Coverage Report

Created: 2026-08-31 06:58

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/capstonenext/Mapping.c
Line
Count
Source
1
/* Capstone Disassembly Engine */
2
/* By Nguyen Anh Quynh <aquynh@gmail.com>, 2013-2019 */
3
/*    Rot127 <unisono@quyllur.org>, 2022-2023 */
4
5
#include "Mapping.h"
6
#include "capstone/capstone.h"
7
#include "cs_priv.h"
8
#include "utils.h"
9
10
// Create a cache to map LLVM instruction IDs to capstone instruction IDs, if
11
// the architecture needs this.
12
cs_err populate_insn_map_cache(cs_struct *handle)
13
56.4k
{
14
56.4k
  unsigned int i;
15
16
  // If this architecture doesn't use instruction mapping, do nothing
17
56.4k
  if (!handle->insn_map || handle->insn_map_size <= 0)
18
52.9k
    return CS_ERR_OK;
19
20
  // Since the instruction map is assumed to be stored in ascending
21
  // order, we can get the maximum LLVM instruction id just by looking at
22
  // the last element.
23
3.51k
  unsigned int cache_elements =
24
3.51k
    handle->insn_map[handle->insn_map_size - 1].id + 1;
25
26
  // This should not be initialized yet.
27
3.51k
  CS_ASSERT(!handle->insn_cache);
28
29
3.51k
  unsigned short *cache = cs_mem_calloc(cache_elements, sizeof(*cache));
30
3.51k
  if (!cache) {
31
0
    handle->errnum = CS_ERR_MEM;
32
0
    return CS_ERR_MEM;
33
0
  }
34
3.51k
  handle->insn_cache = cache;
35
36
21.8M
  for (i = 1; i < handle->insn_map_size; ++i)
37
21.8M
    handle->insn_cache[handle->insn_map[i].id] = i;
38
39
3.51k
  return CS_ERR_OK;
40
3.51k
}
41
42
const insn_map *lookup_insn_map(cs_struct *handle, unsigned short id)
43
160k
{
44
  // If this is getting called, we need the cache to already be populated
45
  // (this should be done when populate_insn_map_cache() gets called).
46
160k
  CS_ASSERT(handle->insn_cache);
47
160k
  CS_ASSERT(handle->insn_map_size);
48
49
160k
  unsigned short highest_id =
50
160k
    handle->insn_map[handle->insn_map_size - 1].id;
51
160k
  if (id > highest_id)
52
0
    return NULL;
53
54
160k
  unsigned short i = handle->insn_cache[id];
55
56
160k
  return &handle->insn_map[i];
57
160k
}
58
59
// Gives the id for the given @name if it is saved in @map.
60
// Returns the id or -1 if not found.
61
int name2id(const name_map *map, int max, const char *name)
62
104k
{
63
104k
  CS_ASSERT_RET_VAL(map && name, -1);
64
104k
  int i;
65
66
12.2M
  for (i = 0; i < max; i++) {
67
12.2M
    if (!map[i].name) {
68
4.33k
      return -1;
69
4.33k
    }
70
12.2M
    if (!strcmp(map[i].name, name)) {
71
95.9k
      return map[i].id;
72
95.9k
    }
73
12.2M
  }
74
75
  // nothing match
76
4.11k
  return -1;
77
104k
}
78
79
// Gives the name for the given @id if it is saved in @map.
80
// Returns the name or NULL if not found.
81
const char *id2name(const name_map *map, int max, const unsigned int id)
82
3.65M
{
83
3.65M
  int i;
84
85
148M
  for (i = 0; i < max; i++) {
86
148M
    if (map[i].id == id) {
87
3.64M
      return map[i].name;
88
3.64M
    }
89
148M
  }
90
91
  // nothing match
92
13.6k
  return NULL;
93
3.65M
}
94
95
/// Adds a register to the implicit write register list.
96
/// It will not add the same register twice.
97
void map_add_implicit_write(MCInst *MI, uint32_t Reg)
98
528k
{
99
528k
  if (!MI->flat_insn->detail)
100
0
    return;
101
102
528k
  uint16_t *regs_write = MI->flat_insn->detail->regs_write;
103
532k
  for (int i = 0; i < MAX_IMPL_W_REGS; ++i) {
104
532k
    if (i == MI->flat_insn->detail->regs_write_count) {
105
503k
      regs_write[i] = Reg;
106
503k
      MI->flat_insn->detail->regs_write_count++;
107
503k
      return;
108
503k
    }
109
28.5k
    if (regs_write[i] == Reg)
110
24.8k
      return;
111
28.5k
  }
112
528k
}
113
114
/// Adds a register to the implicit read register list.
115
/// It will not add the same register twice.
116
void map_add_implicit_read(MCInst *MI, uint32_t Reg)
117
234k
{
118
234k
  if (!MI->flat_insn->detail)
119
0
    return;
120
121
234k
  uint16_t *regs_read = MI->flat_insn->detail->regs_read;
122
247k
  for (int i = 0; i < MAX_IMPL_R_REGS; ++i) {
123
247k
    if (i == MI->flat_insn->detail->regs_read_count) {
124
212k
      regs_read[i] = Reg;
125
212k
      MI->flat_insn->detail->regs_read_count++;
126
212k
      return;
127
212k
    }
128
35.0k
    if (regs_read[i] == Reg)
129
21.5k
      return;
130
35.0k
  }
131
234k
}
132
133
/// Removes a register from the implicit write register list.
134
void map_remove_implicit_write(MCInst *MI, uint32_t Reg)
135
39.5k
{
136
39.5k
  if (!MI->flat_insn->detail)
137
0
    return;
138
139
39.5k
  uint16_t *regs_write = MI->flat_insn->detail->regs_write;
140
39.5k
  bool shorten_list = false;
141
43.8k
  for (int i = 0; i < MAX_IMPL_W_REGS; ++i) {
142
43.8k
    if (shorten_list) {
143
4.35k
      regs_write[i - 1] = regs_write[i];
144
4.35k
    }
145
43.8k
    if (i >= MI->flat_insn->detail->regs_write_count)
146
39.5k
      return;
147
148
4.35k
    if (regs_write[i] == Reg) {
149
4.35k
      MI->flat_insn->detail->regs_write_count--;
150
      // The register should exist only once in the list.
151
4.35k
      CS_ASSERT_RET(!shorten_list);
152
4.35k
      shorten_list = true;
153
4.35k
    }
154
4.35k
  }
155
39.5k
}
156
157
/// Copies the implicit read registers of @imap to @MI->flat_insn.
158
/// Already present registers will be preserved.
159
void map_implicit_reads(MCInst *MI, const insn_map *imap)
160
2.29M
{
161
2.29M
#ifndef CAPSTONE_DIET
162
2.29M
  if (!MI->flat_insn->detail)
163
0
    return;
164
165
2.29M
  cs_detail *detail = MI->flat_insn->detail;
166
2.29M
  unsigned Opcode = MCInst_getOpcode(MI);
167
2.29M
  unsigned i = 0;
168
2.29M
  uint16_t reg = imap[Opcode].regs_use[i];
169
2.45M
  while (reg != 0) {
170
156k
    if (i >= MAX_IMPL_R_REGS ||
171
156k
        detail->regs_read_count >= MAX_IMPL_R_REGS) {
172
0
      printf("ERROR: Too many implicit read register defined in "
173
0
             "instruction mapping.\n");
174
0
      return;
175
0
    }
176
156k
    detail->regs_read[detail->regs_read_count++] = reg;
177
156k
    if (i + 1 < MAX_IMPL_R_REGS) {
178
      // Select next one
179
156k
      reg = imap[Opcode].regs_use[++i];
180
156k
    }
181
156k
  }
182
2.29M
#endif // CAPSTONE_DIET
183
2.29M
}
184
185
/// Copies the implicit write registers of @imap to @MI->flat_insn.
186
/// Already present registers will be preserved.
187
void map_implicit_writes(MCInst *MI, const insn_map *imap)
188
2.29M
{
189
2.29M
#ifndef CAPSTONE_DIET
190
2.29M
  if (!MI->flat_insn->detail)
191
0
    return;
192
193
2.29M
  cs_detail *detail = MI->flat_insn->detail;
194
2.29M
  unsigned Opcode = MCInst_getOpcode(MI);
195
2.29M
  unsigned i = 0;
196
2.29M
  uint16_t reg = imap[Opcode].regs_mod[i];
197
2.67M
  while (reg != 0) {
198
378k
    if (i >= MAX_IMPL_W_REGS ||
199
378k
        detail->regs_write_count >= MAX_IMPL_W_REGS) {
200
0
      printf("ERROR: Too many implicit write register defined in "
201
0
             "instruction mapping.\n");
202
0
      return;
203
0
    }
204
378k
    detail->regs_write[detail->regs_write_count++] = reg;
205
378k
    if (i + 1 < MAX_IMPL_W_REGS) {
206
      // Select next one
207
378k
      reg = imap[Opcode].regs_mod[++i];
208
378k
    }
209
378k
  }
210
2.29M
#endif // CAPSTONE_DIET
211
2.29M
}
212
213
/// Adds a given group to @MI->flat_insn.
214
/// A group is never added twice.
215
void add_group(MCInst *MI, unsigned /* arch_group */ group)
216
211k
{
217
211k
#ifndef CAPSTONE_DIET
218
211k
  if (!MI->flat_insn->detail)
219
0
    return;
220
221
211k
  cs_detail *detail = MI->flat_insn->detail;
222
211k
  if (detail->groups_count >= MAX_NUM_GROUPS) {
223
0
    printf("ERROR: Too many groups defined.\n");
224
0
    return;
225
0
  }
226
394k
  for (int i = 0; i < detail->groups_count; ++i) {
227
184k
    if (detail->groups[i] == group) {
228
992
      return;
229
992
    }
230
184k
  }
231
210k
  detail->groups[detail->groups_count++] = group;
232
210k
#endif // CAPSTONE_DIET
233
210k
}
234
235
/// Copies the groups from @imap to @MI->flat_insn.
236
/// Already present groups will be preserved.
237
void map_groups(MCInst *MI, const insn_map *imap)
238
2.29M
{
239
2.29M
#ifndef CAPSTONE_DIET
240
2.29M
  if (!MI->flat_insn->detail)
241
0
    return;
242
243
2.29M
  cs_detail *detail = MI->flat_insn->detail;
244
2.29M
  unsigned Opcode = MCInst_getOpcode(MI);
245
2.29M
  unsigned i = 0;
246
2.29M
  uint16_t group = imap[Opcode].groups[i];
247
4.98M
  while (group != 0) {
248
2.68M
    if (detail->groups_count >= MAX_NUM_GROUPS) {
249
0
      printf("ERROR: Too many groups defined in instruction mapping.\n");
250
0
      return;
251
0
    }
252
2.68M
    detail->groups[detail->groups_count++] = group;
253
2.68M
    group = imap[Opcode].groups[++i];
254
2.68M
  }
255
2.29M
#endif // CAPSTONE_DIET
256
2.29M
}
257
258
/// Returns the pointer to the supllementary information in
259
/// the instruction mapping table @imap or NULL in case of failure.
260
const void *map_get_suppl_info(MCInst *MI, const insn_map *imap)
261
1.79M
{
262
1.79M
#ifndef CAPSTONE_DIET
263
1.79M
  if (!MI->flat_insn->detail)
264
0
    return NULL;
265
266
1.79M
  unsigned Opcode = MCInst_getOpcode(MI);
267
1.79M
  return &imap[Opcode].suppl_info;
268
#else
269
  return NULL;
270
#endif // CAPSTONE_DIET
271
1.79M
}
272
273
// Search for the CS instruction id for the given @MC_Opcode in @imap.
274
// return -1 if none is found.
275
unsigned int find_cs_id(unsigned MC_Opcode, const insn_map *imap,
276
      unsigned imap_size)
277
2.29M
{
278
  // binary searching since the IDs are sorted in order
279
2.29M
  unsigned int left, right, m;
280
2.29M
  unsigned int max = imap_size;
281
282
2.29M
  right = max - 1;
283
284
2.29M
  if (MC_Opcode < imap[0].id || MC_Opcode > imap[right].id)
285
    // not found
286
0
    return -1;
287
288
2.29M
  left = 0;
289
290
25.8M
  while (left <= right) {
291
25.8M
    m = (left + right) / 2;
292
25.8M
    if (MC_Opcode == imap[m].id) {
293
2.29M
      return m;
294
2.29M
    }
295
296
23.5M
    if (MC_Opcode < imap[m].id)
297
8.26M
      right = m - 1;
298
15.2M
    else
299
15.2M
      left = m + 1;
300
23.5M
  }
301
302
0
  return -1;
303
2.29M
}
304
305
/// Sets the Capstone instruction id which maps to the @MI opcode.
306
/// If no mapping is found the function returns and prints an error.
307
void map_cs_id(MCInst *MI, const insn_map *imap, unsigned int imap_size)
308
2.29M
{
309
2.29M
  unsigned int i = find_cs_id(MCInst_getOpcode(MI), imap, imap_size);
310
2.29M
  if (i != -1) {
311
2.29M
    MI->flat_insn->id = imap[i].mapid;
312
2.29M
    return;
313
2.29M
  }
314
0
  printf("ERROR: Could not find CS id for MCInst opcode: %d\n",
315
0
         MCInst_getOpcode(MI));
316
0
  return;
317
2.29M
}
318
319
/// Returns the operand type information from the
320
/// mapping table for instruction operands.
321
/// Only usable by `auto-sync` archs!
322
const cs_op_type mapping_get_op_type(MCInst *MI, unsigned OpNum,
323
             const map_insn_ops *insn_ops_map,
324
             size_t map_size)
325
18.2M
{
326
18.2M
  assert(MI);
327
18.2M
  assert(MI->Opcode < map_size);
328
18.2M
  assert(OpNum < sizeof(insn_ops_map[MI->Opcode].ops) /
329
18.2M
             sizeof(insn_ops_map[MI->Opcode].ops[0]));
330
331
18.2M
  return insn_ops_map[MI->Opcode].ops[OpNum].type;
332
18.2M
}
333
334
/// Returns the operand access flags from the
335
/// mapping table for instruction operands.
336
/// Only usable by `auto-sync` archs!
337
const cs_ac_type mapping_get_op_access(MCInst *MI, unsigned OpNum,
338
               const map_insn_ops *insn_ops_map,
339
               size_t map_size)
340
6.83M
{
341
6.83M
  assert(MI);
342
6.83M
  assert(MI->Opcode < map_size);
343
6.83M
  assert(OpNum < sizeof(insn_ops_map[MI->Opcode].ops) /
344
6.83M
             sizeof(insn_ops_map[MI->Opcode].ops[0]));
345
346
6.83M
  cs_ac_type access = insn_ops_map[MI->Opcode].ops[OpNum].access;
347
6.83M
  if (MCInst_opIsTied(MI, OpNum) || MCInst_opIsTying(MI, OpNum))
348
471k
    access |= (access == CS_AC_READ) ? CS_AC_WRITE : CS_AC_READ;
349
6.83M
  return access;
350
6.83M
}
351
352
/// Returns the operand at detail->arch.operands[op_count + offset]
353
/// Or NULL if detail is not set or the offset would be out of bounds.
354
#define DEFINE_get_detail_op(arch, ARCH, ARCH_UPPER) \
355
  cs_##arch##_op *ARCH##_get_detail_op(MCInst *MI, int offset) \
356
26.1M
  { \
357
26.1M
    if (!MI->flat_insn->detail) \
358
26.1M
      return NULL; \
359
26.1M
    int OpIdx = MI->flat_insn->detail->arch.op_count + offset; \
360
26.1M
    if (OpIdx < 0 || OpIdx >= NUM_##ARCH_UPPER##_OPS) { \
361
8.99k
      return NULL; \
362
8.99k
    } \
363
26.1M
    return &MI->flat_insn->detail->arch.operands[OpIdx]; \
364
26.1M
  }
365
366
15.6M
DEFINE_get_detail_op(arm, ARM, ARM);
367
995k
DEFINE_get_detail_op(ppc, PPC, PPC);
368
0
DEFINE_get_detail_op(tricore, TriCore, TRICORE);
369
5.95M
DEFINE_get_detail_op(aarch64, AArch64, AARCH64);
370
0
DEFINE_get_detail_op(alpha, Alpha, ALPHA);
371
0
DEFINE_get_detail_op(hppa, HPPA, HPPA);
372
0
DEFINE_get_detail_op(loongarch, LoongArch, LOONGARCH);
373
1.71M
DEFINE_get_detail_op(mips, Mips, MIPS);
374
0
DEFINE_get_detail_op(riscv, RISCV, RISCV);
375
1.31M
DEFINE_get_detail_op(systemz, SystemZ, SYSTEMZ);
376
152k
DEFINE_get_detail_op(xtensa, Xtensa, XTENSA);
377
0
DEFINE_get_detail_op(bpf, BPF, BPF);
378
0
DEFINE_get_detail_op(arc, ARC, ARC);
379
364k
DEFINE_get_detail_op(sparc, Sparc, SPARC);
380
381
/// Returns the operand at detail->arch.operands[index]
382
/// Or NULL if detail is not set or the index would be out of bounds.
383
#define DEFINE_get_detail_op_at(arch, ARCH, ARCH_UPPER) \
384
  cs_##arch##_op *ARCH##_get_detail_op_at(MCInst *MI, int index) \
385
203k
  { \
386
203k
    if (!MI->flat_insn->detail) \
387
203k
      return NULL; \
388
203k
    if (index < 0 || index >= NUM_##ARCH_UPPER##_OPS) { \
389
0
      return NULL; \
390
0
    } \
391
203k
    return &MI->flat_insn->detail->arch.operands[index]; \
392
203k
  }
393
394
0
DEFINE_get_detail_op_at(arm, ARM, ARM);
395
0
DEFINE_get_detail_op_at(ppc, PPC, PPC);
396
0
DEFINE_get_detail_op_at(tricore, TriCore, TRICORE);
397
0
DEFINE_get_detail_op_at(aarch64, AArch64, AARCH64);
398
0
DEFINE_get_detail_op_at(alpha, Alpha, ALPHA);
399
0
DEFINE_get_detail_op_at(hppa, HPPA, HPPA);
400
0
DEFINE_get_detail_op_at(loongarch, LoongArch, LOONGARCH);
401
0
DEFINE_get_detail_op_at(mips, Mips, MIPS);
402
203k
DEFINE_get_detail_op_at(riscv, RISCV, RISCV);
403
0
DEFINE_get_detail_op_at(systemz, SystemZ, SYSTEMZ);
404
0
DEFINE_get_detail_op_at(xtensa, Xtensa, XTENSA);
405
0
DEFINE_get_detail_op_at(bpf, BPF, BPF);
406
0
DEFINE_get_detail_op_at(arc, ARC, ARC);
407
0
DEFINE_get_detail_op_at(sparc, Sparc, SPARC);
408
409
/// Returns true if for this architecture the
410
/// alias operands should be filled.
411
/// TODO: Replace this with a proper option.
412
///       So it can be toggled between disas() calls.
413
bool map_use_alias_details(const MCInst *MI)
414
3.97M
{
415
3.97M
  assert(MI);
416
3.97M
  return (MI->csh->detail_opt & CS_OPT_ON) &&
417
3.97M
         !(MI->csh->detail_opt & CS_OPT_DETAIL_REAL);
418
3.97M
}
419
420
/// Sets the setDetailOps flag to @p Val.
421
/// If detail == NULLit refuses to set the flag to true.
422
void map_set_fill_detail_ops(MCInst *MI, bool Val)
423
3.88M
{
424
3.88M
  CS_ASSERT_RET(MI);
425
3.88M
  if (!detail_is_set(MI)) {
426
0
    MI->fillDetailOps = false;
427
0
    return;
428
0
  }
429
430
3.88M
  MI->fillDetailOps = Val;
431
3.88M
}
432
433
/// Sets the instruction alias flags and the given alias id.
434
void map_set_is_alias_insn(MCInst *MI, bool Val, uint64_t Alias)
435
0
{
436
0
  CS_ASSERT_RET(MI);
437
0
  MI->isAliasInstr = Val;
438
0
  MI->flat_insn->is_alias = Val;
439
0
  MI->flat_insn->alias_id = Alias;
440
0
}
441
442
static inline bool char_ends_mnem(const char c, cs_arch arch)
443
481k
{
444
481k
  switch (arch) {
445
353k
  default:
446
353k
    return (!c || c == ' ' || c == '\t' || c == '.');
447
61.1k
  case CS_ARCH_PPC:
448
106k
  case CS_ARCH_RISCV:
449
106k
    return (!c || c == ' ' || c == '\t');
450
21.0k
  case CS_ARCH_SPARC:
451
21.0k
    return (!c || c == ' ' || c == '\t' || c == ',');
452
481k
  }
453
481k
}
454
455
/// Sets an alternative id for some instruction.
456
/// Or -1 if it fails.
457
/// You must add (<ARCH>_INS_ALIAS_BEGIN + 1) to the id to get the real id.
458
void map_set_alias_id(MCInst *MI, const SStream *O,
459
          const name_map *alias_mnem_id_map, int map_size)
460
2.28M
{
461
2.28M
  if (!MCInst_isAlias(MI)) {
462
2.17M
    MI->flat_insn->alias_id = 0;
463
2.17M
    return;
464
2.17M
  }
465
466
104k
  char alias_mnem[16] = { 0 };
467
104k
  int i = 0, j = 0;
468
104k
  const char *asm_str_buf = O->buffer;
469
  // Skip spaces and tabs
470
169k
  while (is_blank_char(asm_str_buf[i])) {
471
64.6k
    if (!asm_str_buf[i]) {
472
0
      MI->flat_insn->alias_id = 0;
473
0
      return;
474
0
    }
475
64.6k
    ++i;
476
64.6k
  }
477
481k
  for (; j < sizeof(alias_mnem) - 1; ++j, ++i) {
478
481k
    if (char_ends_mnem(asm_str_buf[i], MI->csh->arch))
479
104k
      break;
480
376k
    alias_mnem[j] = asm_str_buf[i];
481
376k
  }
482
483
104k
  int alias_id = name2id(alias_mnem_id_map, map_size, alias_mnem);
484
104k
  MI->flat_insn->alias_id = alias_id < 0 ? 0 : alias_id;
485
104k
}
486
487
/// Does a binary search over the given map and searches for @id.
488
/// If @id exists in @map, it sets @found to true and returns
489
/// the value for the @id.
490
/// Otherwise, @found is set to false and it returns UINT64_MAX.
491
///
492
/// Of course it assumes the map is sorted.
493
uint64_t enum_map_bin_search(const cs_enum_id_map *map, size_t map_len,
494
           const char *id, bool *found)
495
0
{
496
0
  size_t l = 0;
497
0
  size_t r = map_len;
498
0
  size_t id_len = strlen(id);
499
500
0
  while (l <= r) {
501
0
    size_t m = (l + r) / 2;
502
0
    size_t j = 0;
503
0
    size_t i = 0;
504
0
    size_t entry_len = strlen(map[m].str);
505
506
0
    while (j < entry_len && i < id_len && id[i] == map[m].str[j]) {
507
0
      ++j, ++i;
508
0
    }
509
0
    if (i == id_len && j == entry_len) {
510
0
      *found = true;
511
0
      return map[m].val;
512
0
    }
513
514
0
    if (id[i] < map[m].str[j]) {
515
0
      r = m - 1;
516
0
    } else if (id[i] > map[m].str[j]) {
517
0
      l = m + 1;
518
0
    }
519
0
    if ((m == 0 && id[i] < map[m].str[j]) ||
520
0
        (l + r) / 2 >= map_len) {
521
      // Break before we go out of bounds.
522
0
      break;
523
0
    }
524
0
  }
525
0
  *found = false;
526
  return UINT64_MAX;
527
0
}