#define OP_LOOKUPSWITCH 512
#define OP_NEED_ACTIVATION 1024
#define OP_STACK_ARGS2 2048
+#define OP_INTERNAL 32768
/* 2 = u30 index into multiname
m = u30 index into method
{0x57, "newactivation", "", 0, 1, 0, OP_NEED_ACTIVATION},
{0x56, "newarray", "n", 0, 1, 0, OP_STACK_ARGS},
{0x5a, "newcatch", "u", 0, 1, 0, 0}, //u = index into exception_info
-#define OP_NEWCLASS 0x58
{0x58, "newclass", "c", -1, 1, 0, 0}, //c = index into class_info
-#define OP_NEWFUNCTION 0x40
{0x40, "newfunction", "m", 0, 1, 0, 0}, //i = index into method_info
{0x55, "newobject", "n", 0, 1, 0, OP_STACK_ARGS2},
{0x1e, "nextname", "", -2, 1, 0, 0},
{0x03, "throw", "", -1, 0, 0, OP_THROW},
{0x95, "typeof", "", -1, 1, 0, 0},
{0xa7, "urshift", "", -2, 1, 0, 0},
+
+/* opcodes not documented, but seen in the wild */
+//0x53: seen in builtin.abc
+{0x53, "applytype", "n", -1, 1, 0, OP_STACK_ARGS},
+
+/* dummy instructions. Warning: these are not actually supported by flash */
+{0xfc, "__rethrow__", "", 0, 0, 0, OP_THROW|OP_INTERNAL},
+{0xfd, "__fallthrough__", "s", 0, 0, 0, OP_INTERNAL},
+{0xfe, "__continue__", "s", 0, 0, 0, OP_RETURN|OP_INTERNAL},
+{0xff, "__break__", "s", 0, 0, 0, OP_RETURN|OP_INTERNAL},
};
static U8 op2index[256] = {254};
opcode_t*op = opcode_get(opcode);
if(!op) {
fprintf(stderr, "Can't parse opcode %02x\n", opcode);
- return head;
+ continue;
}
//printf("%s\n", op->name);fflush(stdout);
NEW(code_t,c);
int j = swf_GetS24(tag);
data = (void*)(ptroff_t)j;
} else if(*p == 's') { // string
- data = strdup((char*)pool_lookup_string(pool, swf_GetU30(tag)));
+ string_t s = pool_lookup_string2(pool, swf_GetU30(tag));
+ data = string_dup3(&s);
} else if(*p == 'D') { // debug
/*type, usually 1*/
U8 type = swf_GetU8(tag);
free(codelookup);
}
-code_t*code_find_start(code_t*c)
-{
- while(c && c->prev)
- c=c->prev;
- return c;
-}
-
void code_free(code_t*c)
{
- c = code_find_start(c);
+ c = code_start(c);
while(c) {
code_t*next = c->next;
opcode_t*op = opcode_get(c->opcode);
swf_SetU8(tag, c->opcode);
len++;
+ if(op->flags & OP_INTERNAL) {
+ if(c->opcode == OPCODE___BREAK__ ||
+ c->opcode == OPCODE___CONTINUE__) {
+ fprintf(stderr, "Unresolved %s\n", op->name);
+ } else {
+ fprintf(stderr, "Error: writing undefined internal opcode %s\n", op->name);
+ }
+ }
+
while(*p) {
void*data = c->data[pos++];
assert(pos<=2);
skip = (c->branch->pos) - c->pos - 4;
len += swf_SetS24(tag, skip);
} else if(*p == 's') { // string
- int index = pool_register_string(pool, data);
+ int index = pool_register_string2(pool, (string_t*)data);
len += swf_SetU30(tag, index);
} else if(*p == 'D') { // debug statement
if(tag)
void code_write(TAG*tag, code_t*code, pool_t*pool, abc_file_t*file)
{
- code = code_find_start(code);
+ code = code_start(code);
int pos = 0;
int length = 0;
code_t*c = code;
int stackpos;
int scopepos;
code_t*code;
- char seen;
+ char flags;
+ char error;
} stackpos_t;
typedef struct {
stats->maxlocal = reg+1;
}
+#define FLAG_SEEN 1
+#define FLAG_ERROR 2
+
static void dumpstack(currentstats_t*stats)
{
int t;
for(t=0;t<stats->num;t++) {
code_t*c = stats->stack[t].code;
opcode_t*op = opcode_get(c->opcode);
- printf("%5d) %c %d:%d %s", t, stats->stack[t].seen?'x':'|',
+ printf("%5d) %c %d:%d %s", t, (stats->stack[t].flags&FLAG_SEEN)?'x':'|',
stats->stack[t].stackpos,
stats->stack[t].scopepos,
op->name);
static char callcode(currentstats_t*stats, int pos, int stack, int scope)
{
while(pos<stats->num) {
- if(stats->stack[pos].seen) {
+ if(stats->stack[pos].flags&FLAG_SEEN) {
if(stats->stack[pos].stackpos != stack ||
stats->stack[pos].scopepos != scope) {
//dumpstack(stats);
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "Stack mismatch at pos %d\n", pos);
fprintf(stderr, "Should be: %d:%d, is: %d:%d\n", stack, scope,
stats->stack[pos].stackpos, stats->stack[pos].scopepos);
return 1;
}
- stats->stack[pos].seen = 1;
+ stats->stack[pos].flags |= FLAG_SEEN;
stats->stack[pos].stackpos = stack;
stats->stack[pos].scopepos = scope;
stack += stack_minus(c);
if(stack<0) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "error: stack underflow at %d (%s)\n", pos, op->name);
/* if we would do true verification (if we would be a vm), this is
if(op->flags & OP_NEED_ACTIVATION)
stats->flags |= FLAGS_ACTIVATION;
- if(c->opcode == OP_NEWCLASS) {
+ if(c->opcode == OPCODE_NEWCLASS) {
abc_class_t*cls = (abc_class_t*)(c->data[0]);
if(scope > cls->init_scope_depth)
cls->init_scope_depth = scope;
}
- if(c->opcode == OP_NEWFUNCTION) {
+ if(c->opcode == OPCODE_NEWFUNCTION) {
abc_method_t*m = (abc_method_t*)(c->data[0]);
if(m->body && scope > m->body->init_scope_depth)
m->body->init_scope_depth = scope;
}
if(op->flags&OP_RETURN) {
if(OP_RETURN==0x48/*returnvalue*/) {
- if(stack!=1)
+ if(stack!=1) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "return(value) with stackposition %d\n", stack);
+ }
} else if(OP_RETURN==0x47) {
- if(stack!=0)
+ if(stack!=0) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "return(void) with stackposition %d\n", stack);
+ }
}
}
if(op->flags & (OP_THROW|OP_RETURN))
return 1;
if(op->flags & OP_JUMP) {
if(!c->branch) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "Error: Invalid jump target in instruction %s at position %d.\n", op->name, pos);
return 0;
}
}
if(op->flags & OP_BRANCH) {
if(!c->branch) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "Error: Invalid jump target in instruction %s at position %d\n", op->name, pos);
return 0;
}
if(op->flags & OP_LOOKUPSWITCH) {
lookupswitch_t*l = c->data[0];
if(!l->def) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "Error: Invalid jump target in instruction %s at position %d\n", op->name, pos);
return 0;
}
code_list_t*t = l->targets;
while(t) {
if(!t->code) {
+ stats->stack[pos].flags |= FLAG_ERROR;
fprintf(stderr, "Error: Invalid jump target in instruction %s at position %d\n", op->name, pos);
return 0;
}
return 1;
}
-static currentstats_t* code_get_stats(code_t*code, exception_list_t*exceptions)
+static currentstats_t* code_get_stats(code_t*code, abc_exception_list_t*exceptions)
{
- code = code_find_start(code);
+ code = code_start(code);
int num = 0;
code_t*c = code;
while(c) {
free(current);
return 0;
}
- exception_list_t*e = exceptions;
+ abc_exception_list_t*e = exceptions;
while(e) {
- if(e->exception->target)
- callcode(current, e->exception->target->pos, 1, 0);
+ if(e->abc_exception->target)
+ callcode(current, e->abc_exception->target->pos, 1, 0);
e = e->next;
}
}
}
-int code_dump(code_t*c, exception_list_t*exceptions, abc_file_t*file, char*prefix, FILE*fo)
+int code_dump(code_t*c)
{
- exception_list_t*e = exceptions;
- c = code_find_start(c);
+ return code_dump2(c, 0, 0, "", stdout);
+}
+int code_dump2(code_t*c, abc_exception_list_t*exceptions, abc_file_t*file, char*prefix, FILE*fo)
+{
+ abc_exception_list_t*e = exceptions;
+ c = code_start(c);
currentstats_t*stats = code_get_stats(c, exceptions);
int pos = 0;
e = exceptions;
while(e) {
- if(c==e->exception->from)
+ if(c==e->abc_exception->from)
fprintf(fo, "%s TRY {\n", prefix);
- if(c==e->exception->target) {
- char*s1 = multiname_tostring(e->exception->exc_type);
- char*s2 = multiname_tostring(e->exception->var_name);
+ if(c==e->abc_exception->target) {
+ char*s1 = multiname_tostring(e->abc_exception->exc_type);
+ char*s2 = multiname_tostring(e->abc_exception->var_name);
fprintf(fo, "%s CATCH(%s %s)\n", prefix, s1, s2);
free(s1);
free(s2);
int i=0;
if(stats) {
- fprintf(fo, "%s%5d) %c %d:%d %s ", prefix, c->pos, stats->stack[c->pos].seen?'x':'|',
+ int f = stats->stack[c->pos].flags;
+ fprintf(fo, "%s%5d) %c %d:%d %s ", prefix, c->pos,
+ (f&FLAG_ERROR)?'E':((f&FLAG_SEEN)?'+':'|'),
stats->stack[c->pos].stackpos,
stats->stack[c->pos].scopepos,
op->name);
free(m);
} else if(*p == 'm') {
abc_method_t*m = (abc_method_t*)data;
- fprintf(fo, "[method %s]", m->name);
+ fprintf(fo, "[method %08x %s]", m->index, m->name);
} else if(*p == 'c') {
abc_class_t*cls = (abc_class_t*)data;
char*classname = multiname_tostring(cls->classname);
- fprintf(fo, "[classinfo %s]", classname);
+ fprintf(fo, "[classinfo %08x %s]", cls->index, classname);
free(classname);
} else if(*p == 'i') {
abc_method_body_t*b = (abc_method_body_t*)data;
int n = (ptroff_t)data;
fprintf(fo, "r%d", n);
} else if(*p == 'b') {
- int b = (ptroff_t)data;
- fprintf(fo, "%02x", b);
+ int b = (signed char)(ptroff_t)data;
+ fprintf(fo, "%d", b);
} else if(*p == 'j') {
if(c->branch)
fprintf(fo, "->%d", c->branch->pos);
else
fprintf(fo, "%08x", c->branch);
} else if(*p == 's') {
- fprintf(fo, "\"%s\"", data);
+ char*s = string_escape((string_t*)data);
+ fprintf(fo, "\"%s\"", s);
+ free(s);
} else if(*p == 'D') {
fprintf(fo, "[register %02x=%s]", (ptroff_t)c->data[1], (char*)c->data[0]);
} else if(*p == 'S') {
if(l->def)
fprintf(fo, "default->%d", l->def->pos);
else
- fprintf(fo, "default->00000000", l->def->pos);
+ fprintf(fo, "default->00000000");
code_list_t*t = l->targets;
while(t) {
if(t->code)
e = exceptions;
while(e) {
- if(c==e->exception->to) {
- if(e->exception->target)
- fprintf(fo, "%s } // END TRY (HANDLER: %d)\n", prefix, e->exception->target->pos);
+ if(c==e->abc_exception->to) {
+ if(e->abc_exception->target)
+ fprintf(fo, "%s } // END TRY (HANDLER: %d)\n", prefix, e->abc_exception->target->pos);
else
fprintf(fo, "%s } // END TRY (HANDLER: 00000000)\n", prefix);
}
return 1;
}
-codestats_t* code_get_statistics(code_t*code, exception_list_t*exceptions)
+codestats_t* code_get_statistics(code_t*code, abc_exception_list_t*exceptions)
{
currentstats_t*current = code_get_stats(code, exceptions);
if(!current)
{
code_t*tmp = (code_t*)rfx_calloc(sizeof(code_t));
tmp->opcode = op;
- tmp->next = 0;
if(atag) {
tmp->prev = atag;
tmp->next = atag->next;
+ if(tmp->next)
+ tmp->next->prev = tmp;
atag->next = tmp;
} else {
tmp->prev = 0;
+ tmp->next = 0;
}
return tmp;
}
printf("scope_depth: %d\n", stats->max_scope_depth);
}
+code_t* code_end(code_t*code)
+{
+ if(!code)
+ return 0;
+ while(code->next)
+ code = code->next;
+ return code;
+}
+code_t* code_start(code_t*code)
+{
+ if(!code)
+ return 0;
+ while(code->prev)
+ code = code->prev;
+ return code;
+}
+
code_t* code_append(code_t*code, code_t*toappend)
{
if(!code)
- return toappend;
+ return code_end(toappend);
if(!toappend)
- return code;
+ return code_end(code);
//find end of first list
while(code->next) {
code = code->next;
}
code->next = start;
start->prev = code;
- return toappend;
+ return code_end(toappend);
+}
+
+lookupswitch_t*lookupswitch_dup(lookupswitch_t*l)
+{
+ lookupswitch_t*n = malloc(sizeof(lookupswitch_t));
+ fprintf(stderr, "Error: lookupswitch dupping not supported yet\n");
+ n->targets = list_clone(l->targets);
+ return 0;
+}
+
+code_t*code_dup(code_t*c)
+{
+ if(!c) return 0;
+
+ while(c->prev) c = c->prev;
+
+ code_t*last = 0;
+ while(c) {
+ NEW(code_t, n);
+ memcpy(n, c, sizeof(code_t));
+
+ opcode_t*op = opcode_get(c->opcode);
+ if(c->branch || c->opcode == OPCODE_LABEL) {
+ fprintf(stderr, "Error: Can't duplicate branching code\n");
+ return 0;
+ }
+ char*p = op?op->params:"";
+ int pos=0;
+ while(*p) {
+ if(*p == '2') { //multiname
+ c->data[pos] = multiname_clone(c->data[pos]);
+ } else if(*p == 's') {
+ c->data[pos] = string_dup3(c->data[pos]);
+ } else if(*p == 'D') {
+ c->data[pos] = strdup(c->data[pos]);
+ } else if(*p == 'f') {
+ double old = *(double*)c->data[pos];
+ c->data[pos] = malloc(sizeof(double));
+ *(double*)c->data[pos] = old;
+ } else if(strchr("S", *p)) {
+ c->data[pos] = lookupswitch_dup(c->data[pos]);
+ }
+ p++;pos++;
+ }
+
+ n->prev = last;
+ if(last) {
+ last->next = n;
+ }
+ last = n;
+ c = c->next;
+ }
+ return last;
}
+code_t*code_cut(code_t*c)
+{
+ if(!c) return c;
+ code_t*prev = c->prev;
+ code_t*next = c->next;
+ c->prev = 0;
+ c->next = 0;
+ if(prev) prev->next=next;
+ if(next) next->prev=prev;
+ code_free(c);
+
+ if(next) return code_end(next);
+ else return prev;
+}
+
+code_t*code_cutlast(code_t*c)
+{
+ if(!c) return c;
+ assert(!c->next);
+ return code_cut(c);
+}
+
+code_t* cut_last_push(code_t*c)
+{
+ assert(!c->next);
+ while(c) {
+ if(!c) break;
+ opcode_t*op = opcode_get(c->opcode);
+ /* cut conversion type operations */
+ if(op->stack_minus == -1 && op->stack_plus == 1 && !(op->flags)) {
+ c = code_cutlast(c);
+ continue;
+ }
+ /* cut any type of push */
+ else if(op->stack_minus == 0 && op->stack_plus == 1 && !(op->flags)) {
+ return code_cutlast(c);
+ }
+ /* cut register lookups */
+ else if(c->opcode == OPCODE_GETLOCAL ||
+ c->opcode == OPCODE_GETLOCAL_0 ||
+ c->opcode == OPCODE_GETLOCAL_1 ||
+ c->opcode == OPCODE_GETLOCAL_2 ||
+ c->opcode == OPCODE_GETLOCAL_3) {
+ return code_cutlast(c);
+ }
+ /* discard function call values */
+ else if(c->opcode == OPCODE_CALLPROPERTY) {
+ c->opcode = OPCODE_CALLPROPVOID;
+ return c;
+ } else if(c->opcode == OPCODE_CALLSUPER) {
+ c->opcode = OPCODE_CALLSUPERVOID;
+ return c;
+ } else if(c->opcode == OPCODE_NEWOBJECT ||
+ c->opcode == OPCODE_NEWARRAY) {
+ // we can discard these if they're not eating up stack parameters
+ if(!c->data[0])
+ return code_cutlast(c);
+ } else if(op->stack_minus ==0 && op->stack_plus == 0 &&
+ !(op->flags&~(OP_REGISTER|OP_SET_DXNS)) && c->prev) {
+ // trim code *before* the kill, inclocal, declocal, dxns
+ code_t*p = c->prev;
+ p->next = 0;
+ c->prev = 0;
+ return code_append(cut_last_push(p), c);
+ } else
+ break;
+ }
+ c = abc_pop(c);
+ return c;
+}
+
+