X-Git-Url: https://notaz.gp2x.de/cgi-bin/gitweb.cgi?a=blobdiff_plain;f=tools%2Ftranslate.c;h=e77e318a77dcc6b0596c97c6eeeddf8ab96b2f4d;hb=4c45fa7302c0baa73d1799d5e5f44810122013fc;hp=dd7ccb111682da0cd085f566cb82a4ac6a866535;hpb=33c35af6a3f14ac142b0ec04f5275bff01a0b0fa;p=ia32rtools.git diff --git a/tools/translate.c b/tools/translate.c index dd7ccb1..e77e318 100644 --- a/tools/translate.c +++ b/tools/translate.c @@ -8,11 +8,13 @@ #define ARRAY_SIZE(x) (sizeof(x) / sizeof(x[0])) #define IS(w, y) !strcmp(w, y) +#define IS_START(w, y) !strncmp(w, y, strlen(y)) #include "protoparse.h" -const char *asmfn; +static const char *asmfn; static int asmln; +static FILE *g_fhdr; #define anote(fmt, ...) \ printf("%s:%d: note: " fmt, asmfn, asmln, ##__VA_ARGS__) @@ -32,6 +34,7 @@ enum op_flags { OPF_CC = (1 << 4), /* uses flags */ OPF_TAIL = (1 << 5), /* ret or tail call */ OPF_REP = (1 << 6), /* prefixed by rep */ + OPF_RSAVE = (1 << 7), /* push/pop is local reg save/load */ }; enum op_op { @@ -46,6 +49,7 @@ enum op_op { OP_NOT, OP_CDQ, OP_STOS, + OP_MOVS, OP_RET, OP_ADD, OP_SUB, @@ -55,6 +59,8 @@ enum op_op { OP_SHL, OP_SHR, OP_SAR, + OP_ROL, + OP_ROR, OP_ADC, OP_SBB, OP_INC, @@ -107,6 +113,7 @@ enum opr_lenmod { struct parsed_opr { enum opr_type type; enum opr_lenmod lmod; + unsigned int is_ptr:1; // pointer in C int reg; unsigned int val; char name[256]; @@ -122,8 +129,8 @@ struct parsed_op { int pfomask; // flagop: parsed_flag_op that can't be delayed int argmask; // push: args that are altered before call int cc_scratch; // scratch storage during analysis - int bt_i; // branch target (for branches) - struct parsed_op *lrl; // label reference list entry + int bt_i; // branch target for branches + struct parsed_data *btj;// branch targets for jumptables void *datap; }; @@ -137,18 +144,51 @@ struct parsed_equ { int offset; }; -#define MAX_OPS 1024 +struct parsed_data { + char label[256]; + enum opr_type type; + enum opr_lenmod lmod; + int count; + int count_alloc; + struct { + union { + char *label; + int val; + } u; + int bt_i; + } *d; +}; + +struct label_ref { + int i; + struct label_ref *next; +}; + +enum ida_func_attr { + IDAFA_BP_FRAME = (1 << 0), + IDAFA_LIB_FUNC = (1 << 1), + IDAFA_STATIC = (1 << 2), + IDAFA_NORETURN = (1 << 3), + IDAFA_THUNK = (1 << 4), + IDAFA_FPD = (1 << 5), +}; + +#define MAX_OPS 4096 static struct parsed_op ops[MAX_OPS]; static struct parsed_equ *g_eqs; static int g_eqcnt; static char g_labels[MAX_OPS][32]; -static struct parsed_op *g_label_refs[MAX_OPS]; +static struct label_ref g_label_refs[MAX_OPS]; static struct parsed_proto g_func_pp; +static struct parsed_data *g_func_pd; +static int g_func_pd_cnt; static char g_func[256]; static char g_comment[256]; static int g_bp_frame; -static int g_bp_stack; +static int g_sp_frame; +static int g_stack_fsz; +static int g_ida_func_attr; #define ferr(op_, fmt, ...) do { \ printf("error:%s:#%ld: '%s': " fmt, g_func, (op_) - ops, \ dump_op(op_), ##__VA_ARGS__); \ @@ -280,7 +320,7 @@ static int parse_indmode(char *name, int *regmask, int need_c_cvt) *d = 0; // skip 'ds:' prefix - if (!strncmp(s, "ds:", 3)) + if (IS_START(s, "ds:")) s += 3; s = next_idt(w, sizeof(w), s); @@ -312,6 +352,89 @@ pass: return c; } +static int is_reg_in_str(const char *s) +{ + int i; + + if (strlen(s) < 3 || (s[3] && !my_issep(s[3]) && !my_isblank(s[3]))) + return 0; + + for (i = 0; i < ARRAY_SIZE(regs_r32); i++) + if (!strncmp(s, regs_r32[i], 3)) + return 1; + + return 0; +} + +static const char *parse_stack_el(const char *name, char *extra_reg) +{ + const char *p, *p2, *s; + char *endp = NULL; + char buf[32]; + long val; + int len; + + p = name; + if (IS_START(p + 3, "+ebp+") && is_reg_in_str(p)) { + p += 4; + if (extra_reg != NULL) { + strncpy(extra_reg, name, 3); + extra_reg[4] = 0; + } + } + + if (IS_START(p, "ebp+")) { + p += 4; + + p2 = strchr(p, '+'); + if (p2 != NULL && is_reg_in_str(p)) { + if (extra_reg != NULL) { + strncpy(extra_reg, p, p2 - p); + extra_reg[p2 - p] = 0; + } + p = p2 + 1; + } + + if (!('0' <= *p && *p <= '9')) + return p; + + return NULL; + } + + if (!IS_START(name, "esp+")) + return NULL; + + p = strchr(name + 4, '+'); + if (p) { + // must be a number after esp+, already converted to 0x.. + s = name + 4; + if (!('0' <= *s && *s <= '9')) { + aerr("%s nan?\n", __func__); + return NULL; + } + if (s[0] == '0' && s[1] == 'x') + s += 2; + len = p - s; + if (len < sizeof(buf) - 1) { + strncpy(buf, s, len); + buf[len] = 0; + val = strtol(buf, &endp, 16); + if (val == 0 || *endp != 0) { + aerr("%s num parse fail for '%s'\n", __func__, buf); + return NULL; + } + } + p++; + } + else + p = name + 4; + + if ('0' <= *p && *p <= '9') + return NULL; + + return p; +} + static int guess_lmod_from_name(struct parsed_opr *opr) { if (!strncmp(opr->name, "dword_", 6)) { @@ -329,6 +452,74 @@ static int guess_lmod_from_name(struct parsed_opr *opr) return 0; } +static int guess_lmod_from_c_type(struct parsed_opr *opr, const char *c_type) +{ + static const char *ptr_types[] = { + "LPCSTR", + }; + static const char *dword_types[] = { + "int", "_DWORD", "DWORD", "HANDLE", "HWND", "HMODULE", + }; + static const char *word_types[] = { + "__int16", "unsigned __int16", + }; + static const char *byte_types[] = { + "char", "__int8", "unsigned __int8", "BYTE", + }; + int i; + + if (strchr(c_type, '*')) { + opr->lmod = OPLM_DWORD; + opr->is_ptr = 1; + return 1; + } + + for (i = 0; i < ARRAY_SIZE(dword_types); i++) { + if (IS(c_type, dword_types[i])) { + opr->lmod = OPLM_DWORD; + return 1; + } + } + + for (i = 0; i < ARRAY_SIZE(ptr_types); i++) { + if (IS(c_type, ptr_types[i])) { + opr->lmod = OPLM_DWORD; + opr->is_ptr = 1; + return 1; + } + } + + for (i = 0; i < ARRAY_SIZE(word_types); i++) { + if (IS(c_type, word_types[i])) { + opr->lmod = OPLM_WORD; + return 1; + } + } + + for (i = 0; i < ARRAY_SIZE(byte_types); i++) { + if (IS(c_type, byte_types[i])) { + opr->lmod = OPLM_BYTE; + return 1; + } + } + + anote("unhandled C type '%s' for '%s'\n", c_type, opr->name); + return 0; +} + +static enum opr_type lmod_from_directive(const char *d) +{ + if (IS(d, "dd")) + return OPLM_DWORD; + else if (IS(d, "dw")) + return OPLM_WORD; + else if (IS(d, "db")) + return OPLM_BYTE; + + aerr("unhandled directive: '%s'\n", d); + return OPLM_UNSPEC; +} + static void setup_reg_opr(struct parsed_opr *opr, int reg, enum opr_lenmod lmod, int *regmask) { @@ -338,72 +529,100 @@ static void setup_reg_opr(struct parsed_opr *opr, int reg, enum opr_lenmod lmod, *regmask |= 1 << reg; } -static struct parsed_equ *equ_find(struct parsed_op *po, const char *name); +static struct parsed_equ *equ_find(struct parsed_op *po, const char *name, + int *extra_offs); static int parse_operand(struct parsed_opr *opr, int *regmask, int *regmask_indirect, - char words[16][256], int wordc, int w, unsigned int op_flags) + char words[16][256], int wordc, int w, unsigned int op_flags) { + struct parsed_proto pp; enum opr_lenmod tmplmod; int ret, len; long number; + int wordc_in; + char *tmp; int i; - if (w >= wordc) - aerr("parse_operand w %d, wordc %d\n", w, wordc); + if (w >= wordc) + aerr("parse_operand w %d, wordc %d\n", w, wordc); - opr->reg = xUNSPEC; + opr->reg = xUNSPEC; - for (i = w; i < wordc; i++) { - len = strlen(words[i]); - if (words[i][len - 1] == ',') { - words[i][len - 1] = 0; - wordc = i + 1; - break; - } - } + for (i = w; i < wordc; i++) { + len = strlen(words[i]); + if (words[i][len - 1] == ',') { + words[i][len - 1] = 0; + wordc = i + 1; + break; + } + } - if (op_flags & OPF_JMP) { - const char *label; - - if (wordc - w == 3 && IS(words[w + 1], "ptr")) - label = words[w + 2]; - else if (wordc - w == 2 && IS(words[w], "short")) - label = words[w + 1]; - else if (wordc - w == 1) - label = words[w]; - else - aerr("jump parse error"); - - opr->type = OPT_LABEL; - strcpy(opr->name, label); - return wordc; - } + wordc_in = wordc - w; - if (wordc - w >= 3) { - if (IS(words[w + 1], "ptr")) { - if (IS(words[w], "dword")) - opr->lmod = OPLM_DWORD; - else if (IS(words[w], "word")) - opr->lmod = OPLM_WORD; - else if (IS(words[w], "byte")) - opr->lmod = OPLM_BYTE; - else - aerr("type parsing failed\n"); - w += 2; - } - } + if ((op_flags & OPF_JMP) && wordc_in > 0 + && !('0' <= words[w][0] && words[w][0] <= '9')) + { + const char *label = NULL; + + if (wordc_in == 3 && !strncmp(words[w], "near", 4) + && IS(words[w + 1], "ptr")) + label = words[w + 2]; + else if (wordc_in == 2 && IS(words[w], "short")) + label = words[w + 1]; + else if (wordc_in == 1 + && strchr(words[w], '[') == NULL + && parse_reg(&tmplmod, words[w]) < 0) + label = words[w]; + + if (label != NULL) { + opr->type = OPT_LABEL; + if (IS_START(label, "ds:")) + label += 3; + strcpy(opr->name, label); + return wordc; + } + } - if (wordc - w == 2 && IS(words[w], "offset")) { - opr->type = OPT_OFFSET; - strcpy(opr->name, words[w + 1]); - return wordc; - } + if (wordc_in >= 3) { + if (IS(words[w + 1], "ptr")) { + if (IS(words[w], "dword")) + opr->lmod = OPLM_DWORD; + else if (IS(words[w], "word")) + opr->lmod = OPLM_WORD; + else if (IS(words[w], "byte")) + opr->lmod = OPLM_BYTE; + else + aerr("type parsing failed\n"); + w += 2; + wordc_in = wordc - w; + } + } + + if (wordc_in == 2) { + if (IS(words[w], "offset")) { + opr->type = OPT_OFFSET; + strcpy(opr->name, words[w + 1]); + return wordc; + } + if (IS(words[w], "(offset")) { + char *p = strchr(words[w + 1], ')'); + if (p == NULL) + aerr("parse of bracketed offset failed\n"); + *p = 0; + opr->type = OPT_OFFSET; + strcpy(opr->name, words[w + 1]); + return wordc; + } + } - if (wordc - w != 1) + if (wordc_in != 1) aerr("parse_operand 1 word expected\n"); - strcpy(opr->name, words[w]); + tmp = words[w]; + if (IS_START(tmp, "ds:")) + tmp += 3; + strcpy(opr->name, tmp); if (words[w][0] == '[') { opr->type = OPT_REGMEM; @@ -412,9 +631,10 @@ static int parse_operand(struct parsed_opr *opr, aerr("[] parse failure\n"); parse_indmode(opr->name, regmask_indirect, 1); - if (opr->lmod == OPLM_UNSPEC && !strncmp(opr->name, "ebp+", 4)) { + if (opr->lmod == OPLM_UNSPEC && parse_stack_el(opr->name, NULL)) { // might be an equ - struct parsed_equ *eq = equ_find(NULL, opr->name + 4); + struct parsed_equ *eq = + equ_find(NULL, parse_stack_el(opr->name, NULL), &i); if (eq) opr->lmod = eq->lmod; } @@ -446,12 +666,20 @@ static int parse_operand(struct parsed_opr *opr, // most likely var in data segment opr->type = OPT_LABEL; + + ret = proto_parse(g_fhdr, opr->name, &pp); + if (ret == 0) { + if (pp.is_fptr) { + opr->lmod = OPLM_DWORD; + opr->is_ptr = 1; + } + else if (opr->lmod == OPLM_UNSPEC) + guess_lmod_from_c_type(opr, pp.ret_type); + } + proto_release(&pp); + if (opr->lmod == OPLM_UNSPEC) guess_lmod_from_name(opr); - if (opr->lmod != OPLM_UNSPEC) - return wordc; - - // TODO: scan data seg to determine type? return wordc; } @@ -481,6 +709,9 @@ static const struct { { "stosb",OP_STOS, 0, 0, OPF_DATA }, { "stosw",OP_STOS, 0, 0, OPF_DATA }, { "stosd",OP_STOS, 0, 0, OPF_DATA }, + { "movsb",OP_MOVS, 0, 0, OPF_DATA }, + { "movsw",OP_MOVS, 0, 0, OPF_DATA }, + { "movsd",OP_MOVS, 0, 0, OPF_DATA }, { "add", OP_ADD, 2, 2, OPF_DATA|OPF_FLAGS }, { "sub", OP_SUB, 2, 2, OPF_DATA|OPF_FLAGS }, { "and", OP_AND, 2, 2, OPF_DATA|OPF_FLAGS }, @@ -490,6 +721,8 @@ static const struct { { "shr", OP_SHR, 2, 2, OPF_DATA|OPF_FLAGS }, { "sal", OP_SHL, 2, 2, OPF_DATA|OPF_FLAGS }, { "sar", OP_SAR, 2, 2, OPF_DATA|OPF_FLAGS }, + { "rol", OP_ROL, 2, 2, OPF_DATA|OPF_FLAGS }, + { "ror", OP_ROR, 2, 2, OPF_DATA|OPF_FLAGS }, { "adc", OP_ADC, 2, 2, OPF_DATA|OPF_FLAGS|OPF_CC }, { "sbb", OP_SBB, 2, 2, OPF_DATA|OPF_FLAGS|OPF_CC }, { "inc", OP_INC, 1, 1, OPF_DATA|OPF_FLAGS }, @@ -565,7 +798,7 @@ static const struct { static void parse_op(struct parsed_op *op, char words[16][256], int wordc) { - enum opr_lenmod lmod; + enum opr_lenmod lmod = OPLM_UNSPEC; int prefix_flags = 0; int regmask_ind; int regmask; @@ -645,11 +878,28 @@ static void parse_op(struct parsed_op *op, char words[16][256], int wordc) else if (IS(words[op_w], "stosd")) lmod = OPLM_DWORD; op->operand_cnt = 3; - setup_reg_opr(&op->operand[0], xDI, lmod, &op->regmask_dst); - setup_reg_opr(&op->operand[1], xCX, OPLM_DWORD, &op->regmask_dst); + setup_reg_opr(&op->operand[0], xDI, lmod, &op->regmask_src); + setup_reg_opr(&op->operand[1], xCX, OPLM_DWORD, &op->regmask_src); + op->regmask_dst = op->regmask_src; setup_reg_opr(&op->operand[2], xAX, OPLM_DWORD, &op->regmask_src); break; + case OP_MOVS: + if (op->operand_cnt != 0) + break; + if (IS(words[op_w], "movsb")) + lmod = OPLM_BYTE; + else if (IS(words[op_w], "movsw")) + lmod = OPLM_WORD; + else if (IS(words[op_w], "movsd")) + lmod = OPLM_DWORD; + op->operand_cnt = 3; + setup_reg_opr(&op->operand[0], xDI, lmod, &op->regmask_src); + setup_reg_opr(&op->operand[1], xSI, OPLM_DWORD, &op->regmask_src); + setup_reg_opr(&op->operand[2], xCX, OPLM_DWORD, &op->regmask_src); + op->regmask_dst = op->regmask_src; + break; + case OP_IMUL: if (op->operand_cnt != 1) break; @@ -676,6 +926,8 @@ static void parse_op(struct parsed_op *op, char words[16][256], int wordc) case OP_SHL: case OP_SHR: case OP_SAR: + case OP_ROL: + case OP_ROR: if (op->operand[1].lmod == OPLM_UNSPEC) op->operand[1].lmod = OPLM_BYTE; break; @@ -703,6 +955,9 @@ static const char *dump_op(struct parsed_op *po) char *p = out; int i; + if (po == NULL) + return "???"; + snprintf(out, sizeof(out), "%s", op_name(po->op)); for (i = 0; i < po->operand_cnt; i++) { p += strlen(p); @@ -716,6 +971,93 @@ static const char *dump_op(struct parsed_op *po) return out; } +static const char *lmod_type_u(struct parsed_op *po, + enum opr_lenmod lmod) +{ + switch (lmod) { + case OPLM_DWORD: + return "u32"; + case OPLM_WORD: + return "u16"; + case OPLM_BYTE: + return "u8"; + default: + ferr(po, "invalid lmod: %d\n", lmod); + return "(_invalid_)"; + } +} + +static const char *lmod_cast_u(struct parsed_op *po, + enum opr_lenmod lmod) +{ + switch (lmod) { + case OPLM_DWORD: + return ""; + case OPLM_WORD: + return "(u16)"; + case OPLM_BYTE: + return "(u8)"; + default: + ferr(po, "invalid lmod: %d\n", lmod); + return "(_invalid_)"; + } +} + +static const char *lmod_cast_u_ptr(struct parsed_op *po, + enum opr_lenmod lmod) +{ + switch (lmod) { + case OPLM_DWORD: + return "*(u32 *)"; + case OPLM_WORD: + return "*(u16 *)"; + case OPLM_BYTE: + return "*(u8 *)"; + default: + ferr(po, "invalid lmod: %d\n", lmod); + return "(_invalid_)"; + } +} + +static const char *lmod_cast_s(struct parsed_op *po, + enum opr_lenmod lmod) +{ + switch (lmod) { + case OPLM_DWORD: + return "(s32)"; + case OPLM_WORD: + return "(s16)"; + case OPLM_BYTE: + return "(s8)"; + default: + ferr(po, "%s: invalid lmod: %d\n", __func__, lmod); + return "(_invalid_)"; + } +} + +static const char *lmod_cast(struct parsed_op *po, + enum opr_lenmod lmod, int is_signed) +{ + return is_signed ? + lmod_cast_s(po, lmod) : + lmod_cast_u(po, lmod); +} + +static int lmod_bytes(struct parsed_op *po, enum opr_lenmod lmod) +{ + switch (lmod) { + case OPLM_DWORD: + return 4; + case OPLM_WORD: + return 2; + case OPLM_BYTE: + return 1; + default: + ferr(po, "%s: invalid lmod: %d\n", __func__, lmod); + return 0; + } +} + static const char *opr_name(struct parsed_op *po, int opr_num) { if (opr_num >= po->operand_cnt) @@ -739,12 +1081,33 @@ static const char *opr_reg_p(struct parsed_op *po, struct parsed_opr *popr) return regs_r32[popr->reg]; } -static struct parsed_equ *equ_find(struct parsed_op *po, const char *name) +static struct parsed_equ *equ_find(struct parsed_op *po, const char *name, + int *extra_offs) { + const char *p; + char *endp; + int namelen; int i; + *extra_offs = 0; + namelen = strlen(name); + + p = strchr(name, '+'); + if (p != NULL) { + namelen = p - name; + if (namelen <= 0) + ferr(po, "equ parse failed for '%s'\n", name); + + if (IS_START(p, "0x")) + p += 2; + *extra_offs = strtol(p, &endp, 16); + if (*endp != 0) + ferr(po, "equ parse failed for '%s'\n", name); + } + for (i = 0; i < g_eqcnt; i++) - if (IS(g_eqs[i].name, name)) + if (strncmp(g_eqs[i].name, name, namelen) == 0 + && g_eqs[i].name[namelen] == 0) break; if (i >= g_eqcnt) { if (po != NULL) @@ -755,23 +1118,40 @@ static struct parsed_equ *equ_find(struct parsed_op *po, const char *name) return &g_eqs[i]; } -static void bg_frame_access(struct parsed_op *po, enum opr_lenmod lmod, - char *buf, size_t buf_size, const char *bp_arg, - int is_src, int is_lea) +static void stack_frame_access(struct parsed_op *po, + enum opr_lenmod lmod, char *buf, size_t buf_size, + const char *name, int is_src, int is_lea) { const char *prefix = ""; + char ofs_reg[16] = { 0, }; struct parsed_equ *eq; int i, arg_i, arg_s; + const char *bp_arg; + int stack_ra = 0; + int offset = 0; int sf_ofs; + bp_arg = parse_stack_el(name, ofs_reg); snprintf(g_comment, sizeof(g_comment), "%s", bp_arg); + eq = equ_find(po, bp_arg, &offset); + if (eq == NULL) + ferr(po, "detected but missing eq\n"); + + offset += eq->offset; - eq = equ_find(po, bp_arg); + if (!strncmp(name, "ebp", 3)) + stack_ra = 4; - if (eq->offset >= 0) { - arg_i = eq->offset / 4 - 2; + if (stack_ra <= offset && offset < stack_ra + 4) + ferr(po, "reference to ra? %d %d\n", offset, stack_ra); + + if (offset > stack_ra) { + arg_i = (offset - stack_ra - 4) / 4; if (arg_i < 0 || arg_i >= g_func_pp.argc_stack) - ferr(po, "offset %d doesn't map to any arg\n", eq->offset); + ferr(po, "offset %d (%s) doesn't map to any arg\n", + offset, bp_arg); + if (ofs_reg[0] != 0) + ferr(po, "offset reg on arg acecss?\n"); for (i = arg_s = 0; i < g_func_pp.argc; i++) { if (g_func_pp.arg[i].reg != NULL) @@ -788,12 +1168,12 @@ static void bg_frame_access(struct parsed_op *po, enum opr_lenmod lmod, snprintf(buf, buf_size, "%sa%d", is_src ? "(u32)" : "", i + 1); } else { - if (g_bp_stack == 0) - ferr(po, "bp_stack access after it was not detected\n"); + if (g_stack_fsz == 0) + ferr(po, "stack var access without stackframe\n"); - sf_ofs = g_bp_stack + eq->offset; + sf_ofs = g_stack_fsz + offset; if (sf_ofs < 0) - ferr(po, "bp_stack offset %d/%d\n", eq->offset, g_bp_stack); + ferr(po, "bp_stack offset %d/%d\n", offset, g_stack_fsz); if (is_lea) prefix = "(u32)&"; @@ -801,13 +1181,28 @@ static void bg_frame_access(struct parsed_op *po, enum opr_lenmod lmod, switch (lmod) { case OPLM_BYTE: - snprintf(buf, buf_size, "%ssf.b[%d]", prefix, sf_ofs); + if (ofs_reg[0] != 0) + snprintf(buf, buf_size, "%ssf.b[%d+%s]", + prefix, sf_ofs, ofs_reg); + else + snprintf(buf, buf_size, "%ssf.b[%d]", + prefix, sf_ofs); break; case OPLM_WORD: - snprintf(buf, buf_size, "%ssf.w[%d]", prefix, sf_ofs / 2); + if (ofs_reg[0] != 0) + snprintf(buf, buf_size, "%ssf.w[%d+%s/2]", + prefix, sf_ofs / 2, ofs_reg); + else + snprintf(buf, buf_size, "%ssf.w[%d]", + prefix, sf_ofs / 2); break; case OPLM_DWORD: - snprintf(buf, buf_size, "%ssf.d[%d]", prefix, sf_ofs / 4); + if (ofs_reg[0] != 0) + snprintf(buf, buf_size, "%ssf.d[%d+%s/4]", + prefix, sf_ofs / 4, ofs_reg); + else + snprintf(buf, buf_size, "%ssf.d[%d]", + prefix, sf_ofs / 4); break; default: ferr(po, "bp_stack bad lmod: %d\n", lmod); @@ -818,7 +1213,6 @@ static void bg_frame_access(struct parsed_op *po, enum opr_lenmod lmod, static char *out_src_opr(char *buf, size_t buf_size, struct parsed_op *po, struct parsed_opr *popr, int is_lea) { - const char *cast = ""; char tmp1[256], tmp2[256]; char expr[256]; int ret; @@ -847,9 +1241,9 @@ static char *out_src_opr(char *buf, size_t buf_size, break; case OPT_REGMEM: - if (g_bp_frame && !strncmp(popr->name, "ebp+", 4)) { - bg_frame_access(po, popr->lmod, buf, buf_size, - popr->name + 4, 1, is_lea); + if (parse_stack_el(popr->name, NULL)) { + stack_frame_access(po, popr->lmod, buf, buf_size, + popr->name, 1, is_lea); break; } @@ -868,20 +1262,8 @@ static char *out_src_opr(char *buf, size_t buf_size, break; } - switch (popr->lmod) { - case OPLM_DWORD: - cast = "*(u32 *)"; - break; - case OPLM_WORD: - cast = "*(u16 *)"; - break; - case OPLM_BYTE: - cast = "*(u8 *)"; - break; - default: - ferr(po, "invalid lmod: %d\n", popr->lmod); - } - snprintf(buf, buf_size, "%s(%s)", cast, expr); + snprintf(buf, buf_size, "%s(%s)", + lmod_cast_u_ptr(po, popr->lmod), expr); break; case OPT_LABEL: @@ -937,14 +1319,18 @@ static char *out_dst_opr(char *buf, size_t buf_size, break; case OPT_REGMEM: - if (g_bp_frame && !strncmp(popr->name, "ebp+", 4)) { - bg_frame_access(po, popr->lmod, buf, buf_size, - popr->name + 4, 0, 0); + if (parse_stack_el(popr->name, NULL)) { + stack_frame_access(po, popr->lmod, buf, buf_size, + popr->name, 0, 0); break; } return out_src_opr(buf, buf_size, po, popr, 0); + case OPT_LABEL: + snprintf(buf, buf_size, "%s", popr->name); + break; + default: ferr(po, "invalid dst type: %d\n", popr->type); } @@ -952,65 +1338,10 @@ static char *out_dst_opr(char *buf, size_t buf_size, return buf; } -static const char *lmod_cast_u(struct parsed_op *po, - enum opr_lenmod lmod) -{ - switch (lmod) { - case OPLM_DWORD: - return ""; - case OPLM_WORD: - return "(u16)"; - case OPLM_BYTE: - return "(u8)"; - default: - ferr(po, "invalid lmod: %d\n", lmod); - return "(_invalid_)"; - } -} - -static const char *lmod_cast_s(struct parsed_op *po, - enum opr_lenmod lmod) -{ - switch (lmod) { - case OPLM_DWORD: - return "(s32)"; - case OPLM_WORD: - return "(s16)"; - case OPLM_BYTE: - return "(s8)"; - default: - ferr(po, "%s: invalid lmod: %d\n", __func__, lmod); - return "(_invalid_)"; - } -} - -static const char *lmod_cast(struct parsed_op *po, - enum opr_lenmod lmod, int is_signed) +static enum parsed_flag_op split_cond(struct parsed_op *po, + enum op_op op, int *is_inv) { - return is_signed ? - lmod_cast_s(po, lmod) : - lmod_cast_u(po, lmod); -} - -static int lmod_bytes(struct parsed_op *po, enum opr_lenmod lmod) -{ - switch (lmod) { - case OPLM_DWORD: - return 4; - case OPLM_WORD: - return 2; - case OPLM_BYTE: - return 1; - default: - ferr(po, "%s: invalid lmod: %d\n", __func__, lmod); - return 0; - } -} - -static enum parsed_flag_op split_cond(struct parsed_op *po, - enum op_op op, int *is_inv) -{ - *is_inv = 0; + *is_inv = 0; switch (op) { case OP_JO: @@ -1214,11 +1545,23 @@ static const char *op_to_c(struct parsed_op *po) } } +static void set_flag_no_dup(struct parsed_op *po, enum op_flags flag, + enum op_flags flag_check) +{ + if (po->flags & flag) + ferr(po, "flag %x already set\n", flag); + if (po->flags & flag_check) + ferr(po, "flag_check %x already set\n", flag_check); + + po->flags |= flag; +} + static int scan_for_pop(int i, int opcnt, const char *reg, - int magic, int do_patch) + int magic, int depth, int *maxdepth, int do_flags) { struct parsed_op *po; int ret = 0; + int j; for (; i < opcnt; i++) { po = &ops[i]; @@ -1229,17 +1572,32 @@ static int scan_for_pop(int i, int opcnt, const char *reg, if (po->flags & OPF_TAIL) return -1; // deadend - if (po->flags & OPF_RMD) + if ((po->flags & OPF_RMD) + || (po->op == OP_PUSH && po->argmask)) // arg push continue; if ((po->flags & OPF_JMP) && po->op != OP_CALL) { + if (po->btj != NULL) { + // jumptable + for (j = 0; j < po->btj->count - 1; j++) { + ret |= scan_for_pop(po->btj->d[j].bt_i, opcnt, reg, magic, + depth, maxdepth, do_flags); + if (ret < 0) + return ret; // dead end + } + // follow last jumptable entry + i = po->btj->d[j].bt_i - 1; + continue; + } + if (po->bt_i < 0) { ferr(po, "dead branch\n"); return -1; } if (po->flags & OPF_CC) { - ret |= scan_for_pop(po->bt_i, opcnt, reg, magic, do_patch); + ret |= scan_for_pop(po->bt_i, opcnt, reg, magic, + depth, maxdepth, do_flags); if (ret < 0) return ret; // dead end } @@ -1249,12 +1607,29 @@ static int scan_for_pop(int i, int opcnt, const char *reg, continue; } - if (po->op == OP_POP && po->operand[0].type == OPT_REG + if ((po->op == OP_POP || po->op == OP_PUSH) + && po->operand[0].type == OPT_REG && IS(po->operand[0].name, reg)) { - if (do_patch) - po->flags |= OPF_RMD; - return 1; + if (po->op == OP_PUSH) { + depth++; + if (depth > *maxdepth) + *maxdepth = depth; + if (do_flags) + set_flag_no_dup(po, OPF_RSAVE, OPF_RMD); + } + else if (depth == 0) { + if (do_flags) + set_flag_no_dup(po, OPF_RMD, OPF_RSAVE); + return 1; + } + else { + depth--; + if (depth < 0) // should not happen + ferr(po, "fail with depth\n"); + if (do_flags) + set_flag_no_dup(po, OPF_RSAVE, OPF_RMD); + } } } @@ -1262,7 +1637,8 @@ static int scan_for_pop(int i, int opcnt, const char *reg, } // scan for pop starting from 'ret' op (all paths) -static int scan_for_pop_ret(int i, int opcnt, const char *reg, int do_patch) +static int scan_for_pop_ret(int i, int opcnt, const char *reg, + int flag_set) { int found = 0; int j; @@ -1281,8 +1657,7 @@ static int scan_for_pop_ret(int i, int opcnt, const char *reg, int do_patch) && IS(ops[j].operand[0].name, reg)) { found = 1; - if (do_patch) - ops[j].flags |= OPF_RMD; + ops[j].flags |= flag_set; break; } @@ -1384,29 +1759,88 @@ static int scan_for_cdq_edx(int i) return -1; } +static int scan_for_reg_clear(int i, int reg) +{ + for (; i >= 0; i--) { + if (ops[i].op == OP_XOR + && ops[i].operand[0].lmod == OPLM_DWORD + && ops[i].operand[0].reg == ops[i].operand[1].reg + && ops[i].operand[0].reg == reg) + return i; + + if (ops[i].regmask_dst & (1 << reg)) + return -1; + if (g_labels[i][0] != 0) + return -1; + } + + return -1; +} + +// scan for positive, constant esp adjust +static int scan_for_esp_adjust(int i, int opcnt, int *adj) +{ + for (; i < opcnt; i++) { + if (ops[i].op == OP_ADD && ops[i].operand[0].reg == xSP) { + if (ops[i].operand[1].type != OPT_CONST) + ferr(&ops[i], "non-const esp adjust?\n"); + *adj = ops[i].operand[1].val; + if (*adj & 3) + ferr(&ops[i], "unaligned esp adjust: %x\n", *adj); + return i; + } + + if ((ops[i].flags & (OPF_JMP|OPF_TAIL)) + || ops[i].op == OP_PUSH || ops[i].op == OP_POP) + return -1; + if (g_labels[i][0] != 0) + return -1; + } + + return -1; +} + +static void add_label_ref(struct label_ref *lr, int op_i) +{ + struct label_ref *lr_new; + + if (lr->i == -1) { + lr->i = op_i; + return; + } + + lr_new = calloc(1, sizeof(*lr_new)); + lr_new->i = op_i; + lr->next = lr_new; +} + static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) { struct parsed_op *po, *delayed_flag_op = NULL, *tmp_op; struct parsed_opr *last_arith_dst = NULL; char buf1[256], buf2[256], buf3[256]; struct parsed_proto *pp, *pp_tmp; + struct parsed_data *pd; const char *tmpname; enum parsed_flag_op pfo; int save_arg_vars = 0; int cmp_result_vars = 0; int need_mul_var = 0; int had_decl = 0; + int regmask_save = 0; int regmask_arg = 0; int regmask = 0; int pfomask = 0; + int found = 0; + int depth = 0; int no_output; + int i, j, l; int dummy; int arg; - int i, j; int reg; int ret; - g_bp_frame = g_bp_stack = 0; + g_bp_frame = g_sp_frame = g_stack_fsz = 0; ret = proto_parse(fhdr, funcn, &g_func_pp); if (ret) @@ -1421,7 +1855,7 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) fprintf(fout, ")\n{\n"); // pass1: - // - handle ebp frame, remove ops related to it + // - handle ebp/esp frame, remove ops related to it if (ops[0].op == OP_PUSH && IS(opr_name(&ops[0], 0), "ebp") && ops[1].op == OP_MOV && IS(opr_name(&ops[1], 0), "ebp") @@ -1432,32 +1866,49 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) g_bp_frame = 1; ops[0].flags |= OPF_RMD; ops[1].flags |= OPF_RMD; + i = 2; if (ops[2].op == OP_SUB && IS(opr_name(&ops[2], 0), "esp")) { - g_bp_stack = opr_const(&ops[2], 1); + g_stack_fsz = opr_const(&ops[2], 1); ops[2].flags |= OPF_RMD; + i++; } else { // another way msvc builds stack frame.. i = 2; while (ops[i].op == OP_PUSH && IS(opr_name(&ops[i], 0), "ecx")) { - g_bp_stack += 4; + g_stack_fsz += 4; ops[i].flags |= OPF_RMD; ecx_push++; i++; } + // and another way.. + if (i == 2 && ops[i].op == OP_MOV && ops[i].operand[0].reg == xAX + && ops[i].operand[1].type == OPT_CONST + && ops[i + 1].op == OP_CALL + && IS(opr_name(&ops[i + 1], 0), "__alloca_probe")) + { + g_stack_fsz += ops[i].operand[1].val; + ops[i].flags |= OPF_RMD; + i++; + ops[i].flags |= OPF_RMD; + i++; + } } - i = 2; + found = 0; do { for (; i < opcnt; i++) if (ops[i].op == OP_RET) break; + if (i == opcnt && (ops[i - 1].flags & OPF_JMP) && found) + break; + if (ops[i - 1].op != OP_POP || !IS(opr_name(&ops[i - 1], 0), "ebp")) ferr(&ops[i - 1], "'pop ebp' expected\n"); ops[i - 1].flags |= OPF_RMD; - if (g_bp_stack != 0) { + if (g_stack_fsz != 0) { if (ops[i - 2].op != OP_MOV || !IS(opr_name(&ops[i - 2], 0), "esp") || !IS(opr_name(&ops[i - 2], 1), "ebp")) @@ -1473,115 +1924,184 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) } } + found = 1; i++; } while (i < opcnt); } + else { + for (i = 0; i < opcnt; i++) { + if (ops[i].op == OP_PUSH || (ops[i].flags & (OPF_JMP|OPF_TAIL))) + break; + if (ops[i].op == OP_SUB && ops[i].operand[0].reg == xSP + && ops[i].operand[1].type == OPT_CONST) + { + g_sp_frame = 1; + break; + } + } + + if (g_sp_frame) + { + g_stack_fsz = ops[i].operand[1].val; + ops[i].flags |= OPF_RMD; + + i++; + do { + for (; i < opcnt; i++) + if (ops[i].op == OP_RET) + break; + if (ops[i - 1].op != OP_ADD + || !IS(opr_name(&ops[i - 1], 0), "esp") + || ops[i - 1].operand[1].type != OPT_CONST + || ops[i - 1].operand[1].val != g_stack_fsz) + ferr(&ops[i - 1], "'add esp' expected\n"); + ops[i - 1].flags |= OPF_RMD; + + i++; + } while (i < opcnt); + } + } // pass2: // - resolve all branches for (i = 0; i < opcnt; i++) { po = &ops[i]; po->bt_i = -1; + po->btj = NULL; if ((po->flags & OPF_RMD) || !(po->flags & OPF_JMP) || po->op == OP_CALL || po->op == OP_RET) continue; - for (j = 0; j < opcnt; j++) { - if (g_labels[j][0] && IS(po->operand[0].name, g_labels[j])) { - po->bt_i = j; - po->lrl = g_label_refs[j]; - g_label_refs[j] = po; + if (po->operand[0].type == OPT_REGMEM) { + char *p = strchr(po->operand[0].name, '['); + if (p == NULL) + ferr(po, "unhandled indirect branch\n"); + ret = p - po->operand[0].name; + strncpy(buf1, po->operand[0].name, ret); + buf1[ret] = 0; + + for (j = 0, pd = NULL; j < g_func_pd_cnt; j++) { + if (IS(g_func_pd[j].label, buf1)) { + pd = &g_func_pd[j]; + break; + } + } + if (pd == NULL) + ferr(po, "label '%s' not parsed?\n", buf1); + if (pd->type != OPT_OFFSET) + ferr(po, "label '%s' with non-offset data?\n", buf1); + + // find all labels, link + for (j = 0; j < pd->count; j++) { + for (l = 0; l < opcnt; l++) { + if (g_labels[l][0] && IS(g_labels[l], pd->d[j].u.label)) { + add_label_ref(&g_label_refs[l], i); + pd->d[j].bt_i = l; + break; + } + } + } + + po->btj = pd; + continue; + } + + for (l = 0; l < opcnt; l++) { + if (g_labels[l][0] && IS(po->operand[0].name, g_labels[l])) { + add_label_ref(&g_label_refs[l], i); + po->bt_i = l; break; } } - if (po->bt_i == -1) { + if (po->bt_i != -1) + continue; + + if (po->operand[0].type == OPT_LABEL) { // assume tail call po->op = OP_CALL; po->flags |= OPF_TAIL; + continue; } + + ferr(po, "unhandled branch\n"); } // pass3: - // - find POPs for PUSHes, rm both - // - scan for all used registers - // - find flag set ops for their users // - process calls - for (i = 0; i < opcnt; i++) { + for (i = 0; i < opcnt; i++) + { po = &ops[i]; if (po->flags & OPF_RMD) continue; - if (po->op == OP_PUSH && po->operand[0].type == OPT_REG) { - if (po->operand[0].reg < 0) - ferr(po, "reg not set for push?\n"); - if (!(regmask & (1 << po->operand[0].reg))) { // reg save - ret = scan_for_pop(i + 1, opcnt, - po->operand[0].name, i + opcnt, 0); - if (ret == 1) { - po->flags |= OPF_RMD; - scan_for_pop(i + 1, opcnt, po->operand[0].name, - i + opcnt * 2, 1); - continue; - } - ret = scan_for_pop_ret(i + 1, opcnt, po->operand[0].name, 0); - if (ret == 0) { - po->flags |= OPF_RMD; - scan_for_pop_ret(i + 1, opcnt, po->operand[0].name, 1); - continue; - } - } - } - - regmask |= po->regmask_src | po->regmask_dst; - - if (po->flags & OPF_CC) + if (po->op == OP_CALL) { - ret = scan_for_flag_set(i - 1); - if (ret < 0) - ferr(po, "unable to trace flag setter\n"); - - tmp_op = &ops[ret]; // flag setter - pfo = split_cond(po, po->op, &dummy); - pfomask = 0; - - // to get nicer code, we try to delay test and cmp; - // if we can't because of operand modification, or if we - // have math op, make it calculate flags explicitly - if (tmp_op->op == OP_TEST || tmp_op->op == OP_CMP) { - if (scan_for_mod(tmp_op, ret + 1, i) >= 0) - pfomask = 1 << pfo; + pp = calloc(1, sizeof(*pp)); + my_assert_not(pp, NULL); + tmpname = opr_name(po, 0); + if (po->operand[0].type != OPT_LABEL) + { + ret = scan_for_esp_adjust(i + 1, opcnt, &j); + if (ret < 0) + ferr(po, "non-__cdecl indirect call unhandled yet\n"); + j /= 4; + if (j > ARRAY_SIZE(pp->arg)) + ferr(po, "esp adjust too large?\n"); + pp->ret_type = strdup("int"); + pp->argc = pp->argc_stack = j; + for (arg = 0; arg < pp->argc; arg++) + pp->arg[arg].type = strdup("int"); } else { - if ((pfo != PFO_Z && pfo != PFO_S && pfo != PFO_P) - || scan_for_mod_opr0(tmp_op, ret + 1, i) >= 0) - pfomask = 1 << pfo; + ret = proto_parse(fhdr, tmpname, pp); + if (ret) + ferr(po, "proto_parse failed for call '%s'\n", tmpname); } - if (pfomask) { - tmp_op->pfomask |= pfomask; - cmp_result_vars |= pfomask; - po->datap = tmp_op; + + ret = scan_for_esp_adjust(i + 1, opcnt, &j); + if (ret >= 0) { + if (pp->argc_stack != j / 4) + ferr(po, "stack tracking failed: %x %x\n", + pp->argc_stack, j); + ops[ret].flags |= OPF_RMD; } - if (po->op == OP_ADC || po->op == OP_SBB) - cmp_result_vars |= 1 << PFO_C; - } - else if (po->op == OP_CALL) - { - pp = malloc(sizeof(*pp)); - my_assert_not(pp, NULL); - tmpname = opr_name(&ops[i], 0); - ret = proto_parse(fhdr, tmpname, pp); - if (ret) - ferr(po, "proto_parse failed for '%s'\n", tmpname); + // can't call functions with non-__cdecl callbacks yet + for (arg = 0; arg < pp->argc; arg++) { + if (pp->arg[arg].fptr != NULL) { + pp_tmp = pp->arg[arg].fptr; + if (pp_tmp->is_stdcall || pp_tmp->argc != pp_tmp->argc_stack) + ferr(po, "'%s' has a non-__cdecl callback\n", tmpname); + } + } + // collect all stack args for (arg = 0; arg < pp->argc; arg++) if (pp->arg[arg].reg == NULL) break; - for (j = i - 1; j >= 0 && arg < pp->argc; j--) { - if (ops[j].op == OP_CALL) { + for (j = i; j >= 0 && arg < pp->argc; ) + { + if (g_labels[j][0] != 0) { + if (j > 0 && ((ops[j - 1].flags & OPF_TAIL) + || (ops[j - 1].flags & (OPF_JMP|OPF_CC)) == OPF_JMP)) + { + // follow the branch in reverse + if (g_label_refs[j].i == -1) + ferr(po, "no refs for '%s'?\n", g_labels[j]); + if (g_label_refs[j].next != NULL) + ferr(po, "unhandled multiple refs to '%s'\n", g_labels[j]); + j = g_label_refs[j].i + 1; + continue; + } + break; + } + j--; + + if (ops[j].op == OP_CALL) + { pp_tmp = ops[j].datap; if (pp_tmp == NULL) ferr(po, "arg collect hit unparsed call\n"); @@ -1594,12 +2114,13 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) { break; } - - if (ops[j].op == OP_PUSH) { + else if (ops[j].op == OP_PUSH) + { pp->arg[arg].datap = &ops[j]; ret = scan_for_mod(&ops[j], j + 1, i); if (ret >= 0) { // mark this push as one that needs operand saving + ops[j].flags &= ~OPF_RMD; ops[j].argmask |= 1 << arg; save_arg_vars |= 1 << arg; } @@ -1611,37 +2132,141 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) if (pp->arg[arg].reg == NULL) break; } - - if (g_labels[j][0] != 0) { - if (j > 0 && ((ops[j - 1].flags & OPF_TAIL) - || (ops[j - 1].flags & (OPF_JMP|OPF_CC)) == OPF_JMP)) - { - // follow the branch in reverse - if (g_label_refs[j] == NULL) - ferr(po, "no refs for '%s'?\n", g_labels[j]); - if (g_label_refs[j]->lrl != NULL) - ferr(po, "unhandled multiple fefs to '%s'\n", g_labels[j]); - j = (g_label_refs[j] - ops) + 1; - continue; - } - break; - } } if (arg < pp->argc) - ferr(po, "arg collect failed for '%s'\n", tmpname); + ferr(po, "arg collect failed for '%s': %d/%d\n", + tmpname, arg, pp->argc); po->datap = pp; } + } + + // pass4: + // - find POPs for PUSHes, rm both + // - scan for all used registers + // - find flag set ops for their users + // - declare indirect functions + for (i = 0; i < opcnt; i++) { + po = &ops[i]; + if (po->flags & OPF_RMD) + continue; + + if (po->op == OP_PUSH + && po->argmask == 0 && !(po->flags & OPF_RSAVE) + && po->operand[0].type == OPT_REG) + { + reg = po->operand[0].reg; + if (reg < 0) + ferr(po, "reg not set for push?\n"); + + depth = 0; + ret = scan_for_pop(i + 1, opcnt, + po->operand[0].name, i + opcnt, 0, &depth, 0); + if (ret == 1) { + if (depth > 1) + ferr(po, "too much depth: %d\n", depth); + if (depth > 0) + regmask_save |= 1 << reg; + + po->flags |= OPF_RMD; + scan_for_pop(i + 1, opcnt, po->operand[0].name, + i + opcnt * 2, 0, &depth, 1); + continue; + } + ret = scan_for_pop_ret(i + 1, opcnt, po->operand[0].name, 0); + if (ret == 0) { + arg = OPF_RMD; + if (regmask & (1 << reg)) { + if (regmask_save & (1 << reg)) + ferr(po, "%s already saved?\n", po->operand[0].name); + arg = OPF_RSAVE; + } + po->flags |= arg; + scan_for_pop_ret(i + 1, opcnt, po->operand[0].name, arg); + continue; + } + } + + regmask |= po->regmask_src | po->regmask_dst; + + if (po->flags & OPF_CC) + { + ret = scan_for_flag_set(i - 1); + if (ret < 0) + ferr(po, "unable to trace flag setter\n"); + + tmp_op = &ops[ret]; // flag setter + pfo = split_cond(po, po->op, &dummy); + pfomask = 0; + + // to get nicer code, we try to delay test and cmp; + // if we can't because of operand modification, or if we + // have math op, make it calculate flags explicitly + if (tmp_op->op == OP_TEST || tmp_op->op == OP_CMP) { + if (scan_for_mod(tmp_op, ret + 1, i) >= 0) + pfomask = 1 << pfo; + } + else { + if ((pfo != PFO_Z && pfo != PFO_S && pfo != PFO_P) + || scan_for_mod_opr0(tmp_op, ret + 1, i) >= 0) + pfomask = 1 << pfo; + } + if (pfomask) { + tmp_op->pfomask |= pfomask; + cmp_result_vars |= pfomask; + po->datap = tmp_op; + } + + if (po->op == OP_ADC || po->op == OP_SBB) + cmp_result_vars |= 1 << PFO_C; + } else if (po->op == OP_MUL || (po->op == OP_IMUL && po->operand_cnt == 1)) { need_mul_var = 1; } + else if (po->op == OP_CALL && po->operand[0].type != OPT_LABEL) { + pp = po->datap; + my_assert_not(pp, NULL); + fprintf(fout, " %s (*icall%d)(", pp->ret_type, i); + for (j = 0; j < pp->argc; j++) { + if (j > 0) + fprintf(fout, ", "); + fprintf(fout, "%s a%d", pp->arg[j].type, j + 1); + } + fprintf(fout, ");\n"); + } + } + + // output LUTs/jumptables + for (i = 0; i < g_func_pd_cnt; i++) { + pd = &g_func_pd[i]; + fprintf(fout, " static const "); + if (pd->type == OPT_OFFSET) { + fprintf(fout, "void *jt_%s[] =\n { ", pd->label); + + for (j = 0; j < pd->count; j++) { + if (j > 0) + fprintf(fout, ", "); + fprintf(fout, "&&%s", pd->d[j].u.label); + } + } + else { + fprintf(fout, "%s %s[] =\n { ", + lmod_type_u(ops, pd->lmod), pd->label); + + for (j = 0; j < pd->count; j++) { + if (j > 0) + fprintf(fout, ", "); + fprintf(fout, "%u", pd->d[j].u.val); + } + } + fprintf(fout, " };\n"); } // declare stack frame - if (g_bp_stack) + if (g_stack_fsz) fprintf(fout, " union { u32 d[%d]; u16 w[%d]; u8 b[%d]; } sf;\n", - (g_bp_stack + 3) / 4, (g_bp_stack + 1) / 2, g_bp_stack); + (g_stack_fsz + 3) / 4, (g_stack_fsz + 1) / 2, g_stack_fsz); // declare arg-registers for (i = 0; i < g_func_pp.argc; i++) { @@ -1665,6 +2290,7 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) } regmask &= ~regmask_arg; + regmask &= ~(1 << xSP); if (g_bp_frame) regmask &= ~(1 << xBP); if (regmask) { @@ -1676,6 +2302,15 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) } } + if (regmask_save) { + for (reg = 0; reg < 8; reg++) { + if (regmask_save & (1 << reg)) { + fprintf(fout, " u32 s_%s;\n", regs_r32[reg]); + had_decl = 1; + } + } + } + if (save_arg_vars) { for (reg = 0; reg < 32; reg++) { if (save_arg_vars & (1 << reg)) { @@ -1705,7 +2340,7 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) // output ops for (i = 0; i < opcnt; i++) { - if (g_labels[i][0] != 0) + if (g_labels[i][0] != 0 && g_label_refs[i].i != -1) fprintf(fout, "\n%s:\n", g_labels[i]); po = &ops[i]; @@ -1779,8 +2414,9 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) case OP_MOV: assert_operand_cnt(2); propagate_lmod(po, &po->operand[0], &po->operand[1]); - fprintf(fout, " %s = %s;", + fprintf(fout, " %s = %s%s;", out_dst_opr(buf1, sizeof(buf1), po, &po->operand[0]), + po->operand[0].is_ptr ? "(void *)" : "", out_src_opr(buf2, sizeof(buf2), po, &po->operand[1], 0)); break; @@ -1837,16 +2473,38 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) if (po->flags & OPF_REP) { fprintf(fout, " for (; ecx != 0; ecx--, edi += %d)\n", lmod_bytes(po, po->operand[0].lmod)); - fprintf(fout, " *(u32 *)edi = eax;"); + fprintf(fout, " %sedi = eax;", + lmod_cast_u_ptr(po, po->operand[0].lmod)); strcpy(g_comment, "rep stos"); } else { - fprintf(fout, " *(u32 *)edi = eax; edi += %d;", + fprintf(fout, " %sedi = eax; edi += %d;", + lmod_cast_u_ptr(po, po->operand[0].lmod), lmod_bytes(po, po->operand[0].lmod)); strcpy(g_comment, "stos"); } break; + case OP_MOVS: + // assumes DF=0 + assert_operand_cnt(3); + j = lmod_bytes(po, po->operand[0].lmod); + strcpy(buf1, lmod_cast_u_ptr(po, po->operand[0].lmod)); + if (po->flags & OPF_REP) { + fprintf(fout, + " for (; ecx != 0; ecx--, edi += %d, esi += %d)\n", + j, j); + fprintf(fout, + " %sedi = %sesi;", buf1, buf1); + strcpy(g_comment, "rep movs"); + } + else { + fprintf(fout, " %sedi = %sesi; edi += %d; esi += %d;", + buf1, buf1, j, j); + strcpy(g_comment, "movs"); + } + break; + // arithmetic w/flags case OP_ADD: case OP_SUB: @@ -1866,6 +2524,35 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) delayed_flag_op = NULL; break; + case OP_SAR: + assert_operand_cnt(2); + out_dst_opr(buf1, sizeof(buf1), po, &po->operand[0]); + fprintf(fout, " %s = %s%s >> %s;", buf1, + lmod_cast_s(po, po->operand[0].lmod), buf1, + out_src_opr(buf2, sizeof(buf2), po, &po->operand[1], 0)); + last_arith_dst = &po->operand[0]; + delayed_flag_op = NULL; + break; + + case OP_ROL: + case OP_ROR: + assert_operand_cnt(2); + out_dst_opr(buf1, sizeof(buf1), po, &po->operand[0]); + if (po->operand[1].type == OPT_CONST) { + j = po->operand[1].val; + j %= lmod_bytes(po, po->operand[0].lmod) * 8; + fprintf(fout, po->op == OP_ROL ? + " %s = (%s << %d) | (%s >> %d);" : + " %s = (%s >> %d) | (%s << %d);", + buf1, buf1, j, buf1, + lmod_bytes(po, po->operand[0].lmod) * 8 - j); + } + else + ferr(po, "TODO\n"); + last_arith_dst = &po->operand[0]; + delayed_flag_op = NULL; + break; + case OP_XOR: assert_operand_cnt(2); propagate_lmod(po, &po->operand[0], &po->operand[1]); @@ -1879,16 +2566,6 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) } goto dualop_arith; - case OP_SAR: - assert_operand_cnt(2); - out_dst_opr(buf1, sizeof(buf1), po, &po->operand[0]); - fprintf(fout, " %s = %s%s >> %s;", buf1, - lmod_cast_s(po, po->operand[0].lmod), buf1, - out_src_opr(buf2, sizeof(buf2), po, &po->operand[1], 0)); - last_arith_dst = &po->operand[0]; - delayed_flag_op = NULL; - break; - case OP_ADC: case OP_SBB: assert_operand_cnt(2); @@ -1904,8 +2581,14 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) case OP_INC: case OP_DEC: out_dst_opr(buf1, sizeof(buf1), po, &po->operand[0]); - strcpy(buf2, po->op == OP_INC ? "++" : "--"); - fprintf(fout, " %s%s;", buf1, buf2); + if (po->operand[0].type == OPT_REG) { + strcpy(buf2, po->op == OP_INC ? "++" : "--"); + fprintf(fout, " %s%s;", buf1, buf2); + } + else { + strcpy(buf2, po->op == OP_INC ? "+" : "-"); + fprintf(fout, " %s %s= 1;", buf1, buf2); + } last_arith_dst = &po->operand[0]; delayed_flag_op = NULL; break; @@ -1947,7 +2630,11 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) ferr(po, "unhandled lmod %d\n", po->operand[0].lmod); // 32bit division is common, look for it - if (scan_for_cdq_edx(i - 1) >= 0) { + if (po->op == OP_DIV) + ret = scan_for_reg_clear(i - 1, xDX); + else + ret = scan_for_cdq_edx(i - 1); + if (ret >= 0) { out_src_opr(buf1, sizeof(buf1), po, &po->operand[0], 0); strcpy(buf2, lmod_cast(po, po->operand[0].lmod, po->op == OP_IDIV)); @@ -1987,21 +2674,31 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) case OP_JMP: assert_operand_cnt(1); - if (po->operand[0].type != OPT_LABEL) - ferr(po, "unhandled call type\n"); + if (po->operand[0].type == OPT_REGMEM) { + ret = sscanf(po->operand[0].name, "%[^[][%[^*]*4]", + buf1, buf2); + if (ret != 2) + ferr(po, "parse failure for jmp '%s'\n", + po->operand[0].name); + fprintf(fout, " goto *jt_%s[%s];", buf1, buf2); + break; + } + else if (po->operand[0].type != OPT_LABEL) + ferr(po, "unhandled jmp type\n"); fprintf(fout, " goto %s;", po->operand[0].name); break; case OP_CALL: assert_operand_cnt(1); - if (po->operand[0].type != OPT_LABEL) - ferr(po, "unhandled call type\n"); - pp = po->datap; if (pp == NULL) ferr(po, "NULL pp\n"); + if (po->operand[0].type != OPT_LABEL) + fprintf(fout, " icall%d = (void *)%s;\n", i, + out_src_opr(buf1, sizeof(buf1), po, &po->operand[0], 0)); + fprintf(fout, " "); if (!IS(pp->ret_type, "void")) { if (po->flags & OPF_TAIL) @@ -2012,7 +2709,15 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) fprintf(fout, "(u32)"); } - fprintf(fout, "%s(", opr_name(po, 0)); + if (po->operand[0].type != OPT_LABEL) { + fprintf(fout, "icall%d(", i); + } + else { + if (pp->name[0] == 0) + ferr(po, "missing pp->name\n"); + fprintf(fout, "%s(", pp->name); + } + for (arg = 0; arg < pp->argc; arg++) { if (arg > 0) fprintf(fout, ", "); @@ -2052,6 +2757,9 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) case OP_RET: if (IS(g_func_pp.ret_type, "void")) fprintf(fout, " return;"); + else if (strchr(g_func_pp.ret_type, '*')) + fprintf(fout, " return (%s)eax;", + g_func_pp.ret_type); else fprintf(fout, " return eax;"); break; @@ -2059,19 +2767,28 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) case OP_PUSH: if (po->argmask) { // special case - saved func arg + out_src_opr(buf1, sizeof(buf1), po, &po->operand[0], 0); for (j = 0; j < 32; j++) { - if (po->argmask & (1 << j)) { - fprintf(fout, " s_a%d = %s;", j + 1, - out_src_opr(buf1, sizeof(buf1), po, &po->operand[0], 0)); - } + if (po->argmask & (1 << j)) + fprintf(fout, " s_a%d = %s;", j + 1, buf1); } break; } - ferr(po, "push encountered\n"); + else if (po->flags & OPF_RSAVE) { + out_src_opr(buf1, sizeof(buf1), po, &po->operand[0], 0); + fprintf(fout, " s_%s = %s;", buf1, buf1); + break; + } + ferr(po, "stray push encountered\n"); break; case OP_POP: - ferr(po, "pop encountered\n"); + if (po->flags & OPF_RSAVE) { + out_src_opr(buf1, sizeof(buf1), po, &po->operand[0], 0); + fprintf(fout, " %s = s_%s;", buf1, buf1); + break; + } + ferr(po, "stray pop encountered\n"); break; case OP_NOP: @@ -2111,6 +2828,17 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) // cleanup for (i = 0; i < opcnt; i++) { + struct label_ref *lr, *lr_del; + + lr = g_label_refs[i].next; + while (lr != NULL) { + lr_del = lr; + lr = lr->next; + free(lr_del); + } + g_label_refs[i].i = -1; + g_label_refs[i].next = NULL; + if (ops[i].op == OP_CALL) { pp = ops[i].datap; if (pp) { @@ -2122,57 +2850,210 @@ static void gen_func(FILE *fout, FILE *fhdr, const char *funcn, int opcnt) proto_release(&g_func_pp); } +static void set_label(int i, const char *name) +{ + const char *p; + int len; + + len = strlen(name); + p = strchr(name, ':'); + if (p != NULL) + len = p - name; + + if (len > sizeof(g_labels[0]) - 1) + aerr("label '%s' too long: %d\n", name, len); + if (g_labels[i][0] != 0) + aerr("dupe label '%s'?\n", name); + memcpy(g_labels[i], name, len); + g_labels[i][len] = 0; +} + +// '=' needs special treatment.. +static char *next_word_s(char *w, size_t wsize, char *s) +{ + size_t i; + + s = sskip(s); + + for (i = 0; i < wsize - 1; i++) { + if (s[i] == 0 || my_isblank(s[i]) || (s[i] == '=' && i > 0)) + break; + w[i] = s[i]; + } + w[i] = 0; + + if (s[i] != 0 && !my_isblank(s[i]) && s[i] != '=') + printf("warning: '%s' truncated\n", w); + + return s + i; +} + +static int cmpstringp(const void *p1, const void *p2) +{ + return strcmp(*(char * const *)p1, *(char * const *)p2); +} + int main(int argc, char *argv[]) { - FILE *fout, *fasm, *fhdr; + FILE *fout, *fasm, *frlist; + struct parsed_data *pd = NULL; + int pd_alloc = 0; + char **rlist = NULL; + int rlist_len = 0; + int rlist_alloc = 0; char line[256]; char words[16][256]; + enum opr_lenmod lmod; int in_func = 0; + int pending_endp = 0; + int skip_func = 0; int skip_warned = 0; int eq_alloc; + int verbose = 0; + int arg_out; + int arg = 1; int pi = 0; - int len; + int i, j, len; char *p; int wordc; - if (argc != 4) { - printf("usage:\n%s <.c> <.asm> \n", + if (argv[1] && IS(argv[1], "-v")) { + verbose = 1; + arg++; + } + + if (argc < arg + 3) { + printf("usage:\n%s [-v] <.c> <.asm> [rlist]*\n", argv[0]); return 1; } - hdrfn = argv[3]; - fhdr = fopen(hdrfn, "r"); - my_assert_not(fhdr, NULL); + arg_out = arg++; - asmfn = argv[2]; + asmfn = argv[arg++]; fasm = fopen(asmfn, "r"); my_assert_not(fasm, NULL); - fout = fopen(argv[1], "w"); + hdrfn = argv[arg++]; + g_fhdr = fopen(hdrfn, "r"); + my_assert_not(g_fhdr, NULL); + + rlist_alloc = 64; + rlist = malloc(rlist_alloc * sizeof(rlist[0])); + my_assert_not(rlist, NULL); + // needs special handling.. + rlist[rlist_len++] = "__alloca_probe"; + + for (; arg < argc; arg++) { + frlist = fopen(argv[arg], "r"); + my_assert_not(frlist, NULL); + + while (fgets(line, sizeof(line), frlist)) { + p = sskip(line); + if (*p == 0 || *p == ';' || *p == '#') + continue; + + p = next_word(words[0], sizeof(words[0]), p); + if (words[0][0] == 0) + continue; + + if (rlist_len >= rlist_alloc) { + rlist_alloc = rlist_alloc * 2 + 64; + rlist = realloc(rlist, rlist_alloc * sizeof(rlist[0])); + my_assert_not(rlist, NULL); + } + rlist[rlist_len++] = strdup(words[0]); + } + + fclose(frlist); + frlist = NULL; + } + + if (rlist_len > 0) + qsort(rlist, rlist_len, sizeof(rlist[0]), cmpstringp); + + fout = fopen(argv[arg_out], "w"); my_assert_not(fout, NULL); eq_alloc = 128; g_eqs = malloc(eq_alloc * sizeof(g_eqs[0])); my_assert_not(g_eqs, NULL); + for (i = 0; i < ARRAY_SIZE(g_label_refs); i++) { + g_label_refs[i].i = -1; + g_label_refs[i].next = NULL; + } + while (fgets(line, sizeof(line), fasm)) { + wordc = 0; asmln++; p = sskip(line); - if (*p == 0 || *p == ';') + if (*p == 0) + continue; + + if (*p == ';') { + static const char *attrs[] = { + "bp-based frame", + "library function", + "static", + "noreturn", + "thunk", + "fpd=", + }; + if (p[2] == '=' && IS_START(p, "; =============== S U B")) + goto do_pending_endp; // eww.. + + if (p[2] != 'A' || !IS_START(p, "; Attributes:")) + continue; + + // parse IDA's attribute-list comment + g_ida_func_attr = 0; + p = sskip(p + 13); + // get rid of random tabs + for (i = 0; p[i] != 0; i++) + if (p[i] == '\t') + p[i] = ' '; + + for (; *p != 0; p = sskip(p)) { + for (i = 0; i < ARRAY_SIZE(attrs); i++) { + if (!strncmp(p, attrs[i], strlen(attrs[i]))) { + g_ida_func_attr |= 1 << i; + p += strlen(attrs[i]); + break; + } + } + if (i == ARRAY_SIZE(attrs)) { + anote("unparsed IDA attr: %s\n", p); + break; + } + if (IS(attrs[i], "fpd=")) { + p = next_word(words[0], sizeof(words[0]), p); + // ignore for now.. + } + } continue; + } +parse_words: memset(words, 0, sizeof(words)); for (wordc = 0; wordc < 16; wordc++) { - p = sskip(next_word(words[wordc], sizeof(words[0]), p)); + p = sskip(next_word_s(words[wordc], sizeof(words[0]), p)); if (*p == 0 || *p == ';') { wordc++; break; } } + // alow asm patches in comments + if (*p == ';' && IS_START(p, "; sctpatch: ")) { + p = sskip(p + 12); + if (*p == 0 || *p == ';') + continue; + goto parse_words; // lame + } + if (wordc == 0) { // shouldn't happen awarn("wordc == 0?\n"); @@ -2188,11 +3069,99 @@ int main(int argc, char *argv[]) continue; } +do_pending_endp: + // do delayed endp processing to collect switch jumptables + if (pending_endp) { + if (in_func && !skip_func && wordc >= 2 + && ((words[0][0] == 'd' && words[0][2] == 0) + || (words[1][0] == 'd' && words[1][2] == 0))) + { + i = 1; + if (words[1][0] == 'd' && words[1][2] == 0) { + // label + if (g_func_pd_cnt >= pd_alloc) { + pd_alloc = pd_alloc * 2 + 16; + g_func_pd = realloc(g_func_pd, + sizeof(g_func_pd[0]) * pd_alloc); + my_assert_not(g_func_pd, NULL); + } + pd = &g_func_pd[g_func_pd_cnt]; + g_func_pd_cnt++; + memset(pd, 0, sizeof(*pd)); + strcpy(pd->label, words[0]); + pd->type = OPT_CONST; + pd->lmod = lmod_from_directive(words[1]); + i = 2; + } + else { + lmod = lmod_from_directive(words[0]); + if (lmod != pd->lmod) + aerr("lmod change? %d->%d\n", pd->lmod, lmod); + } + + if (pd->count_alloc < pd->count + wordc) { + pd->count_alloc = pd->count_alloc * 2 + 14 + wordc; + pd->d = realloc(pd->d, sizeof(pd->d[0]) * pd->count_alloc); + my_assert_not(pd->d, NULL); + } + for (; i < wordc; i++) { + if (IS(words[i], "offset")) { + pd->type = OPT_OFFSET; + i++; + } + p = strchr(words[i], ','); + if (p != NULL) + *p = 0; + if (pd->type == OPT_OFFSET) + pd->d[pd->count].u.label = strdup(words[i]); + else + pd->d[pd->count].u.val = parse_number(words[i]); + pd->d[pd->count].bt_i = -1; + pd->count++; + } + continue; + } + + if (in_func && !skip_func) + gen_func(fout, g_fhdr, g_func, pi); + + pending_endp = 0; + in_func = 0; + g_ida_func_attr = 0; + skip_warned = 0; + skip_func = 0; + g_func[0] = 0; + if (pi != 0) { + memset(&ops, 0, pi * sizeof(ops[0])); + memset(g_labels, 0, pi * sizeof(g_labels[0])); + pi = 0; + } + g_eqcnt = 0; + for (i = 0; i < g_func_pd_cnt; i++) { + pd = &g_func_pd[i]; + if (pd->type == OPT_OFFSET) { + for (j = 0; j < pd->count; j++) + free(pd->d[j].u.label); + } + free(pd->d); + pd->d = NULL; + } + g_func_pd_cnt = 0; + pd = NULL; + if (wordc == 0) + continue; + } + if (IS(words[1], "proc")) { if (in_func) aerr("proc '%s' while in_func '%s'?\n", words[0], g_func); + p = words[0]; + if ((g_ida_func_attr & IDAFA_THUNK) + || bsearch(&p, rlist, rlist_len, sizeof(rlist[0]), cmpstringp)) + skip_func = 1; strcpy(g_func, words[0]); + set_label(0, words[0]); in_func = 1; continue; } @@ -2203,21 +3172,28 @@ int main(int argc, char *argv[]) if (!IS(g_func, words[0])) aerr("endp '%s' while in_func '%s'?\n", words[0], g_func); - gen_func(fout, fhdr, g_func, pi); - in_func = 0; - skip_warned = 0; - g_func[0] = 0; - if (pi != 0) { - memset(&ops, 0, pi * sizeof(ops[0])); - memset(g_labels, 0, pi * sizeof(g_labels[0])); - memset(g_label_refs, 0, pi * sizeof(g_label_refs[0])); - pi = 0; + + pending_endp = 1; + continue; + } + + p = strchr(words[0], ':'); + if (p != NULL) { + set_label(pi, words[0]); + continue; + } + + if (!in_func || skip_func) { + if (!skip_warned && !skip_func && g_labels[pi][0] != 0) { + if (verbose) + anote("skipping from '%s'\n", g_labels[pi]); + skip_warned = 1; } - g_eqcnt = 0; + g_labels[pi][0] = 0; continue; } - if (IS(words[1], "=")) { + if (wordc > 1 && IS(words[1], "=")) { if (wordc != 5) aerr("unhandled equ, wc=%d\n", wordc); if (g_eqcnt >= eq_alloc) { @@ -2250,34 +3226,13 @@ int main(int argc, char *argv[]) if (pi >= ARRAY_SIZE(ops)) aerr("too many ops\n"); - p = strchr(words[0], ':'); - if (p != NULL) { - len = p - words[0]; - if (len > sizeof(g_labels[0]) - 1) - aerr("label too long: %d\n", len); - if (g_labels[pi][0] != 0) - aerr("dupe label?\n"); - memcpy(g_labels[pi], words[0], len); - g_labels[pi][len] = 0; - continue; - } - - if (!in_func) { - if (!skip_warned && g_labels[pi][0] != 0) { - anote("skipping from '%s'\n", g_labels[pi]); - skip_warned = 1; - } - g_labels[pi][0] = 0; - continue; - } - parse_op(&ops[pi], words, wordc); pi++; } fclose(fout); fclose(fasm); - fclose(fhdr); + fclose(g_fhdr); return 0; }