Control Flow
Control flow instructions terminate a basic block and transfer execution. Every basic block must end with exactly one control flow instruction.
JMP
Jumps to OP1, continues virtual execution.
| Instruction | Operand 1 | Operation |
|---|---|---|
JMP | Reg/Imm | goto OP1 (virtual) |
JS
Conditional jump - jumps to OP2 if OP1 is non-zero, otherwise jumps to OP3. Continues virtual execution.
| Instruction | Operand 1 | Operand 2 | Operand 3 | Operation |
|---|---|---|---|---|
JS | Reg/Imm | Reg/Imm | Reg/Imm | goto OP1 ? OP2 : OP3 (virtual) |
VEXIT
Jumps to OP1, continues real (native) execution. Used when de-virtualized code returns to the host binary.
| Instruction | Operand 1 | Operation |
|---|---|---|
VEXIT | Reg/Imm | goto OP1 (native) |
VXCALL
Calls into OP1, pauses virtual execution until the call returns. Used for cross-calls into native code from within the virtual IL.
| Instruction | Operand 1 | Operation |
|---|---|---|
VXCALL | Reg/Imm | call OP1 (pauses virtual exec) |
Example
auto cond = block->tmp(1);
block->te(cond, X86_REG_RAX, 0);
block->js(cond, is_zero_block->entry_vip, nonzero_block->entry_vip);