Skip to content

high-level Capstone system bindings for Rust

Notifications You must be signed in to change notification settings

Lancern/capstone-rs

 
 

Repository files navigation

capstone-rs

Crates.io Badge

Linux Github Workflow CI Badge | Windows Appveyor CI Badge | FreeBSD Cirrus CI Badge

codecov

API Documentation

Bindings to the capstone library disassembly framework.

The Capstone struct is the main interface to the library.

Requirements

capstone-rs uses the capstone-sys crate to provide the low-level bindings to the Capstone C library.

See the capstone-sys page for the requirements and supported platforms.

  • Minimum Rust Version: 1.60.0

Example

extern crate capstone;

use capstone::arch::x86::X86ArchTag;
use capstone::prelude::*;

const X86_CODE: &'static [u8] = b"\x55\x48\x8b\x05\xb8\x13\x00\x00\xe9\x14\x9e\x08\x00\x45\x31\xe4";

/// Print register names
fn reg_names<A, I>(cs: &Capstone<A>, regs: I) -> String
where
    A: ArchTag,
    I: Iterator<Item = A::RegId>,
{
    let names: Vec<String> = regs.map(|x| cs.reg_name(x).unwrap()).collect();
    names.join(", ")
}

/// Print instruction group names
fn group_names<A, I>(cs: &Capstone<A>, regs: I) -> String
where
    A: ArchTag,
    I: Iterator<Item = A::InsnGroupId>,
{
    let names: Vec<String> = regs.map(|x| cs.group_name(x).unwrap()).collect();
    names.join(", ")
}

fn main() {
    let cs = Capstone::<X86ArchTag>::new()
        .mode(arch::x86::ArchMode::Mode64)
        .syntax(arch::x86::ArchSyntax::Att)
        .detail(true)
        .build()
        .expect("Failed to create Capstone object");

    let insns = cs.disasm_all(X86_CODE, 0x1000)
        .expect("Failed to disassemble");
    println!("Found {} instructions", insns.len());
    for i in insns.as_ref() {
        println!();
        println!("{}", i);

        let detail = cs.insn_detail(&i).expect("Failed to get insn detail");
        let arch_detail = detail.arch_detail();
        let ops = arch_detail.operands();

        let output: &[(&str, String)] = &[
            ("insn id:", format!("{:?}", i.id().0)),
            ("bytes:", format!("{:?}", i.bytes())),
            ("read regs:", reg_names(&cs, detail.regs_read())),
            ("write regs:", reg_names(&cs, detail.regs_write())),
            ("insn groups:", group_names(&cs, detail.groups())),
        ];

        for &(ref name, ref message) in output.iter() {
            println!("{:4}{:12} {}", "", name, message);
        }

        println!("{:4}operands: {}", "", ops.len());
        for op in ops {
            println!("{:8}{:?}", "", op);
        }
    }
}

Produces:

Found 4 instructions

0x1000: pushq %rbp
    read regs:   rsp
    write regs:  rsp
    insn groups: mode64

0x1001: movq 0x13b8(%rip), %rax
    read regs:
    write regs:
    insn groups:

0x1008: jmp 0x8ae21
    read regs:
    write regs:
    insn groups: jump

0x100d: xorl %r12d, %r12d
    read regs:
    write regs:  rflags
    insn groups:

To see more demos, see the examples/ directory. More complex demos welcome!

Features

  • full: do not compile Capstone C library in diet mode
  • std: enable std-only features, such as the Error trait
  • use_bindgen: run bindgen to generate Rust bindings to Capstone C library instead of using pre-generated bindings (not recommended).

: enabled by default

Reporting Issues

Please open a Github issue

Author

You may find a full list of contributors on Github.

License

MIT

About

high-level Capstone system bindings for Rust

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages

  • C 85.8%
  • Rust 4.0%
  • C# 2.8%
  • Python 2.3%
  • Java 2.1%
  • OCaml 1.3%
  • Other 1.7%