0
mirror of https://github.com/sampletext32/ParkanPlayground.git synced 2025-05-19 11:51:17 +03:00
ParkanPlayground/X86Disassembler/X86/Handlers/Sub/SubImmFromRm16Handler.cs

91 lines
2.8 KiB
C#
Raw Normal View History

using X86Disassembler.X86.Operands;
namespace X86Disassembler.X86.Handlers.Sub;
/// <summary>
/// Handler for SUB r/m16, imm16 instruction (0x81 /5 with 0x66 prefix)
/// </summary>
public class SubImmFromRm16Handler : InstructionHandler
{
/// <summary>
/// Initializes a new instance of the SubImmFromRm16Handler class
/// </summary>
/// <param name="decoder">The instruction decoder that owns this handler</param>
public SubImmFromRm16Handler(InstructionDecoder decoder)
: base(decoder)
{
}
/// <summary>
/// Checks if this handler can decode the given opcode
/// </summary>
/// <param name="opcode">The opcode to check</param>
/// <returns>True if this handler can decode the opcode</returns>
public override bool CanHandle(byte opcode)
{
// Check if the opcode is 0x81 and we have a 0x66 prefix
if (opcode != 0x81 || !Decoder.HasOperandSizeOverridePrefix())
{
return false;
}
// Check if we have enough bytes to read the ModR/M byte
if (!Decoder.CanReadByte())
{
return false;
}
// Check if the reg field is 5 (SUB)
2025-04-15 02:42:47 +03:00
var reg = ModRMDecoder.PeakModRMReg();
return reg == 5; // 5 = SUB
}
/// <summary>
/// Decodes a SUB r/m16, imm16 instruction
/// </summary>
/// <param name="opcode">The opcode of the instruction</param>
/// <param name="instruction">The instruction object to populate</param>
/// <returns>True if the instruction was successfully decoded</returns>
public override bool Decode(byte opcode, Instruction instruction)
{
// Set the instruction type
instruction.Type = InstructionType.Sub;
// Check if we have enough bytes for the ModR/M byte
if (!Decoder.CanReadByte())
{
return false;
}
2025-04-13 18:22:44 +03:00
// Read the ModR/M byte
// For SUB r/m16, imm16 (0x81 /5 with 0x66 prefix):
// - The r/m field with mod specifies the destination operand (register or memory)
// - The immediate value is the source operand
2025-04-15 02:42:47 +03:00
var (_, _, _, destinationOperand) = ModRMDecoder.ReadModRM();
2025-04-13 18:22:44 +03:00
// Adjust the operand size to 16-bit
destinationOperand.Size = 16;
2025-04-13 18:22:44 +03:00
// Check if we have enough bytes for the immediate value
if (!Decoder.CanReadUShort())
{
return false;
}
2025-04-13 18:22:44 +03:00
// Read the immediate value (16-bit)
2025-04-13 18:22:44 +03:00
ushort immediate = Decoder.ReadUInt16();
// Create the source immediate operand
var sourceOperand = OperandFactory.CreateImmediateOperand(immediate, 16);
// Set the structured operands
instruction.StructuredOperands =
[
destinationOperand,
sourceOperand
];
2025-04-13 18:22:44 +03:00
return true;
}
2025-04-13 18:22:44 +03:00
}