forked from beehive-lab/mambo
-
Notifications
You must be signed in to change notification settings - Fork 1
/
util.S
406 lines (346 loc) · 6.87 KB
/
util.S
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
/*
This file is part of MAMBO, a low-overhead dynamic binary modification tool:
https://github.com/beehive-lab/mambo
Copyright 2013-2016 Cosmin Gorgovan <cosmin at linux-geek dot org>
Copyright 2017 The University of Manchester
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
#include <asm/unistd.h>
# These helpers are executed from .text and are not copied to the code cache
#ifdef __arm__
.syntax unified
#endif
.global dbm_client_entry
.func dbm_client_entry
.type dbm_client_entry, %function
#ifdef __arm__
.code 32
dbm_client_entry:
MOV SP, R1
MOV LR, R0
MOV R0, #0
MOV R1, #0
MOV R2, #0
MOV R3, #0
BLX LR
BX LR
#endif // __arm__
#ifdef __aarch64__
dbm_client_entry:
MOV SP, X1
STP XZR, XZR, [SP, #-16]!
BR X0
#endif
.endfunc
# R0 - new SP
.global th_enter
.func th_enter
.type th_enter, %function
#ifdef __arm__
.thumb_func
th_enter:
MOV SP, R0
STR R1, [SP, #56]
POP {R0-R12, R14}
POP {PC}
#endif
#ifdef __aarch64__
th_enter:
MOV SP, X0
LDP X4, X5, [SP, #16]
LDP X6, X7, [SP, #32]
LDP X8, X9, [SP, #48]
LDP X10, X11, [SP, #64]
LDP X12, X13, [SP, #80]
LDP X14, X15, [SP, #96]
LDP X16, X17, [SP, #112]
LDP X18, X19, [SP, #128]
LDP X20, X21, [SP, #144]
LDP X22, X23, [SP, #160]
LDP X24, X25, [SP, #176]
LDP X26, X27, [SP, #192]
LDR X28, [SP, #208]
LDP X29, X30, [SP, #224]
LDP X2, X3, [SP], #240
BR X1
#endif
.endfunc
.global new_thread_trampoline
.func
.type new_thread_trampoline, %function
new_thread_trampoline:
#ifdef __arm__
PUSH {R4-R12, LR}
MOV R1, SP
#elif __aarch64__
STP X19, X20, [SP, #-96]!
STP X21, X22, [SP, #16]
STP X23, X24, [SP, #32]
STP X25, X26, [SP, #48]
STP X27, X28, [SP, #64]
STP X29, X30, [SP, #80]
MOV X1, SP
#endif
B dbm_start_thread_pth
.endfunc
.global return_with_sp
.func
.type return_with_sp, %function
return_with_sp:
#ifdef __arm__
MOV SP, R0
POP {R4-R12, PC}
#elif __aarch64__
MOV SP, X0
LDP X21, X22, [SP, #16]
LDP X23, X24, [SP, #32]
LDP X25, X26, [SP, #48]
LDP X27, X28, [SP, #64]
LDP X29, X30, [SP, #80]
LDP X19, X20, [SP], #96
RET
#endif
.endfunc
.global raw_syscall
.func raw_syscall
.type raw_syscall, %function
raw_syscall:
#ifdef __arm__
MOV R12, SP
PUSH {R4 - R7}
MOV R7, R0
MOV R0, R1
MOV R1, R2
MOV R2, R3
LDM R12, {R3 - R6}
SVC 0
POP {R4 - R7}
BX LR
#endif
#ifdef __aarch64__
MOV W8, W0
MOV X0, X1
MOV X1, X2
MOV X2, X3
MOV X3, X4
MOV X4, X5
MOV X5, X6
MOV X6, X7
SVC 0
RET
#endif
.endfunc
.global signal_trampoline
.func signal_trampoline
.type signal_trampoline, %function
signal_trampoline:
#ifdef __arm__
SUB SP, SP, #4
PUSH {r0-r3, r9, r12, lr}
BL signal_dispatcher
CBZ R0, sigret
STR R0, [SP, #28]
POP {r0-r3, r9, r12, lr}
POP {PC}
sigret:
ADD SP, SP, #32
MOV R7, #__NR_rt_sigreturn
SVC 0
#endif
#ifdef __aarch64__
STP X2, X3, [SP, #-176]!
STP X4, X5, [SP, #16]
STP X6, X7, [SP, #32]
STP X8, X9, [SP, #48]
STP X10, X11, [SP, #64]
STP X12, X13, [SP, #80]
STP X14, X15, [SP, #96]
STP X16, X17, [SP, #112]
STP X18, X29, [SP, #128]
STR X30, [SP, #144]
STP X0, X1, [SP, #160]
BL signal_dispatcher
LDP X4, X5, [SP, #16]
LDP X6, X7, [SP, #32]
LDP X8, X9, [SP, #48]
LDP X10, X11, [SP, #64]
LDP X12, X13, [SP, #80]
LDP X14, X15, [SP, #96]
LDP X16, X17, [SP, #112]
LDP X18, X29, [SP, #128]
LDR X30, [SP, #144]
LDP X2, X3, [SP], #160
CBZ X0, sigret
BR X0
sigret:
ADD SP, SP, #16
MOV X8, #__NR_rt_sigreturn
SVC 0
#endif
.endfunc
.global atomic_increment_u64
.func atomic_increment_u64
.type atomic_increment_u64, %function
atomic_increment_u64:
#ifdef __arm__
// R0 - ptr, R2 inc (low), R3, inc (high)
PUSH {R4, R5}
retry:
LDREXD R4, R5, [R0]
ADDS R4, R2
ADC R5, R3
STREXD R1, R4, R5, [R0]
CMP R1, #0
BNE retry
MOV R0, R4
MOV R1, R5
POP {R4, R5}
BX LR
#elif __aarch64__
LDXR X2, [X0]
ADD X2, X2, X1
STXR W3, X2, [X0]
CBNZ W3, atomic_increment_u64
MOV X0, X2
RET
#endif
.endfunc
.global atomic_increment_u32
.func atomic_increment_u32
.type atomic_increment_u32, %function
atomic_increment_u32:
#ifdef __arm__
LDREX R2, [R0]
ADD R2, R1
STREX R3, R2, [R0]
CMP R3, #0
BNE atomic_increment_u32
MOV R0, R2
BX LR
#elif __aarch64__
LDXR W2, [X0]
ADD W2, W2, W1
STXR W3, W2, [X0]
CBNZ W3, atomic_increment_u32
MOV W0, W2
RET
#endif
.endfunc
.global atomic_decrement_if_positive_i32
.func atomic_decrement_if_positive_i32
.type atomic_decrement_if_positive_i32, %function
atomic_decrement_if_positive_i32:
#ifdef __arm__
LDREX R2, [R0]
CMP R2, R1
BLT abort
SUB R2, R2, R1
STREX R3, R2, [R0]
CMP R3, #0
BNE atomic_decrement_if_positive_i32
MOV R0, R2
BX LR
abort:
CLREX
MOV R0, #-1
BX LR
#elif __aarch64__
LDXR W2, [X0]
CMP W2, W1
BLT abort
SUB W2, W2, W1
STXR W3, W2, [X0]
CBNZ W3, atomic_decrement_if_positive_i32
MOV W0, W2
RET
abort:
CLREX
MOV W0, #-1
RET
#endif
.endfunc
.global safe_fcall_trampoline
.func safe_fcall_trampoline
.type safe_fcall_trampoline, %function
safe_fcall_trampoline:
#ifdef __arm__
PUSH {R5-R7, R9, R12, LR}
VPUSH {d16-d31}
VPUSH {d0-d7}
MOV R7, SP
BIC R6, R7, #7
MOV SP, R6
MRS R5, CPSR
VMRS R6, FPSCR
BLX R4
MOV SP, R7
MSR CPSR, R5
VMSR FPSCR, R6
VPOP {d0-d7}
VPOP {d16-d31}
POP {R5-R7, R9, R12, PC}
#elif __aarch64__
STP X8, X9, [SP, #-128]!
STP X10, X11, [SP, #16]
STP X12, X13, [SP, #32]
STP X14, X15, [SP, #48]
STP X16, X17, [SP, #64]
STP X18, X19, [SP, #80]
STP X20, X21, [SP, #96]
STP X29, X30, [SP, #112]
MRS X19, NZCV
MRS X20, FPCR
MRS X21, FPSR
BL push_neon
BLR X8
BL pop_neon
MSR NZCV, X19
MSR FPCR, X20
MSR FPSR, X21
LDP X10, X11, [SP, #16]
LDP X12, X13, [SP, #32]
LDP X14, X15, [SP, #48]
LDP X16, X17, [SP, #64]
LDP X18, X19, [SP, #80]
LDP X20, X21, [SP, #96]
LDP X29, X30, [SP, #112]
LDP X8, X9, [SP], #128
RET
#endif
.endfunc
.global __try_memcpy_error
.type __try_memcpy_error, %function
.global __try_memcpy
.type __try_memcpy, %function
__try_memcpy:
#ifdef __arm__
LDRB R3, [R1], #1
STRB R3, [R0], #1
SUB R2, #1
CBZ R2, __try_memcpy_ret
B __try_memcpy
__try_memcpy_ret:
MOV R0, #0
BX LR
__try_memcpy_error:
MOV R0, #-1
BX LR
#elif __aarch64__
LDRB W3, [X1], #1
STRB W3, [X0], #1
SUB X2, X2, #1
CBNZ X2, __try_memcpy
MOV X0, #0
RET
__try_memcpy_error:
MOV X0, #-1
RET
#endif