From cdce6ba84e8aa5972fb4b5820fab87ce1b197d77 Mon Sep 17 00:00:00 2001 From: iximeow Date: Sun, 17 Mar 2019 01:04:40 -0700 Subject: several tweaks: * DisplacementI32 was never used, DisplacementU64 added to distinguish 8 and 4 byte addresses * Added setCC instructions * Fix sign extension bug for displacement as interpreted by E operands * Add operand code support for a0,a1,a2,a3 movs * Add operand code support for Ivs, Ibs * Complete support for 0x81 * Clean up tests --- test/test.rs | 191 ++++++++++++++++++++++++++--------------------------------- 1 file changed, 85 insertions(+), 106 deletions(-) (limited to 'test') diff --git a/test/test.rs b/test/test.rs index 8a0b6cb..7f00432 100644 --- a/test/test.rs +++ b/test/test.rs @@ -1,146 +1,125 @@ +extern crate yaxpeax_arch; extern crate yaxpeax_x86; +use std::fmt::Write; + +use yaxpeax_arch::Decodable; use yaxpeax_x86::{Instruction, Opcode, decode_one}; fn decode(bytes: &[u8]) -> Option { let mut instr = Instruction::invalid(); - match decode_one(bytes, &mut instr) { + match decode_one(bytes.iter().map(|x| *x).take(16).collect::>(), &mut instr) { Some(()) => Some(instr), None => None } } +fn test_display(data: &[u8], expected: &'static str) { + let mut hex = String::new(); + for b in data { + write!(hex, "{:02x}", b); + } + match Instruction::decode(data.into_iter().map(|x| *x)) { + Some(instr) => { + let text = format!("{}", instr); + assert!( + text == expected, + "display error for {}:\n decoded: {:?}\n displayed: {}\n expected: {}\n", + hex, + instr, + text, + expected + ); + }, + None => { + assert!(false, "decode error for {}:\n expected: {}\n", hex, expected); + } + } +} + +#[test] +fn test_arithmetic() { + test_display(&[0x81, 0xec, 0x10, 0x03, 0x00, 0x00], "sub esp, 0x310"); +} + +#[test] +fn test_E_decode() { + test_display(&[0xff, 0x75, 0xb8], "push [rbp - 0x48]"); + test_display(&[0xff, 0x75, 0x08], "push [rbp + 0x8]"); +} + +// SETLE, SETNG, ... + #[test] fn test_mov() { - assert_eq!(&format!("{}", decode( - &[0x48, 0xc7, 0x04, 0x24, 0x00, 0x00, 0x00, 0x00] - ).unwrap()), "mov [rsp], 0x0"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x89, 0x44, 0x24, 0x08] - ).unwrap()), "mov [rsp + 0x8], rax"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x89, 0x43, 0x18] - ).unwrap()), "mov [rbx + 0x18], rax"); - assert_eq!(&format!("{}", decode( - &[0x48, 0xc7, 0x43, 0x10, 0x00, 0x00, 0x00, 0x00] - ).unwrap()), "mov [rbx + 0x10], 0x0"); - assert_eq!(&format!("{}", decode( - &[0x49, 0x89, 0x4e, 0x08] - ).unwrap()), "mov [r14 + 0x8], rcx"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x8b, 0x32] - ).unwrap()), "mov rsi, [rdx]"); - assert_eq!(&format!("{}", decode( - &[0x49, 0x89, 0x46, 0x10] - ).unwrap()), "mov [r14 + 0x10], rax"); - assert_eq!(&format!("{}", decode( - &[0x4d, 0x0f, 0x43, 0xec, 0x49] - ).unwrap()), "cmovnb r13, r12"); - assert_eq!(&format!("{}", decode( - &[0x0f, 0xb6, 0x06] - ).unwrap()), "movzx eax, byte [rsi]"); - assert_eq!(&format!("{}", decode( - &[0x0f, 0xb7, 0x06] - ).unwrap()), "movzx eax, word [rsi]"); + // test_display(&[0xa1, 0x93, 0x62, 0xc4, 0x00, 0x12, 0x34, 0x12, 0x34], "mov eax, [0x3412341200c46293]"); + // RCT.exe 32bit version, TODO: FIX + test_display(&[0xa1, 0x93, 0x62, 0xc4, 0x00], "mov eax, [0xc46293]"); + test_display(&[0x48, 0xc7, 0x04, 0x24, 0x00, 0x00, 0x00, 0x00], "mov [rsp], 0x0"); + test_display(&[0x48, 0x89, 0x44, 0x24, 0x08], "mov [rsp + 0x8], rax"); + test_display(&[0x48, 0x89, 0x43, 0x18], "mov [rbx + 0x18], rax"); + test_display(&[0x48, 0xc7, 0x43, 0x10, 0x00, 0x00, 0x00, 0x00], "mov [rbx + 0x10], 0x0"); + test_display(&[0x49, 0x89, 0x4e, 0x08], "mov [r14 + 0x8], rcx"); + test_display(&[0x48, 0x8b, 0x32], "mov rsi, [rdx]"); + test_display(&[0x49, 0x89, 0x46, 0x10], "mov [r14 + 0x10], rax"); + test_display(&[0x4d, 0x0f, 0x43, 0xec, 0x49], "cmovnb r13, r12"); + test_display(&[0x0f, 0xb6, 0x06], "movzx eax, byte [rsi]"); + test_display(&[0x0f, 0xb7, 0x06], "movzx eax, word [rsi]"); + test_display(&[0x89, 0x55, 0x94], "mov [rbp - 0x6c], edx"); } #[test] fn test_stack() { - assert_eq!(&format!("{}", decode( - &[0x66, 0x41, 0x50] - ).unwrap()), "push r8w"); + test_display(&[0x66, 0x41, 0x50], "push r8w"); } #[test] fn test_prefixes() { - assert_eq!(&format!("{}", decode( - &[0x66, 0x41, 0x31, 0xc0] - ).unwrap()), "xor r8w, ax"); - assert_eq!(&format!("{}", decode( - &[0x66, 0x41, 0x32, 0xc0] - ).unwrap()), "xor al, r8b"); - assert_eq!(&format!("{}", decode( - &[0x40, 0x32, 0xc5] - ).unwrap()), "xor al, bpl"); + test_display(&[0x66, 0x41, 0x31, 0xc0], "xor r8w, ax"); + test_display(&[0x66, 0x41, 0x32, 0xc0], "xor al, r8b"); + test_display(&[0x40, 0x32, 0xc5], "xor al, bpl"); } #[test] fn test_control_flow() { - assert_eq!(&format!("{}", decode( - &[0x73, 0x31] - ).unwrap()), "jnb 0x31"); - assert_eq!(&format!("{}", decode( - &[0x72, 0x5a] - ).unwrap()), "jb 0x5a"); - assert_eq!(&format!("{}", decode( - &[0x0f, 0x86, 0x8b, 0x01, 0x00, 0x00] - ).unwrap()), "jna 0x18b"); - assert_eq!(&format!("{}", decode( - &[0x74, 0x47] - ).unwrap()), "jz 0x47"); - assert_eq!(&format!("{}", decode( - &[0xff, 0x15, 0x7e, 0x72, 0x24, 0x00] - ).unwrap()), "call [rip + 0x24727e]"); - assert_eq!(&format!("{}", decode( - &[0xc3] - ).unwrap()), "ret"); + test_display(&[0x73, 0x31], "jnb 0x31"); + test_display(&[0x72, 0x5a], "jb 0x5a"); + test_display(&[0x0f, 0x86, 0x8b, 0x01, 0x00, 0x00], "jna 0x18b"); + test_display(&[0x74, 0x47], "jz 0x47"); + test_display(&[0xff, 0x15, 0x7e, 0x72, 0x24, 0x00], "call [rip + 0x24727e]"); + test_display(&[0xc3], "ret"); } #[test] fn test_test_cmp() { - assert_eq!(&format!("{}", decode( - &[0x48, 0x3d, 0x01, 0xf0, 0xff, 0xff] - ).unwrap()), "cmp rax, 0xfffffffffffff001"); - assert_eq!(&format!("{}", decode( - &[0x3d, 0x01, 0xf0, 0xff, 0xff] - ).unwrap()), "cmp eax, 0xfffff001"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x83, 0xf8, 0xff] - ).unwrap()), "cmp rax, 0xffffffffffffffff"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x39, 0xc6] - ).unwrap()), "cmp rsi, rax"); + test_display(&[0x48, 0x3d, 0x01, 0xf0, 0xff, 0xff], "cmp rax, 0xfffffffffffff001"); + test_display(&[0x3d, 0x01, 0xf0, 0xff, 0xff], "cmp eax, 0xfffff001"); + test_display(&[0x48, 0x83, 0xf8, 0xff], "cmp rax, 0xffffffffffffffff"); + test_display(&[0x48, 0x39, 0xc6], "cmp rsi, rax"); } #[test] #[ignore] // VEX prefixes are not supported at the moment, in any form fn test_avx() { - assert_eq!(&format!("{}", decode( - &[0xc5, 0xf8, 0x10, 0x00] - ).unwrap()), "vmovups xmm0, xmmword [rax]"); + test_display(&[0xc5, 0xf8, 0x10, 0x00], "vmovups xmm0, xmmword [rax]"); +} + +#[test] +fn test_push_pop() { + test_display(&[0x5b], "pop rbx"); + test_display(&[0x41, 0x5e], "pop r14"); + test_display(&[0x68, 0x7f, 0x63, 0xc4, 0x00], "push 0xc4637f"); } #[test] fn test_misc() { - assert_eq!(&format!("{}", decode( - &[0x48, 0x8d, 0xa4, 0xc7, 0x20, 0x00, 0x00, 0x12] - ).unwrap()), "lea rsp, [rdi + rax * 8 + 0x12000020]"); - assert_eq!(&format!("{}", decode( - &[0x33, 0xc0] - ).unwrap()), "xor eax, eax"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x8d, 0x53, 0x08] - ).unwrap()), "lea rdx, [rbx + 0x8]"); - assert_eq!(&format!("{}", decode( - &[0x31, 0xc9] - ).unwrap()), "xor ecx, ecx"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x29, 0xc8] - ).unwrap()), "sub rax, rcx"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x03, 0x0b] - ).unwrap()), "add rcx, [rbx]"); - assert_eq!(&format!("{}", decode( - &[0x5b] - ).unwrap()), "pop rbx"); - assert_eq!(&format!("{}", decode( - &[0x41, 0x5e] - ).unwrap()), "pop r14"); - assert_eq!(&format!("{}", decode( - &[0x48, 0x8d, 0x0c, 0x12] - ).unwrap()), "lea rcx, [rdx + rdx]"); - assert_eq!(&format!("{}", decode( - &[0xf6, 0xc2, 0x18] - ).unwrap()), "test dl, 0x18"); + test_display(&[0x48, 0x8d, 0xa4, 0xc7, 0x20, 0x00, 0x00, 0x12], "lea rsp, [rdi + rax * 8 + 0x12000020]"); + test_display(&[0x33, 0xc0], "xor eax, eax"); + test_display(&[0x48, 0x8d, 0x53, 0x08], "lea rdx, [rbx + 0x8]"); + test_display(&[0x31, 0xc9], "xor ecx, ecx"); + test_display(&[0x48, 0x29, 0xc8], "sub rax, rcx"); + test_display(&[0x48, 0x03, 0x0b], "add rcx, [rbx]"); + test_display(&[0x48, 0x8d, 0x0c, 0x12], "lea rcx, [rdx + rdx]"); + test_display(&[0xf6, 0xc2, 0x18], "test dl, 0x18"); } -- cgit v1.1