/src/capstonev5/arch/BPF/BPFMapping.c
Line  | Count  | Source  | 
1  |  | /* Capstone Disassembly Engine */  | 
2  |  | /* BPF Backend by david942j <david942j@gmail.com>, 2019 */  | 
3  |  |  | 
4  |  | #include <string.h>  | 
5  |  |  | 
6  |  | #include "BPFConstants.h"  | 
7  |  | #include "BPFMapping.h"  | 
8  |  | #include "../../utils.h"  | 
9  |  |  | 
10  |  | #ifndef CAPSTONE_DIET  | 
11  |  | static const name_map group_name_maps[] = { | 
12  |  |   { BPF_GRP_INVALID, NULL }, | 
13  |  |  | 
14  |  |   { BPF_GRP_LOAD, "load" }, | 
15  |  |   { BPF_GRP_STORE, "store" }, | 
16  |  |   { BPF_GRP_ALU, "alu" }, | 
17  |  |   { BPF_GRP_JUMP, "jump" }, | 
18  |  |   { BPF_GRP_CALL, "call" }, | 
19  |  |   { BPF_GRP_RETURN, "return" }, | 
20  |  |   { BPF_GRP_MISC, "misc" }, | 
21  |  | };  | 
22  |  | #endif  | 
23  |  |  | 
24  |  | const char *BPF_group_name(csh handle, unsigned int id)  | 
25  | 34.2k  | { | 
26  | 34.2k  | #ifndef CAPSTONE_DIET  | 
27  | 34.2k  |   return id2name(group_name_maps, ARR_SIZE(group_name_maps), id);  | 
28  |  | #else  | 
29  |  |   return NULL;  | 
30  |  | #endif  | 
31  | 34.2k  | }  | 
32  |  |  | 
33  |  | #ifndef CAPSTONE_DIET  | 
34  |  | static const name_map insn_name_maps[BPF_INS_ENDING] = { | 
35  |  |   { BPF_INS_INVALID, NULL }, | 
36  |  |  | 
37  |  |   { BPF_INS_ADD, "add" }, | 
38  |  |   { BPF_INS_SUB, "sub" }, | 
39  |  |   { BPF_INS_MUL, "mul" }, | 
40  |  |   { BPF_INS_DIV, "div" }, | 
41  |  |   { BPF_INS_OR, "or" }, | 
42  |  |   { BPF_INS_AND, "and" }, | 
43  |  |   { BPF_INS_LSH, "lsh" }, | 
44  |  |   { BPF_INS_RSH, "rsh" }, | 
45  |  |   { BPF_INS_NEG, "neg" }, | 
46  |  |   { BPF_INS_MOD, "mod" }, | 
47  |  |   { BPF_INS_XOR, "xor" }, | 
48  |  |   { BPF_INS_MOV, "mov" }, | 
49  |  |   { BPF_INS_ARSH, "arsh" }, | 
50  |  |  | 
51  |  |   { BPF_INS_ADD64, "add64" }, | 
52  |  |   { BPF_INS_SUB64, "sub64" }, | 
53  |  |   { BPF_INS_MUL64, "mul64" }, | 
54  |  |   { BPF_INS_DIV64, "div64" }, | 
55  |  |   { BPF_INS_OR64, "or64" }, | 
56  |  |   { BPF_INS_AND64, "and64" }, | 
57  |  |   { BPF_INS_LSH64, "lsh64" }, | 
58  |  |   { BPF_INS_RSH64, "rsh64" }, | 
59  |  |   { BPF_INS_NEG64, "neg64" }, | 
60  |  |   { BPF_INS_MOD64, "mod64" }, | 
61  |  |   { BPF_INS_XOR64, "xor64" }, | 
62  |  |   { BPF_INS_MOV64, "mov64" }, | 
63  |  |   { BPF_INS_ARSH64, "arsh64" }, | 
64  |  |  | 
65  |  |   { BPF_INS_LE16, "le16" }, | 
66  |  |   { BPF_INS_LE32, "le32" }, | 
67  |  |   { BPF_INS_LE64, "le64" }, | 
68  |  |   { BPF_INS_BE16, "be16" }, | 
69  |  |   { BPF_INS_BE32, "be32" }, | 
70  |  |   { BPF_INS_BE64, "be64" }, | 
71  |  |  | 
72  |  |   { BPF_INS_LDW, "ldw" }, | 
73  |  |   { BPF_INS_LDH, "ldh" }, | 
74  |  |   { BPF_INS_LDB, "ldb" }, | 
75  |  |   { BPF_INS_LDDW, "lddw" }, | 
76  |  |   { BPF_INS_LDXW, "ldxw" }, | 
77  |  |   { BPF_INS_LDXH, "ldxh" }, | 
78  |  |   { BPF_INS_LDXB, "ldxb" }, | 
79  |  |   { BPF_INS_LDXDW, "ldxdw" }, | 
80  |  |  | 
81  |  |   { BPF_INS_STW, "stw" }, | 
82  |  |   { BPF_INS_STH, "sth" }, | 
83  |  |   { BPF_INS_STB, "stb" }, | 
84  |  |   { BPF_INS_STDW, "stdw" }, | 
85  |  |   { BPF_INS_STXW, "stxw" }, | 
86  |  |   { BPF_INS_STXH, "stxh" }, | 
87  |  |   { BPF_INS_STXB, "stxb" }, | 
88  |  |   { BPF_INS_STXDW, "stxdw" }, | 
89  |  |   { BPF_INS_XADDW, "xaddw" }, | 
90  |  |   { BPF_INS_XADDDW, "xadddw" }, | 
91  |  |  | 
92  |  |   { BPF_INS_JMP, "jmp" }, | 
93  |  |   { BPF_INS_JEQ, "jeq" }, | 
94  |  |   { BPF_INS_JGT, "jgt" }, | 
95  |  |   { BPF_INS_JGE, "jge" }, | 
96  |  |   { BPF_INS_JSET, "jset" }, | 
97  |  |   { BPF_INS_JNE, "jne" }, | 
98  |  |   { BPF_INS_JSGT, "jsgt" }, | 
99  |  |   { BPF_INS_JSGE, "jsge" }, | 
100  |  |   { BPF_INS_CALL, "call" }, | 
101  |  |   { BPF_INS_CALLX, "callx" }, | 
102  |  |   { BPF_INS_EXIT, "exit" }, | 
103  |  |   { BPF_INS_JLT, "jlt" }, | 
104  |  |   { BPF_INS_JLE, "jle" }, | 
105  |  |   { BPF_INS_JSLT, "jslt" }, | 
106  |  |   { BPF_INS_JSLE, "jsle" }, | 
107  |  |  | 
108  |  |   { BPF_INS_RET, "ret" }, | 
109  |  |  | 
110  |  |   { BPF_INS_TAX, "tax" }, | 
111  |  |   { BPF_INS_TXA, "txa" }, | 
112  |  | };  | 
113  |  | #endif  | 
114  |  |  | 
115  |  | const char *BPF_insn_name(csh handle, unsigned int id)  | 
116  | 68.5k  | { | 
117  | 68.5k  | #ifndef CAPSTONE_DIET  | 
118  |  |   /* We have some special cases because 'ld' in cBPF is equivalent to 'ldw'  | 
119  |  |    * in eBPF, and we don't want to see 'ldw' appears in cBPF mode.  | 
120  |  |    */  | 
121  | 68.5k  |   if (!EBPF_MODE(handle)) { | 
122  | 23.9k  |     switch (id) { | 
123  | 4.65k  |     case BPF_INS_LD: return "ld";  | 
124  | 2.17k  |     case BPF_INS_LDX: return "ldx";  | 
125  | 908  |     case BPF_INS_ST: return "st";  | 
126  | 204  |     case BPF_INS_STX: return "stx";  | 
127  | 23.9k  |     }  | 
128  | 23.9k  |   }  | 
129  | 60.6k  |   return id2name(insn_name_maps, ARR_SIZE(insn_name_maps), id);  | 
130  |  | #else  | 
131  |  |   return NULL;  | 
132  |  | #endif  | 
133  | 68.5k  | }  | 
134  |  |  | 
135  |  | const char *BPF_reg_name(csh handle, unsigned int reg)  | 
136  | 45.5k  | { | 
137  | 45.5k  | #ifndef CAPSTONE_DIET  | 
138  | 45.5k  |   if (EBPF_MODE(handle)) { | 
139  | 27.7k  |     if (reg < BPF_REG_R0 || reg > BPF_REG_R10)  | 
140  | 0  |       return NULL;  | 
141  | 27.7k  |     static const char reg_names[11][4] = { | 
142  | 27.7k  |       "r0", "r1", "r2", "r3", "r4",  | 
143  | 27.7k  |       "r5", "r6", "r7", "r8", "r9",  | 
144  | 27.7k  |       "r10"  | 
145  | 27.7k  |     };  | 
146  | 27.7k  |     return reg_names[reg - BPF_REG_R0];  | 
147  | 27.7k  |   }  | 
148  |  |  | 
149  |  |   /* cBPF mode */  | 
150  | 17.8k  |   if (reg == BPF_REG_A)  | 
151  | 12.4k  |     return "a";  | 
152  | 5.41k  |   else if (reg == BPF_REG_X)  | 
153  | 5.41k  |     return "x";  | 
154  | 0  |   else  | 
155  | 0  |     return NULL;  | 
156  |  | #else  | 
157  |  |   return NULL;  | 
158  |  | #endif  | 
159  | 17.8k  | }  | 
160  |  |  | 
161  |  | static bpf_insn op2insn_ld(unsigned opcode)  | 
162  | 8.42k  | { | 
163  | 8.42k  | #define CASE(c) case BPF_SIZE_##c: \  | 
164  | 8.42k  |     if (BPF_CLASS(opcode) == BPF_CLASS_LD) \  | 
165  | 8.42k  |       return BPF_INS_LD##c; \  | 
166  | 8.42k  |     else \  | 
167  | 8.42k  |       return BPF_INS_LDX##c;  | 
168  |  |  | 
169  | 8.42k  |   switch (BPF_SIZE(opcode)) { | 
170  | 4.20k  |   CASE(W);  | 
171  | 1.55k  |   CASE(H);  | 
172  | 1.13k  |   CASE(B);  | 
173  | 1.53k  |   CASE(DW);  | 
174  | 8.42k  |   }  | 
175  | 0  | #undef CASE  | 
176  |  |  | 
177  | 0  |   return BPF_INS_INVALID;  | 
178  | 8.42k  | }  | 
179  |  |  | 
180  |  | static bpf_insn op2insn_st(unsigned opcode)  | 
181  | 4.07k  | { | 
182  |  |   /*  | 
183  |  |    * - BPF_STX | BPF_XADD | BPF_{W,DW} | 
184  |  |    * - BPF_ST* | BPF_MEM | BPF_{W,H,B,DW} | 
185  |  |    */  | 
186  |  |  | 
187  | 4.07k  |   if (opcode == (BPF_CLASS_STX | BPF_MODE_XADD | BPF_SIZE_W))  | 
188  | 522  |     return BPF_INS_XADDW;  | 
189  | 3.54k  |   if (opcode == (BPF_CLASS_STX | BPF_MODE_XADD | BPF_SIZE_DW))  | 
190  | 516  |     return BPF_INS_XADDDW;  | 
191  |  |  | 
192  |  |   /* should be BPF_MEM */  | 
193  | 3.03k  | #define CASE(c) case BPF_SIZE_##c: \  | 
194  | 3.03k  |     if (BPF_CLASS(opcode) == BPF_CLASS_ST) \  | 
195  | 3.03k  |       return BPF_INS_ST##c; \  | 
196  | 3.03k  |     else \  | 
197  | 3.03k  |       return BPF_INS_STX##c;  | 
198  | 3.03k  |   switch (BPF_SIZE(opcode)) { | 
199  | 1.47k  |   CASE(W);  | 
200  | 452  |   CASE(H);  | 
201  | 454  |   CASE(B);  | 
202  | 656  |   CASE(DW);  | 
203  | 3.03k  |   }  | 
204  | 0  | #undef CASE  | 
205  |  |  | 
206  | 0  |   return BPF_INS_INVALID;  | 
207  | 3.03k  | }  | 
208  |  |  | 
209  |  | static bpf_insn op2insn_alu(unsigned opcode)  | 
210  | 8.30k  | { | 
211  |  |   /* Endian is a special case */  | 
212  | 8.30k  |   if (BPF_OP(opcode) == BPF_ALU_END) { | 
213  | 808  |     switch (opcode ^ BPF_CLASS_ALU ^ BPF_ALU_END) { | 
214  | 260  |     case BPF_SRC_LITTLE | (16 << 4):  | 
215  | 260  |       return BPF_INS_LE16;  | 
216  | 68  |     case BPF_SRC_LITTLE | (32 << 4):  | 
217  | 68  |       return BPF_INS_LE32;  | 
218  | 68  |     case BPF_SRC_LITTLE | (64 << 4):  | 
219  | 68  |       return BPF_INS_LE64;  | 
220  | 30  |     case BPF_SRC_BIG | (16 << 4):  | 
221  | 30  |       return BPF_INS_BE16;  | 
222  | 256  |     case BPF_SRC_BIG | (32 << 4):  | 
223  | 256  |       return BPF_INS_BE32;  | 
224  | 126  |     case BPF_SRC_BIG | (64 << 4):  | 
225  | 126  |       return BPF_INS_BE64;  | 
226  | 808  |     }  | 
227  | 0  |     return BPF_INS_INVALID;  | 
228  | 808  |   }  | 
229  |  |  | 
230  | 7.49k  | #define CASE(c) case BPF_ALU_##c: \  | 
231  | 7.49k  |     if (BPF_CLASS(opcode) == BPF_CLASS_ALU) \  | 
232  | 7.49k  |       return BPF_INS_##c; \  | 
233  | 7.49k  |     else \  | 
234  | 7.49k  |       return BPF_INS_##c##64;  | 
235  |  |  | 
236  | 7.49k  |   switch (BPF_OP(opcode)) { | 
237  | 444  |   CASE(ADD);  | 
238  | 386  |   CASE(SUB);  | 
239  | 422  |   CASE(MUL);  | 
240  | 538  |   CASE(DIV);  | 
241  | 726  |   CASE(OR);  | 
242  | 694  |   CASE(AND);  | 
243  | 396  |   CASE(LSH);  | 
244  | 694  |   CASE(RSH);  | 
245  | 1.03k  |   CASE(NEG);  | 
246  | 422  |   CASE(MOD);  | 
247  | 706  |   CASE(XOR);  | 
248  | 398  |   CASE(MOV);  | 
249  | 636  |   CASE(ARSH);  | 
250  | 7.49k  |   }  | 
251  | 0  | #undef CASE  | 
252  |  |  | 
253  | 0  |   return BPF_INS_INVALID;  | 
254  | 7.49k  | }  | 
255  |  |  | 
256  |  | static bpf_insn op2insn_jmp(unsigned opcode)  | 
257  | 5.89k  | { | 
258  | 5.89k  |   if (opcode == (BPF_CLASS_JMP | BPF_JUMP_CALL | BPF_SRC_X)) { | 
259  | 262  |     return BPF_INS_CALLX;  | 
260  | 262  |   }  | 
261  |  |  | 
262  | 5.63k  | #define CASE(c) case BPF_JUMP_##c: return BPF_INS_##c  | 
263  | 5.63k  |   switch (BPF_OP(opcode)) { | 
264  | 908  |   case BPF_JUMP_JA:  | 
265  | 908  |     return BPF_INS_JMP;  | 
266  | 540  |   CASE(JEQ);  | 
267  | 686  |   CASE(JGT);  | 
268  | 536  |   CASE(JGE);  | 
269  | 268  |   CASE(JSET);  | 
270  | 192  |   CASE(JNE);  | 
271  | 196  |   CASE(JSGT);  | 
272  | 240  |   CASE(JSGE);  | 
273  | 520  |   CASE(CALL);  | 
274  | 516  |   CASE(EXIT);  | 
275  | 202  |   CASE(JLT);  | 
276  | 446  |   CASE(JLE);  | 
277  | 194  |   CASE(JSLT);  | 
278  | 5.63k  |   CASE(JSLE);  | 
279  | 5.63k  |   }  | 
280  | 0  | #undef CASE  | 
281  |  |  | 
282  | 0  |   return BPF_INS_INVALID;  | 
283  | 5.63k  | }  | 
284  |  |  | 
285  |  | static void update_regs_access(cs_struct *ud, cs_detail *detail,  | 
286  |  |     bpf_insn insn_id, unsigned int opcode)  | 
287  | 14.4k  | { | 
288  | 14.4k  |   if (insn_id == BPF_INS_INVALID)  | 
289  | 0  |     return;  | 
290  | 14.4k  | #define PUSH_READ(r) do { \ | 
291  | 3.19k  |     detail->regs_read[detail->regs_read_count] = r; \  | 
292  | 3.19k  |     detail->regs_read_count++; \  | 
293  | 3.19k  |   } while (0)  | 
294  | 14.4k  | #define PUSH_WRITE(r) do { \ | 
295  | 5.14k  |     detail->regs_write[detail->regs_write_count] = r; \  | 
296  | 5.14k  |     detail->regs_write_count++; \  | 
297  | 5.14k  |   } while (0)  | 
298  |  |   /*  | 
299  |  |    * In eBPF mode, only these instructions have implicit registers access:  | 
300  |  |    * - legacy ld{w,h,b,dw} * // w: r0 | 
301  |  |    * - exit // r: r0  | 
302  |  |    */  | 
303  | 14.4k  |   if (EBPF_MODE(ud)) { | 
304  | 8.24k  |     switch (insn_id) { | 
305  | 6.61k  |     default:  | 
306  | 6.61k  |       break;  | 
307  | 6.61k  |     case BPF_INS_LDW:  | 
308  | 518  |     case BPF_INS_LDH:  | 
309  | 717  |     case BPF_INS_LDB:  | 
310  | 1.37k  |     case BPF_INS_LDDW:  | 
311  | 1.37k  |       if (BPF_MODE(opcode) == BPF_MODE_ABS || BPF_MODE(opcode) == BPF_MODE_IND) { | 
312  | 984  |         PUSH_WRITE(BPF_REG_R0);  | 
313  | 984  |       }  | 
314  | 1.37k  |       break;  | 
315  | 258  |     case BPF_INS_EXIT:  | 
316  | 258  |       PUSH_READ(BPF_REG_R0);  | 
317  | 258  |       break;  | 
318  | 8.24k  |     }  | 
319  | 8.24k  |     return;  | 
320  | 8.24k  |   }  | 
321  |  |  | 
322  |  |   /* cBPF mode */  | 
323  | 6.16k  |   switch (BPF_CLASS(opcode)) { | 
324  | 595  |   default:  | 
325  | 595  |     break;  | 
326  | 1.88k  |   case BPF_CLASS_LD:  | 
327  | 1.88k  |     PUSH_WRITE(BPF_REG_A);  | 
328  | 1.88k  |     break;  | 
329  | 486  |   case BPF_CLASS_LDX:  | 
330  | 486  |     PUSH_WRITE(BPF_REG_X);  | 
331  | 486  |     break;  | 
332  | 386  |   case BPF_CLASS_ST:  | 
333  | 386  |     PUSH_READ(BPF_REG_A);  | 
334  | 386  |     break;  | 
335  | 68  |   case BPF_CLASS_STX:  | 
336  | 68  |     PUSH_READ(BPF_REG_X);  | 
337  | 68  |     break;  | 
338  | 1.32k  |   case BPF_CLASS_ALU:  | 
339  | 1.32k  |     PUSH_READ(BPF_REG_A);  | 
340  | 1.32k  |     PUSH_WRITE(BPF_REG_A);  | 
341  | 1.32k  |     break;  | 
342  | 957  |   case BPF_CLASS_JMP:  | 
343  | 957  |     if (insn_id != BPF_INS_JMP) // except the unconditional jump  | 
344  | 698  |       PUSH_READ(BPF_REG_A);  | 
345  | 957  |     break;  | 
346  |  |   /* case BPF_CLASS_RET: */  | 
347  | 465  |   case BPF_CLASS_MISC:  | 
348  | 465  |     if (insn_id == BPF_INS_TAX) { | 
349  | 283  |       PUSH_READ(BPF_REG_A);  | 
350  | 283  |       PUSH_WRITE(BPF_REG_X);  | 
351  | 283  |     }  | 
352  | 182  |     else { | 
353  | 182  |       PUSH_READ(BPF_REG_X);  | 
354  | 182  |       PUSH_WRITE(BPF_REG_A);  | 
355  | 182  |     }  | 
356  | 465  |     break;  | 
357  | 6.16k  |   }  | 
358  | 6.16k  | }  | 
359  |  |  | 
360  |  | /*  | 
361  |  |  * 1. Convert opcode(id) to BPF_INS_*  | 
362  |  |  * 2. Set regs_read/regs_write/groups  | 
363  |  |  */  | 
364  |  | void BPF_get_insn_id(cs_struct *ud, cs_insn *insn, unsigned int opcode)  | 
365  | 28.8k  | { | 
366  |  |   // No need to care the mode (cBPF or eBPF) since all checks has be done in  | 
367  |  |   // BPF_getInstruction, we can simply map opcode to BPF_INS_*.  | 
368  | 28.8k  |   cs_detail *detail;  | 
369  | 28.8k  |   bpf_insn id = BPF_INS_INVALID;  | 
370  | 28.8k  |   bpf_insn_group grp;  | 
371  |  |  | 
372  | 28.8k  |   detail = insn->detail;  | 
373  | 28.8k  | #ifndef CAPSTONE_DIET  | 
374  | 28.8k  |  #define PUSH_GROUP(grp) do { \ | 
375  | 28.8k  |     if (detail) { \ | 
376  | 14.4k  |       detail->groups[detail->groups_count] = grp; \  | 
377  | 14.4k  |       detail->groups_count++; \  | 
378  | 14.4k  |     } \  | 
379  | 28.8k  |   } while(0)  | 
380  |  | #else  | 
381  |  |  #define PUSH_GROUP  | 
382  |  | #endif  | 
383  |  |  | 
384  | 28.8k  |   switch (BPF_CLASS(opcode)) { | 
385  | 0  |   default:  // will never happen  | 
386  | 0  |     break;  | 
387  | 6.52k  |   case BPF_CLASS_LD:  | 
388  | 8.42k  |   case BPF_CLASS_LDX:  | 
389  | 8.42k  |     id = op2insn_ld(opcode);  | 
390  | 8.42k  |     PUSH_GROUP(BPF_GRP_LOAD);  | 
391  | 8.42k  |     break;  | 
392  | 1.79k  |   case BPF_CLASS_ST:  | 
393  | 4.07k  |   case BPF_CLASS_STX:  | 
394  | 4.07k  |     id = op2insn_st(opcode);  | 
395  | 4.07k  |     PUSH_GROUP(BPF_GRP_STORE);  | 
396  | 4.07k  |     break;  | 
397  | 5.11k  |   case BPF_CLASS_ALU:  | 
398  | 5.11k  |     id = op2insn_alu(opcode);  | 
399  | 5.11k  |     PUSH_GROUP(BPF_GRP_ALU);  | 
400  | 5.11k  |     break;  | 
401  | 5.89k  |   case BPF_CLASS_JMP:  | 
402  | 5.89k  |     grp = BPF_GRP_JUMP;  | 
403  | 5.89k  |     id = op2insn_jmp(opcode);  | 
404  | 5.89k  |     if (id == BPF_INS_CALL || id == BPF_INS_CALLX)  | 
405  | 782  |       grp = BPF_GRP_CALL;  | 
406  | 5.11k  |     else if (id == BPF_INS_EXIT)  | 
407  | 516  |       grp = BPF_GRP_RETURN;  | 
408  | 5.89k  |     PUSH_GROUP(grp);  | 
409  | 5.89k  |     break;  | 
410  | 1.19k  |   case BPF_CLASS_RET:  | 
411  | 1.19k  |     id = BPF_INS_RET;  | 
412  | 1.19k  |     PUSH_GROUP(BPF_GRP_RETURN);  | 
413  | 1.19k  |     break;  | 
414  |  |   // BPF_CLASS_MISC and BPF_CLASS_ALU64 have exactly same value  | 
415  | 4.12k  |   case BPF_CLASS_MISC:  | 
416  |  |   /* case BPF_CLASS_ALU64: */  | 
417  | 4.12k  |     if (EBPF_MODE(ud)) { | 
418  |  |       // ALU64 in eBPF  | 
419  | 3.19k  |       id = op2insn_alu(opcode);  | 
420  | 3.19k  |       PUSH_GROUP(BPF_GRP_ALU);  | 
421  | 3.19k  |     }  | 
422  | 930  |     else { | 
423  | 930  |       if (BPF_MISCOP(opcode) == BPF_MISCOP_TXA)  | 
424  | 364  |         id = BPF_INS_TXA;  | 
425  | 566  |       else  | 
426  | 566  |         id = BPF_INS_TAX;  | 
427  | 930  |       PUSH_GROUP(BPF_GRP_MISC);  | 
428  | 930  |     }  | 
429  | 4.12k  |     break;  | 
430  | 28.8k  |   }  | 
431  |  |  | 
432  | 28.8k  |   insn->id = id;  | 
433  | 28.8k  | #undef PUSH_GROUP  | 
434  |  |  | 
435  | 28.8k  | #ifndef CAPSTONE_DIET  | 
436  | 28.8k  |   if (detail) { | 
437  | 14.4k  |     update_regs_access(ud, detail, id, opcode);  | 
438  | 14.4k  |   }  | 
439  | 28.8k  | #endif  | 
440  | 28.8k  | }  | 
441  |  |  | 
442  |  | static void sort_and_uniq(cs_regs arr, uint8_t n, uint8_t *new_n)  | 
443  | 0  | { | 
444  |  |   /* arr is always a tiny (usually n < 3) array,  | 
445  |  |    * a simple O(n^2) sort is efficient enough. */  | 
446  | 0  |   int i;  | 
447  | 0  |   int j;  | 
448  | 0  |   int iMin;  | 
449  | 0  |   int tmp;  | 
450  |  |  | 
451  |  |   /* a modified selection sort for sorting and making unique */  | 
452  | 0  |   for (j = 0; j < n; j++) { | 
453  |  |     /* arr[iMin] will be min(arr[j .. n-1]) */  | 
454  | 0  |     iMin = j;  | 
455  | 0  |     for (i = j + 1; i < n; i++) { | 
456  | 0  |       if (arr[i] < arr[iMin])  | 
457  | 0  |         iMin = i;  | 
458  | 0  |     }  | 
459  | 0  |     if (j != 0 && arr[iMin] == arr[j - 1]) { // duplicate ele found | 
460  | 0  |       arr[iMin] = arr[n - 1];  | 
461  | 0  |       --n;  | 
462  | 0  |     }  | 
463  | 0  |     else { | 
464  | 0  |       tmp = arr[iMin];  | 
465  | 0  |       arr[iMin] = arr[j];  | 
466  | 0  |       arr[j] = tmp;  | 
467  | 0  |     }  | 
468  | 0  |   }  | 
469  |  | 
  | 
470  | 0  |   *new_n = n;  | 
471  | 0  | }  | 
472  |  | void BPF_reg_access(const cs_insn *insn,  | 
473  |  |     cs_regs regs_read, uint8_t *regs_read_count,  | 
474  |  |     cs_regs regs_write, uint8_t *regs_write_count)  | 
475  | 0  | { | 
476  | 0  |   unsigned i;  | 
477  | 0  |   uint8_t read_count, write_count;  | 
478  | 0  |   const cs_bpf *bpf = &(insn->detail->bpf);  | 
479  |  | 
  | 
480  | 0  |   read_count = insn->detail->regs_read_count;  | 
481  | 0  |   write_count = insn->detail->regs_write_count;  | 
482  |  |  | 
483  |  |   // implicit registers  | 
484  | 0  |   memcpy(regs_read, insn->detail->regs_read, read_count * sizeof(insn->detail->regs_read[0]));  | 
485  | 0  |   memcpy(regs_write, insn->detail->regs_write, write_count * sizeof(insn->detail->regs_write[0]));  | 
486  |  | 
  | 
487  | 0  |   for (i = 0; i < bpf->op_count; i++) { | 
488  | 0  |     const cs_bpf_op *op = &(bpf->operands[i]);  | 
489  | 0  |     switch (op->type) { | 
490  | 0  |     default:  | 
491  | 0  |       break;  | 
492  | 0  |     case BPF_OP_REG:  | 
493  | 0  |       if (op->access & CS_AC_READ) { | 
494  | 0  |         regs_read[read_count] = op->reg;  | 
495  | 0  |         read_count++;  | 
496  | 0  |       }  | 
497  | 0  |       if (op->access & CS_AC_WRITE) { | 
498  | 0  |         regs_write[write_count] = op->reg;  | 
499  | 0  |         write_count++;  | 
500  | 0  |       }  | 
501  | 0  |       break;  | 
502  | 0  |     case BPF_OP_MEM:  | 
503  | 0  |       if (op->mem.base != BPF_REG_INVALID) { | 
504  | 0  |         regs_read[read_count] = op->mem.base;  | 
505  | 0  |         read_count++;  | 
506  | 0  |       }  | 
507  | 0  |       break;  | 
508  | 0  |     }  | 
509  | 0  |   }  | 
510  |  |  | 
511  | 0  |   sort_and_uniq(regs_read, read_count, regs_read_count);  | 
512  | 0  |   sort_and_uniq(regs_write, write_count, regs_write_count);  | 
513  | 0  | }  |