2 * Copyright (C) 2016 Veertu Inc,
3 * Copyright (C) 2017 Google Inc,
5 * This program is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU Lesser General Public
7 * License as published by the Free Software Foundation; either
8 * version 2.1 of the License, or (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 * Lesser General Public License for more details.
15 * You should have received a copy of the GNU Lesser General Public
16 * License along with this program; if not, see <http://www.gnu.org/licenses/>.
19 /////////////////////////////////////////////////////////////////////////
21 // Copyright (C) 2001-2012 The Bochs Project
23 // This library is free software; you can redistribute it and/or
24 // modify it under the terms of the GNU Lesser General Public
25 // License as published by the Free Software Foundation; either
26 // version 2.1 of the License, or (at your option) any later version.
28 // This library is distributed in the hope that it will be useful,
29 // but WITHOUT ANY WARRANTY; without even the implied warranty of
30 // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
31 // Lesser General Public License for more details.
33 // You should have received a copy of the GNU Lesser General Public
34 // License along with this library; if not, write to the Free Software
35 // Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA B 02110-1301 USA
36 /////////////////////////////////////////////////////////////////////////
38 #include "qemu/osdep.h"
40 #include "x86_decode.h"
44 #include "x86_flags.h"
48 void hvf_handle_io(struct CPUState
*cpu
, uint16_t port
, void *data
,
49 int direction
, int size
, uint32_t count
);
51 #define EXEC_2OP_FLAGS_CMD(env, decode, cmd, FLAGS_FUNC, save_res) \
53 fetch_operands(env, decode, 2, true, true, false); \
54 switch (decode->operand_size) { \
57 uint8_t v1 = (uint8_t)decode->op[0].val; \
58 uint8_t v2 = (uint8_t)decode->op[1].val; \
59 uint8_t diff = v1 cmd v2; \
61 write_val_ext(env, decode->op[0].ptr, diff, 1); \
63 FLAGS_FUNC##8(env, v1, v2, diff); \
68 uint16_t v1 = (uint16_t)decode->op[0].val; \
69 uint16_t v2 = (uint16_t)decode->op[1].val; \
70 uint16_t diff = v1 cmd v2; \
72 write_val_ext(env, decode->op[0].ptr, diff, 2); \
74 FLAGS_FUNC##16(env, v1, v2, diff); \
79 uint32_t v1 = (uint32_t)decode->op[0].val; \
80 uint32_t v2 = (uint32_t)decode->op[1].val; \
81 uint32_t diff = v1 cmd v2; \
83 write_val_ext(env, decode->op[0].ptr, diff, 4); \
85 FLAGS_FUNC##32(env, v1, v2, diff); \
89 VM_PANIC("bad size\n"); \
93 target_ulong read_reg(CPUX86State *env, int reg, int size)
97 return x86_reg(env
, reg
)->lx
;
99 return x86_reg(env
, reg
)->rx
;
101 return x86_reg(env
, reg
)->erx
;
103 return x86_reg(env
, reg
)->rrx
;
110 void write_reg(CPUX86State
*env
, int reg
, target_ulong val
, int size
)
114 x86_reg(env
, reg
)->lx
= val
;
117 x86_reg(env
, reg
)->rx
= val
;
120 x86_reg(env
, reg
)->rrx
= (uint32_t)val
;
123 x86_reg(env
, reg
)->rrx
= val
;
130 target_ulong
read_val_from_reg(target_ulong reg_ptr
, int size
)
136 val
= *(uint8_t *)reg_ptr
;
139 val
= *(uint16_t *)reg_ptr
;
142 val
= *(uint32_t *)reg_ptr
;
145 val
= *(uint64_t *)reg_ptr
;
153 void write_val_to_reg(target_ulong reg_ptr
, target_ulong val
, int size
)
157 *(uint8_t *)reg_ptr
= val
;
160 *(uint16_t *)reg_ptr
= val
;
163 *(uint64_t *)reg_ptr
= (uint32_t)val
;
166 *(uint64_t *)reg_ptr
= val
;
173 static bool is_host_reg(CPUX86State
*env
, target_ulong ptr
)
175 return (ptr
- (target_ulong
)&env
->regs
[0]) < sizeof(env
->regs
);
178 void write_val_ext(CPUX86State
*env
, target_ulong ptr
, target_ulong val
, int size
)
180 if (is_host_reg(env
, ptr
)) {
181 write_val_to_reg(ptr
, val
, size
);
184 vmx_write_mem(env_cpu(env
), ptr
, &val
, size
);
187 uint8_t *read_mmio(CPUX86State
*env
, target_ulong ptr
, int bytes
)
189 vmx_read_mem(env_cpu(env
), env
->hvf_mmio_buf
, ptr
, bytes
);
190 return env
->hvf_mmio_buf
;
194 target_ulong
read_val_ext(CPUX86State
*env
, target_ulong ptr
, int size
)
199 if (is_host_reg(env
, ptr
)) {
200 return read_val_from_reg(ptr
, size
);
203 mmio_ptr
= read_mmio(env
, ptr
, size
);
206 val
= *(uint8_t *)mmio_ptr
;
209 val
= *(uint16_t *)mmio_ptr
;
212 val
= *(uint32_t *)mmio_ptr
;
215 val
= *(uint64_t *)mmio_ptr
;
218 VM_PANIC("bad size\n");
224 static void fetch_operands(CPUX86State
*env
, struct x86_decode
*decode
,
225 int n
, bool val_op0
, bool val_op1
, bool val_op2
)
228 bool calc_val
[3] = {val_op0
, val_op1
, val_op2
};
230 for (i
= 0; i
< n
; i
++) {
231 switch (decode
->op
[i
].type
) {
232 case X86_VAR_IMMEDIATE
:
235 VM_PANIC_ON(!decode
->op
[i
].ptr
);
237 decode
->op
[i
].val
= read_val_from_reg(decode
->op
[i
].ptr
,
238 decode
->operand_size
);
242 calc_modrm_operand(env
, decode
, &decode
->op
[i
]);
244 decode
->op
[i
].val
= read_val_ext(env
, decode
->op
[i
].ptr
,
245 decode
->operand_size
);
249 decode
->op
[i
].ptr
= decode_linear_addr(env
, decode
,
253 decode
->op
[i
].val
= read_val_ext(env
, decode
->op
[i
].ptr
,
254 decode
->operand_size
);
263 static void exec_mov(CPUX86State
*env
, struct x86_decode
*decode
)
265 fetch_operands(env
, decode
, 2, false, true, false);
266 write_val_ext(env
, decode
->op
[0].ptr
, decode
->op
[1].val
,
267 decode
->operand_size
);
269 env
->eip
+= decode
->len
;
272 static void exec_add(CPUX86State
*env
, struct x86_decode
*decode
)
274 EXEC_2OP_FLAGS_CMD(env
, decode
, +, SET_FLAGS_OSZAPC_ADD
, true);
275 env
->eip
+= decode
->len
;
278 static void exec_or(CPUX86State
*env
, struct x86_decode
*decode
)
280 EXEC_2OP_FLAGS_CMD(env
, decode
, |, SET_FLAGS_OSZAPC_LOGIC
, true);
281 env
->eip
+= decode
->len
;
284 static void exec_adc(CPUX86State
*env
, struct x86_decode
*decode
)
286 EXEC_2OP_FLAGS_CMD(env
, decode
, +get_CF(env
)+, SET_FLAGS_OSZAPC_ADD
, true);
287 env
->eip
+= decode
->len
;
290 static void exec_sbb(CPUX86State
*env
, struct x86_decode
*decode
)
292 EXEC_2OP_FLAGS_CMD(env
, decode
, -get_CF(env
)-, SET_FLAGS_OSZAPC_SUB
, true);
293 env
->eip
+= decode
->len
;
296 static void exec_and(CPUX86State
*env
, struct x86_decode
*decode
)
298 EXEC_2OP_FLAGS_CMD(env
, decode
, &, SET_FLAGS_OSZAPC_LOGIC
, true);
299 env
->eip
+= decode
->len
;
302 static void exec_sub(CPUX86State
*env
, struct x86_decode
*decode
)
304 EXEC_2OP_FLAGS_CMD(env
, decode
, -, SET_FLAGS_OSZAPC_SUB
, true);
305 env
->eip
+= decode
->len
;
308 static void exec_xor(CPUX86State
*env
, struct x86_decode
*decode
)
310 EXEC_2OP_FLAGS_CMD(env
, decode
, ^, SET_FLAGS_OSZAPC_LOGIC
, true);
311 env
->eip
+= decode
->len
;
314 static void exec_neg(CPUX86State
*env
, struct x86_decode
*decode
)
316 /*EXEC_2OP_FLAGS_CMD(env, decode, -, SET_FLAGS_OSZAPC_SUB, false);*/
318 fetch_operands(env
, decode
, 2, true, true, false);
320 val
= 0 - sign(decode
->op
[1].val
, decode
->operand_size
);
321 write_val_ext(env
, decode
->op
[1].ptr
, val
, decode
->operand_size
);
323 if (4 == decode
->operand_size
) {
324 SET_FLAGS_OSZAPC_SUB32(env
, 0, 0 - val
, val
);
325 } else if (2 == decode
->operand_size
) {
326 SET_FLAGS_OSZAPC_SUB16(env
, 0, 0 - val
, val
);
327 } else if (1 == decode
->operand_size
) {
328 SET_FLAGS_OSZAPC_SUB8(env
, 0, 0 - val
, val
);
330 VM_PANIC("bad op size\n");
333 /*lflags_to_rflags(env);*/
334 env
->eip
+= decode
->len
;
337 static void exec_cmp(CPUX86State
*env
, struct x86_decode
*decode
)
339 EXEC_2OP_FLAGS_CMD(env
, decode
, -, SET_FLAGS_OSZAPC_SUB
, false);
340 env
->eip
+= decode
->len
;
343 static void exec_inc(CPUX86State
*env
, struct x86_decode
*decode
)
345 decode
->op
[1].type
= X86_VAR_IMMEDIATE
;
346 decode
->op
[1].val
= 0;
348 EXEC_2OP_FLAGS_CMD(env
, decode
, +1+, SET_FLAGS_OSZAP_ADD
, true);
350 env
->eip
+= decode
->len
;
353 static void exec_dec(CPUX86State
*env
, struct x86_decode
*decode
)
355 decode
->op
[1].type
= X86_VAR_IMMEDIATE
;
356 decode
->op
[1].val
= 0;
358 EXEC_2OP_FLAGS_CMD(env
, decode
, -1-, SET_FLAGS_OSZAP_SUB
, true);
359 env
->eip
+= decode
->len
;
362 static void exec_tst(CPUX86State
*env
, struct x86_decode
*decode
)
364 EXEC_2OP_FLAGS_CMD(env
, decode
, &, SET_FLAGS_OSZAPC_LOGIC
, false);
365 env
->eip
+= decode
->len
;
368 static void exec_not(CPUX86State
*env
, struct x86_decode
*decode
)
370 fetch_operands(env
, decode
, 1, true, false, false);
372 write_val_ext(env
, decode
->op
[0].ptr
, ~decode
->op
[0].val
,
373 decode
->operand_size
);
374 env
->eip
+= decode
->len
;
377 void exec_movzx(CPUX86State
*env
, struct x86_decode
*decode
)
380 int op_size
= decode
->operand_size
;
382 fetch_operands(env
, decode
, 1, false, false, false);
384 if (0xb6 == decode
->opcode
[1]) {
389 decode
->operand_size
= src_op_size
;
390 calc_modrm_operand(env
, decode
, &decode
->op
[1]);
391 decode
->op
[1].val
= read_val_ext(env
, decode
->op
[1].ptr
, src_op_size
);
392 write_val_ext(env
, decode
->op
[0].ptr
, decode
->op
[1].val
, op_size
);
394 env
->eip
+= decode
->len
;
397 static void exec_out(CPUX86State
*env
, struct x86_decode
*decode
)
399 switch (decode
->opcode
[0]) {
401 hvf_handle_io(env_cpu(env
), decode
->op
[0].val
, &AL(env
), 1, 1, 1);
404 hvf_handle_io(env_cpu(env
), decode
->op
[0].val
, &RAX(env
), 1,
405 decode
->operand_size
, 1);
408 hvf_handle_io(env_cpu(env
), DX(env
), &AL(env
), 1, 1, 1);
411 hvf_handle_io(env_cpu(env
), DX(env
), &RAX(env
), 1,
412 decode
->operand_size
, 1);
415 VM_PANIC("Bad out opcode\n");
418 env
->eip
+= decode
->len
;
421 static void exec_in(CPUX86State
*env
, struct x86_decode
*decode
)
423 target_ulong val
= 0;
424 switch (decode
->opcode
[0]) {
426 hvf_handle_io(env_cpu(env
), decode
->op
[0].val
, &AL(env
), 0, 1, 1);
429 hvf_handle_io(env_cpu(env
), decode
->op
[0].val
, &val
, 0,
430 decode
->operand_size
, 1);
431 if (decode
->operand_size
== 2) {
434 RAX(env
) = (uint32_t)val
;
438 hvf_handle_io(env_cpu(env
), DX(env
), &AL(env
), 0, 1, 1);
441 hvf_handle_io(env_cpu(env
), DX(env
), &val
, 0, decode
->operand_size
, 1);
442 if (decode
->operand_size
== 2) {
445 RAX(env
) = (uint32_t)val
;
450 VM_PANIC("Bad in opcode\n");
454 env
->eip
+= decode
->len
;
457 static inline void string_increment_reg(CPUX86State
*env
, int reg
,
458 struct x86_decode
*decode
)
460 target_ulong val
= read_reg(env
, reg
, decode
->addressing_size
);
461 if (env
->eflags
& DF_MASK
) {
462 val
-= decode
->operand_size
;
464 val
+= decode
->operand_size
;
466 write_reg(env
, reg
, val
, decode
->addressing_size
);
469 static inline void string_rep(CPUX86State
*env
, struct x86_decode
*decode
,
470 void (*func
)(CPUX86State
*env
,
471 struct x86_decode
*ins
), int rep
)
473 target_ulong rcx
= read_reg(env
, R_ECX
, decode
->addressing_size
);
476 write_reg(env
, R_ECX
, rcx
, decode
->addressing_size
);
477 if ((PREFIX_REP
== rep
) && !get_ZF(env
)) {
480 if ((PREFIX_REPN
== rep
) && get_ZF(env
)) {
486 static void exec_ins_single(CPUX86State
*env
, struct x86_decode
*decode
)
488 target_ulong addr
= linear_addr_size(env_cpu(env
), RDI(env
),
489 decode
->addressing_size
, R_ES
);
491 hvf_handle_io(env_cpu(env
), DX(env
), env
->hvf_mmio_buf
, 0,
492 decode
->operand_size
, 1);
493 vmx_write_mem(env_cpu(env
), addr
, env
->hvf_mmio_buf
,
494 decode
->operand_size
);
496 string_increment_reg(env
, R_EDI
, decode
);
499 static void exec_ins(CPUX86State
*env
, struct x86_decode
*decode
)
502 string_rep(env
, decode
, exec_ins_single
, 0);
504 exec_ins_single(env
, decode
);
507 env
->eip
+= decode
->len
;
510 static void exec_outs_single(CPUX86State
*env
, struct x86_decode
*decode
)
512 target_ulong addr
= decode_linear_addr(env
, decode
, RSI(env
), R_DS
);
514 vmx_read_mem(env_cpu(env
), env
->hvf_mmio_buf
, addr
,
515 decode
->operand_size
);
516 hvf_handle_io(env_cpu(env
), DX(env
), env
->hvf_mmio_buf
, 1,
517 decode
->operand_size
, 1);
519 string_increment_reg(env
, R_ESI
, decode
);
522 static void exec_outs(CPUX86State
*env
, struct x86_decode
*decode
)
525 string_rep(env
, decode
, exec_outs_single
, 0);
527 exec_outs_single(env
, decode
);
530 env
->eip
+= decode
->len
;
533 static void exec_movs_single(CPUX86State
*env
, struct x86_decode
*decode
)
535 target_ulong src_addr
;
536 target_ulong dst_addr
;
539 src_addr
= decode_linear_addr(env
, decode
, RSI(env
), R_DS
);
540 dst_addr
= linear_addr_size(env_cpu(env
), RDI(env
),
541 decode
->addressing_size
, R_ES
);
543 val
= read_val_ext(env
, src_addr
, decode
->operand_size
);
544 write_val_ext(env
, dst_addr
, val
, decode
->operand_size
);
546 string_increment_reg(env
, R_ESI
, decode
);
547 string_increment_reg(env
, R_EDI
, decode
);
550 static void exec_movs(CPUX86State
*env
, struct x86_decode
*decode
)
553 string_rep(env
, decode
, exec_movs_single
, 0);
555 exec_movs_single(env
, decode
);
558 env
->eip
+= decode
->len
;
561 static void exec_cmps_single(CPUX86State
*env
, struct x86_decode
*decode
)
563 target_ulong src_addr
;
564 target_ulong dst_addr
;
566 src_addr
= decode_linear_addr(env
, decode
, RSI(env
), R_DS
);
567 dst_addr
= linear_addr_size(env_cpu(env
), RDI(env
),
568 decode
->addressing_size
, R_ES
);
570 decode
->op
[0].type
= X86_VAR_IMMEDIATE
;
571 decode
->op
[0].val
= read_val_ext(env
, src_addr
, decode
->operand_size
);
572 decode
->op
[1].type
= X86_VAR_IMMEDIATE
;
573 decode
->op
[1].val
= read_val_ext(env
, dst_addr
, decode
->operand_size
);
575 EXEC_2OP_FLAGS_CMD(env
, decode
, -, SET_FLAGS_OSZAPC_SUB
, false);
577 string_increment_reg(env
, R_ESI
, decode
);
578 string_increment_reg(env
, R_EDI
, decode
);
581 static void exec_cmps(CPUX86State
*env
, struct x86_decode
*decode
)
584 string_rep(env
, decode
, exec_cmps_single
, decode
->rep
);
586 exec_cmps_single(env
, decode
);
588 env
->eip
+= decode
->len
;
592 static void exec_stos_single(CPUX86State
*env
, struct x86_decode
*decode
)
597 addr
= linear_addr_size(env_cpu(env
), RDI(env
),
598 decode
->addressing_size
, R_ES
);
599 val
= read_reg(env
, R_EAX
, decode
->operand_size
);
600 vmx_write_mem(env_cpu(env
), addr
, &val
, decode
->operand_size
);
602 string_increment_reg(env
, R_EDI
, decode
);
606 static void exec_stos(CPUX86State
*env
, struct x86_decode
*decode
)
609 string_rep(env
, decode
, exec_stos_single
, 0);
611 exec_stos_single(env
, decode
);
614 env
->eip
+= decode
->len
;
617 static void exec_scas_single(CPUX86State
*env
, struct x86_decode
*decode
)
621 addr
= linear_addr_size(env_cpu(env
), RDI(env
),
622 decode
->addressing_size
, R_ES
);
623 decode
->op
[1].type
= X86_VAR_IMMEDIATE
;
624 vmx_read_mem(env_cpu(env
), &decode
->op
[1].val
, addr
, decode
->operand_size
);
626 EXEC_2OP_FLAGS_CMD(env
, decode
, -, SET_FLAGS_OSZAPC_SUB
, false);
627 string_increment_reg(env
, R_EDI
, decode
);
630 static void exec_scas(CPUX86State
*env
, struct x86_decode
*decode
)
632 decode
->op
[0].type
= X86_VAR_REG
;
633 decode
->op
[0].reg
= R_EAX
;
635 string_rep(env
, decode
, exec_scas_single
, decode
->rep
);
637 exec_scas_single(env
, decode
);
640 env
->eip
+= decode
->len
;
643 static void exec_lods_single(CPUX86State
*env
, struct x86_decode
*decode
)
646 target_ulong val
= 0;
648 addr
= decode_linear_addr(env
, decode
, RSI(env
), R_DS
);
649 vmx_read_mem(env_cpu(env
), &val
, addr
, decode
->operand_size
);
650 write_reg(env
, R_EAX
, val
, decode
->operand_size
);
652 string_increment_reg(env
, R_ESI
, decode
);
655 static void exec_lods(CPUX86State
*env
, struct x86_decode
*decode
)
658 string_rep(env
, decode
, exec_lods_single
, 0);
660 exec_lods_single(env
, decode
);
663 env
->eip
+= decode
->len
;
666 void simulate_rdmsr(struct CPUState
*cpu
)
668 X86CPU
*x86_cpu
= X86_CPU(cpu
);
669 CPUX86State
*env
= &x86_cpu
->env
;
670 CPUState
*cs
= env_cpu(env
);
671 uint32_t msr
= ECX(env
);
676 val
= rdtscp() + rvmcs(cpu
->hvf
->fd
, VMCS_TSC_OFFSET
);
678 case MSR_IA32_APICBASE
:
679 val
= cpu_get_apic_base(X86_CPU(cpu
)->apic_state
);
681 case MSR_IA32_UCODE_REV
:
682 val
= x86_cpu
->ucode_rev
;
685 val
= rvmcs(cpu
->hvf
->fd
, VMCS_GUEST_IA32_EFER
);
688 val
= rvmcs(cpu
->hvf
->fd
, VMCS_GUEST_FS_BASE
);
691 val
= rvmcs(cpu
->hvf
->fd
, VMCS_GUEST_GS_BASE
);
693 case MSR_KERNELGSBASE
:
694 val
= rvmcs(cpu
->hvf
->fd
, VMCS_HOST_FS_BASE
);
705 case MSR_IA32_MISC_ENABLE
:
706 val
= env
->msr_ia32_misc_enable
;
708 case MSR_MTRRphysBase(0):
709 case MSR_MTRRphysBase(1):
710 case MSR_MTRRphysBase(2):
711 case MSR_MTRRphysBase(3):
712 case MSR_MTRRphysBase(4):
713 case MSR_MTRRphysBase(5):
714 case MSR_MTRRphysBase(6):
715 case MSR_MTRRphysBase(7):
716 val
= env
->mtrr_var
[(ECX(env
) - MSR_MTRRphysBase(0)) / 2].base
;
718 case MSR_MTRRphysMask(0):
719 case MSR_MTRRphysMask(1):
720 case MSR_MTRRphysMask(2):
721 case MSR_MTRRphysMask(3):
722 case MSR_MTRRphysMask(4):
723 case MSR_MTRRphysMask(5):
724 case MSR_MTRRphysMask(6):
725 case MSR_MTRRphysMask(7):
726 val
= env
->mtrr_var
[(ECX(env
) - MSR_MTRRphysMask(0)) / 2].mask
;
728 case MSR_MTRRfix64K_00000
:
729 val
= env
->mtrr_fixed
[0];
731 case MSR_MTRRfix16K_80000
:
732 case MSR_MTRRfix16K_A0000
:
733 val
= env
->mtrr_fixed
[ECX(env
) - MSR_MTRRfix16K_80000
+ 1];
735 case MSR_MTRRfix4K_C0000
:
736 case MSR_MTRRfix4K_C8000
:
737 case MSR_MTRRfix4K_D0000
:
738 case MSR_MTRRfix4K_D8000
:
739 case MSR_MTRRfix4K_E0000
:
740 case MSR_MTRRfix4K_E8000
:
741 case MSR_MTRRfix4K_F0000
:
742 case MSR_MTRRfix4K_F8000
:
743 val
= env
->mtrr_fixed
[ECX(env
) - MSR_MTRRfix4K_C0000
+ 3];
745 case MSR_MTRRdefType
:
746 val
= env
->mtrr_deftype
;
748 case MSR_CORE_THREAD_COUNT
:
749 val
= cs
->nr_threads
* cs
->nr_cores
; /* thread count, bits 15..0 */
750 val
|= ((uint32_t)cs
->nr_cores
<< 16); /* core count, bits 31..16 */
753 /* fprintf(stderr, "%s: unknown msr 0x%x\n", __func__, msr); */
758 RAX(env
) = (uint32_t)val
;
759 RDX(env
) = (uint32_t)(val
>> 32);
762 static void exec_rdmsr(CPUX86State
*env
, struct x86_decode
*decode
)
764 simulate_rdmsr(env_cpu(env
));
765 env
->eip
+= decode
->len
;
768 void simulate_wrmsr(struct CPUState
*cpu
)
770 X86CPU
*x86_cpu
= X86_CPU(cpu
);
771 CPUX86State
*env
= &x86_cpu
->env
;
772 uint32_t msr
= ECX(env
);
773 uint64_t data
= ((uint64_t)EDX(env
) << 32) | EAX(env
);
778 case MSR_IA32_APICBASE
:
779 cpu_set_apic_base(X86_CPU(cpu
)->apic_state
, data
);
782 wvmcs(cpu
->hvf
->fd
, VMCS_GUEST_FS_BASE
, data
);
785 wvmcs(cpu
->hvf
->fd
, VMCS_GUEST_GS_BASE
, data
);
787 case MSR_KERNELGSBASE
:
788 wvmcs(cpu
->hvf
->fd
, VMCS_HOST_FS_BASE
, data
);
800 /*printf("new efer %llx\n", EFER(cpu));*/
801 wvmcs(cpu
->hvf
->fd
, VMCS_GUEST_IA32_EFER
, data
);
802 if (data
& MSR_EFER_NXE
) {
803 hv_vcpu_invalidate_tlb(cpu
->hvf
->fd
);
806 case MSR_MTRRphysBase(0):
807 case MSR_MTRRphysBase(1):
808 case MSR_MTRRphysBase(2):
809 case MSR_MTRRphysBase(3):
810 case MSR_MTRRphysBase(4):
811 case MSR_MTRRphysBase(5):
812 case MSR_MTRRphysBase(6):
813 case MSR_MTRRphysBase(7):
814 env
->mtrr_var
[(ECX(env
) - MSR_MTRRphysBase(0)) / 2].base
= data
;
816 case MSR_MTRRphysMask(0):
817 case MSR_MTRRphysMask(1):
818 case MSR_MTRRphysMask(2):
819 case MSR_MTRRphysMask(3):
820 case MSR_MTRRphysMask(4):
821 case MSR_MTRRphysMask(5):
822 case MSR_MTRRphysMask(6):
823 case MSR_MTRRphysMask(7):
824 env
->mtrr_var
[(ECX(env
) - MSR_MTRRphysMask(0)) / 2].mask
= data
;
826 case MSR_MTRRfix64K_00000
:
827 env
->mtrr_fixed
[ECX(env
) - MSR_MTRRfix64K_00000
] = data
;
829 case MSR_MTRRfix16K_80000
:
830 case MSR_MTRRfix16K_A0000
:
831 env
->mtrr_fixed
[ECX(env
) - MSR_MTRRfix16K_80000
+ 1] = data
;
833 case MSR_MTRRfix4K_C0000
:
834 case MSR_MTRRfix4K_C8000
:
835 case MSR_MTRRfix4K_D0000
:
836 case MSR_MTRRfix4K_D8000
:
837 case MSR_MTRRfix4K_E0000
:
838 case MSR_MTRRfix4K_E8000
:
839 case MSR_MTRRfix4K_F0000
:
840 case MSR_MTRRfix4K_F8000
:
841 env
->mtrr_fixed
[ECX(env
) - MSR_MTRRfix4K_C0000
+ 3] = data
;
843 case MSR_MTRRdefType
:
844 env
->mtrr_deftype
= data
;
850 /* Related to support known hypervisor interface */
851 /* if (g_hypervisor_iface)
852 g_hypervisor_iface->wrmsr_handler(cpu, msr, data);
854 printf("write msr %llx\n", RCX(cpu));*/
857 static void exec_wrmsr(CPUX86State
*env
, struct x86_decode
*decode
)
859 simulate_wrmsr(env_cpu(env
));
860 env
->eip
+= decode
->len
;
865 * 0 - bt, 1 - btc, 2 - bts, 3 - btr
867 static void do_bt(CPUX86State
*env
, struct x86_decode
*decode
, int flag
)
869 int32_t displacement
;
872 int mask
= (4 == decode
->operand_size
) ? 0x1f : 0xf;
874 VM_PANIC_ON(decode
->rex
.rex
);
876 fetch_operands(env
, decode
, 2, false, true, false);
877 index
= decode
->op
[1].val
& mask
;
879 if (decode
->op
[0].type
!= X86_VAR_REG
) {
880 if (4 == decode
->operand_size
) {
881 displacement
= ((int32_t) (decode
->op
[1].val
& 0xffffffe0)) / 32;
882 decode
->op
[0].ptr
+= 4 * displacement
;
883 } else if (2 == decode
->operand_size
) {
884 displacement
= ((int16_t) (decode
->op
[1].val
& 0xfff0)) / 16;
885 decode
->op
[0].ptr
+= 2 * displacement
;
887 VM_PANIC("bt 64bit\n");
890 decode
->op
[0].val
= read_val_ext(env
, decode
->op
[0].ptr
,
891 decode
->operand_size
);
892 cf
= (decode
->op
[0].val
>> index
) & 0x01;
899 decode
->op
[0].val
^= (1u << index
);
902 decode
->op
[0].val
|= (1u << index
);
905 decode
->op
[0].val
&= ~(1u << index
);
908 write_val_ext(env
, decode
->op
[0].ptr
, decode
->op
[0].val
,
909 decode
->operand_size
);
913 static void exec_bt(CPUX86State
*env
, struct x86_decode
*decode
)
915 do_bt(env
, decode
, 0);
916 env
->eip
+= decode
->len
;
919 static void exec_btc(CPUX86State
*env
, struct x86_decode
*decode
)
921 do_bt(env
, decode
, 1);
922 env
->eip
+= decode
->len
;
925 static void exec_btr(CPUX86State
*env
, struct x86_decode
*decode
)
927 do_bt(env
, decode
, 3);
928 env
->eip
+= decode
->len
;
931 static void exec_bts(CPUX86State
*env
, struct x86_decode
*decode
)
933 do_bt(env
, decode
, 2);
934 env
->eip
+= decode
->len
;
937 void exec_shl(CPUX86State
*env
, struct x86_decode
*decode
)
942 fetch_operands(env
, decode
, 2, true, true, false);
944 count
= decode
->op
[1].val
;
945 count
&= 0x1f; /* count is masked to 5 bits*/
950 switch (decode
->operand_size
) {
955 res
= (decode
->op
[0].val
<< count
);
956 cf
= (decode
->op
[0].val
>> (8 - count
)) & 0x1;
957 of
= cf
^ (res
>> 7);
960 write_val_ext(env
, decode
->op
[0].ptr
, res
, 1);
961 SET_FLAGS_OSZAPC_LOGIC8(env
, 0, 0, res
);
962 SET_FLAGS_OxxxxC(env
, of
, cf
);
971 res
= (decode
->op
[0].val
<< count
);
972 cf
= (decode
->op
[0].val
>> (16 - count
)) & 0x1;
973 of
= cf
^ (res
>> 15); /* of = cf ^ result15 */
976 write_val_ext(env
, decode
->op
[0].ptr
, res
, 2);
977 SET_FLAGS_OSZAPC_LOGIC16(env
, 0, 0, res
);
978 SET_FLAGS_OxxxxC(env
, of
, cf
);
983 uint32_t res
= decode
->op
[0].val
<< count
;
985 write_val_ext(env
, decode
->op
[0].ptr
, res
, 4);
986 SET_FLAGS_OSZAPC_LOGIC32(env
, 0, 0, res
);
987 cf
= (decode
->op
[0].val
>> (32 - count
)) & 0x1;
988 of
= cf
^ (res
>> 31); /* of = cf ^ result31 */
989 SET_FLAGS_OxxxxC(env
, of
, cf
);
997 /* lflags_to_rflags(env); */
998 env
->eip
+= decode
->len
;
1001 void exec_movsx(CPUX86State
*env
, struct x86_decode
*decode
)
1004 int op_size
= decode
->operand_size
;
1006 fetch_operands(env
, decode
, 2, false, false, false);
1008 if (0xbe == decode
->opcode
[1]) {
1014 decode
->operand_size
= src_op_size
;
1015 calc_modrm_operand(env
, decode
, &decode
->op
[1]);
1016 decode
->op
[1].val
= sign(read_val_ext(env
, decode
->op
[1].ptr
, src_op_size
),
1019 write_val_ext(env
, decode
->op
[0].ptr
, decode
->op
[1].val
, op_size
);
1021 env
->eip
+= decode
->len
;
1024 void exec_ror(CPUX86State
*env
, struct x86_decode
*decode
)
1028 fetch_operands(env
, decode
, 2, true, true, false);
1029 count
= decode
->op
[1].val
;
1031 switch (decode
->operand_size
) {
1034 uint32_t bit6
, bit7
;
1037 if ((count
& 0x07) == 0) {
1039 bit6
= ((uint8_t)decode
->op
[0].val
>> 6) & 1;
1040 bit7
= ((uint8_t)decode
->op
[0].val
>> 7) & 1;
1041 SET_FLAGS_OxxxxC(env
, bit6
^ bit7
, bit7
);
1044 count
&= 0x7; /* use only bottom 3 bits */
1045 res
= ((uint8_t)decode
->op
[0].val
>> count
) |
1046 ((uint8_t)decode
->op
[0].val
<< (8 - count
));
1047 write_val_ext(env
, decode
->op
[0].ptr
, res
, 1);
1048 bit6
= (res
>> 6) & 1;
1049 bit7
= (res
>> 7) & 1;
1050 /* set eflags: ROR count affects the following flags: C, O */
1051 SET_FLAGS_OxxxxC(env
, bit6
^ bit7
, bit7
);
1057 uint32_t bit14
, bit15
;
1060 if ((count
& 0x0f) == 0) {
1062 bit14
= ((uint16_t)decode
->op
[0].val
>> 14) & 1;
1063 bit15
= ((uint16_t)decode
->op
[0].val
>> 15) & 1;
1064 /* of = result14 ^ result15 */
1065 SET_FLAGS_OxxxxC(env
, bit14
^ bit15
, bit15
);
1068 count
&= 0x0f; /* use only 4 LSB's */
1069 res
= ((uint16_t)decode
->op
[0].val
>> count
) |
1070 ((uint16_t)decode
->op
[0].val
<< (16 - count
));
1071 write_val_ext(env
, decode
->op
[0].ptr
, res
, 2);
1073 bit14
= (res
>> 14) & 1;
1074 bit15
= (res
>> 15) & 1;
1075 /* of = result14 ^ result15 */
1076 SET_FLAGS_OxxxxC(env
, bit14
^ bit15
, bit15
);
1082 uint32_t bit31
, bit30
;
1087 res
= ((uint32_t)decode
->op
[0].val
>> count
) |
1088 ((uint32_t)decode
->op
[0].val
<< (32 - count
));
1089 write_val_ext(env
, decode
->op
[0].ptr
, res
, 4);
1091 bit31
= (res
>> 31) & 1;
1092 bit30
= (res
>> 30) & 1;
1093 /* of = result30 ^ result31 */
1094 SET_FLAGS_OxxxxC(env
, bit30
^ bit31
, bit31
);
1099 env
->eip
+= decode
->len
;
1102 void exec_rol(CPUX86State
*env
, struct x86_decode
*decode
)
1106 fetch_operands(env
, decode
, 2, true, true, false);
1107 count
= decode
->op
[1].val
;
1109 switch (decode
->operand_size
) {
1112 uint32_t bit0
, bit7
;
1115 if ((count
& 0x07) == 0) {
1117 bit0
= ((uint8_t)decode
->op
[0].val
& 1);
1118 bit7
= ((uint8_t)decode
->op
[0].val
>> 7);
1119 SET_FLAGS_OxxxxC(env
, bit0
^ bit7
, bit0
);
1122 count
&= 0x7; /* use only lowest 3 bits */
1123 res
= ((uint8_t)decode
->op
[0].val
<< count
) |
1124 ((uint8_t)decode
->op
[0].val
>> (8 - count
));
1126 write_val_ext(env
, decode
->op
[0].ptr
, res
, 1);
1128 * ROL count affects the following flags: C, O
1132 SET_FLAGS_OxxxxC(env
, bit0
^ bit7
, bit0
);
1138 uint32_t bit0
, bit15
;
1141 if ((count
& 0x0f) == 0) {
1143 bit0
= ((uint16_t)decode
->op
[0].val
& 0x1);
1144 bit15
= ((uint16_t)decode
->op
[0].val
>> 15);
1145 /* of = cf ^ result15 */
1146 SET_FLAGS_OxxxxC(env
, bit0
^ bit15
, bit0
);
1149 count
&= 0x0f; /* only use bottom 4 bits */
1150 res
= ((uint16_t)decode
->op
[0].val
<< count
) |
1151 ((uint16_t)decode
->op
[0].val
>> (16 - count
));
1153 write_val_ext(env
, decode
->op
[0].ptr
, res
, 2);
1155 bit15
= (res
>> 15);
1156 /* of = cf ^ result15 */
1157 SET_FLAGS_OxxxxC(env
, bit0
^ bit15
, bit0
);
1163 uint32_t bit0
, bit31
;
1168 res
= ((uint32_t)decode
->op
[0].val
<< count
) |
1169 ((uint32_t)decode
->op
[0].val
>> (32 - count
));
1171 write_val_ext(env
, decode
->op
[0].ptr
, res
, 4);
1173 bit31
= (res
>> 31);
1174 /* of = cf ^ result31 */
1175 SET_FLAGS_OxxxxC(env
, bit0
^ bit31
, bit0
);
1180 env
->eip
+= decode
->len
;
1184 void exec_rcl(CPUX86State
*env
, struct x86_decode
*decode
)
1189 fetch_operands(env
, decode
, 2, true, true, false);
1190 count
= decode
->op
[1].val
& 0x1f;
1192 switch (decode
->operand_size
) {
1195 uint8_t op1_8
= decode
->op
[0].val
;
1203 res
= (op1_8
<< 1) | get_CF(env
);
1205 res
= (op1_8
<< count
) | (get_CF(env
) << (count
- 1)) |
1206 (op1_8
>> (9 - count
));
1209 write_val_ext(env
, decode
->op
[0].ptr
, res
, 1);
1211 cf
= (op1_8
>> (8 - count
)) & 0x01;
1212 of
= cf
^ (res
>> 7); /* of = cf ^ result7 */
1213 SET_FLAGS_OxxxxC(env
, of
, cf
);
1219 uint16_t op1_16
= decode
->op
[0].val
;
1227 res
= (op1_16
<< 1) | get_CF(env
);
1228 } else if (count
== 16) {
1229 res
= (get_CF(env
) << 15) | (op1_16
>> 1);
1230 } else { /* 2..15 */
1231 res
= (op1_16
<< count
) | (get_CF(env
) << (count
- 1)) |
1232 (op1_16
>> (17 - count
));
1235 write_val_ext(env
, decode
->op
[0].ptr
, res
, 2);
1237 cf
= (op1_16
>> (16 - count
)) & 0x1;
1238 of
= cf
^ (res
>> 15); /* of = cf ^ result15 */
1239 SET_FLAGS_OxxxxC(env
, of
, cf
);
1245 uint32_t op1_32
= decode
->op
[0].val
;
1252 res
= (op1_32
<< 1) | get_CF(env
);
1254 res
= (op1_32
<< count
) | (get_CF(env
) << (count
- 1)) |
1255 (op1_32
>> (33 - count
));
1258 write_val_ext(env
, decode
->op
[0].ptr
, res
, 4);
1260 cf
= (op1_32
>> (32 - count
)) & 0x1;
1261 of
= cf
^ (res
>> 31); /* of = cf ^ result31 */
1262 SET_FLAGS_OxxxxC(env
, of
, cf
);
1266 env
->eip
+= decode
->len
;
1269 void exec_rcr(CPUX86State
*env
, struct x86_decode
*decode
)
1274 fetch_operands(env
, decode
, 2, true, true, false);
1275 count
= decode
->op
[1].val
& 0x1f;
1277 switch (decode
->operand_size
) {
1280 uint8_t op1_8
= decode
->op
[0].val
;
1287 res
= (op1_8
>> count
) | (get_CF(env
) << (8 - count
)) |
1288 (op1_8
<< (9 - count
));
1290 write_val_ext(env
, decode
->op
[0].ptr
, res
, 1);
1292 cf
= (op1_8
>> (count
- 1)) & 0x1;
1293 of
= (((res
<< 1) ^ res
) >> 7) & 0x1; /* of = result6 ^ result7 */
1294 SET_FLAGS_OxxxxC(env
, of
, cf
);
1299 uint16_t op1_16
= decode
->op
[0].val
;
1306 res
= (op1_16
>> count
) | (get_CF(env
) << (16 - count
)) |
1307 (op1_16
<< (17 - count
));
1309 write_val_ext(env
, decode
->op
[0].ptr
, res
, 2);
1311 cf
= (op1_16
>> (count
- 1)) & 0x1;
1312 of
= ((uint16_t)((res
<< 1) ^ res
) >> 15) & 0x1; /* of = result15 ^
1314 SET_FLAGS_OxxxxC(env
, of
, cf
);
1320 uint32_t op1_32
= decode
->op
[0].val
;
1327 res
= (op1_32
>> 1) | (get_CF(env
) << 31);
1329 res
= (op1_32
>> count
) | (get_CF(env
) << (32 - count
)) |
1330 (op1_32
<< (33 - count
));
1333 write_val_ext(env
, decode
->op
[0].ptr
, res
, 4);
1335 cf
= (op1_32
>> (count
- 1)) & 0x1;
1336 of
= ((res
<< 1) ^ res
) >> 31; /* of = result30 ^ result31 */
1337 SET_FLAGS_OxxxxC(env
, of
, cf
);
1341 env
->eip
+= decode
->len
;
1344 static void exec_xchg(CPUX86State
*env
, struct x86_decode
*decode
)
1346 fetch_operands(env
, decode
, 2, true, true, false);
1348 write_val_ext(env
, decode
->op
[0].ptr
, decode
->op
[1].val
,
1349 decode
->operand_size
);
1350 write_val_ext(env
, decode
->op
[1].ptr
, decode
->op
[0].val
,
1351 decode
->operand_size
);
1353 env
->eip
+= decode
->len
;
1356 static void exec_xadd(CPUX86State
*env
, struct x86_decode
*decode
)
1358 EXEC_2OP_FLAGS_CMD(env
, decode
, +, SET_FLAGS_OSZAPC_ADD
, true);
1359 write_val_ext(env
, decode
->op
[1].ptr
, decode
->op
[0].val
,
1360 decode
->operand_size
);
1362 env
->eip
+= decode
->len
;
1365 static struct cmd_handler
{
1366 enum x86_decode_cmd cmd
;
1367 void (*handler
)(CPUX86State
*env
, struct x86_decode
*ins
);
1369 {X86_DECODE_CMD_INVL
, NULL
,},
1370 {X86_DECODE_CMD_MOV
, exec_mov
},
1371 {X86_DECODE_CMD_ADD
, exec_add
},
1372 {X86_DECODE_CMD_OR
, exec_or
},
1373 {X86_DECODE_CMD_ADC
, exec_adc
},
1374 {X86_DECODE_CMD_SBB
, exec_sbb
},
1375 {X86_DECODE_CMD_AND
, exec_and
},
1376 {X86_DECODE_CMD_SUB
, exec_sub
},
1377 {X86_DECODE_CMD_NEG
, exec_neg
},
1378 {X86_DECODE_CMD_XOR
, exec_xor
},
1379 {X86_DECODE_CMD_CMP
, exec_cmp
},
1380 {X86_DECODE_CMD_INC
, exec_inc
},
1381 {X86_DECODE_CMD_DEC
, exec_dec
},
1382 {X86_DECODE_CMD_TST
, exec_tst
},
1383 {X86_DECODE_CMD_NOT
, exec_not
},
1384 {X86_DECODE_CMD_MOVZX
, exec_movzx
},
1385 {X86_DECODE_CMD_OUT
, exec_out
},
1386 {X86_DECODE_CMD_IN
, exec_in
},
1387 {X86_DECODE_CMD_INS
, exec_ins
},
1388 {X86_DECODE_CMD_OUTS
, exec_outs
},
1389 {X86_DECODE_CMD_RDMSR
, exec_rdmsr
},
1390 {X86_DECODE_CMD_WRMSR
, exec_wrmsr
},
1391 {X86_DECODE_CMD_BT
, exec_bt
},
1392 {X86_DECODE_CMD_BTR
, exec_btr
},
1393 {X86_DECODE_CMD_BTC
, exec_btc
},
1394 {X86_DECODE_CMD_BTS
, exec_bts
},
1395 {X86_DECODE_CMD_SHL
, exec_shl
},
1396 {X86_DECODE_CMD_ROL
, exec_rol
},
1397 {X86_DECODE_CMD_ROR
, exec_ror
},
1398 {X86_DECODE_CMD_RCR
, exec_rcr
},
1399 {X86_DECODE_CMD_RCL
, exec_rcl
},
1400 /*{X86_DECODE_CMD_CPUID, exec_cpuid},*/
1401 {X86_DECODE_CMD_MOVS
, exec_movs
},
1402 {X86_DECODE_CMD_CMPS
, exec_cmps
},
1403 {X86_DECODE_CMD_STOS
, exec_stos
},
1404 {X86_DECODE_CMD_SCAS
, exec_scas
},
1405 {X86_DECODE_CMD_LODS
, exec_lods
},
1406 {X86_DECODE_CMD_MOVSX
, exec_movsx
},
1407 {X86_DECODE_CMD_XCHG
, exec_xchg
},
1408 {X86_DECODE_CMD_XADD
, exec_xadd
},
1411 static struct cmd_handler _cmd_handler
[X86_DECODE_CMD_LAST
];
1413 static void init_cmd_handler()
1416 for (i
= 0; i
< ARRAY_SIZE(handlers
); i
++) {
1417 _cmd_handler
[handlers
[i
].cmd
] = handlers
[i
];
1421 void load_regs(struct CPUState
*cpu
)
1423 X86CPU
*x86_cpu
= X86_CPU(cpu
);
1424 CPUX86State
*env
= &x86_cpu
->env
;
1427 RRX(env
, R_EAX
) = rreg(cpu
->hvf
->fd
, HV_X86_RAX
);
1428 RRX(env
, R_EBX
) = rreg(cpu
->hvf
->fd
, HV_X86_RBX
);
1429 RRX(env
, R_ECX
) = rreg(cpu
->hvf
->fd
, HV_X86_RCX
);
1430 RRX(env
, R_EDX
) = rreg(cpu
->hvf
->fd
, HV_X86_RDX
);
1431 RRX(env
, R_ESI
) = rreg(cpu
->hvf
->fd
, HV_X86_RSI
);
1432 RRX(env
, R_EDI
) = rreg(cpu
->hvf
->fd
, HV_X86_RDI
);
1433 RRX(env
, R_ESP
) = rreg(cpu
->hvf
->fd
, HV_X86_RSP
);
1434 RRX(env
, R_EBP
) = rreg(cpu
->hvf
->fd
, HV_X86_RBP
);
1435 for (i
= 8; i
< 16; i
++) {
1436 RRX(env
, i
) = rreg(cpu
->hvf
->fd
, HV_X86_RAX
+ i
);
1439 env
->eflags
= rreg(cpu
->hvf
->fd
, HV_X86_RFLAGS
);
1440 rflags_to_lflags(env
);
1441 env
->eip
= rreg(cpu
->hvf
->fd
, HV_X86_RIP
);
1444 void store_regs(struct CPUState
*cpu
)
1446 X86CPU
*x86_cpu
= X86_CPU(cpu
);
1447 CPUX86State
*env
= &x86_cpu
->env
;
1450 wreg(cpu
->hvf
->fd
, HV_X86_RAX
, RAX(env
));
1451 wreg(cpu
->hvf
->fd
, HV_X86_RBX
, RBX(env
));
1452 wreg(cpu
->hvf
->fd
, HV_X86_RCX
, RCX(env
));
1453 wreg(cpu
->hvf
->fd
, HV_X86_RDX
, RDX(env
));
1454 wreg(cpu
->hvf
->fd
, HV_X86_RSI
, RSI(env
));
1455 wreg(cpu
->hvf
->fd
, HV_X86_RDI
, RDI(env
));
1456 wreg(cpu
->hvf
->fd
, HV_X86_RBP
, RBP(env
));
1457 wreg(cpu
->hvf
->fd
, HV_X86_RSP
, RSP(env
));
1458 for (i
= 8; i
< 16; i
++) {
1459 wreg(cpu
->hvf
->fd
, HV_X86_RAX
+ i
, RRX(env
, i
));
1462 lflags_to_rflags(env
);
1463 wreg(cpu
->hvf
->fd
, HV_X86_RFLAGS
, env
->eflags
);
1464 macvm_set_rip(cpu
, env
->eip
);
1467 bool exec_instruction(CPUX86State
*env
, struct x86_decode
*ins
)
1469 /*if (hvf_vcpu_id(cpu))
1470 printf("%d, %llx: exec_instruction %s\n", hvf_vcpu_id(cpu), env->eip,
1471 decode_cmd_to_string(ins->cmd));*/
1473 if (!_cmd_handler
[ins
->cmd
].handler
) {
1474 printf("Unimplemented handler (%llx) for %d (%x %x) \n", env
->eip
,
1475 ins
->cmd
, ins
->opcode
[0],
1476 ins
->opcode_len
> 1 ? ins
->opcode
[1] : 0);
1477 env
->eip
+= ins
->len
;
1481 _cmd_handler
[ins
->cmd
].handler(env
, ins
);