#pragma once #include namespace theo::obf { /// /// jcc rewrite pass which rewrites rip relative jcc's so that they are position /// independent. /// /// given the following code: /// /// jnz label1 /// ; other code goes here /// label1: /// ; more code here /// /// the jnz instruction will be rewritten so that the following code is /// generated: /// /// jnz br2 /// br1: /// jmp [rip] ; address after this instruction contains the address /// ; of the instruction after the jcc. /// br2: /// jmp [rip] ; address after this instruction contains the address of where /// ; branch 2 is located. /// /// its important to note that other passes will encrypt (transform) the address /// of the next instruction. There is actually no jmp [rip] either, push/ret is /// used. /// class jcc_rewrite_pass_t : public pass_t { explicit jcc_rewrite_pass_t() : pass_t(decomp::sym_type_t::instruction){}; public: static jcc_rewrite_pass_t* get(); void run(decomp::symbol_t* sym); }; } // namespace theo::obf