510
511
0
    if (id[i] < map[m].str[j]) {
512
0
      r = m - 1;
513
0
    } else if (id[i] > map[m].str[j]) {
514
0
      l = m + 1;
515
0
    }
516
0
    if ((m == 0 && id[i] < map[m].str[j]) ||
517
0
        (l + r) / 2 >= map_len) {
518
      // Break before we go out of bounds.
519
0
      break;
520
0
    }
521
0
  }
522
0
  *found = false;
523
  return UINT64_MAX;
524
0
}