1 /* Read the export table symbols from a portable executable and
2 convert to internal format, for GDB. Used as a last resort if no
3 debugging symbols recognized.
5 Copyright (C) 2003-2017 Free Software Foundation, Inc.
7 This file is part of GDB.
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 Contributed by Raoul M. Gough (RaoulGough@yahoo.co.uk). */
26 #include "coff-pe-read.h"
36 #include "common/common-utils.h"
37 #include "coff/internal.h"
41 /* Internal section information */
43 /* Coff PE read debugging flag:
45 value 1 outputs problems encountered while parsing PE file,
46 value above 1 also lists all generated minimal symbols. */
47 static unsigned int debug_coff_pe_read;
49 struct read_pe_section_data
51 CORE_ADDR vma_offset; /* Offset to loaded address of section. */
52 unsigned long rva_start; /* Start offset within the pe. */
53 unsigned long rva_end; /* End offset within the pe. */
54 enum minimal_symbol_type ms_type; /* Type to assign symbols in
56 unsigned int index; /* BFD section number. */
57 const char *section_name; /* Recorded section name. */
60 #define IMAGE_SCN_CNT_CODE 0x20
61 #define IMAGE_SCN_CNT_INITIALIZED_DATA 0x40
62 #define IMAGE_SCN_CNT_UNINITIALIZED_DATA 0x80
63 #define PE_SECTION_INDEX_TEXT 0
64 #define PE_SECTION_INDEX_DATA 1
65 #define PE_SECTION_INDEX_BSS 2
66 #define PE_SECTION_TABLE_SIZE 3
67 #define PE_SECTION_INDEX_INVALID -1
69 /* Get the index of the named section in our own array, which contains
70 text, data and bss in that order. Return PE_SECTION_INDEX_INVALID
71 if passed an unrecognised section name. */
74 read_pe_section_index (const char *section_name)
76 if (strcmp (section_name, ".text") == 0)
78 return PE_SECTION_INDEX_TEXT;
81 else if (strcmp (section_name, ".data") == 0)
83 return PE_SECTION_INDEX_DATA;
86 else if (strcmp (section_name, ".bss") == 0)
88 return PE_SECTION_INDEX_BSS;
93 return PE_SECTION_INDEX_INVALID;
97 /* Get the index of the named section in our own full array.
98 text, data and bss in that order. Return PE_SECTION_INDEX_INVALID
99 if passed an unrecognised section name. */
102 get_pe_section_index (const char *section_name,
103 struct read_pe_section_data *sections,
108 for (i = 0; i < nb_sections; i++)
109 if (strcmp (sections[i].section_name, section_name) == 0)
111 return PE_SECTION_INDEX_INVALID;
114 /* Structure used by get_section_vmas function below
115 to access section_data array and the size of the array
116 stored in nb_sections field. */
117 struct pe_sections_info
120 struct read_pe_section_data *sections;
123 /* Record the virtual memory address of a section. */
126 get_section_vmas (bfd *abfd, asection *sectp, void *context)
128 struct pe_sections_info *data = (struct pe_sections_info *) context;
129 struct read_pe_section_data *sections = data->sections;
130 int sectix = get_pe_section_index (sectp->name, sections,
133 if (sectix != PE_SECTION_INDEX_INVALID)
135 /* Data within the section start at rva_start in the pe and at
136 bfd_get_section_vma() within memory. Store the offset. */
138 sections[sectix].vma_offset
139 = bfd_get_section_vma (abfd, sectp) - sections[sectix].rva_start;
143 /* Create a minimal symbol entry for an exported symbol.
144 SYM_NAME contains the exported name or NULL if exported by ordinal,
145 FUNC_RVA contains the Relative Virtual Address of the symbol,
146 ORDINAL is the ordinal index value of the symbol,
147 SECTION_DATA contains information about the section in which the
149 DLL_NAME is the internal name of the DLL file,
150 OBJFILE is the objfile struct of DLL_NAME. */
153 add_pe_exported_sym (minimal_symbol_reader &reader,
154 const char *sym_name,
155 unsigned long func_rva,
157 const struct read_pe_section_data *section_data,
158 const char *dll_name, struct objfile *objfile)
160 char *qualified_name, *bare_name;
161 /* Add the stored offset to get the loaded address of the symbol. */
162 CORE_ADDR vma = func_rva + section_data->vma_offset;
164 /* Generate a (hopefully unique) qualified name using the first part
165 of the dll name, e.g. KERNEL32!AddAtomA. This matches the style
166 used by windbg from the "Microsoft Debugging Tools for Windows". */
168 if (sym_name == NULL || *sym_name == '\0')
169 bare_name = xstrprintf ("#%d", ordinal);
171 bare_name = xstrdup (sym_name);
173 qualified_name = xstrprintf ("%s!%s", dll_name, bare_name);
175 if ((section_data->ms_type == mst_unknown) && debug_coff_pe_read)
176 fprintf_unfiltered (gdb_stdlog , _("Unknown section type for \"%s\""
177 " for entry \"%s\" in dll \"%s\"\n"),
178 section_data->section_name, sym_name, dll_name);
180 reader.record_with_info (qualified_name, vma, section_data->ms_type,
181 section_data->index);
183 /* Enter the plain name as well, which might not be unique. */
184 reader.record_with_info (bare_name, vma, section_data->ms_type,
185 section_data->index);
186 if (debug_coff_pe_read > 1)
187 fprintf_unfiltered (gdb_stdlog, _("Adding exported symbol \"%s\""
188 " in dll \"%s\"\n"), sym_name, dll_name);
189 xfree (qualified_name);
193 /* Create a minimal symbol entry for an exported forward symbol.
194 Return 1 if the forwarded function was found 0 otherwise.
195 SYM_NAME contains the exported name or NULL if exported by ordinal,
196 FORWARD_DLL_NAME is the name of the DLL in which the target symobl resides,
197 FORWARD_FUNC_NAME is the name of the target symbol in that DLL,
198 ORDINAL is the ordinal index value of the symbol,
199 DLL_NAME is the internal name of the DLL file,
200 OBJFILE is the objfile struct of DLL_NAME. */
203 add_pe_forwarded_sym (minimal_symbol_reader &reader,
204 const char *sym_name, const char *forward_dll_name,
205 const char *forward_func_name, int ordinal,
206 const char *dll_name, struct objfile *objfile)
208 CORE_ADDR vma, baseaddr;
209 struct bound_minimal_symbol msymbol;
210 enum minimal_symbol_type msymtype;
211 char *qualified_name, *bare_name;
212 int forward_dll_name_len = strlen (forward_dll_name);
213 int forward_func_name_len = strlen (forward_func_name);
214 int forward_len = forward_dll_name_len + forward_func_name_len + 2;
215 char *forward_qualified_name = (char *) alloca (forward_len);
218 xsnprintf (forward_qualified_name, forward_len, "%s!%s", forward_dll_name,
222 msymbol = lookup_minimal_symbol_and_objfile (forward_qualified_name);
228 for (i = 0; i < forward_dll_name_len; i++)
229 forward_qualified_name[i] = tolower (forward_qualified_name[i]);
230 msymbol = lookup_minimal_symbol_and_objfile (forward_qualified_name);
235 if (debug_coff_pe_read)
236 fprintf_unfiltered (gdb_stdlog, _("Unable to find function \"%s\" in"
237 " dll \"%s\", forward of \"%s\" in dll \"%s\"\n"),
238 forward_func_name, forward_dll_name, sym_name,
243 if (debug_coff_pe_read > 1)
244 fprintf_unfiltered (gdb_stdlog, _("Adding forwarded exported symbol"
245 " \"%s\" in dll \"%s\", pointing to \"%s\"\n"),
246 sym_name, dll_name, forward_qualified_name);
248 vma = BMSYMBOL_VALUE_ADDRESS (msymbol);
249 msymtype = MSYMBOL_TYPE (msymbol.minsym);
250 section = MSYMBOL_SECTION (msymbol.minsym);
252 /* Generate a (hopefully unique) qualified name using the first part
253 of the dll name, e.g. KERNEL32!AddAtomA. This matches the style
254 used by windbg from the "Microsoft Debugging Tools for Windows". */
256 if (sym_name == NULL || *sym_name == '\0')
257 bare_name = xstrprintf ("#%d", ordinal);
259 bare_name = xstrdup (sym_name);
261 qualified_name = xstrprintf ("%s!%s", dll_name, bare_name);
263 /* Note that this code makes a minimal symbol whose value may point
264 outside of any section in this objfile. These symbols can't
265 really be relocated properly, but nevertheless we make a stab at
266 it, choosing an approach consistent with the history of this
268 baseaddr = ANOFFSET (objfile->section_offsets, SECT_OFF_TEXT (objfile));
270 reader.record_with_info (qualified_name, vma - baseaddr, msymtype, section);
272 /* Enter the plain name as well, which might not be unique. */
273 reader.record_with_info (bare_name, vma - baseaddr, msymtype, section);
274 xfree (qualified_name);
280 /* Truncate a dll_name at the last dot character. */
283 read_pe_truncate_name (char *dll_name)
285 char *last_point = strrchr (dll_name, '.');
287 if (last_point != NULL)
291 /* Low-level support functions, direct from the ld module pe-dll.c. */
293 pe_get16 (bfd *abfd, int where)
297 bfd_seek (abfd, (file_ptr) where, SEEK_SET);
298 bfd_bread (b, (bfd_size_type) 2, abfd);
299 return b[0] + (b[1] << 8);
303 pe_get32 (bfd *abfd, int where)
307 bfd_seek (abfd, (file_ptr) where, SEEK_SET);
308 bfd_bread (b, (bfd_size_type) 4, abfd);
309 return b[0] + (b[1] << 8) + (b[2] << 16) + (b[3] << 24);
315 unsigned char *b = (unsigned char *) ptr;
317 return b[0] + (b[1] << 8);
323 unsigned char *b = (unsigned char *) ptr;
325 return b[0] + (b[1] << 8) + (b[2] << 16) + (b[3] << 24);
328 /* Read the (non-debug) export symbol table from a portable
329 executable. Code originally lifted from the ld function
330 pe_implied_import_dll in pe-dll.c. */
333 read_pe_exported_syms (minimal_symbol_reader &reader,
334 struct objfile *objfile)
336 bfd *dll = objfile->obfd;
337 unsigned long nbnormal, nbforward;
338 unsigned long pe_header_offset, opthdr_ofs, num_entries, i;
339 unsigned long export_opthdrrva, export_opthdrsize;
340 unsigned long export_rva, export_size, nsections, secptr, expptr;
341 unsigned long exp_funcbase;
342 unsigned char *expdata, *erva;
343 unsigned long name_rvas, ordinals, nexp, ordbase;
344 char *dll_name = (char *) dll->filename;
345 int otherix = PE_SECTION_TABLE_SIZE;
349 /* Array elements are for text, data and bss in that order
350 Initialization with RVA_START > RVA_END guarantees that
351 unused sections won't be matched. */
352 struct read_pe_section_data *section_data;
353 struct pe_sections_info pe_sections_info;
355 struct cleanup *back_to = make_cleanup (null_cleanup, 0);
357 char const *target = bfd_get_target (objfile->obfd);
359 section_data = XCNEWVEC (struct read_pe_section_data, PE_SECTION_TABLE_SIZE);
361 make_cleanup (free_current_contents, §ion_data);
363 for (i=0; i < PE_SECTION_TABLE_SIZE; i++)
365 section_data[i].vma_offset = 0;
366 section_data[i].rva_start = 1;
367 section_data[i].rva_end = 0;
369 section_data[PE_SECTION_INDEX_TEXT].ms_type = mst_text;
370 section_data[PE_SECTION_INDEX_TEXT].section_name = ".text";
371 section_data[PE_SECTION_INDEX_DATA].ms_type = mst_data;
372 section_data[PE_SECTION_INDEX_DATA].section_name = ".data";
373 section_data[PE_SECTION_INDEX_BSS].ms_type = mst_bss;
374 section_data[PE_SECTION_INDEX_BSS].section_name = ".bss";
376 is_pe64 = (strcmp (target, "pe-x86-64") == 0
377 || strcmp (target, "pei-x86-64") == 0);
378 is_pe32 = (strcmp (target, "pe-i386") == 0
379 || strcmp (target, "pei-i386") == 0
380 || strcmp (target, "pe-arm-wince-little") == 0
381 || strcmp (target, "pei-arm-wince-little") == 0);
382 if (!is_pe32 && !is_pe64)
384 /* This is not a recognized PE format file. Abort now, because
385 the code is untested on anything else. *FIXME* test on
386 further architectures and loosen or remove this test. */
387 do_cleanups (back_to);
391 /* Get pe_header, optional header and numbers of export entries. */
392 pe_header_offset = pe_get32 (dll, 0x3c);
393 opthdr_ofs = pe_header_offset + 4 + 20;
395 num_entries = pe_get32 (dll, opthdr_ofs + 108);
397 num_entries = pe_get32 (dll, opthdr_ofs + 92);
399 if (num_entries < 1) /* No exports. */
401 do_cleanups (back_to);
406 export_opthdrrva = pe_get32 (dll, opthdr_ofs + 112);
407 export_opthdrsize = pe_get32 (dll, opthdr_ofs + 116);
411 export_opthdrrva = pe_get32 (dll, opthdr_ofs + 96);
412 export_opthdrsize = pe_get32 (dll, opthdr_ofs + 100);
414 nsections = pe_get16 (dll, pe_header_offset + 4 + 2);
415 secptr = (pe_header_offset + 4 + 20 +
416 pe_get16 (dll, pe_header_offset + 4 + 16));
420 /* Get the rva and size of the export section. */
421 for (i = 0; i < nsections; i++)
424 unsigned long secptr1 = secptr + 40 * i;
425 unsigned long vaddr = pe_get32 (dll, secptr1 + 12);
426 unsigned long vsize = pe_get32 (dll, secptr1 + 16);
427 unsigned long fptr = pe_get32 (dll, secptr1 + 20);
429 bfd_seek (dll, (file_ptr) secptr1, SEEK_SET);
430 bfd_bread (sname, (bfd_size_type) sizeof (sname), dll);
432 if ((strcmp (sname, ".edata") == 0)
433 || (vaddr <= export_opthdrrva && export_opthdrrva < vaddr + vsize))
435 if (strcmp (sname, ".edata") != 0)
437 if (debug_coff_pe_read)
438 fprintf_unfiltered (gdb_stdlog, _("Export RVA for dll "
439 "\"%s\" is in section \"%s\"\n"),
442 else if (export_opthdrrva != vaddr && debug_coff_pe_read)
443 fprintf_unfiltered (gdb_stdlog, _("Wrong value of export RVA"
444 " for dll \"%s\": 0x%lx instead of 0x%lx\n"),
445 dll_name, export_opthdrrva, vaddr);
446 expptr = fptr + (export_opthdrrva - vaddr);
451 export_rva = export_opthdrrva;
452 export_size = export_opthdrsize;
454 if (export_size == 0)
456 /* Empty export table. */
457 do_cleanups (back_to);
461 /* Scan sections and store the base and size of the relevant
463 for (i = 0; i < nsections; i++)
465 unsigned long secptr1 = secptr + 40 * i;
466 unsigned long vsize = pe_get32 (dll, secptr1 + 8);
467 unsigned long vaddr = pe_get32 (dll, secptr1 + 12);
468 unsigned long characteristics = pe_get32 (dll, secptr1 + 36);
469 char sec_name[SCNNMLEN + 1];
471 unsigned int bfd_section_index;
474 bfd_seek (dll, (file_ptr) secptr1 + 0, SEEK_SET);
475 bfd_bread (sec_name, (bfd_size_type) SCNNMLEN, dll);
476 sec_name[SCNNMLEN] = '\0';
478 sectix = read_pe_section_index (sec_name);
479 section = bfd_get_section_by_name (dll, sec_name);
481 bfd_section_index = section->index;
483 bfd_section_index = -1;
485 if (sectix != PE_SECTION_INDEX_INVALID)
487 section_data[sectix].rva_start = vaddr;
488 section_data[sectix].rva_end = vaddr + vsize;
489 section_data[sectix].index = bfd_section_index;
495 section_data = XRESIZEVEC (struct read_pe_section_data, section_data,
497 name = xstrdup (sec_name);
498 section_data[otherix].section_name = name;
499 make_cleanup (xfree, name);
500 section_data[otherix].rva_start = vaddr;
501 section_data[otherix].rva_end = vaddr + vsize;
502 section_data[otherix].vma_offset = 0;
503 section_data[otherix].index = bfd_section_index;
504 if (characteristics & IMAGE_SCN_CNT_CODE)
505 section_data[otherix].ms_type = mst_text;
506 else if (characteristics & IMAGE_SCN_CNT_INITIALIZED_DATA)
507 section_data[otherix].ms_type = mst_data;
508 else if (characteristics & IMAGE_SCN_CNT_UNINITIALIZED_DATA)
509 section_data[otherix].ms_type = mst_bss;
511 section_data[otherix].ms_type = mst_unknown;
516 expdata = (unsigned char *) xmalloc (export_size);
517 make_cleanup (xfree, expdata);
519 bfd_seek (dll, (file_ptr) expptr, SEEK_SET);
520 bfd_bread (expdata, (bfd_size_type) export_size, dll);
521 erva = expdata - export_rva;
523 nexp = pe_as32 (expdata + 24);
524 name_rvas = pe_as32 (expdata + 32);
525 ordinals = pe_as32 (expdata + 36);
526 ordbase = pe_as32 (expdata + 16);
527 exp_funcbase = pe_as32 (expdata + 28);
529 /* Use internal dll name instead of full pathname. */
530 dll_name = (char *) (pe_as32 (expdata + 12) + erva);
532 pe_sections_info.nb_sections = otherix;
533 pe_sections_info.sections = section_data;
535 bfd_map_over_sections (dll, get_section_vmas, &pe_sections_info);
537 /* Truncate name at first dot. Should maybe also convert to all
538 lower case for convenience on Windows. */
539 read_pe_truncate_name (dll_name);
541 if (debug_coff_pe_read)
542 fprintf_unfiltered (gdb_stdlog, _("DLL \"%s\" has %ld export entries,"
543 " base=%ld\n"), dll_name, nexp, ordbase);
546 /* Iterate through the list of symbols. */
547 for (i = 0; i < nexp; i++)
549 /* Pointer to the names vector. */
550 unsigned long name_rva = pe_as32 (erva + name_rvas + i * 4);
551 /* Retrieve ordinal value. */
553 unsigned long ordinal = pe_as16 (erva + ordinals + i * 2);
556 /* Pointer to the function address vector. */
557 /* This is relatived to ordinal value. */
558 unsigned long func_rva = pe_as32 (erva + exp_funcbase +
561 /* Find this symbol's section in our own array. */
563 int section_found = 0;
565 /* First handle forward cases. */
566 if (func_rva >= export_rva && func_rva < export_rva + export_size)
568 char *forward_name = (char *) (erva + func_rva);
569 char *funcname = (char *) (erva + name_rva);
570 char *forward_dll_name = forward_name;
571 char *forward_func_name = forward_name;
572 char *sep = strrchr (forward_name, '.');
576 int len = (int) (sep - forward_name);
578 forward_dll_name = (char *) alloca (len + 1);
579 strncpy (forward_dll_name, forward_name, len);
580 forward_dll_name[len] = '\0';
581 forward_func_name = ++sep;
583 if (add_pe_forwarded_sym (reader, funcname, forward_dll_name,
584 forward_func_name, ordinal,
585 dll_name, objfile) != 0)
590 for (sectix = 0; sectix < otherix; ++sectix)
592 if ((func_rva >= section_data[sectix].rva_start)
593 && (func_rva < section_data[sectix].rva_end))
595 char *sym_name = (char *) (erva + name_rva);
598 add_pe_exported_sym (reader, sym_name, func_rva, ordinal,
599 section_data + sectix, dll_name, objfile);
606 char *funcname = (char *) (erva + name_rva);
610 add_pe_exported_sym (reader, NULL, func_rva, ordinal,
611 section_data, dll_name, objfile);
614 else if (debug_coff_pe_read)
615 fprintf_unfiltered (gdb_stdlog, _("Export name \"%s\" ord. %lu,"
616 " RVA 0x%lx in dll \"%s\" not handled\n"),
617 funcname, ordinal, func_rva, dll_name);
621 if (debug_coff_pe_read)
622 fprintf_unfiltered (gdb_stdlog, _("Finished reading \"%s\", exports %ld,"
623 " forwards %ld, total %ld/%ld.\n"), dll_name, nbnormal,
624 nbforward, nbnormal + nbforward, nexp);
625 /* Discard expdata and section_data. */
626 do_cleanups (back_to);
629 /* Extract from ABFD the offset of the .text section.
630 This offset is mainly related to the offset within the file.
631 The value was previously expected to be 0x1000 for all files,
632 but some Windows OS core DLLs seem to use 0x10000 section alignement
633 which modified the return value of that function.
634 Still return default 0x1000 value if ABFD is NULL or
635 if '.text' section is not found, but that should not happen... */
637 #define DEFAULT_COFF_PE_TEXT_SECTION_OFFSET 0x1000
640 pe_text_section_offset (struct bfd *abfd)
643 unsigned long pe_header_offset, i;
644 unsigned long nsections, secptr;
650 return DEFAULT_COFF_PE_TEXT_SECTION_OFFSET;
652 target = bfd_get_target (abfd);
654 is_pe64 = (strcmp (target, "pe-x86-64") == 0
655 || strcmp (target, "pei-x86-64") == 0);
656 is_pe32 = (strcmp (target, "pe-i386") == 0
657 || strcmp (target, "pei-i386") == 0
658 || strcmp (target, "pe-arm-wince-little") == 0
659 || strcmp (target, "pei-arm-wince-little") == 0);
661 if (!is_pe32 && !is_pe64)
663 /* This is not a recognized PE format file. Abort now, because
664 the code is untested on anything else. *FIXME* test on
665 further architectures and loosen or remove this test. */
666 return DEFAULT_COFF_PE_TEXT_SECTION_OFFSET;
669 /* Get pe_header, optional header and numbers of sections. */
670 pe_header_offset = pe_get32 (abfd, 0x3c);
671 nsections = pe_get16 (abfd, pe_header_offset + 4 + 2);
672 secptr = (pe_header_offset + 4 + 20 +
673 pe_get16 (abfd, pe_header_offset + 4 + 16));
675 /* Get the rva and size of the export section. */
676 for (i = 0; i < nsections; i++)
678 char sname[SCNNMLEN + 1];
679 unsigned long secptr1 = secptr + 40 * i;
680 unsigned long vaddr = pe_get32 (abfd, secptr1 + 12);
682 bfd_seek (abfd, (file_ptr) secptr1, SEEK_SET);
683 bfd_bread (sname, (bfd_size_type) SCNNMLEN, abfd);
684 sname[SCNNMLEN] = '\0';
685 if (strcmp (sname, ".text") == 0)
689 return DEFAULT_COFF_PE_TEXT_SECTION_OFFSET;
692 /* Implements "show debug coff_pe_read" command. */
695 show_debug_coff_pe_read (struct ui_file *file, int from_tty,
696 struct cmd_list_element *c, const char *value)
698 fprintf_filtered (file, _("Coff PE read debugging is %s.\n"), value);
701 /* Adds "Set/show debug coff_pe_read" commands. */
704 _initialize_coff_pe_read (void)
706 add_setshow_zuinteger_cmd ("coff-pe-read", class_maintenance,
708 _("Set coff PE read debugging."),
709 _("Show coff PE read debugging."),
710 _("When set, debugging messages for coff reading "
711 "of exported symbols are displayed."),
712 NULL, show_debug_coff_pe_read,
713 &setdebuglist, &showdebuglist);