diff options
Diffstat (limited to '')
| -rw-r--r-- | miasm2/arch/x86/arch.py | 73 | ||||
| -rw-r--r-- | miasm2/arch/x86/sem.py | 68 |
2 files changed, 92 insertions, 49 deletions
diff --git a/miasm2/arch/x86/arch.py b/miasm2/arch/x86/arch.py index 33fd428f..f966c860 100644 --- a/miasm2/arch/x86/arch.py +++ b/miasm2/arch/x86/arch.py @@ -3751,13 +3751,30 @@ addop("outsd", [bs8(0x6f), bs_opmode64]) # addop("pause", [bs8(0xf3), bs8(0x90)]) -addop("pop", [bs8(0x8f), stk] + rmmod(d0)) -addop("pop", [bs("01011"), stk, reg]) -addop("pop", [bs8(0x1f), stk, d_ds]) -addop("pop", [bs8(0x07), stk, d_es]) -addop("pop", [bs8(0x17), stk, d_ss]) -addop("pop", [bs8(0x0f), stk, bs8(0xa1), d_fs]) -addop("pop", [bs8(0x0f), stk, bs8(0xa9), d_gs]) +addop("popw", [bs8(0x8f), stk, bs_opmode16] + rmmod(d0)) +addop("popw", [bs("01011"), stk, reg, bs_opmode16]) +addop("popw", [bs8(0x1f), stk, d_ds, bs_opmode16]) +addop("popw", [bs8(0x07), stk, d_es, bs_opmode16]) +addop("popw", [bs8(0x17), stk, d_ss, bs_opmode16]) +addop("popw", [bs8(0x0f), stk, bs8(0xa1), d_fs, bs_opmode16]) +addop("popw", [bs8(0x0f), stk, bs8(0xa9), d_gs, bs_opmode16]) + +addop("pop", [bs8(0x8f), stk, bs_opmode32] + rmmod(d0)) +addop("pop", [bs("01011"), stk, reg, bs_opmode32]) +addop("pop", [bs8(0x1f), stk, d_ds, bs_opmode32]) +addop("pop", [bs8(0x07), stk, d_es, bs_opmode32]) +addop("pop", [bs8(0x17), stk, d_ss, bs_opmode32]) +addop("pop", [bs8(0x0f), stk, bs8(0xa1), d_fs, bs_opmode32]) +addop("pop", [bs8(0x0f), stk, bs8(0xa9), d_gs, bs_opmode32]) + +addop("pop", [bs8(0x8f), stk, bs_opmode64] + rmmod(d0)) +addop("pop", [bs("01011"), stk, reg, bs_opmode64]) +addop("pop", [bs8(0x1f), stk, d_ds, bs_opmode64]) +addop("pop", [bs8(0x07), stk, d_es, bs_opmode64]) +addop("pop", [bs8(0x17), stk, d_ss, bs_opmode64]) +addop("pop", [bs8(0x0f), stk, bs8(0xa1), d_fs, bs_opmode64]) +addop("pop", [bs8(0x0f), stk, bs8(0xa9), d_gs, bs_opmode64]) + # popa_name = {16:'POPA', 32:'POPAD'} # bs_popa_name = bs_modname_size(l=0, name=popa_name) @@ -3777,16 +3794,38 @@ addop("prefetch1", [bs8(0x0f), bs8(0x18)] + rmmod(d2, rm_arg_m08)) addop("prefetch2", [bs8(0x0f), bs8(0x18)] + rmmod(d3, rm_arg_m08)) addop("prefetchnta", [bs8(0x0f), bs8(0x18)] + rmmod(d0, rm_arg_m08)) -addop("push", [bs8(0xff), stk] + rmmod(d6)) -addop("push", [bs("01010"), stk, reg]) -addop("push", [bs8(0x6a), s08, stk]) -addop("push", [bs8(0x68), d_imm, stk]) -addop("push", [bs8(0x0e), stk, d_cs]) -addop("push", [bs8(0x16), stk, d_ss]) -addop("push", [bs8(0x1e), stk, d_ds]) -addop("push", [bs8(0x06), stk, d_es]) -addop("push", [bs8(0x0f), stk, bs8(0xa0), d_fs]) -addop("push", [bs8(0x0f), stk, bs8(0xa8), d_gs]) +addop("pushw", [bs8(0xff), stk, bs_opmode16] + rmmod(d6)) +addop("pushw", [bs("01010"), stk, reg, bs_opmode16]) +addop("pushw", [bs8(0x6a), s08, stk, bs_opmode16]) +addop("pushw", [bs8(0x68), d_imm, stk, bs_opmode16]) +addop("pushw", [bs8(0x0e), stk, d_cs, bs_opmode16]) +addop("pushw", [bs8(0x16), stk, d_ss, bs_opmode16]) +addop("pushw", [bs8(0x1e), stk, d_ds, bs_opmode16]) +addop("pushw", [bs8(0x06), stk, d_es, bs_opmode16]) +addop("pushw", [bs8(0x0f), stk, bs8(0xa0), d_fs, bs_opmode16]) +addop("pushw", [bs8(0x0f), stk, bs8(0xa8), d_gs, bs_opmode16]) + +addop("push", [bs8(0xff), stk, bs_opmode32] + rmmod(d6)) +addop("push", [bs("01010"), stk, reg, bs_opmode32]) +addop("push", [bs8(0x6a), s08, stk, bs_opmode32]) +addop("push", [bs8(0x68), d_imm, stk, bs_opmode32]) +addop("push", [bs8(0x0e), stk, d_cs, bs_opmode32]) +addop("push", [bs8(0x16), stk, d_ss, bs_opmode32]) +addop("push", [bs8(0x1e), stk, d_ds, bs_opmode32]) +addop("push", [bs8(0x06), stk, d_es, bs_opmode32]) +addop("push", [bs8(0x0f), stk, bs8(0xa0), d_fs, bs_opmode32]) +addop("push", [bs8(0x0f), stk, bs8(0xa8), d_gs, bs_opmode32]) + +addop("push", [bs8(0xff), stk, bs_opmode64] + rmmod(d6)) +addop("push", [bs("01010"), stk, reg, bs_opmode64]) +addop("push", [bs8(0x6a), s08, stk, bs_opmode64]) +addop("push", [bs8(0x68), d_imm, stk, bs_opmode64]) +addop("push", [bs8(0x0e), stk, d_cs, bs_opmode64]) +addop("push", [bs8(0x16), stk, d_ss, bs_opmode64]) +addop("push", [bs8(0x1e), stk, d_ds, bs_opmode64]) +addop("push", [bs8(0x06), stk, d_es, bs_opmode64]) +addop("push", [bs8(0x0f), stk, bs8(0xa0), d_fs, bs_opmode64]) +addop("push", [bs8(0x0f), stk, bs8(0xa8), d_gs, bs_opmode64]) # pusha_name = {16:'PUSHA', 32:'PUSHAD'} # bs_pusha_name = bs_modname_size(l=0, name=pusha_name) diff --git a/miasm2/arch/x86/sem.py b/miasm2/arch/x86/sem.py index 4dafc809..6b5ae583 100644 --- a/miasm2/arch/x86/sem.py +++ b/miasm2/arch/x86/sem.py @@ -620,55 +620,57 @@ def dec(ir, instr, a): return e, [] -def push(ir, instr, a): +def push_gen(ir, instr, a, size): e = [] - s = instr.mode - size = instr.v_opmode() - opmode, admode = s, instr.v_admode() - # special case segment regs - if a in [ES, CS, SS, DS, FS, GS]: - off = admode - else: - off = a.size - if not s in [16, 32, 64]: + if not size in [16, 32, 64]: raise ValueError('bad size stacker!') - if isinstance(a, m2_expr.ExprInt): - a = m2_expr.ExprInt_fromsize(s, a.arg) + if a.size < size: + a = a.zeroExtend(size) + elif a.size == size: + pass + else: + raise ValueError('strange arg size') - c = mRSP[instr.mode][:s] - m2_expr.ExprInt_fromsize(s, off / 8) - e.append(m2_expr.ExprAff(mRSP[instr.mode][:s], c)) - # we sub vopmode to stack, but mem access is arg size wide + sp = mRSP[instr.mode] + new_sp = sp - m2_expr.ExprInt_from(sp, size / 8) + e.append(m2_expr.ExprAff(sp, new_sp)) if ir.do_stk_segm: - c = m2_expr.ExprOp('segm', SS, c) - e.append(m2_expr.ExprAff(m2_expr.ExprMem(c, a.size), a)) + new_sp = m2_expr.ExprOp('segm', SS, new_sp) + e.append(m2_expr.ExprAff(m2_expr.ExprMem(new_sp, size), a)) return e, [] +def push(ir, instr, a): + return push_gen(ir, instr, a, instr.mode) -def pop(ir, instr, a): +def pushw(ir, instr, a): + return push_gen(ir, instr, a, 16) + + +def pop_gen(ir, instr, a, size): e = [] - s = instr.mode - size = instr.v_opmode() - opmode, admode = s, instr.v_admode() - # special case segment regs - if a in [ES, CS, SS, DS, FS, GS]: - off = admode - else: - off = a.size - if not s in [16, 32, 64]: + if not size in [16, 32, 64]: raise ValueError('bad size stacker!') - new_esp = mRSP[instr.mode][:s] + m2_expr.ExprInt_fromsize(s, off / 8) + + sp = mRSP[instr.mode] + new_sp = sp + m2_expr.ExprInt_from(sp, size / 8) # don't generate ESP incrementation on POP ESP if a != ir.sp: - e.append(m2_expr.ExprAff(mRSP[instr.mode][:s], new_esp)) + e.append(m2_expr.ExprAff(sp, new_sp)) # XXX FIX XXX for pop [esp] if isinstance(a, m2_expr.ExprMem): - a = a.replace_expr({mRSP[instr.mode]: new_esp}) - c = mRSP[instr.mode][:s] + a = a.replace_expr({sp: new_sp}) + c = sp if ir.do_stk_segm: c = m2_expr.ExprOp('segm', SS, c) e.append(m2_expr.ExprAff(a, m2_expr.ExprMem(c, a.size))) return e, [] +def pop(ir, instr, a): + return pop_gen(ir, instr, a, instr.mode) + +def popw(ir, instr, a): + return pop_gen(ir, instr, a, 16) + def sete(ir, instr, a): e = [] @@ -944,7 +946,7 @@ def pushfd(ir, instr): def pushfw(ir, instr): - return push(ir, instr, compose_eflag(16)) + return pushw(ir, instr, compose_eflag(16)) def popfd(ir, instr): @@ -3175,7 +3177,9 @@ mnemo_func = {'mov': mov, 'inc': inc, 'dec': dec, 'push': push, + 'pushw': pushw, 'pop': pop, + 'popw': popw, 'sete': sete, 'setnz': setnz, 'setl': setl, |