6
#include <capstone/capstone.h>
9
void print_string_hex(const char *comment, unsigned char *str, size_t len);
11
static const char *get_eflag_name(uint64_t flag)
16
case X86_EFLAGS_UNDEFINED_OF:
18
case X86_EFLAGS_UNDEFINED_SF:
20
case X86_EFLAGS_UNDEFINED_ZF:
22
case X86_EFLAGS_MODIFY_AF:
24
case X86_EFLAGS_UNDEFINED_PF:
26
case X86_EFLAGS_MODIFY_CF:
28
case X86_EFLAGS_MODIFY_SF:
30
case X86_EFLAGS_MODIFY_ZF:
32
case X86_EFLAGS_UNDEFINED_AF:
34
case X86_EFLAGS_MODIFY_PF:
36
case X86_EFLAGS_UNDEFINED_CF:
38
case X86_EFLAGS_MODIFY_OF:
40
case X86_EFLAGS_RESET_OF:
42
case X86_EFLAGS_RESET_CF:
44
case X86_EFLAGS_RESET_DF:
46
case X86_EFLAGS_RESET_IF:
48
case X86_EFLAGS_RESET_ZF:
50
case X86_EFLAGS_TEST_OF:
52
case X86_EFLAGS_TEST_SF:
54
case X86_EFLAGS_TEST_ZF:
56
case X86_EFLAGS_TEST_PF:
58
case X86_EFLAGS_TEST_CF:
60
case X86_EFLAGS_RESET_SF:
62
case X86_EFLAGS_RESET_AF:
64
case X86_EFLAGS_RESET_TF:
66
case X86_EFLAGS_RESET_NT:
68
case X86_EFLAGS_PRIOR_OF:
70
case X86_EFLAGS_PRIOR_SF:
72
case X86_EFLAGS_PRIOR_ZF:
74
case X86_EFLAGS_PRIOR_AF:
76
case X86_EFLAGS_PRIOR_PF:
78
case X86_EFLAGS_PRIOR_CF:
80
case X86_EFLAGS_PRIOR_TF:
82
case X86_EFLAGS_PRIOR_IF:
84
case X86_EFLAGS_PRIOR_DF:
86
case X86_EFLAGS_TEST_NT:
88
case X86_EFLAGS_TEST_DF:
90
case X86_EFLAGS_RESET_PF:
92
case X86_EFLAGS_PRIOR_NT:
94
case X86_EFLAGS_MODIFY_TF:
96
case X86_EFLAGS_MODIFY_IF:
98
case X86_EFLAGS_MODIFY_DF:
100
case X86_EFLAGS_MODIFY_NT:
102
case X86_EFLAGS_MODIFY_RF:
104
case X86_EFLAGS_SET_CF:
106
case X86_EFLAGS_SET_DF:
108
case X86_EFLAGS_SET_IF:
110
case X86_EFLAGS_SET_OF:
112
case X86_EFLAGS_SET_SF:
114
case X86_EFLAGS_SET_ZF:
116
case X86_EFLAGS_SET_AF:
118
case X86_EFLAGS_SET_PF:
120
case X86_EFLAGS_TEST_AF:
122
case X86_EFLAGS_TEST_TF:
124
case X86_EFLAGS_TEST_RF:
126
case X86_EFLAGS_RESET_0F:
128
case X86_EFLAGS_RESET_AC:
133
static const char *get_fpu_flag_name(uint64_t flag)
138
case X86_FPU_FLAGS_MODIFY_C0:
140
case X86_FPU_FLAGS_MODIFY_C1:
142
case X86_FPU_FLAGS_MODIFY_C2:
144
case X86_FPU_FLAGS_MODIFY_C3:
146
case X86_FPU_FLAGS_RESET_C0:
148
case X86_FPU_FLAGS_RESET_C1:
150
case X86_FPU_FLAGS_RESET_C2:
152
case X86_FPU_FLAGS_RESET_C3:
154
case X86_FPU_FLAGS_SET_C0:
156
case X86_FPU_FLAGS_SET_C1:
158
case X86_FPU_FLAGS_SET_C2:
160
case X86_FPU_FLAGS_SET_C3:
162
case X86_FPU_FLAGS_UNDEFINED_C0:
164
case X86_FPU_FLAGS_UNDEFINED_C1:
166
case X86_FPU_FLAGS_UNDEFINED_C2:
168
case X86_FPU_FLAGS_UNDEFINED_C3:
170
case X86_FPU_FLAGS_TEST_C0:
172
case X86_FPU_FLAGS_TEST_C1:
174
case X86_FPU_FLAGS_TEST_C2:
176
case X86_FPU_FLAGS_TEST_C3:
181
void print_insn_detail_x86(csh ud, cs_mode mode, cs_insn *ins)
185
cs_regs regs_read, regs_write;
186
uint8_t regs_read_count, regs_write_count;
189
if (ins->detail == NULL)
192
x86 = &(ins->detail->x86);
194
print_string_hex("\tPrefix:", x86->prefix, 4);
195
print_string_hex("\tOpcode:", x86->opcode, 4);
196
printf("\trex: 0x%x\n", x86->rex);
197
printf("\taddr_size: %u\n", x86->addr_size);
198
printf("\tmodrm: 0x%x\n", x86->modrm);
199
printf("\tdisp: 0x%" PRIx64 "\n", x86->disp);
202
if ((mode & CS_MODE_16) == 0) {
203
printf("\tsib: 0x%x\n", x86->sib);
204
if (x86->sib_base != X86_REG_INVALID)
205
printf("\t\tsib_base: %s\n", cs_reg_name(ud, x86->sib_base));
206
if (x86->sib_index != X86_REG_INVALID)
207
printf("\t\tsib_index: %s\n", cs_reg_name(ud, x86->sib_index));
208
if (x86->sib_scale != 0)
209
printf("\t\tsib_scale: %d\n", x86->sib_scale);
213
if (x86->xop_cc != X86_XOP_CC_INVALID) {
214
printf("\txop_cc: %u\n", x86->xop_cc);
218
if (x86->sse_cc != X86_SSE_CC_INVALID) {
219
printf("\tsse_cc: %u\n", x86->sse_cc);
223
if (x86->avx_cc != X86_AVX_CC_INVALID) {
224
printf("\tavx_cc: %u\n", x86->avx_cc);
229
printf("\tavx_sae: %u\n", x86->avx_sae);
233
if (x86->avx_rm != X86_AVX_RM_INVALID) {
234
printf("\tavx_rm: %u\n", x86->avx_rm);
238
count = cs_op_count(ud, ins, X86_OP_IMM);
240
printf("\timm_count: %u\n", count);
241
for (i = 1; i < count + 1; i++) {
242
int index = cs_op_index(ud, ins, X86_OP_IMM, i);
243
printf("\t\timms[%u]: 0x%" PRIx64 "\n", i, x86->operands[index].imm);
248
printf("\top_count: %u\n", x86->op_count);
251
for (i = 0; i < x86->op_count; i++) {
252
cs_x86_op *op = &(x86->operands[i]);
254
switch((int)op->type) {
256
printf("\t\toperands[%u].type: REG = %s\n", i, cs_reg_name(ud, op->reg));
259
printf("\t\toperands[%u].type: IMM = 0x%" PRIx64 "\n", i, op->imm);
262
printf("\t\toperands[%u].type: MEM\n", i);
263
if (op->mem.segment != X86_REG_INVALID)
264
printf("\t\t\toperands[%u].mem.segment: REG = %s\n", i, cs_reg_name(ud, op->mem.segment));
265
if (op->mem.base != X86_REG_INVALID)
266
printf("\t\t\toperands[%u].mem.base: REG = %s\n", i, cs_reg_name(ud, op->mem.base));
267
if (op->mem.index != X86_REG_INVALID)
268
printf("\t\t\toperands[%u].mem.index: REG = %s\n", i, cs_reg_name(ud, op->mem.index));
269
if (op->mem.scale != 1)
270
printf("\t\t\toperands[%u].mem.scale: %u\n", i, op->mem.scale);
271
if (op->mem.disp != 0)
272
printf("\t\t\toperands[%u].mem.disp: 0x%" PRIx64 "\n", i, op->mem.disp);
279
if (op->avx_bcast != X86_AVX_BCAST_INVALID)
280
printf("\t\toperands[%u].avx_bcast: %u\n", i, op->avx_bcast);
283
if (op->avx_zero_opmask != false)
284
printf("\t\toperands[%u].avx_zero_opmask: TRUE\n", i);
286
printf("\t\toperands[%u].size: %u\n", i, op->size);
292
printf("\t\toperands[%u].access: READ\n", i);
295
printf("\t\toperands[%u].access: WRITE\n", i);
297
case CS_AC_READ | CS_AC_WRITE:
298
printf("\t\toperands[%u].access: READ | WRITE\n", i);
304
if (!cs_regs_access(ud, ins,
305
regs_read, ®s_read_count,
306
regs_write, ®s_write_count)) {
307
if (regs_read_count) {
308
printf("\tRegisters read:");
309
for(i = 0; i < regs_read_count; i++) {
310
printf(" %s", cs_reg_name(ud, regs_read[i]));
315
if (regs_write_count) {
316
printf("\tRegisters modified:");
317
for(i = 0; i < regs_write_count; i++) {
318
printf(" %s", cs_reg_name(ud, regs_write[i]));
324
if (x86->eflags || x86->fpu_flags) {
325
for(i = 0; i < ins->detail->groups_count; i++) {
326
if (ins->detail->groups[i] == X86_GRP_FPU) {
327
printf("\tFPU_FLAGS:");
328
for(i = 0; i <= 63; i++)
329
if (x86->fpu_flags & ((uint64_t)1 << i)) {
330
printf(" %s", get_fpu_flag_name((uint64_t)1 << i));
337
if (i == ins->detail->groups_count) {
339
for(i = 0; i <= 63; i++)
340
if (x86->eflags & ((uint64_t)1 << i)) {
341
printf(" %s", get_eflag_name((uint64_t)1 << i));