1 /* Read the export table symbols from a portable executable and
2 convert to internal format, for GDB. Used as a last resort if no
3 debugging symbols recognized.
5 Copyright (C) 2003, 2007-2012 Free Software Foundation, Inc.
7 This file is part of GDB.
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
22 Contributed by Raoul M. Gough (RaoulGough@yahoo.co.uk). */
26 #include "coff-pe-read.h"
36 #include "common/common-utils.h"
37 #include "coff/internal.h"
41 /* Internal section information */
43 /* Coff PE read debugging flag:
45 value 1 outputs problems encountered while parsing PE file,
46 value above 1 also lists all generated minimal symbols. */
47 static unsigned int debug_coff_pe_read;
49 struct read_pe_section_data
51 CORE_ADDR vma_offset; /* Offset to loaded address of section. */
52 unsigned long rva_start; /* Start offset within the pe. */
53 unsigned long rva_end; /* End offset within the pe. */
54 enum minimal_symbol_type ms_type; /* Type to assign symbols in
56 char *section_name; /* Recorded section name. */
59 #define IMAGE_SCN_CNT_CODE 0x20
60 #define IMAGE_SCN_CNT_INITIALIZED_DATA 0x40
61 #define IMAGE_SCN_CNT_UNINITIALIZED_DATA 0x80
62 #define PE_SECTION_INDEX_TEXT 0
63 #define PE_SECTION_INDEX_DATA 1
64 #define PE_SECTION_INDEX_BSS 2
65 #define PE_SECTION_TABLE_SIZE 3
66 #define PE_SECTION_INDEX_INVALID -1
68 /* Get the index of the named section in our own array, which contains
69 text, data and bss in that order. Return PE_SECTION_INDEX_INVALID
70 if passed an unrecognised section name. */
73 read_pe_section_index (const char *section_name)
75 if (strcmp (section_name, ".text") == 0)
77 return PE_SECTION_INDEX_TEXT;
80 else if (strcmp (section_name, ".data") == 0)
82 return PE_SECTION_INDEX_DATA;
85 else if (strcmp (section_name, ".bss") == 0)
87 return PE_SECTION_INDEX_BSS;
92 return PE_SECTION_INDEX_INVALID;
96 /* Get the index of the named section in our own full arrayi.
97 text, data and bss in that order. Return PE_SECTION_INDEX_INVALID
98 if passed an unrecognised section name. */
101 get_pe_section_index (const char *section_name,
102 struct read_pe_section_data *sections,
107 for (i = 0; i < nb_sections; i++)
108 if (strcmp (sections[i].section_name, section_name) == 0)
110 return PE_SECTION_INDEX_INVALID;
113 /* Structure used by get_section_vmas function below
114 to access section_data array and the size of the array
115 stored in nb_sections field. */
116 struct pe_sections_info
119 struct read_pe_section_data *sections;
122 /* Record the virtual memory address of a section. */
125 get_section_vmas (bfd *abfd, asection *sectp, void *context)
127 struct pe_sections_info *data = context;
128 struct read_pe_section_data *sections = data->sections;
129 int sectix = get_pe_section_index (sectp->name, sections,
132 if (sectix != PE_SECTION_INDEX_INVALID)
134 /* Data within the section start at rva_start in the pe and at
135 bfd_get_section_vma() within memory. Store the offset. */
137 sections[sectix].vma_offset
138 = bfd_get_section_vma (abfd, sectp) - sections[sectix].rva_start;
142 /* Create a minimal symbol entry for an exported symbol.
143 SYM_NAME contains the exported name or NULL if exported by ordinal,
144 FUNC_RVA contains the Relative Virtual Address of the symbol,
145 ORDINAL is the ordinal index value of the symbol,
146 SECTION_DATA contains information about the section in which the
148 DLL_NAME is the internal name of the DLL file,
149 OBJFILE is the objfile struct of DLL_NAME. */
152 add_pe_exported_sym (const char *sym_name,
153 unsigned long func_rva,
155 const struct read_pe_section_data *section_data,
156 const char *dll_name, struct objfile *objfile)
158 char *qualified_name, *bare_name;
159 /* Add the stored offset to get the loaded address of the symbol. */
160 CORE_ADDR vma = func_rva + section_data->vma_offset;
161 int dll_name_len = strlen (dll_name);
163 /* Generate a (hopefully unique) qualified name using the first part
164 of the dll name, e.g. KERNEL32!AddAtomA. This matches the style
165 used by windbg from the "Microsoft Debugging Tools for Windows". */
167 if (sym_name == NULL || *sym_name == '\0')
168 bare_name = xstrprintf ("#%d", ordinal);
170 bare_name = xstrdup (sym_name);
172 qualified_name = xstrprintf ("%s!%s", dll_name, bare_name);
174 if ((section_data->ms_type == mst_unknown) && debug_coff_pe_read)
175 fprintf_unfiltered (gdb_stdlog , _("Unknown section type for \"%s\""
176 " for entry \"%s\" in dll \"%s\"\n"),
177 section_data->section_name, sym_name, dll_name);
179 prim_record_minimal_symbol (qualified_name, vma,
180 section_data->ms_type, objfile);
182 /* Enter the plain name as well, which might not be unique. */
183 prim_record_minimal_symbol (bare_name, vma, section_data->ms_type, objfile);
184 if (debug_coff_pe_read > 1)
185 fprintf_unfiltered (gdb_stdlog, _("Adding exported symbol \"%s\""
186 " in dll \"%s\"\n"), sym_name, dll_name);
187 xfree (qualified_name);
191 /* Create a minimal symbol entry for an exported forward symbol.
192 Return 1 if the forwarded function was found 0 otherwise.
193 SYM_NAME contains the exported name or NULL if exported by ordinal,
194 FORWARD_DLL_NAME is the name of the DLL in which the target symobl resides,
195 FORWARD_FUNC_NAME is the name of the target symbol in that DLL,
196 ORDINAL is the ordinal index value of the symbol,
197 DLL_NAME is the internal name of the DLL file,
198 OBJFILE is the objfile struct of DLL_NAME. */
201 add_pe_forwarded_sym (const char *sym_name, const char *forward_dll_name,
202 const char *forward_func_name, int ordinal,
203 const char *dll_name, struct objfile *objfile)
206 struct objfile *forward_objfile;
207 struct minimal_symbol *msymbol;
209 enum minimal_symbol_type msymtype;
210 int dll_name_len = strlen (dll_name);
211 char *qualified_name, *bare_name;
212 int forward_dll_name_len = strlen (forward_dll_name);
213 int forward_func_name_len = strlen (forward_func_name);
214 int forward_len = forward_dll_name_len + forward_func_name_len + 2;
215 char *forward_qualified_name = alloca (forward_len);
217 xsnprintf (forward_qualified_name, forward_len, "%s!%s", forward_dll_name,
221 msymbol = lookup_minimal_symbol_and_objfile (forward_qualified_name,
228 for (i = 0; i < forward_dll_name_len; i++)
229 forward_qualified_name[i] = tolower (forward_qualified_name[i]);
230 msymbol = lookup_minimal_symbol_and_objfile (forward_qualified_name,
236 if (debug_coff_pe_read)
237 fprintf_unfiltered (gdb_stdlog, _("Unable to find function \"%s\" in"
238 " dll \"%s\", forward of \"%s\" in dll \"%s\"\n"),
239 forward_func_name, forward_dll_name, sym_name,
244 if (debug_coff_pe_read > 1)
245 fprintf_unfiltered (gdb_stdlog, _("Adding forwarded exported symbol"
246 " \"%s\" in dll \"%s\", pointing to \"%s\"\n"),
247 sym_name, dll_name, forward_qualified_name);
249 vma = SYMBOL_VALUE_ADDRESS (msymbol);
250 section = SYMBOL_SECTION (msymbol);
251 msymtype = MSYMBOL_TYPE (msymbol);
253 /* Generate a (hopefully unique) qualified name using the first part
254 of the dll name, e.g. KERNEL32!AddAtomA. This matches the style
255 used by windbg from the "Microsoft Debugging Tools for Windows". */
257 if (sym_name == NULL || *sym_name == '\0')
258 bare_name = xstrprintf ("#%d", ordinal);
260 bare_name = xstrdup (sym_name);
262 qualified_name = xstrprintf ("%s!%s", dll_name, bare_name);
264 prim_record_minimal_symbol (qualified_name, vma, msymtype, objfile);
266 /* Enter the plain name as well, which might not be unique. */
267 prim_record_minimal_symbol (bare_name, vma, msymtype, objfile);
268 xfree (qualified_name);
274 /* Truncate a dll_name at the last dot character. */
277 read_pe_truncate_name (char *dll_name)
279 char *last_point = strrchr (dll_name, '.');
281 if (last_point != NULL)
285 /* Low-level support functions, direct from the ld module pe-dll.c. */
287 pe_get16 (bfd *abfd, int where)
291 bfd_seek (abfd, (file_ptr) where, SEEK_SET);
292 bfd_bread (b, (bfd_size_type) 2, abfd);
293 return b[0] + (b[1] << 8);
297 pe_get32 (bfd *abfd, int where)
301 bfd_seek (abfd, (file_ptr) where, SEEK_SET);
302 bfd_bread (b, (bfd_size_type) 4, abfd);
303 return b[0] + (b[1] << 8) + (b[2] << 16) + (b[3] << 24);
309 unsigned char *b = ptr;
311 return b[0] + (b[1] << 8);
317 unsigned char *b = ptr;
319 return b[0] + (b[1] << 8) + (b[2] << 16) + (b[3] << 24);
322 /* Read the (non-debug) export symbol table from a portable
323 executable. Code originally lifted from the ld function
324 pe_implied_import_dll in pe-dll.c. */
327 read_pe_exported_syms (struct objfile *objfile)
329 bfd *dll = objfile->obfd;
330 unsigned long nbnormal, nbforward;
331 unsigned long pe_header_offset, opthdr_ofs, num_entries, i;
332 unsigned long export_opthdrrva, export_opthdrsize;
333 unsigned long export_rva, export_size, nsections, secptr, expptr;
334 unsigned long exp_funcbase;
335 unsigned char *expdata, *erva;
336 unsigned long name_rvas, ordinals, nexp, ordbase;
337 char *dll_name = (char *) dll->filename;
338 int otherix = PE_SECTION_TABLE_SIZE;
343 /* Array elements are for text, data and bss in that order
344 Initialization with RVA_START > RVA_END guarantees that
345 unused sections won't be matched. */
346 struct read_pe_section_data *section_data;
347 struct pe_sections_info pe_sections_info;
349 struct cleanup *back_to = make_cleanup (null_cleanup, 0);
351 char const *target = bfd_get_target (objfile->obfd);
353 section_data = xzalloc (PE_SECTION_TABLE_SIZE
354 * sizeof (struct read_pe_section_data));
356 make_cleanup (free_current_contents, §ion_data);
358 for (i=0; i < PE_SECTION_TABLE_SIZE; i++)
360 section_data[i].vma_offset = 0;
361 section_data[i].rva_start = 1;
362 section_data[i].rva_end = 0;
364 section_data[PE_SECTION_INDEX_TEXT].ms_type = mst_text;
365 section_data[PE_SECTION_INDEX_TEXT].section_name = ".text";
366 section_data[PE_SECTION_INDEX_DATA].ms_type = mst_data;
367 section_data[PE_SECTION_INDEX_DATA].section_name = ".data";
368 section_data[PE_SECTION_INDEX_BSS].ms_type = mst_bss;
369 section_data[PE_SECTION_INDEX_BSS].section_name = ".bss";
371 is_pe64 = (strcmp (target, "pe-x86-64") == 0
372 || strcmp (target, "pei-x86-64") == 0);
373 is_pe32 = (strcmp (target, "pe-i386") == 0
374 || strcmp (target, "pei-i386") == 0
375 || strcmp (target, "pe-arm-wince-little") == 0
376 || strcmp (target, "pei-arm-wince-little") == 0);
377 if (!is_pe32 && !is_pe64)
379 /* This is not a recognized PE format file. Abort now, because
380 the code is untested on anything else. *FIXME* test on
381 further architectures and loosen or remove this test. */
385 /* Get pe_header, optional header and numbers of export entries. */
386 pe_header_offset = pe_get32 (dll, 0x3c);
387 opthdr_ofs = pe_header_offset + 4 + 20;
389 num_entries = pe_get32 (dll, opthdr_ofs + 108);
391 num_entries = pe_get32 (dll, opthdr_ofs + 92);
393 if (num_entries < 1) /* No exports. */
399 export_opthdrrva = pe_get32 (dll, opthdr_ofs + 112);
400 export_opthdrsize = pe_get32 (dll, opthdr_ofs + 116);
404 export_opthdrrva = pe_get32 (dll, opthdr_ofs + 96);
405 export_opthdrsize = pe_get32 (dll, opthdr_ofs + 100);
407 nsections = pe_get16 (dll, pe_header_offset + 4 + 2);
408 secptr = (pe_header_offset + 4 + 20 +
409 pe_get16 (dll, pe_header_offset + 4 + 16));
413 /* Get the rva and size of the export section. */
414 for (i = 0; i < nsections; i++)
417 unsigned long secptr1 = secptr + 40 * i;
418 unsigned long vaddr = pe_get32 (dll, secptr1 + 12);
419 unsigned long vsize = pe_get32 (dll, secptr1 + 16);
420 unsigned long fptr = pe_get32 (dll, secptr1 + 20);
422 bfd_seek (dll, (file_ptr) secptr1, SEEK_SET);
423 bfd_bread (sname, (bfd_size_type) sizeof (sname), dll);
425 if ((strcmp (sname, ".edata") == 0)
426 || (vaddr <= export_opthdrrva && export_opthdrrva < vaddr + vsize))
428 if (strcmp (sname, ".edata") != 0)
430 if (debug_coff_pe_read)
431 fprintf_unfiltered (gdb_stdlog, _("Export RVA for dll "
432 "\"%s\" is in section \"%s\"\n"),
435 else if (export_opthdrrva != vaddr && debug_coff_pe_read)
436 fprintf_unfiltered (gdb_stdlog, _("Wrong value of export RVA"
437 " for dll \"%s\": 0x%lx instead of 0x%lx\n"),
438 dll_name, export_opthdrrva, vaddr);
439 expptr = fptr + (export_opthdrrva - vaddr);
445 export_rva = export_opthdrrva;
446 export_size = export_opthdrsize;
448 if (export_size == 0)
450 /* Empty export table. */
454 /* Scan sections and store the base and size of the relevant
456 for (i = 0; i < nsections; i++)
458 unsigned long secptr1 = secptr + 40 * i;
459 unsigned long vsize = pe_get32 (dll, secptr1 + 8);
460 unsigned long vaddr = pe_get32 (dll, secptr1 + 12);
461 unsigned long characteristics = pe_get32 (dll, secptr1 + 36);
462 char sec_name[SCNNMLEN + 1];
465 bfd_seek (dll, (file_ptr) secptr1 + 0, SEEK_SET);
466 bfd_bread (sec_name, (bfd_size_type) SCNNMLEN, dll);
467 sec_name[SCNNMLEN] = '\0';
469 sectix = read_pe_section_index (sec_name);
471 if (sectix != PE_SECTION_INDEX_INVALID)
473 section_data[sectix].rva_start = vaddr;
474 section_data[sectix].rva_end = vaddr + vsize;
480 section_data = xrealloc (section_data, (otherix + 1)
481 * sizeof (struct read_pe_section_data));
482 name = xstrdup (sec_name);
483 section_data[otherix].section_name = name;
484 make_cleanup (xfree, name);
485 section_data[otherix].rva_start = vaddr;
486 section_data[otherix].rva_end = vaddr + vsize;
487 section_data[otherix].vma_offset = 0;
488 if (characteristics & IMAGE_SCN_CNT_CODE)
489 section_data[otherix].ms_type = mst_text;
490 else if (characteristics & IMAGE_SCN_CNT_INITIALIZED_DATA)
491 section_data[otherix].ms_type = mst_data;
492 else if (characteristics & IMAGE_SCN_CNT_UNINITIALIZED_DATA)
493 section_data[otherix].ms_type = mst_bss;
495 section_data[otherix].ms_type = mst_unknown;
500 expdata = (unsigned char *) xmalloc (export_size);
501 make_cleanup (xfree, expdata);
503 bfd_seek (dll, (file_ptr) expptr, SEEK_SET);
504 bfd_bread (expdata, (bfd_size_type) export_size, dll);
505 erva = expdata - export_rva;
507 nexp = pe_as32 (expdata + 24);
508 name_rvas = pe_as32 (expdata + 32);
509 ordinals = pe_as32 (expdata + 36);
510 ordbase = pe_as32 (expdata + 16);
511 exp_funcbase = pe_as32 (expdata + 28);
513 /* Use internal dll name instead of full pathname. */
514 dll_name = pe_as32 (expdata + 12) + erva;
516 pe_sections_info.nb_sections = otherix;
517 pe_sections_info.sections = section_data;
519 bfd_map_over_sections (dll, get_section_vmas, &pe_sections_info);
521 /* Adjust the vma_offsets in case this PE got relocated. This
522 assumes that *all* sections share the same relocation offset
523 as the text section. */
524 for (i = 0; i < otherix; i++)
526 section_data[i].vma_offset
527 += ANOFFSET (objfile->section_offsets, SECT_OFF_TEXT (objfile));
530 /* Truncate name at first dot. Should maybe also convert to all
531 lower case for convenience on Windows. */
532 read_pe_truncate_name (dll_name);
534 if (debug_coff_pe_read)
535 fprintf_unfiltered (gdb_stdlog, _("DLL \"%s\" has %ld export entries,"
536 " base=%ld\n"), dll_name, nexp, ordbase);
539 /* Iterate through the list of symbols. */
540 for (i = 0; i < nexp; i++)
542 /* Pointer to the names vector. */
543 unsigned long name_rva = pe_as32 (erva + name_rvas + i * 4);
544 /* Retrieve ordinal value. */
546 unsigned long ordinal = pe_as16 (erva + ordinals + i * 2);
549 /* Pointer to the function address vector. */
550 /* This is relatived to ordinal value. */
551 unsigned long func_rva = pe_as32 (erva + exp_funcbase +
554 /* Find this symbol's section in our own array. */
556 int section_found = 0;
558 /* First handle forward cases. */
559 if (func_rva >= export_rva && func_rva < export_rva + export_size)
561 char *forward_name = (char *) (erva + func_rva);
562 char *funcname = (char *) (erva + name_rva);
563 char *forward_dll_name = forward_name;
564 char *forward_func_name = forward_name;
565 char *sep = strrchr (forward_name, '.');
569 int len = (int) (sep - forward_name);
571 forward_dll_name = alloca (len + 1);
572 strncpy (forward_dll_name, forward_name, len);
573 forward_dll_name[len] = '\0';
574 forward_func_name = ++sep;
576 if (add_pe_forwarded_sym (funcname, forward_dll_name,
577 forward_func_name, ordinal,
578 dll_name, objfile) != 0)
583 for (sectix = 0; sectix < otherix; ++sectix)
585 if ((func_rva >= section_data[sectix].rva_start)
586 && (func_rva < section_data[sectix].rva_end))
589 add_pe_exported_sym (erva + name_rva,
591 section_data + sectix, dll_name, objfile);
598 char *funcname = (char *) (erva + name_rva);
602 add_pe_exported_sym (NULL, func_rva, ordinal,
603 section_data, dll_name, objfile);
606 else if (debug_coff_pe_read)
607 fprintf_unfiltered (gdb_stdlog, _("Export name \"%s\" ord. %lu,"
608 " RVA 0x%lx in dll \"%s\" not handled\n"),
609 funcname, ordinal, func_rva, dll_name);
613 if (debug_coff_pe_read)
614 fprintf_unfiltered (gdb_stdlog, _("Finished reading \"%s\", exports %ld,"
615 " forwards %ld, total %ld/%ld.\n"), dll_name, nbnormal,
616 nbforward, nbnormal + nbforward, nexp);
617 /* Discard expdata and section_data. */
618 do_cleanups (back_to);
621 /* Extract from ABFD the offset of the .text section.
622 This offset is mainly related to the offset within the file.
623 The value was previously expected to be 0x1000 for all files,
624 but some Windows OS core DLLs seem to use 0x10000 section alignement
625 which modified the return value of that function.
626 Still return default 0x1000 value if ABFD is NULL or
627 if '.text' section is not found, but that should not happen... */
629 #define DEFAULT_COFF_PE_TEXT_SECTION_OFFSET 0x1000
632 pe_text_section_offset (struct bfd *abfd)
635 unsigned long pe_header_offset, opthdr_ofs, num_entries, i;
636 unsigned long export_rva, export_size, nsections, secptr, expptr;
637 unsigned long exp_funcbase;
638 unsigned char *expdata, *erva;
639 unsigned long name_rvas, ordinals, nexp, ordbase;
646 return DEFAULT_COFF_PE_TEXT_SECTION_OFFSET;
648 target = bfd_get_target (abfd);
650 is_pe64 = (strcmp (target, "pe-x86-64") == 0
651 || strcmp (target, "pei-x86-64") == 0);
652 is_pe32 = (strcmp (target, "pe-i386") == 0
653 || strcmp (target, "pei-i386") == 0
654 || strcmp (target, "pe-arm-wince-little") == 0
655 || strcmp (target, "pei-arm-wince-little") == 0);
657 if (!is_pe32 && !is_pe64)
659 /* This is not a recognized PE format file. Abort now, because
660 the code is untested on anything else. *FIXME* test on
661 further architectures and loosen or remove this test. */
662 return DEFAULT_COFF_PE_TEXT_SECTION_OFFSET;
665 /* Get pe_header, optional header and numbers of sections. */
666 pe_header_offset = pe_get32 (abfd, 0x3c);
667 opthdr_ofs = pe_header_offset + 4 + 20;
668 nsections = pe_get16 (abfd, pe_header_offset + 4 + 2);
669 secptr = (pe_header_offset + 4 + 20 +
670 pe_get16 (abfd, pe_header_offset + 4 + 16));
672 /* Get the rva and size of the export section. */
673 for (i = 0; i < nsections; i++)
676 unsigned long secptr1 = secptr + 40 * i;
677 unsigned long vaddr = pe_get32 (abfd, secptr1 + 12);
679 bfd_seek (abfd, (file_ptr) secptr1, SEEK_SET);
680 bfd_bread (sname, (bfd_size_type) 8, abfd);
681 if (strcmp (sname, ".text") == 0)
685 return DEFAULT_COFF_PE_TEXT_SECTION_OFFSET;
688 /* Implements "show debug coff_pe_read" command. */
691 show_debug_coff_pe_read (struct ui_file *file, int from_tty,
692 struct cmd_list_element *c, const char *value)
694 fprintf_filtered (file, _("Coff PE read debugging is %s.\n"), value);
697 /* Provide a prototype to silence -Wmissing-prototypes. */
699 void _initialize_coff_pe_read (void);
701 /* Adds "Set/show debug coff_pe_read" commands. */
704 _initialize_coff_pe_read (void)
706 add_setshow_uinteger_cmd ("coff_pe_read", class_maintenance,
708 _("Set coff PE read debugging."),
709 _("Show coff PE read debugging."),
710 _("When set, debugging messages for coff reading "
711 "of exported symbols are displayed."),
712 NULL, show_debug_coff_pe_read,
713 &setdebuglist, &showdebuglist);