Coverage Report

Created: 2026-08-14 06:51

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/capstonev5/cs.c
Line
Count
Source
1
/* Capstone Disassembly Engine */
2
/* By Nguyen Anh Quynh <aquynh@gmail.com>, 2013-2019 */
3
#if defined (WIN32) || defined (WIN64) || defined (_WIN32) || defined (_WIN64)
4
#pragma warning(disable:4996)     // disable MSVC's warning on strcpy()
5
#pragma warning(disable:28719)    // disable MSVC's warning on strcpy()
6
#endif
7
#if defined(CAPSTONE_HAS_OSXKERNEL)
8
#include <Availability.h>
9
#include <libkern/libkern.h>
10
#else
11
#include <stddef.h>
12
#include <stdio.h>
13
#include <stdlib.h>
14
#endif
15
16
#include <string.h>
17
#include <capstone/capstone.h>
18
19
#include "utils.h"
20
#include "MCRegisterInfo.h"
21
22
#if defined(_KERNEL_MODE)
23
#include "windows\winkernel_mm.h"
24
#endif
25
26
// Issue #681: Windows kernel does not support formatting float point
27
#if defined(_KERNEL_MODE) && !defined(CAPSTONE_DIET)
28
#if defined(CAPSTONE_HAS_ARM) || defined(CAPSTONE_HAS_ARM64) || defined(CAPSTONE_HAS_M68K)
29
#define CAPSTONE_STR_INTERNAL(x) #x
30
#define CAPSTONE_STR(x) CAPSTONE_STR_INTERNAL(x)
31
#define CAPSTONE_MSVC_WRANING_PREFIX __FILE__ "("CAPSTONE_STR(__LINE__)") : warning message : "
32
33
#pragma message(CAPSTONE_MSVC_WRANING_PREFIX "Windows driver does not support full features for selected architecture(s). Define CAPSTONE_DIET to compile Capstone with only supported features. See issue #681 for details.")
34
35
#undef CAPSTONE_MSVC_WRANING_PREFIX
36
#undef CAPSTONE_STR
37
#undef CAPSTONE_STR_INTERNAL
38
#endif
39
#endif  // defined(_KERNEL_MODE) && !defined(CAPSTONE_DIET)
40
41
#if !defined(CAPSTONE_HAS_OSXKERNEL) && !defined(CAPSTONE_DIET) && !defined(_KERNEL_MODE)
42
38.4k
#define INSN_CACHE_SIZE 32
43
#else
44
// reduce stack variable size for kernel/firmware
45
#define INSN_CACHE_SIZE 8
46
#endif
47
48
// default SKIPDATA mnemonic
49
#ifndef CAPSTONE_DIET
50
38.4k
#define SKIPDATA_MNEM ".byte"
51
#else // No printing is available in diet mode
52
#define SKIPDATA_MNEM NULL
53
#endif
54
55
#include "arch/AArch64/AArch64Module.h"
56
#include "arch/ARM/ARMModule.h"
57
#include "arch/EVM/EVMModule.h"
58
#include "arch/WASM/WASMModule.h"
59
#include "arch/M680X/M680XModule.h"
60
#include "arch/M68K/M68KModule.h"
61
#include "arch/Mips/MipsModule.h"
62
#include "arch/PowerPC/PPCModule.h"
63
#include "arch/Sparc/SparcModule.h"
64
#include "arch/SystemZ/SystemZModule.h"
65
#include "arch/TMS320C64x/TMS320C64xModule.h"
66
#include "arch/X86/X86Module.h"
67
#include "arch/XCore/XCoreModule.h"
68
#include "arch/RISCV/RISCVModule.h"
69
#include "arch/MOS65XX/MOS65XXModule.h"
70
#include "arch/BPF/BPFModule.h"
71
#include "arch/SH/SHModule.h"
72
#include "arch/TriCore/TriCoreModule.h"
73
74
static const struct {
75
  // constructor initialization
76
  cs_err (*arch_init)(cs_struct *);
77
  // support cs_option()
78
  cs_err (*arch_option)(cs_struct *, cs_opt_type, size_t value);
79
  // bitmask for finding disallowed modes for an arch:
80
  // to be called in cs_open()/cs_option()
81
  cs_mode arch_disallowed_mode_mask;
82
} arch_configs[MAX_ARCH] = {
83
#ifdef CAPSTONE_HAS_ARM
84
  {
85
    ARM_global_init,
86
    ARM_option,
87
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_ARM | CS_MODE_V8 | CS_MODE_MCLASS
88
        | CS_MODE_THUMB | CS_MODE_BIG_ENDIAN)
89
  },
90
#else
91
  { NULL, NULL, 0 },
92
#endif
93
#ifdef CAPSTONE_HAS_ARM64
94
  {
95
    AArch64_global_init,
96
    AArch64_option,
97
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_ARM | CS_MODE_BIG_ENDIAN),
98
  },
99
#else
100
  { NULL, NULL, 0 },
101
#endif
102
#ifdef CAPSTONE_HAS_MIPS
103
  {
104
    Mips_global_init,
105
    Mips_option,
106
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_32 | CS_MODE_64 | CS_MODE_MICRO
107
        | CS_MODE_MIPS32R6 | CS_MODE_BIG_ENDIAN | CS_MODE_MIPS2 | CS_MODE_MIPS3),
108
  },
109
#else
110
  { NULL, NULL, 0 },
111
#endif
112
#ifdef CAPSTONE_HAS_X86
113
  {
114
    X86_global_init,
115
    X86_option,
116
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_32 | CS_MODE_64 | CS_MODE_16),
117
  },
118
#else
119
  { NULL, NULL, 0 },
120
#endif
121
#ifdef CAPSTONE_HAS_POWERPC
122
  {
123
    PPC_global_init,
124
    PPC_option,
125
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_32 | CS_MODE_64 | CS_MODE_BIG_ENDIAN
126
        | CS_MODE_QPX | CS_MODE_PS),
127
  },
128
#else
129
  { NULL, NULL, 0 },
130
#endif
131
#ifdef CAPSTONE_HAS_SPARC
132
  {
133
    Sparc_global_init,
134
    Sparc_option,
135
    ~(CS_MODE_BIG_ENDIAN | CS_MODE_V9),
136
  },
137
#else
138
  { NULL, NULL, 0 },
139
#endif
140
#ifdef CAPSTONE_HAS_SYSZ
141
  {
142
    SystemZ_global_init,
143
    SystemZ_option,
144
    ~(CS_MODE_BIG_ENDIAN),
145
  },
146
#else
147
  { NULL, NULL, 0 },
148
#endif
149
#ifdef CAPSTONE_HAS_XCORE
150
  {
151
    XCore_global_init,
152
    XCore_option,
153
    ~(CS_MODE_BIG_ENDIAN),
154
  },
155
#else
156
  { NULL, NULL, 0 },
157
#endif
158
#ifdef CAPSTONE_HAS_M68K
159
  {
160
    M68K_global_init,
161
    M68K_option,
162
    ~(CS_MODE_BIG_ENDIAN | CS_MODE_M68K_000 | CS_MODE_M68K_010 | CS_MODE_M68K_020
163
        | CS_MODE_M68K_030 | CS_MODE_M68K_040 | CS_MODE_M68K_060),
164
  },
165
#else
166
  { NULL, NULL, 0 },
167
#endif
168
#ifdef CAPSTONE_HAS_TMS320C64X
169
  {
170
    TMS320C64x_global_init,
171
    TMS320C64x_option,
172
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_BIG_ENDIAN),
173
  },
174
#else
175
  { NULL, NULL, 0 },
176
#endif
177
#ifdef CAPSTONE_HAS_M680X
178
  {
179
    M680X_global_init,
180
    M680X_option,
181
    ~(CS_MODE_M680X_6301 | CS_MODE_M680X_6309 | CS_MODE_M680X_6800
182
        | CS_MODE_M680X_6801 | CS_MODE_M680X_6805 | CS_MODE_M680X_6808
183
        | CS_MODE_M680X_6809 | CS_MODE_M680X_6811 | CS_MODE_M680X_CPU12
184
        | CS_MODE_M680X_HCS08),
185
  },
186
#else
187
  { NULL, NULL, 0 },
188
#endif
189
#ifdef CAPSTONE_HAS_EVM
190
  {
191
    EVM_global_init,
192
    EVM_option,
193
    0,
194
  },
195
#else
196
  { NULL, NULL, 0 },
197
#endif
198
#ifdef CAPSTONE_HAS_MOS65XX
199
  {
200
    MOS65XX_global_init,
201
    MOS65XX_option,
202
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_MOS65XX_6502 | CS_MODE_MOS65XX_65C02
203
        | CS_MODE_MOS65XX_W65C02 | CS_MODE_MOS65XX_65816_LONG_MX),
204
  },
205
#else
206
  { NULL, NULL, 0 },
207
#endif
208
#ifdef CAPSTONE_HAS_WASM
209
  {
210
    WASM_global_init,
211
    WASM_option,
212
    0,
213
  },
214
#else
215
  { NULL, NULL, 0 },
216
#endif
217
#ifdef CAPSTONE_HAS_BPF
218
  {
219
    BPF_global_init,
220
    BPF_option,
221
    ~(CS_MODE_LITTLE_ENDIAN | CS_MODE_BPF_CLASSIC | CS_MODE_BPF_EXTENDED
222
        | CS_MODE_BIG_ENDIAN),
223
  },
224
#else
225
  { NULL, NULL, 0 },
226
#endif
227
#ifdef CAPSTONE_HAS_RISCV
228
  {
229
    RISCV_global_init,
230
    RISCV_option,
231
    ~(CS_MODE_RISCV32 | CS_MODE_RISCV64 | CS_MODE_RISCVC),
232
  },
233
#else
234
  { NULL, NULL, 0 },
235
#endif
236
#ifdef CAPSTONE_HAS_SH
237
  {
238
    SH_global_init,
239
    SH_option,
240
    ~(CS_MODE_SH2 | CS_MODE_SH2A | CS_MODE_SH3 |
241
      CS_MODE_SH4 | CS_MODE_SH4A |
242
      CS_MODE_SHFPU | CS_MODE_SHDSP|CS_MODE_BIG_ENDIAN),
243
  },
244
#else
245
  { NULL, NULL, 0 },
246
#endif
247
#ifdef CAPSTONE_HAS_TRICORE
248
  {
249
    TRICORE_global_init,
250
    TRICORE_option,
251
    ~(CS_MODE_TRICORE_110 | CS_MODE_TRICORE_120 | CS_MODE_TRICORE_130
252
    | CS_MODE_TRICORE_131 | CS_MODE_TRICORE_160 | CS_MODE_TRICORE_161
253
    | CS_MODE_TRICORE_162 | CS_MODE_LITTLE_ENDIAN),
254
  },
255
#else
256
  { NULL, NULL, 0 },
257
#endif
258
};
259
260
// bitmask of enabled architectures
261
static const uint32_t all_arch = 0
262
#ifdef CAPSTONE_HAS_ARM
263
  | (1 << CS_ARCH_ARM)
264
#endif
265
#ifdef CAPSTONE_HAS_ARM64
266
  | (1 << CS_ARCH_ARM64)
267
#endif
268
#ifdef CAPSTONE_HAS_MIPS
269
  | (1 << CS_ARCH_MIPS)
270
#endif
271
#ifdef CAPSTONE_HAS_X86
272
  | (1 << CS_ARCH_X86)
273
#endif
274
#ifdef CAPSTONE_HAS_POWERPC
275
  | (1 << CS_ARCH_PPC)
276
#endif
277
#ifdef CAPSTONE_HAS_SPARC
278
  | (1 << CS_ARCH_SPARC)
279
#endif
280
#ifdef CAPSTONE_HAS_SYSZ
281
  | (1 << CS_ARCH_SYSZ)
282
#endif
283
#ifdef CAPSTONE_HAS_XCORE
284
  | (1 << CS_ARCH_XCORE)
285
#endif
286
#ifdef CAPSTONE_HAS_M68K
287
  | (1 << CS_ARCH_M68K)
288
#endif
289
#ifdef CAPSTONE_HAS_TMS320C64X
290
  | (1 << CS_ARCH_TMS320C64X)
291
#endif
292
#ifdef CAPSTONE_HAS_M680X
293
  | (1 << CS_ARCH_M680X)
294
#endif
295
#ifdef CAPSTONE_HAS_EVM
296
  | (1 << CS_ARCH_EVM)
297
#endif
298
#ifdef CAPSTONE_HAS_MOS65XX
299
  | (1 << CS_ARCH_MOS65XX)
300
#endif
301
#ifdef CAPSTONE_HAS_WASM
302
  | (1 << CS_ARCH_WASM)
303
#endif
304
#ifdef CAPSTONE_HAS_BPF
305
  | (1 << CS_ARCH_BPF)
306
#endif
307
#ifdef CAPSTONE_HAS_RISCV
308
  | (1 << CS_ARCH_RISCV)
309
#endif
310
#ifdef CAPSTONE_HAS_SH
311
  | (1 << CS_ARCH_SH)
312
#endif
313
#ifdef CAPSTONE_HAS_TRICORE
314
  | (1 << CS_ARCH_TRICORE)
315
#endif
316
;
317
318
319
#if defined(CAPSTONE_USE_SYS_DYN_MEM)
320
#if !defined(CAPSTONE_HAS_OSXKERNEL) && !defined(_KERNEL_MODE)
321
// default
322
cs_malloc_t cs_mem_malloc = malloc;
323
cs_calloc_t cs_mem_calloc = calloc;
324
cs_realloc_t cs_mem_realloc = realloc;
325
cs_free_t cs_mem_free = free;
326
#if defined(_WIN32_WCE)
327
cs_vsnprintf_t cs_vsnprintf = _vsnprintf;
328
#else
329
cs_vsnprintf_t cs_vsnprintf = vsnprintf;
330
#endif  // defined(_WIN32_WCE)
331
332
#elif defined(_KERNEL_MODE)
333
// Windows driver
334
cs_malloc_t cs_mem_malloc = cs_winkernel_malloc;
335
cs_calloc_t cs_mem_calloc = cs_winkernel_calloc;
336
cs_realloc_t cs_mem_realloc = cs_winkernel_realloc;
337
cs_free_t cs_mem_free = cs_winkernel_free;
338
cs_vsnprintf_t cs_vsnprintf = cs_winkernel_vsnprintf;
339
#else
340
// OSX kernel
341
extern void* kern_os_malloc(size_t size);
342
extern void kern_os_free(void* addr);
343
extern void* kern_os_realloc(void* addr, size_t nsize);
344
345
static void* cs_kern_os_calloc(size_t num, size_t size)
346
{
347
  size_t alloc = num * size;
348
  if (num && size != alloc / num) {
349
    return NULL; // overflow check
350
  }
351
  return kern_os_malloc(alloc); // malloc bzeroes the buffer
352
}
353
354
cs_malloc_t cs_mem_malloc = kern_os_malloc;
355
cs_calloc_t cs_mem_calloc = cs_kern_os_calloc;
356
cs_realloc_t cs_mem_realloc = kern_os_realloc;
357
cs_free_t cs_mem_free = kern_os_free;
358
cs_vsnprintf_t cs_vsnprintf = vsnprintf;
359
#endif  // !defined(CAPSTONE_HAS_OSXKERNEL) && !defined(_KERNEL_MODE)
360
#else
361
// User-defined
362
cs_malloc_t cs_mem_malloc = NULL;
363
cs_calloc_t cs_mem_calloc = NULL;
364
cs_realloc_t cs_mem_realloc = NULL;
365
cs_free_t cs_mem_free = NULL;
366
cs_vsnprintf_t cs_vsnprintf = NULL;
367
368
#endif  // defined(CAPSTONE_USE_SYS_DYN_MEM)
369
370
CAPSTONE_EXPORT
371
unsigned int CAPSTONE_API cs_version(int *major, int *minor)
372
0
{
373
0
  if (major != NULL && minor != NULL) {
374
0
    *major = CS_API_MAJOR;
375
0
    *minor = CS_API_MINOR;
376
0
  }
377
378
0
  return (CS_API_MAJOR << 8) + CS_API_MINOR;
379
0
}
380
381
CAPSTONE_EXPORT
382
bool CAPSTONE_API cs_support(int query)
383
0
{
384
0
  if (query == CS_ARCH_ALL)
385
0
    return all_arch == ((1 << CS_ARCH_ARM)   | (1 << CS_ARCH_ARM64)      |
386
0
            (1 << CS_ARCH_MIPS)  | (1 << CS_ARCH_X86)        |
387
0
            (1 << CS_ARCH_PPC)   | (1 << CS_ARCH_SPARC)      |
388
0
            (1 << CS_ARCH_SYSZ)  | (1 << CS_ARCH_XCORE)      |
389
0
            (1 << CS_ARCH_M68K)  | (1 << CS_ARCH_TMS320C64X) |
390
0
            (1 << CS_ARCH_M680X) | (1 << CS_ARCH_EVM)        |
391
0
            (1 << CS_ARCH_RISCV) | (1 << CS_ARCH_MOS65XX)    |
392
0
            (1 << CS_ARCH_WASM)  | (1 << CS_ARCH_BPF)        |
393
0
            (1 << CS_ARCH_SH)    | (1 << CS_ARCH_TRICORE));
394
395
0
  if ((unsigned int)query < CS_ARCH_MAX)
396
0
    return all_arch & (1 << query);
397
398
0
  if (query == CS_SUPPORT_DIET) {
399
#ifdef CAPSTONE_DIET
400
    return true;
401
#else
402
0
    return false;
403
0
#endif
404
0
  }
405
406
0
  if (query == CS_SUPPORT_X86_REDUCE) {
407
#if defined(CAPSTONE_HAS_X86) && defined(CAPSTONE_X86_REDUCE)
408
    return true;
409
#else
410
0
    return false;
411
0
#endif
412
0
  }
413
414
  // unsupported query
415
0
  return false;
416
0
}
417
418
CAPSTONE_EXPORT
419
cs_err CAPSTONE_API cs_errno(csh handle)
420
0
{
421
0
  struct cs_struct *ud;
422
0
  if (!handle)
423
0
    return CS_ERR_CSH;
424
425
0
  ud = (struct cs_struct *)(uintptr_t)handle;
426
427
0
  return ud->errnum;
428
0
}
429
430
CAPSTONE_EXPORT
431
const char * CAPSTONE_API cs_strerror(cs_err code)
432
0
{
433
0
  switch(code) {
434
0
    default:
435
0
      return "Unknown error code";
436
0
    case CS_ERR_OK:
437
0
      return "OK (CS_ERR_OK)";
438
0
    case CS_ERR_MEM:
439
0
      return "Out of memory (CS_ERR_MEM)";
440
0
    case CS_ERR_ARCH:
441
0
      return "Invalid/unsupported architecture(CS_ERR_ARCH)";
442
0
    case CS_ERR_HANDLE:
443
0
      return "Invalid handle (CS_ERR_HANDLE)";
444
0
    case CS_ERR_CSH:
445
0
      return "Invalid csh (CS_ERR_CSH)";
446
0
    case CS_ERR_MODE:
447
0
      return "Invalid mode (CS_ERR_MODE)";
448
0
    case CS_ERR_OPTION:
449
0
      return "Invalid option (CS_ERR_OPTION)";
450
0
    case CS_ERR_DETAIL:
451
0
      return "Details are unavailable (CS_ERR_DETAIL)";
452
0
    case CS_ERR_MEMSETUP:
453
0
      return "Dynamic memory management uninitialized (CS_ERR_MEMSETUP)";
454
0
    case CS_ERR_VERSION:
455
0
      return "Different API version between core & binding (CS_ERR_VERSION)";
456
0
    case CS_ERR_DIET:
457
0
      return "Information irrelevant in diet engine (CS_ERR_DIET)";
458
0
    case CS_ERR_SKIPDATA:
459
0
      return "Information irrelevant for 'data' instruction in SKIPDATA mode (CS_ERR_SKIPDATA)";
460
0
    case CS_ERR_X86_ATT:
461
0
      return "AT&T syntax is unavailable (CS_ERR_X86_ATT)";
462
0
    case CS_ERR_X86_INTEL:
463
0
      return "INTEL syntax is unavailable (CS_ERR_X86_INTEL)";
464
0
    case CS_ERR_X86_MASM:
465
0
      return "MASM syntax is unavailable (CS_ERR_X86_MASM)";
466
0
  }
467
0
}
468
469
CAPSTONE_EXPORT
470
cs_err CAPSTONE_API cs_open(cs_arch arch, cs_mode mode, csh *handle)
471
38.4k
{
472
38.4k
  cs_err err;
473
38.4k
  struct cs_struct *ud;
474
38.4k
  if (!cs_mem_malloc || !cs_mem_calloc || !cs_mem_realloc || !cs_mem_free || !cs_vsnprintf)
475
    // Error: before cs_open(), dynamic memory management must be initialized
476
    // with cs_option(CS_OPT_MEM)
477
0
    return CS_ERR_MEMSETUP;
478
479
38.4k
  if (arch < CS_ARCH_MAX && arch_configs[arch].arch_init) {
480
    // verify if requested mode is valid
481
38.4k
    if (mode & arch_configs[arch].arch_disallowed_mode_mask) {
482
2
      *handle = 0;
483
2
      return CS_ERR_MODE;
484
2
    }
485
486
38.4k
    ud = cs_mem_calloc(1, sizeof(*ud));
487
38.4k
    if (!ud) {
488
      // memory insufficient
489
0
      return CS_ERR_MEM;
490
0
    }
491
492
38.4k
    ud->errnum = CS_ERR_OK;
493
38.4k
    ud->arch = arch;
494
38.4k
    ud->mode = mode;
495
    // by default, do not break instruction into details
496
38.4k
    ud->detail = CS_OPT_OFF;
497
498
    // default skipdata setup
499
38.4k
    ud->skipdata_setup.mnemonic = SKIPDATA_MNEM;
500
501
38.4k
    err = arch_configs[ud->arch].arch_init(ud);
502
38.4k
    if (err) {
503
0
      cs_mem_free(ud);
504
0
      *handle = 0;
505
0
      return err;
506
0
    }
507
508
38.4k
    *handle = (uintptr_t)ud;
509
510
38.4k
    return CS_ERR_OK;
511
38.4k
  } else {
512
0
    *handle = 0;
513
0
    return CS_ERR_ARCH;
514
0
  }
515
38.4k
}
516
517
CAPSTONE_EXPORT
518
cs_err CAPSTONE_API cs_close(csh *handle)
519
38.4k
{
520
38.4k
  struct cs_struct *ud;
521
38.4k
  struct insn_mnem *next, *tmp;
522
523
38.4k
  if (*handle == 0)
524
    // invalid handle
525
0
    return CS_ERR_CSH;
526
527
38.4k
  ud = (struct cs_struct *)(*handle);
528
529
38.4k
  if (ud->printer_info)
530
36.4k
    cs_mem_free(ud->printer_info);
531
532
  // free the linked list of customized mnemonic
533
38.4k
  tmp = ud->mnem_list;
534
38.4k
  while(tmp) {
535
0
    next = tmp->next;
536
0
    cs_mem_free(tmp);
537
0
    tmp = next;
538
0
  }
539
540
38.4k
  cs_mem_free(ud->insn_cache);
541
38.4k
  cs_mem_free(ud->x86_insn_lut);
542
38.4k
  cs_mem_free(ud->x86_insn_reg_lut);
543
544
38.4k
  memset(ud, 0, sizeof(*ud));
545
38.4k
  cs_mem_free(ud);
546
547
  // invalidate this handle by ZERO out its value.
548
  // this is to make sure it is unusable after cs_close()
549
38.4k
  *handle = 0;
550
551
38.4k
  return CS_ERR_OK;
552
38.4k
}
553
554
// replace str1 in target with str2; target starts with str1
555
// output is put into result (which is array of char with size CS_MNEMONIC_SIZE)
556
// return 0 on success, -1 on failure
557
static int str_replace(char *result, char *target, const char *str1, char *str2)
558
0
{
559
  // only perform replacement if the output fits into result
560
0
  if (strlen(target) - strlen(str1) + strlen(str2) < CS_MNEMONIC_SIZE - 1)  {
561
    // copy str2 to begining of result
562
0
    strcpy(result, str2);
563
    // skip str1 - already replaced by str2
564
0
    strcat(result, target + strlen(str1));
565
566
0
    return 0;
567
0
  } else
568
0
    return -1;
569
0
}
570
571
// fill insn with mnemonic & operands info
572
static void fill_insn(struct cs_struct *handle, cs_insn *insn, char *buffer, MCInst *mci,
573
    PostPrinter_t postprinter, const uint8_t *code)
574
2.55M
{
575
2.55M
#ifndef CAPSTONE_DIET
576
2.55M
  char *sp, *mnem;
577
2.55M
#endif
578
2.55M
  uint16_t copy_size = MIN(sizeof(insn->bytes), insn->size);
579
580
  // fill the instruction bytes.
581
  // we might skip some redundant bytes in front in the case of X86
582
2.55M
  memcpy(insn->bytes, code + insn->size - copy_size, copy_size);
583
2.55M
  insn->op_str[0] = '\0';
584
  // mnemonic is filled below, after the post printer runs: post printers
585
  // must derive any checks from insn_asm, never from insn->mnemonic
586
2.55M
  insn->mnemonic[0] = '\0';
587
2.55M
  insn->size = copy_size;
588
589
  // alias instruction might have ID saved in OpcodePub
590
2.55M
  if (MCInst_getOpcodePub(mci))
591
163k
    insn->id = MCInst_getOpcodePub(mci);
592
593
  // post printer handles some corner cases (hacky)
594
2.55M
  if (postprinter)
595
1.87M
    postprinter((csh)handle, insn, buffer, mci);
596
597
2.55M
#ifndef CAPSTONE_DIET
598
2.55M
  mnem = insn->mnemonic;
599
  // memset(mnem, 0, CS_MNEMONIC_SIZE);
600
14.6M
  for (sp = buffer; *sp; sp++) {
601
14.4M
    if (*sp == ' '|| *sp == '\t')
602
2.42M
      break;
603
12.0M
    if (*sp == '|')  // lock|rep prefix for x86
604
82.3k
      *sp = ' ';
605
    // copy to @mnemonic
606
12.0M
    *mnem = *sp;
607
12.0M
    mnem++;
608
12.0M
  }
609
610
2.55M
  *mnem = '\0';
611
612
  // we might have customized mnemonic
613
2.55M
  if (handle->mnem_list) {
614
0
    struct insn_mnem *tmp = handle->mnem_list;
615
0
    while(tmp) {
616
0
      if (tmp->insn.id == insn->id) {
617
0
        char str[CS_MNEMONIC_SIZE];
618
619
0
        if (!str_replace(str, insn->mnemonic, cs_insn_name((csh)handle, insn->id), tmp->insn.mnemonic)) {
620
          // copy result to mnemonic
621
0
          (void)strncpy(insn->mnemonic, str, sizeof(insn->mnemonic) - 1);
622
0
          insn->mnemonic[sizeof(insn->mnemonic) - 1] = '\0';
623
0
        }
624
625
0
        break;
626
0
      }
627
0
      tmp = tmp->next;
628
0
    }
629
0
  }
630
631
  // copy @op_str
632
2.55M
  if (*sp) {
633
    // find the next non-space char
634
2.42M
    sp++;
635
2.42M
    for (; ((*sp == ' ') || (*sp == '\t')); sp++);
636
2.42M
    strncpy(insn->op_str, sp, sizeof(insn->op_str) - 1);
637
2.42M
    insn->op_str[sizeof(insn->op_str) - 1] = '\0';
638
2.42M
  } else
639
129k
    insn->op_str[0] = '\0';
640
641
2.55M
#endif
642
2.55M
}
643
644
// how many bytes will we skip when encountering data (CS_OPT_SKIPDATA)?
645
// this very much depends on instruction alignment requirement of each arch.
646
static uint8_t skipdata_size(cs_struct *handle)
647
0
{
648
0
  switch(handle->arch) {
649
0
    default:
650
      // should never reach
651
0
      return (uint8_t)-1;
652
0
    case CS_ARCH_ARM:
653
      // skip 2 bytes on Thumb mode.
654
0
      if (handle->mode & CS_MODE_THUMB)
655
0
        return 2;
656
      // otherwise, skip 4 bytes
657
0
      return 4;
658
0
    case CS_ARCH_ARM64:
659
0
    case CS_ARCH_MIPS:
660
0
    case CS_ARCH_PPC:
661
0
    case CS_ARCH_SPARC:
662
      // skip 4 bytes
663
0
      return 4;
664
0
    case CS_ARCH_SYSZ:
665
      // SystemZ instruction's length can be 2, 4 or 6 bytes,
666
      // so we just skip 2 bytes
667
0
      return 2;
668
0
    case CS_ARCH_X86:
669
      // X86 has no restriction on instruction alignment
670
0
      return 1;
671
0
    case CS_ARCH_XCORE:
672
      // XCore instruction's length can be 2 or 4 bytes,
673
      // so we just skip 2 bytes
674
0
      return 2;
675
0
    case CS_ARCH_M68K:
676
      // M68K has 2 bytes instruction alignment but contain multibyte instruction so we skip 2 bytes
677
0
      return 2;
678
0
    case CS_ARCH_TMS320C64X:
679
      // TMS320C64x alignment is 4.
680
0
      return 4;
681
0
    case CS_ARCH_M680X:
682
      // M680X alignment is 1.
683
0
      return 1;
684
0
    case CS_ARCH_EVM:
685
      // EVM alignment is 1.
686
0
      return 1;
687
0
    case CS_ARCH_WASM:
688
      //WASM alignment is 1
689
0
      return 1;
690
0
    case CS_ARCH_MOS65XX:
691
      // MOS65XX alignment is 1.
692
0
      return 1;
693
0
    case CS_ARCH_BPF:
694
      // both classic and extended BPF have alignment 8.
695
0
      return 8;
696
0
    case CS_ARCH_RISCV:
697
      // special compress mode
698
0
      if (handle->mode & CS_MODE_RISCVC)
699
0
        return 2;
700
0
      return 4;
701
0
    case CS_ARCH_SH:
702
0
      return 2;
703
0
    case CS_ARCH_TRICORE:
704
      // TriCore instruction's length can be 2 or 4 bytes,
705
      // so we just skip 2 bytes
706
0
      return 2;
707
0
  }
708
0
}
709
710
CAPSTONE_EXPORT
711
cs_err CAPSTONE_API cs_option(csh ud, cs_opt_type type, size_t value)
712
49.1k
{
713
49.1k
  struct cs_struct *handle;
714
49.1k
  cs_opt_mnem *opt;
715
716
  // cs_option() can be called with NULL handle just for CS_OPT_MEM
717
  // This is supposed to be executed before all other APIs (even cs_open())
718
49.1k
  if (type == CS_OPT_MEM) {
719
0
    cs_opt_mem *mem = (cs_opt_mem *)value;
720
721
0
    cs_mem_malloc = mem->malloc;
722
0
    cs_mem_calloc = mem->calloc;
723
0
    cs_mem_realloc = mem->realloc;
724
0
    cs_mem_free = mem->free;
725
0
    cs_vsnprintf = mem->vsnprintf;
726
727
0
    return CS_ERR_OK;
728
0
  }
729
730
49.1k
  handle = (struct cs_struct *)(uintptr_t)ud;
731
49.1k
  if (!handle)
732
0
    return CS_ERR_CSH;
733
734
49.1k
  switch(type) {
735
10.6k
    default:
736
10.6k
      break;
737
738
10.6k
    case CS_OPT_UNSIGNED:
739
0
      handle->imm_unsigned = (cs_opt_value)value;
740
0
      return CS_ERR_OK;
741
742
38.4k
    case CS_OPT_DETAIL:
743
38.4k
      handle->detail = (cs_opt_value)value;
744
38.4k
      return CS_ERR_OK;
745
746
0
    case CS_OPT_SKIPDATA:
747
0
      handle->skipdata = (value == CS_OPT_ON);
748
0
      if (handle->skipdata) {
749
0
        if (handle->skipdata_size == 0) {
750
          // set the default skipdata size
751
0
          handle->skipdata_size = skipdata_size(handle);
752
0
        }
753
0
      }
754
0
      return CS_ERR_OK;
755
756
0
    case CS_OPT_SKIPDATA_SETUP:
757
0
      if (value) {
758
0
        handle->skipdata_setup = *((cs_opt_skipdata *)value);
759
0
        if (handle->skipdata_setup.mnemonic == NULL) {
760
0
          handle->skipdata_setup.mnemonic = SKIPDATA_MNEM;
761
0
        }
762
0
      }
763
0
      return CS_ERR_OK;
764
765
0
    case CS_OPT_MNEMONIC:
766
0
      opt = (cs_opt_mnem *)value;
767
0
      if (opt->id) {
768
0
        if (opt->mnemonic) {
769
0
          struct insn_mnem *tmp;
770
771
          // add new instruction, or replace existing instruction
772
          // 1. find if we already had this insn in the linked list
773
0
          tmp = handle->mnem_list;
774
0
          while(tmp) {
775
0
            if (tmp->insn.id == opt->id) {
776
              // found this instruction, so replace its mnemonic
777
0
              (void)strncpy(tmp->insn.mnemonic, opt->mnemonic, sizeof(tmp->insn.mnemonic) - 1);
778
0
              tmp->insn.mnemonic[sizeof(tmp->insn.mnemonic) - 1] = '\0';
779
0
              break;
780
0
            }
781
0
            tmp = tmp->next;
782
0
          }
783
784
          // 2. add this instruction if we have not had it yet
785
0
          if (!tmp) {
786
0
            tmp = cs_mem_malloc(sizeof(*tmp));
787
0
            if (!tmp) {
788
0
              return CS_ERR_MEM;
789
0
            }
790
0
            tmp->insn.id = opt->id;
791
0
            (void)strncpy(tmp->insn.mnemonic, opt->mnemonic, sizeof(tmp->insn.mnemonic) - 1);
792
0
            tmp->insn.mnemonic[sizeof(tmp->insn.mnemonic) - 1] = '\0';
793
            // this new instruction is heading the list
794
0
            tmp->next = handle->mnem_list;
795
0
            handle->mnem_list = tmp;
796
0
          }
797
0
          return CS_ERR_OK;
798
0
        } else {
799
0
          struct insn_mnem *prev, *tmp;
800
801
          // we want to delete an existing instruction
802
          // iterate the list to find the instruction to remove it
803
0
          tmp = handle->mnem_list;
804
0
          prev = tmp;
805
0
          while(tmp) {
806
0
            if (tmp->insn.id == opt->id) {
807
              // delete this instruction
808
0
              if (tmp == prev) {
809
                // head of the list
810
0
                handle->mnem_list = tmp->next;
811
0
              } else {
812
0
                prev->next = tmp->next;
813
0
              }
814
0
              cs_mem_free(tmp);
815
0
              break;
816
0
            }
817
0
            prev = tmp;
818
0
            tmp = tmp->next;
819
0
          }
820
0
        }
821
0
      }
822
0
      return CS_ERR_OK;
823
824
0
    case CS_OPT_MODE:
825
      // verify if requested mode is valid
826
0
      if (value & arch_configs[handle->arch].arch_disallowed_mode_mask) {
827
0
        return CS_ERR_OPTION;
828
0
      }
829
0
      break;
830
49.1k
  }
831
832
10.6k
  return arch_configs[handle->arch].arch_option(handle, type, value);
833
49.1k
}
834
835
// generate @op_str for data instruction of SKIPDATA
836
#ifndef CAPSTONE_DIET
837
static void skipdata_opstr(char *opstr, const uint8_t *buffer, size_t size)
838
0
{
839
0
  char *p = opstr;
840
0
  int len;
841
0
  size_t i;
842
0
  size_t available = sizeof(((cs_insn*)NULL)->op_str);
843
844
0
  if (!size) {
845
0
    opstr[0] = '\0';
846
0
    return;
847
0
  }
848
849
0
  len = cs_snprintf(p, available, "0x%02x", buffer[0]);
850
0
  p+= len;
851
0
  available -= len;
852
853
0
  for(i = 1; i < size; i++) {
854
0
    len = cs_snprintf(p, available, ", 0x%02x", buffer[i]);
855
0
    if (len < 0) {
856
0
      break;
857
0
    }
858
0
    if ((size_t)len > available - 1) {
859
0
      break;
860
0
    }
861
0
    p+= len;
862
0
    available -= len;
863
0
  }
864
0
}
865
#endif
866
867
// dynamicly allocate memory to contain disasm insn
868
// NOTE: caller must free() the allocated memory itself to avoid memory leaking
869
CAPSTONE_EXPORT
870
size_t CAPSTONE_API cs_disasm(csh ud, const uint8_t *buffer, size_t size, uint64_t offset, size_t count, cs_insn **insn)
871
38.4k
{
872
38.4k
  struct cs_struct *handle;
873
38.4k
  MCInst mci;
874
38.4k
  uint16_t insn_size;
875
38.4k
  size_t c = 0, i;
876
38.4k
  unsigned int f = 0; // index of the next instruction in the cache
877
38.4k
  cs_insn *insn_cache;  // cache contains disassembled instructions
878
38.4k
  void *total = NULL;
879
38.4k
  size_t total_size = 0;  // total size of output buffer containing all insns
880
38.4k
  bool r;
881
38.4k
  void *tmp;
882
38.4k
  size_t skipdata_bytes;
883
38.4k
  uint64_t offset_org; // save all the original info of the buffer
884
38.4k
  size_t size_org;
885
38.4k
  const uint8_t *buffer_org;
886
38.4k
  unsigned int cache_size = INSN_CACHE_SIZE;
887
38.4k
  size_t next_offset;
888
889
38.4k
  handle = (struct cs_struct *)(uintptr_t)ud;
890
38.4k
  if (!handle) {
891
    // FIXME: how to handle this case:
892
    // handle->errnum = CS_ERR_HANDLE;
893
0
    return 0;
894
0
  }
895
896
38.4k
  handle->errnum = CS_ERR_OK;
897
898
  // reset IT block of ARM structure
899
38.4k
  if (handle->arch == CS_ARCH_ARM)
900
7.05k
    handle->ITBlock.size = 0;
901
902
38.4k
#ifdef CAPSTONE_USE_SYS_DYN_MEM
903
38.4k
  if (count > 0 && count <= INSN_CACHE_SIZE)
904
0
    cache_size = (unsigned int) count;
905
38.4k
#endif
906
907
  // save the original offset for SKIPDATA
908
38.4k
  buffer_org = buffer;
909
38.4k
  offset_org = offset;
910
38.4k
  size_org = size;
911
912
38.4k
  total_size = sizeof(cs_insn) * cache_size;
913
38.4k
  total = cs_mem_calloc(sizeof(cs_insn), cache_size);
914
38.4k
  if (total == NULL) {
915
    // insufficient memory
916
0
    handle->errnum = CS_ERR_MEM;
917
0
    return 0;
918
0
  }
919
920
38.4k
  insn_cache = total;
921
922
2.59M
  while (size > 0) {
923
2.57M
    MCInst_Init(&mci);
924
2.57M
    mci.csh = handle;
925
926
    // relative branches need to know the address & size of current insn
927
2.57M
    mci.address = offset;
928
929
2.57M
    if (handle->detail) {
930
      // allocate memory for @detail pointer
931
2.57M
      insn_cache->detail = cs_mem_malloc(sizeof(cs_detail));
932
2.57M
      if (insn_cache->detail == NULL) {
933
        // insufficient memory
934
0
        handle->errnum = CS_ERR_MEM;
935
0
        break;
936
0
      }
937
2.57M
    } else {
938
0
      insn_cache->detail = NULL;
939
0
    }
940
941
    // save all the information for non-detailed mode
942
2.57M
    mci.flat_insn = insn_cache;
943
2.57M
    mci.flat_insn->address = offset;
944
#ifdef CAPSTONE_DIET
945
    // zero out mnemonic & op_str
946
    mci.flat_insn->mnemonic[0] = '\0';
947
    mci.flat_insn->op_str[0] = '\0';
948
#endif
949
950
2.57M
    r = handle->disasm(ud, buffer, size, &mci, &insn_size, offset, handle->getinsn_info);
951
2.57M
    if (r) {
952
2.55M
      SStream ss;
953
2.55M
      SStream_Init(&ss);
954
955
2.55M
      mci.flat_insn->size = insn_size;
956
957
      // map internal instruction opcode to public insn ID
958
959
2.55M
      handle->insn_id(handle, insn_cache, mci.Opcode);
960
961
2.55M
      handle->printer(&mci, &ss, handle->printer_info);
962
2.55M
      fill_insn(handle, insn_cache, ss.buffer, &mci, handle->post_printer, buffer);
963
964
      // adjust for pseudo opcode (X86)
965
2.55M
      if (handle->arch == CS_ARCH_X86 && insn_cache->id != X86_INS_VCMP)
966
643k
        insn_cache->id += mci.popcode_adjust;
967
968
2.55M
      next_offset = insn_size;
969
2.55M
    } else {
970
      // encounter a broken instruction
971
972
      // free memory of @detail pointer
973
20.3k
      if (handle->detail) {
974
20.3k
        cs_mem_free(insn_cache->detail);
975
20.3k
      }
976
977
      // if there is no request to skip data, or remaining data is too small,
978
      // then bail out
979
20.3k
      if (!handle->skipdata || handle->skipdata_size > size)
980
20.3k
        break;
981
982
0
      if (handle->skipdata_setup.callback) {
983
0
        skipdata_bytes = handle->skipdata_setup.callback(buffer_org, size_org,
984
0
            (size_t)(offset - offset_org), handle->skipdata_setup.user_data);
985
0
        if (skipdata_bytes > size)
986
          // remaining data is not enough
987
0
          break;
988
989
0
        if (!skipdata_bytes)
990
          // user requested not to skip data, so bail out
991
0
          break;
992
0
      } else
993
0
        skipdata_bytes = handle->skipdata_size;
994
995
      // we have to skip some amount of data, depending on arch & mode
996
      // invalid ID for this "data" instruction
997
0
      insn_cache->id = 0;
998
0
      insn_cache->address = offset;
999
0
      insn_cache->size = (uint16_t)MIN(
1000
0
        skipdata_bytes, sizeof(insn_cache->bytes));
1001
0
      memcpy(insn_cache->bytes, buffer,
1002
0
             MIN(skipdata_bytes, sizeof(insn_cache->bytes)));
1003
#ifdef CAPSTONE_DIET
1004
      insn_cache->mnemonic[0] = '\0';
1005
      insn_cache->op_str[0] = '\0';
1006
#else
1007
0
      strncpy(insn_cache->mnemonic, handle->skipdata_setup.mnemonic,
1008
0
          sizeof(insn_cache->mnemonic) - 1);
1009
0
      skipdata_opstr(insn_cache->op_str, buffer, skipdata_bytes);
1010
0
#endif
1011
0
      insn_cache->detail = NULL;
1012
1013
0
      next_offset = skipdata_bytes;
1014
0
    }
1015
1016
    // one more instruction entering the cache
1017
2.55M
    f++;
1018
1019
    // one more instruction disassembled
1020
2.55M
    c++;
1021
2.55M
    if (count > 0 && c == count)
1022
      // already got requested number of instructions
1023
0
      break;
1024
1025
2.55M
    if (f == cache_size) {
1026
      // full cache, so expand the cache to contain incoming insns
1027
26.0k
      cache_size = cache_size * 8 / 5; // * 1.6 ~ golden ratio
1028
26.0k
      total_size += (sizeof(cs_insn) * cache_size);
1029
26.0k
      tmp = cs_mem_realloc(total, total_size);
1030
26.0k
      if (tmp == NULL) { // insufficient memory
1031
0
        if (handle->detail) {
1032
0
          insn_cache = (cs_insn *)total;
1033
0
          for (i = 0; i < c; i++, insn_cache++)
1034
0
            cs_mem_free(insn_cache->detail);
1035
0
        }
1036
1037
0
        cs_mem_free(total);
1038
0
        *insn = NULL;
1039
0
        handle->errnum = CS_ERR_MEM;
1040
0
        return 0;
1041
0
      }
1042
1043
26.0k
      total = tmp;
1044
      // continue to fill in the cache after the last instruction
1045
26.0k
      insn_cache = (cs_insn *)((char *)total + sizeof(cs_insn) * c);
1046
1047
      // reset f back to 0, so we fill in the cache from begining
1048
26.0k
      f = 0;
1049
26.0k
    } else
1050
2.53M
      insn_cache++;
1051
1052
2.55M
    buffer += next_offset;
1053
2.55M
    size -= next_offset;
1054
2.55M
    offset += next_offset;
1055
2.55M
  }
1056
1057
38.4k
  if (!c) {
1058
    // we did not disassemble any instruction
1059
837
    cs_mem_free(total);
1060
837
    total = NULL;
1061
37.5k
  } else if (f != cache_size) {
1062
    // total did not fully use the last cache, so downsize it
1063
37.5k
    tmp = cs_mem_realloc(total, total_size - (cache_size - f) * sizeof(*insn_cache));
1064
37.5k
    if (tmp == NULL) { // insufficient memory
1065
      // free all detail pointers
1066
0
      if (handle->detail) {
1067
0
        insn_cache = (cs_insn *)total;
1068
0
        for (i = 0; i < c; i++, insn_cache++)
1069
0
          cs_mem_free(insn_cache->detail);
1070
0
      }
1071
1072
0
      cs_mem_free(total);
1073
0
      *insn = NULL;
1074
1075
0
      handle->errnum = CS_ERR_MEM;
1076
0
      return 0;
1077
0
    }
1078
1079
37.5k
    total = tmp;
1080
37.5k
  }
1081
1082
38.4k
  *insn = total;
1083
1084
38.4k
  return c;
1085
38.4k
}
1086
1087
CAPSTONE_EXPORT
1088
void CAPSTONE_API cs_free(cs_insn *insn, size_t count)
1089
37.5k
{
1090
37.5k
  size_t i;
1091
1092
  // free all detail pointers
1093
2.59M
  for (i = 0; i < count; i++)
1094
2.55M
    cs_mem_free(insn[i].detail);
1095
1096
  // then free pointer to cs_insn array
1097
37.5k
  cs_mem_free(insn);
1098
37.5k
}
1099
1100
CAPSTONE_EXPORT
1101
cs_insn * CAPSTONE_API cs_malloc(csh ud)
1102
0
{
1103
0
  cs_insn *insn;
1104
0
  struct cs_struct *handle = (struct cs_struct *)(uintptr_t)ud;
1105
1106
0
  insn = cs_mem_malloc(sizeof(cs_insn));
1107
0
  if (!insn) {
1108
    // insufficient memory
1109
0
    handle->errnum = CS_ERR_MEM;
1110
0
    return NULL;
1111
0
  } else {
1112
0
    if (handle->detail) {
1113
      // allocate memory for @detail pointer
1114
0
      insn->detail = cs_mem_malloc(sizeof(cs_detail));
1115
0
      if (insn->detail == NULL) { // insufficient memory
1116
0
        cs_mem_free(insn);
1117
0
        handle->errnum = CS_ERR_MEM;
1118
0
        return NULL;
1119
0
      }
1120
0
    } else
1121
0
      insn->detail = NULL;
1122
0
  }
1123
1124
0
  return insn;
1125
0
}
1126
1127
// iterator for instruction "single-stepping"
1128
CAPSTONE_EXPORT
1129
bool CAPSTONE_API cs_disasm_iter(csh ud, const uint8_t **code, size_t *size,
1130
    uint64_t *address, cs_insn *insn)
1131
0
{
1132
0
  if (*size == 0)
1133
0
    return false;
1134
1135
0
  struct cs_struct *handle;
1136
0
  uint16_t insn_size;
1137
0
  MCInst mci;
1138
0
  bool r;
1139
1140
0
  handle = (struct cs_struct *)(uintptr_t)ud;
1141
0
  if (!handle) {
1142
0
    return false;
1143
0
  }
1144
1145
0
  handle->errnum = CS_ERR_OK;
1146
1147
0
  MCInst_Init(&mci);
1148
0
  mci.csh = handle;
1149
1150
  // relative branches need to know the address & size of current insn
1151
0
  mci.address = *address;
1152
1153
  // save all the information for non-detailed mode
1154
0
  mci.flat_insn = insn;
1155
0
  mci.flat_insn->address = *address;
1156
#ifdef CAPSTONE_DIET
1157
  // zero out mnemonic & op_str
1158
  mci.flat_insn->mnemonic[0] = '\0';
1159
  mci.flat_insn->op_str[0] = '\0';
1160
#endif
1161
1162
0
  r = handle->disasm(ud, *code, *size, &mci, &insn_size, *address, handle->getinsn_info);
1163
0
  if (r) {
1164
0
    SStream ss;
1165
0
    SStream_Init(&ss);
1166
1167
0
    mci.flat_insn->size = insn_size;
1168
1169
    // map internal instruction opcode to public insn ID
1170
0
    handle->insn_id(handle, insn, mci.Opcode);
1171
1172
0
    handle->printer(&mci, &ss, handle->printer_info);
1173
1174
0
    fill_insn(handle, insn, ss.buffer, &mci, handle->post_printer, *code);
1175
1176
    // adjust for pseudo opcode (X86)
1177
0
    if (handle->arch == CS_ARCH_X86)
1178
0
      insn->id += mci.popcode_adjust;
1179
1180
0
    *code += insn_size;
1181
0
    *size -= insn_size;
1182
0
    *address += insn_size;
1183
0
  } else {   // encounter a broken instruction
1184
0
    size_t skipdata_bytes;
1185
1186
    // if there is no request to skip data, or remaining data is too small,
1187
    // then bail out
1188
0
    if (!handle->skipdata || handle->skipdata_size > *size)
1189
0
      return false;
1190
1191
0
    if (handle->skipdata_setup.callback) {
1192
0
      skipdata_bytes = handle->skipdata_setup.callback(*code, *size,
1193
0
          0, handle->skipdata_setup.user_data);
1194
0
      if (skipdata_bytes > *size)
1195
        // remaining data is not enough
1196
0
        return false;
1197
1198
0
      if (!skipdata_bytes)
1199
        // user requested not to skip data, so bail out
1200
0
        return false;
1201
0
    } else
1202
0
      skipdata_bytes = handle->skipdata_size;
1203
1204
    // we have to skip some amount of data, depending on arch & mode
1205
0
    insn->id = 0; // invalid ID for this "data" instruction
1206
0
    insn->address = *address;
1207
0
    insn->size = (uint16_t)MIN(skipdata_bytes, sizeof(insn->bytes));
1208
0
    memcpy(insn->bytes, *code,
1209
0
           MIN(skipdata_bytes, sizeof(insn->bytes)));
1210
#ifdef CAPSTONE_DIET
1211
    insn->mnemonic[0] = '\0';
1212
    insn->op_str[0] = '\0';
1213
#else
1214
0
    strncpy(insn->mnemonic, handle->skipdata_setup.mnemonic,
1215
0
        sizeof(insn->mnemonic) - 1);
1216
0
    skipdata_opstr(insn->op_str, *code, skipdata_bytes);
1217
0
#endif
1218
1219
0
    *code += skipdata_bytes;
1220
0
    *size -= skipdata_bytes;
1221
0
    *address += skipdata_bytes;
1222
0
  }
1223
1224
0
  return true;
1225
0
}
1226
1227
// return friendly name of register in a string
1228
CAPSTONE_EXPORT
1229
const char * CAPSTONE_API cs_reg_name(csh ud, unsigned int reg)
1230
1.98M
{
1231
1.98M
  struct cs_struct *handle = (struct cs_struct *)(uintptr_t)ud;
1232
1233
1.98M
  if (!handle || handle->reg_name == NULL) {
1234
0
    return NULL;
1235
0
  }
1236
1237
1.98M
  return handle->reg_name(ud, reg);
1238
1.98M
}
1239
1240
CAPSTONE_EXPORT
1241
const char * CAPSTONE_API cs_insn_name(csh ud, unsigned int insn)
1242
2.55M
{
1243
2.55M
  struct cs_struct *handle = (struct cs_struct *)(uintptr_t)ud;
1244
1245
2.55M
  if (!handle || handle->insn_name == NULL) {
1246
0
    return NULL;
1247
0
  }
1248
1249
2.55M
  return handle->insn_name(ud, insn);
1250
2.55M
}
1251
1252
CAPSTONE_EXPORT
1253
const char * CAPSTONE_API cs_group_name(csh ud, unsigned int group)
1254
2.06M
{
1255
2.06M
  struct cs_struct *handle = (struct cs_struct *)(uintptr_t)ud;
1256
1257
2.06M
  if (!handle || handle->group_name == NULL) {
1258
0
    return NULL;
1259
0
  }
1260
1261
2.06M
  return handle->group_name(ud, group);
1262
2.06M
}
1263
1264
CAPSTONE_EXPORT
1265
bool CAPSTONE_API cs_insn_group(csh ud, const cs_insn *insn, unsigned int group_id)
1266
0
{
1267
0
  struct cs_struct *handle;
1268
0
  if (!ud)
1269
0
    return false;
1270
1271
0
  handle = (struct cs_struct *)(uintptr_t)ud;
1272
1273
0
  if (!handle->detail) {
1274
0
    handle->errnum = CS_ERR_DETAIL;
1275
0
    return false;
1276
0
  }
1277
1278
0
  if (!insn->id) {
1279
0
    handle->errnum = CS_ERR_SKIPDATA;
1280
0
    return false;
1281
0
  }
1282
1283
0
  if (!insn->detail) {
1284
0
    handle->errnum = CS_ERR_DETAIL;
1285
0
    return false;
1286
0
  }
1287
1288
0
  return arr_exist8(insn->detail->groups, insn->detail->groups_count, group_id);
1289
0
}
1290
1291
CAPSTONE_EXPORT
1292
bool CAPSTONE_API cs_reg_read(csh ud, const cs_insn *insn, unsigned int reg_id)
1293
0
{
1294
0
  struct cs_struct *handle;
1295
0
  if (!ud)
1296
0
    return false;
1297
1298
0
  handle = (struct cs_struct *)(uintptr_t)ud;
1299
1300
0
  if (!handle->detail) {
1301
0
    handle->errnum = CS_ERR_DETAIL;
1302
0
    return false;
1303
0
  }
1304
1305
0
  if (!insn->id) {
1306
0
    handle->errnum = CS_ERR_SKIPDATA;
1307
0
    return false;
1308
0
  }
1309
1310
0
  if (!insn->detail) {
1311
0
    handle->errnum = CS_ERR_DETAIL;
1312
0
    return false;
1313
0
  }
1314
1315
0
  return arr_exist(insn->detail->regs_read, insn->detail->regs_read_count, reg_id);
1316
0
}
1317
1318
CAPSTONE_EXPORT
1319
bool CAPSTONE_API cs_reg_write(csh ud, const cs_insn *insn, unsigned int reg_id)
1320
1.01M
{
1321
1.01M
  struct cs_struct *handle;
1322
1.01M
  if (!ud)
1323
0
    return false;
1324
1325
1.01M
  handle = (struct cs_struct *)(uintptr_t)ud;
1326
1327
1.01M
  if (!handle->detail) {
1328
0
    handle->errnum = CS_ERR_DETAIL;
1329
0
    return false;
1330
0
  }
1331
1332
1.01M
  if (!insn->id) {
1333
0
    handle->errnum = CS_ERR_SKIPDATA;
1334
0
    return false;
1335
0
  }
1336
1337
1.01M
  if (!insn->detail) {
1338
0
    handle->errnum = CS_ERR_DETAIL;
1339
0
    return false;
1340
0
  }
1341
1342
1.01M
  return arr_exist(insn->detail->regs_write, insn->detail->regs_write_count, reg_id);
1343
1.01M
}
1344
1345
CAPSTONE_EXPORT
1346
int CAPSTONE_API cs_op_count(csh ud, const cs_insn *insn, unsigned int op_type)
1347
0
{
1348
0
  struct cs_struct *handle;
1349
0
  unsigned int count = 0, i;
1350
0
  if (!ud)
1351
0
    return -1;
1352
1353
0
  handle = (struct cs_struct *)(uintptr_t)ud;
1354
1355
0
  if (!handle->detail) {
1356
0
    handle->errnum = CS_ERR_DETAIL;
1357
0
    return -1;
1358
0
  }
1359
1360
0
  if (!insn->id) {
1361
0
    handle->errnum = CS_ERR_SKIPDATA;
1362
0
    return -1;
1363
0
  }
1364
1365
0
  if (!insn->detail) {
1366
0
    handle->errnum = CS_ERR_DETAIL;
1367
0
    return -1;
1368
0
  }
1369
1370
0
  handle->errnum = CS_ERR_OK;
1371
1372
0
  switch (handle->arch) {
1373
0
    default:
1374
0
      handle->errnum = CS_ERR_HANDLE;
1375
0
      return -1;
1376
0
    case CS_ARCH_ARM:
1377
0
      for (i = 0; i < insn->detail->arm.op_count; i++)
1378
0
        if (insn->detail->arm.operands[i].type == (arm_op_type)op_type)
1379
0
          count++;
1380
0
      break;
1381
0
    case CS_ARCH_ARM64:
1382
0
      for (i = 0; i < insn->detail->arm64.op_count; i++)
1383
0
        if (insn->detail->arm64.operands[i].type == (arm64_op_type)op_type)
1384
0
          count++;
1385
0
      break;
1386
0
    case CS_ARCH_X86:
1387
0
      for (i = 0; i < insn->detail->x86.op_count; i++)
1388
0
        if (insn->detail->x86.operands[i].type == (x86_op_type)op_type)
1389
0
          count++;
1390
0
      break;
1391
0
    case CS_ARCH_MIPS:
1392
0
      for (i = 0; i < insn->detail->mips.op_count; i++)
1393
0
        if (insn->detail->mips.operands[i].type == (mips_op_type)op_type)
1394
0
          count++;
1395
0
      break;
1396
0
    case CS_ARCH_PPC:
1397
0
      for (i = 0; i < insn->detail->ppc.op_count; i++)
1398
0
        if (insn->detail->ppc.operands[i].type == (ppc_op_type)op_type)
1399
0
          count++;
1400
0
      break;
1401
0
    case CS_ARCH_SPARC:
1402
0
      for (i = 0; i < insn->detail->sparc.op_count; i++)
1403
0
        if (insn->detail->sparc.operands[i].type == (sparc_op_type)op_type)
1404
0
          count++;
1405
0
      break;
1406
0
    case CS_ARCH_SYSZ:
1407
0
      for (i = 0; i < insn->detail->sysz.op_count; i++)
1408
0
        if (insn->detail->sysz.operands[i].type == (sysz_op_type)op_type)
1409
0
          count++;
1410
0
      break;
1411
0
    case CS_ARCH_XCORE:
1412
0
      for (i = 0; i < insn->detail->xcore.op_count; i++)
1413
0
        if (insn->detail->xcore.operands[i].type == (xcore_op_type)op_type)
1414
0
          count++;
1415
0
      break;
1416
0
    case CS_ARCH_M68K:
1417
0
      for (i = 0; i < insn->detail->m68k.op_count; i++)
1418
0
        if (insn->detail->m68k.operands[i].type == (m68k_op_type)op_type)
1419
0
          count++;
1420
0
      break;
1421
0
    case CS_ARCH_TMS320C64X:
1422
0
      for (i = 0; i < insn->detail->tms320c64x.op_count; i++)
1423
0
        if (insn->detail->tms320c64x.operands[i].type == (tms320c64x_op_type)op_type)
1424
0
          count++;
1425
0
      break;
1426
0
    case CS_ARCH_M680X:
1427
0
      for (i = 0; i < insn->detail->m680x.op_count; i++)
1428
0
        if (insn->detail->m680x.operands[i].type == (m680x_op_type)op_type)
1429
0
          count++;
1430
0
      break;
1431
0
    case CS_ARCH_EVM:
1432
0
      break;
1433
0
    case CS_ARCH_MOS65XX:
1434
0
      for (i = 0; i < insn->detail->mos65xx.op_count; i++)
1435
0
        if (insn->detail->mos65xx.operands[i].type == (mos65xx_op_type)op_type)
1436
0
          count++;
1437
0
      break;
1438
0
    case CS_ARCH_WASM:
1439
0
      for (i = 0; i < insn->detail->wasm.op_count; i++)
1440
0
        if (insn->detail->wasm.operands[i].type == (wasm_op_type)op_type)
1441
0
          count++;
1442
0
      break;
1443
0
    case CS_ARCH_BPF:
1444
0
      for (i = 0; i < insn->detail->bpf.op_count; i++)
1445
0
        if (insn->detail->bpf.operands[i].type == (bpf_op_type)op_type)
1446
0
          count++;
1447
0
      break;
1448
0
    case CS_ARCH_RISCV:
1449
0
      for (i = 0; i < insn->detail->riscv.op_count; i++)
1450
0
        if (insn->detail->riscv.operands[i].type == (riscv_op_type)op_type)
1451
0
          count++;
1452
0
      break;
1453
0
    case CS_ARCH_TRICORE:
1454
0
      for (i = 0; i < insn->detail->tricore.op_count; i++)
1455
0
        if (insn->detail->tricore.operands[i].type == (tricore_op_type)op_type)
1456
0
          count++;
1457
0
      break;
1458
0
  }
1459
1460
0
  return count;
1461
0
}
1462
1463
CAPSTONE_EXPORT
1464
int CAPSTONE_API cs_op_index(csh ud, const cs_insn *insn, unsigned int op_type,
1465
    unsigned int post)
1466
0
{
1467
0
  struct cs_struct *handle;
1468
0
  unsigned int count = 0, i;
1469
0
  if (!ud)
1470
0
    return -1;
1471
1472
0
  handle = (struct cs_struct *)(uintptr_t)ud;
1473
1474
0
  if (!handle->detail) {
1475
0
    handle->errnum = CS_ERR_DETAIL;
1476
0
    return -1;
1477
0
  }
1478
1479
0
  if (!insn->id) {
1480
0
    handle->errnum = CS_ERR_SKIPDATA;
1481
0
    return -1;
1482
0
  }
1483
1484
0
  if (!insn->detail) {
1485
0
    handle->errnum = CS_ERR_DETAIL;
1486
0
    return -1;
1487
0
  }
1488
1489
0
  handle->errnum = CS_ERR_OK;
1490
1491
0
  switch (handle->arch) {
1492
0
    default:
1493
0
      handle->errnum = CS_ERR_HANDLE;
1494
0
      return -1;
1495
0
    case CS_ARCH_ARM:
1496
0
      for (i = 0; i < insn->detail->arm.op_count; i++) {
1497
0
        if (insn->detail->arm.operands[i].type == (arm_op_type)op_type)
1498
0
          count++;
1499
0
        if (count == post)
1500
0
          return i;
1501
0
      }
1502
0
      break;
1503
0
    case CS_ARCH_ARM64:
1504
0
      for (i = 0; i < insn->detail->arm64.op_count; i++) {
1505
0
        if (insn->detail->arm64.operands[i].type == (arm64_op_type)op_type)
1506
0
          count++;
1507
0
        if (count == post)
1508
0
          return i;
1509
0
      }
1510
0
      break;
1511
0
    case CS_ARCH_X86:
1512
0
      for (i = 0; i < insn->detail->x86.op_count; i++) {
1513
0
        if (insn->detail->x86.operands[i].type == (x86_op_type)op_type)
1514
0
          count++;
1515
0
        if (count == post)
1516
0
          return i;
1517
0
      }
1518
0
      break;
1519
0
    case CS_ARCH_MIPS:
1520
0
      for (i = 0; i < insn->detail->mips.op_count; i++) {
1521
0
        if (insn->detail->mips.operands[i].type == (mips_op_type)op_type)
1522
0
          count++;
1523
0
        if (count == post)
1524
0
          return i;
1525
0
      }
1526
0
      break;
1527
0
    case CS_ARCH_PPC:
1528
0
      for (i = 0; i < insn->detail->ppc.op_count; i++) {
1529
0
        if (insn->detail->ppc.operands[i].type == (ppc_op_type)op_type)
1530
0
          count++;
1531
0
        if (count == post)
1532
0
          return i;
1533
0
      }
1534
0
      break;
1535
0
    case CS_ARCH_SPARC:
1536
0
      for (i = 0; i < insn->detail->sparc.op_count; i++) {
1537
0
        if (insn->detail->sparc.operands[i].type == (sparc_op_type)op_type)
1538
0
          count++;
1539
0
        if (count == post)
1540
0
          return i;
1541
0
      }
1542
0
      break;
1543
0
    case CS_ARCH_SYSZ:
1544
0
      for (i = 0; i < insn->detail->sysz.op_count; i++) {
1545
0
        if (insn->detail->sysz.operands[i].type == (sysz_op_type)op_type)
1546
0
          count++;
1547
0
        if (count == post)
1548
0
          return i;
1549
0
      }
1550
0
      break;
1551
0
    case CS_ARCH_XCORE:
1552
0
      for (i = 0; i < insn->detail->xcore.op_count; i++) {
1553
0
        if (insn->detail->xcore.operands[i].type == (xcore_op_type)op_type)
1554
0
          count++;
1555
0
        if (count == post)
1556
0
          return i;
1557
0
      }
1558
0
      break;
1559
0
    case CS_ARCH_TRICORE:
1560
0
      for (i = 0; i < insn->detail->tricore.op_count; i++) {
1561
0
        if (insn->detail->tricore.operands[i].type == (tricore_op_type)op_type)
1562
0
          count++;
1563
0
        if (count == post)
1564
0
          return i;
1565
0
      }
1566
0
      break;
1567
0
    case CS_ARCH_M68K:
1568
0
      for (i = 0; i < insn->detail->m68k.op_count; i++) {
1569
0
        if (insn->detail->m68k.operands[i].type == (m68k_op_type)op_type)
1570
0
          count++;
1571
0
        if (count == post)
1572
0
          return i;
1573
0
      }
1574
0
      break;
1575
0
    case CS_ARCH_TMS320C64X:
1576
0
      for (i = 0; i < insn->detail->tms320c64x.op_count; i++) {
1577
0
        if (insn->detail->tms320c64x.operands[i].type == (tms320c64x_op_type)op_type)
1578
0
          count++;
1579
0
        if (count == post)
1580
0
          return i;
1581
0
      }
1582
0
      break;
1583
0
    case CS_ARCH_M680X:
1584
0
      for (i = 0; i < insn->detail->m680x.op_count; i++) {
1585
0
        if (insn->detail->m680x.operands[i].type == (m680x_op_type)op_type)
1586
0
          count++;
1587
0
        if (count == post)
1588
0
          return i;
1589
0
      }
1590
0
      break;
1591
0
    case CS_ARCH_EVM:
1592
#if 0
1593
      for (i = 0; i < insn->detail->evm.op_count; i++) {
1594
        if (insn->detail->evm.operands[i].type == (evm_op_type)op_type)
1595
          count++;
1596
        if (count == post)
1597
          return i;
1598
      }
1599
#endif
1600
0
      break;
1601
0
    case CS_ARCH_MOS65XX:
1602
0
      for (i = 0; i < insn->detail->mos65xx.op_count; i++) {
1603
0
        if (insn->detail->mos65xx.operands[i].type == (mos65xx_op_type)op_type)
1604
0
          count++;
1605
0
        if (count == post)
1606
0
          return i;
1607
0
      }
1608
0
      break;
1609
0
    case CS_ARCH_WASM:
1610
0
      for (i = 0; i < insn->detail->wasm.op_count; i++) {
1611
0
        if (insn->detail->wasm.operands[i].type == (wasm_op_type)op_type)
1612
0
          count++;
1613
0
        if (count == post)
1614
0
          return i;
1615
0
      }
1616
0
      break;
1617
0
    case CS_ARCH_BPF:
1618
0
      for (i = 0; i < insn->detail->bpf.op_count; i++) {
1619
0
        if (insn->detail->bpf.operands[i].type == (bpf_op_type)op_type)
1620
0
          count++;
1621
0
        if (count == post)
1622
0
          return i;
1623
0
      }
1624
0
      break;
1625
0
    case CS_ARCH_RISCV:
1626
0
      for (i = 0; i < insn->detail->riscv.op_count; i++) {
1627
0
        if (insn->detail->riscv.operands[i].type == (riscv_op_type)op_type)
1628
0
          count++;
1629
0
        if (count == post)
1630
0
          return i;
1631
0
      }
1632
0
      break;
1633
0
    case CS_ARCH_SH:
1634
0
      for (i = 0; i < insn->detail->sh.op_count; i++) {
1635
0
        if (insn->detail->sh.operands[i].type == (sh_op_type)op_type)
1636
0
          count++;
1637
0
        if (count == post)
1638
0
          return i;
1639
0
      }
1640
0
      break;
1641
0
  }
1642
1643
0
  return -1;
1644
0
}
1645
1646
CAPSTONE_EXPORT
1647
cs_err CAPSTONE_API cs_regs_access(csh ud, const cs_insn *insn,
1648
    cs_regs regs_read, uint8_t *regs_read_count,
1649
    cs_regs regs_write, uint8_t *regs_write_count)
1650
0
{
1651
0
  struct cs_struct *handle;
1652
1653
0
  if (!ud)
1654
0
    return -1;
1655
1656
0
  handle = (struct cs_struct *)(uintptr_t)ud;
1657
1658
#ifdef CAPSTONE_DIET
1659
  // This API does not work in DIET mode
1660
  handle->errnum = CS_ERR_DIET;
1661
  return CS_ERR_DIET;
1662
#else
1663
0
  if (!handle->detail) {
1664
0
    handle->errnum = CS_ERR_DETAIL;
1665
0
    return CS_ERR_DETAIL;
1666
0
  }
1667
1668
0
  if (!insn->id) {
1669
0
    handle->errnum = CS_ERR_SKIPDATA;
1670
0
    return CS_ERR_SKIPDATA;
1671
0
  }
1672
1673
0
  if (!insn->detail) {
1674
0
    handle->errnum = CS_ERR_DETAIL;
1675
0
    return CS_ERR_DETAIL;
1676
0
  }
1677
1678
0
  if (handle->reg_access) {
1679
0
    handle->reg_access(insn, regs_read, regs_read_count, regs_write, regs_write_count);
1680
0
  } else {
1681
    // this arch is unsupported yet
1682
0
    handle->errnum = CS_ERR_ARCH;
1683
0
    return CS_ERR_ARCH;
1684
0
  }
1685
1686
0
  return CS_ERR_OK;
1687
0
#endif
1688
0
}