6cf39b613accd98f396d6e47274115733caa5ac8
[b43-tools.git] / disassembler / main.c
1 /*
2  *   Copyright (C) 2006-2010  Michael Buesch <m@bues.ch>
3  *
4  *   This program is free software; you can redistribute it and/or modify
5  *   it under the terms of the GNU General Public License version 2
6  *   as published by the Free Software Foundation.
7  *
8  *   This program is distributed in the hope that it will be useful,
9  *   but WITHOUT ANY WARRANTY; without even the implied warranty of
10  *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
11  *   GNU General Public License for more details.
12  */
13
14 #include "main.h"
15 #include "list.h"
16 #include "util.h"
17 #include "args.h"
18
19 #include <stdio.h>
20 #include <stdint.h>
21 #include <stdlib.h>
22 #include <string.h>
23
24
25 struct bin_instruction {
26         unsigned int opcode;
27         unsigned int operands[3];
28 };
29
30 struct statement {
31         enum {
32                 STMT_INSN,
33                 STMT_LABEL,
34         } type;
35
36         union {
37                 struct {
38                         struct bin_instruction *bin;
39                         const char *name;
40                         const char *operands[5];
41
42                         int labelref_operand;
43                         unsigned int labeladdr;
44                         struct statement *labelref;
45                 } insn;
46                 struct {
47                         char *name;
48                 } label;
49         } u;
50
51         struct list_head list;
52 };
53
54 struct disassembler_context {
55         /* The architecture of the input file. */
56         unsigned int arch;
57
58         struct bin_instruction *code;
59         size_t nr_insns;
60
61         struct list_head stmt_list;
62 };
63
64
65 FILE *infile;
66 FILE *outfile;
67 const char *infile_name;
68 const char *outfile_name;
69
70
71 #define _msg_helper(type, msg, x...)    do {            \
72         fprintf(stderr, "Disassembler " type            \
73                 ":\n  " msg "\n" ,##x);                 \
74                                         } while (0)
75
76 #define dasm_error(msg, x...)   do {            \
77         _msg_helper("ERROR", msg ,##x);         \
78         exit(1);                                \
79                                 } while (0)
80
81 #define dasm_int_error(msg, x...) \
82         dasm_error("Internal error (bug): " msg ,##x)
83
84 #define dasm_warn(msg, x...)    \
85         _msg_helper("warning", msg ,##x)
86
87 #define asm_info(msg, x...)     \
88         _msg_helper("info", msg ,##x)
89
90 static const char * gen_raw_code(unsigned int operand)
91 {
92         char *ret;
93
94         ret = xmalloc(6);
95         snprintf(ret, 6, "@%X", operand);
96
97         return ret;
98 }
99
100 static const char * disasm_mem_operand(unsigned int operand)
101 {
102         char *ret;
103
104         ret = xmalloc(9);
105         snprintf(ret, 9, "[0x%X]", operand);
106
107         return ret;
108 }
109
110 static const char * disasm_indirect_mem_operand(unsigned int operand)
111 {
112         char *ret;
113         unsigned int offset, reg;
114
115         switch (cmdargs.arch) {
116         case 5:
117                 offset = (operand & 0x3F);
118                 reg = ((operand >> 6) & 0x7);
119                 break;
120         case 15:
121                 offset = (operand & 0x7F);
122                 reg = ((operand >> 7) & 0x7);
123                 break;
124         default:
125                 dasm_int_error("disasm_indirect_mem_operand invalid arch");
126         }
127         ret = xmalloc(12);
128         snprintf(ret, 12, "[0x%02X,off%u]", offset, reg);
129
130         return ret;
131 }
132
133 static const char * disasm_imm_operand(unsigned int operand)
134 {
135         char *ret;
136         unsigned int signmask;
137         unsigned int mask;
138
139         switch (cmdargs.arch) {
140         case 5:
141                 signmask = (1 << 9);
142                 mask = 0x3FF;
143                 break;
144         case 15:
145                 signmask = (1 << 10);
146                 mask = 0x7FF;
147                 break;
148         default:
149                 dasm_int_error("disasm_imm_operand invalid arch");
150         }
151
152         operand &= mask;
153
154         ret = xmalloc(7);
155         if (operand & signmask)
156                 operand = (operand | (~mask & 0xFFFF));
157         snprintf(ret, 7, "0x%X", operand);
158
159         return ret;
160 }
161
162 static const char * disasm_spr_operand(unsigned int operand)
163 {
164         char *ret;
165         unsigned int mask;
166
167         switch (cmdargs.arch) {
168         case 5:
169                 mask = 0x1FF;
170                 break;
171         case 15:
172                 mask = 0x7FF;
173                 break;
174         default:
175                 dasm_int_error("disasm_spr_operand invalid arch");
176         }
177
178         ret = xmalloc(8);
179         snprintf(ret, 8, "spr%X", (operand & mask));
180
181         return ret;
182 }
183
184 static const char * disasm_gpr_operand(unsigned int operand)
185 {
186         char *ret;
187         unsigned int mask;
188
189         switch (cmdargs.arch) {
190         case 5:
191                 mask = 0x3F;
192                 break;
193         case 15:
194                 mask = 0x7F;
195                 break;
196         default:
197                 dasm_int_error("disasm_gpr_operand invalid arch");
198         }
199
200         ret = xmalloc(5);
201         snprintf(ret, 5, "r%u", (operand & mask));
202
203         return ret;
204 }
205
206 static void disasm_raw_operand(struct statement *stmt,
207                                int oper_idx,
208                                int out_idx)
209 {
210         unsigned int operand = stmt->u.insn.bin->operands[oper_idx];
211
212         stmt->u.insn.operands[out_idx] = gen_raw_code(operand);
213 }
214
215 static void disasm_std_operand(struct statement *stmt,
216                                int oper_idx,
217                                int out_idx)
218 {
219         unsigned int operand = stmt->u.insn.bin->operands[oper_idx];
220
221         switch (cmdargs.arch) {
222         case 5:
223                 if (!(operand & 0x800)) {
224                         stmt->u.insn.operands[out_idx] = disasm_mem_operand(operand);
225                         return;
226                 } else if ((operand & 0xC00) == 0xC00) { 
227                         stmt->u.insn.operands[out_idx] = disasm_imm_operand(operand);
228                         return;
229                 } else if ((operand & 0xFC0) == 0xBC0) {
230                         stmt->u.insn.operands[out_idx] = disasm_gpr_operand(operand);
231                         return;
232                 } else if ((operand & 0xE00) == 0x800) {
233                         stmt->u.insn.operands[out_idx] = disasm_spr_operand(operand);
234                         return;
235                 } else if ((operand & 0xE00) == 0xA00) {
236                         stmt->u.insn.operands[out_idx] = disasm_indirect_mem_operand(operand);
237                         return;
238                 }
239                 break;
240         case 15:
241                 if (!(operand & 0x1000)) {
242                         stmt->u.insn.operands[out_idx] = disasm_mem_operand(operand);
243                         return;
244                 } else if ((operand & 0x1800) == 0x1800) { 
245                         stmt->u.insn.operands[out_idx] = disasm_imm_operand(operand);
246                         return;
247                 } else if ((operand & 0x1F80) == 0x1780) {
248                         stmt->u.insn.operands[out_idx] = disasm_gpr_operand(operand);
249                         return;
250                 } else if ((operand & 0x1C00) == 0x1000) {
251                         stmt->u.insn.operands[out_idx] = disasm_spr_operand(operand);
252                         return;
253                 } else if ((operand & 0x1C00) == 0x1400) {
254                         stmt->u.insn.operands[out_idx] = disasm_indirect_mem_operand(operand);
255                         return;
256                 }
257                 break;
258         default:
259                 dasm_int_error("disasm_std_operand invalid arch");
260         }
261         /* No luck. Disassemble to raw operand. */
262         disasm_raw_operand(stmt, oper_idx, out_idx);
263 }
264
265 static void disasm_opcode_raw(struct disassembler_context *ctx,
266                               struct statement *stmt,
267                               int raw_operands)
268 {
269         stmt->u.insn.name = gen_raw_code(stmt->u.insn.bin->opcode);
270         if (raw_operands) {
271                 disasm_raw_operand(stmt, 0, 0);
272                 disasm_raw_operand(stmt, 1, 1);
273                 disasm_raw_operand(stmt, 2, 2);
274         } else {
275                 disasm_std_operand(stmt, 0, 0);
276                 disasm_std_operand(stmt, 1, 1);
277                 disasm_std_operand(stmt, 2, 2);
278         }
279 }
280
281 static void disasm_constant_opcodes(struct disassembler_context *ctx,
282                                     struct statement *stmt)
283 {
284         struct bin_instruction *bin = stmt->u.insn.bin;
285
286         switch (bin->opcode) {
287         case 0x1C0:
288                 stmt->u.insn.name = "add";
289                 disasm_std_operand(stmt, 0, 0);
290                 disasm_std_operand(stmt, 1, 1);
291                 disasm_std_operand(stmt, 2, 2);
292                 break;
293         case 0x1C2:
294                 stmt->u.insn.name = "add.";
295                 disasm_std_operand(stmt, 0, 0);
296                 disasm_std_operand(stmt, 1, 1);
297                 disasm_std_operand(stmt, 2, 2);
298                 break;
299         case 0x1C1:
300                 stmt->u.insn.name = "addc";
301                 disasm_std_operand(stmt, 0, 0);
302                 disasm_std_operand(stmt, 1, 1);
303                 disasm_std_operand(stmt, 2, 2);
304                 break;
305         case 0x1C3:
306                 stmt->u.insn.name = "addc.";
307                 disasm_std_operand(stmt, 0, 0);
308                 disasm_std_operand(stmt, 1, 1);
309                 disasm_std_operand(stmt, 2, 2);
310                 break;
311         case 0x1D0:
312                 stmt->u.insn.name = "sub";
313                 disasm_std_operand(stmt, 0, 0);
314                 disasm_std_operand(stmt, 1, 1);
315                 disasm_std_operand(stmt, 2, 2);
316                 break;
317         case 0x1D2:
318                 stmt->u.insn.name = "sub.";
319                 disasm_std_operand(stmt, 0, 0);
320                 disasm_std_operand(stmt, 1, 1);
321                 disasm_std_operand(stmt, 2, 2);
322                 break;
323         case 0x1D1:
324                 stmt->u.insn.name = "subc";
325                 disasm_std_operand(stmt, 0, 0);
326                 disasm_std_operand(stmt, 1, 1);
327                 disasm_std_operand(stmt, 2, 2);
328                 break;
329         case 0x1D3:
330                 stmt->u.insn.name = "subc.";
331                 disasm_std_operand(stmt, 0, 0);
332                 disasm_std_operand(stmt, 1, 1);
333                 disasm_std_operand(stmt, 2, 2);
334                 break;
335         case 0x130:
336                 stmt->u.insn.name = "sra";
337                 disasm_std_operand(stmt, 0, 0);
338                 disasm_std_operand(stmt, 1, 1);
339                 disasm_std_operand(stmt, 2, 2);
340                 break;
341         case 0x160:
342                 stmt->u.insn.name = "or";
343                 disasm_std_operand(stmt, 0, 0);
344                 disasm_std_operand(stmt, 1, 1);
345                 disasm_std_operand(stmt, 2, 2);
346                 break;
347         case 0x140:
348                 stmt->u.insn.name = "and";
349                 disasm_std_operand(stmt, 0, 0);
350                 disasm_std_operand(stmt, 1, 1);
351                 disasm_std_operand(stmt, 2, 2);
352                 break;
353         case 0x170:
354                 stmt->u.insn.name = "xor";
355                 disasm_std_operand(stmt, 0, 0);
356                 disasm_std_operand(stmt, 1, 1);
357                 disasm_std_operand(stmt, 2, 2);
358                 break;
359         case 0x120:
360                 stmt->u.insn.name = "sr";
361                 disasm_std_operand(stmt, 0, 0);
362                 disasm_std_operand(stmt, 1, 1);
363                 disasm_std_operand(stmt, 2, 2);
364                 break;
365         case 0x110:
366                 stmt->u.insn.name = "sl";
367                 disasm_std_operand(stmt, 0, 0);
368                 disasm_std_operand(stmt, 1, 1);
369                 disasm_std_operand(stmt, 2, 2);
370                 break;
371         case 0x1A0:
372                 stmt->u.insn.name = "rl";
373                 disasm_std_operand(stmt, 0, 0);
374                 disasm_std_operand(stmt, 1, 1);
375                 disasm_std_operand(stmt, 2, 2);
376                 break;
377         case 0x1B0:
378                 stmt->u.insn.name = "rr";
379                 disasm_std_operand(stmt, 0, 0);
380                 disasm_std_operand(stmt, 1, 1);
381                 disasm_std_operand(stmt, 2, 2);
382                 break;
383         case 0x150:
384                 stmt->u.insn.name = "nand";
385                 disasm_std_operand(stmt, 0, 0);
386                 disasm_std_operand(stmt, 1, 1);
387                 disasm_std_operand(stmt, 2, 2);
388                 break;
389         case 0x040:
390                 stmt->u.insn.name = "jand";
391                 stmt->u.insn.labelref_operand = 2;
392                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
393                 disasm_std_operand(stmt, 0, 0);
394                 disasm_std_operand(stmt, 1, 1);
395                 break;
396         case (0x040 | 0x1):
397                 stmt->u.insn.name = "jnand";
398                 stmt->u.insn.labelref_operand = 2;
399                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
400                 disasm_std_operand(stmt, 0, 0);
401                 disasm_std_operand(stmt, 1, 1);
402                 break;
403         case 0x050:
404                 stmt->u.insn.name = "js";
405                 stmt->u.insn.labelref_operand = 2;
406                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
407                 disasm_std_operand(stmt, 0, 0);
408                 disasm_std_operand(stmt, 1, 1);
409                 break;
410         case (0x050 | 0x1):
411                 stmt->u.insn.name = "jns";
412                 stmt->u.insn.labelref_operand = 2;
413                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
414                 disasm_std_operand(stmt, 0, 0);
415                 disasm_std_operand(stmt, 1, 1);
416                 break;
417         case 0x0D0:
418                 stmt->u.insn.name = "je";
419                 stmt->u.insn.labelref_operand = 2;
420                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
421                 disasm_std_operand(stmt, 0, 0);
422                 disasm_std_operand(stmt, 1, 1);
423                 break;
424         case (0x0D0 | 0x1):
425                 stmt->u.insn.name = "jne";
426                 stmt->u.insn.labelref_operand = 2;
427                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
428                 disasm_std_operand(stmt, 0, 0);
429                 disasm_std_operand(stmt, 1, 1);
430                 break;
431         case 0x0D2:
432                 stmt->u.insn.name = "jls";
433                 stmt->u.insn.labelref_operand = 2;
434                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
435                 disasm_std_operand(stmt, 0, 0);
436                 disasm_std_operand(stmt, 1, 1);
437                 break;
438         case (0x0D2 | 0x1):
439                 stmt->u.insn.name = "jges";
440                 stmt->u.insn.labelref_operand = 2;
441                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
442                 disasm_std_operand(stmt, 0, 0);
443                 disasm_std_operand(stmt, 1, 1);
444                 break;
445         case 0x0D4:
446                 stmt->u.insn.name = "jgs";
447                 stmt->u.insn.labelref_operand = 2;
448                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
449                 disasm_std_operand(stmt, 0, 0);
450                 disasm_std_operand(stmt, 1, 1);
451                 break;
452         case (0x0D4 | 0x1):
453                 stmt->u.insn.name = "jles";
454                 stmt->u.insn.labelref_operand = 2;
455                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
456                 disasm_std_operand(stmt, 0, 0);
457                 disasm_std_operand(stmt, 1, 1);
458                 break;
459         case 0x0D6:
460                 stmt->u.insn.name = "@D6"; /* FIXME */
461                 stmt->u.insn.labelref_operand = 2;
462                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
463                 disasm_std_operand(stmt, 0, 0);
464                 disasm_std_operand(stmt, 1, 1);
465                 break;
466         case (0x0D6 | 0x1):
467                 stmt->u.insn.name = "@D7"; /* FIXME */
468                 stmt->u.insn.labelref_operand = 2;
469                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
470                 disasm_std_operand(stmt, 0, 0);
471                 disasm_std_operand(stmt, 1, 1);
472                 break;
473         case 0x0D8:
474                 stmt->u.insn.name = "@D8"; /* FIXME */
475                 stmt->u.insn.labelref_operand = 2;
476                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
477                 disasm_std_operand(stmt, 0, 0);
478                 disasm_std_operand(stmt, 1, 1);
479                 break;
480         case (0x0D8 | 0x1):
481                 stmt->u.insn.name = "@D9"; /* FIXME */
482                 stmt->u.insn.labelref_operand = 2;
483                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
484                 disasm_std_operand(stmt, 0, 0);
485                 disasm_std_operand(stmt, 1, 1);
486                 break;
487         case 0x0DA:
488                 stmt->u.insn.name = "jl";
489                 stmt->u.insn.labelref_operand = 2;
490                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
491                 disasm_std_operand(stmt, 0, 0);
492                 disasm_std_operand(stmt, 1, 1);
493                 break;
494         case (0x0DA | 0x1):
495                 stmt->u.insn.name = "jge";
496                 stmt->u.insn.labelref_operand = 2;
497                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
498                 disasm_std_operand(stmt, 0, 0);
499                 disasm_std_operand(stmt, 1, 1);
500                 break;
501         case 0x0DC:
502                 stmt->u.insn.name = "jg";
503                 stmt->u.insn.labelref_operand = 2;
504                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
505                 disasm_std_operand(stmt, 0, 0);
506                 disasm_std_operand(stmt, 1, 1);
507                 break;
508         case (0x0DC | 0x1):
509                 stmt->u.insn.name = "jle";
510                 stmt->u.insn.labelref_operand = 2;
511                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
512                 disasm_std_operand(stmt, 0, 0);
513                 disasm_std_operand(stmt, 1, 1);
514                 break;
515         case 0x002: {
516                 char *str;
517
518                 switch (cmdargs.arch) {
519                 case 5:
520                         stmt->u.insn.name = "call";
521                         stmt->u.insn.labelref_operand = 1;
522                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
523                         str = xmalloc(4);
524                         snprintf(str, 4, "lr%u", stmt->u.insn.bin->operands[0]);
525                         stmt->u.insn.operands[0] = str;
526                         break;
527                 case 15:
528                         //FIXME: This opcode is different on r15. Decode raw for now.
529                         disasm_opcode_raw(ctx, stmt, 1);
530                         break;
531                 }
532                 break;
533         }
534         case 0x003: {
535                 char *str;
536
537                 stmt->u.insn.name = "ret";
538                 str = xmalloc(4);
539                 snprintf(str, 4, "lr%u", stmt->u.insn.bin->operands[0]);
540                 stmt->u.insn.operands[0] = str;
541                 str = xmalloc(4);
542                 snprintf(str, 4, "lr%u", stmt->u.insn.bin->operands[2]);
543                 stmt->u.insn.operands[2] = str;
544                 break;
545         }
546         case 0x004: {
547                 if (cmdargs.arch != 15) {
548                         dasm_error("arch 15 'calls' instruction found in arch %d binary",
549                                    cmdargs.arch);
550                 }
551                 stmt->u.insn.name = "calls";
552                 stmt->u.insn.labelref_operand = 0;
553                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
554                 if (stmt->u.insn.bin->operands[0] != 0x1780 ||
555                     stmt->u.insn.bin->operands[1] != 0x1780)
556                         dasm_warn("r15 calls: Invalid first or second argument");
557                 break;
558         }
559         case 0x005: {
560                 if (cmdargs.arch != 15) {
561                         dasm_error("arch 15 'rets' instruction found in arch %d binary",
562                                    cmdargs.arch);
563                 }
564                 stmt->u.insn.name = "rets";
565                 if (stmt->u.insn.bin->operands[0] != 0x1780 ||
566                     stmt->u.insn.bin->operands[1] != 0x1780 ||
567                     stmt->u.insn.bin->operands[2] != 0)
568                         dasm_warn("r15 rets: Invalid argument(s)");
569                 break;
570         }
571         case 0x1E0: {
572                 unsigned int flags, mask;
573
574                 switch (cmdargs.arch) {
575                 case 5:
576                         mask = 0x3FF;
577                         break;
578                 case 15:
579                         mask = 0x7FF;
580                         break;
581                 default:
582                         dasm_int_error("TKIP invalid arch");
583                 }
584
585                 flags = stmt->u.insn.bin->operands[1];
586                 switch (flags & mask) {
587                 case 0x1:
588                         stmt->u.insn.name = "tkiph";
589                         break;
590                 case (0x1 | 0x2):
591                         stmt->u.insn.name = "tkiphs";
592                         break;
593                 case 0x0:
594                         stmt->u.insn.name = "tkipl";
595                         break;
596                 case (0x0 | 0x2):
597                         stmt->u.insn.name = "tkipls";
598                         break;
599                 default:
600                         dasm_error("Invalid TKIP flags %X", flags);
601                 }
602                 disasm_std_operand(stmt, 0, 0);
603                 disasm_std_operand(stmt, 2, 2);
604                 break;
605         }
606         case 0x001: {
607                 unsigned int mask;
608
609                 stmt->u.insn.name = "nap";
610                 switch (cmdargs.arch) {
611                 case 5:
612                         mask = 0xBC0;
613                         break;
614                 case 15:
615                         mask = 0x1780;
616                         break;
617                 default:
618                         dasm_int_error("NAP invalid arch");
619                 }
620                 if (stmt->u.insn.bin->operands[0] != mask) {
621                         dasm_warn("NAP: invalid first argument 0x%04X\n",
622                                   stmt->u.insn.bin->operands[0]);
623                 }
624                 if (stmt->u.insn.bin->operands[1] != mask) {
625                         dasm_warn("NAP: invalid second argument 0x%04X\n",
626                                   stmt->u.insn.bin->operands[1]);
627                 }
628                 if (stmt->u.insn.bin->operands[2] != 0) {
629                         dasm_warn("NAP: invalid third argument 0x%04X\n",
630                                   stmt->u.insn.bin->operands[2]);
631                 }
632                 break;
633         }
634         case 0x000:
635                 disasm_opcode_raw(ctx, stmt, 1);
636                 break;
637         default:
638                 disasm_opcode_raw(ctx, stmt, (cmdargs.unknown_decode == 0));
639                 break;
640         }
641 }
642
643 static void disasm_opcodes(struct disassembler_context *ctx)
644 {
645         struct bin_instruction *bin;
646         size_t i;
647         struct statement *stmt;
648         char *str;
649
650         for (i = 0; i < ctx->nr_insns; i++) {
651                 bin = &(ctx->code[i]);
652
653                 stmt = xmalloc(sizeof(struct statement));
654                 stmt->type = STMT_INSN;
655                 INIT_LIST_HEAD(&stmt->list);
656                 stmt->u.insn.bin = bin;
657                 stmt->u.insn.labelref_operand = -1; /* none */
658
659                 switch (bin->opcode & 0xF00) {
660                 case 0x200:
661                         stmt->u.insn.name = "srx";
662
663                         str = xmalloc(3);
664                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
665                         stmt->u.insn.operands[0] = str;
666                         str = xmalloc(3);
667                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
668                         stmt->u.insn.operands[1] = str;
669
670                         disasm_std_operand(stmt, 0, 2);
671                         disasm_std_operand(stmt, 1, 3);
672                         disasm_std_operand(stmt, 2, 4);
673                         break;
674                 case 0x300:
675                         stmt->u.insn.name = "orx";
676
677                         str = xmalloc(3);
678                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
679                         stmt->u.insn.operands[0] = str;
680                         str = xmalloc(3);
681                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
682                         stmt->u.insn.operands[1] = str;
683
684                         disasm_std_operand(stmt, 0, 2);
685                         disasm_std_operand(stmt, 1, 3);
686                         disasm_std_operand(stmt, 2, 4);
687                         break;
688                 case 0x400:
689                         stmt->u.insn.name = "jzx";
690
691                         str = xmalloc(3);
692                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
693                         stmt->u.insn.operands[0] = str;
694                         str = xmalloc(3);
695                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
696                         stmt->u.insn.operands[1] = str;
697
698                         disasm_std_operand(stmt, 0, 2);
699                         disasm_std_operand(stmt, 1, 3);
700                         stmt->u.insn.labelref_operand = 4;
701                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
702                         break;
703                 case 0x500:
704                         stmt->u.insn.name = "jnzx";
705
706                         str = xmalloc(3);
707                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
708                         stmt->u.insn.operands[0] = str;
709                         str = xmalloc(3);
710                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
711                         stmt->u.insn.operands[1] = str;
712
713                         disasm_std_operand(stmt, 0, 2);
714                         disasm_std_operand(stmt, 1, 3);
715                         stmt->u.insn.labelref_operand = 4;
716                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
717                         break;
718                 case 0x600:
719                         stmt->u.insn.name = "jnext";
720
721                         str = xmalloc(5);
722                         snprintf(str, 5, "0x%02X", (bin->opcode & 0x0FF));
723                         stmt->u.insn.operands[0] = str;
724
725                         /* We don't disassemble the first and second operand, as
726                          * that always is a dummy r0 operand.
727                          * disasm_std_operand(stmt, 0, 1);
728                          * disasm_std_operand(stmt, 1, 2);
729                          * stmt->u.insn.labelref_operand = 3;
730                          */
731                         stmt->u.insn.labelref_operand = 1;
732                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
733                         break;
734                 case 0x700:
735                         stmt->u.insn.name = "jext";
736
737                         str = xmalloc(5);
738                         snprintf(str, 5, "0x%02X", (bin->opcode & 0x0FF));
739                         stmt->u.insn.operands[0] = str;
740
741                         /* We don't disassemble the first and second operand, as
742                          * that always is a dummy r0 operand.
743                          * disasm_std_operand(stmt, 0, 1);
744                          * disasm_std_operand(stmt, 1, 2);
745                          * stmt->u.insn.labelref_operand = 3;
746                          */
747                         stmt->u.insn.labelref_operand = 1;
748                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
749                         break;
750                 default:
751                         disasm_constant_opcodes(ctx, stmt);
752                         break;
753                 }
754
755                 list_add_tail(&stmt->list, &ctx->stmt_list);
756         }
757 }
758
759 static struct statement * get_label_at(struct disassembler_context *ctx,
760                                        unsigned int addr)
761 {
762         unsigned int addrcnt = 0;
763         struct statement *stmt, *ret, *prev;
764
765         list_for_each_entry(stmt, &ctx->stmt_list, list) {
766                 if (stmt->type != STMT_INSN)
767                         continue;
768                 if (addrcnt == addr) {
769                         prev = list_entry(stmt->list.prev, struct statement, list);
770                         if (prev->type == STMT_LABEL)
771                                 return prev;
772                         ret = xmalloc(sizeof(struct statement));
773                         INIT_LIST_HEAD(&ret->list);
774                         ret->type = STMT_LABEL;
775                         list_add(&ret->list, &prev->list);
776
777                         return ret;
778                 }
779                 addrcnt++;
780         }
781
782         return NULL;
783 }
784
785 static void resolve_labels(struct disassembler_context *ctx)
786 {
787         struct statement *stmt;
788         struct statement *label;
789         struct statement *n;
790         unsigned int labeladdr;
791         unsigned int namecnt = 0;
792
793         /* Resolve label references */
794         list_for_each_entry_safe(stmt, n, &ctx->stmt_list, list) {
795                 if (stmt->type != STMT_INSN)
796                         continue;
797                 if (stmt->u.insn.labelref_operand < 0)
798                         continue; /* Doesn't have label reference operand. */
799                 labeladdr = stmt->u.insn.labeladdr;
800                 label = get_label_at(ctx, labeladdr);
801                 if (!label)
802                         dasm_error("Labeladdress %X out of bounds", labeladdr);
803                 stmt->u.insn.labelref = label;
804         }
805
806         /* Name the labels */
807         list_for_each_entry(stmt, &ctx->stmt_list, list) {
808                 if (stmt->type != STMT_LABEL)
809                         continue;
810                 stmt->u.label.name = xmalloc(20);
811                 snprintf(stmt->u.label.name, 20, "L%u", namecnt);
812                 namecnt++;
813         }
814 }
815
816 static void emit_asm(struct disassembler_context *ctx)
817 {
818         struct statement *stmt;
819         int first;
820         int err;
821         unsigned int i, addr = 0;
822
823         err = open_output_file();
824         if (err)
825                 exit(1);
826
827         fprintf(outfile, "%%arch %u\n", ctx->arch);
828         fprintf(outfile, "%%start entry\n\n");
829         fprintf(outfile, "entry:\n");
830         list_for_each_entry(stmt, &ctx->stmt_list, list) {
831                 switch (stmt->type) {
832                 case STMT_INSN:
833                         if (cmdargs.print_addresses)
834                                 fprintf(outfile, "/* %04X */", addr);
835                         fprintf(outfile, "\t%s", stmt->u.insn.name);
836                         first = 1;
837                         for (i = 0; i < ARRAY_SIZE(stmt->u.insn.operands); i++) {
838                                 if (!stmt->u.insn.operands[i] &&
839                                     (stmt->u.insn.labelref_operand < 0 ||
840                                      (unsigned int)stmt->u.insn.labelref_operand != i))
841                                         continue;
842                                 if (first)
843                                         fprintf(outfile, "\t");
844                                 if (!first)
845                                         fprintf(outfile, ", ");
846                                 first = 0;
847                                 if (stmt->u.insn.labelref_operand >= 0 &&
848                                     (unsigned int)stmt->u.insn.labelref_operand == i) {
849                                         fprintf(outfile, "%s",
850                                                 stmt->u.insn.labelref->u.label.name);
851                                 } else {
852                                         fprintf(outfile, "%s",
853                                                 stmt->u.insn.operands[i]);
854                                 }
855                         }
856                         fprintf(outfile, "\n");
857                         addr++;
858                         break;
859                 case STMT_LABEL:
860                         fprintf(outfile, "%s:\n", stmt->u.label.name);
861                         break;
862                 }
863         }
864
865         close_output_file();
866 }
867
868 static int read_input(struct disassembler_context *ctx)
869 {
870         size_t size = 0, pos = 0;
871         size_t ret;
872         struct bin_instruction *code = NULL;
873         unsigned char tmp[sizeof(uint64_t)];
874         uint64_t codeword;
875         struct fw_header hdr;
876         int err;
877
878         err = open_input_file();
879         if (err)
880                 goto error;
881
882         switch (cmdargs.informat) {
883         case FMT_RAW_LE32:
884         case FMT_RAW_BE32:
885                 /* Nothing */
886                 break;
887         case FMT_B43:
888                 ret = fread(&hdr, 1, sizeof(hdr), infile);
889                 if (ret != sizeof(hdr)) {
890                         fprintf(stderr, "Corrupt input file (no b43 header found)\n");
891                         goto err_close;
892                 }
893                 if (hdr.type != FW_TYPE_UCODE) {
894                         fprintf(stderr, "Corrupt input file. Not a b43 microcode image.\n");
895                         goto err_close;
896                 }
897                 if (hdr.ver != FW_HDR_VER) {
898                         fprintf(stderr, "Invalid input file header version.\n");
899                         goto err_close;
900                 }
901                 break;
902         }
903
904         while (1) {
905                 if (pos >= size) {
906                         size += 512;
907                         code = xrealloc(code, size * sizeof(struct bin_instruction));
908                 }
909                 ret = fread(tmp, 1, sizeof(uint64_t), infile);
910                 if (!ret)
911                         break;
912                 if (ret != sizeof(uint64_t)) {
913                         fprintf(stderr, "Corrupt input file (not 8 byte aligned)\n");
914                         goto err_free_code;
915                 }
916
917                 switch (cmdargs.informat) {
918                 case FMT_B43:
919                 case FMT_RAW_BE32:
920                         codeword = 0;
921                         codeword |= ((uint64_t)tmp[0]) << 56;
922                         codeword |= ((uint64_t)tmp[1]) << 48;
923                         codeword |= ((uint64_t)tmp[2]) << 40;
924                         codeword |= ((uint64_t)tmp[3]) << 32;
925                         codeword |= ((uint64_t)tmp[4]) << 24;
926                         codeword |= ((uint64_t)tmp[5]) << 16;
927                         codeword |= ((uint64_t)tmp[6]) << 8;
928                         codeword |= ((uint64_t)tmp[7]);
929                         codeword = ((codeword & (uint64_t)0xFFFFFFFF00000000ULL) >> 32) |
930                                    ((codeword & (uint64_t)0x00000000FFFFFFFFULL) << 32);
931                         break;
932                 case FMT_RAW_LE32:
933                         codeword = 0;
934                         codeword |= ((uint64_t)tmp[7]) << 56;
935                         codeword |= ((uint64_t)tmp[6]) << 48;
936                         codeword |= ((uint64_t)tmp[5]) << 40;
937                         codeword |= ((uint64_t)tmp[4]) << 32;
938                         codeword |= ((uint64_t)tmp[3]) << 24;
939                         codeword |= ((uint64_t)tmp[2]) << 16;
940                         codeword |= ((uint64_t)tmp[1]) << 8;
941                         codeword |= ((uint64_t)tmp[0]);
942                         break;
943                 }
944
945                 switch (cmdargs.arch) {
946                 case 5:
947                         if (codeword >> 48) {
948                                 fprintf(stderr, "Instruction format error at 0x%X (upper not clear). "
949                                         "Wrong input format or architecture?\n", (unsigned int)pos);
950                                 goto err_free_code;
951                         }
952                         code[pos].opcode = (codeword >> 36) & 0xFFF;
953                         code[pos].operands[2] = codeword & 0xFFF;
954                         code[pos].operands[1] = (codeword >> 12) & 0xFFF;
955                         code[pos].operands[0] = (codeword >> 24) & 0xFFF;
956                         break;
957                 case 15:
958                         if (codeword >> 51) {
959                                 fprintf(stderr, "Instruction format error at 0x%X (upper not clear). "
960                                         "Wrong input format or architecture?\n", (unsigned int)pos);
961                                 goto err_free_code;
962                         }
963                         code[pos].opcode = (codeword >> 39) & 0xFFF;
964                         code[pos].operands[2] = codeword & 0x1FFF;
965                         code[pos].operands[1] = (codeword >> 13) & 0x1FFF;
966                         code[pos].operands[0] = (codeword >> 26) & 0x1FFF;
967                         break;
968                 default:
969                         fprintf(stderr, "Internal error: read_input unknown arch %u\n",
970                                 cmdargs.arch);
971                         goto err_free_code;
972                 }
973
974                 pos++;
975         }
976
977         ctx->code = code;
978         ctx->nr_insns = pos;
979
980         close_input_file();
981
982         return 0;
983
984 err_free_code:
985         free(code);
986 err_close:
987         close_input_file();
988 error:
989         return -1;
990 }
991
992 static void disassemble(void)
993 {
994         struct disassembler_context ctx;
995         int err;
996
997         memset(&ctx, 0, sizeof(ctx));
998         INIT_LIST_HEAD(&ctx.stmt_list);
999         ctx.arch = cmdargs.arch;
1000
1001         err = read_input(&ctx);
1002         if (err)
1003                 exit(1);
1004         disasm_opcodes(&ctx);
1005         resolve_labels(&ctx);
1006         emit_asm(&ctx);
1007 }
1008
1009 int main(int argc, char **argv)
1010 {
1011         int err, res = 1;
1012
1013         err = parse_args(argc, argv);
1014         if (err < 0)
1015                 goto out;
1016         if (err > 0) {
1017                 res = 0;
1018                 goto out;
1019         }
1020         disassemble();
1021         res = 0;
1022 out:
1023         /* Lazyman simply leaks all allocated memory. */
1024         return res;
1025 }