From 2c70359ad01055d32d78a1d0aa8b0dcbd5fc73ed Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20Balv=C3=ADn?= Date: Wed, 7 Oct 2026 12:57:14 +0200 Subject: [PATCH] feat(disasm): name the amd64 encodings x86asm refuses The toolchain's assembler corpus carries 195 amd64 encodings the x/arch decoder rejects or degenerates: the BMI1/BMI2 VEX families (ANDN, BEXTR, BLSI, BLSMSK, BLSR, BZHI, MULX, PDEP, PEXT, RORX, SARX, SHLX, SHRX), the 0F 01 quartet CLAC, STAC, RDPKRU and WRPKRU, the bare and REX-only RDSEED forms, and UD1. The supplementary naming table decodes the VEX prefix and the ModR/M shape and renders the toolchain's own spellings; every corpus row is pinned in the unlisted fixture and round-trips byte for byte through the encoder, and the boundary test pins the prefix shapes no family carries. Assisted-by: GLM 5.3 --- disasm/naming_amd64.go | 177 ++++++++++++++++++-- disasm/naming_amd64_test.go | 63 ++++++- disasm/testdata/parity_amd64_unlisted.txt | 195 ++++++++++++++++++++++ 3 files changed, 419 insertions(+), 16 deletions(-) diff --git a/disasm/naming_amd64.go b/disasm/naming_amd64.go index 57b3ee2..9d94334 100644 --- a/disasm/naming_amd64.go +++ b/disasm/naming_amd64.go @@ -194,7 +194,18 @@ func (rm amd64RM) text() string { // Unmatched bytes keep the renderer's own placeholder output. func nameAMD64Degenerate(code []byte) (string, int, bool) { p, ok := scanAMD64Prefixes(code) - if !ok || len(code) < p.n+3 || code[p.n] != 0x0f { + if !ok || len(code) < p.n+2 || code[p.n] != 0x0f { + return "", 0, false + } + // UD1, the second undefined-instruction opcode: the toolchain's table + // carries it with no operands, exactly two bytes, so the listing + // consumes nothing behind them. Any bytes that follow belong to the + // next instruction. + if code[p.n+1] == 0xb9 && + !p.osz && !p.rep && !p.repne && !p.rexW && !p.rexR && !p.rexX && !p.rexB { + return "UD1", p.n + 2, true + } + if len(code) < p.n+3 { return "", 0, false } tail := code[p.n+1:] @@ -320,22 +331,166 @@ func nameAMD64Endbr(p amd64Prefixes, tail []byte) (string, int, bool) { } // nameAMD64Rejected names an amd64 encoding the decoder refuses outright, -// one family at a time as the corpus rows land. CLDEMOTE, NP 0F 1C /r -// with a memory operand, is the first: the toolchain's own table carries -// it as a memory-only instruction, and the decoder rejects the encoding -// instead of naming it. The register forms of the same opcode are the -// hint NOPs the corpus does not spell, and they stay rejected. +// one family at a time as the corpus rows land. Three kinds live here: +// CLDEMOTE, NP 0F 1C /r with a memory operand, the toolchain's own table +// being a memory-only instruction while the decoder rejects the encoding; +// the register forms of the same opcode are the hint NOPs the corpus does +// not spell, and they stay rejected. The 0F 01 pair CLAC/STAC and the +// protection-key pair RDPKRU/WRPKRU, fixed three-byte encodings no ModR/M +// shape distinguishes, which the decoder rejects although the corpus +// assembles them. And the BMI1/BMI2 VEX families below. func nameAMD64Rejected(code []byte) (string, int, bool) { p, ok := scanAMD64Prefixes(code) if !ok || p.osz || p.rep || p.repne { return "", 0, false } - if len(code) < p.n+3 || code[p.n] != 0x0f || code[p.n+1] != 0x1c { + if p.n == 0 && len(code) > 0 && code[0] == 0xc4 { + return nameAMD64VEX(code) + } + if len(code) < p.n+3 || code[p.n] != 0x0f { return "", 0, false } - rm, ok := decodeAMD64RM(code[p.n+2:], p.rexR, p.rexX, p.rexB) - if !ok || rm.regForm { - return "", 0, false + switch code[p.n+1] { + case 0x1c: + rm, ok := decodeAMD64RM(code[p.n+2:], p.rexR, p.rexX, p.rexB) + if !ok || rm.regForm { + return "", 0, false + } + return "CLDEMOTE " + rm.text(), p.n + 2 + rm.n, true + case 0x01: + if !p.rexW && !p.rexR && !p.rexX && !p.rexB { + switch code[p.n+2] { + case 0xca: + return "CLAC", p.n + 3, true + case 0xcb: + return "STAC", p.n + 3, true + case 0xee: + return "RDPKRU", p.n + 3, true + case 0xef: + return "WRPKRU", p.n + 3, true + } + } + case 0xc7: + // The error branch of the RDSEED family: the operand-size and + // rep forms come back degenerate (handled above), while the + // bare and REX-only forms are refused outright. + if !p.rexR && !p.rexX { + return nameAMD64RNG(p, code[p.n+2:]) + } } - return "CLDEMOTE " + rm.text(), p.n + 2 + rm.n, true + return "", 0, false +} + +// amd64VEX is the reading of one three-byte VEX prefix, C4 rx bm wlpp. +// REX extension, the escaped opcode map and the payload byte are decoded +// once here; the families below are keyed on the pieces. +type amd64VEX struct { + r, x, b bool // register-extension bits, REX-style + w bool // operand-width bit + vvvv int // the inverted operand-register field + l bool // vector-length bit, clear in every GPR family + pp int // the legacy-prefix selector + m int // the escaped opcode map, 2 for 0F38 and 3 for 0F3A + n int // bytes consumed: C4 plus its two payload bytes +} + +// parseAMD64VEX reads the C4 prefix at the start of code. A two-byte C5 +// VEX is not read: every corpus family here is three-byte. +func parseAMD64VEX(code []byte) (amd64VEX, bool) { + var v amd64VEX + if len(code) < 4 || code[0] != 0xc4 { + return v, false + } + b1, b2 := code[1], code[2] + v.r = b1&0x80 == 0 + v.x = b1&0x40 == 0 + v.b = b1&0x20 == 0 + v.m = int(b1 & 0x1f) + v.w = b2&0x80 != 0 + v.vvvv = int(^b2>>3) & 15 + v.l = b2&0x04 != 0 + v.pp = int(b2 & 0x03) + v.n = 3 + return v, true +} + +// nameAMD64VEX names the BMI1/BMI2 general-purpose VEX families the decoder +// refuses with "unknown AVX Opcode". Every family is pinned to the prefix +// selector, opcode map and operand arrangement the toolchain's corpus +// carries; a byte pattern outside those (the vector-length bit set, a +// different selector, a ModR/M reg field the family does not define) keeps +// the placeholder. +func nameAMD64VEX(code []byte) (string, int, bool) { + v, ok := parseAMD64VEX(code) + if !ok || v.l || v.m < 2 || v.m > 3 { + return "", 0, false + } + opcode := code[v.n] + rm, ok := decodeAMD64RM(code[v.n+1:], v.r, v.x, v.b) + if !ok { + return "", 0, false + } + suffix := "L" + if v.w { + suffix = "Q" + } + reg := amd64GPRNames[rm.reg] + vvvv := amd64GPRNames[v.vvvv] + + // Families on the 0F38 map. + if v.m == 2 { + switch { + case opcode == 0xf2 && v.pp == 0x0: + // ANDN rm, vvvv, reg. + return "ANDN" + suffix + " " + rm.text() + ", " + vvvv + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf3 && v.pp == 0x0: + // The three one-source pseudo-instructions share the + // opcode: the ModR/M reg field selects the family. + var name string + switch rm.reg { + case 1: + name = "BLSR" + case 2: + name = "BLSMSK" + case 3: + name = "BLSI" + } + if name == "" { + return "", 0, false + } + return name + suffix + " " + rm.text() + ", " + vvvv, v.n + 1 + rm.n, true + case opcode == 0xf5 && v.pp == 0x0: + // BZHI vvvv, rm, reg. + return "BZHI" + suffix + " " + vvvv + ", " + rm.text() + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf6 && v.pp == 0x3: + // MULX rm, vvvv, reg. + return "MULX" + suffix + " " + rm.text() + ", " + vvvv + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf5 && v.pp == 0x3: + // PDEP rm, vvvv, reg. + return "PDEP" + suffix + " " + rm.text() + ", " + vvvv + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf5 && v.pp == 0x2: + // PEXT rm, vvvv, reg. + return "PEXT" + suffix + " " + rm.text() + ", " + vvvv + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf7 && v.pp == 0x0: + // BEXTR vvvv, rm, reg. + return "BEXTR" + suffix + " " + vvvv + ", " + rm.text() + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf7 && v.pp == 0x2: + // SARX vvvv, rm, reg. + return "SARX" + suffix + " " + vvvv + ", " + rm.text() + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf7 && v.pp == 0x1: + // SHLX vvvv, rm, reg. + return "SHLX" + suffix + " " + vvvv + ", " + rm.text() + ", " + reg, v.n + 1 + rm.n, true + case opcode == 0xf7 && v.pp == 0x3: + // SHRX vvvv, rm, reg. + return "SHRX" + suffix + " " + vvvv + ", " + rm.text() + ", " + reg, v.n + 1 + rm.n, true + } + return "", 0, false + } + + // The 0F3A map: RORX $imm, rm, reg, with a dead vvvv field. + if opcode == 0xf0 && v.pp == 0x3 && v.vvvv == 0 && v.n+1+rm.n < len(code) { + imm := int8(code[v.n+1+rm.n]) + return fmt.Sprintf("RORX%s $%d, %s, %s", suffix, imm, rm.text(), reg), v.n + 2 + rm.n, true + } + return "", 0, false } diff --git a/disasm/naming_amd64_test.go b/disasm/naming_amd64_test.go index e994b46..fa6bd5e 100644 --- a/disasm/naming_amd64_test.go +++ b/disasm/naming_amd64_test.go @@ -80,6 +80,46 @@ func TestDegenerateNaming(t *testing.T) { // rejects the encoding outright; the table names it from the // bytes. {[]byte{0x0f, 0x1c, 0x03}, "CLDEMOTE 0(BX)"}, + // amd64enc.s: the BMI1/BMI2 VEX families the decoder refuses + // with "unknown AVX Opcode". One row per family and operand + // shape; every corpus row is pinned in the unlisted fixture. + {[]byte{0xc4, 0xe2, 0x30, 0xf2, 0x13}, "ANDNL 0(BX), R9, DX"}, + {[]byte{0xc4, 0xe2, 0x88, 0xf2, 0xd2}, "ANDNQ DX, R14, DX"}, + {[]byte{0xc4, 0xe2, 0x30, 0xf7, 0x13}, "BEXTRL R9, 0(BX), DX"}, + {[]byte{0xc4, 0x62, 0x88, 0xf7, 0xda}, "BEXTRQ R14, DX, R11"}, + {[]byte{0xc4, 0xe2, 0x30, 0xf3, 0x1b}, "BLSIL 0(BX), R9"}, + {[]byte{0xc4, 0xe2, 0x30, 0xf3, 0x13}, "BLSMSKL 0(BX), R9"}, + {[]byte{0xc4, 0xe2, 0x30, 0xf3, 0x0b}, "BLSRL 0(BX), R9"}, + {[]byte{0xc4, 0xe2, 0x88, 0xf3, 0xca}, "BLSRQ DX, R14"}, + {[]byte{0xc4, 0xe2, 0x30, 0xf5, 0x13}, "BZHIL R9, 0(BX), DX"}, + {[]byte{0xc4, 0x42, 0x88, 0xf5, 0xdb}, "BZHIQ R14, R11, R11"}, + {[]byte{0xc4, 0xe2, 0x33, 0xf6, 0x13}, "MULXL 0(BX), R9, DX"}, + {[]byte{0xc4, 0x62, 0x8b, 0xf6, 0xda}, "MULXQ DX, R14, R11"}, + {[]byte{0xc4, 0xe2, 0x33, 0xf5, 0x13}, "PDEPL 0(BX), R9, DX"}, + {[]byte{0xc4, 0xe2, 0x32, 0xf5, 0x13}, "PEXTL 0(BX), R9, DX"}, + {[]byte{0xc4, 0xe3, 0x7b, 0xf0, 0x13, 0x07}, "RORXL $7, 0(BX), DX"}, + {[]byte{0xc4, 0xe3, 0xfb, 0xf0, 0x10, 0xff}, "RORXQ $-1, 0(AX), DX"}, + {[]byte{0xc4, 0xe2, 0x32, 0xf7, 0x13}, "SARXL R9, 0(BX), DX"}, + {[]byte{0xc4, 0xe2, 0x31, 0xf7, 0x13}, "SHLXL R9, 0(BX), DX"}, + {[]byte{0xc4, 0xe2, 0x33, 0xf7, 0x13}, "SHRXL R9, 0(BX), DX"}, + {[]byte{0xc4, 0x42, 0x89, 0xf7, 0xdb}, "SHLXQ R14, R11, R11"}, + // amd64enc.s: CLAC // 0f01ca, STAC // 0f01cb, RDPKRU // 0f01ee + // and WRPKRU // 0f01ef; the decoder rejects the encodings. + {[]byte{0x0f, 0x01, 0xca}, "CLAC"}, + {[]byte{0x0f, 0x01, 0xcb}, "STAC"}, + {[]byte{0x0f, 0x01, 0xee}, "RDPKRU"}, + {[]byte{0x0f, 0x01, 0xef}, "WRPKRU"}, + // amd64enc.s: RDSEEDL DX // 0fc7fa and RDSEEDQ DX // 480fc7fa. + // The bare and REX-only forms are refused outright (the 66 and + // f3 forms above come back degenerate), so they are named in + // the rejected-encoding table. + {[]byte{0x0f, 0xc7, 0xfa}, "RDSEEDL DX"}, + {[]byte{0x41, 0x0f, 0xc7, 0xfb}, "RDSEEDL R11"}, + {[]byte{0x48, 0x0f, 0xc7, 0xfa}, "RDSEEDQ DX"}, + {[]byte{0x49, 0x0f, 0xc7, 0xfb}, "RDSEEDQ R11"}, + // amd64enc.s: UD1 // 0fb9, decoded with no error but the + // degenerate zero instruction. + {[]byte{0x0f, 0xb9}, "UD1"}, } { ins, err := Decode(arch.AMD64, tt.code, 0) if err != nil { @@ -105,14 +145,27 @@ func TestDegenerateNamingBoundaries(t *testing.T) { code []byte text string }{ - // Rejected outright: RDSEED without the operand-size override - // (the bare 0F C7 /7 register form), MONITORX and MWAITX, and - // the register form of the hint NOP opcode, which the corpus - // does not spell. - {[]byte{0x0f, 0xc7, 0xfa}, "???"}, + // Rejected outright: MONITORX and MWAITX, and the register + // form of the hint NOP opcode, which the corpus does not + // spell. {[]byte{0x0f, 0x01, 0xfa}, "???"}, {[]byte{0x0f, 0x01, 0xfb}, "???"}, {[]byte{0x0f, 0x1c, 0xc3}, "???"}, + // The 0F 01 family keeps its fixed three bytes: a REX prefix + // extends nothing the instructions carry. + {[]byte{0x41, 0x0f, 0x01, 0xca}, "???"}, + // The VEX families stay pinned to the corpus prefix shapes: + // the vector-length bit set (a reserved encoding in every GPR + // family), the operand-size selector on the ANDN opcode (the + // selector belongs to no F2 family), RORX with a live vvvv + // field (the toolchain keeps it dead), the BLS* selector + // outside its three defined reg fields, and the one-byte-map + // escape, which no family here uses. + {[]byte{0xc4, 0xe3, 0x34, 0xf2, 0x13}, "???"}, + {[]byte{0xc4, 0xe2, 0x31, 0xf2, 0x13}, "???"}, + {[]byte{0xc4, 0xe3, 0x63, 0xf0, 0x13, 0x07}, "???"}, + {[]byte{0xc4, 0xe2, 0x30, 0xf3, 0x03}, "???"}, + {[]byte{0xc4, 0xe1, 0x70, 0xf2, 0x13}, "???"}, // Degenerate but outside the table's prefix gates: repne ADCX is // no instruction the corpus names. {[]byte{0xf2, 0x0f, 0x38, 0xf6, 0xd2}, "REPNE; Op(0)"}, diff --git a/disasm/testdata/parity_amd64_unlisted.txt b/disasm/testdata/parity_amd64_unlisted.txt index 10b4c46..6958a44 100644 --- a/disasm/testdata/parity_amd64_unlisted.txt +++ b/disasm/testdata/parity_amd64_unlisted.txt @@ -1229,3 +1229,198 @@ f30faef3 UMONITOR BX f20faef3 UMWAIT BX f30f1efa ENDBR64 0f1c03 CLDEMOTE 0(BX) +c4e230f213 ANDNL 0(BX), R9, DX +c4c230f213 ANDNL 0(R11), R9, DX +c4e230f2d2 ANDNL DX, R9, DX +c4c230f2d3 ANDNL R11, R9, DX +c46230f21b ANDNL 0(BX), R9, R11 +c44230f21b ANDNL 0(R11), R9, R11 +c46230f2da ANDNL DX, R9, R11 +c44230f2db ANDNL R11, R9, R11 +c4e288f213 ANDNQ 0(BX), R14, DX +c4c288f213 ANDNQ 0(R11), R14, DX +c4e288f2d2 ANDNQ DX, R14, DX +c4c288f2d3 ANDNQ R11, R14, DX +c46288f21b ANDNQ 0(BX), R14, R11 +c44288f21b ANDNQ 0(R11), R14, R11 +c46288f2da ANDNQ DX, R14, R11 +c44288f2db ANDNQ R11, R14, R11 +c4e230f713 BEXTRL R9, 0(BX), DX +c4c230f713 BEXTRL R9, 0(R11), DX +c4e230f7d2 BEXTRL R9, DX, DX +c4c230f7d3 BEXTRL R9, R11, DX +c46230f71b BEXTRL R9, 0(BX), R11 +c44230f71b BEXTRL R9, 0(R11), R11 +c46230f7da BEXTRL R9, DX, R11 +c44230f7db BEXTRL R9, R11, R11 +c4e288f713 BEXTRQ R14, 0(BX), DX +c4c288f713 BEXTRQ R14, 0(R11), DX +c4e288f7d2 BEXTRQ R14, DX, DX +c4c288f7d3 BEXTRQ R14, R11, DX +c46288f71b BEXTRQ R14, 0(BX), R11 +c44288f71b BEXTRQ R14, 0(R11), R11 +c46288f7da BEXTRQ R14, DX, R11 +c44288f7db BEXTRQ R14, R11, R11 +c4e230f31b BLSIL 0(BX), R9 +c4c230f31b BLSIL 0(R11), R9 +c4e230f3da BLSIL DX, R9 +c4c230f3db BLSIL R11, R9 +c4e288f31b BLSIQ 0(BX), R14 +c4c288f31b BLSIQ 0(R11), R14 +c4e288f3da BLSIQ DX, R14 +c4c288f3db BLSIQ R11, R14 +c4e230f313 BLSMSKL 0(BX), R9 +c4c230f313 BLSMSKL 0(R11), R9 +c4e230f3d2 BLSMSKL DX, R9 +c4c230f3d3 BLSMSKL R11, R9 +c4e288f313 BLSMSKQ 0(BX), R14 +c4c288f313 BLSMSKQ 0(R11), R14 +c4e288f3d2 BLSMSKQ DX, R14 +c4c288f3d3 BLSMSKQ R11, R14 +c4e230f30b BLSRL 0(BX), R9 +c4c230f30b BLSRL 0(R11), R9 +c4e230f3ca BLSRL DX, R9 +c4c230f3cb BLSRL R11, R9 +c4e288f30b BLSRQ 0(BX), R14 +c4c288f30b BLSRQ 0(R11), R14 +c4e288f3ca BLSRQ DX, R14 +c4c288f3cb BLSRQ R11, R14 +c4e230f513 BZHIL R9, 0(BX), DX +c4c230f513 BZHIL R9, 0(R11), DX +c4e230f5d2 BZHIL R9, DX, DX +c4c230f5d3 BZHIL R9, R11, DX +c46230f51b BZHIL R9, 0(BX), R11 +c44230f51b BZHIL R9, 0(R11), R11 +c46230f5da BZHIL R9, DX, R11 +c44230f5db BZHIL R9, R11, R11 +c4e288f513 BZHIQ R14, 0(BX), DX +c4c288f513 BZHIQ R14, 0(R11), DX +c4e288f5d2 BZHIQ R14, DX, DX +c4c288f5d3 BZHIQ R14, R11, DX +c46288f51b BZHIQ R14, 0(BX), R11 +c44288f51b BZHIQ R14, 0(R11), R11 +c46288f5da BZHIQ R14, DX, R11 +c44288f5db BZHIQ R14, R11, R11 +0f01ca CLAC +c4e233f613 MULXL 0(BX), R9, DX +c4c233f613 MULXL 0(R11), R9, DX +c4e233f6d2 MULXL DX, R9, DX +c4c233f6d3 MULXL R11, R9, DX +c46233f61b MULXL 0(BX), R9, R11 +c44233f61b MULXL 0(R11), R9, R11 +c46233f6da MULXL DX, R9, R11 +c44233f6db MULXL R11, R9, R11 +c4e28bf613 MULXQ 0(BX), R14, DX +c4c28bf613 MULXQ 0(R11), R14, DX +c4e28bf6d2 MULXQ DX, R14, DX +c4c28bf6d3 MULXQ R11, R14, DX +c4628bf61b MULXQ 0(BX), R14, R11 +c4428bf61b MULXQ 0(R11), R14, R11 +c4628bf6da MULXQ DX, R14, R11 +c4428bf6db MULXQ R11, R14, R11 +c4e233f513 PDEPL 0(BX), R9, DX +c4c233f513 PDEPL 0(R11), R9, DX +c4e233f5d2 PDEPL DX, R9, DX +c4c233f5d3 PDEPL R11, R9, DX +c46233f51b PDEPL 0(BX), R9, R11 +c44233f51b PDEPL 0(R11), R9, R11 +c46233f5da PDEPL DX, R9, R11 +c44233f5db PDEPL R11, R9, R11 +c4e28bf513 PDEPQ 0(BX), R14, DX +c4c28bf513 PDEPQ 0(R11), R14, DX +c4e28bf5d2 PDEPQ DX, R14, DX +c4c28bf5d3 PDEPQ R11, R14, DX +c4628bf51b PDEPQ 0(BX), R14, R11 +c4428bf51b PDEPQ 0(R11), R14, R11 +c4628bf5da PDEPQ DX, R14, R11 +c4428bf5db PDEPQ R11, R14, R11 +c4e232f513 PEXTL 0(BX), R9, DX +c4c232f513 PEXTL 0(R11), R9, DX +c4e232f5d2 PEXTL DX, R9, DX +c4c232f5d3 PEXTL R11, R9, DX +c46232f51b PEXTL 0(BX), R9, R11 +c44232f51b PEXTL 0(R11), R9, R11 +c46232f5da PEXTL DX, R9, R11 +c44232f5db PEXTL R11, R9, R11 +c4e28af513 PEXTQ 0(BX), R14, DX +c4c28af513 PEXTQ 0(R11), R14, DX +c4e28af5d2 PEXTQ DX, R14, DX +c4c28af5d3 PEXTQ R11, R14, DX +c4628af51b PEXTQ 0(BX), R14, R11 +c4428af51b PEXTQ 0(R11), R14, R11 +c4628af5da PEXTQ DX, R14, R11 +c4428af5db PEXTQ R11, R14, R11 +0f01ee RDPKRU +0fc7fa RDSEEDL DX +410fc7fb RDSEEDL R11 +480fc7fa RDSEEDQ DX +490fc7fb RDSEEDQ R11 +c4e37bf01307 RORXL $7, 0(BX), DX +c4c37bf01307 RORXL $7, 0(R11), DX +c4e37bf0d207 RORXL $7, DX, DX +c4c37bf0d307 RORXL $7, R11, DX +c4637bf01b07 RORXL $7, 0(BX), R11 +c4437bf01b07 RORXL $7, 0(R11), R11 +c4637bf0da07 RORXL $7, DX, R11 +c4437bf0db07 RORXL $7, R11, R11 +c4e3fbf01307 RORXQ $7, 0(BX), DX +c4c3fbf01307 RORXQ $7, 0(R11), DX +c4e3fbf0d207 RORXQ $7, DX, DX +c4c3fbf0d307 RORXQ $7, R11, DX +c463fbf01b07 RORXQ $7, 0(BX), R11 +c443fbf01b07 RORXQ $7, 0(R11), R11 +c463fbf0da07 RORXQ $7, DX, R11 +c443fbf0db07 RORXQ $7, R11, R11 +c4e232f713 SARXL R9, 0(BX), DX +c4c232f713 SARXL R9, 0(R11), DX +c4e232f7d2 SARXL R9, DX, DX +c4c232f7d3 SARXL R9, R11, DX +c46232f71b SARXL R9, 0(BX), R11 +c44232f71b SARXL R9, 0(R11), R11 +c46232f7da SARXL R9, DX, R11 +c44232f7db SARXL R9, R11, R11 +c4e28af713 SARXQ R14, 0(BX), DX +c4c28af713 SARXQ R14, 0(R11), DX +c4e28af7d2 SARXQ R14, DX, DX +c4c28af7d3 SARXQ R14, R11, DX +c4628af71b SARXQ R14, 0(BX), R11 +c4428af71b SARXQ R14, 0(R11), R11 +c4628af7da SARXQ R14, DX, R11 +c4428af7db SARXQ R14, R11, R11 +c4e231f713 SHLXL R9, 0(BX), DX +c4c231f713 SHLXL R9, 0(R11), DX +c4e231f7d2 SHLXL R9, DX, DX +c4c231f7d3 SHLXL R9, R11, DX +c46231f71b SHLXL R9, 0(BX), R11 +c44231f71b SHLXL R9, 0(R11), R11 +c46231f7da SHLXL R9, DX, R11 +c44231f7db SHLXL R9, R11, R11 +c4e289f713 SHLXQ R14, 0(BX), DX +c4c289f713 SHLXQ R14, 0(R11), DX +c4e289f7d2 SHLXQ R14, DX, DX +c4c289f7d3 SHLXQ R14, R11, DX +c46289f71b SHLXQ R14, 0(BX), R11 +c44289f71b SHLXQ R14, 0(R11), R11 +c46289f7da SHLXQ R14, DX, R11 +c44289f7db SHLXQ R14, R11, R11 +c4e233f713 SHRXL R9, 0(BX), DX +c4c233f713 SHRXL R9, 0(R11), DX +c4e233f7d2 SHRXL R9, DX, DX +c4c233f7d3 SHRXL R9, R11, DX +c46233f71b SHRXL R9, 0(BX), R11 +c44233f71b SHRXL R9, 0(R11), R11 +c46233f7da SHRXL R9, DX, R11 +c44233f7db SHRXL R9, R11, R11 +c4e28bf713 SHRXQ R14, 0(BX), DX +c4c28bf713 SHRXQ R14, 0(R11), DX +c4e28bf7d2 SHRXQ R14, DX, DX +c4c28bf7d3 SHRXQ R14, R11, DX +c4628bf71b SHRXQ R14, 0(BX), R11 +c4428bf71b SHRXQ R14, 0(R11), R11 +c4628bf7da SHRXQ R14, DX, R11 +c4428bf7db SHRXQ R14, R11, R11 +0f01cb STAC +0fb9 UD1 +0f01ef WRPKRU +c4e37bf010ff RORXL $-1, 0(AX), DX +c4e3fbf010ff RORXQ $-1, 0(AX), DX