dis_arm64.lua 29 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207
  1. ----------------------------------------------------------------------------
  2. -- LuaJIT ARM64 disassembler module.
  3. --
  4. -- Copyright (C) 2005-2023 Mike Pall. All rights reserved.
  5. -- Released under the MIT license. See Copyright Notice in luajit.h
  6. --
  7. -- Contributed by Djordje Kovacevic and Stefan Pejic from RT-RK.com.
  8. -- Sponsored by Cisco Systems, Inc.
  9. ----------------------------------------------------------------------------
  10. -- This is a helper module used by the LuaJIT machine code dumper module.
  11. --
  12. -- It disassembles most user-mode AArch64 instructions.
  13. -- NYI: Advanced SIMD and VFP instructions.
  14. ------------------------------------------------------------------------------
  15. local type = type
  16. local sub, byte, format = string.sub, string.byte, string.format
  17. local match, gmatch, gsub = string.match, string.gmatch, string.gsub
  18. local concat = table.concat
  19. local bit = require("bit")
  20. local band, bor, bxor, tohex = bit.band, bit.bor, bit.bxor, bit.tohex
  21. local lshift, rshift, arshift = bit.lshift, bit.rshift, bit.arshift
  22. local ror = bit.ror
  23. ------------------------------------------------------------------------------
  24. -- Opcode maps
  25. ------------------------------------------------------------------------------
  26. local map_adr = { -- PC-relative addressing.
  27. shift = 31, mask = 1,
  28. [0] = "adrDBx", "adrpDBx"
  29. }
  30. local map_addsubi = { -- Add/subtract immediate.
  31. shift = 29, mask = 3,
  32. [0] = "add|movDNIg", "adds|cmnD0NIg", "subDNIg", "subs|cmpD0NIg",
  33. }
  34. local map_logi = { -- Logical immediate.
  35. shift = 31, mask = 1,
  36. [0] = {
  37. shift = 22, mask = 1,
  38. [0] = {
  39. shift = 29, mask = 3,
  40. [0] = "andDNig", "orr|movDN0ig", "eorDNig", "ands|tstD0Nig"
  41. },
  42. false -- unallocated
  43. },
  44. {
  45. shift = 29, mask = 3,
  46. [0] = "andDNig", "orr|movDN0ig", "eorDNig", "ands|tstD0Nig"
  47. }
  48. }
  49. local map_movwi = { -- Move wide immediate.
  50. shift = 31, mask = 1,
  51. [0] = {
  52. shift = 22, mask = 1,
  53. [0] = {
  54. shift = 29, mask = 3,
  55. [0] = "movnDWRg", false, "movz|movDYRg", "movkDWRg"
  56. }, false -- unallocated
  57. },
  58. {
  59. shift = 29, mask = 3,
  60. [0] = "movnDWRg", false, "movz|movDYRg", "movkDWRg"
  61. },
  62. }
  63. local map_bitf = { -- Bitfield.
  64. shift = 31, mask = 1,
  65. [0] = {
  66. shift = 22, mask = 1,
  67. [0] = {
  68. shift = 29, mask = 3,
  69. [0] = "sbfm|sbfiz|sbfx|asr|sxtw|sxth|sxtbDN12w",
  70. "bfm|bfi|bfxilDN13w",
  71. "ubfm|ubfiz|ubfx|lsr|lsl|uxth|uxtbDN12w"
  72. }
  73. },
  74. {
  75. shift = 22, mask = 1,
  76. {
  77. shift = 29, mask = 3,
  78. [0] = "sbfm|sbfiz|sbfx|asr|sxtw|sxth|sxtbDN12x",
  79. "bfm|bfi|bfxilDN13x",
  80. "ubfm|ubfiz|ubfx|lsr|lsl|uxth|uxtbDN12x"
  81. }
  82. }
  83. }
  84. local map_datai = { -- Data processing - immediate.
  85. shift = 23, mask = 7,
  86. [0] = map_adr, map_adr, map_addsubi, false,
  87. map_logi, map_movwi, map_bitf,
  88. {
  89. shift = 15, mask = 0x1c0c1,
  90. [0] = "extr|rorDNM4w", [0x10080] = "extr|rorDNM4x",
  91. [0x10081] = "extr|rorDNM4x"
  92. }
  93. }
  94. local map_logsr = { -- Logical, shifted register.
  95. shift = 31, mask = 1,
  96. [0] = {
  97. shift = 15, mask = 1,
  98. [0] = {
  99. shift = 29, mask = 3,
  100. [0] = {
  101. shift = 21, mask = 1,
  102. [0] = "andDNMSg", "bicDNMSg"
  103. },
  104. {
  105. shift = 21, mask = 1,
  106. [0] = "orr|movDN0MSg", "orn|mvnDN0MSg"
  107. },
  108. {
  109. shift = 21, mask = 1,
  110. [0] = "eorDNMSg", "eonDNMSg"
  111. },
  112. {
  113. shift = 21, mask = 1,
  114. [0] = "ands|tstD0NMSg", "bicsDNMSg"
  115. }
  116. },
  117. false -- unallocated
  118. },
  119. {
  120. shift = 29, mask = 3,
  121. [0] = {
  122. shift = 21, mask = 1,
  123. [0] = "andDNMSg", "bicDNMSg"
  124. },
  125. {
  126. shift = 21, mask = 1,
  127. [0] = "orr|movDN0MSg", "orn|mvnDN0MSg"
  128. },
  129. {
  130. shift = 21, mask = 1,
  131. [0] = "eorDNMSg", "eonDNMSg"
  132. },
  133. {
  134. shift = 21, mask = 1,
  135. [0] = "ands|tstD0NMSg", "bicsDNMSg"
  136. }
  137. }
  138. }
  139. local map_assh = {
  140. shift = 31, mask = 1,
  141. [0] = {
  142. shift = 15, mask = 1,
  143. [0] = {
  144. shift = 29, mask = 3,
  145. [0] = {
  146. shift = 22, mask = 3,
  147. [0] = "addDNMSg", "addDNMSg", "addDNMSg", "addDNMg"
  148. },
  149. {
  150. shift = 22, mask = 3,
  151. [0] = "adds|cmnD0NMSg", "adds|cmnD0NMSg",
  152. "adds|cmnD0NMSg", "adds|cmnD0NMg"
  153. },
  154. {
  155. shift = 22, mask = 3,
  156. [0] = "sub|negDN0MSg", "sub|negDN0MSg", "sub|negDN0MSg", "sub|negDN0Mg"
  157. },
  158. {
  159. shift = 22, mask = 3,
  160. [0] = "subs|cmp|negsD0N0MzSg", "subs|cmp|negsD0N0MzSg",
  161. "subs|cmp|negsD0N0MzSg", "subs|cmp|negsD0N0Mzg"
  162. },
  163. },
  164. false -- unallocated
  165. },
  166. {
  167. shift = 29, mask = 3,
  168. [0] = {
  169. shift = 22, mask = 3,
  170. [0] = "addDNMSg", "addDNMSg", "addDNMSg", "addDNMg"
  171. },
  172. {
  173. shift = 22, mask = 3,
  174. [0] = "adds|cmnD0NMSg", "adds|cmnD0NMSg", "adds|cmnD0NMSg",
  175. "adds|cmnD0NMg"
  176. },
  177. {
  178. shift = 22, mask = 3,
  179. [0] = "sub|negDN0MSg", "sub|negDN0MSg", "sub|negDN0MSg", "sub|negDN0Mg"
  180. },
  181. {
  182. shift = 22, mask = 3,
  183. [0] = "subs|cmp|negsD0N0MzSg", "subs|cmp|negsD0N0MzSg",
  184. "subs|cmp|negsD0N0MzSg", "subs|cmp|negsD0N0Mzg"
  185. }
  186. }
  187. }
  188. local map_addsubsh = { -- Add/subtract, shifted register.
  189. shift = 22, mask = 3,
  190. [0] = map_assh, map_assh, map_assh
  191. }
  192. local map_addsubex = { -- Add/subtract, extended register.
  193. shift = 22, mask = 3,
  194. [0] = {
  195. shift = 29, mask = 3,
  196. [0] = "addDNMXg", "adds|cmnD0NMXg", "subDNMXg", "subs|cmpD0NMzXg",
  197. }
  198. }
  199. local map_addsubc = { -- Add/subtract, with carry.
  200. shift = 10, mask = 63,
  201. [0] = {
  202. shift = 29, mask = 3,
  203. [0] = "adcDNMg", "adcsDNMg", "sbc|ngcDN0Mg", "sbcs|ngcsDN0Mg",
  204. }
  205. }
  206. local map_ccomp = {
  207. shift = 4, mask = 1,
  208. [0] = {
  209. shift = 10, mask = 3,
  210. [0] = { -- Conditional compare register.
  211. shift = 29, mask = 3,
  212. "ccmnNMVCg", false, "ccmpNMVCg",
  213. },
  214. [2] = { -- Conditional compare immediate.
  215. shift = 29, mask = 3,
  216. "ccmnN5VCg", false, "ccmpN5VCg",
  217. }
  218. }
  219. }
  220. local map_csel = { -- Conditional select.
  221. shift = 11, mask = 1,
  222. [0] = {
  223. shift = 10, mask = 1,
  224. [0] = {
  225. shift = 29, mask = 3,
  226. [0] = "cselDNMzCg", false, "csinv|cinv|csetmDNMcg", false,
  227. },
  228. {
  229. shift = 29, mask = 3,
  230. [0] = "csinc|cinc|csetDNMcg", false, "csneg|cnegDNMcg", false,
  231. }
  232. }
  233. }
  234. local map_data1s = { -- Data processing, 1 source.
  235. shift = 29, mask = 1,
  236. [0] = {
  237. shift = 31, mask = 1,
  238. [0] = {
  239. shift = 10, mask = 0x7ff,
  240. [0] = "rbitDNg", "rev16DNg", "revDNw", false, "clzDNg", "clsDNg"
  241. },
  242. {
  243. shift = 10, mask = 0x7ff,
  244. [0] = "rbitDNg", "rev16DNg", "rev32DNx", "revDNx", "clzDNg", "clsDNg"
  245. }
  246. }
  247. }
  248. local map_data2s = { -- Data processing, 2 sources.
  249. shift = 29, mask = 1,
  250. [0] = {
  251. shift = 10, mask = 63,
  252. false, "udivDNMg", "sdivDNMg", false, false, false, false, "lslDNMg",
  253. "lsrDNMg", "asrDNMg", "rorDNMg"
  254. }
  255. }
  256. local map_data3s = { -- Data processing, 3 sources.
  257. shift = 29, mask = 7,
  258. [0] = {
  259. shift = 21, mask = 7,
  260. [0] = {
  261. shift = 15, mask = 1,
  262. [0] = "madd|mulDNMA0g", "msub|mnegDNMA0g"
  263. }
  264. }, false, false, false,
  265. {
  266. shift = 15, mask = 1,
  267. [0] = {
  268. shift = 21, mask = 7,
  269. [0] = "madd|mulDNMA0g", "smaddl|smullDxNMwA0x", "smulhDNMx", false,
  270. false, "umaddl|umullDxNMwA0x", "umulhDNMx"
  271. },
  272. {
  273. shift = 21, mask = 7,
  274. [0] = "msub|mnegDNMA0g", "smsubl|smneglDxNMwA0x", false, false,
  275. false, "umsubl|umneglDxNMwA0x"
  276. }
  277. }
  278. }
  279. local map_datar = { -- Data processing, register.
  280. shift = 28, mask = 1,
  281. [0] = {
  282. shift = 24, mask = 1,
  283. [0] = map_logsr,
  284. {
  285. shift = 21, mask = 1,
  286. [0] = map_addsubsh, map_addsubex
  287. }
  288. },
  289. {
  290. shift = 21, mask = 15,
  291. [0] = map_addsubc, false, map_ccomp, false, map_csel, false,
  292. {
  293. shift = 30, mask = 1,
  294. [0] = map_data2s, map_data1s
  295. },
  296. false, map_data3s, map_data3s, map_data3s, map_data3s, map_data3s,
  297. map_data3s, map_data3s, map_data3s
  298. }
  299. }
  300. local map_lrl = { -- Load register, literal.
  301. shift = 26, mask = 1,
  302. [0] = {
  303. shift = 30, mask = 3,
  304. [0] = "ldrDwB", "ldrDxB", "ldrswDxB"
  305. },
  306. {
  307. shift = 30, mask = 3,
  308. [0] = "ldrDsB", "ldrDdB"
  309. }
  310. }
  311. local map_lsriind = { -- Load/store register, immediate pre/post-indexed.
  312. shift = 30, mask = 3,
  313. [0] = {
  314. shift = 26, mask = 1,
  315. [0] = {
  316. shift = 22, mask = 3,
  317. [0] = "strbDwzL", "ldrbDwzL", "ldrsbDxzL", "ldrsbDwzL"
  318. }
  319. },
  320. {
  321. shift = 26, mask = 1,
  322. [0] = {
  323. shift = 22, mask = 3,
  324. [0] = "strhDwzL", "ldrhDwzL", "ldrshDxzL", "ldrshDwzL"
  325. }
  326. },
  327. {
  328. shift = 26, mask = 1,
  329. [0] = {
  330. shift = 22, mask = 3,
  331. [0] = "strDwzL", "ldrDwzL", "ldrswDxzL"
  332. },
  333. {
  334. shift = 22, mask = 3,
  335. [0] = "strDszL", "ldrDszL"
  336. }
  337. },
  338. {
  339. shift = 26, mask = 1,
  340. [0] = {
  341. shift = 22, mask = 3,
  342. [0] = "strDxzL", "ldrDxzL"
  343. },
  344. {
  345. shift = 22, mask = 3,
  346. [0] = "strDdzL", "ldrDdzL"
  347. }
  348. }
  349. }
  350. local map_lsriro = {
  351. shift = 21, mask = 1,
  352. [0] = { -- Load/store register immediate.
  353. shift = 10, mask = 3,
  354. [0] = { -- Unscaled immediate.
  355. shift = 26, mask = 1,
  356. [0] = {
  357. shift = 30, mask = 3,
  358. [0] = {
  359. shift = 22, mask = 3,
  360. [0] = "sturbDwK", "ldurbDwK"
  361. },
  362. {
  363. shift = 22, mask = 3,
  364. [0] = "sturhDwK", "ldurhDwK"
  365. },
  366. {
  367. shift = 22, mask = 3,
  368. [0] = "sturDwK", "ldurDwK"
  369. },
  370. {
  371. shift = 22, mask = 3,
  372. [0] = "sturDxK", "ldurDxK"
  373. }
  374. }
  375. }, map_lsriind, false, map_lsriind
  376. },
  377. { -- Load/store register, register offset.
  378. shift = 10, mask = 3,
  379. [2] = {
  380. shift = 26, mask = 1,
  381. [0] = {
  382. shift = 30, mask = 3,
  383. [0] = {
  384. shift = 22, mask = 3,
  385. [0] = "strbDwO", "ldrbDwO", "ldrsbDxO", "ldrsbDwO"
  386. },
  387. {
  388. shift = 22, mask = 3,
  389. [0] = "strhDwO", "ldrhDwO", "ldrshDxO", "ldrshDwO"
  390. },
  391. {
  392. shift = 22, mask = 3,
  393. [0] = "strDwO", "ldrDwO", "ldrswDxO"
  394. },
  395. {
  396. shift = 22, mask = 3,
  397. [0] = "strDxO", "ldrDxO"
  398. }
  399. },
  400. {
  401. shift = 30, mask = 3,
  402. [2] = {
  403. shift = 22, mask = 3,
  404. [0] = "strDsO", "ldrDsO"
  405. },
  406. [3] = {
  407. shift = 22, mask = 3,
  408. [0] = "strDdO", "ldrDdO"
  409. }
  410. }
  411. }
  412. }
  413. }
  414. local map_lsp = { -- Load/store register pair, offset.
  415. shift = 22, mask = 1,
  416. [0] = {
  417. shift = 30, mask = 3,
  418. [0] = {
  419. shift = 26, mask = 1,
  420. [0] = "stpDzAzwP", "stpDzAzsP",
  421. },
  422. {
  423. shift = 26, mask = 1,
  424. "stpDzAzdP"
  425. },
  426. {
  427. shift = 26, mask = 1,
  428. [0] = "stpDzAzxP"
  429. }
  430. },
  431. {
  432. shift = 30, mask = 3,
  433. [0] = {
  434. shift = 26, mask = 1,
  435. [0] = "ldpDzAzwP", "ldpDzAzsP",
  436. },
  437. {
  438. shift = 26, mask = 1,
  439. [0] = "ldpswDAxP", "ldpDzAzdP"
  440. },
  441. {
  442. shift = 26, mask = 1,
  443. [0] = "ldpDzAzxP"
  444. }
  445. }
  446. }
  447. local map_ls = { -- Loads and stores.
  448. shift = 24, mask = 0x31,
  449. [0x10] = map_lrl, [0x30] = map_lsriro,
  450. [0x20] = {
  451. shift = 23, mask = 3,
  452. map_lsp, map_lsp, map_lsp
  453. },
  454. [0x21] = {
  455. shift = 23, mask = 3,
  456. map_lsp, map_lsp, map_lsp
  457. },
  458. [0x31] = {
  459. shift = 26, mask = 1,
  460. [0] = {
  461. shift = 30, mask = 3,
  462. [0] = {
  463. shift = 22, mask = 3,
  464. [0] = "strbDwzU", "ldrbDwzU"
  465. },
  466. {
  467. shift = 22, mask = 3,
  468. [0] = "strhDwzU", "ldrhDwzU"
  469. },
  470. {
  471. shift = 22, mask = 3,
  472. [0] = "strDwzU", "ldrDwzU"
  473. },
  474. {
  475. shift = 22, mask = 3,
  476. [0] = "strDxzU", "ldrDxzU"
  477. }
  478. },
  479. {
  480. shift = 30, mask = 3,
  481. [2] = {
  482. shift = 22, mask = 3,
  483. [0] = "strDszU", "ldrDszU"
  484. },
  485. [3] = {
  486. shift = 22, mask = 3,
  487. [0] = "strDdzU", "ldrDdzU"
  488. }
  489. }
  490. },
  491. }
  492. local map_datafp = { -- Data processing, SIMD and FP.
  493. shift = 28, mask = 7,
  494. { -- 001
  495. shift = 24, mask = 1,
  496. [0] = {
  497. shift = 21, mask = 1,
  498. {
  499. shift = 10, mask = 3,
  500. [0] = {
  501. shift = 12, mask = 1,
  502. [0] = {
  503. shift = 13, mask = 1,
  504. [0] = {
  505. shift = 14, mask = 1,
  506. [0] = {
  507. shift = 15, mask = 1,
  508. [0] = { -- FP/int conversion.
  509. shift = 31, mask = 1,
  510. [0] = {
  511. shift = 16, mask = 0xff,
  512. [0x20] = "fcvtnsDwNs", [0x21] = "fcvtnuDwNs",
  513. [0x22] = "scvtfDsNw", [0x23] = "ucvtfDsNw",
  514. [0x24] = "fcvtasDwNs", [0x25] = "fcvtauDwNs",
  515. [0x26] = "fmovDwNs", [0x27] = "fmovDsNw",
  516. [0x28] = "fcvtpsDwNs", [0x29] = "fcvtpuDwNs",
  517. [0x30] = "fcvtmsDwNs", [0x31] = "fcvtmuDwNs",
  518. [0x38] = "fcvtzsDwNs", [0x39] = "fcvtzuDwNs",
  519. [0x60] = "fcvtnsDwNd", [0x61] = "fcvtnuDwNd",
  520. [0x62] = "scvtfDdNw", [0x63] = "ucvtfDdNw",
  521. [0x64] = "fcvtasDwNd", [0x65] = "fcvtauDwNd",
  522. [0x68] = "fcvtpsDwNd", [0x69] = "fcvtpuDwNd",
  523. [0x70] = "fcvtmsDwNd", [0x71] = "fcvtmuDwNd",
  524. [0x78] = "fcvtzsDwNd", [0x79] = "fcvtzuDwNd"
  525. },
  526. {
  527. shift = 16, mask = 0xff,
  528. [0x20] = "fcvtnsDxNs", [0x21] = "fcvtnuDxNs",
  529. [0x22] = "scvtfDsNx", [0x23] = "ucvtfDsNx",
  530. [0x24] = "fcvtasDxNs", [0x25] = "fcvtauDxNs",
  531. [0x28] = "fcvtpsDxNs", [0x29] = "fcvtpuDxNs",
  532. [0x30] = "fcvtmsDxNs", [0x31] = "fcvtmuDxNs",
  533. [0x38] = "fcvtzsDxNs", [0x39] = "fcvtzuDxNs",
  534. [0x60] = "fcvtnsDxNd", [0x61] = "fcvtnuDxNd",
  535. [0x62] = "scvtfDdNx", [0x63] = "ucvtfDdNx",
  536. [0x64] = "fcvtasDxNd", [0x65] = "fcvtauDxNd",
  537. [0x66] = "fmovDxNd", [0x67] = "fmovDdNx",
  538. [0x68] = "fcvtpsDxNd", [0x69] = "fcvtpuDxNd",
  539. [0x70] = "fcvtmsDxNd", [0x71] = "fcvtmuDxNd",
  540. [0x78] = "fcvtzsDxNd", [0x79] = "fcvtzuDxNd"
  541. }
  542. }
  543. },
  544. { -- FP data-processing, 1 source.
  545. shift = 31, mask = 1,
  546. [0] = {
  547. shift = 22, mask = 3,
  548. [0] = {
  549. shift = 15, mask = 63,
  550. [0] = "fmovDNf", "fabsDNf", "fnegDNf",
  551. "fsqrtDNf", false, "fcvtDdNs", false, false,
  552. "frintnDNf", "frintpDNf", "frintmDNf", "frintzDNf",
  553. "frintaDNf", false, "frintxDNf", "frintiDNf",
  554. },
  555. {
  556. shift = 15, mask = 63,
  557. [0] = "fmovDNf", "fabsDNf", "fnegDNf",
  558. "fsqrtDNf", "fcvtDsNd", false, false, false,
  559. "frintnDNf", "frintpDNf", "frintmDNf", "frintzDNf",
  560. "frintaDNf", false, "frintxDNf", "frintiDNf",
  561. }
  562. }
  563. }
  564. },
  565. { -- FP compare.
  566. shift = 31, mask = 1,
  567. [0] = {
  568. shift = 14, mask = 3,
  569. [0] = {
  570. shift = 23, mask = 1,
  571. [0] = {
  572. shift = 0, mask = 31,
  573. [0] = "fcmpNMf", [8] = "fcmpNZf",
  574. [16] = "fcmpeNMf", [24] = "fcmpeNZf",
  575. }
  576. }
  577. }
  578. }
  579. },
  580. { -- FP immediate.
  581. shift = 31, mask = 1,
  582. [0] = {
  583. shift = 5, mask = 31,
  584. [0] = {
  585. shift = 23, mask = 1,
  586. [0] = "fmovDFf"
  587. }
  588. }
  589. }
  590. },
  591. { -- FP conditional compare.
  592. shift = 31, mask = 1,
  593. [0] = {
  594. shift = 23, mask = 1,
  595. [0] = {
  596. shift = 4, mask = 1,
  597. [0] = "fccmpNMVCf", "fccmpeNMVCf"
  598. }
  599. }
  600. },
  601. { -- FP data-processing, 2 sources.
  602. shift = 31, mask = 1,
  603. [0] = {
  604. shift = 23, mask = 1,
  605. [0] = {
  606. shift = 12, mask = 15,
  607. [0] = "fmulDNMf", "fdivDNMf", "faddDNMf", "fsubDNMf",
  608. "fmaxDNMf", "fminDNMf", "fmaxnmDNMf", "fminnmDNMf",
  609. "fnmulDNMf"
  610. }
  611. }
  612. },
  613. { -- FP conditional select.
  614. shift = 31, mask = 1,
  615. [0] = {
  616. shift = 23, mask = 1,
  617. [0] = "fcselDNMCf"
  618. }
  619. }
  620. }
  621. },
  622. { -- FP data-processing, 3 sources.
  623. shift = 31, mask = 1,
  624. [0] = {
  625. shift = 15, mask = 1,
  626. [0] = {
  627. shift = 21, mask = 5,
  628. [0] = "fmaddDNMAf", "fnmaddDNMAf"
  629. },
  630. {
  631. shift = 21, mask = 5,
  632. [0] = "fmsubDNMAf", "fnmsubDNMAf"
  633. }
  634. }
  635. }
  636. }
  637. }
  638. local map_br = { -- Branches, exception generating and system instructions.
  639. shift = 29, mask = 7,
  640. [0] = "bB",
  641. { -- Compare & branch, immediate.
  642. shift = 24, mask = 3,
  643. [0] = "cbzDBg", "cbnzDBg", "tbzDTBw", "tbnzDTBw"
  644. },
  645. { -- Conditional branch, immediate.
  646. shift = 24, mask = 3,
  647. [0] = {
  648. shift = 4, mask = 1,
  649. [0] = {
  650. shift = 0, mask = 15,
  651. [0] = "beqB", "bneB", "bhsB", "bloB", "bmiB", "bplB", "bvsB", "bvcB",
  652. "bhiB", "blsB", "bgeB", "bltB", "bgtB", "bleB", "balB"
  653. }
  654. }
  655. }, false, "blB",
  656. { -- Compare & branch, immediate.
  657. shift = 24, mask = 3,
  658. [0] = "cbzDBg", "cbnzDBg", "tbzDTBx", "tbnzDTBx"
  659. },
  660. {
  661. shift = 24, mask = 3,
  662. [0] = { -- Exception generation.
  663. shift = 0, mask = 0xe0001f,
  664. [0x200000] = "brkW"
  665. },
  666. { -- System instructions.
  667. shift = 0, mask = 0x3fffff,
  668. [0x03201f] = "nop"
  669. },
  670. { -- Unconditional branch, register.
  671. shift = 0, mask = 0xfffc1f,
  672. [0x1f0000] = "brNx", [0x3f0000] = "blrNx",
  673. [0x5f0000] = "retNx"
  674. },
  675. }
  676. }
  677. local map_init = {
  678. shift = 25, mask = 15,
  679. [0] = false, false, false, false, map_ls, map_datar, map_ls, map_datafp,
  680. map_datai, map_datai, map_br, map_br, map_ls, map_datar, map_ls, map_datafp
  681. }
  682. ------------------------------------------------------------------------------
  683. local map_regs = { x = {}, w = {}, d = {}, s = {} }
  684. for i=0,30 do
  685. map_regs.x[i] = "x"..i
  686. map_regs.w[i] = "w"..i
  687. map_regs.d[i] = "d"..i
  688. map_regs.s[i] = "s"..i
  689. end
  690. map_regs.x[31] = "sp"
  691. map_regs.w[31] = "wsp"
  692. map_regs.d[31] = "d31"
  693. map_regs.s[31] = "s31"
  694. local map_cond = {
  695. [0] = "eq", "ne", "cs", "cc", "mi", "pl", "vs", "vc",
  696. "hi", "ls", "ge", "lt", "gt", "le", "al",
  697. }
  698. local map_shift = { [0] = "lsl", "lsr", "asr", "ror"}
  699. local map_extend = {
  700. [0] = "uxtb", "uxth", "uxtw", "uxtx", "sxtb", "sxth", "sxtw", "sxtx",
  701. }
  702. ------------------------------------------------------------------------------
  703. -- Output a nicely formatted line with an opcode and operands.
  704. local function putop(ctx, text, operands)
  705. local pos = ctx.pos
  706. local extra = ""
  707. if ctx.rel then
  708. local sym = ctx.symtab[ctx.rel]
  709. if sym then
  710. extra = "\t->"..sym
  711. end
  712. end
  713. if ctx.hexdump > 0 then
  714. ctx.out(format("%08x %s %-5s %s%s\n",
  715. ctx.addr+pos, tohex(ctx.op), text, concat(operands, ", "), extra))
  716. else
  717. ctx.out(format("%08x %-5s %s%s\n",
  718. ctx.addr+pos, text, concat(operands, ", "), extra))
  719. end
  720. ctx.pos = pos + 4
  721. end
  722. -- Fallback for unknown opcodes.
  723. local function unknown(ctx)
  724. return putop(ctx, ".long", { "0x"..tohex(ctx.op) })
  725. end
  726. local function match_reg(p, pat, regnum)
  727. return map_regs[match(pat, p.."%w-([xwds])")][regnum]
  728. end
  729. local function fmt_hex32(x)
  730. if x < 0 then
  731. return tohex(x)
  732. else
  733. return format("%x", x)
  734. end
  735. end
  736. local imm13_rep = { 0x55555555, 0x11111111, 0x01010101, 0x00010001, 0x00000001 }
  737. local function decode_imm13(op)
  738. local imms = band(rshift(op, 10), 63)
  739. local immr = band(rshift(op, 16), 63)
  740. if band(op, 0x00400000) == 0 then
  741. local len = 5
  742. if imms >= 56 then
  743. if imms >= 60 then len = 1 else len = 2 end
  744. elseif imms >= 48 then len = 3 elseif imms >= 32 then len = 4 end
  745. local l = lshift(1, len)-1
  746. local s = band(imms, l)
  747. local r = band(immr, l)
  748. local imm = ror(rshift(-1, 31-s), r)
  749. if len ~= 5 then imm = band(imm, lshift(1, l)-1) + rshift(imm, 31-l) end
  750. imm = imm * imm13_rep[len]
  751. local ix = fmt_hex32(imm)
  752. if rshift(op, 31) ~= 0 then
  753. return ix..tohex(imm)
  754. else
  755. return ix
  756. end
  757. else
  758. local lo, hi = -1, 0
  759. if imms < 32 then lo = rshift(-1, 31-imms) else hi = rshift(-1, 63-imms) end
  760. if immr ~= 0 then
  761. lo, hi = ror(lo, immr), ror(hi, immr)
  762. local x = immr == 32 and 0 or band(bxor(lo, hi), lshift(-1, 32-immr))
  763. lo, hi = bxor(lo, x), bxor(hi, x)
  764. if immr >= 32 then lo, hi = hi, lo end
  765. end
  766. if hi ~= 0 then
  767. return fmt_hex32(hi)..tohex(lo)
  768. else
  769. return fmt_hex32(lo)
  770. end
  771. end
  772. end
  773. local function parse_immpc(op, name)
  774. if name == "b" or name == "bl" then
  775. return arshift(lshift(op, 6), 4)
  776. elseif name == "adr" or name == "adrp" then
  777. local immlo = band(rshift(op, 29), 3)
  778. local immhi = lshift(arshift(lshift(op, 8), 13), 2)
  779. return bor(immhi, immlo)
  780. elseif name == "tbz" or name == "tbnz" then
  781. return lshift(arshift(lshift(op, 13), 18), 2)
  782. else
  783. return lshift(arshift(lshift(op, 8), 13), 2)
  784. end
  785. end
  786. local function parse_fpimm8(op)
  787. local sign = band(op, 0x100000) == 0 and 1 or -1
  788. local exp = bxor(rshift(arshift(lshift(op, 12), 5), 24), 0x80) - 131
  789. local frac = 16+band(rshift(op, 13), 15)
  790. return sign * frac * 2^exp
  791. end
  792. local function prefer_bfx(sf, uns, imms, immr)
  793. if imms < immr or imms == 31 or imms == 63 then
  794. return false
  795. end
  796. if immr == 0 then
  797. if sf == 0 and (imms == 7 or imms == 15) then
  798. return false
  799. end
  800. if sf ~= 0 and uns == 0 and (imms == 7 or imms == 15 or imms == 31) then
  801. return false
  802. end
  803. end
  804. return true
  805. end
  806. -- Disassemble a single instruction.
  807. local function disass_ins(ctx)
  808. local pos = ctx.pos
  809. local b0, b1, b2, b3 = byte(ctx.code, pos+1, pos+4)
  810. local op = bor(lshift(b3, 24), lshift(b2, 16), lshift(b1, 8), b0)
  811. local operands = {}
  812. local suffix = ""
  813. local last, name, pat
  814. local map_reg
  815. ctx.op = op
  816. ctx.rel = nil
  817. last = nil
  818. local opat
  819. opat = map_init[band(rshift(op, 25), 15)]
  820. while type(opat) ~= "string" do
  821. if not opat then return unknown(ctx) end
  822. opat = opat[band(rshift(op, opat.shift), opat.mask)] or opat._
  823. end
  824. name, pat = match(opat, "^([a-z0-9]*)(.*)")
  825. local altname, pat2 = match(pat, "|([a-z0-9_.|]*)(.*)")
  826. if altname then pat = pat2 end
  827. if sub(pat, 1, 1) == "." then
  828. local s2, p2 = match(pat, "^([a-z0-9.]*)(.*)")
  829. suffix = suffix..s2
  830. pat = p2
  831. end
  832. local rt = match(pat, "[gf]")
  833. if rt then
  834. if rt == "g" then
  835. map_reg = band(op, 0x80000000) ~= 0 and map_regs.x or map_regs.w
  836. else
  837. map_reg = band(op, 0x400000) ~= 0 and map_regs.d or map_regs.s
  838. end
  839. end
  840. local second0, immr
  841. for p in gmatch(pat, ".") do
  842. local x = nil
  843. if p == "D" then
  844. local regnum = band(op, 31)
  845. x = rt and map_reg[regnum] or match_reg(p, pat, regnum)
  846. elseif p == "N" then
  847. local regnum = band(rshift(op, 5), 31)
  848. x = rt and map_reg[regnum] or match_reg(p, pat, regnum)
  849. elseif p == "M" then
  850. local regnum = band(rshift(op, 16), 31)
  851. x = rt and map_reg[regnum] or match_reg(p, pat, regnum)
  852. elseif p == "A" then
  853. local regnum = band(rshift(op, 10), 31)
  854. x = rt and map_reg[regnum] or match_reg(p, pat, regnum)
  855. elseif p == "B" then
  856. local addr = ctx.addr + pos + parse_immpc(op, name)
  857. ctx.rel = addr
  858. x = "0x"..tohex(addr)
  859. elseif p == "T" then
  860. x = bor(band(rshift(op, 26), 32), band(rshift(op, 19), 31))
  861. elseif p == "V" then
  862. x = band(op, 15)
  863. elseif p == "C" then
  864. x = map_cond[band(rshift(op, 12), 15)]
  865. elseif p == "c" then
  866. local rn = band(rshift(op, 5), 31)
  867. local rm = band(rshift(op, 16), 31)
  868. local cond = band(rshift(op, 12), 15)
  869. local invc = bxor(cond, 1)
  870. x = map_cond[cond]
  871. if altname and cond ~= 14 and cond ~= 15 then
  872. local a1, a2 = match(altname, "([^|]*)|(.*)")
  873. if rn == rm then
  874. local n = #operands
  875. operands[n] = nil
  876. x = map_cond[invc]
  877. if rn ~= 31 then
  878. if a1 then name = a1 else name = altname end
  879. else
  880. operands[n-1] = nil
  881. name = a2
  882. end
  883. end
  884. end
  885. elseif p == "W" then
  886. x = band(rshift(op, 5), 0xffff)
  887. elseif p == "Y" then
  888. x = band(rshift(op, 5), 0xffff)
  889. local hw = band(rshift(op, 21), 3)
  890. if altname and (hw == 0 or x ~= 0) then
  891. name = altname
  892. end
  893. elseif p == "L" then
  894. local rn = map_regs.x[band(rshift(op, 5), 31)]
  895. local imm9 = arshift(lshift(op, 11), 23)
  896. if band(op, 0x800) ~= 0 then
  897. x = "["..rn..", #"..imm9.."]!"
  898. else
  899. x = "["..rn.."], #"..imm9
  900. end
  901. elseif p == "U" then
  902. local rn = map_regs.x[band(rshift(op, 5), 31)]
  903. local sz = band(rshift(op, 30), 3)
  904. local imm12 = lshift(rshift(lshift(op, 10), 20), sz)
  905. if imm12 ~= 0 then
  906. x = "["..rn..", #"..imm12.."]"
  907. else
  908. x = "["..rn.."]"
  909. end
  910. elseif p == "K" then
  911. local rn = map_regs.x[band(rshift(op, 5), 31)]
  912. local imm9 = arshift(lshift(op, 11), 23)
  913. if imm9 ~= 0 then
  914. x = "["..rn..", #"..imm9.."]"
  915. else
  916. x = "["..rn.."]"
  917. end
  918. elseif p == "O" then
  919. local rn, rm = map_regs.x[band(rshift(op, 5), 31)]
  920. local m = band(rshift(op, 13), 1)
  921. if m == 0 then
  922. rm = map_regs.w[band(rshift(op, 16), 31)]
  923. else
  924. rm = map_regs.x[band(rshift(op, 16), 31)]
  925. end
  926. x = "["..rn..", "..rm
  927. local opt = band(rshift(op, 13), 7)
  928. local s = band(rshift(op, 12), 1)
  929. local sz = band(rshift(op, 30), 3)
  930. -- extension to be applied
  931. if opt == 3 then
  932. if s == 0 then x = x.."]"
  933. else x = x..", lsl #"..sz.."]" end
  934. elseif opt == 2 or opt == 6 or opt == 7 then
  935. if s == 0 then x = x..", "..map_extend[opt].."]"
  936. else x = x..", "..map_extend[opt].." #"..sz.."]" end
  937. else
  938. x = x.."]"
  939. end
  940. elseif p == "P" then
  941. local sh = 2 + rshift(op, 31 - band(rshift(op, 26), 1))
  942. local imm7 = lshift(arshift(lshift(op, 10), 25), sh)
  943. local rn = map_regs.x[band(rshift(op, 5), 31)]
  944. local ind = band(rshift(op, 23), 3)
  945. if ind == 1 then
  946. x = "["..rn.."], #"..imm7
  947. elseif ind == 2 then
  948. if imm7 == 0 then
  949. x = "["..rn.."]"
  950. else
  951. x = "["..rn..", #"..imm7.."]"
  952. end
  953. elseif ind == 3 then
  954. x = "["..rn..", #"..imm7.."]!"
  955. end
  956. elseif p == "I" then
  957. local shf = band(rshift(op, 22), 3)
  958. local imm12 = band(rshift(op, 10), 0x0fff)
  959. local rn, rd = band(rshift(op, 5), 31), band(op, 31)
  960. if altname == "mov" and shf == 0 and imm12 == 0 and (rn == 31 or rd == 31) then
  961. name = altname
  962. x = nil
  963. elseif shf == 0 then
  964. x = imm12
  965. elseif shf == 1 then
  966. x = imm12..", lsl #12"
  967. end
  968. elseif p == "i" then
  969. x = "#0x"..decode_imm13(op)
  970. elseif p == "1" then
  971. immr = band(rshift(op, 16), 63)
  972. x = immr
  973. elseif p == "2" then
  974. x = band(rshift(op, 10), 63)
  975. if altname then
  976. local a1, a2, a3, a4, a5, a6 =
  977. match(altname, "([^|]*)|([^|]*)|([^|]*)|([^|]*)|([^|]*)|(.*)")
  978. local sf = band(rshift(op, 26), 32)
  979. local uns = band(rshift(op, 30), 1)
  980. if prefer_bfx(sf, uns, x, immr) then
  981. name = a2
  982. x = x - immr + 1
  983. elseif immr == 0 and x == 7 then
  984. local n = #operands
  985. operands[n] = nil
  986. if sf ~= 0 then
  987. operands[n-1] = gsub(operands[n-1], "x", "w")
  988. end
  989. last = operands[n-1]
  990. name = a6
  991. x = nil
  992. elseif immr == 0 and x == 15 then
  993. local n = #operands
  994. operands[n] = nil
  995. if sf ~= 0 then
  996. operands[n-1] = gsub(operands[n-1], "x", "w")
  997. end
  998. last = operands[n-1]
  999. name = a5
  1000. x = nil
  1001. elseif x == 31 or x == 63 then
  1002. if x == 31 and immr == 0 and name == "sbfm" then
  1003. name = a4
  1004. local n = #operands
  1005. operands[n] = nil
  1006. if sf ~= 0 then
  1007. operands[n-1] = gsub(operands[n-1], "x", "w")
  1008. end
  1009. last = operands[n-1]
  1010. else
  1011. name = a3
  1012. end
  1013. x = nil
  1014. elseif band(x, 31) ~= 31 and immr == x+1 and name == "ubfm" then
  1015. name = a4
  1016. last = "#"..(sf+32 - immr)
  1017. operands[#operands] = last
  1018. x = nil
  1019. elseif x < immr then
  1020. name = a1
  1021. last = "#"..(sf+32 - immr)
  1022. operands[#operands] = last
  1023. x = x + 1
  1024. end
  1025. end
  1026. elseif p == "3" then
  1027. x = band(rshift(op, 10), 63)
  1028. if altname then
  1029. local a1, a2 = match(altname, "([^|]*)|(.*)")
  1030. if x < immr then
  1031. name = a1
  1032. local sf = band(rshift(op, 26), 32)
  1033. last = "#"..(sf+32 - immr)
  1034. operands[#operands] = last
  1035. x = x + 1
  1036. else
  1037. name = a2
  1038. x = x - immr + 1
  1039. end
  1040. end
  1041. elseif p == "4" then
  1042. x = band(rshift(op, 10), 63)
  1043. local rn = band(rshift(op, 5), 31)
  1044. local rm = band(rshift(op, 16), 31)
  1045. if altname and rn == rm then
  1046. local n = #operands
  1047. operands[n] = nil
  1048. last = operands[n-1]
  1049. name = altname
  1050. end
  1051. elseif p == "5" then
  1052. x = band(rshift(op, 16), 31)
  1053. elseif p == "S" then
  1054. x = band(rshift(op, 10), 63)
  1055. if x == 0 then x = nil
  1056. else x = map_shift[band(rshift(op, 22), 3)].." #"..x end
  1057. elseif p == "X" then
  1058. local opt = band(rshift(op, 13), 7)
  1059. -- Width specifier <R>.
  1060. if opt ~= 3 and opt ~= 7 then
  1061. last = map_regs.w[band(rshift(op, 16), 31)]
  1062. operands[#operands] = last
  1063. end
  1064. x = band(rshift(op, 10), 7)
  1065. -- Extension.
  1066. if opt == 2 + band(rshift(op, 31), 1) and
  1067. band(rshift(op, second0 and 5 or 0), 31) == 31 then
  1068. if x == 0 then x = nil
  1069. else x = "lsl #"..x end
  1070. else
  1071. if x == 0 then x = map_extend[band(rshift(op, 13), 7)]
  1072. else x = map_extend[band(rshift(op, 13), 7)].." #"..x end
  1073. end
  1074. elseif p == "R" then
  1075. x = band(rshift(op,21), 3)
  1076. if x == 0 then x = nil
  1077. else x = "lsl #"..x*16 end
  1078. elseif p == "z" then
  1079. local n = #operands
  1080. if operands[n] == "sp" then operands[n] = "xzr"
  1081. elseif operands[n] == "wsp" then operands[n] = "wzr"
  1082. end
  1083. elseif p == "Z" then
  1084. x = 0
  1085. elseif p == "F" then
  1086. x = parse_fpimm8(op)
  1087. elseif p == "g" or p == "f" or p == "x" or p == "w" or
  1088. p == "d" or p == "s" then
  1089. -- These are handled in D/N/M/A.
  1090. elseif p == "0" then
  1091. if last == "sp" or last == "wsp" then
  1092. local n = #operands
  1093. operands[n] = nil
  1094. last = operands[n-1]
  1095. if altname then
  1096. local a1, a2 = match(altname, "([^|]*)|(.*)")
  1097. if not a1 then
  1098. name = altname
  1099. elseif second0 then
  1100. name, altname = a2, a1
  1101. else
  1102. name, altname = a1, a2
  1103. end
  1104. end
  1105. end
  1106. second0 = true
  1107. else
  1108. assert(false)
  1109. end
  1110. if x then
  1111. last = x
  1112. if type(x) == "number" then x = "#"..x end
  1113. operands[#operands+1] = x
  1114. end
  1115. end
  1116. return putop(ctx, name..suffix, operands)
  1117. end
  1118. ------------------------------------------------------------------------------
  1119. -- Disassemble a block of code.
  1120. local function disass_block(ctx, ofs, len)
  1121. if not ofs then ofs = 0 end
  1122. local stop = len and ofs+len or #ctx.code
  1123. ctx.pos = ofs
  1124. ctx.rel = nil
  1125. while ctx.pos < stop do disass_ins(ctx) end
  1126. end
  1127. -- Extended API: create a disassembler context. Then call ctx:disass(ofs, len).
  1128. local function create(code, addr, out)
  1129. local ctx = {}
  1130. ctx.code = code
  1131. ctx.addr = addr or 0
  1132. ctx.out = out or io.write
  1133. ctx.symtab = {}
  1134. ctx.disass = disass_block
  1135. ctx.hexdump = 8
  1136. return ctx
  1137. end
  1138. -- Simple API: disassemble code (a string) at address and output via out.
  1139. local function disass(code, addr, out)
  1140. create(code, addr, out):disass()
  1141. end
  1142. -- Return register name for RID.
  1143. local function regname(r)
  1144. if r < 32 then return map_regs.x[r] end
  1145. return map_regs.d[r-32]
  1146. end
  1147. -- Public module functions.
  1148. return {
  1149. create = create,
  1150. disass = disass,
  1151. regname = regname
  1152. }