Source code of Windows XP (NT5)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

1228 lines
32 KiB

  1. /* disasm.c
  2. Future Features -
  3. Current bugs -
  4. Data32 for
  5. (callf fword ptr [mem]), (jmpf fword ptr [mem])
  6. Floating point insns
  7. Call not tested
  8. jecxz disassembled as large_address, not large_data
  9. lidt/lgdt are 6-byte operands
  10. segload doesn't set memXxxxx vars
  11. some 0x0f opcodes should set gpSafe flag
  12. bt, bts, btr, btc
  13. SetBcc [mem]
  14. SHD[l,r]
  15. */
  16. #include <string.h>
  17. #include <windows.h> /* wsprintf() */
  18. #include "disasm.h"
  19. #define STATIC /* static */
  20. STATIC byte lookup[256]; /* lookup table for first byte of opcode */
  21. STATIC int dataSize, adrSize, /* flag to indicate 32 bit data/code */
  22. segSize; /* flag if 32 bit code segment */
  23. STATIC char *preSeg = ""; /* segment prefix string */
  24. /* static char *prefix = ""; /* REP/REPE prefix string */
  25. enum { /* operand decoding classes */
  26. UNK, NOOP, BREG, VREG, SREG, BWI, BRI, WRI,
  27. SMOV, IMOV, IBYTE, IWORD, JMPW, JMPB, LEA, JCond,
  28. GrpF, Grp1, Grp2, Grp3, Grp4, Grp5, IADR, MOVABS,
  29. RRM, RRMW, IMUL, POPMEM, TEST, ENTER, FLOP, ARPL,
  30. INOUT, IWORD1, ASCII, XLAT,
  31. };
  32. STATIC char bregs[8][3] = {"al", "cl", "dl", "bl", "ah", "ch", "dh", "bh"};
  33. STATIC char wregs[8][3] = {"ax", "cx", "dx", "bx", "sp", "bp", "si", "di"};
  34. STATIC char dregs[8][4] = {"eax", "ecx", "edx", "ebx", "esp", "ebp", "esi", "edi"};
  35. STATIC char sregs[8][3] = {"es", "cs", "ss", "ds", "fs", "gs", "?", "?"};
  36. STATIC char grp1[8][4] = {"add", "or", "adc", "sbb", "and", "sub", "xor", "cmp"};
  37. STATIC char grp2[8][4] = {"rol", "ror", "rcl", "rcr", "shl", "shr", "shl", "sar"};
  38. STATIC char grp3[8][5] = {"test", "?", "not", "neg", "mul", "imul", "div", "idiv"};
  39. STATIC char grp5[8][6] = {"inc", "dec", "call", "callf", "jmp", "jmpf", "push", "?"};
  40. STATIC char grp6[8][5] = {"sldt", "str", "lldt", "ltr", "verr", "verw", "?", "?"};
  41. STATIC char grp7[8][7] = {"sgdt", "sidt", "lgdt", "lidt", "smsw", "?", "lmsw", "invlpg"};
  42. STATIC char grp8[8][4] = {"?", "?", "?", "?", "bt", "bts", "btr", "btc"};
  43. STATIC char *jcond[] = {"jo", "jno", "jb", "jae", "jz", "jnz", "jbe", "ja",
  44. "js", "jns", "jp", "jnp", "jl", "jge", "jle", "jg"};
  45. #define opBase 0
  46. STATIC struct {
  47. char *name; /* opcode mnemonic */
  48. byte base, count; /* first table entry, number of entries */
  49. byte operand; /* operand class */
  50. } ops[] = {
  51. "?UNKNOWN", 0, 0, UNK, "add", 0x00, 6, BWI,
  52. "or", 0x08, 6, BWI, "FGrp", 0x0f, 1, GrpF,
  53. "adc", 0x10, 6, BWI, "sbb", 0x18, 6, BWI,
  54. "and", 0x20, 6, BWI, "sub", 0x28, 6, BWI,
  55. "xor", 0x30, 6, BWI, "cmp", 0x38, 6, BWI,
  56. "inc", 0x40, 8, VREG, "dec", 0x48, 8, VREG,
  57. "push", 0x50, 8, VREG, "pop", 0x58, 8, VREG,
  58. "bound", 0x62, 1, RRMW, "arpl", 0x63, 1, ARPL,
  59. "push", 0x68, 1, IWORD, "imul", 0x69, 3, IMUL,
  60. "push", 0x6a, 1, IBYTE, "jcond", 0x70, 16, JCond,
  61. "Grp1", 0x80, 4, Grp1, "test", 0x84, 2, RRM,
  62. "xchg", 0x86, 2, RRM, "mov", 0x88, 4, BWI,
  63. "mov", 0x8c, 3, SMOV, "lea", 0x8d, 1, LEA,
  64. "pop", 0x8f, 1, POPMEM, "xchg", 0x90, 8, VREG,
  65. "callf", 0x9a, 1, IADR, "mov", 0xa0, 4, MOVABS,
  66. "test", 0xa8, 2, TEST, "mov", 0xb0, 8, BRI,
  67. "mov", 0xb8, 8, WRI, "Grp2", 0xc0, 2, Grp2,
  68. "retn", 0xc2, 1, IWORD1, "les", 0xc4, 1, RRMW,
  69. "lds", 0xc5, 1, RRMW, "mov", 0xc6, 2, IMOV,
  70. "enter", 0xc8, 1, ENTER, "retf", 0xca, 1, IWORD1,
  71. "int", 0xcd, 1, IBYTE, "Grp2", 0xd0, 4, Grp2,
  72. "aam", 0xd4, 1, ASCII, "aad", 0xd5, 1, ASCII,
  73. "xlat", 0xd7, 1, XLAT,
  74. "float", 0xd8, 8, FLOP, "loopne", 0xe0, 1, JMPB,
  75. "loope", 0xe1, 1, JMPB, "loop", 0xe2, 1, JMPB,
  76. "jcxz", 0xe3, 1, JMPB, "in", 0xe4, 2, INOUT,
  77. "out", 0xe6, 2, INOUT, "call", 0xe8, 1, JMPW,
  78. "jmp", 0xe9, 1, JMPW, "jmpf", 0xea, 1, IADR,
  79. "jmp", 0xeb, 1, JMPB, "Grp3", 0xf6, 2, Grp3,
  80. "Grp4", 0xfe, 1, Grp4, "Grp5", 0xff, 1, Grp5,
  81. };
  82. #define opCnt (sizeof(ops)/sizeof(ops[0]))
  83. #define simpleBase (opBase + opCnt)
  84. STATIC struct { /* these are single byte opcodes, no decode */
  85. byte val;
  86. char *name;
  87. } simple[] = {
  88. 0x06, "push es",
  89. 0x07, "pop es",
  90. 0x0e, "push cs",
  91. 0x16, "push ss",
  92. 0x17, "pop ss",
  93. 0x1e, "push ds",
  94. 0x1f, "pop ds",
  95. 0x27, "daa",
  96. 0x2f, "das",
  97. 0x37, "aaa",
  98. 0x3f, "aas",
  99. 0x90, "nop",
  100. 0x9b, "wait",
  101. 0x9e, "sahf",
  102. 0x9f, "lahf",
  103. 0xc3, "retn",
  104. 0xc9, "leave",
  105. 0xcb, "retf",
  106. 0xcc, "int 3",
  107. 0xce, "into",
  108. 0xec, "in al, dx",
  109. 0xee, "out dx, al",
  110. 0xf0, "lock",
  111. 0xf2, "repne",
  112. 0xf3, "rep/repe",
  113. 0xf4, "hlt",
  114. 0xf5, "cmc",
  115. 0xf8, "clc",
  116. 0xf9, "stc",
  117. 0xfa, "cli",
  118. 0xfb, "sti",
  119. 0xfc, "cld",
  120. 0xfd, "std",
  121. };
  122. #define simpleCnt (sizeof(simple)/sizeof(simple[0]))
  123. #define dSimpleBase (simpleBase + simpleCnt)
  124. STATIC struct { /* these are simple opcodes that change */
  125. byte val; /* based on current data size */
  126. char *name, *name32;
  127. } dsimple[] = {
  128. 0x60, "pusha", "pushad",
  129. 0x61, "popa", "popad",
  130. 0x98, "cbw", "cwde",
  131. 0x99, "cwd", "cdq",
  132. 0x9c, "pushf", "pushfd",
  133. 0x9d, "popf", "popfd",
  134. 0xcf, "iret", "iretd",
  135. 0xed, "in ax, dx", "in eax, dx",
  136. 0xef, "out dx, ax", "out dx, eax",
  137. };
  138. #define dSimpleCnt (sizeof(dsimple)/sizeof(dsimple[0]))
  139. #define STR_S 1 /* string op, source regs */
  140. #define STR_D 2 /* string op, dest regs */
  141. #define STR_D_Read 4 /* string op, reads from dest regs */
  142. #define STR_NO_COND 8 /* rep ignores flags */
  143. #define stringOpBase (dSimpleBase+ dSimpleCnt)
  144. STATIC struct {
  145. byte val;
  146. char *name;
  147. byte flag; /* should be 'next' to op, to pack nicely */
  148. } stringOp[] = {
  149. 0x6c, "ins", STR_D | STR_NO_COND,
  150. 0x6e, "outs", STR_S | STR_NO_COND,
  151. 0xa4, "movs", STR_S | STR_D | STR_NO_COND,
  152. 0xa6, "cmps", STR_S | STR_D | STR_D_Read,
  153. 0xaa, "stos", STR_D | STR_NO_COND,
  154. 0xac, "lods", STR_S | STR_NO_COND,
  155. 0xae, "scas", STR_D | STR_D_Read,
  156. };
  157. #define stringOpCnt (sizeof(stringOp)/sizeof(stringOp[0]))
  158. STATIC void InitDisAsm86(void) {
  159. int i, j;
  160. for (i=0; i<opCnt; i++) { /* Init complex entries */
  161. for (j=0; j<(int)ops[i].count; j++)
  162. lookup[ops[i].base+j] = (byte)i + opBase;
  163. }
  164. for (i=0; i<simpleCnt; i++) /* Init simple entries */
  165. lookup[simple[i].val] = (byte)(i + simpleBase);
  166. for (i=0; i<dSimpleCnt; i++) /* Init simple 16/32 bit entries */
  167. lookup[dsimple[i].val] = (byte)(i + dSimpleBase);
  168. for (i=0; i<stringOpCnt; i++) { /* Init string op table */
  169. lookup[stringOp[i].val] = (byte)(i + stringOpBase);
  170. lookup[stringOp[i].val+1] = (byte)(i + stringOpBase);
  171. }
  172. } /* InitDisAsm86 */
  173. STATIC byte far *code; /* this is ugly - it saves passing current */
  174. /* code position to all the GetByte() funcs */
  175. #define Mid(v) (((v) >> 3) & 7) /* extract middle 3 bits from a byte */
  176. word gpSafe, gpRegs, gpStack; /* indicate side effects of instruction */
  177. extern word regs[]; /* this is a lie - this is really a struct - */
  178. extern dword regs32[]; /* and so is this - but array access is more */
  179. /* convenient in this module */
  180. /* If you don't want to return memory access info, #def NO_MEM */
  181. #if !defined(NO_MEM)
  182. /* global vars set by DisAsm() to indicate current instruction's memory */
  183. /* access type. */
  184. word memSeg, memSize, memOp; /* segment value, operand size, operation */
  185. word memSeg2, memSize2, memOp2, /* instruction may have two memory accesses */
  186. memDouble;
  187. dword memLinear, memLinear2; /* offset from segment of access */
  188. STATIC dword memReg, memDisp; /* used to pass information from GetReg()... */
  189. char *memName[] = { /* used to convert 'enum memOp' to ascii */
  190. "NOP",
  191. "Read",
  192. "Write",
  193. "RMW",
  194. "MovStr",
  195. };
  196. #define SetMemSize(s) memSize = s
  197. #define SetMemSeg(s) memSeg = regs[s+9]
  198. #define SetMemOp(o) memOp = o
  199. #define SetMemLinear(l) memLinear = l
  200. #define SetMemSeg2(s) memSeg2 = regs[s+9]
  201. #define SetMemOp2(o) memOp2 = o
  202. #define SetMemLinear2(l) memLinear2 = l
  203. #define ModMemLinear(l) memLinear += l
  204. #define SetMemReg(r) memReg = r
  205. #define SetMemDisp(d) memDisp = d
  206. #define Read_RMW(o) ((o) ? memRead : memRMW)
  207. #else
  208. #define SetMemSeg(s)
  209. #define SetMemSize(s)
  210. #define SetMemOp(o)
  211. #define SetMemLinear(l)
  212. #define SetMemSeg2(s)
  213. #define SetMemOp2(o)
  214. #define SetMemLinear2(l)
  215. #define ModMemLinear(l)
  216. #define SetMemReg(r)
  217. #define SetMemDisp(d)
  218. #define Read_RMW(o) 0
  219. #endif
  220. /******************** Register Decode *******************************/
  221. /* These helper functions return char pointers to register names.
  222. They are safe to call multiple times, as the return values are not
  223. stored in a single buffer. The ?Reg() functions are passed a register
  224. number. They mask this with 7, so you can pass in the raw opcode.
  225. The ?Mid() functions extract the register field from e.g. a ModRM byte.
  226. The Vxxx() functions look at dataSize to choose between 16 and 32 bit
  227. registers. The Xxxx() functions look at the passed in W bit, and then
  228. the dataSize global, do decide between 8, 16, and 32 bit registers.
  229. */
  230. STATIC char *BReg(int reg) { /* Byte Registers */
  231. reg &= 7;
  232. SetMemReg(((byte *)regs)[reg]);
  233. return bregs[reg];
  234. } /* BReg */
  235. STATIC char *BMid(int reg) {
  236. return BReg(Mid(reg));
  237. } /* BMid */
  238. STATIC char *WReg(int reg) { /* Word Registers */
  239. reg &= 7;
  240. SetMemReg(regs[reg]);
  241. return wregs[reg];
  242. } /* WReg */
  243. /* STATIC char *WMid(int op) {
  244. return WReg(Mid(op));
  245. } /* WMid */
  246. STATIC char *DReg(int reg) { /* DWord Registers */
  247. reg &= 7;
  248. SetMemReg(regs32[reg]);
  249. return dregs[reg];
  250. } /* DReg */
  251. STATIC char *DMid(int op) {
  252. return DReg(Mid(op));
  253. } /* DMid */
  254. STATIC char *VReg(int reg) { /* Word or DWord Registers */
  255. if (dataSize) return DReg(reg);
  256. return WReg(reg);
  257. } /* VReg */
  258. STATIC char *VMid(int op) {
  259. return VReg(Mid(op));
  260. } /* VMid */
  261. STATIC char *XReg(int w, int reg) { /* Byte, Word, DWord Registers */
  262. if (!w) return BReg(reg);
  263. return VReg(reg);
  264. } /* XReg */
  265. STATIC char *XMid(int w, int op) {
  266. return XReg(w, Mid(op));
  267. } /* XMid */
  268. /************************* Opcode Fetch ***************************/
  269. /* hexData is a global array, containing a hexadecimal dump of the */
  270. /* opcodes of the last instruction disassembled. */
  271. char hexData[40]; /* We dump the opcode fetched here */
  272. STATIC int hexPos; /* current position in hexData buffer */
  273. /* GetByte(), GetWord(), and GetDWord() read from the code segment */
  274. /* and increment the pointer appropriately. They also add the current */
  275. /* value to the hexData display, and set the MemDisp global in case the */
  276. /* value fetched was a memory displacement */
  277. STATIC byte GetByte(void) { /* Read one byte from code segment */
  278. sprintf(hexData+hexPos, " %02x", *code);
  279. hexPos += 3;
  280. SetMemDisp(*code);
  281. return *code++;
  282. } /* GetByte */
  283. STATIC word GetWord(void) { /* Read two bytes from code seg */
  284. word w = *(word far *)code;
  285. sprintf(hexData+hexPos, " %04x", w);
  286. hexPos += 5;
  287. code += 2;
  288. SetMemDisp(w);
  289. return w;
  290. } /* GetWord */
  291. STATIC long GetDWord(void) { /* Read four bytes from code seg */
  292. unsigned long l = *(long far *)code;
  293. sprintf(hexData+hexPos, " %08lx", l);
  294. hexPos += 9;
  295. code += 4;
  296. SetMemDisp(l);
  297. return l;
  298. } /* GetDWord */
  299. STATIC char immData[9]; /* Get Immediate values from code */
  300. /* GetImmByte(), GetImmWord(), and GetImmDWord() all get the proper size */
  301. /* data object, convert it to hex/ascii, and return the string created. */
  302. /* They return a pointer to a shared static object, so don't combine */
  303. /* multiple calls to these functions in a single expression. */
  304. STATIC char *GetImmByte(void) {
  305. sprintf(immData, "%02x", GetByte());
  306. return immData;
  307. } /* GetImmByte */
  308. STATIC char *GetSImmByte(void) {
  309. sprintf(immData, "%02x", (char)GetByte());
  310. memDisp = (signed char)memDisp; /* sign extend */
  311. return immData;
  312. } /* GetSImmByte */
  313. STATIC char *GetImmWord(void) {
  314. sprintf(immData, "%04x", GetWord());
  315. return immData;
  316. } /* GetImmWord */
  317. STATIC char *GetImmDWord(void) {
  318. sprintf(immData, "%08lx", GetDWord());
  319. return immData;
  320. } /* GetImmDWord */
  321. /* GetImmAdr() and GetImmData() call GetImm????() as required by the */
  322. /* 'width' flag passed in, and the adrSize or dataSize global flags. */
  323. /* They return the proper character string - note that these just call */
  324. /* GetImm????(), and use the same static buffer, so don't call more than */
  325. /* once in a single expression */
  326. STATIC char *GetImmAdr(int w) { /* Get an immediate address value */
  327. if (!w) return GetImmByte();
  328. else if (!adrSize) return GetImmWord();
  329. return GetImmDWord();
  330. } /* GetImmAdr */
  331. STATIC char *GetImmData(int w) { /* Get an immediate data value */
  332. if (!w) return GetImmByte();
  333. else if (!dataSize) return GetImmWord();
  334. return GetImmDWord();
  335. } /* GetImmData */
  336. /************************* Helper Functions **************************/
  337. STATIC char *JRel(int jsize) { /* Perform relative jump sizing */
  338. long rel;
  339. static char adr[9];
  340. char *s;
  341. if (jsize < 2) {
  342. rel = (char)GetByte();
  343. s = "short ";
  344. } else if (!adrSize) {
  345. rel = (short)GetWord();
  346. s = "near ";
  347. } else {
  348. rel = GetDWord();
  349. s = "";
  350. }
  351. rel += (word)(long)code;
  352. sprintf(adr, adrSize ? "%s%08lx" : "%s%04lx", (FP)s, rel);
  353. return adr;
  354. } /* JRel */
  355. enum {
  356. RegAX, RegCX, RegDX, RegBX, RegSP, RegBP, RegSI, RegDI
  357. };
  358. #define Reg1(r1) (r1) | 0x80
  359. #define Reg2(r1, r2) (r1 | (r2 << 4))
  360. #define RegSS 8
  361. STATIC byte rms[] = { /* 16 bit addressing modes */
  362. Reg2(RegBX, RegSI),
  363. Reg2(RegBX, RegDI),
  364. Reg2(RegBP|RegSS, RegSI), /* if base reg is BP, def seg is SS */
  365. Reg2(RegBP|RegSS, RegDI),
  366. Reg1(RegSI),
  367. Reg1(RegDI),
  368. Reg1(RegBP|RegSS),
  369. Reg1(RegBX),
  370. };
  371. /* Based on the second byte of opcode, width flag, adrSize and dataSize, */
  372. /* determine the disassembly of the current instruction, and what */
  373. /* memory address was referenced */
  374. /* needinfo indicates that we need a size override on a memory operand */
  375. /* for example, "mov [bx], ax" is obviously a 16 bit move, while */
  376. /* "mov [bx], 0" could be 8, 16, or 32 bit. We add the proper */
  377. /* "mov word ptr [bx], 0" information. */
  378. /* The 'mem' parameter indicates the kind of operation, Read, Write, RMW */
  379. /* don't bother trying to understand this code without an Intel manual */
  380. /* and assembler nearby. :-) */
  381. STATIC char *ModRMGeneral(byte op, int w, int needInfo, int mem) {
  382. static char m[30]; /* write result to this static buf */
  383. int mod = op >> 6;
  384. int rm = op & 7;
  385. char *size, *base, *index, *disp;
  386. char indexBuf[6];
  387. base = index = disp = "";
  388. if (!w) { /* set mem size, and info string */
  389. size = "byte ptr ";
  390. SetMemSize(1);
  391. } else if (!dataSize) {
  392. size = "word ptr ";
  393. SetMemSize(2);
  394. } else {
  395. size = "dword ptr ";
  396. SetMemSize(4);
  397. }
  398. if (!needInfo) size = ""; /* never-mind */
  399. if (adrSize) { /* do 32 bit addressing */
  400. if (mod == 3) return XReg(w, rm); /* register operand */
  401. if (rm == 4) { /* [esp+?] is special S-I-B style */
  402. byte sib = GetByte();
  403. int scaleVal = sib >> 6, indexVal = Mid(sib), baseVal = sib & 7;
  404. SetMemLinear(0);
  405. if (baseVal == 5 && mod == 0) /* [ebp+{s_i}] becomes [d32+{s_i}] */
  406. mod = 2;
  407. else {
  408. base = DReg(baseVal);
  409. ModMemLinear(memReg);
  410. }
  411. if (indexVal != 4) { /* [base+esp*X] is undefined */
  412. sprintf(indexBuf, "%s*%d", (FP)DMid(sib), 1 << scaleVal);
  413. index = indexBuf;
  414. ModMemLinear(memReg << scaleVal);
  415. }
  416. } else { /* not S-I-B */
  417. if (mod == 0 && rm == 5) mod = 2; /* [ebp] becomes [d32] */
  418. else base = DReg(rm);
  419. }
  420. if (mod==1) disp = GetImmAdr(0);
  421. else if (mod == 2) disp = GetImmAdr(1);
  422. if (mod) ModMemLinear(memDisp);
  423. } else { /* do 16 bit addressing */
  424. if (mod == 3) return XReg(w, rm); /* register operand */
  425. if (mod == 0 && rm == 6) { /* [bp] becomes [mem16] */
  426. disp = GetImmAdr(1);
  427. SetMemLinear(memDisp);
  428. } else {
  429. base = WReg(rms[rm] & 7);
  430. SetMemLinear(memReg);
  431. if (!(rms[rm] & 0x80)) { /* if two-reg effective address */
  432. index = WReg(rms[rm] >> 4);
  433. ModMemLinear(memReg);
  434. }
  435. if (rms[rm] & RegSS && !preSeg[0]) { /* BP is relative to SS */
  436. SetMemSeg(memSS);
  437. }
  438. if (mod) { /* (mod3 already returned) */
  439. disp = GetImmAdr(mod-1); /* mod==1 is byte, mod==2 is (d)word */
  440. ModMemLinear(memDisp);
  441. }
  442. }
  443. }
  444. sprintf(m, "%s%s[%s", (FP)size, (FP)preSeg, (FP)base);
  445. if (*index) strcat(strcat(m, "+"), index);
  446. if (*disp) {
  447. if (*base || *index) strcat(m, "+");
  448. strcat(m, disp);
  449. }
  450. SetMemOp(mem);
  451. strcat(m, "]");
  452. return m;
  453. } /* ModRMGeneral */
  454. /* magic func that sets 'info-required' flag to ModRMGeneral */
  455. STATIC char *ModRMInfo(byte op, int w, int mem) {
  456. return ModRMGeneral(op, w, 1, mem);
  457. } /* ModRMInfo */
  458. /* magic func that doesn't require info */
  459. STATIC char *ModRM(byte op, int w, int mem) {
  460. return ModRMGeneral(op, w, 0, mem);
  461. } /* ModRM */
  462. STATIC char line[80]; /* this is bad - global var where insn is created */
  463. /* CatX() - combine opcode and 0 to 3 operands, store in line[] */
  464. /* It places the TAB after the opcode, and ', ' between operands */
  465. STATIC char *Cat0(char *s0) {
  466. return strcat(line, s0);
  467. #if 0
  468. if (prefix[0]) {
  469. char temp[80];
  470. if (s0 == line) {
  471. strcpy(temp, s0);
  472. s0 = temp;
  473. }
  474. strcat(strcpy(line, prefix), s0);
  475. prefix = "";
  476. } else strcpy(line, s0);
  477. return line;
  478. #endif
  479. } /* Cat0 */
  480. STATIC char *Cat1(char *s0, char *s1) {
  481. return strcat(strcat(Cat0(s0), "\t"), s1);
  482. } /* Cat1 */
  483. STATIC char *Cat2(char *s0, char *s1, char *s2) {
  484. return strcat(strcat(Cat1(s0, s1), ", "), s2);
  485. } /* Cat2 */
  486. STATIC char *Cat3(char *s0, char *s1, char *s2, char *s3) {
  487. return strcat(strcat(Cat2(s0, s1, s2), ", "), s3);
  488. } /* Cat3 */
  489. #define SetGroup(g) /* group = g */
  490. /* STATIC int group; */
  491. /* Disassemble the 386 instructions whose first opcode is 0x0f */
  492. /* Sorry, but this is just too ugly to comment */
  493. STATIC char *DisAsmF(void) {
  494. byte op0, op1;
  495. char temp[8];
  496. char *s0, *s1;
  497. int mask;
  498. op0 = GetByte();
  499. switch (op0 >> 4) { /* switch on top 4 bits of opcode */
  500. case 0:
  501. switch (op0 & 0xf) {
  502. case 0: /* grp6 */
  503. SetGroup(2);
  504. op1 = GetByte();
  505. dataSize = 0;
  506. return Cat1(grp6[Mid(op1)], ModRMInfo(op1, 1, Read_RMW(Mid(op1) >= 2)));
  507. case 1: /* grp7 */
  508. SetGroup(2);
  509. op1 = GetByte();
  510. dataSize = 0;
  511. return Cat1(grp7[Mid(op1)], ModRMInfo(op1, 1, Read_RMW(Mid(op1) & 2)));
  512. case 2:
  513. op1 = GetByte();
  514. s1 = VMid(op1);
  515. /* dataSize = 0; */
  516. return Cat2("lar", s1, ModRMInfo(op1, 1, memRead));
  517. case 3:
  518. op1 = GetByte();
  519. s1 = VMid(op1);
  520. /* dataSize = 0; */
  521. return Cat2("lsl", s1, ModRMInfo(op1, 1, memRead));
  522. case 6: return "clts";
  523. case 8: return "invd";
  524. case 9: return "wbinvd";
  525. }
  526. break;
  527. case 2: /* Mov C/D/Treg, reg */
  528. op1 = GetByte();
  529. switch (op0 & 0xf) {
  530. case 0:
  531. case 2:
  532. s1 = "c";
  533. mask = 1 + 4 + 8;
  534. break;
  535. case 1:
  536. case 3:
  537. s1 = "d";
  538. mask = 1 + 2 + 4 + 8 + 64 + 128;
  539. break;
  540. case 4:
  541. case 6:
  542. s1 = "t";
  543. mask = 8 + 16 + 32 + 64 + 128;
  544. break;
  545. default:
  546. s1 = "??";
  547. mask = 0;
  548. }
  549. if (!((1 << Mid(op1)) & mask)) /* various legal register combos */
  550. return "Illegal reg";
  551. s0 = DReg(op1);
  552. if (op0 & 2) sprintf(line, "mov\t%sr%d, %s", (FP)s1, Mid(op1), (FP)s0);
  553. else sprintf(line, "mov\t%s, %sr%d", (FP)s0, (FP)s1, Mid(op1));
  554. return line;
  555. case 8: /* long displacement jump on condition */
  556. return Cat1(jcond[op0&0xf], JRel(2));
  557. case 9: /* byte set on condition */
  558. strcpy(temp, "set");
  559. strcat(temp, jcond[op0&0xf]+1);
  560. return Cat1(temp, ModRMInfo(GetByte(), 0, memWrite));
  561. case 0xa:
  562. switch (op0 & 0xf) {
  563. case 0: return "push fs";
  564. case 1: return "pop fs";
  565. case 3: case 0xb:
  566. s0 = op0 & 8 ? "bts" : "bt";
  567. op1 = GetByte();
  568. return Cat2(s0, ModRM(op1, 1, memRMW), VMid(op1));
  569. case 4: case 0xc:
  570. s0 = op0 & 8 ? "shrd" : "shld";
  571. op1 = GetByte();
  572. s1 = ModRM(op1, 1, memRMW);
  573. return Cat3(s0, s1, VMid(op1), GetImmData(0));
  574. case 5: case 0xd:
  575. s0 = op0 & 8 ? "shrd" : "shld";
  576. op1 = GetByte();
  577. s1 = ModRM(op1, 1, memRMW);
  578. return Cat3(s0, s1, VMid(op1), "cl");
  579. case 6:
  580. op1 = GetByte();
  581. return Cat2("cmpxchg", ModRM(op1, 0, memRMW), BMid(op1));
  582. case 7:
  583. op1 = GetByte();
  584. return Cat2("cmpxchg", ModRM(op1, 1, memRMW), VMid(op1));
  585. case 8: return "push gs";
  586. case 9: return "pop gs";
  587. case 0xf:
  588. op1 = GetByte();
  589. return Cat2("imul", VMid(op1), ModRM(op1, 1, memRead));
  590. }
  591. break;
  592. case 0xb:
  593. switch (op0 & 0xf) {
  594. case 2: case 4: case 5:
  595. s0 = (op0 & 2) ? "lss" : (op0 &1) ? "lgs" : "lfs";
  596. op1 = GetByte();
  597. return Cat2(s0, VMid(op1), ModRM(op1, 1, memRead));
  598. case 3: case 0xb:
  599. s0 = (op0 & 8) ? "btc": "btr";
  600. op1 = GetByte();
  601. return Cat2(s0, ModRM(op1, 1, memRMW), VMid(op1));
  602. case 6: case 7: case 0xe: case 0xf:
  603. s0 = (op0 & 8) ? "movsx" : "movzx";
  604. op1 = GetByte();
  605. s1 = VMid(op1);
  606. dataSize = 0;
  607. return Cat2(s0, s1, ModRMInfo(op1, op0&1, memRead));
  608. case 0xa:
  609. SetGroup(2);
  610. op1 = GetByte();
  611. s0 = grp8[Mid(op1)];
  612. s1 = ModRMInfo(op1, 1, memRMW);
  613. return Cat2(s0, s1, GetImmData(0));
  614. case 0xc: case 0xd:
  615. op1 = GetByte();
  616. s0 = (op0 & 1) ? "bsr" : "bsf";
  617. return Cat2(s0, VMid(op1), ModRM(op1, 1, memRead));
  618. }
  619. break;
  620. case 0xc:
  621. if (op0 > 0xc7) return Cat1("bswap", DReg(op0 & 7));
  622. if (op0 < 0xc2) {
  623. op1 = GetByte();
  624. return Cat2("xadd", ModRM(op1, op0&1, memRMW), XMid(op0&1, op1));
  625. }
  626. break;
  627. default:
  628. break;
  629. }
  630. sprintf(line, "?Unknown 0f %02x", op0);
  631. return line;
  632. } /* DisAsmF */
  633. int IsPrefix(byte op0) {
  634. switch (op0) { /* check for prefix bytes */
  635. #define CSEG 0x2e
  636. #define DSEG 0x3e
  637. #define ESEG 0x26
  638. #define SSEG 0x36
  639. #define FSEG 0x64
  640. #define GSEG 0x65
  641. #define REP 0xf3
  642. #define REPNE 0xf2
  643. #define DATA32 0x66
  644. #define ADR32 0x67
  645. case CSEG: preSeg = "cs:"; SetMemSeg(memCS); break;
  646. case DSEG: preSeg = "ds:"; SetMemSeg(memDS); break;
  647. case ESEG: preSeg = "es:"; SetMemSeg(memES); break;
  648. case SSEG: preSeg = "ss:"; SetMemSeg(memSS); break;
  649. case FSEG: preSeg = "fs:"; SetMemSeg(memFS); break;
  650. case GSEG: preSeg = "gs:"; SetMemSeg(memGS); break;
  651. case REP: strcpy(line, "repe\t"); gpRegs |= strCX; break;
  652. case REPNE: strcpy(line, "repne\t"); gpRegs |= strCX; break;
  653. case ADR32:
  654. /* printf("Adr32\n"); */
  655. adrSize = !adrSize; break;
  656. case DATA32:
  657. /* printf("Data32\n"); */
  658. dataSize = !dataSize; break;
  659. default:
  660. return 0;
  661. }
  662. return 1;
  663. } /* IsPrefix */
  664. /* like, call this with a pointer to the instruction, it will return */
  665. /* the opcode bytes used in *len, and a pointer to the disassembled insn */
  666. char *DisAsm86(byte far *codeParm, int *len) {
  667. byte far *oldcode;
  668. byte op0, op1;
  669. byte opclass;
  670. static int init;
  671. char operand[40];
  672. char *(*Reg)(int);
  673. char *s0, *s1, *s2, *s3;
  674. if (!init) {
  675. InitDisAsm86();
  676. init = 1;
  677. }
  678. adrSize = dataSize = segSize;
  679. preSeg = "";
  680. hexPos = 0;
  681. memDouble = 0;
  682. line[0] = 0;
  683. gpSafe = gpRegs = gpStack = 0;
  684. code = oldcode = codeParm;
  685. do {
  686. op0 = GetByte();
  687. } while (IsPrefix(op0));
  688. opclass = lookup[op0];
  689. SetMemOp(memNOP);
  690. if (!preSeg[0]) SetMemSeg(memDS);
  691. if (opclass >= simpleBase) { /* is it special */
  692. if (opclass >= stringOpBase) { /* string operations? */
  693. char cmd;
  694. opclass -= stringOpBase;
  695. cmd = stringOp[opclass].flag;
  696. if (cmd & STR_NO_COND) strcpy(line+3, "\t");
  697. if (cmd & STR_S) {
  698. gpRegs |= strSI;
  699. SetMemOp(memRead);
  700. /* DS already set */
  701. VReg(RegSI);
  702. SetMemLinear(memReg);
  703. if (cmd & STR_D) {
  704. gpRegs |= strDI;
  705. SetMemOp2(cmd & STR_D_Read ? memRead : memWrite);
  706. SetMemSeg2(memES);
  707. VReg(RegDI);
  708. SetMemLinear2(memReg);
  709. memDouble = 1;
  710. }
  711. } else {
  712. gpRegs |= strDI;
  713. SetMemOp(cmd & STR_D_Read ? memRead : memWrite);
  714. SetMemSeg(memES);
  715. VReg(RegDI);
  716. SetMemLinear(memReg);
  717. }
  718. if (op0 & 1) {
  719. if (dataSize) { s1 = "d"; SetMemSize(4); }
  720. else { s1 = "w"; SetMemSize(2); }
  721. } else { s1 = "b"; SetMemSize(1); }
  722. s0 = strcat(strcpy(operand, stringOp[opclass].name), s1);
  723. } else if (opclass >= dSimpleBase) {
  724. opclass -= dSimpleBase;
  725. s0 = dataSize ? dsimple[opclass].name32 : dsimple[opclass].name;
  726. } else {
  727. s0 = simple[opclass-simpleBase].name;
  728. if (op0 == 7) { /* pop ES */
  729. gpRegs = segES;
  730. gpSafe = 1;
  731. gpStack = 1;
  732. } else if (op0 == 0x1f) { /* pop DS */
  733. gpRegs = segDS;
  734. gpSafe = 1;
  735. gpStack = 1;
  736. }
  737. }
  738. Cat0(s0);
  739. goto DisAsmDone;
  740. }
  741. if (op0 == 0x0f) { /* is it an extended opcode? */
  742. s0 = DisAsmF();
  743. strcpy(line, s0);
  744. goto DisAsmDone;
  745. }
  746. s0 = ops[opclass].name;
  747. switch (ops[opclass].operand) {
  748. case NOOP:
  749. Cat0(s0);
  750. break;
  751. case VREG: /* inc, dec, push, pop, xchg */
  752. if ((op0 & ~7) == 0x90) Cat2(s0, "ax", VReg(op0&7));
  753. else Cat1(s0, VReg(op0&7));
  754. /* Set memop for Push/Pop as modifying stack values */
  755. break;
  756. case BWI: /* byte/word/immediate */
  757. gpSafe = 1;
  758. if (!(op0&1)) Reg = BReg;
  759. else if (!dataSize) Reg = WReg;
  760. else Reg = DReg;
  761. if (op0 & 4) {
  762. Cat2(s0, Reg(0), GetImmData(op0&1));
  763. } else {
  764. int i;
  765. op1 = GetByte();
  766. if ((op0 & 0xf8) == 0x38) i = memRead;
  767. else if ((op0 & 0xfe) == 0x88) i = memWrite;
  768. else i = Read_RMW(op0 & 2);
  769. s1 = ModRM(op1, op0&1, i);
  770. s2 = Reg(Mid(op1));
  771. if (op0 & 2) {
  772. s3 = s2; s2 = s1; s1 = s3;
  773. }
  774. Cat2(s0, s1, s2);
  775. }
  776. break;
  777. case BRI: /* byte reg immediate */
  778. Cat2(s0, BReg(op0 & 7), GetImmData(0));
  779. break;
  780. case WRI: /* word reg immediate */
  781. Cat2(s0, VReg(op0 & 7), GetImmData(1));
  782. break;
  783. case Grp1: /* group 1 instructions */
  784. gpSafe = 1;
  785. SetGroup(1);
  786. op1 = GetByte();
  787. s1 = ModRMInfo(op1, op0&1, Mid(op1) == 7 ? memRead : memRMW);
  788. Cat2(grp1[Mid(op1)], s1, GetImmData((op0&3)==1));
  789. break;
  790. case Grp2: /* group 2 instructions */
  791. gpSafe = 1;
  792. SetGroup(1);
  793. op1 = GetByte();
  794. s1 = ModRMInfo(op1, op0&1, memRMW);
  795. s2 = (op0 & 0x10) ? (op0 & 2 ? "cl" : "1") : GetImmData(0);
  796. Cat2(grp2[Mid(op1)], s1, s2);
  797. break;
  798. case Grp3: /* group 3 instructions */
  799. gpSafe = 1;
  800. SetGroup(1);
  801. op1 = GetByte();
  802. s1 = ModRMInfo(op1, op0&1, Read_RMW(Mid(op1) <2 || Mid(op1) >3));
  803. s0 = grp3[Mid(op1)];
  804. if (Mid(op1) < 2) Cat2(s0, s1, GetImmData(op0&1));
  805. else Cat1(s0, s1);
  806. break;
  807. case Grp4: /* group 4 instructions */
  808. SetGroup(1);
  809. op1 = GetByte();
  810. if (Mid(op1) > 1) Cat0("?");
  811. else {
  812. Cat1(grp5[Mid(op1)], ModRMInfo(op1, op0&1, memRMW));
  813. gpSafe = 1;
  814. }
  815. break;
  816. case Grp5: /* group 5 instructions */
  817. op1 = GetByte();
  818. if (Mid(op1) < 3) {
  819. gpSafe = 1;
  820. if (Mid(op1) == 2) {
  821. gpStack = -1 << dataSize;
  822. }
  823. }
  824. SetGroup(1);
  825. Cat1(grp5[Mid(op1)], ModRMInfo(op1, op0&1, Read_RMW(Mid(op1) >= 2)));
  826. break;
  827. case SMOV: /* segment move */
  828. gpSafe = 1;
  829. op1 = GetByte();
  830. dataSize = 0;
  831. s1 = ModRM(op1, 1, Read_RMW(op0&2));
  832. s2 = sregs[Mid(op1)];
  833. if (op0 & 2) { /* if moving _to_ SREG */
  834. s3 = s2; s2 = s1; s1 = s3; /* switch operands */
  835. switch (Mid(op1)) {
  836. case 0: gpRegs = segES; break;
  837. case 3: gpRegs = segDS; break;
  838. case 4: gpRegs = segFS; break;
  839. case 5: gpRegs = segGS; break;
  840. default: gpSafe = 0;
  841. }
  842. }
  843. Cat2(s0, s1, s2);
  844. break;
  845. case IMOV: /* immediate move to reg/mem */
  846. gpSafe = 1;
  847. op1 = GetByte();
  848. s1 = ModRMInfo(op1, op0&1, memWrite);
  849. Cat2(s0, s1, GetImmData(op0&1));
  850. break;
  851. case IBYTE: /* immediate byte to reg */
  852. sprintf(line, "%s\t%02x", (FP)s0, (char)GetByte());
  853. break;
  854. case IWORD: /* immediate word to reg - size of data */
  855. Cat1(s0, GetImmData(1));
  856. break;
  857. case IWORD1: /* immediate word - always 16 bit */
  858. Cat1(s0, GetImmWord());
  859. break;
  860. case JMPW:
  861. Cat1(s0, JRel(2));
  862. break;
  863. case JMPB:
  864. Cat1(s0, JRel(1));
  865. break;
  866. case LEA:
  867. op1 = GetByte();
  868. Cat2(s0, VMid(op1), ModRM(op1, 1, memNOP));
  869. break;
  870. case JCond:
  871. Cat1(jcond[op0&0xf], JRel(1));
  872. break;
  873. case IADR:
  874. s2 = GetImmAdr(1);
  875. sprintf(line, "%s\t%04x:%s", (FP)s0, GetWord(), (FP)s2);
  876. break;
  877. case MOVABS: /* move between accum and abs mem address */
  878. gpSafe = 1;
  879. s1 = XReg(op0 & 1, 0);
  880. sprintf(operand, "[%s%s]", (FP)preSeg, (FP)GetImmAdr(1));
  881. SetMemLinear(memDisp);
  882. SetMemSize(!(op0&1) ? 1 : (!dataSize ? 2 : 4));
  883. SetMemOp(op0&2 ? memWrite : memRead);
  884. s2 = operand;
  885. if (op0 & 2) {
  886. s3 = s2; s2 = s1; s1 = s3;
  887. }
  888. Cat2(s0, s1, s2);
  889. break;
  890. case IMUL:
  891. op1 = GetByte();
  892. s1 = VMid(op1);
  893. s2 = ModRM(op1, 1, memRead);
  894. s3 = GetImmData(!(op0&2));
  895. Cat3(s0, s1, s2, s3);
  896. break;
  897. case POPMEM:
  898. gpSafe = 1;
  899. gpStack = 1 << dataSize;
  900. Cat1(s0, ModRMInfo(GetByte(), 1, memWrite));
  901. break;
  902. case RRM: /* test and xchg */
  903. gpSafe = 1;
  904. op1 = GetByte();
  905. s2 = ModRM(op1, op0&1, memRMW);
  906. Cat2(s0, XMid(op0&1, op1), s2);
  907. break;
  908. case RRMW: /* bound, les, lds */
  909. op1 = GetByte();
  910. switch (op0) {
  911. case 0xc4: /* les reg, [mem] */
  912. gpRegs = segES;
  913. gpSafe = 1;
  914. break;
  915. case 0xc5: /* lds reg, [mem] */
  916. gpRegs = segDS;
  917. gpSafe = 1;
  918. break;
  919. }
  920. Cat2(s0, VMid(op1), ModRM(op1, 1, memRead));
  921. break;
  922. case TEST: /* test al/ax/eax, imm */
  923. Cat2(s0, XReg(op0&1, 0), GetImmData(op0&1));
  924. break;
  925. case ENTER:
  926. strcpy(operand, GetImmWord());
  927. Cat2(s0, operand, GetImmData(0));
  928. break;
  929. case FLOP:
  930. op1 = GetByte();
  931. Cat1(s0, ModRMInfo(op1, 1, memNOP));
  932. break;
  933. case ARPL:
  934. op1 = GetByte();
  935. dataSize = 0;
  936. s1 = ModRM(op1, 1, memRMW);
  937. s2 = VMid(op1);
  938. Cat2(s0, s1, s2);
  939. break;
  940. case INOUT:
  941. s1 = XReg(op0&1, 0);
  942. s2 = GetImmAdr(0);
  943. if (op0 & 2) {
  944. s3 = s2; s2 = s1; s1 = s3;
  945. }
  946. Cat2(s0, s1, s2);
  947. break;
  948. case ASCII:
  949. Cat0(GetByte() == 10 ? s0 : "?");
  950. break;
  951. case XLAT:
  952. gpSafe = 1;
  953. SetMemOp(memRead);
  954. SetMemLinear(regs[RegBX] + (regs[RegAX] & 0xff));
  955. break;
  956. default:
  957. sprintf(line, "?Unknown opcode %02x", op0);
  958. }
  959. DisAsmDone:
  960. *len = (int)(code - oldcode);
  961. return line;
  962. } /* DisAsm86 */
  963. /* if you're in a 32 bit code segment, call DisAsm386 which sets */
  964. /* default data and address size to 32 bit */
  965. char *DisAsm386(byte far *code, int *len) {
  966. adrSize = dataSize = 1;
  967. return DisAsm86(code, len);
  968. } /* DisAsm386 */
  969. /* #define FOOBAR */
  970. #if defined(FOOBAR)
  971. STATIC int GroupSize(int op) {
  972. if (op == 0xf) return 256;
  973. /* op = lookup[op];
  974. if (op > 0x80) return 1;
  975. if (ops[op].name[0] == 'G') return 8;
  976. if (ops[op].name[0] == 'F') return 256; */
  977. return 1;
  978. } /* IsGroup */
  979. /* #pragma inline */
  980. void testfunc() {
  981. /* asm {
  982. .386p
  983. mov eax, ss:[si+33h]
  984. rep movsb
  985. mov eax, ds:[ebp+eax*2+1234h]
  986. } */
  987. }
  988. byte foo[10];
  989. /* #include <dos.h> */
  990. extern void DisTest(), EndTest();
  991. word regs[] = {1, 2, 4, 8, 0x10, 0x20, 0x40, 0x80, -1, -1,
  992. 0xeeee, 0xcccc, 0x5555, 0xdddd, 0xffff, 0x6666};
  993. dword regs32[] = {0x100, 0x200, 0x400, 0x800, 0x1000, 0x2000, 0x4000, 0x8000};
  994. STATIC char *Tab2Spc(char *temp) {
  995. char newbuf[80], *s1, *s2;
  996. s1 = temp;
  997. s2 = newbuf;
  998. while ((*s2 = *s1++) != 0) {
  999. if (*s2++ == 9) {
  1000. s2[-1] = ' ';
  1001. while ((s2-newbuf) & 7) *s2++ = ' ';
  1002. }
  1003. }
  1004. strcpy(temp, newbuf);
  1005. return temp;
  1006. } /* Tab2Spc */
  1007. void MemTest(void) {
  1008. void far *vp = (void far *)DisTest;
  1009. byte far *cp = vp, far *ep;
  1010. int len;
  1011. char *s;
  1012. vp = (void far *)EndTest;
  1013. ep = vp;
  1014. while (cp < ep) {
  1015. s = DisAsm86(cp, &len);
  1016. Tab2Spc(s);
  1017. printf("\n%04x\t%-28s", (int)cp, s);
  1018. if (memOp) {
  1019. printf("%04x:%04lx(%d) %-6s ",
  1020. memSeg, memLinear, memSize, memName[memOp]);
  1021. if (memDouble) {
  1022. printf("%04x:%04lx(%d) %-6s",
  1023. memSeg2, memLinear2, memSize, memName[memOp2]);
  1024. }
  1025. }
  1026. memSeg = memLinear = memSize = memOp = 0;
  1027. cp += len;
  1028. }
  1029. } /* MemTest */
  1030. void main(void) {
  1031. #if 0
  1032. int i, j, g;
  1033. void far *vp = (void far *)DisTest;
  1034. byte far *cp = vp;
  1035. byte far *ep;
  1036. int len = 3, count;
  1037. char *s;
  1038. #endif
  1039. MemTest();
  1040. #if 0
  1041. vp = (void far *)EndTest;
  1042. ep = vp;
  1043. printf("DisAsm86\n", (int)foo << len);
  1044. for (i=0; i<9; i++) foo[i] = i;
  1045. /* #define CHECK */
  1046. #if defined(CHECK)
  1047. for (i=0x0; i<256; i++) {
  1048. foo[0] = i;
  1049. count = GroupSize(i);
  1050. for (j=0; j<count; j++) {
  1051. if (((count > 1) && ((j & 7) == 0)) ||
  1052. ((count == 1) && ((i & 7) == 0)))
  1053. printf("\n");
  1054. foo[1] = j;
  1055. foo[2] = 0;
  1056. s = DisAsm386(foo, &len);
  1057. if (*s != '?') printf("%02x\t%s\n", i, (FP)s);
  1058. if (group) {
  1059. for (g = 1; g<8; g++) {
  1060. foo[group] = g << 3;
  1061. s = DisAsm386(foo, &len);
  1062. if (*s != '?') printf("%02x %02x\t%s\n", i, foo[group], (FP)s);
  1063. }
  1064. group = 0;
  1065. }
  1066. }
  1067. #else
  1068. /* for (i=0; i<10; i++) { */
  1069. while (cp < ep) {
  1070. s = DisAsm86(cp, &len);
  1071. printf("%04x\t%s\n", (word)cp, (FP)s);
  1072. cp += len;
  1073. #endif
  1074. }
  1075. #endif
  1076. } /* main */
  1077. void far foobar() {}
  1078. #endif