aboutsummaryrefslogtreecommitdiffstats
path: root/pkg/ifuzz/arm64/arm64.go
blob: a2d3263398eea59701172785dff5c69374e892a4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
// Copyright 2024 syzkaller project authors. All rights reserved.
// Use of this source code is governed by Apache 2 LICENSE that can be found in the LICENSE file.

//go:generate go run gen/gen.go gen/json/arm64.json generated/insns.go

// Package arm64 allows to generate and mutate arm64 machine code.
package arm64

import (
	"encoding/binary"
	"fmt"
	"math/rand"

	"github.com/google/syzkaller/pkg/ifuzz/iset"
)

type InsnField struct {
	Name   string
	Start  uint // Little endian bit order.
	Length uint
}

type Insn struct {
	Name       string
	OpcodeMask uint32
	Opcode     uint32
	Fields     []InsnField
	AsUInt32   uint32
	Operands   []uint32
	Pseudo     bool
	Priv       bool
	Generator  func(cfg *iset.Config, r *rand.Rand) []byte // for pseudo instructions
}

type InsnSet struct {
	modeInsns iset.ModeInsns
	Insns     []*Insn
}

func Register(insns []*Insn) {
	if len(insns) == 0 {
		panic("no instructions")
	}
	insnset := &InsnSet{
		Insns: append(insns, pseudo...),
	}
	for _, insn := range insnset.Insns {
		insnset.modeInsns.Add(insn)
	}
	iset.Arches[iset.ArchArm64] = insnset
	templates = insns
}

func (insnset *InsnSet) GetInsns(mode iset.Mode, typ iset.Type) []iset.Insn {
	return insnset.modeInsns[mode][typ]
}

func (insn *Insn) Info() (string, iset.Mode, bool, bool) {
	return insn.Name, 1 << iset.ModeLong64, insn.Pseudo, insn.Priv
}

func (insn *Insn) Encode(cfg *iset.Config, r *rand.Rand) []byte {
	if insn.Pseudo {
		return insn.Generator(cfg, r)
	}
	ret := make([]byte, 4)
	binary.LittleEndian.PutUint32(ret, insn.AsUInt32)
	return ret
}

func (insnset *InsnSet) Decode(mode iset.Mode, text []byte) (int, error) {
	if len(text) < 4 {
		return 0, fmt.Errorf("must be at least 4 bytes")
	}
	opcode := binary.LittleEndian.Uint32(text[:4])
	_, err := ParseInsn(opcode)
	if err != nil {
		return 0, fmt.Errorf("failed to decode %x", opcode)
	}
	return 4, nil
}

func (insnset *InsnSet) DecodeExt(mode iset.Mode, text []byte) (int, error) {
	return 0, fmt.Errorf("no external decoder")
}

var templates []*Insn

func (insn *Insn) initFromValue(val uint32) {
	operands := []uint32{}
	for _, field := range insn.Fields {
		extracted := extractBits(val, field.Start, field.Length)
		operands = append(operands, extracted)
	}
	insn.Operands = operands
	insn.AsUInt32 = val
}

func (insn *Insn) matchesValue(val uint32) bool {
	opcode := val & insn.OpcodeMask
	return opcode == insn.Opcode
}

func ParseInsn(val uint32) (Insn, error) {
	for _, tmpl := range templates {
		if tmpl.matchesValue(val) {
			newInsn := *tmpl
			newInsn.initFromValue(val)
			return newInsn, nil
		}
	}
	unknown := Insn{
		Name: "unknown",
	}
	return unknown, fmt.Errorf("unrecognized instruction: %08x", val)
}