fc1c61f5 |
1 | /* |
2 | * ia32rtools |
3 | * (C) notaz, 2013,2014 |
4 | * |
5 | * This work is licensed under the terms of 3-clause BSD license. |
6 | * See COPYING file in the top-level directory. |
7 | */ |
8 | |
d8891fcc |
9 | #define NO_OBSOLETE_FUNCS |
10 | #include <ida.hpp> |
11 | #include <idp.hpp> |
12 | #include <bytes.hpp> |
13 | #include <loader.hpp> |
14 | #include <kernwin.hpp> |
15 | |
16 | #include <name.hpp> |
17 | #include <frame.hpp> |
18 | #include <struct.hpp> |
fc1c61f5 |
19 | #include <offset.hpp> |
d8891fcc |
20 | #include <auto.hpp> |
15c7b2a4 |
21 | #include <intel.hpp> |
d8891fcc |
22 | |
23 | #define IS_START(w, y) !strncmp(w, y, strlen(y)) |
24 | #define ARRAY_SIZE(x) (sizeof(x) / sizeof(x[0])) |
25 | |
97609f07 |
26 | static char **name_cache; |
27 | static size_t name_cache_size; |
28 | |
15c7b2a4 |
29 | // non-local branch targets |
30 | static ea_t *nonlocal_bt; |
31 | static int nonlocal_bt_alloc; |
32 | static int nonlocal_bt_cnt; |
33 | |
d8891fcc |
34 | //-------------------------------------------------------------------------- |
35 | static int idaapi init(void) |
36 | { |
37 | return PLUGIN_OK; |
38 | } |
39 | |
40 | //-------------------------------------------------------------------------- |
41 | static void idaapi term(void) |
42 | { |
97609f07 |
43 | size_t i; |
44 | |
15c7b2a4 |
45 | if (nonlocal_bt != NULL) { |
46 | free(nonlocal_bt); |
47 | nonlocal_bt = NULL; |
48 | } |
49 | nonlocal_bt_alloc = 0; |
97609f07 |
50 | |
51 | if (name_cache != NULL) { |
52 | for (i = 0; i < name_cache_size; i++) |
53 | free(name_cache[i]); |
54 | free(name_cache); |
55 | name_cache = NULL; |
56 | } |
57 | name_cache_size = 0; |
d8891fcc |
58 | } |
59 | |
60 | //-------------------------------------------------------------------------- |
61 | |
62 | static const char *reserved_names[] = { |
63 | "name", |
b587e6ae |
64 | "type", |
d8891fcc |
65 | "offset", |
b587e6ae |
66 | "aam", |
e74324f9 |
67 | "aas", |
1402b79d |
68 | "text", |
de8a204c |
69 | "size", |
70 | "c", |
97609f07 |
71 | "align", |
e74324f9 |
72 | "addr", |
d8891fcc |
73 | }; |
74 | |
75 | static int is_name_reserved(const char *name) |
76 | { |
77 | int i; |
78 | for (i = 0; i < ARRAY_SIZE(reserved_names); i++) |
79 | if (strcasecmp(name, reserved_names[i]) == 0) |
80 | return 1; |
81 | |
82 | return 0; |
83 | } |
84 | |
15c7b2a4 |
85 | static int nonlocal_bt_cmp(const void *p1, const void *p2) |
86 | { |
87 | const ea_t *e1 = (const ea_t *)p1, *e2 = (const ea_t *)p2; |
88 | return *e1 - *e2; |
89 | } |
90 | |
91 | static void nonlocal_add(ea_t ea) |
92 | { |
93 | if (nonlocal_bt_cnt >= nonlocal_bt_alloc) { |
94 | nonlocal_bt_alloc += nonlocal_bt_alloc * 2 + 64; |
95 | nonlocal_bt = (ea_t *)realloc(nonlocal_bt, |
96 | nonlocal_bt_alloc * sizeof(nonlocal_bt[0])); |
97 | if (nonlocal_bt == NULL) { |
98 | msg("OOM\n"); |
99 | return; |
100 | } |
101 | } |
102 | nonlocal_bt[nonlocal_bt_cnt++] = ea; |
103 | } |
104 | |
b587e6ae |
105 | // is instruction a (un)conditional jump (not call)? |
106 | static int is_insn_jmp(uint16 itype) |
107 | { |
108 | return itype == NN_jmp || (NN_ja <= itype && itype <= NN_jz); |
109 | } |
110 | |
d53d4cc7 |
111 | static void do_def_line(char *buf, size_t buf_size, const char *line, |
e74324f9 |
112 | ea_t ea, func_t *func) |
d8891fcc |
113 | { |
e74324f9 |
114 | char func_name[256] = "<nf>"; |
115 | int is_libfunc = 0; |
116 | int global_label; |
d53d4cc7 |
117 | ea_t *ea_ret; |
e74324f9 |
118 | int i, len; |
d53d4cc7 |
119 | char *p; |
d8891fcc |
120 | |
121 | tag_remove(line, buf, buf_size); // remove color codes |
122 | len = strlen(buf); |
123 | if (len < 9) { |
124 | buf[0] = 0; |
125 | return; |
126 | } |
127 | memmove(buf, buf + 9, len - 9 + 1); // rm address |
15c7b2a4 |
128 | |
d53d4cc7 |
129 | p = buf; |
130 | while (*p && *p != ' ' && *p != ':') |
131 | p++; |
132 | if (*p == ':') { |
133 | ea_ret = (ea_t *)bsearch(&ea, nonlocal_bt, nonlocal_bt_cnt, |
134 | sizeof(nonlocal_bt[0]), nonlocal_bt_cmp); |
e74324f9 |
135 | global_label = (ea_ret != NULL); |
136 | if (!global_label) { |
137 | if (func != NULL) { |
138 | get_func_name(ea, func_name, sizeof(func_name)); |
139 | is_libfunc = func->flags & FUNC_LIB; |
140 | } |
141 | for (i = 0; i < get_item_size(ea); i++) { |
142 | xrefblk_t xb; |
143 | if (xb.first_to(ea + i, XREF_DATA)) { |
144 | if (!is_libfunc && xb.type == dr_O) |
145 | msg("%x: offset xref in %s\n", ea, func_name); |
146 | global_label = 1; |
147 | } |
148 | } |
149 | } |
150 | if (global_label) { |
d53d4cc7 |
151 | if (p[1] != ' ') |
152 | msg("no trailing blank in '%s'\n", buf); |
153 | else |
154 | p[1] = ':'; |
15c7b2a4 |
155 | } |
156 | } |
d8891fcc |
157 | } |
158 | |
97609f07 |
159 | static int name_cache_cmp(const void *p1, const void *p2) |
160 | { |
161 | // masm ignores case, so do we |
162 | return stricmp(*(char * const *)p1, *(char * const *)p2); |
163 | } |
164 | |
165 | static void rebuild_name_cache(void) |
166 | { |
167 | size_t i, newsize; |
168 | void *tmp; |
169 | |
170 | // build a sorted name cache |
171 | newsize = get_nlist_size(); |
172 | if (newsize > name_cache_size) { |
173 | tmp = realloc(name_cache, newsize * sizeof(name_cache[0])); |
174 | if (tmp == NULL) { |
175 | msg("OOM for name cache\n"); |
176 | return; |
177 | } |
178 | name_cache = (char **)tmp; |
179 | } |
180 | for (i = 0; i < name_cache_size; i++) |
181 | free(name_cache[i]); |
182 | for (i = 0; i < newsize; i++) |
183 | name_cache[i] = strdup(get_nlist_name(i)); |
184 | |
185 | name_cache_size = newsize; |
186 | qsort(name_cache, name_cache_size, sizeof(name_cache[0]), |
187 | name_cache_cmp); |
188 | } |
189 | |
190 | static void my_rename(ea_t ea, char *name) |
191 | { |
192 | char buf[256]; |
193 | char *p, **pp; |
194 | int n = 0; |
195 | |
196 | qsnprintf(buf, sizeof(buf), "%s", name); |
197 | do { |
198 | p = buf; |
199 | pp = (char **)bsearch(&p, name_cache, name_cache_size, |
200 | sizeof(name_cache[0]), name_cache_cmp); |
201 | if (pp == NULL) |
202 | break; |
203 | |
204 | qsnprintf(buf, sizeof(buf), "%s_g%d", name, n); |
205 | n++; |
206 | } |
207 | while (n < 100); |
208 | |
209 | if (n == 100) |
210 | msg("rename failure? '%s'\n", name); |
211 | |
212 | do_name_anyway(ea, buf); |
213 | rebuild_name_cache(); |
214 | } |
215 | |
ee8e1bea |
216 | static void make_align(ea_t ea) |
217 | { |
218 | ea_t tmp_ea; |
219 | int n; |
220 | |
221 | tmp_ea = next_head(ea, inf.maxEA); |
222 | if ((tmp_ea & 0x03) == 0) { |
223 | n = calc_max_align(tmp_ea); |
224 | if (n > 4) // masm doesn't like more.. |
225 | n = 4; |
226 | msg("%x: align %d\n", ea, 1 << n); |
227 | do_unknown(ea, DOUNK_SIMPLE); |
228 | doAlign(ea, tmp_ea - ea, n); |
229 | } |
230 | } |
231 | |
d8891fcc |
232 | static void idaapi run(int /*arg*/) |
233 | { |
15c7b2a4 |
234 | // isEnabled(ea) // address belongs to disassembly |
d8891fcc |
235 | // ea_t ea = get_screen_ea(); |
ee8e1bea |
236 | // extern foo; |
15c7b2a4 |
237 | // foo = DecodeInstruction(ScreenEA()); |
d8891fcc |
238 | FILE *fout = NULL; |
239 | int fout_line = 0; |
240 | char buf[MAXSTR]; |
1caf86bb |
241 | char buf2[MAXSTR]; |
b587e6ae |
242 | const char *name; |
3a0df310 |
243 | const char *cp; |
d8891fcc |
244 | struc_t *frame; |
245 | func_t *func; |
15c7b2a4 |
246 | ea_t ui_ea_block = 0, ea_size; |
247 | ea_t tmp_ea, target_ea; |
d8891fcc |
248 | ea_t ea; |
b587e6ae |
249 | flags_t ea_flags; |
1caf86bb |
250 | uval_t idx; |
d8891fcc |
251 | int i, o, m, n; |
252 | int ret; |
97609f07 |
253 | char **pp; |
d8891fcc |
254 | char *p; |
255 | |
15c7b2a4 |
256 | nonlocal_bt_cnt = 0; |
257 | |
1caf86bb |
258 | // get rid of structs, masm doesn't understand them |
259 | idx = get_first_struc_idx(); |
260 | while (idx != BADNODE) { |
261 | tid_t tid = get_struc_by_idx(idx); |
262 | struc_t *struc = get_struc(tid); |
263 | get_struc_name(tid, buf, sizeof(buf)); |
264 | msg("removing struct '%s'\n", buf); |
265 | //del_struc_members(struc, 0, get_max_offset(struc)); |
266 | del_struc(struc); |
267 | |
268 | idx = get_first_struc_idx(); |
269 | } |
270 | |
97609f07 |
271 | rebuild_name_cache(); |
272 | |
15c7b2a4 |
273 | // 1st pass: walk through all funcs |
97609f07 |
274 | ea = inf.minEA; |
275 | func = get_func(ea); |
d8891fcc |
276 | while (func != NULL) |
277 | { |
15c7b2a4 |
278 | func_tail_iterator_t fti(func); |
279 | if (!fti.main()) { |
280 | msg("%x: func_tail_iterator_t main failed\n", ea); |
281 | return; |
282 | } |
283 | const area_t &f_area = fti.chunk(); |
284 | ea = f_area.startEA; |
285 | |
286 | // rename global syms which conflict with frame member names |
d8891fcc |
287 | frame = get_frame(func); |
288 | if (frame != NULL) |
289 | { |
290 | for (m = 0; m < (int)frame->memqty; m++) |
291 | { |
292 | ret = get_member_name(frame->members[m].id, buf, sizeof(buf)); |
293 | if (ret <= 0) { |
294 | msg("%x: member has no name?\n", ea); |
295 | return; |
296 | } |
297 | if (buf[0] == ' ') // what's this? |
298 | continue; |
299 | if (IS_START(buf, "arg_") || IS_START(buf, "var_")) |
300 | continue; |
301 | |
1caf86bb |
302 | // check for dupe names |
303 | int m1, dupe = 0; |
304 | for (m1 = 0; m1 < m; m1++) { |
305 | get_member_name(frame->members[m1].id, buf2, sizeof(buf2)); |
306 | if (stricmp(buf, buf2) == 0) |
307 | dupe = 1; |
308 | } |
309 | |
310 | if (is_name_reserved(buf) || dupe) { |
d8891fcc |
311 | msg("%x: renaming '%s'\n", ea, buf); |
312 | qstrncat(buf, "_", sizeof(buf)); |
313 | ret = set_member_name(frame, frame->members[m].soff, buf); |
314 | if (!ret) { |
315 | msg("%x: renaming failed\n", ea); |
316 | return; |
317 | } |
318 | } |
319 | |
97609f07 |
320 | p = buf; |
321 | pp = (char **)bsearch(&p, name_cache, name_cache_size, |
322 | sizeof(name_cache[0]), name_cache_cmp); |
323 | if (pp == NULL) |
d8891fcc |
324 | continue; |
325 | |
97609f07 |
326 | tmp_ea = get_name_ea(BADADDR, *pp); |
327 | msg("%x: renaming '%s' because of '%s' at %x\n", |
328 | tmp_ea, *pp, buf, ea); |
329 | my_rename(tmp_ea, *pp); |
d8891fcc |
330 | } |
331 | } |
332 | |
a84bddd1 |
333 | // detect tailcalls to next func with 'jmp $+5' (offset 0) |
334 | if (f_area.endEA - f_area.startEA >= 5 |
335 | && decode_insn(f_area.endEA - 5) && cmd.itype == NN_jmp |
336 | && cmd.Operands[0].type == o_near |
337 | && cmd.Operands[0].addr == f_area.endEA |
338 | && get_name(BADADDR, f_area.endEA, buf, sizeof(buf)) |
339 | && get_cmt(f_area.endEA - 5, false, buf2, sizeof(buf2)) <= 0) |
340 | { |
341 | qsnprintf(buf2, sizeof(buf2), "sctpatch: jmp %s", buf); |
342 | set_cmt(f_area.endEA - 5, buf2, false); |
343 | } |
344 | |
d8891fcc |
345 | func = get_next_func(ea); |
15c7b2a4 |
346 | } |
347 | |
b587e6ae |
348 | // 2nd pass over whole .text and .(ro)data segments |
15c7b2a4 |
349 | for (ea = inf.minEA; ea != BADADDR; ea = next_head(ea, inf.maxEA)) |
350 | { |
351 | segment_t *seg = getseg(ea); |
b587e6ae |
352 | if (!seg) |
353 | break; |
354 | if (seg->type == SEG_XTRN) |
355 | continue; |
356 | if (seg->type != SEG_CODE && seg->type != SEG_DATA) |
15c7b2a4 |
357 | break; |
358 | |
b587e6ae |
359 | ea_flags = get_flags_novalue(ea); |
15c7b2a4 |
360 | func = get_func(ea); |
361 | if (isCode(ea_flags)) |
362 | { |
363 | if (!decode_insn(ea)) { |
364 | msg("%x: decode_insn() failed\n", ea); |
365 | continue; |
366 | } |
367 | |
b587e6ae |
368 | // masm doesn't understand IDA's float/xmm types |
369 | if (cmd.itype == NN_fld || cmd.itype == NN_fst |
370 | || cmd.itype == NN_movapd || cmd.itype == NN_movlpd) |
371 | { |
372 | for (o = 0; o < UA_MAXOP; o++) { |
373 | if (cmd.Operands[o].type == o_void) |
374 | break; |
375 | |
376 | if (cmd.Operands[o].type == o_mem) { |
377 | tmp_ea = cmd.Operands[o].addr; |
11437ea1 |
378 | flags_t tmp_flg = get_flags_novalue(tmp_ea); |
379 | buf[0] = 0; |
380 | if (isDouble(tmp_flg)) |
feb0ee5d |
381 | { |
b587e6ae |
382 | get_name(ea, tmp_ea, buf, sizeof(buf)); |
11437ea1 |
383 | msg("%x: converting dbl %x '%s'\n", ea, tmp_ea, buf); |
384 | doQwrd(tmp_ea, 8); |
385 | } |
386 | if (isOwrd(tmp_flg) || isYwrd(tmp_flg) || isTbyt(tmp_flg)) |
387 | { |
388 | get_name(ea, tmp_ea, buf, sizeof(buf)); |
389 | msg("%x: undefining lrg %x '%s'\n", ea, tmp_ea, buf); |
b587e6ae |
390 | do_unknown(tmp_ea, DOUNK_EXPAND); |
391 | } |
392 | } |
393 | } |
394 | } |
1caf86bb |
395 | else if (cmd.itype == NN_lea) { |
fc1c61f5 |
396 | // detect code alignment |
1caf86bb |
397 | if (cmd.Operands[0].reg == cmd.Operands[1].reg |
398 | && cmd.Operands[1].type == o_displ |
399 | && cmd.Operands[1].addr == 0) |
400 | { |
ee8e1bea |
401 | // lea eax, [eax+0] |
402 | make_align(ea); |
1caf86bb |
403 | } |
fc1c61f5 |
404 | else if (!isDefArg1(ea_flags) |
405 | && cmd.Operands[1].type == o_mem // why o_mem? |
406 | && cmd.Operands[1].dtyp == dt_dword) |
407 | { |
408 | if (inf.minEA <= cmd.Operands[1].addr |
409 | && cmd.Operands[1].addr < inf.maxEA) |
410 | { |
411 | // lea to segments, like ds:58D6A8h[edx*8] |
412 | msg("%x: lea offset to %x\n", ea, cmd.Operands[1].addr); |
413 | op_offset(ea, 1, REF_OFF32); |
414 | } |
415 | else |
416 | { |
417 | // ds:0[eax*8] -> [eax*8+0] |
418 | msg("%x: dropping ds: for %x\n", ea, cmd.Operands[1].addr); |
419 | op_hex(ea, 1); |
420 | } |
421 | } |
1caf86bb |
422 | } |
ee8e1bea |
423 | else if (cmd.itype == NN_mov && cmd.segpref == 0x1e // 2e? |
424 | && cmd.Operands[0].type == o_reg |
425 | && cmd.Operands[1].type == o_reg |
426 | && cmd.Operands[0].dtyp == cmd.Operands[1].dtyp |
427 | && cmd.Operands[0].reg == cmd.Operands[1].reg) |
428 | { |
429 | // db 2Eh; mov eax, eax |
430 | make_align(ea); |
431 | } |
b587e6ae |
432 | |
15c7b2a4 |
433 | // find non-local branches |
b587e6ae |
434 | if (is_insn_jmp(cmd.itype) && cmd.Operands[0].type == o_near) |
15c7b2a4 |
435 | { |
436 | target_ea = cmd.Operands[0].addr; |
437 | if (func == NULL) |
438 | nonlocal_add(target_ea); |
439 | else { |
440 | ret = get_func_chunknum(func, target_ea); |
441 | if (ret != 0) { |
442 | // a jump to another func or chunk |
443 | // check if it lands on func start |
444 | if (!isFunc(get_flags_novalue(target_ea))) |
445 | nonlocal_add(target_ea); |
446 | } |
447 | } |
448 | } |
449 | } |
450 | else { // not code |
1caf86bb |
451 | int do_undef = 0; |
452 | ea_size = get_item_size(ea); |
453 | |
15c7b2a4 |
454 | if (func == NULL && isOff0(ea_flags)) { |
15c7b2a4 |
455 | for (tmp_ea = 0; tmp_ea < ea_size; tmp_ea += 4) |
456 | nonlocal_add(get_long(ea + tmp_ea)); |
457 | } |
b587e6ae |
458 | |
459 | // IDA vs masm float/mmx/xmm type incompatibility |
11437ea1 |
460 | if (isDouble(ea_flags)) |
461 | { |
462 | msg("%x: converting double\n", ea); |
463 | doQwrd(ea, 8); |
464 | } |
465 | else if (isTbyt(ea_flags) || isPackReal(ea_flags)) |
b587e6ae |
466 | { |
1caf86bb |
467 | do_undef = 1; |
468 | } |
469 | else if (isOwrd(ea_flags)) { |
b587e6ae |
470 | buf[0] = 0; |
471 | get_name(BADADDR, ea, buf, sizeof(buf)); |
1caf86bb |
472 | if (IS_START(buf, "xmm")) |
473 | do_undef = 1; |
474 | } |
475 | // masm doesn't understand IDA's unicode |
476 | else if (isASCII(ea_flags) && ea_size >= 4 |
477 | && (get_long(ea) & 0xff00ff00) == 0) // lame.. |
478 | { |
479 | do_undef = 1; |
480 | } |
481 | // masm doesn't understand large aligns |
e74324f9 |
482 | else if (isAlign(ea_flags) && ea_size >= 0x10) |
483 | { |
1caf86bb |
484 | msg("%x: undefining align %d\n", ea, ea_size); |
b587e6ae |
485 | do_unknown(ea, DOUNK_EXPAND); |
486 | } |
1caf86bb |
487 | |
488 | if (do_undef) { |
b587e6ae |
489 | buf[0] = 0; |
490 | get_name(BADADDR, ea, buf, sizeof(buf)); |
1caf86bb |
491 | msg("%x: undefining '%s'\n", ea, buf); |
492 | do_unknown(ea, DOUNK_EXPAND); |
b587e6ae |
493 | } |
494 | } |
495 | } |
496 | |
e74324f9 |
497 | // check namelist for reserved names and |
498 | // matching names with different case (nasm ignores case) |
b587e6ae |
499 | n = get_nlist_size(); |
500 | for (i = 0; i < n; i++) { |
501 | ea = get_nlist_ea(i); |
502 | name = get_nlist_name(i); |
503 | if (name == NULL) { |
504 | msg("%x: null name?\n", ea); |
505 | continue; |
506 | } |
e74324f9 |
507 | qsnprintf(buf, sizeof(buf), "%s", name); |
508 | |
509 | int need_rename = is_name_reserved(name); |
510 | if (!need_rename) { |
511 | p = buf; |
512 | pp = (char **)bsearch(&p, name_cache, name_cache_size, |
513 | sizeof(name_cache[0]), name_cache_cmp); |
514 | if (pp != NULL) { |
515 | if (pp > name_cache && stricmp(pp[-1], pp[0]) == 0) |
516 | need_rename = 1; |
517 | else if (pp < name_cache + name_cache_size - 1 |
518 | && stricmp(pp[0], pp[1]) == 0) |
519 | { |
520 | need_rename = 1; |
521 | } |
522 | } |
523 | } |
b587e6ae |
524 | |
b25f320a |
525 | // rename vars with '?@' (funcs are ok) |
526 | int change_qat = 0; |
527 | ea_flags = get_flags_novalue(ea); |
3a0df310 |
528 | if (!isCode(ea_flags)) { |
9bbecbfb |
529 | if (IS_START(name, "__imp_")) |
530 | /* some import */; |
531 | else if (name[0] == '?' && strstr(name, "@@")) |
532 | /* c++ import */; |
533 | else if (strchr(name, '?')) |
3a0df310 |
534 | change_qat = 1; |
535 | else if ((cp = strchr(name, '@'))) { |
536 | char *endp = NULL; |
537 | strtol(cp + 1, &endp, 10); |
538 | if (endp == NULL || *endp != 0) |
539 | change_qat = 1; |
540 | } |
541 | } |
b25f320a |
542 | |
e74324f9 |
543 | if (need_rename || change_qat) { |
b587e6ae |
544 | msg("%x: renaming name '%s'\n", ea, name); |
b25f320a |
545 | |
546 | if (change_qat) { |
547 | for (p = buf; *p != 0; p++) { |
548 | if (*p == '?' || *p == '@') { |
549 | qsnprintf(buf2, sizeof(buf2), "%02x", (unsigned char)*p); |
550 | memmove(p + 1, p, strlen(p) + 1); |
551 | memcpy(p, buf2, 2); |
552 | } |
553 | } |
554 | } |
555 | |
97609f07 |
556 | my_rename(ea, buf); |
15c7b2a4 |
557 | } |
558 | } |
559 | |
560 | if (nonlocal_bt_cnt > 1) { |
561 | qsort(nonlocal_bt, nonlocal_bt_cnt, |
562 | sizeof(nonlocal_bt[0]), nonlocal_bt_cmp); |
d8891fcc |
563 | } |
564 | |
565 | char *fname = askfile_c(1, NULL, "Save asm file"); |
566 | if (fname == NULL) |
567 | return; |
568 | fout = qfopen(fname, "w"); |
569 | if (fout == NULL) { |
570 | msg("couldn't open '%s'\n", fname); |
571 | return; |
572 | } |
573 | |
574 | show_wait_box("Saving.."); |
575 | |
576 | // deal with the beginning |
577 | ea = inf.minEA; |
578 | int flags = 0; // calc_default_idaplace_flags(); |
579 | linearray_t ln(&flags); |
580 | idaplace_t pl; |
581 | pl.ea = ea; |
582 | pl.lnnum = 0; |
583 | ln.set_place(&pl); |
584 | n = ln.get_linecnt(); |
585 | for (i = 0; i < n - 1; i++) { |
e74324f9 |
586 | do_def_line(buf, sizeof(buf), ln.down(), ea, NULL); |
d8891fcc |
587 | if (strstr(buf, "include")) |
588 | continue; |
589 | |
590 | fout_line++; |
591 | qfprintf(fout, "%s\n", buf); |
592 | p = strstr(buf, ".mmx"); |
593 | if (p != NULL) { |
594 | memcpy(p, ".xmm", 4); |
595 | fout_line++; |
596 | qfprintf(fout, "%s\n", buf); |
1402b79d |
597 | continue; |
598 | } |
599 | p = strstr(buf, ".model"); |
600 | if (p != NULL) { |
601 | qstrncpy(p, "include imports.inc", sizeof(buf) - (p - buf)); |
602 | fout_line++; |
603 | qfprintf(fout, "\n%s\n", buf); |
de8a204c |
604 | i++; |
605 | break; |
d8891fcc |
606 | } |
607 | } |
b587e6ae |
608 | pl.lnnum = i; |
d8891fcc |
609 | |
610 | for (;;) |
611 | { |
94cd6e34 |
612 | int drop_large = 0, do_rva = 0, set_scale = 0, jmp_near = 0; |
ed6ebb48 |
613 | int word_imm = 0, dword_imm = 0, do_pushf = 0, do_nops = 0; |
15c7b2a4 |
614 | |
d8891fcc |
615 | if ((ea >> 14) != ui_ea_block) { |
616 | ui_ea_block = ea >> 14; |
617 | showAddr(ea); |
618 | if (wasBreak()) |
619 | break; |
620 | } |
621 | |
e74324f9 |
622 | func = get_func(ea); |
623 | |
d8891fcc |
624 | segment_t *seg = getseg(ea); |
b587e6ae |
625 | if (!seg || (seg->type != SEG_CODE && seg->type != SEG_DATA)) |
d8891fcc |
626 | goto pass; |
627 | |
b587e6ae |
628 | ea_flags = get_flags_novalue(ea); |
629 | if (isCode(ea_flags)) |
630 | { |
631 | if (!decode_insn(ea)) |
632 | goto pass; |
d8891fcc |
633 | |
1caf86bb |
634 | if (is_insn_jmp(cmd.itype) && cmd.Operands[0].type == o_near |
635 | && cmd.Operands[0].dtyp == dt_dword) |
636 | { |
637 | jmp_near = 1; |
638 | } |
639 | else if ((cmd.itype == NN_pushf || cmd.itype == NN_popf) |
640 | && natop()) |
641 | { |
642 | do_pushf = 1; |
643 | } |
644 | |
b587e6ae |
645 | for (o = 0; o < UA_MAXOP; o++) { |
1caf86bb |
646 | const op_t &opr = cmd.Operands[o]; |
647 | if (opr.type == o_void) |
b587e6ae |
648 | break; |
d8891fcc |
649 | |
1caf86bb |
650 | // correct? |
651 | if (opr.type == o_mem && opr.specval_shorts.high == 0x21) |
b587e6ae |
652 | drop_large = 1; |
1caf86bb |
653 | if (opr.hasSIB && x86_scale(opr) == 0 |
654 | && x86_index(opr) != INDEX_NONE) |
655 | { |
656 | set_scale = 1; |
657 | } |
658 | // annoying alignment variant.. |
659 | if (opr.type == o_imm && opr.dtyp == dt_dword |
660 | && (opr.value < 0x80 || opr.value > 0xffffff80) |
661 | && cmd.size >= opr.offb + 4) |
662 | { |
663 | if (get_long(ea + opr.offb) == opr.value) |
664 | dword_imm = 1; |
665 | } |
666 | else if (opr.type == o_imm && opr.dtyp == dt_word |
667 | && (opr.value < 0x80 || opr.value > 0xff80) |
668 | && cmd.size >= opr.offb + 2) |
669 | { |
670 | if (get_word(ea + opr.offb) == (ushort)opr.value) |
671 | word_imm = 1; |
15c7b2a4 |
672 | } |
ed6ebb48 |
673 | else if (opr.type == o_displ && opr.addr == 0 |
674 | && opr.offb != 0 && opr.hasSIB && opr.sib == 0x24) |
675 | { |
676 | // uses [esp+0] with 0 encoded into op |
677 | do_nops++; |
678 | } |
15c7b2a4 |
679 | } |
b587e6ae |
680 | } |
681 | else { // not code |
682 | if (isOff0(ea_flags)) |
94cd6e34 |
683 | do_rva = 1; |
d8891fcc |
684 | } |
685 | |
686 | pass: |
b587e6ae |
687 | n = ln.get_linecnt(); |
688 | for (i = pl.lnnum; i < n; i++) { |
e74324f9 |
689 | do_def_line(buf, sizeof(buf), ln.down(), ea, func); |
15c7b2a4 |
690 | |
1402b79d |
691 | char *fw; |
692 | for (fw = buf; *fw != 0 && *fw == ' '; ) |
693 | fw++; |
694 | |
1caf86bb |
695 | // patches.. |
b587e6ae |
696 | if (drop_large) { |
1402b79d |
697 | p = strstr(fw, "large "); |
b587e6ae |
698 | if (p != NULL) |
699 | memmove(p, p + 6, strlen(p + 6) + 1); |
700 | } |
94cd6e34 |
701 | while (do_rva) { |
1402b79d |
702 | p = strstr(fw, " rva "); |
b587e6ae |
703 | if (p == NULL) |
704 | break; |
94cd6e34 |
705 | memmove(p + 4 + 3, p + 4, strlen(p + 4) + 1); |
706 | memcpy(p + 1, "offset", 6); |
b587e6ae |
707 | } |
1caf86bb |
708 | if (set_scale) { |
1402b79d |
709 | p = strchr(fw, '['); |
1caf86bb |
710 | if (p != NULL) |
711 | p = strchr(p, '+'); |
712 | if (p != NULL && p[1] == 'e') { |
713 | p += 4; |
714 | // scale is 1, must specify it explicitly so that |
715 | // masm chooses the right scaled reg |
716 | memmove(p + 2, p, strlen(p) + 1); |
717 | memcpy(p, "*1", 2); |
718 | } |
719 | } |
720 | else if (jmp_near) { |
9aaf1dcf |
721 | p = NULL; |
722 | if (fw != buf && fw[0] == 'j') |
723 | p = fw; |
1caf86bb |
724 | while (p && *p != ' ') |
725 | p++; |
726 | while (p && *p == ' ') |
727 | p++; |
728 | if (p != NULL) { |
729 | memmove(p + 9, p, strlen(p) + 1); |
730 | memcpy(p, "near ptr ", 9); |
9aaf1dcf |
731 | jmp_near = 0; |
1caf86bb |
732 | } |
733 | } |
734 | if (word_imm) { |
1402b79d |
735 | p = strstr(fw, ", "); |
1caf86bb |
736 | if (p != NULL && '0' <= p[2] && p[2] <= '9') { |
737 | p += 2; |
738 | memmove(p + 9, p, strlen(p) + 1); |
739 | memcpy(p, "word ptr ", 9); |
740 | } |
741 | } |
742 | else if (dword_imm) { |
1402b79d |
743 | p = strstr(fw, ", "); |
1caf86bb |
744 | if (p != NULL && '0' <= p[2] && p[2] <= '9') { |
745 | p += 2; |
746 | memmove(p + 10, p, strlen(p) + 1); |
747 | memcpy(p, "dword ptr ", 10); |
748 | } |
749 | } |
750 | else if (do_pushf) { |
1402b79d |
751 | p = strstr(fw, "pushf"); |
1caf86bb |
752 | if (p == NULL) |
1402b79d |
753 | p = strstr(fw, "popf"); |
1caf86bb |
754 | if (p != NULL) { |
755 | p = strchr(p, 'f') + 1; |
756 | memmove(p + 1, p, strlen(p) + 1); |
757 | *p = 'd'; |
758 | } |
759 | } |
b587e6ae |
760 | |
de8a204c |
761 | if (fw[0] == 'a' && IS_START(fw, "assume cs")) { |
762 | // "assume cs" causes problems with ext syms |
763 | memmove(fw + 1, fw, strlen(fw) + 1); |
764 | *fw = ';'; |
765 | } |
766 | else if (fw[0] == 'e' && IS_START(fw, "end") && fw[3] == ' ') { |
1402b79d |
767 | fout_line++; |
768 | qfprintf(fout, "include public.inc\n\n"); |
769 | |
770 | // kill entry point |
771 | fw[3] = 0; |
772 | } |
773 | |
b587e6ae |
774 | fout_line++; |
775 | qfprintf(fout, "%s\n", buf); |
776 | } |
d8891fcc |
777 | |
ed6ebb48 |
778 | while (do_nops-- > 0) |
779 | qfprintf(fout, " nop ; adj\n"); |
780 | |
15c7b2a4 |
781 | // note: next_head skips some undefined stuff |
d8891fcc |
782 | ea = next_not_tail(ea); // correct? |
15c7b2a4 |
783 | if (ea == BADADDR) |
d8891fcc |
784 | break; |
785 | |
786 | pl.ea = ea; |
787 | pl.lnnum = 0; |
788 | ln.set_place(&pl); |
d8891fcc |
789 | } |
790 | |
791 | if (fout != NULL) |
792 | qfclose(fout); |
15c7b2a4 |
793 | if (fname != NULL) |
794 | qfree(fname); |
d8891fcc |
795 | |
796 | hide_wait_box(); |
797 | msg("%d lines saved.\n", fout_line); |
798 | } |
799 | |
800 | //-------------------------------------------------------------------------- |
801 | |
3682b4b1 |
802 | static const char comment[] = "Generate disassembly for nasm"; |
d8891fcc |
803 | static const char help[] = "Generate asm file\n"; |
804 | static const char wanted_name[] = "Save asm"; |
3682b4b1 |
805 | static const char wanted_hotkey[] = "Shift-S"; |
d8891fcc |
806 | |
807 | //-------------------------------------------------------------------------- |
808 | // |
809 | // PLUGIN DESCRIPTION BLOCK |
810 | // |
811 | //-------------------------------------------------------------------------- |
812 | plugin_t PLUGIN = |
813 | { |
814 | IDP_INTERFACE_VERSION, |
815 | 0, // plugin flags |
816 | init, // initialize |
817 | term, // terminate. this pointer may be NULL. |
818 | run, // invoke plugin |
819 | comment, // long comment about the plugin |
820 | // it could appear in the status line |
821 | // or as a hint |
822 | help, // multiline help about the plugin |
823 | wanted_name, // the preferred short name of the plugin |
824 | wanted_hotkey // the preferred hotkey to run the plugin |
825 | }; |
826 | |
827 | // vim:ts=2:shiftwidth=2:expandtab |