namespace X86Disassembler.X86.Handlers.Mov; /// /// Handler for MOV r/m32, imm32 instruction (0xC7) /// public class MovRm32Imm32Handler : InstructionHandler { /// /// Initializes a new instance of the MovRm32Imm32Handler class /// /// The buffer containing the code to decode /// The instruction decoder that owns this handler /// The length of the buffer public MovRm32Imm32Handler(byte[] codeBuffer, InstructionDecoder decoder, int length) : base(codeBuffer, decoder, length) { } /// /// Checks if this handler can decode the given opcode /// /// The opcode to check /// True if this handler can decode the opcode public override bool CanHandle(byte opcode) { return opcode == 0xC7; } /// /// Decodes a MOV r/m32, imm32 instruction /// /// The opcode of the instruction /// The instruction object to populate /// True if the instruction was successfully decoded public override bool Decode(byte opcode, Instruction instruction) { // Save the original position for raw bytes calculation int startPosition = Decoder.GetPosition(); // Set the mnemonic instruction.Mnemonic = "mov"; if (startPosition >= Length) { instruction.Operands = "??"; instruction.RawBytes = new byte[] { opcode }; return true; } // Use ModRMDecoder to decode the ModR/M byte var (mod, reg, rm, operand) = ModRMDecoder.ReadModRM(false); // MOV r/m32, imm32 only uses reg=0 if (reg != 0) { instruction.Operands = "??"; byte[] rawBytesReg = new byte[Decoder.GetPosition() - startPosition + 1]; // +1 for opcode rawBytesReg[0] = opcode; for (int i = 0; i < Decoder.GetPosition() - startPosition; i++) { if (startPosition + i < Length) { rawBytesReg[i + 1] = CodeBuffer[startPosition + i]; } } instruction.RawBytes = rawBytesReg; return true; } // Get the position after decoding the ModR/M byte int newPosition = Decoder.GetPosition(); // Check if we have enough bytes for the immediate value (4 bytes) if (newPosition + 3 >= Length) { instruction.Operands = "??"; byte[] rawBytesImm = new byte[newPosition - startPosition + 1]; // +1 for opcode rawBytesImm[0] = opcode; for (int i = 0; i < newPosition - startPosition; i++) { if (startPosition + i < Length) { rawBytesImm[i + 1] = CodeBuffer[startPosition + i]; } } instruction.RawBytes = rawBytesImm; return true; } // Read the immediate dword uint imm32 = Decoder.ReadUInt32(); // Set the operands instruction.Operands = $"{operand}, 0x{imm32:X8}"; // Set the raw bytes byte[] rawBytes = new byte[Decoder.GetPosition() - startPosition + 1]; // +1 for opcode rawBytes[0] = opcode; for (int i = 0; i < Decoder.GetPosition() - startPosition; i++) { if (startPosition + i < Length) { rawBytes[i + 1] = CodeBuffer[startPosition + i]; } } instruction.RawBytes = rawBytes; return true; } }