ROSE  0.10.13.0
ModulesX86.h
1 #ifndef ROSE_Partitioner2_ModulesX86_H
2 #define ROSE_Partitioner2_ModulesX86_H
3 
4 #include <rosePublicConfig.h>
5 #ifdef ROSE_BUILD_BINARY_ANALYSIS_SUPPORT
6 
7 #include <Partitioner2/Modules.h>
8 #include <Partitioner2/Thunk.h>
9 
10 namespace Rose {
11 namespace BinaryAnalysis {
12 namespace Partitioner2 {
13 
15 namespace ModulesX86 {
16 
29 protected:
30  Function::Ptr function_;
31 public:
32  static Ptr instance() { return Ptr(new MatchStandardPrologue); }
33  virtual std::vector<Function::Ptr> functions() const ROSE_OVERRIDE { return std::vector<Function::Ptr>(1, function_); }
34  virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE;
35 };
36 
46 public:
47  static Ptr instance() { return Ptr(new MatchHotPatchPrologue); }
48  virtual std::vector<Function::Ptr> functions() const ROSE_OVERRIDE { return std::vector<Function::Ptr>(1, function_); }
49  virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE;
50 };
51 
54 protected:
55  Function::Ptr function_;
56 public:
57  static Ptr instance() { return Ptr(new MatchAbbreviatedPrologue); }
58  virtual std::vector<Function::Ptr> functions() const ROSE_OVERRIDE { return std::vector<Function::Ptr>(1, function_); }
59  virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE;
60 };
61 
64 protected:
65  Function::Ptr function_;
66 public:
67  static Ptr instance() { return Ptr(new MatchEnterPrologue); }
68  virtual std::vector<Function::Ptr> functions() const ROSE_OVERRIDE { return std::vector<Function::Ptr>(1, function_); }
69  virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE;
70 };
71 
74 protected:
75  Function::Ptr function_;
76 public:
77  static Ptr instance() { return Ptr(new MatchRetPadPush); }
78  virtual std::vector<Function::Ptr> functions() const ROSE_OVERRIDE { return std::vector<Function::Ptr>(1, function_); }
79  virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE;
80 };
81 
89 public:
90  static Ptr instance() { return Ptr(new FunctionReturnDetector); }
91  virtual bool operator()(bool chain, const Args&) ROSE_OVERRIDE;
92 };
93 
99 public:
100  static Ptr instance() { return Ptr(new SwitchSuccessors); }
101  virtual bool operator()(bool chain, const Args&) ROSE_OVERRIDE;
102 };
103 
106 
110 Sawyer::Optional<rose_addr_t> matchJmpConst(const Partitioner&, SgAsmX86Instruction*);
111 
113 bool matchLeaCxMemBpConst(const Partitioner&, SgAsmX86Instruction*);
114 
116 bool matchJmpMem(const Partitioner&, SgAsmX86Instruction*);
117 
119 bool matchMovBpSp(const Partitioner&, SgAsmX86Instruction*);
120 
122 bool matchMovDiDi(const Partitioner&, SgAsmX86Instruction*);
123 
125 bool matchPushBp(const Partitioner&, SgAsmX86Instruction*);
126 
128 bool matchPushSi(const Partitioner&, SgAsmX86Instruction*);
129 
145 std::vector<rose_addr_t> scanCodeAddressTable(const Partitioner&, AddressInterval &tableLimits /*in,out*/,
146  const AddressInterval &targetLimits, size_t tableEntrySize,
147  Sawyer::Optional<rose_addr_t> probableStartVa = Sawyer::Nothing(),
148  size_t nSkippable = 0);
149 
160 Sawyer::Optional<rose_addr_t> findTableBase(SgAsmExpression*);
161 
162 
163 } // namespace
164 } // namespace
165 } // namespace
166 } // namespace
167 
168 #endif
169 #endif
Match RET followed by PUSH with intervening no-op padding.
Definition: ModulesX86.h:73
Basic block callback to detect "switch" statements.
Definition: ModulesX86.h:98
virtual std::vector< Function::Ptr > functions() const ROSE_OVERRIDE
Returns the function(s) for the previous successful match.
Definition: ModulesX86.h:78
virtual std::vector< Function::Ptr > functions() const ROSE_OVERRIDE
Returns the function(s) for the previous successful match.
Definition: ModulesX86.h:48
Base class for adjusting basic blocks during discovery.
Definition: Modules.h:43
Base class for matching function prologues.
Definition: Modules.h:112
std::vector< rose_addr_t > scanCodeAddressTable(const Partitioner &, AddressInterval &tableLimits, const AddressInterval &targetLimits, size_t tableEntrySize, Sawyer::Optional< rose_addr_t > probableStartVa=Sawyer::Nothing(), size_t nSkippable=0)
Reads a table of code addresses.
Sawyer::Optional< rose_addr_t > findTableBase(SgAsmExpression *)
Try to match a base+offset expression.
bool matchMovDiDi(const Partitioner &, SgAsmX86Instruction *)
Matches "MOV EDI, EDI" or variant.
STL namespace.
virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE
Attempt to match an instruction pattern.
virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE
Attempt to match an instruction pattern.
bool matchPushBp(const Partitioner &, SgAsmX86Instruction *)
Matches "PUSH EBP" or variant.
Main namespace for the ROSE library.
Basic block callback to detect function returns.
Definition: ModulesX86.h:88
bool matchLeaCxMemBpConst(const Partitioner &, SgAsmX86Instruction *)
Matches "LEA ECX, [EBP + constant]" or variant.
Name space for the entire library.
virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE
Attempt to match an instruction pattern.
virtual bool operator()(bool chain, const Args &) ROSE_OVERRIDE
Callback method.
Matches an x86 MOV EDI,EDI; PUSH ESI function prologe.
Definition: ModulesX86.h:53
Sawyer::Optional< rose_addr_t > matchJmpConst(const Partitioner &, SgAsmX86Instruction *)
Matches "JMP constant".
bool matchPushSi(const Partitioner &, SgAsmX86Instruction *)
Matches "PUSH SI" or variant.
Represents one Intel x86 machine instruction.
Base class for expressions.
bool matchMovBpSp(const Partitioner &, SgAsmX86Instruction *)
Matches "MOV EBP, ESP" or variant.
virtual std::vector< Function::Ptr > functions() const ROSE_OVERRIDE
Returns the function(s) for the previous successful match.
Definition: ModulesX86.h:33
virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE
Attempt to match an instruction pattern.
bool matchEnterAnyZero(const Partitioner &, SgAsmX86Instruction *)
Matches "ENTER x, 0".
Sawyer::SharedPointer< FunctionPrologueMatcher > Ptr
Shared-ownership pointer to a FunctionPrologueMatcher.
Definition: Modules.h:115
virtual bool match(const Partitioner &partitioner, rose_addr_t anchor) ROSE_OVERRIDE
Attempt to match an instruction pattern.
virtual std::vector< Function::Ptr > functions() const ROSE_OVERRIDE
Returns the function(s) for the previous successful match.
Definition: ModulesX86.h:68
Sawyer::SharedPointer< BasicBlockCallback > Ptr
Shared-ownership pointer to a BasicBlockCallback.
Definition: Modules.h:46
Partitions instructions into basic blocks and functions.
Definition: Partitioner.h:321
virtual std::vector< Function::Ptr > functions() const ROSE_OVERRIDE
Returns the function(s) for the previous successful match.
Definition: ModulesX86.h:58
bool matchJmpMem(const Partitioner &, SgAsmX86Instruction *)
Matches "JMP [address]" or variant.
Matches an x86 function prologue with hot patch.
Definition: ModulesX86.h:45