forked from mdarin/gapstone
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathbpf.SPEC
More file actions
85 lines (74 loc) · 1.88 KB
/
Copy pathbpf.SPEC
File metadata and controls
85 lines (74 loc) · 1.88 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
****************
Platform: cBPF Le
Code: 0x94 0x09 0x00 0x00 0x37 0x13 0x03 0x00 0x87 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x07 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x16 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x80 0x00 0x00 0x00 0x00 0x00 0x00 0x00
Disasm:
0x0: mod 0x31337
Groups: alu
Operand count: 1
operands[0].type: IMM = 0x31337
Registers read: a
Registers modified: a
0x8: txa
Groups: misc
Operand count: 0
Registers read: x
Registers modified: a
0x10: tax
Groups: misc
Operand count: 0
Registers read: a
Registers modified: x
0x18: ret a
Groups: return
Operand count: 1
operands[0].type: REG = a
Registers read: a
0x20: ld #len
Groups: load
Operand count: 1
operands[0].type: EXT = #len
Registers modified: a
****************
Platform: eBPF Le
Code: 0x97 0x09 0x00 0x00 0x37 0x13 0x03 0x00 0xdc 0x02 0x00 0x00 0x20 0x00 0x00 0x00 0x30 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0xdb 0x3a 0x00 0x01 0x00 0x00 0x00 0x00 0x84 0x02 0x00 0x00 0x00 0x00 0x00 0x00 0x6d 0x33 0x17 0x02 0x00 0x00 0x00 0x00
Disasm:
0x0: mod64 r9, 0x31337
Groups: alu
Operand count: 2
operands[0].type: REG = r9
operands[1].type: IMM = 0x31337
Registers read: r9
Registers modified: r9
0x8: be32 r2
Groups: alu
Operand count: 1
operands[0].type: REG = r2
Registers read: r2
Registers modified: r2
0x10: ldb [0x0]
Groups: load
Operand count: 1
operands[0].type: MEM
operands[0].mem.disp: 0x0
Registers modified: r0
0x18: xadddw [r10+0x100], r3
Groups: store
Operand count: 2
operands[0].type: MEM
operands[0].mem.base: REG = r10
operands[0].mem.disp: 0x100
operands[1].type: REG = r3
Registers read: r3 r10
0x20: neg r2
Groups: alu
Operand count: 1
operands[0].type: REG = r2
Registers read: r2
Registers modified: r2
0x28: jsgt r3, r3, +0x217
Groups: jump
Operand count: 3
operands[0].type: REG = r3
operands[1].type: REG = r3
operands[2].type: OFF = +0x217
Registers read: r3