Coverage Report

Created: 2026-03-03 06:14

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/capstonenext/arch/WASM/WASMDisassembler.c
Line
Count
Source
1
/* Capstone Disassembly Engine */
2
/* By Spike, xwings 2019 */
3
4
#include <string.h>
5
#include <stddef.h>
6
7
#include "WASMDisassembler.h"
8
#include "WASMMapping.h"
9
#include "../../cs_priv.h"
10
11
static const short opcodes[256] = {
12
  WASM_INS_UNREACHABLE,
13
  WASM_INS_NOP,
14
  WASM_INS_BLOCK,
15
  WASM_INS_LOOP,
16
  WASM_INS_IF,
17
  WASM_INS_ELSE,
18
  -1,
19
  -1,
20
  -1,
21
  -1,
22
  -1,
23
  WASM_INS_END,
24
  WASM_INS_BR,
25
  WASM_INS_BR_IF,
26
  WASM_INS_BR_TABLE,
27
  WASM_INS_RETURN,
28
  WASM_INS_CALL,
29
  WASM_INS_CALL_INDIRECT,
30
  -1,
31
  -1,
32
  -1,
33
  -1,
34
  -1,
35
  -1,
36
  -1,
37
  -1,
38
  WASM_INS_DROP,
39
  WASM_INS_SELECT,
40
  -1,
41
  -1,
42
  -1,
43
  -1,
44
  WASM_INS_GET_LOCAL,
45
  WASM_INS_SET_LOCAL,
46
  WASM_INS_TEE_LOCAL,
47
  WASM_INS_GET_GLOBAL,
48
  WASM_INS_SET_GLOBAL,
49
  -1,
50
  -1,
51
  -1,
52
  WASM_INS_I32_LOAD,
53
  WASM_INS_I64_LOAD,
54
  WASM_INS_F32_LOAD,
55
  WASM_INS_F64_LOAD,
56
  WASM_INS_I32_LOAD8_S,
57
  WASM_INS_I32_LOAD8_U,
58
  WASM_INS_I32_LOAD16_S,
59
  WASM_INS_I32_LOAD16_U,
60
  WASM_INS_I64_LOAD8_S,
61
  WASM_INS_I64_LOAD8_U,
62
  WASM_INS_I64_LOAD16_S,
63
  WASM_INS_I64_LOAD16_U,
64
  WASM_INS_I64_LOAD32_S,
65
  WASM_INS_I64_LOAD32_U,
66
  WASM_INS_I32_STORE,
67
  WASM_INS_I64_STORE,
68
  WASM_INS_F32_STORE,
69
  WASM_INS_F64_STORE,
70
  WASM_INS_I32_STORE8,
71
  WASM_INS_I32_STORE16,
72
  WASM_INS_I64_STORE8,
73
  WASM_INS_I64_STORE16,
74
  WASM_INS_I64_STORE32,
75
  WASM_INS_CURRENT_MEMORY,
76
  WASM_INS_GROW_MEMORY,
77
  WASM_INS_I32_CONST,
78
  WASM_INS_I64_CONST,
79
  WASM_INS_F32_CONST,
80
  WASM_INS_F64_CONST,
81
  WASM_INS_I32_EQZ,
82
  WASM_INS_I32_EQ,
83
  WASM_INS_I32_NE,
84
  WASM_INS_I32_LT_S,
85
  WASM_INS_I32_LT_U,
86
  WASM_INS_I32_GT_S,
87
  WASM_INS_I32_GT_U,
88
  WASM_INS_I32_LE_S,
89
  WASM_INS_I32_LE_U,
90
  WASM_INS_I32_GE_S,
91
  WASM_INS_I32_GE_U,
92
  WASM_INS_I64_EQZ,
93
  WASM_INS_I64_EQ,
94
  WASM_INS_I64_NE,
95
  WASM_INS_I64_LT_S,
96
  WASM_INS_I64_LT_U,
97
  WASN_INS_I64_GT_S,
98
  WASM_INS_I64_GT_U,
99
  WASM_INS_I64_LE_S,
100
  WASM_INS_I64_LE_U,
101
  WASM_INS_I64_GE_S,
102
  WASM_INS_I64_GE_U,
103
  WASM_INS_F32_EQ,
104
  WASM_INS_F32_NE,
105
  WASM_INS_F32_LT,
106
  WASM_INS_F32_GT,
107
  WASM_INS_F32_LE,
108
  WASM_INS_F32_GE,
109
  WASM_INS_F64_EQ,
110
  WASM_INS_F64_NE,
111
  WASM_INS_F64_LT,
112
  WASM_INS_F64_GT,
113
  WASM_INS_F64_LE,
114
  WASM_INS_F64_GE,
115
  WASM_INS_I32_CLZ,
116
  WASM_INS_I32_CTZ,
117
  WASM_INS_I32_POPCNT,
118
  WASM_INS_I32_ADD,
119
  WASM_INS_I32_SUB,
120
  WASM_INS_I32_MUL,
121
  WASM_INS_I32_DIV_S,
122
  WASM_INS_I32_DIV_U,
123
  WASM_INS_I32_REM_S,
124
  WASM_INS_I32_REM_U,
125
  WASM_INS_I32_AND,
126
  WASM_INS_I32_OR,
127
  WASM_INS_I32_XOR,
128
  WASM_INS_I32_SHL,
129
  WASM_INS_I32_SHR_S,
130
  WASM_INS_I32_SHR_U,
131
  WASM_INS_I32_ROTL,
132
  WASM_INS_I32_ROTR,
133
  WASM_INS_I64_CLZ,
134
  WASM_INS_I64_CTZ,
135
  WASM_INS_I64_POPCNT,
136
  WASM_INS_I64_ADD,
137
  WASM_INS_I64_SUB,
138
  WASM_INS_I64_MUL,
139
  WASM_INS_I64_DIV_S,
140
  WASM_INS_I64_DIV_U,
141
  WASM_INS_I64_REM_S,
142
  WASM_INS_I64_REM_U,
143
  WASM_INS_I64_AND,
144
  WASM_INS_I64_OR,
145
  WASM_INS_I64_XOR,
146
  WASM_INS_I64_SHL,
147
  WASM_INS_I64_SHR_S,
148
  WASM_INS_I64_SHR_U,
149
  WASM_INS_I64_ROTL,
150
  WASM_INS_I64_ROTR,
151
  WASM_INS_F32_ABS,
152
  WASM_INS_F32_NEG,
153
  WASM_INS_F32_CEIL,
154
  WASM_INS_F32_FLOOR,
155
  WASM_INS_F32_TRUNC,
156
  WASM_INS_F32_NEAREST,
157
  WASM_INS_F32_SQRT,
158
  WASM_INS_F32_ADD,
159
  WASM_INS_F32_SUB,
160
  WASM_INS_F32_MUL,
161
  WASM_INS_F32_DIV,
162
  WASM_INS_F32_MIN,
163
  WASM_INS_F32_MAX,
164
  WASM_INS_F32_COPYSIGN,
165
  WASM_INS_F64_ABS,
166
  WASM_INS_F64_NEG,
167
  WASM_INS_F64_CEIL,
168
  WASM_INS_F64_FLOOR,
169
  WASM_INS_F64_TRUNC,
170
  WASM_INS_F64_NEAREST,
171
  WASM_INS_F64_SQRT,
172
  WASM_INS_F64_ADD,
173
  WASM_INS_F64_SUB,
174
  WASM_INS_F64_MUL,
175
  WASM_INS_F64_DIV,
176
  WASM_INS_F64_MIN,
177
  WASM_INS_F64_MAX,
178
  WASM_INS_F64_COPYSIGN,
179
  WASM_INS_I32_WARP_I64,
180
  WASP_INS_I32_TRUNC_S_F32,
181
  WASM_INS_I32_TRUNC_U_F32,
182
  WASM_INS_I32_TRUNC_S_F64,
183
  WASM_INS_I32_TRUNC_U_F64,
184
  WASM_INS_I64_EXTEND_S_I32,
185
  WASM_INS_I64_EXTEND_U_I32,
186
  WASM_INS_I64_TRUNC_S_F32,
187
  WASM_INS_I64_TRUNC_U_F32,
188
  WASM_INS_I64_TRUNC_S_F64,
189
  WASM_INS_I64_TRUNC_U_F64,
190
  WASM_INS_F32_CONVERT_S_I32,
191
  WASM_INS_F32_CONVERT_U_I32,
192
  WASM_INS_F32_CONVERT_S_I64,
193
  WASM_INS_F32_CONVERT_U_I64,
194
  WASM_INS_F32_DEMOTE_F64,
195
  WASM_INS_F64_CONVERT_S_I32,
196
  WASM_INS_F64_CONVERT_U_I32,
197
  WASM_INS_F64_CONVERT_S_I64,
198
  WASM_INS_F64_CONVERT_U_I64,
199
  WASM_INS_F64_PROMOTE_F32,
200
  WASM_INS_I32_REINTERPRET_F32,
201
  WASM_INS_I64_REINTERPRET_F64,
202
  WASM_INS_F32_REINTERPRET_I32,
203
  WASM_INS_F64_REINTERPRET_I64,
204
  -1,
205
  -1,
206
  -1,
207
  -1,
208
  -1,
209
  -1,
210
  -1,
211
  -1,
212
  -1,
213
  -1,
214
  -1,
215
  -1,
216
  -1,
217
  -1,
218
  -1,
219
  -1,
220
  -1,
221
  -1,
222
  -1,
223
  -1,
224
  -1,
225
  -1,
226
  -1,
227
  -1,
228
  -1,
229
  -1,
230
  -1,
231
  -1,
232
  -1,
233
  -1,
234
  -1,
235
  -1,
236
  -1,
237
  -1,
238
  -1,
239
  -1,
240
  -1,
241
  -1,
242
  -1,
243
  -1,
244
  -1,
245
  -1,
246
  -1,
247
  -1,
248
  -1,
249
  -1,
250
  -1,
251
  -1,
252
  -1,
253
  -1,
254
  -1,
255
  -1,
256
  -1,
257
  -1,
258
  -1,
259
  -1,
260
  -1,
261
  -1,
262
  -1,
263
  -1,
264
  -1,
265
  -1,
266
  -1,
267
  -1,
268
};
269
270
// input  | code: code pointer start from varuint32
271
//        | code_len: real code len count from varint
272
//        | leng: return value, means length of varint. -1 means error
273
// return | varint
274
static uint32_t get_varuint32(const uint8_t *code, size_t code_len,
275
            size_t *leng)
276
10.1k
{
277
10.1k
  uint32_t data = 0;
278
10.1k
  int i;
279
280
11.6k
  for (i = 0;; i++) {
281
11.6k
    if (code_len < i + 1) {
282
41
      *leng = -1;
283
41
      return 0;
284
41
    }
285
286
11.6k
    if (i > 4 || (i == 4 && (code[i] & 0x7f) > 0x0f)) {
287
18
      *leng = -1;
288
18
      return 0;
289
18
    }
290
291
11.6k
    data = data + (((uint32_t)code[i] & 0x7f) << (i * 7));
292
11.6k
    if (code[i] >> 7 == 0) {
293
10.0k
      break;
294
10.0k
    }
295
11.6k
  }
296
297
10.0k
  *leng = i + 1;
298
299
10.0k
  return data;
300
10.1k
}
301
302
// input  | code : code pointer start from varuint64
303
//        | code_len : real code len count from varint
304
//        | leng: return value, means length of varint. -1 means error
305
// return   | varint
306
static uint64_t get_varuint64(const uint8_t *code, size_t code_len,
307
            size_t *leng)
308
137
{
309
137
  uint64_t data;
310
137
  int i;
311
312
137
  data = 0;
313
146
  for (i = 0;; i++) {
314
146
    if (code_len < i + 1) {
315
0
      *leng = -1;
316
0
      return 0;
317
0
    }
318
319
146
    if (i > 9 || (i == 9 && (code[i] & 0x7f) > 0x01)) {
320
0
      *leng = -1;
321
0
      return 0;
322
0
    }
323
324
146
    data = data + (((uint64_t)code[i] & 0x7f) << (i * 7));
325
146
    if (code[i] >> 7 == 0) {
326
137
      break;
327
137
    }
328
146
  }
329
330
137
  *leng = i + 1;
331
332
137
  return data;
333
137
}
334
335
// input  | code : code pointer start from uint32
336
//      | dest : the pointer where we store the uint32
337
// return | None
338
static void get_uint32(const uint8_t *code, uint32_t *dest)
339
18
{
340
18
  memcpy(dest, code, 4);
341
18
}
342
343
// input  | code : code pointer start from uint32
344
//      | dest : the pointer where we store the uint64
345
// return   | None
346
static void get_uint64(const uint8_t *code, uint64_t *dest)
347
110
{
348
110
  memcpy(dest, code, 8);
349
110
}
350
351
// input  | code : code pointer start from varint7
352
//      | code_len : start from the code pointer to the end, how long is it
353
//      | leng : length of the param , -1 means error
354
// return   | data of varint7
355
static int8_t get_varint7(const uint8_t *code, size_t code_len, size_t *leng)
356
455
{
357
455
  int8_t data;
358
359
455
  if (code_len < 1) {
360
0
    *leng = -1;
361
0
    return -1;
362
0
  }
363
364
455
  *leng = 1;
365
366
455
  if (code[0] == 0x40) {
367
24
    return -1;
368
24
  }
369
370
431
  data = code[0] & 0x7f;
371
372
431
  return data;
373
455
}
374
375
// input  | code : code pointer start from varuint32
376
//      | code_len : start from the code pointer to the end, how long is it
377
//      | param_size : pointer of the param size
378
//      | MI : Mcinst handler in this round of disasm
379
// return   | true/false if the function successfully finished
380
static bool read_varuint32(const uint8_t *code, size_t code_len,
381
         uint16_t *param_size, MCInst *MI)
382
1.20k
{
383
1.20k
  size_t len = 0;
384
1.20k
  uint32_t data;
385
386
1.20k
  data = get_varuint32(code, code_len, &len);
387
1.20k
  if (len == -1) {
388
7
    return false;
389
7
  }
390
391
1.20k
  if (MI->flat_insn->detail) {
392
1.20k
    MI->flat_insn->detail->wasm.op_count = 1;
393
1.20k
    MI->flat_insn->detail->wasm.operands[0].type =
394
1.20k
      WASM_OP_VARUINT32;
395
1.20k
    MI->flat_insn->detail->wasm.operands[0].size = len;
396
1.20k
    MI->flat_insn->detail->wasm.operands[0].varuint32 = data;
397
1.20k
  }
398
399
1.20k
  MI->wasm_data.size = len;
400
1.20k
  MI->wasm_data.type = WASM_OP_VARUINT32;
401
1.20k
  MI->wasm_data.uint32 = data;
402
1.20k
  *param_size = len;
403
404
1.20k
  return true;
405
1.20k
}
406
407
// input  | code : code pointer start from varuint64
408
//      | code_len : start from the code pointer to the end, how long is it
409
//      | param_size : pointer of the param size
410
//      | MI : Mcinst handler in this round of disasm
411
// return   | true/false if the function successfully finished
412
static bool read_varuint64(const uint8_t *code, size_t code_len,
413
         uint16_t *param_size, MCInst *MI)
414
137
{
415
137
  size_t len = 0;
416
137
  uint64_t data;
417
418
137
  data = get_varuint64(code, code_len, &len);
419
137
  if (len == -1) {
420
0
    return false;
421
0
  }
422
423
137
  if (MI->flat_insn->detail) {
424
137
    MI->flat_insn->detail->wasm.op_count = 1;
425
137
    MI->flat_insn->detail->wasm.operands[0].type =
426
137
      WASM_OP_VARUINT64;
427
137
    MI->flat_insn->detail->wasm.operands[0].size = len;
428
137
    MI->flat_insn->detail->wasm.operands[0].varuint64 = data;
429
137
  }
430
431
137
  MI->wasm_data.size = len;
432
137
  MI->wasm_data.type = WASM_OP_VARUINT64;
433
137
  MI->wasm_data.uint64 = data;
434
137
  *param_size = len;
435
436
137
  return true;
437
137
}
438
439
// input  | code : code pointer start from memoryimmediate
440
//      | code_len : start from the code pointer to the end, how long is it
441
//      | param_size : pointer of the param size (sum of two params)
442
//      | MI : Mcinst handler in this round of disasm
443
// return   | true/false if the function successfully finished
444
static bool read_memoryimmediate(const uint8_t *code, size_t code_len,
445
         uint16_t *param_size, MCInst *MI)
446
3.91k
{
447
3.91k
  size_t tmp, len = 0;
448
3.91k
  uint32_t data[2];
449
450
3.91k
  if (MI->flat_insn->detail) {
451
3.91k
    MI->flat_insn->detail->wasm.op_count = 2;
452
3.91k
  }
453
454
3.91k
  data[0] = get_varuint32(code, code_len, &tmp);
455
3.91k
  if (tmp == -1) {
456
10
    return false;
457
10
  }
458
459
3.90k
  if (MI->flat_insn->detail) {
460
3.90k
    MI->flat_insn->detail->wasm.operands[0].type =
461
3.90k
      WASM_OP_VARUINT32;
462
3.90k
    MI->flat_insn->detail->wasm.operands[0].size = tmp;
463
3.90k
    MI->flat_insn->detail->wasm.operands[0].varuint32 = data[0];
464
3.90k
  }
465
466
3.90k
  len = tmp;
467
3.90k
  data[1] = get_varuint32(&code[len], code_len - len, &tmp);
468
3.90k
  if (tmp == -1) {
469
34
    return false;
470
34
  }
471
472
3.87k
  if (MI->flat_insn->detail) {
473
3.87k
    MI->flat_insn->detail->wasm.operands[1].type =
474
3.87k
      WASM_OP_VARUINT32;
475
3.87k
    MI->flat_insn->detail->wasm.operands[1].size = tmp;
476
3.87k
    MI->flat_insn->detail->wasm.operands[1].varuint32 = data[1];
477
3.87k
  }
478
479
3.87k
  len += tmp;
480
3.87k
  MI->wasm_data.size = len;
481
3.87k
  MI->wasm_data.type = WASM_OP_IMM;
482
3.87k
  MI->wasm_data.immediate[0] = data[0];
483
3.87k
  MI->wasm_data.immediate[1] = data[1];
484
3.87k
  *param_size = len;
485
486
3.87k
  return true;
487
3.90k
}
488
489
// input  | code : code pointer start from uint32
490
//      | code_len : start from the code pointer to the end, how long is it
491
//      | param_size : pointer of the param size
492
//      | MI : Mcinst handler in this round of disasm
493
// return   | true/false if the function successfully finished
494
static bool read_uint32(const uint8_t *code, size_t code_len,
495
      uint16_t *param_size, MCInst *MI)
496
9
{
497
9
  if (code_len < 4) {
498
0
    return false;
499
0
  }
500
501
9
  get_uint32(code, &(MI->wasm_data.uint32));
502
503
9
  if (MI->flat_insn->detail) {
504
9
    MI->flat_insn->detail->wasm.op_count = 1;
505
9
    MI->flat_insn->detail->wasm.operands[0].type = WASM_OP_UINT32;
506
9
    MI->flat_insn->detail->wasm.operands[0].size = 4;
507
9
    get_uint32(code,
508
9
         &(MI->flat_insn->detail->wasm.operands[0].uint32));
509
9
  }
510
511
9
  MI->wasm_data.size = 4;
512
9
  MI->wasm_data.type = WASM_OP_UINT32;
513
9
  *param_size = 4;
514
515
9
  return true;
516
9
}
517
518
// input  | code : code pointer start from uint64
519
//      | code_len : start from the code pointer to the end, how long is it
520
//      | param_size : pointer of the param size
521
//      | MI : Mcinst handler in this round of disasm
522
// return   | true/false if the function successfully finished
523
static bool read_uint64(const uint8_t *code, size_t code_len,
524
      uint16_t *param_size, MCInst *MI)
525
56
{
526
56
  if (code_len < 8) {
527
1
    return false;
528
1
  }
529
530
55
  get_uint64(code, &(MI->wasm_data.uint64));
531
532
55
  if (MI->flat_insn->detail) {
533
55
    MI->flat_insn->detail->wasm.op_count = 1;
534
55
    MI->flat_insn->detail->wasm.operands[0].type = WASM_OP_UINT64;
535
55
    MI->flat_insn->detail->wasm.operands[0].size = 8;
536
55
    get_uint64(code,
537
55
         &(MI->flat_insn->detail->wasm.operands[0].uint64));
538
55
  }
539
540
55
  MI->wasm_data.size = 8;
541
55
  MI->wasm_data.type = WASM_OP_UINT64;
542
55
  *param_size = 8;
543
544
55
  return true;
545
56
}
546
547
// input  | code : code pointer start from brtable
548
//      | code_len : start from the code pointer to the end, how long is it
549
//      | param_size : pointer of the param size (sum of all param)
550
//      | MI : Mcinst handler in this round of disasm
551
// return   | true/false if the function successfully finished
552
static bool read_brtable(const uint8_t *code, size_t code_len,
553
       uint16_t *param_size, MCInst *MI)
554
336
{
555
336
  uint32_t length, default_target;
556
336
  int tmp_len = 0, i;
557
336
  size_t var_len;
558
559
  // read length
560
336
  length = get_varuint32(code, code_len, &var_len);
561
336
  if (var_len == -1) {
562
1
    return false;
563
1
  }
564
565
335
  tmp_len += var_len;
566
335
  MI->wasm_data.brtable.length = length;
567
335
  if (length >= UINT32_MAX - tmp_len) {
568
    // integer overflow check
569
1
    return false;
570
1
  }
571
334
  if (code_len < tmp_len + length) {
572
    // safety check that we have minimum enough data to read
573
11
    return false;
574
11
  }
575
  // base address + 1 byte opcode + tmp_len for number of cases = start of targets
576
323
  MI->wasm_data.brtable.address = MI->address + 1 + tmp_len;
577
578
323
  if (MI->flat_insn->detail) {
579
323
    MI->flat_insn->detail->wasm.op_count = 1;
580
323
    MI->flat_insn->detail->wasm.operands[0].type = WASM_OP_BRTABLE;
581
323
    MI->flat_insn->detail->wasm.operands[0].brtable.length =
582
323
      MI->wasm_data.brtable.length;
583
323
    MI->flat_insn->detail->wasm.operands[0].brtable.address =
584
323
      MI->wasm_data.brtable.address;
585
323
  }
586
587
  // read data
588
778
  for (i = 0; i < length; i++) {
589
460
    if (code_len < tmp_len) {
590
0
      return false;
591
0
    }
592
593
460
    get_varuint32(code + tmp_len, code_len - tmp_len, &var_len);
594
460
    if (var_len == -1) {
595
5
      return false;
596
5
    }
597
598
455
    tmp_len += var_len;
599
455
  }
600
601
  // read default target
602
318
  default_target =
603
318
    get_varuint32(code + tmp_len, code_len - tmp_len, &var_len);
604
318
  if (var_len == -1) {
605
2
    return false;
606
2
  }
607
608
316
  MI->wasm_data.brtable.default_target = default_target;
609
316
  MI->wasm_data.type = WASM_OP_BRTABLE;
610
316
  *param_size = tmp_len + var_len;
611
612
316
  if (MI->flat_insn->detail) {
613
316
    MI->flat_insn->detail->wasm.operands[0].size = *param_size;
614
316
    MI->flat_insn->detail->wasm.operands[0].brtable.default_target =
615
316
      MI->wasm_data.brtable.default_target;
616
316
  }
617
618
316
  return true;
619
318
}
620
621
// input  | code : code pointer start from varint7
622
//      | code_len : start from the code pointer to the end, how long is it
623
//      | param_size : pointer of the param size
624
//      | MI : Mcinst handler in this round of disasm
625
// return   | true/false if the function successfully finished
626
static bool read_varint7(const uint8_t *code, size_t code_len,
627
       uint16_t *param_size, MCInst *MI)
628
455
{
629
455
  size_t len = 0;
630
631
455
  MI->wasm_data.type = WASM_OP_INT7;
632
455
  MI->wasm_data.int7 = get_varint7(code, code_len, &len);
633
455
  if (len == -1) {
634
0
    return false;
635
0
  }
636
637
455
  if (MI->flat_insn->detail) {
638
455
    MI->flat_insn->detail->wasm.op_count = 1;
639
455
    MI->flat_insn->detail->wasm.operands[0].type = WASM_OP_INT7;
640
455
    MI->flat_insn->detail->wasm.operands[0].size = 1;
641
455
    MI->flat_insn->detail->wasm.operands[0].int7 =
642
455
      MI->wasm_data.int7;
643
455
  }
644
645
455
  *param_size = len;
646
647
455
  return true;
648
455
}
649
650
bool WASM_getInstruction(csh ud, const uint8_t *code, size_t code_len,
651
       MCInst *MI, uint16_t *size, uint64_t address,
652
       void *inst_info)
653
35.2k
{
654
35.2k
  unsigned char opcode;
655
35.2k
  uint16_t param_size;
656
657
35.2k
  if (code_len == 0)
658
0
    return false;
659
660
35.2k
  opcode = code[0];
661
35.2k
  if (opcodes[opcode] == -1) {
662
    // invalid opcode
663
143
    return false;
664
143
  }
665
666
  // valid opcode
667
35.0k
  MI->address = address;
668
35.0k
  MI->OpcodePub = MI->Opcode = opcode;
669
670
35.0k
  if (MI->flat_insn->detail) {
671
35.0k
    memset(MI->flat_insn->detail, 0,
672
35.0k
           offsetof(cs_detail, wasm) + sizeof(cs_wasm));
673
35.0k
    WASM_get_insn_id((cs_struct *)ud, MI->flat_insn, opcode);
674
35.0k
  }
675
676
  // setup groups
677
35.0k
  switch (opcode) {
678
0
  default:
679
0
    return false;
680
681
60
  case WASM_INS_I32_CONST:
682
60
    if (code_len == 1 ||
683
59
        !read_varuint32(&code[1], code_len - 1, &param_size, MI)) {
684
3
      return false;
685
3
    }
686
687
57
    if (MI->flat_insn->detail) {
688
57
      MI->flat_insn->detail->wasm.op_count = 1;
689
57
      MI->flat_insn->detail
690
57
        ->groups[MI->flat_insn->detail->groups_count] =
691
57
        WASM_GRP_NUMBERIC;
692
57
      MI->flat_insn->detail->groups_count++;
693
57
    }
694
695
57
    *size = param_size + 1;
696
697
57
    break;
698
699
138
  case WASM_INS_I64_CONST:
700
138
    if (code_len == 1 ||
701
137
        !read_varuint64(&code[1], code_len - 1, &param_size, MI)) {
702
1
      return false;
703
1
    }
704
705
137
    if (MI->flat_insn->detail) {
706
137
      MI->flat_insn->detail->wasm.op_count = 1;
707
137
      MI->flat_insn->detail
708
137
        ->groups[MI->flat_insn->detail->groups_count] =
709
137
        WASM_GRP_NUMBERIC;
710
137
      MI->flat_insn->detail->groups_count++;
711
137
    }
712
713
137
    *size = param_size + 1;
714
715
137
    break;
716
717
9
  case WASM_INS_F32_CONST:
718
9
    if (code_len == 1 ||
719
9
        !read_uint32(&code[1], code_len - 1, &param_size, MI)) {
720
0
      return false;
721
0
    }
722
723
9
    if (MI->flat_insn->detail) {
724
9
      MI->flat_insn->detail->wasm.op_count = 1;
725
9
      MI->flat_insn->detail
726
9
        ->groups[MI->flat_insn->detail->groups_count] =
727
9
        WASM_GRP_NUMBERIC;
728
9
      MI->flat_insn->detail->groups_count++;
729
9
    }
730
731
9
    *size = param_size + 1;
732
733
9
    break;
734
735
57
  case WASM_INS_F64_CONST:
736
57
    if (code_len == 1 ||
737
56
        !read_uint64(&code[1], code_len - 1, &param_size, MI)) {
738
2
      return false;
739
2
    }
740
741
55
    if (MI->flat_insn->detail) {
742
55
      MI->flat_insn->detail->wasm.op_count = 1;
743
55
      MI->flat_insn->detail
744
55
        ->groups[MI->flat_insn->detail->groups_count] =
745
55
        WASM_GRP_NUMBERIC;
746
55
      MI->flat_insn->detail->groups_count++;
747
55
    }
748
749
55
    *size = param_size + 1;
750
751
55
    break;
752
753
593
  case WASM_INS_I32_EQZ:
754
710
  case WASM_INS_I32_EQ:
755
725
  case WASM_INS_I32_NE:
756
885
  case WASM_INS_I32_LT_S:
757
911
  case WASM_INS_I32_LT_U:
758
1.10k
  case WASM_INS_I32_GT_S:
759
1.23k
  case WASM_INS_I32_GT_U:
760
1.27k
  case WASM_INS_I32_LE_S:
761
1.42k
  case WASM_INS_I32_LE_U:
762
1.46k
  case WASM_INS_I32_GE_S:
763
1.54k
  case WASM_INS_I32_GE_U:
764
1.65k
  case WASM_INS_I64_EQZ:
765
1.72k
  case WASM_INS_I64_EQ:
766
1.98k
  case WASM_INS_I64_NE:
767
2.00k
  case WASM_INS_I64_LT_S:
768
2.14k
  case WASM_INS_I64_LT_U:
769
2.30k
  case WASN_INS_I64_GT_S:
770
2.40k
  case WASM_INS_I64_GT_U:
771
2.67k
  case WASM_INS_I64_LE_S:
772
3.13k
  case WASM_INS_I64_LE_U:
773
3.17k
  case WASM_INS_I64_GE_S:
774
3.37k
  case WASM_INS_I64_GE_U:
775
3.39k
  case WASM_INS_F32_EQ:
776
3.63k
  case WASM_INS_F32_NE:
777
3.66k
  case WASM_INS_F32_LT:
778
3.69k
  case WASM_INS_F32_GT:
779
3.91k
  case WASM_INS_F32_LE:
780
6.15k
  case WASM_INS_F32_GE:
781
6.75k
  case WASM_INS_F64_EQ:
782
6.82k
  case WASM_INS_F64_NE:
783
7.06k
  case WASM_INS_F64_LT:
784
8.29k
  case WASM_INS_F64_GT:
785
8.35k
  case WASM_INS_F64_LE:
786
8.42k
  case WASM_INS_F64_GE:
787
8.48k
  case WASM_INS_I32_CLZ:
788
8.72k
  case WASM_INS_I32_CTZ:
789
8.89k
  case WASM_INS_I32_POPCNT:
790
8.95k
  case WASM_INS_I32_ADD:
791
9.17k
  case WASM_INS_I32_SUB:
792
9.29k
  case WASM_INS_I32_MUL:
793
9.35k
  case WASM_INS_I32_DIV_S:
794
9.54k
  case WASM_INS_I32_DIV_U:
795
9.62k
  case WASM_INS_I32_REM_S:
796
9.99k
  case WASM_INS_I32_REM_U:
797
10.0k
  case WASM_INS_I32_AND:
798
10.1k
  case WASM_INS_I32_OR:
799
10.2k
  case WASM_INS_I32_XOR:
800
10.3k
  case WASM_INS_I32_SHL:
801
10.4k
  case WASM_INS_I32_SHR_S:
802
10.9k
  case WASM_INS_I32_SHR_U:
803
11.1k
  case WASM_INS_I32_ROTL:
804
11.3k
  case WASM_INS_I32_ROTR:
805
11.6k
  case WASM_INS_I64_CLZ:
806
11.8k
  case WASM_INS_I64_CTZ:
807
12.3k
  case WASM_INS_I64_POPCNT:
808
12.4k
  case WASM_INS_I64_ADD:
809
12.6k
  case WASM_INS_I64_SUB:
810
13.0k
  case WASM_INS_I64_MUL:
811
13.0k
  case WASM_INS_I64_DIV_S:
812
13.2k
  case WASM_INS_I64_DIV_U:
813
13.3k
  case WASM_INS_I64_REM_S:
814
13.6k
  case WASM_INS_I64_REM_U:
815
13.6k
  case WASM_INS_I64_AND:
816
13.9k
  case WASM_INS_I64_OR:
817
13.9k
  case WASM_INS_I64_XOR:
818
14.2k
  case WASM_INS_I64_SHL:
819
14.3k
  case WASM_INS_I64_SHR_S:
820
14.5k
  case WASM_INS_I64_SHR_U:
821
14.9k
  case WASM_INS_I64_ROTL:
822
14.9k
  case WASM_INS_I64_ROTR:
823
15.0k
  case WASM_INS_F32_ABS:
824
15.2k
  case WASM_INS_F32_NEG:
825
15.2k
  case WASM_INS_F32_CEIL:
826
15.3k
  case WASM_INS_F32_FLOOR:
827
15.4k
  case WASM_INS_F32_TRUNC:
828
15.6k
  case WASM_INS_F32_NEAREST:
829
15.8k
  case WASM_INS_F32_SQRT:
830
15.8k
  case WASM_INS_F32_ADD:
831
15.9k
  case WASM_INS_F32_SUB:
832
16.2k
  case WASM_INS_F32_MUL:
833
16.3k
  case WASM_INS_F32_DIV:
834
16.4k
  case WASM_INS_F32_MIN:
835
16.5k
  case WASM_INS_F32_MAX:
836
16.6k
  case WASM_INS_F32_COPYSIGN:
837
16.7k
  case WASM_INS_F64_ABS:
838
16.9k
  case WASM_INS_F64_NEG:
839
16.9k
  case WASM_INS_F64_CEIL:
840
18.2k
  case WASM_INS_F64_FLOOR:
841
18.3k
  case WASM_INS_F64_TRUNC:
842
18.3k
  case WASM_INS_F64_NEAREST:
843
18.3k
  case WASM_INS_F64_SQRT:
844
18.5k
  case WASM_INS_F64_ADD:
845
18.7k
  case WASM_INS_F64_SUB:
846
18.8k
  case WASM_INS_F64_MUL:
847
18.9k
  case WASM_INS_F64_DIV:
848
19.0k
  case WASM_INS_F64_MIN:
849
19.1k
  case WASM_INS_F64_MAX:
850
19.1k
  case WASM_INS_F64_COPYSIGN:
851
19.9k
  case WASM_INS_I32_WARP_I64:
852
19.9k
  case WASP_INS_I32_TRUNC_S_F32:
853
20.0k
  case WASM_INS_I32_TRUNC_U_F32:
854
20.1k
  case WASM_INS_I32_TRUNC_S_F64:
855
20.3k
  case WASM_INS_I32_TRUNC_U_F64:
856
20.3k
  case WASM_INS_I64_EXTEND_S_I32:
857
20.3k
  case WASM_INS_I64_EXTEND_U_I32:
858
20.4k
  case WASM_INS_I64_TRUNC_S_F32:
859
20.5k
  case WASM_INS_I64_TRUNC_U_F32:
860
20.5k
  case WASM_INS_I64_TRUNC_S_F64:
861
20.8k
  case WASM_INS_I64_TRUNC_U_F64:
862
21.0k
  case WASM_INS_F32_CONVERT_S_I32:
863
21.1k
  case WASM_INS_F32_CONVERT_U_I32:
864
21.2k
  case WASM_INS_F32_CONVERT_S_I64:
865
21.5k
  case WASM_INS_F32_CONVERT_U_I64:
866
21.6k
  case WASM_INS_F32_DEMOTE_F64:
867
21.8k
  case WASM_INS_F64_CONVERT_S_I32:
868
21.9k
  case WASM_INS_F64_CONVERT_U_I32:
869
22.0k
  case WASM_INS_F64_CONVERT_S_I64:
870
22.0k
  case WASM_INS_F64_CONVERT_U_I64:
871
22.0k
  case WASM_INS_F64_PROMOTE_F32:
872
22.2k
  case WASM_INS_I32_REINTERPRET_F32:
873
22.3k
  case WASM_INS_I64_REINTERPRET_F64:
874
22.4k
  case WASM_INS_F32_REINTERPRET_I32:
875
22.6k
  case WASM_INS_F64_REINTERPRET_I64:
876
22.6k
    MI->wasm_data.type = WASM_OP_NONE;
877
878
22.6k
    if (MI->flat_insn->detail) {
879
22.6k
      MI->flat_insn->detail->wasm.op_count = 0;
880
22.6k
      MI->flat_insn->detail
881
22.6k
        ->groups[MI->flat_insn->detail->groups_count] =
882
22.6k
        WASM_GRP_NUMBERIC;
883
22.6k
      MI->flat_insn->detail->groups_count++;
884
22.6k
    }
885
886
22.6k
    *size = 1;
887
888
22.6k
    break;
889
890
159
  case WASM_INS_DROP:
891
201
  case WASM_INS_SELECT:
892
201
    MI->wasm_data.type = WASM_OP_NONE;
893
894
201
    if (MI->flat_insn->detail) {
895
201
      MI->flat_insn->detail->wasm.op_count = 0;
896
201
      MI->flat_insn->detail
897
201
        ->groups[MI->flat_insn->detail->groups_count] =
898
201
        WASM_GRP_PARAMETRIC;
899
201
      MI->flat_insn->detail->groups_count++;
900
201
    }
901
902
201
    *size = 1;
903
904
201
    break;
905
906
464
  case WASM_INS_GET_LOCAL:
907
589
  case WASM_INS_SET_LOCAL:
908
626
  case WASM_INS_TEE_LOCAL:
909
790
  case WASM_INS_GET_GLOBAL:
910
846
  case WASM_INS_SET_GLOBAL:
911
846
    if (code_len == 1 ||
912
841
        !read_varuint32(&code[1], code_len - 1, &param_size, MI)) {
913
9
      return false;
914
9
    }
915
916
837
    if (MI->flat_insn->detail) {
917
837
      MI->flat_insn->detail->wasm.op_count = 1;
918
837
      MI->flat_insn->detail
919
837
        ->groups[MI->flat_insn->detail->groups_count] =
920
837
        WASM_GRP_VARIABLE;
921
837
      MI->flat_insn->detail->groups_count++;
922
837
    }
923
924
837
    *size = param_size + 1;
925
926
837
    break;
927
928
64
  case WASM_INS_I32_LOAD:
929
142
  case WASM_INS_I64_LOAD:
930
222
  case WASM_INS_F32_LOAD:
931
284
  case WASM_INS_F64_LOAD:
932
375
  case WASM_INS_I32_LOAD8_S:
933
477
  case WASM_INS_I32_LOAD8_U:
934
535
  case WASM_INS_I32_LOAD16_S:
935
849
  case WASM_INS_I32_LOAD16_U:
936
1.10k
  case WASM_INS_I64_LOAD8_S:
937
1.62k
  case WASM_INS_I64_LOAD8_U:
938
1.74k
  case WASM_INS_I64_LOAD16_S:
939
1.98k
  case WASM_INS_I64_LOAD16_U:
940
2.05k
  case WASM_INS_I64_LOAD32_S:
941
2.58k
  case WASM_INS_I64_LOAD32_U:
942
2.97k
  case WASM_INS_I32_STORE:
943
3.08k
  case WASM_INS_I64_STORE:
944
3.13k
  case WASM_INS_F32_STORE:
945
3.19k
  case WASM_INS_F64_STORE:
946
3.39k
  case WASM_INS_I32_STORE8:
947
3.45k
  case WASM_INS_I32_STORE16:
948
3.65k
  case WASM_INS_I64_STORE8:
949
3.83k
  case WASM_INS_I64_STORE16:
950
3.92k
  case WASM_INS_I64_STORE32:
951
3.92k
    if (code_len == 1 ||
952
3.91k
        !read_memoryimmediate(&code[1], code_len - 1, &param_size,
953
3.91k
            MI)) {
954
53
      return false;
955
53
    }
956
957
3.87k
    if (MI->flat_insn->detail) {
958
3.87k
      MI->flat_insn->detail->wasm.op_count = 2;
959
3.87k
      MI->flat_insn->detail
960
3.87k
        ->groups[MI->flat_insn->detail->groups_count] =
961
3.87k
        WASM_GRP_MEMORY;
962
3.87k
      MI->flat_insn->detail->groups_count++;
963
3.87k
    }
964
965
3.87k
    *size = param_size + 1;
966
967
3.87k
    break;
968
969
60
  case WASM_INS_CURRENT_MEMORY:
970
325
  case WASM_INS_GROW_MEMORY:
971
325
    MI->wasm_data.type = WASM_OP_NONE;
972
973
325
    if (MI->flat_insn->detail) {
974
325
      MI->flat_insn->detail->wasm.op_count = 0;
975
325
      MI->flat_insn->detail
976
325
        ->groups[MI->flat_insn->detail->groups_count] =
977
325
        WASM_GRP_MEMORY;
978
325
      MI->flat_insn->detail->groups_count++;
979
325
    }
980
981
325
    *size = 1;
982
983
325
    break;
984
985
5.26k
  case WASM_INS_UNREACHABLE:
986
5.36k
  case WASM_INS_NOP:
987
5.59k
  case WASM_INS_ELSE:
988
5.60k
  case WASM_INS_END:
989
5.82k
  case WASM_INS_RETURN:
990
5.82k
    MI->wasm_data.type = WASM_OP_NONE;
991
992
5.82k
    if (MI->flat_insn->detail) {
993
5.82k
      MI->flat_insn->detail->wasm.op_count = 0;
994
5.82k
      MI->flat_insn->detail
995
5.82k
        ->groups[MI->flat_insn->detail->groups_count] =
996
5.82k
        WASM_GRP_CONTROL;
997
5.82k
      MI->flat_insn->detail->groups_count++;
998
5.82k
    }
999
1000
5.82k
    *size = 1;
1001
1002
5.82k
    break;
1003
1004
226
  case WASM_INS_BLOCK:
1005
290
  case WASM_INS_LOOP:
1006
459
  case WASM_INS_IF:
1007
459
    if (code_len == 1 ||
1008
455
        !read_varint7(&code[1], code_len - 1, &param_size, MI)) {
1009
4
      return false;
1010
4
    }
1011
1012
455
    if (MI->flat_insn->detail) {
1013
455
      MI->flat_insn->detail->wasm.op_count = 1;
1014
455
      MI->flat_insn->detail
1015
455
        ->groups[MI->flat_insn->detail->groups_count] =
1016
455
        WASM_GRP_CONTROL;
1017
455
      MI->flat_insn->detail->groups_count++;
1018
455
    }
1019
1020
455
    *size = param_size + 1;
1021
1022
455
    break;
1023
1024
86
  case WASM_INS_BR:
1025
131
  case WASM_INS_BR_IF:
1026
213
  case WASM_INS_CALL:
1027
315
  case WASM_INS_CALL_INDIRECT:
1028
315
    if (code_len == 1 ||
1029
309
        !read_varuint32(&code[1], code_len - 1, &param_size, MI)) {
1030
7
      return false;
1031
7
    }
1032
1033
308
    if (MI->flat_insn->detail) {
1034
308
      MI->flat_insn->detail->wasm.op_count = 1;
1035
308
      MI->flat_insn->detail
1036
308
        ->groups[MI->flat_insn->detail->groups_count] =
1037
308
        WASM_GRP_CONTROL;
1038
308
      MI->flat_insn->detail->groups_count++;
1039
308
    }
1040
1041
308
    *size = param_size + 1;
1042
1043
308
    break;
1044
1045
338
  case WASM_INS_BR_TABLE:
1046
338
    if (code_len == 1 ||
1047
336
        !read_brtable(&code[1], code_len - 1, &param_size, MI)) {
1048
22
      return false;
1049
22
    }
1050
1051
316
    if (MI->flat_insn->detail) {
1052
316
      MI->flat_insn->detail->wasm.op_count = 1;
1053
316
      MI->flat_insn->detail
1054
316
        ->groups[MI->flat_insn->detail->groups_count] =
1055
316
        WASM_GRP_CONTROL;
1056
316
      MI->flat_insn->detail->groups_count++;
1057
316
    }
1058
1059
316
    *size = param_size + 1;
1060
1061
316
    break;
1062
35.0k
  }
1063
1064
34.9k
  return true;
1065
35.0k
}