VTILVTIL

Control Flow

Control flow instructions terminate a basic block and transfer execution. Every basic block must end with exactly one control flow instruction.

JMP

Jumps to OP1, continues virtual execution.

InstructionOperand 1Operation
JMPReg/Immgoto OP1 (virtual)

JS

Conditional jump - jumps to OP2 if OP1 is non-zero, otherwise jumps to OP3. Continues virtual execution.

InstructionOperand 1Operand 2Operand 3Operation
JSReg/ImmReg/ImmReg/Immgoto OP1 ? OP2 : OP3 (virtual)

VEXIT

Jumps to OP1, continues real (native) execution. Used when de-virtualized code returns to the host binary.

InstructionOperand 1Operation
VEXITReg/Immgoto OP1 (native)

VXCALL

Calls into OP1, pauses virtual execution until the call returns. Used for cross-calls into native code from within the virtual IL.

InstructionOperand 1Operation
VXCALLReg/Immcall OP1 (pauses virtual exec)

Example

auto cond = block->tmp(1);
block->te(cond, X86_REG_RAX, 0);
block->js(cond, is_zero_block->entry_vip, nonzero_block->entry_vip);