b0d2c7b04dcd993fbd2178dc9a80eb52b2ebac07
[b43-tools.git] / disassembler / main.c
1 /*
2  *   Copyright (C) 2006-2010  Michael Buesch <mb@bu3sch.de>
3  *
4  *   This program is free software; you can redistribute it and/or modify
5  *   it under the terms of the GNU General Public License version 2
6  *   as published by the Free Software Foundation.
7  *
8  *   This program is distributed in the hope that it will be useful,
9  *   but WITHOUT ANY WARRANTY; without even the implied warranty of
10  *   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
11  *   GNU General Public License for more details.
12  */
13
14 #include "main.h"
15 #include "list.h"
16 #include "util.h"
17 #include "args.h"
18
19 #include <stdio.h>
20 #include <stdint.h>
21 #include <stdlib.h>
22 #include <string.h>
23
24
25 struct bin_instruction {
26         unsigned int opcode;
27         unsigned int operands[3];
28 };
29
30 struct statement {
31         enum {
32                 STMT_INSN,
33                 STMT_LABEL,
34         } type;
35
36         union {
37                 struct {
38                         struct bin_instruction *bin;
39                         const char *name;
40                         const char *operands[5];
41
42                         int is_labelref;
43                         unsigned int labeladdr;
44                         struct statement *labelref;
45                 } insn;
46                 struct {
47                         char *name;
48                 } label;
49         } u;
50
51         struct list_head list;
52 };
53
54 struct disassembler_context {
55         /* The architecture of the input file. */
56         unsigned int arch;
57
58         struct bin_instruction *code;
59         size_t nr_insns;
60
61         struct list_head stmt_list;
62 };
63
64
65 FILE *infile;
66 FILE *outfile;
67 const char *infile_name;
68 const char *outfile_name;
69
70
71 #define _msg_helper(type, msg, x...)    do {            \
72         fprintf(stderr, "Disassembler " type            \
73                 ":\n  " msg "\n" ,##x);                 \
74                                         } while (0)
75
76 #define dasm_error(msg, x...)   do {            \
77         _msg_helper("ERROR", msg ,##x);         \
78         exit(1);                                \
79                                 } while (0)
80
81 #define dasm_int_error(msg, x...) \
82         dasm_error("Internal error (bug): " msg ,##x)
83
84 #define dasm_warn(msg, x...)    \
85         _msg_helper("warning", msg ,##x)
86
87 #define asm_info(msg, x...)     \
88         _msg_helper("info", msg ,##x)
89
90 static const char * gen_raw_code(unsigned int operand)
91 {
92         char *ret;
93
94         ret = xmalloc(6);
95         snprintf(ret, 6, "@%X", operand);
96
97         return ret;
98 }
99
100 static const char * disasm_mem_operand(unsigned int operand)
101 {
102         char *ret;
103
104         ret = xmalloc(9);
105         snprintf(ret, 9, "[0x%X]", operand);
106
107         return ret;
108 }
109
110 static const char * disasm_indirect_mem_operand(unsigned int operand)
111 {
112         char *ret;
113         unsigned int offset, reg;
114
115         switch (cmdargs.arch) {
116         case 5:
117                 offset = (operand & 0x3F);
118                 reg = ((operand >> 6) & 0x7);
119                 break;
120         case 15:
121                 offset = (operand & 0x7F);
122                 reg = ((operand >> 7) & 0x7);
123                 break;
124         default:
125                 dasm_int_error("disasm_indirect_mem_operand invalid arch");
126         }
127         ret = xmalloc(12);
128         snprintf(ret, 12, "[0x%02X,off%u]", offset, reg);
129
130         return ret;
131 }
132
133 static const char * disasm_imm_operand(unsigned int operand)
134 {
135         char *ret;
136         unsigned int signmask;
137         unsigned int mask;
138
139         switch (cmdargs.arch) {
140         case 5:
141                 signmask = (1 << 9);
142                 mask = 0x3FF;
143                 break;
144         case 15:
145                 signmask = (1 << 10);
146                 mask = 0x7FF;
147                 break;
148         default:
149                 dasm_int_error("disasm_imm_operand invalid arch");
150         }
151
152         operand &= mask;
153
154         ret = xmalloc(7);
155         if (operand & signmask)
156                 operand = (operand | (~mask & 0xFFFF));
157         snprintf(ret, 7, "0x%X", operand);
158
159         return ret;
160 }
161
162 static const char * disasm_spr_operand(unsigned int operand)
163 {
164         char *ret;
165         unsigned int mask;
166
167         switch (cmdargs.arch) {
168         case 5:
169                 mask = 0x1FF;
170                 break;
171         case 15:
172                 mask = 0x7FF;
173                 break;
174         default:
175                 dasm_int_error("disasm_spr_operand invalid arch");
176         }
177
178         ret = xmalloc(8);
179         snprintf(ret, 8, "spr%X", (operand & mask));
180
181         return ret;
182 }
183
184 static const char * disasm_gpr_operand(unsigned int operand)
185 {
186         char *ret;
187         unsigned int mask;
188
189         switch (cmdargs.arch) {
190         case 5:
191                 mask = 0x3F;
192                 break;
193         case 15:
194                 mask = 0x7F;
195                 break;
196         default:
197                 dasm_int_error("disasm_gpr_operand invalid arch");
198         }
199
200         ret = xmalloc(5);
201         snprintf(ret, 5, "r%u", (operand & mask));
202
203         return ret;
204 }
205
206 static void disasm_raw_operand(struct statement *stmt,
207                                int oper_idx,
208                                int out_idx)
209 {
210         unsigned int operand = stmt->u.insn.bin->operands[oper_idx];
211
212         stmt->u.insn.operands[out_idx] = gen_raw_code(operand);
213 }
214
215 static void disasm_std_operand(struct statement *stmt,
216                                int oper_idx,
217                                int out_idx)
218 {
219         unsigned int operand = stmt->u.insn.bin->operands[oper_idx];
220
221         switch (cmdargs.arch) {
222         case 5:
223                 if (!(operand & 0x800)) {
224                         stmt->u.insn.operands[out_idx] = disasm_mem_operand(operand);
225                         return;
226                 } else if ((operand & 0xC00) == 0xC00) { 
227                         stmt->u.insn.operands[out_idx] = disasm_imm_operand(operand);
228                         return;
229                 } else if ((operand & 0xFC0) == 0xBC0) {
230                         stmt->u.insn.operands[out_idx] = disasm_gpr_operand(operand);
231                         return;
232                 } else if ((operand & 0xE00) == 0x800) {
233                         stmt->u.insn.operands[out_idx] = disasm_spr_operand(operand);
234                         return;
235                 } else if ((operand & 0xE00) == 0xA00) {
236                         stmt->u.insn.operands[out_idx] = disasm_indirect_mem_operand(operand);
237                         return;
238                 }
239                 break;
240         case 15:
241                 if (!(operand & 0x1000)) {
242                         stmt->u.insn.operands[out_idx] = disasm_mem_operand(operand);
243                         return;
244                 } else if ((operand & 0x1800) == 0x1800) { 
245                         stmt->u.insn.operands[out_idx] = disasm_imm_operand(operand);
246                         return;
247                 } else if ((operand & 0x1F80) == 0x1780) {
248                         stmt->u.insn.operands[out_idx] = disasm_gpr_operand(operand);
249                         return;
250                 } else if ((operand & 0x1C00) == 0x1000) {
251                         stmt->u.insn.operands[out_idx] = disasm_spr_operand(operand);
252                         return;
253                 } else if ((operand & 0x1C00) == 0x1400) {
254                         stmt->u.insn.operands[out_idx] = disasm_indirect_mem_operand(operand);
255                         return;
256                 }
257                 break;
258         default:
259                 dasm_int_error("disasm_std_operand invalid arch");
260         }
261         /* No luck. Disassemble to raw operand. */
262         disasm_raw_operand(stmt, oper_idx, out_idx);
263 }
264
265 static void disasm_opcode_raw(struct disassembler_context *ctx,
266                               struct statement *stmt,
267                               int raw_operands)
268 {
269         stmt->u.insn.name = gen_raw_code(stmt->u.insn.bin->opcode);
270         if (raw_operands) {
271                 disasm_raw_operand(stmt, 0, 0);
272                 disasm_raw_operand(stmt, 1, 1);
273                 disasm_raw_operand(stmt, 2, 2);
274         } else {
275                 disasm_std_operand(stmt, 0, 0);
276                 disasm_std_operand(stmt, 1, 1);
277                 disasm_std_operand(stmt, 2, 2);
278         }
279 }
280
281 static void disasm_constant_opcodes(struct disassembler_context *ctx,
282                                     struct statement *stmt)
283 {
284         struct bin_instruction *bin = stmt->u.insn.bin;
285
286         switch (bin->opcode) {
287         case 0x1C0:
288                 stmt->u.insn.name = "add";
289                 disasm_std_operand(stmt, 0, 0);
290                 disasm_std_operand(stmt, 1, 1);
291                 disasm_std_operand(stmt, 2, 2);
292                 break;
293         case 0x1C2:
294                 stmt->u.insn.name = "add.";
295                 disasm_std_operand(stmt, 0, 0);
296                 disasm_std_operand(stmt, 1, 1);
297                 disasm_std_operand(stmt, 2, 2);
298                 break;
299         case 0x1C1:
300                 stmt->u.insn.name = "addc";
301                 disasm_std_operand(stmt, 0, 0);
302                 disasm_std_operand(stmt, 1, 1);
303                 disasm_std_operand(stmt, 2, 2);
304                 break;
305         case 0x1C3:
306                 stmt->u.insn.name = "addc.";
307                 disasm_std_operand(stmt, 0, 0);
308                 disasm_std_operand(stmt, 1, 1);
309                 disasm_std_operand(stmt, 2, 2);
310                 break;
311         case 0x1D0:
312                 stmt->u.insn.name = "sub";
313                 disasm_std_operand(stmt, 0, 0);
314                 disasm_std_operand(stmt, 1, 1);
315                 disasm_std_operand(stmt, 2, 2);
316                 break;
317         case 0x1D2:
318                 stmt->u.insn.name = "sub.";
319                 disasm_std_operand(stmt, 0, 0);
320                 disasm_std_operand(stmt, 1, 1);
321                 disasm_std_operand(stmt, 2, 2);
322                 break;
323         case 0x1D1:
324                 stmt->u.insn.name = "subc";
325                 disasm_std_operand(stmt, 0, 0);
326                 disasm_std_operand(stmt, 1, 1);
327                 disasm_std_operand(stmt, 2, 2);
328                 break;
329         case 0x1D3:
330                 stmt->u.insn.name = "subc.";
331                 disasm_std_operand(stmt, 0, 0);
332                 disasm_std_operand(stmt, 1, 1);
333                 disasm_std_operand(stmt, 2, 2);
334                 break;
335         case 0x130:
336                 stmt->u.insn.name = "sra";
337                 disasm_std_operand(stmt, 0, 0);
338                 disasm_std_operand(stmt, 1, 1);
339                 disasm_std_operand(stmt, 2, 2);
340                 break;
341         case 0x160:
342                 stmt->u.insn.name = "or";
343                 disasm_std_operand(stmt, 0, 0);
344                 disasm_std_operand(stmt, 1, 1);
345                 disasm_std_operand(stmt, 2, 2);
346                 break;
347         case 0x140:
348                 stmt->u.insn.name = "and";
349                 disasm_std_operand(stmt, 0, 0);
350                 disasm_std_operand(stmt, 1, 1);
351                 disasm_std_operand(stmt, 2, 2);
352                 break;
353         case 0x170:
354                 stmt->u.insn.name = "xor";
355                 disasm_std_operand(stmt, 0, 0);
356                 disasm_std_operand(stmt, 1, 1);
357                 disasm_std_operand(stmt, 2, 2);
358                 break;
359         case 0x120:
360                 stmt->u.insn.name = "sr";
361                 disasm_std_operand(stmt, 0, 0);
362                 disasm_std_operand(stmt, 1, 1);
363                 disasm_std_operand(stmt, 2, 2);
364                 break;
365         case 0x110:
366                 stmt->u.insn.name = "sl";
367                 disasm_std_operand(stmt, 0, 0);
368                 disasm_std_operand(stmt, 1, 1);
369                 disasm_std_operand(stmt, 2, 2);
370                 break;
371         case 0x1A0:
372                 stmt->u.insn.name = "rl";
373                 disasm_std_operand(stmt, 0, 0);
374                 disasm_std_operand(stmt, 1, 1);
375                 disasm_std_operand(stmt, 2, 2);
376                 break;
377         case 0x1B0:
378                 stmt->u.insn.name = "rr";
379                 disasm_std_operand(stmt, 0, 0);
380                 disasm_std_operand(stmt, 1, 1);
381                 disasm_std_operand(stmt, 2, 2);
382                 break;
383         case 0x150:
384                 stmt->u.insn.name = "nand";
385                 disasm_std_operand(stmt, 0, 0);
386                 disasm_std_operand(stmt, 1, 1);
387                 disasm_std_operand(stmt, 2, 2);
388                 break;
389         case 0x040:
390                 stmt->u.insn.name = "jand";
391                 stmt->u.insn.is_labelref = 2;
392                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
393                 disasm_std_operand(stmt, 0, 0);
394                 disasm_std_operand(stmt, 1, 1);
395                 break;
396         case (0x040 | 0x1):
397                 stmt->u.insn.name = "jnand";
398                 stmt->u.insn.is_labelref = 2;
399                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
400                 disasm_std_operand(stmt, 0, 0);
401                 disasm_std_operand(stmt, 1, 1);
402                 break;
403         case 0x050:
404                 stmt->u.insn.name = "js";
405                 stmt->u.insn.is_labelref = 2;
406                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
407                 disasm_std_operand(stmt, 0, 0);
408                 disasm_std_operand(stmt, 1, 1);
409                 break;
410         case (0x050 | 0x1):
411                 stmt->u.insn.name = "jns";
412                 stmt->u.insn.is_labelref = 2;
413                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
414                 disasm_std_operand(stmt, 0, 0);
415                 disasm_std_operand(stmt, 1, 1);
416                 break;
417         case 0x0D0:
418                 stmt->u.insn.name = "je";
419                 stmt->u.insn.is_labelref = 2;
420                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
421                 disasm_std_operand(stmt, 0, 0);
422                 disasm_std_operand(stmt, 1, 1);
423                 break;
424         case (0x0D0 | 0x1):
425                 stmt->u.insn.name = "jne";
426                 stmt->u.insn.is_labelref = 2;
427                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
428                 disasm_std_operand(stmt, 0, 0);
429                 disasm_std_operand(stmt, 1, 1);
430                 break;
431         case 0x0D2:
432                 stmt->u.insn.name = "jls";
433                 stmt->u.insn.is_labelref = 2;
434                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
435                 disasm_std_operand(stmt, 0, 0);
436                 disasm_std_operand(stmt, 1, 1);
437                 break;
438         case (0x0D2 | 0x1):
439                 stmt->u.insn.name = "jges";
440                 stmt->u.insn.is_labelref = 2;
441                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
442                 disasm_std_operand(stmt, 0, 0);
443                 disasm_std_operand(stmt, 1, 1);
444                 break;
445         case 0x0D4:
446                 stmt->u.insn.name = "jgs";
447                 stmt->u.insn.is_labelref = 2;
448                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
449                 disasm_std_operand(stmt, 0, 0);
450                 disasm_std_operand(stmt, 1, 1);
451                 break;
452         case (0x0D4 | 0x1):
453                 stmt->u.insn.name = "jles";
454                 stmt->u.insn.is_labelref = 2;
455                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
456                 disasm_std_operand(stmt, 0, 0);
457                 disasm_std_operand(stmt, 1, 1);
458                 break;
459         case 0x0D6:
460                 stmt->u.insn.name = "@D6"; /* FIXME */
461                 stmt->u.insn.is_labelref = 2;
462                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
463                 disasm_std_operand(stmt, 0, 0);
464                 disasm_std_operand(stmt, 1, 1);
465                 break;
466         case (0x0D6 | 0x1):
467                 stmt->u.insn.name = "@D7"; /* FIXME */
468                 stmt->u.insn.is_labelref = 2;
469                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
470                 disasm_std_operand(stmt, 0, 0);
471                 disasm_std_operand(stmt, 1, 1);
472         case 0x0D8:
473                 stmt->u.insn.name = "@D8"; /* FIXME */
474                 stmt->u.insn.is_labelref = 2;
475                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
476                 disasm_std_operand(stmt, 0, 0);
477                 disasm_std_operand(stmt, 1, 1);
478                 break;
479         case (0x0D8 | 0x1):
480                 stmt->u.insn.name = "@D9"; /* FIXME */
481                 stmt->u.insn.is_labelref = 2;
482                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
483                 disasm_std_operand(stmt, 0, 0);
484                 disasm_std_operand(stmt, 1, 1);
485                 break;
486         case 0x0DA:
487                 stmt->u.insn.name = "jl";
488                 stmt->u.insn.is_labelref = 2;
489                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
490                 disasm_std_operand(stmt, 0, 0);
491                 disasm_std_operand(stmt, 1, 1);
492                 break;
493         case (0x0DA | 0x1):
494                 stmt->u.insn.name = "jge";
495                 stmt->u.insn.is_labelref = 2;
496                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
497                 disasm_std_operand(stmt, 0, 0);
498                 disasm_std_operand(stmt, 1, 1);
499                 break;
500         case 0x0DC:
501                 stmt->u.insn.name = "jg";
502                 stmt->u.insn.is_labelref = 2;
503                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
504                 disasm_std_operand(stmt, 0, 0);
505                 disasm_std_operand(stmt, 1, 1);
506                 break;
507         case (0x0DC | 0x1):
508                 stmt->u.insn.name = "jle";
509                 stmt->u.insn.is_labelref = 2;
510                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
511                 disasm_std_operand(stmt, 0, 0);
512                 disasm_std_operand(stmt, 1, 1);
513                 break;
514         case 0x002: {
515                 char *str;
516
517                 switch (cmdargs.arch) {
518                 case 5:
519                         stmt->u.insn.name = "call";
520                         stmt->u.insn.is_labelref = 1;
521                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
522                         str = xmalloc(4);
523                         snprintf(str, 4, "lr%u", stmt->u.insn.bin->operands[0]);
524                         stmt->u.insn.operands[0] = str;
525                         break;
526                 case 15:
527                         //FIXME: This opcode is different on r15. Decode raw for now.
528                         disasm_opcode_raw(ctx, stmt, 1);
529                         break;
530                 }
531                 break;
532         }
533         case 0x003: {
534                 char *str;
535
536                 stmt->u.insn.name = "ret";
537                 str = xmalloc(4);
538                 snprintf(str, 4, "lr%u", stmt->u.insn.bin->operands[0]);
539                 stmt->u.insn.operands[0] = str;
540                 str = xmalloc(4);
541                 snprintf(str, 4, "lr%u", stmt->u.insn.bin->operands[2]);
542                 stmt->u.insn.operands[2] = str;
543                 break;
544         }
545         case 0x004: {
546                 if (cmdargs.arch != 15) {
547                         dasm_error("arch 15 'calls' instruction found in arch %d binary",
548                                    cmdargs.arch);
549                 }
550                 stmt->u.insn.name = "calls";
551                 stmt->u.insn.is_labelref = 0;
552                 stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
553                 if (stmt->u.insn.bin->operands[0] != 0x1780 ||
554                     stmt->u.insn.bin->operands[1] != 0x1780)
555                         dasm_warn("r15 calls: Invalid first or second argument");
556                 break;
557         }
558         case 0x005: {
559                 if (cmdargs.arch != 15) {
560                         dasm_error("arch 15 'rets' instruction found in arch %d binary",
561                                    cmdargs.arch);
562                 }
563                 stmt->u.insn.name = "rets";
564                 if (stmt->u.insn.bin->operands[0] != 0x1780 ||
565                     stmt->u.insn.bin->operands[1] != 0x1780 ||
566                     stmt->u.insn.bin->operands[2] != 0)
567                         dasm_warn("r15 rets: Invalid argument(s)");
568                 break;
569         }
570         case 0x1E0: {
571                 unsigned int flags, mask;
572
573                 switch (cmdargs.arch) {
574                 case 5:
575                         mask = 0x3FF;
576                         break;
577                 case 15:
578                         mask = 0x7FF;
579                         break;
580                 default:
581                         dasm_int_error("TKIP invalid arch");
582                 }
583
584                 flags = stmt->u.insn.bin->operands[1];
585                 switch (flags & mask) {
586                 case 0x1:
587                         stmt->u.insn.name = "tkiph";
588                         break;
589                 case (0x1 | 0x2):
590                         stmt->u.insn.name = "tkiphs";
591                         break;
592                 case 0x0:
593                         stmt->u.insn.name = "tkipl";
594                         break;
595                 case (0x0 | 0x2):
596                         stmt->u.insn.name = "tkipls";
597                         break;
598                 default:
599                         dasm_error("Invalid TKIP flags %X", flags);
600                 }
601                 disasm_std_operand(stmt, 0, 0);
602                 disasm_std_operand(stmt, 2, 2);
603                 break;
604         }
605         case 0x001: {
606                 unsigned int mask;
607
608                 stmt->u.insn.name = "nap";
609                 switch (cmdargs.arch) {
610                 case 5:
611                         mask = 0xBC0;
612                         break;
613                 case 15:
614                         mask = 0x1780;
615                         break;
616                 default:
617                         dasm_int_error("NAP invalid arch");
618                 }
619                 if (stmt->u.insn.bin->operands[0] != mask) {
620                         dasm_warn("NAP: invalid first argument 0x%04X\n",
621                                   stmt->u.insn.bin->operands[0]);
622                 }
623                 if (stmt->u.insn.bin->operands[1] != mask) {
624                         dasm_warn("NAP: invalid second argument 0x%04X\n",
625                                   stmt->u.insn.bin->operands[1]);
626                 }
627                 if (stmt->u.insn.bin->operands[2] != 0) {
628                         dasm_warn("NAP: invalid third argument 0x%04X\n",
629                                   stmt->u.insn.bin->operands[2]);
630                 }
631                 break;
632         }
633         case 0x000:
634                 disasm_opcode_raw(ctx, stmt, 1);
635                 break;
636         default:
637                 disasm_opcode_raw(ctx, stmt, (cmdargs.unknown_decode == 0));
638                 break;
639         }
640 }
641
642 static void disasm_opcodes(struct disassembler_context *ctx)
643 {
644         struct bin_instruction *bin;
645         size_t i;
646         struct statement *stmt;
647         char *str;
648
649         for (i = 0; i < ctx->nr_insns; i++) {
650                 bin = &(ctx->code[i]);
651
652                 stmt = xmalloc(sizeof(struct statement));
653                 stmt->type = STMT_INSN;
654                 INIT_LIST_HEAD(&stmt->list);
655                 stmt->u.insn.bin = bin;
656                 stmt->u.insn.is_labelref = -1;
657
658                 switch (bin->opcode & 0xF00) {
659                 case 0x200:
660                         stmt->u.insn.name = "srx";
661
662                         str = xmalloc(3);
663                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
664                         stmt->u.insn.operands[0] = str;
665                         str = xmalloc(3);
666                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
667                         stmt->u.insn.operands[1] = str;
668
669                         disasm_std_operand(stmt, 0, 2);
670                         disasm_std_operand(stmt, 1, 3);
671                         disasm_std_operand(stmt, 2, 4);
672                         break;
673                 case 0x300:
674                         stmt->u.insn.name = "orx";
675
676                         str = xmalloc(3);
677                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
678                         stmt->u.insn.operands[0] = str;
679                         str = xmalloc(3);
680                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
681                         stmt->u.insn.operands[1] = str;
682
683                         disasm_std_operand(stmt, 0, 2);
684                         disasm_std_operand(stmt, 1, 3);
685                         disasm_std_operand(stmt, 2, 4);
686                         break;
687                 case 0x400:
688                         stmt->u.insn.name = "jzx";
689
690                         str = xmalloc(3);
691                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
692                         stmt->u.insn.operands[0] = str;
693                         str = xmalloc(3);
694                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
695                         stmt->u.insn.operands[1] = str;
696
697                         disasm_std_operand(stmt, 0, 2);
698                         disasm_std_operand(stmt, 1, 3);
699                         stmt->u.insn.is_labelref = 4;
700                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
701                         break;
702                 case 0x500:
703                         stmt->u.insn.name = "jnzx";
704
705                         str = xmalloc(3);
706                         snprintf(str, 3, "%d", (bin->opcode & 0x0F0) >> 4);
707                         stmt->u.insn.operands[0] = str;
708                         str = xmalloc(3);
709                         snprintf(str, 3, "%d", (bin->opcode & 0x00F));
710                         stmt->u.insn.operands[1] = str;
711
712                         disasm_std_operand(stmt, 0, 2);
713                         disasm_std_operand(stmt, 1, 3);
714                         stmt->u.insn.is_labelref = 4;
715                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
716                         break;
717                 case 0x600:
718                         stmt->u.insn.name = "jnext";
719
720                         str = xmalloc(5);
721                         snprintf(str, 5, "0x%02X", (bin->opcode & 0x0FF));
722                         stmt->u.insn.operands[0] = str;
723
724                         /* We don't disassemble the first and second operand, as
725                          * that always is a dummy r0 operand.
726                          * disasm_std_operand(stmt, 0, 1);
727                          * disasm_std_operand(stmt, 1, 2);
728                          * stmt->u.insn.is_labelref = 3;
729                          */
730                         stmt->u.insn.is_labelref = 1;
731                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
732                         break;
733                 case 0x700:
734                         stmt->u.insn.name = "jext";
735
736                         str = xmalloc(5);
737                         snprintf(str, 5, "0x%02X", (bin->opcode & 0x0FF));
738                         stmt->u.insn.operands[0] = str;
739
740                         /* We don't disassemble the first and second operand, as
741                          * that always is a dummy r0 operand.
742                          * disasm_std_operand(stmt, 0, 1);
743                          * disasm_std_operand(stmt, 1, 2);
744                          * stmt->u.insn.is_labelref = 3;
745                          */
746                         stmt->u.insn.is_labelref = 1;
747                         stmt->u.insn.labeladdr = stmt->u.insn.bin->operands[2];
748                         break;
749                 default:
750                         disasm_constant_opcodes(ctx, stmt);
751                         break;
752                 }
753
754                 list_add_tail(&stmt->list, &ctx->stmt_list);
755         }
756 }
757
758 static struct statement * get_label_at(struct disassembler_context *ctx,
759                                        unsigned int addr)
760 {
761         unsigned int addrcnt = 0;
762         struct statement *stmt, *ret, *prev;
763
764         list_for_each_entry(stmt, &ctx->stmt_list, list) {
765                 if (stmt->type != STMT_INSN)
766                         continue;
767                 if (addrcnt == addr) {
768                         prev = list_entry(stmt->list.prev, struct statement, list);
769                         if (prev->type == STMT_LABEL)
770                                 return prev;
771                         ret = xmalloc(sizeof(struct statement));
772                         INIT_LIST_HEAD(&ret->list);
773                         ret->type = STMT_LABEL;
774                         list_add(&ret->list, &prev->list);
775
776                         return ret;
777                 }
778                 addrcnt++;
779         }
780
781         return NULL;
782 }
783
784 static void resolve_labels(struct disassembler_context *ctx)
785 {
786         struct statement *stmt;
787         struct statement *label;
788         struct statement *n;
789         unsigned int labeladdr;
790         unsigned int namecnt = 0;
791
792         /* Resolve label references */
793         list_for_each_entry_safe(stmt, n, &ctx->stmt_list, list) {
794                 if (stmt->type != STMT_INSN)
795                         continue;
796                 if (stmt->u.insn.is_labelref == -1)
797                         continue;
798                 labeladdr = stmt->u.insn.labeladdr;
799                 label = get_label_at(ctx, labeladdr);
800                 if (!label)
801                         dasm_error("Labeladdress %X out of bounds", labeladdr);
802                 stmt->u.insn.labelref = label;
803         }
804
805         /* Name the labels */
806         list_for_each_entry(stmt, &ctx->stmt_list, list) {
807                 if (stmt->type != STMT_LABEL)
808                         continue;
809                 stmt->u.label.name = xmalloc(20);
810                 snprintf(stmt->u.label.name, 20, "L%u", namecnt);
811                 namecnt++;
812         }
813 }
814
815 static void emit_asm(struct disassembler_context *ctx)
816 {
817         struct statement *stmt;
818         int first;
819         int err;
820         unsigned int i, addr = 0;
821
822         err = open_output_file();
823         if (err)
824                 exit(1);
825
826         fprintf(outfile, "%%arch %u\n", ctx->arch);
827         fprintf(outfile, "%%start entry\n\n");
828         fprintf(outfile, "entry:\n");
829         list_for_each_entry(stmt, &ctx->stmt_list, list) {
830                 switch (stmt->type) {
831                 case STMT_INSN:
832                         if (cmdargs.print_addresses)
833                                 fprintf(outfile, "/* %04X */", addr);
834                         fprintf(outfile, "\t%s", stmt->u.insn.name);
835                         first = 1;
836                         for (i = 0; i < ARRAY_SIZE(stmt->u.insn.operands); i++) {
837                                 if (!stmt->u.insn.operands[i] &&
838                                     (stmt->u.insn.is_labelref < 0 ||
839                                      (unsigned int)stmt->u.insn.is_labelref != i))
840                                         continue;
841                                 if (first)
842                                         fprintf(outfile, "\t");
843                                 if (!first)
844                                         fprintf(outfile, ", ");
845                                 first = 0;
846                                 if (stmt->u.insn.is_labelref >= 0 &&
847                                     (unsigned int)stmt->u.insn.is_labelref == i) {
848                                         fprintf(outfile, "%s",
849                                                 stmt->u.insn.labelref->u.label.name);
850                                 } else {
851                                         fprintf(outfile, "%s",
852                                                 stmt->u.insn.operands[i]);
853                                 }
854                         }
855                         fprintf(outfile, "\n");
856                         addr++;
857                         break;
858                 case STMT_LABEL:
859                         fprintf(outfile, "%s:\n", stmt->u.label.name);
860                         break;
861                 }
862         }
863
864         close_output_file();
865 }
866
867 static int read_input(struct disassembler_context *ctx)
868 {
869         size_t size = 0, pos = 0;
870         size_t ret;
871         struct bin_instruction *code = NULL;
872         unsigned char tmp[sizeof(uint64_t)];
873         uint64_t codeword;
874         struct fw_header hdr;
875         int err;
876
877         err = open_input_file();
878         if (err)
879                 goto error;
880
881         switch (cmdargs.informat) {
882         case FMT_RAW_LE32:
883         case FMT_RAW_BE32:
884                 /* Nothing */
885                 break;
886         case FMT_B43:
887                 ret = fread(&hdr, 1, sizeof(hdr), infile);
888                 if (ret != sizeof(hdr)) {
889                         fprintf(stderr, "Corrupt input file (no b43 header found)\n");
890                         goto err_close;
891                 }
892                 if (hdr.type != FW_TYPE_UCODE) {
893                         fprintf(stderr, "Corrupt input file. Not a b43 microcode image.\n");
894                         goto err_close;
895                 }
896                 if (hdr.ver != FW_HDR_VER) {
897                         fprintf(stderr, "Invalid input file header version.\n");
898                         goto err_close;
899                 }
900                 break;
901         }
902
903         while (1) {
904                 if (pos >= size) {
905                         size += 512;
906                         code = xrealloc(code, size * sizeof(struct bin_instruction));
907                 }
908                 ret = fread(tmp, 1, sizeof(uint64_t), infile);
909                 if (!ret)
910                         break;
911                 if (ret != sizeof(uint64_t)) {
912                         fprintf(stderr, "Corrupt input file (not 8 byte aligned)\n");
913                         goto err_free_code;
914                 }
915
916                 switch (cmdargs.informat) {
917                 case FMT_B43:
918                 case FMT_RAW_BE32:
919                         codeword = 0;
920                         codeword |= ((uint64_t)tmp[0]) << 56;
921                         codeword |= ((uint64_t)tmp[1]) << 48;
922                         codeword |= ((uint64_t)tmp[2]) << 40;
923                         codeword |= ((uint64_t)tmp[3]) << 32;
924                         codeword |= ((uint64_t)tmp[4]) << 24;
925                         codeword |= ((uint64_t)tmp[5]) << 16;
926                         codeword |= ((uint64_t)tmp[6]) << 8;
927                         codeword |= ((uint64_t)tmp[7]);
928                         codeword = ((codeword & (uint64_t)0xFFFFFFFF00000000ULL) >> 32) |
929                                    ((codeword & (uint64_t)0x00000000FFFFFFFFULL) << 32);
930                         break;
931                 case FMT_RAW_LE32:
932                         codeword = 0;
933                         codeword |= ((uint64_t)tmp[7]) << 56;
934                         codeword |= ((uint64_t)tmp[6]) << 48;
935                         codeword |= ((uint64_t)tmp[5]) << 40;
936                         codeword |= ((uint64_t)tmp[4]) << 32;
937                         codeword |= ((uint64_t)tmp[3]) << 24;
938                         codeword |= ((uint64_t)tmp[2]) << 16;
939                         codeword |= ((uint64_t)tmp[1]) << 8;
940                         codeword |= ((uint64_t)tmp[0]);
941                         break;
942                 }
943
944                 switch (cmdargs.arch) {
945                 case 5:
946                         if (codeword >> 48) {
947                                 fprintf(stderr, "Instruction format error at 0x%X (upper not clear). "
948                                         "Wrong input format or architecture?\n", (unsigned int)pos);
949                                 goto err_free_code;
950                         }
951                         code[pos].opcode = (codeword >> 36) & 0xFFF;
952                         code[pos].operands[2] = codeword & 0xFFF;
953                         code[pos].operands[1] = (codeword >> 12) & 0xFFF;
954                         code[pos].operands[0] = (codeword >> 24) & 0xFFF;
955                         break;
956                 case 15:
957                         if (codeword >> 51) {
958                                 fprintf(stderr, "Instruction format error at 0x%X (upper not clear). "
959                                         "Wrong input format or architecture?\n", (unsigned int)pos);
960                                 goto err_free_code;
961                         }
962                         code[pos].opcode = (codeword >> 39) & 0xFFF;
963                         code[pos].operands[2] = codeword & 0x1FFF;
964                         code[pos].operands[1] = (codeword >> 13) & 0x1FFF;
965                         code[pos].operands[0] = (codeword >> 26) & 0x1FFF;
966                         break;
967                 default:
968                         fprintf(stderr, "Internal error: read_input unknown arch %u\n",
969                                 cmdargs.arch);
970                         goto err_free_code;
971                 }
972
973                 pos++;
974         }
975
976         ctx->code = code;
977         ctx->nr_insns = pos;
978
979         close_input_file();
980
981         return 0;
982
983 err_free_code:
984         free(code);
985 err_close:
986         close_input_file();
987 error:
988         return -1;
989 }
990
991 static void disassemble(void)
992 {
993         struct disassembler_context ctx;
994         int err;
995
996         memset(&ctx, 0, sizeof(ctx));
997         INIT_LIST_HEAD(&ctx.stmt_list);
998         ctx.arch = cmdargs.arch;
999
1000         err = read_input(&ctx);
1001         if (err)
1002                 exit(1);
1003         disasm_opcodes(&ctx);
1004         resolve_labels(&ctx);
1005         emit_asm(&ctx);
1006 }
1007
1008 int main(int argc, char **argv)
1009 {
1010         int err, res = 1;
1011
1012         err = parse_args(argc, argv);
1013         if (err < 0)
1014                 goto out;
1015         if (err > 0) {
1016                 res = 0;
1017                 goto out;
1018         }
1019         disassemble();
1020         res = 0;
1021 out:
1022         /* Lazyman simply leaks all allocated memory. */
1023         return res;
1024 }