unsigned int type_from_var:1; // .. in header, sometimes wrong
unsigned int size_mismatch:1; // type override differs from C
unsigned int size_lt:1; // type override is larger than C
- unsigned int had_ds:1; // had ds: prefix
+ unsigned int segment:7; // had segment override (enum segment)
const struct parsed_proto *pp; // for OPT_LABEL
unsigned int val;
char name[NAMELEN];
X87_CONST_Z,
};
+enum segment {
+ SEG_CS = 1,
+ SEG_DS,
+ SEG_SS,
+ SEG_ES,
+ SEG_FS,
+ SEG_GS,
+};
+
// note: limited to 32k due to p_argnext
#define MAX_OPS 4096
#define MAX_ARG_GRP 2
static int g_sp_frame;
static int g_stack_frame_used;
static int g_stack_fsz;
+static int g_seh_found;
+static int g_seh_size;
static int g_ida_func_attr;
static int g_sct_func_attr;
static int g_stack_clear_start; // in dwords
return 0;
switch (s[0]) {
- case 'c': return 1;
- case 'd': return 2;
- case 's': return 3;
- case 'e': return 4;
- case 'f': return 5;
- case 'g': return 6;
+ case 'c': return SEG_CS;
+ case 'd': return SEG_DS;
+ case 's': return SEG_SS;
+ case 'e': return SEG_ES;
+ case 'f': return SEG_FS;
+ case 'g': return SEG_GS;
default: return 0;
}
}
opr->type = OPT_LABEL;
ret = check_segment_prefix(label);
if (ret != 0) {
- if (ret >= 5)
- aerr("fs/gs used\n");
- opr->had_ds = 1;
+ opr->segment = ret;
label += 3;
}
strcpy(opr->name, label);
ret = check_segment_prefix(words[w]);
if (ret != 0) {
- if (ret >= 5)
- aerr("fs/gs used\n");
- opr->had_ds = 1;
+ opr->segment = ret;
memmove(words[w], words[w] + 3, strlen(words[w]) - 2);
+ if (ret == SEG_FS && IS(words[w], "0"))
+ g_seh_found = 1;
}
strcpy(opr->name, words[w]);
return pp->name;
}
+static void check_opr(struct parsed_op *po, struct parsed_opr *popr)
+{
+ if (popr->segment == SEG_FS)
+ ferr(po, "fs: used\n");
+ if (popr->segment == SEG_GS)
+ ferr(po, "gs: used\n");
+}
+
static char *out_src_opr(char *buf, size_t buf_size,
struct parsed_op *po, struct parsed_opr *popr, const char *cast,
int is_lea)
char *p;
int ret;
+ check_opr(po, popr);
+
if (cast == NULL)
cast = "";
static char *out_dst_opr(char *buf, size_t buf_size,
struct parsed_op *po, struct parsed_opr *popr)
{
+ check_opr(po, popr);
+
switch (popr->type) {
case OPT_REG:
switch (popr->lmod) {
ferr(po, "call to loc_*\n");
if (IS(tmpname, "__alloca_probe"))
continue;
+ if (IS(tmpname, "__SEH_prolog")) {
+ ferr_assert(po, g_seh_found == 0);
+ g_seh_found = 2;
+ continue;
+ }
+ if (IS(tmpname, "__SEH_epilog"))
+ continue;
// convert some calls to pseudo-ops
for (l = 0; l < ARRAY_SIZE(pseudo_ops); l++) {
}
}
+static int resolve_origin(int i, const struct parsed_opr *opr,
+ int magic, int *op_i, int *is_caller);
+
+static void eliminate_seh_writes(int opcnt)
+{
+ const struct parsed_opr *opr;
+ char ofs_reg[16];
+ int offset;
+ int i;
+
+ // assume all sf writes above g_seh_size to be seh related
+ // (probably unsafe but oh well)
+ for (i = 0; i < opcnt; i++) {
+ if (ops[i].op != OP_MOV)
+ continue;
+ opr = &ops[i].operand[0];
+ if (opr->type != OPT_REGMEM)
+ continue;
+ if (!is_stack_access(&ops[i], opr))
+ continue;
+
+ offset = 0;
+ parse_stack_access(&ops[i], opr->name, ofs_reg, &offset,
+ NULL, NULL, 0);
+ if (offset < 0 && offset >= -g_seh_size)
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ }
+}
+
+static void eliminate_seh(int opcnt)
+{
+ int i, j, k, ret;
+
+ for (i = 0; i < opcnt; i++) {
+ if (ops[i].op != OP_MOV)
+ continue;
+ if (ops[i].operand[0].segment != SEG_FS)
+ continue;
+ if (!IS(opr_name(&ops[i], 0), "0"))
+ continue;
+
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ if (ops[i].operand[1].reg == xSP) {
+ for (j = i - 1; j >= 0; j--) {
+ if (ops[j].op != OP_PUSH)
+ continue;
+ ops[j].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ g_seh_size += 4;
+ if (ops[j].operand[0].val == ~0)
+ break;
+ if (ops[j].operand[0].type == OPT_REG) {
+ k = -1;
+ ret = resolve_origin(j, &ops[j].operand[0],
+ j + opcnt * 22, &k, NULL);
+ if (ret == 1)
+ ops[k].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ }
+ }
+ if (j < 0)
+ ferr(ops, "missing seh terminator\n");
+ }
+ else {
+ k = -1;
+ ret = resolve_origin(i, &ops[i].operand[1],
+ i + opcnt * 23, &k, NULL);
+ if (ret == 1)
+ ops[k].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ }
+ }
+
+ eliminate_seh_writes(opcnt);
+}
+
+static void eliminate_seh_calls(int opcnt)
+{
+ int epilog_found = 0;
+ int i;
+
+ g_bp_frame = 1;
+ g_seh_size = 0x10;
+
+ i = 0;
+ ferr_assert(&ops[i], ops[i].op == OP_PUSH
+ && ops[i].operand[0].type == OPT_CONST);
+ g_stack_fsz = g_seh_size + ops[i].operand[0].val;
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+
+ i++;
+ ferr_assert(&ops[i], ops[i].op == OP_PUSH
+ && ops[i].operand[0].type == OPT_OFFSET);
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+
+ i++;
+ ferr_assert(&ops[i], ops[i].op == OP_CALL
+ && IS(opr_name(&ops[i], 0), "__SEH_prolog"));
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+
+ for (i++; i < opcnt; i++) {
+ if (ops[i].op != OP_CALL)
+ continue;
+ if (!IS(opr_name(&ops[i], 0), "__SEH_epilog"))
+ continue;
+
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ epilog_found = 1;
+ }
+ ferr_assert(ops, epilog_found);
+
+ eliminate_seh_writes(opcnt);
+}
+
+static int scan_prologue(int i, int opcnt, int *ecx_push, int *esp_sub)
+{
+ int j;
+
+ for (; i < opcnt; i++)
+ if (!(ops[i].flags & OPF_DONE))
+ break;
+
+ while (ops[i].op == OP_PUSH && IS(opr_name(&ops[i], 0), "ecx")) {
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ g_stack_fsz += 4;
+ (*ecx_push)++;
+ i++;
+ }
+
+ for (; i < opcnt; i++) {
+ if (i > 0 && g_labels[i] != NULL)
+ break;
+ if (ops[i].op == OP_PUSH || (ops[i].flags & (OPF_JMP|OPF_TAIL)))
+ break;
+ if (ops[i].op == OP_SUB && ops[i].operand[0].reg == xSP
+ && ops[i].operand[1].type == OPT_CONST)
+ {
+ g_stack_fsz += opr_const(&ops[i], 1);
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ i++;
+ *esp_sub = 1;
+ break;
+ }
+ if (ops[i].op == OP_MOV && ops[i].operand[0].reg == xAX
+ && ops[i].operand[1].type == OPT_CONST)
+ {
+ for (j = i + 1; j < opcnt; j++)
+ if (!(ops[j].flags & OPF_DONE))
+ break;
+ if (ops[j].op == OP_CALL
+ && IS(opr_name(&ops[j], 0), "__alloca_probe"))
+ {
+ g_stack_fsz += opr_const(&ops[i], 1);
+ ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ ops[j].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
+ i = j + 1;
+ *esp_sub = 1;
+ }
+ break;
+ }
+ }
+
+ return i;
+}
+
static void scan_prologue_epilogue(int opcnt, int *stack_align)
{
int ecx_push = 0, esp_sub = 0, pusha = 0;
int found;
int i, j, l;
+ if (g_seh_found == 2) {
+ eliminate_seh_calls(opcnt);
+ return;
+ }
+ if (g_seh_found) {
+ eliminate_seh(opcnt);
+ // ida treats seh as part of sf
+ g_stack_fsz = g_seh_size;
+ esp_sub = 1;
+ }
+
if (ops[0].op == OP_PUSH && IS(opr_name(&ops[0], 0), "ebp")
&& ops[1].op == OP_MOV
&& IS(opr_name(&ops[1], 0), "ebp")
g_bp_frame = 1;
ops[0].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
ops[1].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i = 2;
+
+ for (i = 2; i < opcnt; i++)
+ if (!(ops[i].flags & OPF_DONE))
+ break;
if (ops[i].op == OP_PUSHA) {
ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
i++;
}
- if (ops[i].op == OP_SUB && IS(opr_name(&ops[i], 0), "esp")) {
- g_stack_fsz = opr_const(&ops[i], 1);
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i++;
- }
- else {
- // another way msvc builds stack frame..
- while (ops[i].op == OP_PUSH && IS(opr_name(&ops[i], 0), "ecx")) {
- g_stack_fsz += 4;
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- ecx_push++;
- i++;
- }
- // and another way..
- if (i == 2 && ops[i].op == OP_MOV && ops[i].operand[0].reg == xAX
- && ops[i].operand[1].type == OPT_CONST
- && ops[i + 1].op == OP_CALL
- && IS(opr_name(&ops[i + 1], 0), "__alloca_probe"))
- {
- g_stack_fsz += ops[i].operand[1].val;
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i++;
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i++;
- }
- }
+ i = scan_prologue(i, opcnt, &ecx_push, &esp_sub);
found = 0;
do {
}
// non-bp frame
- i = 0;
- while (ops[i].op == OP_PUSH && IS(opr_name(&ops[i], 0), "ecx")) {
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- g_stack_fsz += 4;
- ecx_push++;
- i++;
- }
-
- for (; i < opcnt; i++) {
- if (ops[i].op == OP_PUSH || (ops[i].flags & (OPF_JMP|OPF_TAIL)))
- break;
- if (ops[i].op == OP_SUB && ops[i].operand[0].reg == xSP
- && ops[i].operand[1].type == OPT_CONST)
- {
- g_stack_fsz = ops[i].operand[1].val;
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i++;
- esp_sub = 1;
- break;
- }
- else if (ops[i].op == OP_MOV && ops[i].operand[0].reg == xAX
- && ops[i].operand[1].type == OPT_CONST
- && ops[i + 1].op == OP_CALL
- && IS(opr_name(&ops[i + 1], 0), "__alloca_probe"))
- {
- g_stack_fsz += ops[i].operand[1].val;
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i++;
- ops[i].flags |= OPF_RMD | OPF_DONE | OPF_NOREGS;
- i++;
- esp_sub = 1;
- break;
- }
- }
+ i = scan_prologue(0, opcnt, &ecx_push, &esp_sub);
if (ecx_push && !esp_sub) {
// could actually be args for a call..
ferr(&ops[i], "unhandled prologue\n");
// recheck
- i = g_stack_fsz = ecx_push = 0;
+ i = ecx_push = 0;
+ g_stack_fsz = g_seh_size;
while (ops[i].op == OP_PUSH && IS(opr_name(&ops[i], 0), "ecx")) {
if (!(ops[i].flags & OPF_RMD))
break;
i--;
j--;
}
+ else if (i < opcnt && (ops[i].flags & OPF_ATAIL)) {
+ // skip arg updates for arg-reuse tailcall
+ for (; j >= 0; j--) {
+ if (ops[j].op != OP_MOV)
+ break;
+ if (ops[j].operand[0].type != OPT_REGMEM)
+ break;
+ if (strstr(ops[j].operand[0].name, "arg_") == NULL)
+ break;
+ }
+ }
- if (ecx_push > 0) {
- for (l = 0; l < ecx_push; l++) {
+ if (ecx_push > 0 && !esp_sub) {
+ for (l = 0; l < ecx_push && j >= 0; l++) {
if (ops[j].op == OP_POP && IS(opr_name(&ops[j], 0), "ecx"))
/* pop ecx */;
else if (ops[j].op == OP_ADD
g_bp_frame = g_sp_frame = g_stack_fsz = 0;
g_stack_frame_used = 0;
+ g_seh_size = 0;
if (g_sct_func_attr & SCTFA_CLEAR_REGS)
regmask_init = g_regmask_init;
// output starts here
+ if (g_seh_found)
+ fprintf(fout, "// had SEH\n");
+
// define userstack size
if (g_func_pp->is_userstack) {
fprintf(fout, "#ifndef US_SZ_%s\n", g_func_pp->name);
fprintf(fout, "%s%s = %s;\n", buf3, pp->name,
out_src_opr(buf1, sizeof(buf1), po, &po->operand[0],
"(void *)", 0));
- if (pp->is_unresolved)
+ if (pp->is_unresolved || IS_START(pp->name, "i_guess"))
fprintf(fout, "%sunresolved_call(\"%s:%d\", %s);\n",
buf3, asmfn, po->asmln, pp->name);
}
g_bp_frame = g_sp_frame = g_stack_fsz = 0;
g_stack_frame_used = 0;
+ g_seh_size = 0;
// pass1:
// - resolve all branches
skip_warned = 0;
g_skip_func = 0;
g_func[0] = 0;
+ g_seh_found = 0;
func_chunks_used = 0;
func_chunk_i = -1;
if (pi != 0) {
aerr("endp '%s' while skipping code\n", words[0]);
if ((g_ida_func_attr & IDAFA_THUNK) && pi == 1
- && ops[0].op == OP_JMP && ops[0].operand[0].had_ds)
+ && ops[0].op == OP_JMP && ops[0].operand[0].segment)
{
// import jump
g_skip_func = 1;