/src/capstonenext/arch/BPF/BPFDisassembler.c
Line  | Count  | Source  | 
1  |  | /* Capstone Disassembly Engine */  | 
2  |  | /* BPF Backend by david942j <david942j@gmail.com>, 2019 */  | 
3  |  | /* SPDX-FileCopyrightText: 2024 Roee Toledano <roeetoledano10@gmail.com> */  | 
4  |  | /* SPDX-License-Identifier: BSD-3 */  | 
5  |  |  | 
6  |  | #ifdef CAPSTONE_HAS_BPF  | 
7  |  |  | 
8  |  | #include <string.h>  | 
9  |  | #include <stddef.h> // offsetof macro  | 
10  |  |  | 
11  |  | #include "BPFConstants.h"  | 
12  |  | #include "BPFDisassembler.h"  | 
13  |  | #include "BPFMapping.h"  | 
14  |  | #include "../../Mapping.h"  | 
15  |  | #include "../../cs_priv.h"  | 
16  |  | #include "../../utils.h"  | 
17  |  |  | 
18  |  | ///< Malloc bpf_internal, also checks if code_len is large enough.  | 
19  |  | static bpf_internal *alloc_bpf_internal(const size_t code_len)  | 
20  | 34.9k  | { | 
21  | 34.9k  |   bpf_internal *bpf;  | 
22  |  |  | 
23  | 34.9k  |   if (code_len < 8)  | 
24  | 400  |     return NULL;  | 
25  | 34.5k  |   bpf = cs_mem_malloc(sizeof(bpf_internal));  | 
26  | 34.5k  |   if (bpf == NULL)  | 
27  | 0  |     return NULL;  | 
28  |  |   /* default value */  | 
29  | 34.5k  |   bpf->insn_size = 8;  | 
30  | 34.5k  |   return bpf;  | 
31  | 34.5k  | }  | 
32  |  |  | 
33  |  | ///< Fetch a cBPF structure from code  | 
34  |  | static bpf_internal *fetch_cbpf(MCInst *instr, const uint8_t *code,  | 
35  |  |         const size_t code_len)  | 
36  | 12.1k  | { | 
37  | 12.1k  |   bpf_internal *bpf;  | 
38  |  |  | 
39  | 12.1k  |   bpf = alloc_bpf_internal(code_len);  | 
40  | 12.1k  |   if (bpf == NULL)  | 
41  | 120  |     return NULL;  | 
42  |  |  | 
43  | 12.0k  |   bpf->op = readBytes16(instr, code);  | 
44  | 12.0k  |   bpf->jt = code[2];  | 
45  | 12.0k  |   bpf->jf = code[3];  | 
46  | 12.0k  |   bpf->k = readBytes32(instr, code + 4);  | 
47  | 12.0k  |   return bpf;  | 
48  | 12.1k  | }  | 
49  |  |  | 
50  |  | ///< Fetch an eBPF structure from code  | 
51  |  | static bpf_internal *fetch_ebpf(MCInst *instr, const uint8_t *code,  | 
52  |  |         const size_t code_len)  | 
53  | 22.8k  | { | 
54  | 22.8k  |   bpf_internal *bpf;  | 
55  |  |  | 
56  | 22.8k  |   bpf = alloc_bpf_internal(code_len);  | 
57  | 22.8k  |   if (bpf == NULL)  | 
58  | 280  |     return NULL;  | 
59  |  |  | 
60  | 22.5k  |   bpf->op = (uint16_t)code[0];  | 
61  | 22.5k  |   bpf->dst = code[1] & 0xf;  | 
62  | 22.5k  |   bpf->src = (code[1] & 0xf0) >> 4;  | 
63  |  |  | 
64  |  |   // eBPF has one 16-byte instruction: BPF_LD | BPF_DW | BPF_IMM,  | 
65  |  |   // in this case imm is combined with the next block's imm.  | 
66  | 22.5k  |   if (bpf->op == (BPF_CLASS_LD | BPF_SIZE_DW | BPF_MODE_IMM)) { | 
67  | 596  |     if (code_len < 16) { | 
68  | 4  |       cs_mem_free(bpf);  | 
69  | 4  |       return NULL;  | 
70  | 4  |     }  | 
71  | 592  |     bpf->k = readBytes32(instr, code + 4) |  | 
72  | 592  |        (((uint64_t)readBytes32(instr, code + 12)) << 32);  | 
73  | 592  |     bpf->insn_size = 16;  | 
74  | 21.9k  |   } else { | 
75  | 21.9k  |     bpf->offset = readBytes16(instr, code + 2);  | 
76  | 21.9k  |     bpf->k = readBytes32(instr, code + 4);  | 
77  | 21.9k  |   }  | 
78  | 22.5k  |   return bpf;  | 
79  | 22.5k  | }  | 
80  |  |  | 
81  |  | #define CHECK_READABLE_REG(ud, reg) \  | 
82  | 14.0k  |   do { \ | 
83  | 14.0k  |     if (!((reg) >= BPF_REG_R0 && (reg) <= BPF_REG_R10)) \  | 
84  | 14.0k  |       return false; \  | 
85  | 14.0k  |   } while (0)  | 
86  |  |  | 
87  |  | #define CHECK_WRITEABLE_REG(ud, reg) \  | 
88  | 5.87k  |   do { \ | 
89  | 5.87k  |     if (!((reg) >= BPF_REG_R0 && (reg) < BPF_REG_R10)) \  | 
90  | 5.87k  |       return false; \  | 
91  | 5.87k  |   } while (0)  | 
92  |  |  | 
93  |  | #define CHECK_READABLE_AND_PUSH(ud, MI, r) \  | 
94  | 14.0k  |   do { \ | 
95  | 14.0k  |     CHECK_READABLE_REG(ud, r + BPF_REG_R0); \  | 
96  | 14.0k  |     MCOperand_CreateReg0(MI, r + BPF_REG_R0); \  | 
97  | 14.0k  |   } while (0)  | 
98  |  |  | 
99  |  | #define CHECK_WRITABLE_AND_PUSH(ud, MI, r) \  | 
100  | 5.87k  |   do { \ | 
101  | 5.87k  |     CHECK_WRITEABLE_REG(ud, r + BPF_REG_R0); \  | 
102  | 5.87k  |     MCOperand_CreateReg0(MI, r + BPF_REG_R0); \  | 
103  | 5.87k  |   } while (0)  | 
104  |  |  | 
105  |  | static bool decodeLoad(MCInst *MI, bpf_internal *bpf)  | 
106  | 9.35k  | { | 
107  | 9.35k  |   if (!EBPF_MODE(MI->csh->mode)) { | 
108  |  |     /*  | 
109  |  |      *  +-----+-----------+--------------------+  | 
110  |  |      *  | ldb |    [k]    |       [x+k]        |  | 
111  |  |      *  | ldh |    [k]    |       [x+k]        |  | 
112  |  |      *  +-----+-----------+--------------------+  | 
113  |  |      */  | 
114  | 4.55k  |     if (BPF_SIZE(bpf->op) == BPF_SIZE_DW)  | 
115  | 4  |       return false;  | 
116  | 4.55k  |     if (BPF_SIZE(bpf->op) == BPF_SIZE_B ||  | 
117  | 3.96k  |         BPF_SIZE(bpf->op) == BPF_SIZE_H) { | 
118  |  |       /* no ldx */  | 
119  | 1.13k  |       if (BPF_CLASS(bpf->op) != BPF_CLASS_LD)  | 
120  | 3  |         return false;  | 
121  |  |       /* can only be BPF_ABS and BPF_IND */  | 
122  | 1.13k  |       if (BPF_MODE(bpf->op) == BPF_MODE_ABS) { | 
123  | 577  |         MCOperand_CreateImm0(MI, bpf->k);  | 
124  | 577  |         return true;  | 
125  | 577  |       } else if (BPF_MODE(bpf->op) == BPF_MODE_IND) { | 
126  | 547  |         MCOperand_CreateReg0(MI, BPF_REG_X);  | 
127  | 547  |         MCOperand_CreateImm0(MI, bpf->k);  | 
128  | 547  |         return true;  | 
129  | 547  |       }  | 
130  | 6  |       return false;  | 
131  | 1.13k  |     }  | 
132  |  |     /*  | 
133  |  |      *  +-----+----+------+------+-----+-------+  | 
134  |  |      *  | ld  | #k | #len | M[k] | [k] | [x+k] |  | 
135  |  |      *  +-----+----+------+------+-----+-------+  | 
136  |  |      *  | ldx | #k | #len | M[k] | 4*([k]&0xf) |  | 
137  |  |      *  +-----+----+------+------+-------------+  | 
138  |  |      */  | 
139  | 3.42k  |     switch (BPF_MODE(bpf->op)) { | 
140  | 1.42k  |     default:  | 
141  | 1.42k  |       break;  | 
142  | 1.42k  |     case BPF_MODE_IMM:  | 
143  | 992  |       MCOperand_CreateImm0(MI, bpf->k);  | 
144  | 992  |       return true;  | 
145  | 474  |     case BPF_MODE_LEN:  | 
146  | 474  |       return true;  | 
147  | 525  |     case BPF_MODE_MEM:  | 
148  | 525  |       MCOperand_CreateImm0(MI, bpf->k);  | 
149  | 525  |       return true;  | 
150  | 3.42k  |     }  | 
151  | 1.42k  |     if (BPF_CLASS(bpf->op) == BPF_CLASS_LD) { | 
152  | 1.03k  |       if (BPF_MODE(bpf->op) == BPF_MODE_ABS) { | 
153  | 600  |         MCOperand_CreateImm0(MI, bpf->k);  | 
154  | 600  |         return true;  | 
155  | 600  |       } else if (BPF_MODE(bpf->op) == BPF_MODE_IND) { | 
156  | 428  |         MCOperand_CreateReg0(MI, BPF_REG_X);  | 
157  | 428  |         MCOperand_CreateImm0(MI, bpf->k);  | 
158  | 428  |         return true;  | 
159  | 428  |       }  | 
160  | 1.03k  |     } else { /* LDX */ | 
161  | 398  |       if (BPF_MODE(bpf->op) == BPF_MODE_MSH) { | 
162  | 394  |         MCOperand_CreateImm0(MI, bpf->k);  | 
163  | 394  |         return true;  | 
164  | 394  |       }  | 
165  | 398  |     }  | 
166  | 7  |     return false;  | 
167  | 1.42k  |   }  | 
168  |  |  | 
169  |  |   /* eBPF mode */  | 
170  |  |   /*  | 
171  |  |    * - IMM: lddw dst, imm64  | 
172  |  |    * - ABS: ld{w,h,b} [k] | 
173  |  |    * - IND: ld{w,h,b} [src] | 
174  |  |    * - MEM: ldx{w,h,b,dw} dst, [src+off] | 
175  |  |    */  | 
176  | 4.79k  |   if (BPF_CLASS(bpf->op) == BPF_CLASS_LD) { | 
177  | 3.35k  |     switch (BPF_MODE(bpf->op)) { | 
178  | 607  |     case BPF_MODE_IMM:  | 
179  | 607  |       if (bpf->op !=  | 
180  | 607  |           (BPF_CLASS_LD | BPF_SIZE_DW | BPF_MODE_IMM))  | 
181  | 15  |         return false;  | 
182  | 592  |       CHECK_WRITABLE_AND_PUSH(ud, MI, bpf->dst);  | 
183  | 590  |       MCOperand_CreateImm0(MI, bpf->k);  | 
184  | 590  |       return true;  | 
185  | 1.38k  |     case BPF_MODE_ABS:  | 
186  | 1.38k  |       MCOperand_CreateImm0(MI, bpf->k);  | 
187  | 1.38k  |       return true;  | 
188  | 1.35k  |     case BPF_MODE_IND:  | 
189  | 1.35k  |       CHECK_READABLE_AND_PUSH(ud, MI, bpf->src);  | 
190  | 1.34k  |       return true;  | 
191  | 3.35k  |     }  | 
192  | 5  |     return false;  | 
193  | 3.35k  |   }  | 
194  |  |   /* LDX */  | 
195  | 1.44k  |   if (BPF_MODE(bpf->op) == BPF_MODE_MEM) { | 
196  | 1.44k  |     CHECK_WRITABLE_AND_PUSH(ud, MI, bpf->dst);  | 
197  | 1.43k  |     CHECK_READABLE_AND_PUSH(ud, MI, bpf->src);  | 
198  | 1.43k  |     MCOperand_CreateImm0(MI, bpf->offset);  | 
199  | 1.43k  |     return true;  | 
200  | 1.43k  |   }  | 
201  | 5  |   return false;  | 
202  | 1.44k  | }  | 
203  |  |  | 
204  |  | static bool decodeStore(MCInst *MI, bpf_internal *bpf)  | 
205  | 4.43k  | { | 
206  |  |   /* in cBPF, only BPF_ST* | BPF_MEM | BPF_W is valid  | 
207  |  |    * while in eBPF:  | 
208  |  |    * - BPF_STX | BPF_XADD | BPF_{W,DW} | 
209  |  |    * - BPF_ST* | BPF_MEM | BPF_{W,H,B,DW} | 
210  |  |    * are valid  | 
211  |  |    */  | 
212  | 4.43k  |   if (!EBPF_MODE(MI->csh->mode)) { | 
213  |  |     /* can only store to M[] */  | 
214  | 561  |     if (bpf->op != (BPF_CLASS(bpf->op) | BPF_MODE_MEM | BPF_SIZE_W))  | 
215  | 5  |       return false;  | 
216  | 556  |     MCOperand_CreateImm0(MI, bpf->k);  | 
217  | 556  |     return true;  | 
218  | 561  |   }  | 
219  |  |  | 
220  |  |   /* eBPF */  | 
221  | 3.87k  |   if (BPF_MODE(bpf->op) == BPF_MODE_ATOMIC) { | 
222  | 935  |     if (BPF_CLASS(bpf->op) != BPF_CLASS_STX)  | 
223  | 2  |       return false;  | 
224  | 933  |     if (BPF_SIZE(bpf->op) != BPF_SIZE_W &&  | 
225  | 417  |         BPF_SIZE(bpf->op) != BPF_SIZE_DW)  | 
226  | 2  |       return false;  | 
227  |  |     /* xadd [dst + off], src */  | 
228  | 931  |     CHECK_READABLE_AND_PUSH(ud, MI, bpf->dst);  | 
229  | 927  |     MCOperand_CreateImm0(MI, bpf->offset);  | 
230  | 927  |     CHECK_READABLE_AND_PUSH(ud, MI, bpf->src);  | 
231  | 925  |     return true;  | 
232  | 927  |   }  | 
233  |  |  | 
234  | 2.94k  |   if (BPF_MODE(bpf->op) != BPF_MODE_MEM)  | 
235  | 8  |     return false;  | 
236  |  |  | 
237  |  |   /* st [dst + off], src */  | 
238  | 2.93k  |   CHECK_READABLE_AND_PUSH(ud, MI, bpf->dst);  | 
239  | 2.93k  |   MCOperand_CreateImm0(MI, bpf->offset);  | 
240  | 2.93k  |   if (BPF_CLASS(bpf->op) == BPF_CLASS_ST)  | 
241  | 1.34k  |     MCOperand_CreateImm0(MI, bpf->k);  | 
242  | 1.58k  |   else  | 
243  | 1.58k  |     CHECK_READABLE_AND_PUSH(ud, MI, bpf->src);  | 
244  | 2.92k  |   return true;  | 
245  | 2.93k  | }  | 
246  |  |  | 
247  |  | static bool decodeALU(MCInst *MI, bpf_internal *bpf)  | 
248  | 5.49k  | { | 
249  |  |   /* Set MI->Operands */  | 
250  |  |  | 
251  |  |   /* cBPF */  | 
252  | 5.49k  |   if (!EBPF_MODE(MI->csh->mode)) { | 
253  | 1.60k  |     if (BPF_OP(bpf->op) > BPF_ALU_XOR)  | 
254  | 1  |       return false;  | 
255  |  |     /* cBPF's NEG has no operands */  | 
256  | 1.60k  |     if (BPF_OP(bpf->op) == BPF_ALU_NEG)  | 
257  | 197  |       return true;  | 
258  | 1.41k  |     if (BPF_SRC(bpf->op) == BPF_SRC_K)  | 
259  | 833  |       MCOperand_CreateImm0(MI, bpf->k);  | 
260  | 577  |     else /* BPF_SRC_X */  | 
261  | 577  |       MCOperand_CreateReg0(MI, BPF_REG_X);  | 
262  | 1.41k  |     return true;  | 
263  | 1.60k  |   }  | 
264  |  |  | 
265  |  |   /* eBPF */  | 
266  |  |  | 
267  | 3.88k  |   if (BPF_OP(bpf->op) > BPF_ALU_END)  | 
268  | 5  |     return false;  | 
269  |  |   /* ENDian's imm must be one of 16, 32, 64 */  | 
270  | 3.88k  |   if (BPF_OP(bpf->op) == BPF_ALU_END) { | 
271  | 389  |     if (bpf->k != 16 && bpf->k != 32 && bpf->k != 64)  | 
272  | 36  |       return false;  | 
273  | 353  |     if (BPF_CLASS(bpf->op) == BPF_CLASS_ALU64 &&  | 
274  | 57  |         BPF_SRC(bpf->op) != BPF_SRC_LITTLE)  | 
275  | 1  |       return false;  | 
276  | 353  |   }  | 
277  |  |  | 
278  |  |   /* - op dst, imm  | 
279  |  |    * - op dst, src  | 
280  |  |    * - neg dst  | 
281  |  |    * - le<imm> dst  | 
282  |  |    */  | 
283  |  |   /* every ALU instructions have dst op */  | 
284  | 3.84k  |   CHECK_WRITABLE_AND_PUSH(ud, MI, bpf->dst);  | 
285  |  |  | 
286  |  |   /* special cases */  | 
287  | 3.84k  |   if (BPF_OP(bpf->op) == BPF_ALU_NEG)  | 
288  | 266  |     return true;  | 
289  | 3.57k  |   if (BPF_OP(bpf->op) == BPF_ALU_END) { | 
290  |  |     /* bpf->k must be one of 16, 32, 64 */  | 
291  | 352  |     bpf->op |= ((uint32_t)bpf->k << 4);  | 
292  | 352  |     return true;  | 
293  | 352  |   }  | 
294  |  |  | 
295  |  |   /* normal cases */  | 
296  | 3.22k  |   if (BPF_SRC(bpf->op) == BPF_SRC_K) { | 
297  | 2.82k  |     MCOperand_CreateImm0(MI, bpf->k);  | 
298  | 2.82k  |   } else { /* BPF_SRC_X */ | 
299  | 399  |     CHECK_READABLE_AND_PUSH(ud, MI, bpf->src);  | 
300  | 399  |   }  | 
301  | 3.22k  |   return true;  | 
302  | 3.22k  | }  | 
303  |  |  | 
304  |  | static bool decodeJump(MCInst *MI, bpf_internal *bpf)  | 
305  | 6.14k  | { | 
306  |  |   /* cBPF and eBPF are very different in class jump */  | 
307  | 6.14k  |   if (!EBPF_MODE(MI->csh->mode)) { | 
308  | 1.03k  |     if (BPF_OP(bpf->op) > BPF_JUMP_JSET)  | 
309  | 1  |       return false;  | 
310  |  |  | 
311  |  |     /* ja is a special case of jumps */  | 
312  | 1.02k  |     if (BPF_OP(bpf->op) == BPF_JUMP_JA) { | 
313  | 214  |       MCOperand_CreateImm0(MI, bpf->k);  | 
314  | 214  |       return true;  | 
315  | 214  |     }  | 
316  |  |  | 
317  | 815  |     if (BPF_SRC(bpf->op) == BPF_SRC_K)  | 
318  | 313  |       MCOperand_CreateImm0(MI, bpf->k);  | 
319  | 502  |     else /* BPF_SRC_X */  | 
320  | 502  |       MCOperand_CreateReg0(MI, BPF_REG_X);  | 
321  | 815  |     MCOperand_CreateImm0(MI, bpf->jt);  | 
322  | 815  |     MCOperand_CreateImm0(MI, bpf->jf);  | 
323  | 5.11k  |   } else { | 
324  | 5.11k  |     if (BPF_OP(bpf->op) > BPF_JUMP_JSLE)  | 
325  | 3  |       return false;  | 
326  |  |  | 
327  |  |     /* JMP32 has no CALL/EXIT instruction */  | 
328  |  |     /* No operands for exit */  | 
329  | 5.10k  |     if (BPF_OP(bpf->op) == BPF_JUMP_EXIT)  | 
330  | 198  |       return bpf->op == (BPF_CLASS_JMP | BPF_JUMP_EXIT);  | 
331  | 4.91k  |     if (BPF_OP(bpf->op) == BPF_JUMP_CALL) { | 
332  | 239  |       if (bpf->op == (BPF_CLASS_JMP | BPF_JUMP_CALL)) { | 
333  | 198  |         MCOperand_CreateImm0(MI, bpf->k);  | 
334  | 198  |         return true;  | 
335  | 198  |       }  | 
336  | 41  |       if (bpf->op ==  | 
337  | 41  |           (BPF_CLASS_JMP | BPF_JUMP_CALL | BPF_SRC_X)) { | 
338  | 40  |         CHECK_READABLE_AND_PUSH(ud, MI, bpf->k);  | 
339  | 10  |         return true;  | 
340  | 40  |       }  | 
341  | 1  |       return false;  | 
342  | 41  |     }  | 
343  |  |  | 
344  |  |     /* ja is a special case of jumps */  | 
345  | 4.67k  |     if (BPF_OP(bpf->op) == BPF_JUMP_JA) { | 
346  | 448  |       if (BPF_SRC(bpf->op) != BPF_SRC_K)  | 
347  | 1  |         return false;  | 
348  | 447  |       if (BPF_CLASS(bpf->op) == BPF_CLASS_JMP)  | 
349  | 235  |         MCOperand_CreateImm0(MI, bpf->offset);  | 
350  | 212  |       else  | 
351  | 212  |         MCOperand_CreateImm0(MI, bpf->k);  | 
352  |  |  | 
353  | 447  |       return true;  | 
354  | 448  |     }  | 
355  |  |  | 
356  |  |     /* <j>  dst, src, +off */  | 
357  | 4.22k  |     CHECK_READABLE_AND_PUSH(ud, MI, bpf->dst);  | 
358  | 4.21k  |     if (BPF_SRC(bpf->op) == BPF_SRC_K)  | 
359  | 3.96k  |       MCOperand_CreateImm0(MI, bpf->k);  | 
360  | 258  |     else  | 
361  | 258  |       CHECK_READABLE_AND_PUSH(ud, MI, bpf->src);  | 
362  | 4.21k  |     MCOperand_CreateImm0(MI, bpf->offset);  | 
363  | 4.21k  |   }  | 
364  | 5.03k  |   return true;  | 
365  | 6.14k  | }  | 
366  |  |  | 
367  |  | static bool decodeReturn(MCInst *MI, bpf_internal *bpf)  | 
368  | 1.20k  | { | 
369  |  |   /* Here only handles the BPF_RET class in cBPF */  | 
370  | 1.20k  |   switch (BPF_RVAL(bpf->op)) { | 
371  | 396  |   case BPF_SRC_K:  | 
372  | 396  |     MCOperand_CreateImm0(MI, bpf->k);  | 
373  | 396  |     return true;  | 
374  | 410  |   case BPF_SRC_X:  | 
375  | 410  |     MCOperand_CreateReg0(MI, BPF_REG_X);  | 
376  | 410  |     return true;  | 
377  | 398  |   case BPF_SRC_A:  | 
378  | 398  |     MCOperand_CreateReg0(MI, BPF_REG_A);  | 
379  | 398  |     return true;  | 
380  | 1.20k  |   }  | 
381  | 2  |   return false;  | 
382  | 1.20k  | }  | 
383  |  |  | 
384  |  | static bool decodeMISC(MCInst *MI, bpf_internal *bpf)  | 
385  | 759  | { | 
386  | 759  |   uint16_t op = bpf->op ^ BPF_CLASS_MISC;  | 
387  | 759  |   return op == BPF_MISCOP_TAX || op == BPF_MISCOP_TXA;  | 
388  | 759  | }  | 
389  |  |  | 
390  |  | ///< 1. Check if the instruction is valid  | 
391  |  | ///< 2. Set MI->opcode  | 
392  |  | ///< 3. Set MI->Operands  | 
393  |  | static bool getInstruction(MCInst *MI, bpf_internal *bpf)  | 
394  | 20.0k  | { | 
395  | 20.0k  |   cs_detail *detail;  | 
396  |  |  | 
397  | 20.0k  |   detail = MI->flat_insn->detail;  | 
398  |  |   // initialize detail  | 
399  | 20.0k  |   if (detail) { | 
400  | 20.0k  |     memset(detail, 0, offsetof(cs_detail, bpf) + sizeof(cs_bpf));  | 
401  | 20.0k  |   }  | 
402  |  |  | 
403  | 20.0k  |   MCInst_clear(MI);  | 
404  |  |  | 
405  | 20.0k  |   switch (BPF_CLASS(bpf->op)) { | 
406  | 0  |   default: /* should never happen */  | 
407  | 0  |     return false;  | 
408  | 3.53k  |   case BPF_CLASS_LD:  | 
409  | 5.11k  |   case BPF_CLASS_LDX:  | 
410  | 5.11k  |     return decodeLoad(MI, bpf);  | 
411  | 912  |   case BPF_CLASS_ST:  | 
412  | 2.38k  |   case BPF_CLASS_STX:  | 
413  | 2.38k  |     return decodeStore(MI, bpf);  | 
414  | 3.15k  |   case BPF_CLASS_ALU:  | 
415  | 3.15k  |     return decodeALU(MI, bpf);  | 
416  | 3.52k  |   case BPF_CLASS_JMP:  | 
417  | 3.52k  |     return decodeJump(MI, bpf);  | 
418  | 3.22k  |   case BPF_CLASS_RET:  | 
419  |  |     /* case BPF_CLASS_JMP32: */  | 
420  | 3.22k  |     if (EBPF_MODE(MI->csh->mode))  | 
421  | 2.61k  |       return decodeJump(MI, bpf);  | 
422  | 610  |     else  | 
423  | 610  |       return decodeReturn(MI, bpf);  | 
424  | 2.62k  |   case BPF_CLASS_MISC:  | 
425  |  |     /* case BPF_CLASS_ALU64: */  | 
426  | 2.62k  |     if (EBPF_MODE(MI->csh->mode))  | 
427  | 2.33k  |       return decodeALU(MI, bpf);  | 
428  | 286  |     else  | 
429  | 286  |       return decodeMISC(MI, bpf);  | 
430  | 20.0k  |   }  | 
431  | 20.0k  | }  | 
432  |  |  | 
433  |  | // Check for regular load instructions  | 
434  |  | #define REG_LOAD_CASE(c) \  | 
435  | 3.53k  |   case BPF_SIZE_##c: \  | 
436  | 3.53k  |     if (BPF_CLASS(opcode) == BPF_CLASS_LD) \  | 
437  | 3.53k  |       return BPF_INS_LD##c; \  | 
438  | 3.53k  |     else \  | 
439  | 3.53k  |       return BPF_INS_LDX##c;  | 
440  |  |  | 
441  |  | static bpf_insn op2insn_ld_cbpf(unsigned opcode)  | 
442  | 3.53k  | { | 
443  | 3.53k  |   switch (BPF_SIZE(opcode)) { | 
444  | 1.86k  |     REG_LOAD_CASE(W);  | 
445  | 440  |     REG_LOAD_CASE(H);  | 
446  | 633  |     REG_LOAD_CASE(B);  | 
447  | 596  |     REG_LOAD_CASE(DW);  | 
448  | 3.53k  |   }  | 
449  |  |  | 
450  | 0  |   return BPF_INS_INVALID;  | 
451  | 3.53k  | }  | 
452  |  | #undef REG_LOAD_CASE  | 
453  |  |  | 
454  |  | // Check for packet load instructions  | 
455  |  | #define PACKET_LOAD_CASE(c) \  | 
456  | 1.55k  |   case BPF_SIZE_##c: \  | 
457  | 1.55k  |     if (BPF_MODE(opcode) == BPF_MODE_ABS) \  | 
458  | 1.55k  |       return BPF_INS_LDABS##c; \  | 
459  | 1.55k  |     else if (BPF_MODE(opcode) == BPF_MODE_IND) \  | 
460  | 691  |       return BPF_INS_LDIND##c; \  | 
461  | 691  |     else \  | 
462  | 691  |       return BPF_INS_INVALID;  | 
463  |  |  | 
464  |  | static bpf_insn op2insn_ld_ebpf(unsigned opcode)  | 
465  | 2.92k  | { | 
466  | 2.92k  |   if (BPF_CLASS(opcode) == BPF_CLASS_LD) { | 
467  | 1.95k  |     switch (BPF_SIZE(opcode)) { | 
468  | 624  |       PACKET_LOAD_CASE(W);  | 
469  | 433  |       PACKET_LOAD_CASE(H);  | 
470  | 495  |       PACKET_LOAD_CASE(B);  | 
471  | 1.95k  |     }  | 
472  | 1.95k  |   }  | 
473  |  |  | 
474  |  |   // If it's not a packet load instruction, it must be a regular load instruction  | 
475  | 1.37k  |   return op2insn_ld_cbpf(opcode);  | 
476  | 2.92k  | }  | 
477  |  | #undef PACKET_LOAD_CASE  | 
478  |  |  | 
479  |  | /* During parsing we already checked to make sure the size is D/DW and   | 
480  |  |  * mode is STX and not ST, so we don't need to check again*/  | 
481  |  | #define ALU_CASE_REG(c) \  | 
482  | 252  |   case BPF_ALU_##c: \  | 
483  | 252  |     if (BPF_SIZE(opcode) == BPF_SIZE_W) \  | 
484  | 252  |       return BPF_INS_A##c; \  | 
485  | 252  |     else \  | 
486  | 252  |       return BPF_INS_A##c##64;  | 
487  |  |  | 
488  |  | #define ALU_CASE_FETCH(c) \  | 
489  | 120  |   case BPF_ALU_##c | BPF_MODE_FETCH: \  | 
490  | 120  |     if (BPF_SIZE(opcode) == BPF_SIZE_W) \  | 
491  | 120  |       return BPF_INS_AF##c; \  | 
492  | 120  |     else \  | 
493  | 120  |       return BPF_INS_AF##c##64;  | 
494  |  |  | 
495  |  | #define COMPLEX_CASE(c) \  | 
496  | 30  |   case BPF_ATOMIC_##c | BPF_MODE_FETCH: \  | 
497  | 30  |     if (BPF_SIZE(opcode) == BPF_SIZE_DW) \  | 
498  | 30  |       return BPF_INS_A##c##64; \  | 
499  | 30  |     else \  | 
500  | 30  |       return BPF_INS_INVALID;  | 
501  |  |  | 
502  |  | #define CASE(c) \  | 
503  | 1.96k  |   case BPF_SIZE_##c: \  | 
504  | 1.96k  |     if (BPF_CLASS(opcode) == BPF_CLASS_ST) \  | 
505  | 1.96k  |       return BPF_INS_ST##c; \  | 
506  | 1.96k  |     else \  | 
507  | 1.96k  |       return BPF_INS_STX##c;  | 
508  |  |  | 
509  |  | static bpf_insn op2insn_st(unsigned opcode, const uint32_t imm)  | 
510  | 2.37k  | { | 
511  |  |   /*  | 
512  |  |    * - BPF_STX | ALU atomic operations | BPF_{W,DW} | 
513  |  |    * - BPF_STX | Complex atomic operations | BPF_{DW} | 
514  |  |    * - BPF_ST* | BPF_MEM | BPF_{W,H,B,DW} | 
515  |  |    */  | 
516  |  |  | 
517  | 2.37k  |   if (BPF_MODE(opcode) == BPF_MODE_ATOMIC) { | 
518  | 406  |     switch (imm) { | 
519  | 122  |       ALU_CASE_REG(ADD);  | 
520  | 36  |       ALU_CASE_REG(OR);  | 
521  | 58  |       ALU_CASE_REG(AND);  | 
522  | 36  |       ALU_CASE_REG(XOR);  | 
523  | 28  |       ALU_CASE_FETCH(ADD);  | 
524  | 36  |       ALU_CASE_FETCH(OR);  | 
525  | 28  |       ALU_CASE_FETCH(AND);  | 
526  | 28  |       ALU_CASE_FETCH(XOR);  | 
527  | 11  |       COMPLEX_CASE(XCHG);  | 
528  | 19  |       COMPLEX_CASE(CMPXCHG);  | 
529  | 4  |     default: // Reached if complex atomic operation is used without fetch modifier  | 
530  | 4  |       return BPF_INS_INVALID;  | 
531  | 406  |     }  | 
532  | 406  |   }  | 
533  |  |  | 
534  |  |   /* should be BPF_MEM */  | 
535  | 1.96k  |   switch (BPF_SIZE(opcode)) { | 
536  | 579  |     CASE(W);  | 
537  | 278  |     CASE(H);  | 
538  | 843  |     CASE(B);  | 
539  | 269  |     CASE(DW);  | 
540  | 1.96k  |   }  | 
541  |  |  | 
542  | 0  |   return BPF_INS_INVALID;  | 
543  | 1.96k  | }  | 
544  |  | #undef CASE  | 
545  |  |  | 
546  |  | #define CASE(c) \  | 
547  | 4.15k  |   case BPF_ALU_##c: \  | 
548  | 4.15k  |     CASE_IF(c)  | 
549  |  |  | 
550  |  | #define CASE_IF(c) \  | 
551  | 5.05k  |   do { \ | 
552  | 5.05k  |     if (BPF_CLASS(opcode) == BPF_CLASS_ALU) \  | 
553  | 5.05k  |       return BPF_INS_##c; \  | 
554  | 5.05k  |     else \  | 
555  | 5.05k  |       return BPF_INS_##c##64; \  | 
556  | 5.05k  |   } while (0)  | 
557  |  |  | 
558  |  | static bpf_insn op2insn_alu(unsigned opcode, const uint16_t off,  | 
559  |  |           const bool is_ebpf)  | 
560  | 5.44k  | { | 
561  |  |   /* Endian is a special case */  | 
562  | 5.44k  |   if (BPF_OP(opcode) == BPF_ALU_END) { | 
563  | 352  |     if (BPF_CLASS(opcode) == BPF_CLASS_ALU64) { | 
564  | 56  |       switch (opcode ^ BPF_CLASS_ALU64 ^ BPF_ALU_END ^  | 
565  | 56  |         BPF_SRC_LITTLE) { | 
566  | 19  |       case (16 << 4):  | 
567  | 19  |         return BPF_INS_BSWAP16;  | 
568  | 19  |       case (32 << 4):  | 
569  | 19  |         return BPF_INS_BSWAP32;  | 
570  | 18  |       case (64 << 4):  | 
571  | 18  |         return BPF_INS_BSWAP64;  | 
572  | 0  |       default:  | 
573  | 0  |         return BPF_INS_INVALID;  | 
574  | 56  |       }  | 
575  | 56  |     }  | 
576  |  |  | 
577  | 296  |     switch (opcode ^ BPF_CLASS_ALU ^ BPF_ALU_END) { | 
578  | 19  |     case BPF_SRC_LITTLE | (16 << 4):  | 
579  | 19  |       return BPF_INS_LE16;  | 
580  | 18  |     case BPF_SRC_LITTLE | (32 << 4):  | 
581  | 18  |       return BPF_INS_LE32;  | 
582  | 18  |     case BPF_SRC_LITTLE | (64 << 4):  | 
583  | 18  |       return BPF_INS_LE64;  | 
584  | 69  |     case BPF_SRC_BIG | (16 << 4):  | 
585  | 69  |       return BPF_INS_BE16;  | 
586  | 154  |     case BPF_SRC_BIG | (32 << 4):  | 
587  | 154  |       return BPF_INS_BE32;  | 
588  | 18  |     case BPF_SRC_BIG | (64 << 4):  | 
589  | 18  |       return BPF_INS_BE64;  | 
590  | 296  |     }  | 
591  | 0  |     return BPF_INS_INVALID;  | 
592  | 296  |   }  | 
593  |  |  | 
594  | 5.09k  |   switch (BPF_OP(opcode)) { | 
595  | 443  |     CASE(ADD);  | 
596  | 393  |     CASE(SUB);  | 
597  | 283  |     CASE(MUL);  | 
598  | 444  |     CASE(OR);  | 
599  | 412  |     CASE(AND);  | 
600  | 457  |     CASE(LSH);  | 
601  | 401  |     CASE(RSH);  | 
602  | 463  |     CASE(NEG);  | 
603  | 462  |     CASE(XOR);  | 
604  | 398  |     CASE(ARSH);  | 
605  | 318  |   case BPF_ALU_DIV:  | 
606  | 318  |     if (!is_ebpf || off == 0)  | 
607  | 227  |       CASE_IF(DIV);  | 
608  | 91  |     else if (off == 1)  | 
609  | 84  |       CASE_IF(SDIV);  | 
610  | 7  |     else  | 
611  | 7  |       return BPF_INS_INVALID;  | 
612  | 387  |   case BPF_ALU_MOD:  | 
613  | 387  |     if (!is_ebpf || off == 0)  | 
614  | 275  |       CASE_IF(MOD);  | 
615  | 112  |     else if (off == 1)  | 
616  | 101  |       CASE_IF(SMOD);  | 
617  | 11  |     else  | 
618  | 11  |       return BPF_INS_INVALID;  | 
619  | 235  |   case BPF_ALU_MOV:  | 
620  |  |     /* BPF_CLASS_ALU can have: mov, mov8s, mov16s  | 
621  |  |      * BPF_CLASS_ALU64 can have: mov, mov8s, mov16s, mov32s  | 
622  |  |      * */  | 
623  | 235  |     if (off == 0)  | 
624  | 40  |       CASE_IF(MOV);  | 
625  | 195  |     else if (off == 8)  | 
626  | 100  |       CASE_IF(MOVSB);  | 
627  | 95  |     else if (off == 16)  | 
628  | 68  |       CASE_IF(MOVSH);  | 
629  | 27  |     else if (off == 32 && BPF_CLASS(opcode) == BPF_CLASS_ALU64)  | 
630  | 18  |       return BPF_INS_MOVSW64;  | 
631  | 9  |     else  | 
632  | 9  |       return BPF_INS_INVALID;  | 
633  | 5.09k  |   }  | 
634  |  |  | 
635  | 0  |   return BPF_INS_INVALID;  | 
636  | 5.09k  | }  | 
637  |  | #undef CASE_IF  | 
638  |  | #undef CASE  | 
639  |  |  | 
640  | 6.09k  | #define BPF_CALLX (BPF_CLASS_JMP | BPF_JUMP_CALL | BPF_SRC_X)  | 
641  |  |  | 
642  |  | #define CASE(c) \  | 
643  | 5.03k  |   case BPF_JUMP_##c: \  | 
644  | 5.03k  |     if (BPF_CLASS(opcode) == BPF_CLASS_JMP) \  | 
645  | 5.03k  |       return BPF_INS_##c; \  | 
646  | 5.03k  |     else \  | 
647  | 5.03k  |       return BPF_INS_##c##32;  | 
648  |  |  | 
649  |  | #define SPEC_CASE(c) \  | 
650  | 395  |   case BPF_JUMP_##c: \  | 
651  | 395  |     if (BPF_CLASS(opcode) == BPF_CLASS_JMP) \  | 
652  | 395  |       return BPF_INS_##c; \  | 
653  | 395  |     else \  | 
654  | 395  |       return BPF_INS_INVALID;  | 
655  |  |  | 
656  |  | static bpf_insn op2insn_jmp(unsigned opcode)  | 
657  | 6.09k  | { | 
658  | 6.09k  |   if (opcode == BPF_CALLX) { | 
659  | 10  |     return BPF_INS_CALLX;  | 
660  | 10  |   }  | 
661  |  |  | 
662  | 6.08k  |   switch (BPF_OP(opcode)) { | 
663  | 661  |   case BPF_JUMP_JA:  | 
664  | 661  |     if (BPF_CLASS(opcode) == BPF_CLASS_JMP)  | 
665  | 449  |       return BPF_INS_JA;  | 
666  | 212  |     else  | 
667  | 212  |       return BPF_INS_JAL;  | 
668  | 466  |     CASE(JEQ);  | 
669  | 482  |     CASE(JGT);  | 
670  | 397  |     CASE(JGE);  | 
671  | 498  |     CASE(JSET);  | 
672  | 476  |     CASE(JNE);  | 
673  | 400  |     CASE(JSGT);  | 
674  | 403  |     CASE(JSGE);  | 
675  | 198  |     SPEC_CASE(CALL);  | 
676  | 197  |     SPEC_CASE(EXIT);  | 
677  | 501  |     CASE(JLT);  | 
678  | 577  |     CASE(JLE);  | 
679  | 396  |     CASE(JSLT);  | 
680  | 437  |     CASE(JSLE);  | 
681  | 6.08k  |   }  | 
682  |  |  | 
683  | 0  |   return BPF_INS_INVALID;  | 
684  | 6.08k  | }  | 
685  |  | #undef SPEC_CASE  | 
686  |  | #undef CASE  | 
687  |  | #undef BPF_CALLX  | 
688  |  |  | 
689  |  | #ifndef CAPSTONE_DIET  | 
690  |  |  | 
691  |  | static void update_regs_access(MCInst *MI, cs_detail *detail, bpf_insn insn_id,  | 
692  |  |              unsigned int opcode)  | 
693  | 19.8k  | { | 
694  | 19.8k  |   if (insn_id == BPF_INS_INVALID)  | 
695  | 0  |     return;  | 
696  |  |   /*  | 
697  |  |    * In eBPF mode, only these instructions have implicit registers access:  | 
698  |  |    * - legacy ld{w,h,b,dw} * // w: r0 | 
699  |  |    * - exit // r: r0  | 
700  |  |    */  | 
701  | 19.8k  |   if (EBPF_MODE(MI->csh->mode)) { | 
702  | 14.0k  |     switch (insn_id) { | 
703  | 11.9k  |     default:  | 
704  | 11.9k  |       break;  | 
705  | 11.9k  |     case BPF_INS_LDABSW:  | 
706  | 561  |     case BPF_INS_LDABSH:  | 
707  | 861  |     case BPF_INS_LDABSB:  | 
708  | 1.15k  |     case BPF_INS_LDINDW:  | 
709  | 1.35k  |     case BPF_INS_LDINDH:  | 
710  | 1.55k  |     case BPF_INS_LDINDB:  | 
711  | 1.95k  |     case BPF_INS_LDDW:  | 
712  | 1.95k  |       if (BPF_MODE(opcode) == BPF_MODE_ABS ||  | 
713  | 937  |           BPF_MODE(opcode) == BPF_MODE_IND)  | 
714  | 1.75k  |         map_add_implicit_write(MI, BPF_REG_R0);  | 
715  | 1.95k  |       break;  | 
716  | 197  |     case BPF_INS_EXIT:  | 
717  | 197  |       map_add_implicit_read(MI, BPF_REG_R0);  | 
718  | 197  |       break;  | 
719  | 14.0k  |     }  | 
720  | 14.0k  |     return;  | 
721  | 14.0k  |   }  | 
722  |  |  | 
723  |  |   /* cBPF mode */  | 
724  | 5.78k  |   switch (BPF_CLASS(opcode)) { | 
725  | 609  |   default:  | 
726  | 609  |     break;  | 
727  | 1.56k  |   case BPF_CLASS_LD:  | 
728  | 1.56k  |     map_add_implicit_write(MI, BPF_REG_A);  | 
729  | 1.56k  |     break;  | 
730  | 599  |   case BPF_CLASS_LDX:  | 
731  | 599  |     map_add_implicit_write(MI, BPF_REG_X);  | 
732  | 599  |     break;  | 
733  | 68  |   case BPF_CLASS_ST:  | 
734  | 68  |     map_add_implicit_read(MI, BPF_REG_A);  | 
735  | 68  |     break;  | 
736  | 34  |   case BPF_CLASS_STX:  | 
737  | 34  |     map_add_implicit_read(MI, BPF_REG_X);  | 
738  | 34  |     break;  | 
739  | 1.60k  |   case BPF_CLASS_ALU:  | 
740  | 1.60k  |     map_add_implicit_read(MI, BPF_REG_A);  | 
741  | 1.60k  |     map_add_implicit_write(MI, BPF_REG_A);  | 
742  | 1.60k  |     break;  | 
743  | 1.02k  |   case BPF_CLASS_JMP:  | 
744  | 1.02k  |     if (insn_id != BPF_INS_JA) // except the unconditional jump  | 
745  | 815  |       map_add_implicit_read(MI, BPF_REG_A);  | 
746  | 1.02k  |     break;  | 
747  |  |   /* case BPF_CLASS_RET: */  | 
748  | 277  |   case BPF_CLASS_MISC:  | 
749  | 277  |     if (insn_id == BPF_INS_TAX) { | 
750  | 209  |       map_add_implicit_read(MI, BPF_REG_A);  | 
751  | 209  |       map_add_implicit_write(MI, BPF_REG_X);  | 
752  | 209  |     } else { | 
753  | 68  |       map_add_implicit_read(MI, BPF_REG_X);  | 
754  | 68  |       map_add_implicit_write(MI, BPF_REG_A);  | 
755  | 68  |     }  | 
756  | 277  |     break;  | 
757  | 5.78k  |   }  | 
758  | 5.78k  | }  | 
759  |  | #endif  | 
760  |  |  | 
761  |  | static bool setFinalOpcode(MCInst *MI, const bpf_internal *bpf)  | 
762  | 19.8k  | { | 
763  | 19.8k  |   bpf_insn id = BPF_INS_INVALID;  | 
764  | 19.8k  | #ifndef CAPSTONE_DIET  | 
765  | 19.8k  |   cs_detail *detail;  | 
766  |  |  | 
767  | 19.8k  |   detail = get_detail(MI);  | 
768  | 19.8k  | #endif  | 
769  |  |  | 
770  | 19.8k  |   const uint16_t opcode = bpf->op;  | 
771  | 19.8k  |   switch (BPF_CLASS(opcode)) { | 
772  | 0  |   default: // will never happen  | 
773  | 0  |     break;  | 
774  | 3.51k  |   case BPF_CLASS_LD:  | 
775  | 5.08k  |   case BPF_CLASS_LDX:  | 
776  | 5.08k  |     if (EBPF_MODE(MI->csh->mode))  | 
777  | 2.92k  |       id = op2insn_ld_ebpf(opcode);  | 
778  | 2.16k  |     else  | 
779  | 2.16k  |       id = op2insn_ld_cbpf(opcode);  | 
780  | 5.08k  |     add_group(MI, BPF_GRP_LOAD);  | 
781  | 5.08k  |     break;  | 
782  | 905  |   case BPF_CLASS_ST:  | 
783  | 2.37k  |   case BPF_CLASS_STX:  | 
784  | 2.37k  |     id = op2insn_st(opcode, bpf->k);  | 
785  | 2.37k  |     add_group(MI, BPF_GRP_STORE);  | 
786  | 2.37k  |     break;  | 
787  | 3.12k  |   case BPF_CLASS_ALU:  | 
788  | 3.12k  |     id = op2insn_alu(opcode, bpf->offset, EBPF_MODE(MI->csh->mode));  | 
789  | 3.12k  |     add_group(MI, BPF_GRP_ALU);  | 
790  | 3.12k  |     break;  | 
791  | 3.48k  |   case BPF_CLASS_JMP:  | 
792  | 3.48k  |     id = op2insn_jmp(opcode);  | 
793  | 3.48k  | #ifndef CAPSTONE_DIET  | 
794  | 3.48k  |     if (id == BPF_INS_CALL || id == BPF_INS_CALLX)  | 
795  | 208  |       add_group(MI, BPF_GRP_CALL);  | 
796  | 3.27k  |     else if (id == BPF_INS_EXIT)  | 
797  | 197  |       add_group(MI, BPF_GRP_RETURN);  | 
798  | 3.08k  |     else  | 
799  | 3.08k  |       add_group(MI, BPF_GRP_JUMP);  | 
800  | 3.48k  | #endif  | 
801  | 3.48k  |     break;  | 
802  | 3.22k  |   case BPF_CLASS_RET:  | 
803  |  |     /* case BPF_CLASS_JMP32: */  | 
804  | 3.22k  |     if (EBPF_MODE(MI->csh->mode)) { | 
805  | 2.61k  |       id = op2insn_jmp(opcode);  | 
806  | 2.61k  |       add_group(MI, BPF_GRP_JUMP);  | 
807  | 2.61k  |     } else { | 
808  | 609  |       id = BPF_INS_RET;  | 
809  | 609  |       add_group(MI, BPF_GRP_RETURN);  | 
810  | 609  |     }  | 
811  | 3.22k  |     break;  | 
812  |  |   // BPF_CLASS_MISC and BPF_CLASS_ALU64 have exactly same value  | 
813  | 2.59k  |   case BPF_CLASS_MISC:  | 
814  |  |     /* case BPF_CLASS_ALU64: */  | 
815  | 2.59k  |     if (EBPF_MODE(MI->csh->mode)) { | 
816  |  |       // ALU64 in eBPF  | 
817  | 2.31k  |       id = op2insn_alu(opcode, bpf->offset, true);  | 
818  | 2.31k  |       add_group(MI, BPF_GRP_ALU);  | 
819  | 2.31k  |     } else { | 
820  | 277  |       if (BPF_MISCOP(opcode) == BPF_MISCOP_TXA)  | 
821  | 68  |         id = BPF_INS_TXA;  | 
822  | 209  |       else  | 
823  | 209  |         id = BPF_INS_TAX;  | 
824  | 277  |       add_group(MI, BPF_GRP_MISC);  | 
825  | 277  |     }  | 
826  | 2.59k  |     break;  | 
827  | 19.8k  |   }  | 
828  |  |  | 
829  | 19.8k  |   if (id == BPF_INS_INVALID)  | 
830  | 33  |     return false;  | 
831  |  |  | 
832  | 19.8k  |   MCInst_setOpcodePub(MI, id);  | 
833  | 19.8k  | #undef PUSH_GROUP  | 
834  |  |  | 
835  | 19.8k  | #ifndef CAPSTONE_DIET  | 
836  | 19.8k  |   if (detail) { | 
837  | 19.8k  |     update_regs_access(MI, detail, id, opcode);  | 
838  | 19.8k  |   }  | 
839  | 19.8k  | #endif  | 
840  | 19.8k  |   return true;  | 
841  | 19.8k  | }  | 
842  |  |  | 
843  |  | bool BPF_getInstruction(csh ud, const uint8_t *code, size_t code_len,  | 
844  |  |       MCInst *instr, uint16_t *size, uint64_t address,  | 
845  |  |       void *info)  | 
846  | 20.3k  | { | 
847  | 20.3k  |   bpf_internal *bpf;  | 
848  |  |  | 
849  | 20.3k  |   if (EBPF_MODE(instr->csh->mode))  | 
850  | 14.4k  |     bpf = fetch_ebpf(instr, code, code_len);  | 
851  | 5.88k  |   else  | 
852  | 5.88k  |     bpf = fetch_cbpf(instr, code, code_len);  | 
853  | 20.3k  |   if (bpf == NULL)  | 
854  | 291  |     return false;  | 
855  | 20.0k  |   if (!getInstruction(instr, bpf) || !setFinalOpcode(instr, bpf)) { | 
856  | 174  |     cs_mem_free(bpf);  | 
857  | 174  |     return false;  | 
858  | 174  |   }  | 
859  | 19.8k  |   MCInst_setOpcode(instr, bpf->op);  | 
860  |  |  | 
861  | 19.8k  |   *size = bpf->insn_size;  | 
862  | 19.8k  |   cs_mem_free(bpf);  | 
863  |  |  | 
864  |  |   return true;  | 
865  | 20.0k  | }  | 
866  |  |  | 
867  |  | #endif  |