namespace X86Disassembler.X86.Handlers.Xor; /// /// Handler for XOR r/m16, imm16 instruction (0x81 /6 with 0x66 prefix) /// public class XorImmWithRm16Handler : InstructionHandler { /// /// Initializes a new instance of the XorImmWithRm16Handler class /// /// The buffer containing the code to decode /// The instruction decoder that owns this handler /// The length of the buffer public XorImmWithRm16Handler(byte[] codeBuffer, InstructionDecoder decoder, int length) : base(codeBuffer, decoder, length) { } /// /// Checks if this handler can decode the given opcode /// /// The opcode to check /// True if this handler can decode the opcode public override bool CanHandle(byte opcode) { if (opcode != 0x81 || !Decoder.HasOperandSizePrefix()) return false; // Check if the reg field of the ModR/M byte is 6 (XOR) int position = Decoder.GetPosition(); if (position >= Length) return false; byte modRM = CodeBuffer[position]; byte reg = (byte)((modRM & 0x38) >> 3); return reg == 6; // 6 = XOR } /// /// Decodes a XOR r/m16, imm16 instruction /// /// The opcode of the instruction /// The instruction object to populate /// True if the instruction was successfully decoded public override bool Decode(byte opcode, Instruction instruction) { // Set the mnemonic instruction.Mnemonic = "xor"; int position = Decoder.GetPosition(); if (position >= Length) { return false; } // Read the ModR/M byte var (mod, reg, rm, memOperand) = ModRMDecoder.ReadModRM(); // For the first operand, handle based on addressing mode string rmOperand; if (mod == 3) // Register addressing mode { // Get 16-bit register name for the operand rmOperand = ModRMDecoder.GetRegisterName(rm, 16); } else // Memory addressing mode { // For memory operands, replace "dword ptr" with "word ptr" if (memOperand.StartsWith("dword ptr ")) { rmOperand = memOperand.Replace("dword ptr", "word ptr"); } else { rmOperand = memOperand; } } // Get the updated position after ModR/M decoding position = Decoder.GetPosition(); // Read the immediate value if (position + 1 >= Length) { return false; } // Read the immediate value using the decoder ushort imm16 = Decoder.ReadUInt16(); // Format the immediate value string immStr = $"0x{imm16:X4}"; // Set the operands instruction.Operands = $"{rmOperand}, {immStr}"; return true; } }