✝️ James 4:13-15
Come now, you who say, “Today or tomorrow we will go to such and such a town and spend a year there, doing business and making money.” Yet you do not even know what tomorrow will bring. What is your life? For you are a mist that appears for a little while and then vanishes. Instead you ought to say, “If the Lord wishes, we will live and do this or that.”
## [Part 1 Reverse engineering](<#Part 1 Reverse engineering>)
## [Part 2 Proof of concept](<#Part 2 Proof of concept>)
## Part 1 Reverse engineering
I was bored and decided to mess around with radare2 and I discovered something pretty cool! So uh before we start I want to tell you how I like to do things, IF the code im looking at is not assembly THEN I don't want to engage, but why you may ask, and the answer is cuz I love assembly because I can see how the binary really works and ikik "muh anti RE techniques" but ignore that, so I compiled r2 with legit everything so it is easier to reverse! I will show you the function `cmd_interpret` but I won't explain the whole function but I will send it in full below, I will only talk about the stuff needed. The reason the function gets called is because of `.`. So, strtab can contain newlines and r2 stores it as such. Anyways, I will start here `loc_1058423A4`, so if the zeroth byte of input signed is greater than 9 then we are at bypass, and there and we make a copy of the input and store it in \*(X29 + inp), input-chan for short! We search for the character `~` in input-chan and store a pointer to it in \*(X29 + filter), or fil for short! So, if fil is 0 then we don't store WZR, aka the 32 bit zero register for AARCH64, bytes at fil, we store \*(\*(core + 0x50) + 0x6F3) & 1 at \*(SP + 0xE0 + var\_B1) and store WZR at \*(\*(core + 0x50) + 0x6F3), and call `r_core_cmd_str` with \*(X29 + core) and input-chan, we use the pseudo instruct MOV to make X8 equal to X0 and store that value at \*(X29 + str) and \*(X29 + ptr), also we r gonna call \*(X29 + core) core for short! We store \*(SP + 0xE0 + var\_B1) & 1 at \*(\*(core + 0x50) + 0x6F3), if fil is not 0 then we store `~` at it, we can ignore the `r_cons_break_push` so after that we are at a loop at `loc_1058424E0` and we can ignore `r_cons_is_breaked`, so now we are at `loc_1058424F8` and we find the newline character in pointer at \*(X29 + ptr), pointy for short! So, we store the result in \*(X29 + eol), end for short, and if end is 0 then we don't store WZR at end, if the zeroth byte at pointy is 0 then we don't call `bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *)` with core and a string with the contents of pointy and fil, appended after pointy. After that, if end is 0 then we exit the loop, else we set pointy to end + 1! and continue the loop! So that was the important part, but what is that `bssl` function you may be asking? The answer is that it just calls `r_core_cmd` AKA treat the string with the contents of pointy and fil appended after the contents of pointy! It is legit treated as an r2 command and ran! Anyways, here are the functions below!
`bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *)`:
```
__text:000000010571C640 __ZN4bsslL41ext_quic_transport_params_add_serverhelloEPNS_13SSL_HANDSHAKEEP6cbb_st_0
__text:000000010571C640 ; CODE XREF: r_main_radare2+8FC↑p
__text:000000010571C640 ; r_main_radare2+1364↑p ...
__text:000000010571C640
__text:000000010571C640 cstr = -0x10
__text:000000010571C640 core = -8
__text:000000010571C640 var_s0 = 0
__text:000000010571C640 var_s8 = 8
__text:000000010571C640
__text:000000010571C640 SUB SP, SP, #0x20
__text:000000010571C644 STP X29, X30, [SP,#0x10+var_s0]
__text:000000010571C648 ADD X29, SP, #0x10
__text:000000010571C64C STR X0, [SP,#0x10+core]
__text:000000010571C650 STR X1, [SP,#0x10+cstr]
__text:000000010571C654 LDR X0, [SP,#0x10+core] ; core
__text:000000010571C658 LDR X1, [SP,#0x10+cstr] ; cstr
__text:000000010571C65C MOV W8, #0
__text:000000010571C660 AND W2, W8, #1 ; log
__text:000000010571C664 BL r_core_cmd
__text:000000010571C668 LDP X29, X30, [SP,#0x10+var_s0]
__text:000000010571C66C ADD SP, SP, #0x20 ; ' '
__text:000000010571C670 RET
__text:000000010571C670 ; End of function bssl::ext_quic_transport_params_add_serverhello(bssl::SSL_HANDSHAKE *,cbb_st *)
```
`cmd_interpret`:
```
__text:0000000105841CDC ; int __cdecl cmd_interpret(void *data, const char *input)
__text:0000000105841CDC cmd_interpret ; DATA XREF: __const:000000010EAAF300↓o
__text:0000000105841CDC
__text:0000000105841CDC var_E0 = -0xE0
__text:0000000105841CDC var_D8 = -0xD8
__text:0000000105841CDC var_D0 = -0xD0
__text:0000000105841CDC var_C4 = -0xC4
__text:0000000105841CDC var_C0 = -0xC0
__text:0000000105841CDC var_B1 = -0xB1
__text:0000000105841CDC var_B0 = -0xB0
__text:0000000105841CDC v = -0xA8
__text:0000000105841CDC file = -0xA0
__text:0000000105841CDC var_98 = -0x98
__text:0000000105841CDC __s = -0x90
__text:0000000105841CDC __s1 = -0x88
__text:0000000105841CDC cstr = -0x80
__text:0000000105841CDC var_74 = -0x74
__text:0000000105841CDC var_70 = -0x70
__text:0000000105841CDC saddr = -0x68
__text:0000000105841CDC len = -0x60
__text:0000000105841CDC addr = -0x58
__text:0000000105841CDC cmd = -0x50
__text:0000000105841CDC core = -0x48
__text:0000000105841CDC inp = -0x40
__text:0000000105841CDC filter = -0x38
__text:0000000105841CDC eol = -0x30
__text:0000000105841CDC ptr = -0x28
__text:0000000105841CDC str = -0x20
__text:0000000105841CDC input = -0x18
__text:0000000105841CDC data = -0x10
__text:0000000105841CDC var_4 = -4
__text:0000000105841CDC var_s0 = 0
__text:0000000105841CDC
__text:0000000105841CDC SUB SP, SP, #0xF0
__text:0000000105841CE0 STP X29, X30, [SP,#0xE0+var_s0]
__text:0000000105841CE4 ADD X29, SP, #0xE0
__text:0000000105841CE8 STUR X0, [X29,#data]
__text:0000000105841CEC STUR X1, [X29,#input]
__text:0000000105841CF0 LDUR X8, [X29,#data]
__text:0000000105841CF4 STUR X8, [X29,#core]
__text:0000000105841CF8 LDUR X0, [X29,#input] ; __s1
__text:0000000105841CFC ADRL X1, asc_10E016AD4 ; "?"
__text:0000000105841D04 BL _strcmp.island
__text:0000000105841D08 CBNZ W0, loc_105841D2C
__text:0000000105841D0C B loc_105841D10
__text:0000000105841D10 ; ---------------------------------------------------------------------------
__text:0000000105841D10
__text:0000000105841D10 loc_105841D10 ; CODE XREF: cmd_interpret+30↑j
__text:0000000105841D10 LDUR X8, [X29,#core]
__text:0000000105841D14 LDR X0, [X8,#0x50] ; cons
__text:0000000105841D18 ADRL X1, help_msg_dot ; help
__text:0000000105841D20 BL r_cons_cmd_help
__text:0000000105841D24 STUR WZR, [X29,#var_4]
__text:0000000105841D28 B loc_1058425A8
__text:0000000105841D2C ; ---------------------------------------------------------------------------
__text:0000000105841D2C
__text:0000000105841D2C loc_105841D2C ; CODE XREF: cmd_interpret+2C↑j
__text:0000000105841D2C LDUR X8, [X29,#input]
__text:0000000105841D30 LDRSB W8, [X8]
__text:0000000105841D34 STR W8, [SP,#0xE0+var_C4]
__text:0000000105841D38 CBZ W8, loc_105841DB0
__text:0000000105841D3C B loc_105841D40
__text:0000000105841D40 ; ---------------------------------------------------------------------------
__text:0000000105841D40
__text:0000000105841D40 loc_105841D40 ; CODE XREF: cmd_interpret+60↑j
__text:0000000105841D40 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841D44 SUBS W8, W8, #0x20 ; ' '
__text:0000000105841D48 B.EQ loc_105842190
__text:0000000105841D4C B loc_105841D50
__text:0000000105841D50 ; ---------------------------------------------------------------------------
__text:0000000105841D50
__text:0000000105841D50 loc_105841D50 ; CODE XREF: cmd_interpret+70↑j
__text:0000000105841D50 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841D54 SUBS W8, W8, #0x21 ; '!'
__text:0000000105841D58 B.EQ loc_10584234C
__text:0000000105841D5C B loc_105841D60
__text:0000000105841D60 ; ---------------------------------------------------------------------------
__text:0000000105841D60
__text:0000000105841D60 loc_105841D60 ; CODE XREF: cmd_interpret+80↑j
__text:0000000105841D60 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841D64 SUBS W8, W8, #0x27 ; '''
__text:0000000105841D68 B.EQ loc_105841DC0
__text:0000000105841D6C B loc_105841D70
__text:0000000105841D70 ; ---------------------------------------------------------------------------
__text:0000000105841D70
__text:0000000105841D70 loc_105841D70 ; CODE XREF: cmd_interpret+90↑j
__text:0000000105841D70 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841D74 SUBS W8, W8, #0x28 ; '('
__text:0000000105841D78 B.EQ loc_105842370
__text:0000000105841D7C B loc_105841D80
__text:0000000105841D80 ; ---------------------------------------------------------------------------
__text:0000000105841D80
__text:0000000105841D80 loc_105841D80 ; CODE XREF: cmd_interpret+A0↑j
__text:0000000105841D80 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841D84 SUBS W8, W8, #0x2A ; '*'
__text:0000000105841D88 B.EQ loc_1058420BC
__text:0000000105841D8C B loc_105841D90
__text:0000000105841D90 ; ---------------------------------------------------------------------------
__text:0000000105841D90
__text:0000000105841D90 loc_105841D90 ; CODE XREF: cmd_interpret+B0↑j
__text:0000000105841D90 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841D94 SUBS W8, W8, #0x2D ; '-'
__text:0000000105841D98 B.EQ loc_105842138
__text:0000000105841D9C B loc_105841DA0
__text:0000000105841DA0 ; ---------------------------------------------------------------------------
__text:0000000105841DA0
__text:0000000105841DA0 loc_105841DA0 ; CODE XREF: cmd_interpret+C0↑j
__text:0000000105841DA0 LDR W8, [SP,#0xE0+var_C4]
__text:0000000105841DA4 SUBS W8, W8, #0x2E ; '.'
__text:0000000105841DA8 B.EQ loc_105841FCC
__text:0000000105841DAC B loc_1058423A4
__text:0000000105841DB0 ; ---------------------------------------------------------------------------
__text:0000000105841DB0
__text:0000000105841DB0 loc_105841DB0 ; CODE XREF: cmd_interpret+5C↑j
__text:0000000105841DB0 LDUR X0, [X29,#core] ; core
__text:0000000105841DB4 MOV W1, #0 ; next
__text:0000000105841DB8 BL lastcmd_repeat
__text:0000000105841DBC B loc_1058425A0
__text:0000000105841DC0 ; ---------------------------------------------------------------------------
__text:0000000105841DC0
__text:0000000105841DC0 loc_105841DC0 ; CODE XREF: cmd_interpret+8C↑j
__text:0000000105841DC0 LDUR X8, [X29,#input]
__text:0000000105841DC4 ADD X8, X8, #1
__text:0000000105841DC8 STUR X8, [X29,#cmd]
__text:0000000105841DCC LDUR X8, [X29,#core]
__text:0000000105841DD0 LDR X8, [X8,#0x18]
__text:0000000105841DD4 STUR X8, [X29,#addr]
__text:0000000105841DD8 LDUR X8, [X29,#input]
__text:0000000105841DDC LDRSB W8, [X8,#1]
__text:0000000105841DE0 SUBS W8, W8, #0x40 ; '@'
__text:0000000105841DE4 B.NE loc_105841EA0
__text:0000000105841DE8 B loc_105841DEC
__text:0000000105841DEC ; ---------------------------------------------------------------------------
__text:0000000105841DEC
__text:0000000105841DEC loc_105841DEC ; CODE XREF: cmd_interpret+10C↑j
__text:0000000105841DEC LDUR X8, [X29,#input]
__text:0000000105841DF0 ADD X0, X8, #1 ; __s
__text:0000000105841DF4 MOV W1, #0x27 ; ''' ; __c
__text:0000000105841DF8 BL _strchr.island
__text:0000000105841DFC STUR X0, [X29,#cmd]
__text:0000000105841E00 LDUR X8, [X29,#cmd]
__text:0000000105841E04 CBNZ X8, loc_105841E54
__text:0000000105841E08 B loc_105841E0C
__text:0000000105841E0C ; ---------------------------------------------------------------------------
__text:0000000105841E0C
__text:0000000105841E0C loc_105841E0C ; CODE XREF: cmd_interpret+12C↑j
__text:0000000105841E0C MOV W0, #1 ; level
__text:0000000105841E10 ADRL X1, aCmdInterpret ; "cmd_interpret"
__text:0000000105841E18 BL r_log_match
__text:0000000105841E1C TBZ W0, #0, loc_105841E4C
__text:0000000105841E20 B loc_105841E24
__text:0000000105841E24 ; ---------------------------------------------------------------------------
__text:0000000105841E24
__text:0000000105841E24 loc_105841E24 ; CODE XREF: cmd_interpret+144↑j
__text:0000000105841E24 MOV W0, #1 ; level
__text:0000000105841E28 ADRL X1, aCmdInterpret ; "cmd_interpret"
__text:0000000105841E30 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c"
__text:0000000105841E38 MOV W3, #0x902 ; line
__text:0000000105841E3C ADRL X4, aMissingSeparat ; "Missing ' separator after .'@"
__text:0000000105841E44 BL r_log_message
__text:0000000105841E48 B loc_105841E4C
__text:0000000105841E4C ; ---------------------------------------------------------------------------
__text:0000000105841E4C
__text:0000000105841E4C loc_105841E4C ; CODE XREF: cmd_interpret+140↑j
__text:0000000105841E4C ; cmd_interpret+16C↑j
__text:0000000105841E4C STUR WZR, [X29,#var_4]
__text:0000000105841E50 B loc_1058425A8
__text:0000000105841E54 ; ---------------------------------------------------------------------------
__text:0000000105841E54
__text:0000000105841E54 loc_105841E54 ; CODE XREF: cmd_interpret+128↑j
__text:0000000105841E54 LDUR X8, [X29,#cmd]
__text:0000000105841E58 LDUR X9, [X29,#input]
__text:0000000105841E5C SUBS X8, X8, X9
__text:0000000105841E60 ADD X8, X8, #2
__text:0000000105841E64 STUR X8, [X29,#len]
__text:0000000105841E68 LDUR X8, [X29,#input]
__text:0000000105841E6C ADD X0, X8, #2 ; ptr
__text:0000000105841E70 LDUR X8, [X29,#len]
__text:0000000105841E74 MOV X1, X8 ; len
__text:0000000105841E78 BL r_str_ndup
__text:0000000105841E7C STUR X0, [X29,#saddr]
__text:0000000105841E80 LDUR X8, [X29,#core]
__text:0000000105841E84 LDR X0, [X8,#0x68] ; s
__text:0000000105841E88 LDUR X1, [X29,#saddr] ; adj
__text:0000000105841E8C BL r_num_get
__text:0000000105841E90 STUR X0, [X29,#addr]
__text:0000000105841E94 LDUR X0, [X29,#saddr] ; void *
__text:0000000105841E98 BL _free.island
__text:0000000105841E9C B loc_105841EA0
__text:0000000105841EA0 ; ---------------------------------------------------------------------------
__text:0000000105841EA0
__text:0000000105841EA0 loc_105841EA0 ; CODE XREF: cmd_interpret+108↑j
__text:0000000105841EA0 ; cmd_interpret+1C0↑j
__text:0000000105841EA0 LDUR X0, [X29,#core] ; core
__text:0000000105841EA4 LDUR X1, [X29,#addr] ; addr
__text:0000000105841EA8 LDUR X2, [X29,#cmd] ; cmd
__text:0000000105841EAC BL r_core_call_str_at
__text:0000000105841EB0 STR X0, [SP,#0xE0+var_70]
__text:0000000105841EB4 LDUR X8, [X29,#core]
__text:0000000105841EB8 LDR X0, [X8,#0x50] ; cons
__text:0000000105841EBC MOV X2, #0 ; user
__text:0000000105841EC0 MOV X1, X2 ; cb
__text:0000000105841EC4 BL r_cons_break_push
__text:0000000105841EC8 LDR X8, [SP,#0xE0+var_70]
__text:0000000105841ECC STUR X8, [X29,#ptr]
__text:0000000105841ED0 B loc_105841ED4
__text:0000000105841ED4 ; ---------------------------------------------------------------------------
__text:0000000105841ED4
__text:0000000105841ED4 loc_105841ED4 ; CODE XREF: cmd_interpret+1F4↑j
__text:0000000105841ED4 ; cmd_interpret+2D4↓j
__text:0000000105841ED4 LDUR X8, [X29,#core]
__text:0000000105841ED8 LDR X0, [X8,#0x50] ; cons
__text:0000000105841EDC BL r_cons_is_breaked
__text:0000000105841EE0 TBZ W0, #0, loc_105841EEC
__text:0000000105841EE4 B loc_105841EE8
__text:0000000105841EE8 ; ---------------------------------------------------------------------------
__text:0000000105841EE8
__text:0000000105841EE8 loc_105841EE8 ; CODE XREF: cmd_interpret+208↑j
__text:0000000105841EE8 B loc_105841FB4
__text:0000000105841EEC ; ---------------------------------------------------------------------------
__text:0000000105841EEC
__text:0000000105841EEC loc_105841EEC ; CODE XREF: cmd_interpret+204↑j
__text:0000000105841EEC LDUR X0, [X29,#ptr] ; __s
__text:0000000105841EF0 MOV W1, #0xA ; __c
__text:0000000105841EF4 BL _strchr.island
__text:0000000105841EF8 STUR X0, [X29,#eol]
__text:0000000105841EFC LDUR X8, [X29,#eol]
__text:0000000105841F00 CBZ X8, loc_105841F14
__text:0000000105841F04 B loc_105841F08
__text:0000000105841F08 ; ---------------------------------------------------------------------------
__text:0000000105841F08
__text:0000000105841F08 loc_105841F08 ; CODE XREF: cmd_interpret+228↑j
__text:0000000105841F08 LDUR X8, [X29,#eol]
__text:0000000105841F0C STRB WZR, [X8]
__text:0000000105841F10 B loc_105841F14
__text:0000000105841F14 ; ---------------------------------------------------------------------------
__text:0000000105841F14
__text:0000000105841F14 loc_105841F14 ; CODE XREF: cmd_interpret+224↑j
__text:0000000105841F14 ; cmd_interpret+234↑j
__text:0000000105841F14 LDUR X8, [X29,#ptr]
__text:0000000105841F18 LDRB W8, [X8]
__text:0000000105841F1C CBZ W8, loc_105841F94
__text:0000000105841F20 B loc_105841F24
__text:0000000105841F24 ; ---------------------------------------------------------------------------
__text:0000000105841F24
__text:0000000105841F24 loc_105841F24 ; CODE XREF: cmd_interpret+244↑j
__text:0000000105841F24 LDUR X0, [X29,#core] ; rnd
__text:0000000105841F28 LDUR X1, [X29,#ptr] ; range
__text:0000000105841F2C BL r_core_call
__text:0000000105841F30 STR W0, [SP,#0xE0+var_74]
__text:0000000105841F34 LDR W8, [SP,#0xE0+var_74]
__text:0000000105841F38 CBZ W8, loc_105841F90
__text:0000000105841F3C B loc_105841F40
__text:0000000105841F40 ; ---------------------------------------------------------------------------
__text:0000000105841F40
__text:0000000105841F40 loc_105841F40 ; CODE XREF: cmd_interpret+260↑j
__text:0000000105841F40 MOV W0, #1 ; level
__text:0000000105841F44 ADRL X1, aCmdInterpret ; "cmd_interpret"
__text:0000000105841F4C BL r_log_match
__text:0000000105841F50 TBZ W0, #0, loc_105841F8C
__text:0000000105841F54 B loc_105841F58
__text:0000000105841F58 ; ---------------------------------------------------------------------------
__text:0000000105841F58
__text:0000000105841F58 loc_105841F58 ; CODE XREF: cmd_interpret+278↑j
__text:0000000105841F58 LDUR X8, [X29,#ptr]
__text:0000000105841F5C MOV X9, SP
__text:0000000105841F60 STR X8, [X9,#0xE0+var_E0]
__text:0000000105841F64 MOV W0, #1 ; level
__text:0000000105841F68 ADRL X1, aCmdInterpret ; "cmd_interpret"
__text:0000000105841F70 ADRL X2, aSourceLibrCore_43 ; "../source/libr/core/cmd.c"
__text:0000000105841F78 MOV W3, #0x917 ; line
__text:0000000105841F7C ADRL X4, aWrongCommandS ; "Wrong command %s"
__text:0000000105841F84 BL r_log_message
__text:0000000105841F88 B loc_105841F8C
__text:0000000105841F8C ; ---------------------------------------------------------------------------
__text:0000000105841F8C
__text:0000000105841F8C loc_105841F8C ; CODE XREF: cmd_interpret+274↑j
__text:0000000105841F8C ; cmd_interpret+2AC↑j
__text:0000000105841F8C B loc_105841FB4
__text:0000000105841F90 ; ---------------------------------------------------------------------------
__text:0000000105841F90
__text:0000000105841F90 loc_105841F90 ; CODE XREF: cmd_interpret+25C↑j
__text:0000000105841F90 B loc_105841F94
__text:0000000105841F94 ; ---------------------------------------------------------------------------
__text:0000000105841F94
__text:0000000105841F94 loc_105841F94 ; CODE XREF: cmd_interpret+240↑j
__text:0000000105841F94 ; cmd_interpret:loc_105841F90↑j
__text:0000000105841F94 LDUR X8, [X29,#eol]
__text:0000000105841F98 CBNZ X8, loc_105841FA4
__text:0000000105841F9C B loc_105841FA0
__text:0000000105841FA0 ; ---------------------------------------------------------------------------
__text:0000000105841FA0
__text:0000000105841FA0 loc_105841FA0 ; CODE XREF: cmd_interpret+2C0↑j
__text:0000000105841FA0 B loc_105841FB4
__text:0000000105841FA4 ; ---------------------------------------------------------------------------
__text:0000000105841FA4
__text:0000000105841FA4 loc_105841FA4 ; CODE XREF: cmd_interpret+2BC↑j
__text:0000000105841FA4 LDUR X8, [X29,#eol]
__text:0000000105841FA8 ADD X8, X8, #1
__text:0000000105841FAC STUR X8, [X29,#ptr]
__text:0000000105841FB0 B loc_105841ED4
__text:0000000105841FB4 ; ---------------------------------------------------------------------------
__text:0000000105841FB4
__text:0000000105841FB4 loc_105841FB4 ; CODE XREF: cmd_interpret:loc_105841EE8↑j
__text:0000000105841FB4 ; cmd_interpret:loc_105841F8C↑j ...
__text:0000000105841FB4 LDUR X8, [X29,#core]
__text:0000000105841FB8 LDR X0, [X8,#0x50] ; cons
__text:0000000105841FBC BL r_cons_break_pop
__text:0000000105841FC0 LDR X0, [SP,#0xE0+var_70] ; void *
__text:0000000105841FC4 BL _free.island
__text:0000000105841FC8 B loc_1058425A0
__text:0000000105841FCC ; ---------------------------------------------------------------------------
__text:0000000105841FCC
__text:0000000105841FCC loc_105841FCC ; CODE XREF: cmd_interpret+CC↑j
__text:0000000105841FCC LDUR X8, [X29,#input]
__text:0000000105841FD0 LDRSB W8, [X8,#1]
__text:0000000105841FD4 SUBS W8, W8, #0x2E ; '.'
__text:0000000105841FD8 B.NE loc_105841FF0
__text:0000000105841FDC B loc_105841FE0
__text:0000000105841FE0 ; ---------------------------------------------------------------------------
__text:0000000105841FE0
__text:0000000105841FE0 loc_105841FE0 ; CODE XREF: cmd_interpret+300↑j
__text:0000000105841FE0 LDUR X0, [X29,#core] ; core
__text:0000000105841FE4 MOV W1, #1 ; next
__text:0000000105841FE8 BL lastcmd_repeat
__text:0000000105841FEC B loc_1058420B8
__text:0000000105841FF0 ; ---------------------------------------------------------------------------
__text:0000000105841FF0
__text:0000000105841FF0 loc_105841FF0 ; CODE XREF: cmd_interpret+2FC↑j
__text:0000000105841FF0 LDUR X8, [X29,#input]
__text:0000000105841FF4 LDRSB W8, [X8,#1]
__text:0000000105841FF8 SUBS W8, W8, #0x20 ; ' '
__text:0000000105841FFC B.NE loc_105842054
__text:0000000105842000 B loc_105842004
__text:0000000105842004 ; ---------------------------------------------------------------------------
__text:0000000105842004
__text:0000000105842004 loc_105842004 ; CODE XREF: cmd_interpret+324↑j
__text:0000000105842004 LDUR X8, [X29,#core]
__text:0000000105842008 STR X8, [SP,#0xE0+var_D0]
__text:000000010584200C LDUR X0, [X29,#input] ; str
__text:0000000105842010 BL r_str_trim_head_ro
__text:0000000105842014 MOV X1, X0 ; cmd
__text:0000000105842018 LDR X0, [SP,#0xE0+var_D0] ; core
__text:000000010584201C BL r_core_cmd_str_pipe
__text:0000000105842020 STR X0, [SP,#0xE0+cstr]
__text:0000000105842024 LDR X8, [SP,#0xE0+cstr]
__text:0000000105842028 CBZ X8, loc_105842050
__text:000000010584202C B loc_105842030
__text:0000000105842030 ; ---------------------------------------------------------------------------
__text:0000000105842030
__text:0000000105842030 loc_105842030 ; CODE XREF: cmd_interpret+350↑j
__text:0000000105842030 LDUR X0, [X29,#core] ; core
__text:0000000105842034 LDR X1, [SP,#0xE0+cstr] ; cstr
__text:0000000105842038 MOV W8, #0
__text:000000010584203C AND W2, W8, #1 ; log
__text:0000000105842040 BL r_core_cmd
__text:0000000105842044 LDR X0, [SP,#0xE0+cstr] ; void *
__text:0000000105842048 BL _free.island
__text:000000010584204C B loc_105842050
__text:0000000105842050 ; ---------------------------------------------------------------------------
__text:0000000105842050
__text:0000000105842050 loc_105842050 ; CODE XREF: cmd_interpret+34C↑j
__text:0000000105842050 ; cmd_interpret+370↑j
__text:0000000105842050 B loc_1058420B4
__text:0000000105842054 ; ---------------------------------------------------------------------------
__text:0000000105842054
__text:0000000105842054 loc_105842054 ; CODE XREF: cmd_interpret+320↑j
__text:0000000105842054 LDUR X8, [X29,#input]
__text:0000000105842058 LDRSB W8, [X8,#1]
__text:000000010584205C CBZ W8, loc_105842098
__text:0000000105842060 B loc_105842064
__text:0000000105842064 ; ---------------------------------------------------------------------------
__text:0000000105842064
__text:0000000105842064 loc_105842064 ; CODE XREF: cmd_interpret+384↑j
__text:0000000105842064 LDUR X8, [X29,#input]
__text:0000000105842068 LDRSB W8, [X8,#1]
__text:000000010584206C SUBS W8, W8, #0x3F ; '?'
__text:0000000105842070 B.EQ loc_105842098
__text:0000000105842074 B loc_105842078
__text:0000000105842078 ; ---------------------------------------------------------------------------
__text:0000000105842078
__text:0000000105842078 loc_105842078 ; CODE XREF: cmd_interpret+398↑j
__text:0000000105842078 LDUR X0, [X29,#core] ; core
__text:000000010584207C LDUR X8, [X29,#input]
__text:0000000105842080 MOV X9, SP
__text:0000000105842084 STR X8, [X9,#0xE0+var_E0]
__text:0000000105842088 ADRL X1, aSS_43 ; "s%s"
__text:0000000105842090 BL r_core_cmdf
__text:0000000105842094 B loc_1058420B0
__text:0000000105842098 ; ---------------------------------------------------------------------------
__text:0000000105842098
__text:0000000105842098 loc_105842098 ; CODE XREF: cmd_interpret+380↑j
__text:0000000105842098 ; cmd_interpret+394↑j
__text:0000000105842098 LDUR X8, [X29,#core]
__text:000000010584209C LDR X0, [X8,#0x50] ; cons
__text:00000001058420A0 ADRL X1, help_msg_dot ; help
__text:00000001058420A8 BL r_cons_cmd_help
__text:00000001058420AC B loc_1058420B0
__text:00000001058420B0 ; ---------------------------------------------------------------------------
__text:00000001058420B0
__text:00000001058420B0 loc_1058420B0 ; CODE XREF: cmd_interpret+3B8↑j
__text:00000001058420B0 ; cmd_interpret+3D0↑j
__text:00000001058420B0 B loc_1058420B4
__text:00000001058420B4 ; ---------------------------------------------------------------------------
__text:00000001058420B4
__text:00000001058420B4 loc_1058420B4 ; CODE XREF: cmd_interpret:loc_105842050↑j
__text:00000001058420B4 ; cmd_interpret:loc_1058420B0↑j
__text:00000001058420B4 B loc_1058420B8
__text:00000001058420B8 ; ---------------------------------------------------------------------------
__text:00000001058420B8
__text:00000001058420B8 loc_1058420B8 ; CODE XREF: cmd_interpret+310↑j
__text:00000001058420B8 ; cmd_interpret:loc_1058420B4↑j
__text:00000001058420B8 B loc_1058425A0
__text:00000001058420BC ; ---------------------------------------------------------------------------
__text:00000001058420BC
__text:00000001058420BC loc_1058420BC ; CODE XREF: cmd_interpret+AC↑j
__text:00000001058420BC LDUR X8, [X29,#input]
__text:00000001058420C0 ADD X0, X8, #1 ; str
__text:00000001058420C4 BL r_str_trim_head_ro
__text:00000001058420C8 STR X0, [SP,#0xE0+__s1]
__text:00000001058420CC LDR X0, [SP,#0xE0+__s1] ; __s1
__text:00000001058420D0 BL _strdup.island
__text:00000001058420D4 STR X0, [SP,#0xE0+__s]
__text:00000001058420D8 LDR X0, [SP,#0xE0+__s] ; __s
__text:00000001058420DC MOV W1, #0x20 ; ' ' ; __c
__text:00000001058420E0 BL _strchr.island
__text:00000001058420E4 STR X0, [SP,#0xE0+var_98]
__text:00000001058420E8 LDR X8, [SP,#0xE0+var_98]
__text:00000001058420EC CBZ X8, loc_105842100
__text:00000001058420F0 B loc_1058420F4
__text:00000001058420F4 ; ---------------------------------------------------------------------------
__text:00000001058420F4
__text:00000001058420F4 loc_1058420F4 ; CODE XREF: cmd_interpret+414↑j
__text:00000001058420F4 LDR X8, [SP,#0xE0+var_98]
__text:00000001058420F8 STRB WZR, [X8]
__text:00000001058420FC B loc_105842100
__text:0000000105842100 ; ---------------------------------------------------------------------------
__text:0000000105842100
__text:0000000105842100 loc_105842100 ; CODE XREF: cmd_interpret+410↑j
__text:0000000105842100 ; cmd_interpret+420↑j
__text:0000000105842100 LDR X8, [SP,#0xE0+__s]
__text:0000000105842104 CBZ X8, loc_10584212C
__text:0000000105842108 B loc_10584210C
__text:000000010584210C ; ---------------------------------------------------------------------------
__text:000000010584210C
__text:000000010584210C loc_10584210C ; CODE XREF: cmd_interpret+42C↑j
__text:000000010584210C LDR X8, [SP,#0xE0+__s]
__text:0000000105842110 LDRSB W8, [X8]
__text:0000000105842114 CBZ W8, loc_10584212C
__text:0000000105842118 B loc_10584211C
__text:000000010584211C ; ---------------------------------------------------------------------------
__text:000000010584211C
__text:000000010584211C loc_10584211C ; CODE XREF: cmd_interpret+43C↑j
__text:000000010584211C LDUR X0, [X29,#core] ; core
__text:0000000105842120 LDR X1, [SP,#0xE0+__s] ; file
__text:0000000105842124 BL r_core_run_script
__text:0000000105842128 B loc_10584212C
__text:000000010584212C ; ---------------------------------------------------------------------------
__text:000000010584212C
__text:000000010584212C loc_10584212C ; CODE XREF: cmd_interpret+428↑j
__text:000000010584212C ; cmd_interpret+438↑j ...
__text:000000010584212C LDR X0, [SP,#0xE0+__s] ; void *
__text:0000000105842130 BL _free.island
__text:0000000105842134 B loc_1058425A0
__text:0000000105842138 ; ---------------------------------------------------------------------------
__text:0000000105842138
__text:0000000105842138 loc_105842138 ; CODE XREF: cmd_interpret+BC↑j
__text:0000000105842138 LDUR X8, [X29,#input]
__text:000000010584213C LDRSB W8, [X8,#1]
__text:0000000105842140 SUBS W8, W8, #0x3F ; '?'
__text:0000000105842144 B.NE loc_105842178
__text:0000000105842148 B loc_10584214C
__text:000000010584214C ; ---------------------------------------------------------------------------
__text:000000010584214C
__text:000000010584214C loc_10584214C ; CODE XREF: cmd_interpret+46C↑j
__text:000000010584214C LDUR X8, [X29,#core]
__text:0000000105842150 LDR X0, [X8,#0x50] ; cons
__text:0000000105842154 ADRL X1, help_msg_dot ; help
__text:000000010584215C ADRL X2, asc_10E13FE8B ; ".-"
__text:0000000105842164 MOV W3, #0 ; spec
__text:0000000105842168 MOV W8, #1
__text:000000010584216C AND W4, W8, #1 ; exact
__text:0000000105842170 BL r_cons_cmd_help_match
__text:0000000105842174 B loc_10584218C
__text:0000000105842178 ; ---------------------------------------------------------------------------
__text:0000000105842178
__text:0000000105842178 loc_105842178 ; CODE XREF: cmd_interpret+468↑j
__text:0000000105842178 LDUR X0, [X29,#core] ; core
__text:000000010584217C ADRL X1, asc_10E01725E ; "-"
__text:0000000105842184 BL r_core_run_script
__text:0000000105842188 B loc_10584218C
__text:000000010584218C ; ---------------------------------------------------------------------------
__text:000000010584218C
__text:000000010584218C loc_10584218C ; CODE XREF: cmd_interpret+498↑j
__text:000000010584218C ; cmd_interpret+4AC↑j
__text:000000010584218C B loc_1058425A0
__text:0000000105842190 ; ---------------------------------------------------------------------------
__text:0000000105842190
__text:0000000105842190 loc_105842190 ; CODE XREF: cmd_interpret+6C↑j
__text:0000000105842190 LDUR X8, [X29,#input]
__text:0000000105842194 ADD X0, X8, #1 ; str
__text:0000000105842198 BL r_str_trim_head_ro
__text:000000010584219C STR X0, [SP,#0xE0+file]
__text:00000001058421A0 LDR X8, [SP,#0xE0+file]
__text:00000001058421A4 LDRSB W8, [X8]
__text:00000001058421A8 SUBS W8, W8, #0x24 ; '