1 /* pecoff.c -- Get debug data from a PE/COFFF file for backtraces.
2 Copyright (C) 2015-2020 Free Software Foundation, Inc.
3 Adapted from elf.c by Tristan Gingold, AdaCore.
5 Redistribution and use in source and binary forms, with or without
6 modification, are permitted provided that the following conditions are
9 (1) Redistributions of source code must retain the above copyright
10 notice, this list of conditions and the following disclaimer.
12 (2) Redistributions in binary form must reproduce the above copyright
13 notice, this list of conditions and the following disclaimer in
14 the documentation and/or other materials provided with the
17 (3) The name of the author may not be used to
18 endorse or promote products derived from this software without
19 specific prior written permission.
21 THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
22 IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
23 WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
24 DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT,
25 INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
26 (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
27 SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
29 STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING
30 IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
31 POSSIBILITY OF SUCH DAMAGE. */
37 #include <sys/types.h>
39 #include "backtrace.h"
42 /* Coff file header. */
46 uint16_t number_of_sections
;
47 uint32_t time_date_stamp
;
48 uint32_t pointer_to_symbol_table
;
49 uint32_t number_of_symbols
;
50 uint16_t size_of_optional_header
;
51 uint16_t characteristics
;
54 /* Coff optional header. */
58 uint8_t major_linker_version
;
59 uint8_t minor_linker_version
;
60 uint32_t size_of_code
;
61 uint32_t size_of_initialized_data
;
62 uint32_t size_of_uninitialized_data
;
63 uint32_t address_of_entry_point
;
64 uint32_t base_of_code
;
67 uint32_t base_of_data
;
74 } b_coff_optional_header
;
76 /* Values of magic in optional header. */
78 #define PE_MAGIC 0x10b /* PE32 executable. */
79 #define PEP_MAGIC 0x20b /* PE32+ executable (for 64bit targets). */
81 /* Coff section header. */
85 uint32_t virtual_size
;
86 uint32_t virtual_address
;
87 uint32_t size_of_raw_data
;
88 uint32_t pointer_to_raw_data
;
89 uint32_t pointer_to_relocations
;
90 uint32_t pointer_to_line_numbers
;
91 uint16_t number_of_relocations
;
92 uint16_t number_of_line_numbers
;
93 uint32_t characteristics
;
94 } b_coff_section_header
;
96 /* Coff symbol name. */
101 unsigned char zeroes
[4];
102 unsigned char off
[4];
106 /* Coff symbol (external representation which is unaligned). */
110 unsigned char value
[4];
111 unsigned char section_number
[2];
112 unsigned char type
[2];
113 unsigned char storage_class
;
114 unsigned char number_of_aux_symbols
;
115 } b_coff_external_symbol
;
119 #define N_TBSHFT 4 /* Shift for the derived type. */
120 #define IMAGE_SYM_DTYPE_FUNCTION 2 /* Function derived type. */
122 /* Size of a coff symbol. */
126 /* Coff symbol, internal representation (aligned). */
134 } b_coff_internal_symbol
;
136 /* Names of sections, indexed by enum dwarf_section in internal.h. */
138 static const char * const debug_section_names
[DEBUG_MAX
] =
146 ".debug_str_offsets",
151 /* Information we gather for the sections we care about. */
153 struct debug_section_info
155 /* Section file offset. */
161 /* Information we keep for an coff symbol. */
165 /* The name of the symbol. */
167 /* The address of the symbol. */
171 /* Information to pass to coff_syminfo. */
173 struct coff_syminfo_data
175 /* Symbols for the next module. */
176 struct coff_syminfo_data
*next
;
177 /* The COFF symbols, sorted by address. */
178 struct coff_symbol
*symbols
;
179 /* The number of symbols. */
183 /* A dummy callback function used when we can't find any debug info. */
186 coff_nodebug (struct backtrace_state
*state ATTRIBUTE_UNUSED
,
187 uintptr_t pc ATTRIBUTE_UNUSED
,
188 backtrace_full_callback callback ATTRIBUTE_UNUSED
,
189 backtrace_error_callback error_callback
, void *data
)
191 error_callback (data
, "no debug info in PE/COFF executable", -1);
195 /* A dummy callback function used when we can't find a symbol
199 coff_nosyms (struct backtrace_state
*state ATTRIBUTE_UNUSED
,
200 uintptr_t addr ATTRIBUTE_UNUSED
,
201 backtrace_syminfo_callback callback ATTRIBUTE_UNUSED
,
202 backtrace_error_callback error_callback
, void *data
)
204 error_callback (data
, "no symbol table in PE/COFF executable", -1);
207 /* Read a potentially unaligned 4 byte word at P, using native endianness. */
210 coff_read4 (const unsigned char *p
)
218 /* Read a potentially unaligned 2 byte word at P, using native endianness.
219 All 2 byte word in symbols are always aligned, but for coherency all
220 fields are declared as char arrays. */
223 coff_read2 (const unsigned char *p
)
227 memcpy (&res
, p
, sizeof (res
));
231 /* Return the length (without the trailing 0) of a COFF short name. */
234 coff_short_name_len (const char *name
)
238 for (i
= 0; i
< 8; i
++)
244 /* Return true iff COFF short name CNAME is the same as NAME (a NUL-terminated
248 coff_short_name_eq (const char *name
, const char *cname
)
252 for (i
= 0; i
< 8; i
++)
254 if (name
[i
] != cname
[i
])
262 /* Return true iff NAME is the same as string at offset OFF. */
265 coff_long_name_eq (const char *name
, unsigned int off
,
266 struct backtrace_view
*str_view
)
268 if (off
>= str_view
->len
)
270 return strcmp (name
, (const char *)str_view
->data
+ off
) == 0;
273 /* Compare struct coff_symbol for qsort. */
276 coff_symbol_compare (const void *v1
, const void *v2
)
278 const struct coff_symbol
*e1
= (const struct coff_symbol
*) v1
;
279 const struct coff_symbol
*e2
= (const struct coff_symbol
*) v2
;
281 if (e1
->address
< e2
->address
)
283 else if (e1
->address
> e2
->address
)
289 /* Convert SYM to internal (and aligned) format ISYM, using string table
290 from STRTAB and STRTAB_SIZE, and number of sections SECTS_NUM.
291 Return -1 in case of error (invalid section number or string index). */
294 coff_expand_symbol (b_coff_internal_symbol
*isym
,
295 const b_coff_external_symbol
*sym
,
297 const unsigned char *strtab
, size_t strtab_size
)
299 isym
->type
= coff_read2 (sym
->type
);
300 isym
->sec
= coff_read2 (sym
->section_number
);
301 isym
->sc
= sym
->storage_class
;
303 if (isym
->sec
> 0 && (uint16_t) isym
->sec
> sects_num
)
305 if (sym
->name
.short_name
[0] != 0)
306 isym
->name
= sym
->name
.short_name
;
309 uint32_t off
= coff_read4 (sym
->name
.long_name
.off
);
311 if (off
>= strtab_size
)
313 isym
->name
= (const char *) strtab
+ off
;
318 /* Return true iff SYM is a defined symbol for a function. Data symbols
319 aren't considered because they aren't easily identified (same type as
320 section names, presence of symbols defined by the linker script). */
323 coff_is_function_symbol (const b_coff_internal_symbol
*isym
)
325 return (isym
->type
>> N_TBSHFT
) == IMAGE_SYM_DTYPE_FUNCTION
329 /* Initialize the symbol table info for coff_syminfo. */
332 coff_initialize_syminfo (struct backtrace_state
*state
,
333 uintptr_t base_address
,
334 const b_coff_section_header
*sects
, size_t sects_num
,
335 const b_coff_external_symbol
*syms
, size_t syms_size
,
336 const unsigned char *strtab
, size_t strtab_size
,
337 backtrace_error_callback error_callback
,
338 void *data
, struct coff_syminfo_data
*sdata
)
342 size_t coff_symstr_len
;
343 size_t coff_symbol_count
;
344 size_t coff_symbol_size
;
345 struct coff_symbol
*coff_symbols
;
346 struct coff_symbol
*coff_sym
;
350 syms_count
= syms_size
/ SYM_SZ
;
352 /* We only care about function symbols. Count them. Also count size of
353 strings for in-symbol names. */
354 coff_symbol_count
= 0;
356 for (i
= 0; i
< syms_count
; ++i
)
358 const b_coff_external_symbol
*asym
= &syms
[i
];
359 b_coff_internal_symbol isym
;
361 if (coff_expand_symbol (&isym
, asym
, sects_num
, strtab
, strtab_size
) < 0)
363 error_callback (data
, "invalid section or offset in coff symbol", 0);
366 if (coff_is_function_symbol (&isym
))
369 if (asym
->name
.short_name
[0] != 0)
370 coff_symstr_len
+= coff_short_name_len (asym
->name
.short_name
) + 1;
373 i
+= asym
->number_of_aux_symbols
;
376 coff_symbol_size
= (coff_symbol_count
+ 1) * sizeof (struct coff_symbol
);
377 coff_symbols
= ((struct coff_symbol
*)
378 backtrace_alloc (state
, coff_symbol_size
, error_callback
,
380 if (coff_symbols
== NULL
)
383 /* Allocate memory for symbols strings. */
384 if (coff_symstr_len
> 0)
386 coff_symstr
= ((char *)
387 backtrace_alloc (state
, coff_symstr_len
, error_callback
,
389 if (coff_symstr
== NULL
)
391 backtrace_free (state
, coff_symbols
, coff_symbol_size
,
392 error_callback
, data
);
400 coff_sym
= coff_symbols
;
401 coff_str
= coff_symstr
;
402 for (i
= 0; i
< syms_count
; ++i
)
404 const b_coff_external_symbol
*asym
= &syms
[i
];
405 b_coff_internal_symbol isym
;
407 if (coff_expand_symbol (&isym
, asym
, sects_num
, strtab
, strtab_size
))
409 /* Should not fail, as it was already tested in the previous
413 if (coff_is_function_symbol (&isym
))
418 if (asym
->name
.short_name
[0] != 0)
420 size_t len
= coff_short_name_len (isym
.name
);
422 memcpy (coff_str
, isym
.name
, len
);
429 /* Strip leading '_'. */
433 /* Symbol value is section relative, so we need to read the address
435 secnum
= coff_read2 (asym
->section_number
);
437 coff_sym
->name
= name
;
438 coff_sym
->address
= (coff_read4 (asym
->value
)
439 + sects
[secnum
- 1].virtual_address
444 i
+= asym
->number_of_aux_symbols
;
447 /* End of symbols marker. */
448 coff_sym
->name
= NULL
;
449 coff_sym
->address
= -1;
451 backtrace_qsort (coff_symbols
, coff_symbol_count
,
452 sizeof (struct coff_symbol
), coff_symbol_compare
);
455 sdata
->symbols
= coff_symbols
;
456 sdata
->count
= coff_symbol_count
;
461 /* Add EDATA to the list in STATE. */
464 coff_add_syminfo_data (struct backtrace_state
*state
,
465 struct coff_syminfo_data
*sdata
)
467 if (!state
->threaded
)
469 struct coff_syminfo_data
**pp
;
471 for (pp
= (struct coff_syminfo_data
**) (void *) &state
->syminfo_data
;
481 struct coff_syminfo_data
**pp
;
483 pp
= (struct coff_syminfo_data
**) (void *) &state
->syminfo_data
;
487 struct coff_syminfo_data
*p
;
489 p
= backtrace_atomic_load_pointer (pp
);
497 if (__sync_bool_compare_and_swap (pp
, NULL
, sdata
))
503 /* Compare an ADDR against an elf_symbol for bsearch. We allocate one
504 extra entry in the array so that this can look safely at the next
508 coff_symbol_search (const void *vkey
, const void *ventry
)
510 const uintptr_t *key
= (const uintptr_t *) vkey
;
511 const struct coff_symbol
*entry
= (const struct coff_symbol
*) ventry
;
515 if (addr
< entry
->address
)
517 else if (addr
>= entry
[1].address
)
523 /* Return the symbol name and value for an ADDR. */
526 coff_syminfo (struct backtrace_state
*state
, uintptr_t addr
,
527 backtrace_syminfo_callback callback
,
528 backtrace_error_callback error_callback ATTRIBUTE_UNUSED
,
531 struct coff_syminfo_data
*sdata
;
532 struct coff_symbol
*sym
= NULL
;
534 if (!state
->threaded
)
536 for (sdata
= (struct coff_syminfo_data
*) state
->syminfo_data
;
540 sym
= ((struct coff_symbol
*)
541 bsearch (&addr
, sdata
->symbols
, sdata
->count
,
542 sizeof (struct coff_symbol
), coff_symbol_search
));
549 struct coff_syminfo_data
**pp
;
551 pp
= (struct coff_syminfo_data
**) (void *) &state
->syminfo_data
;
554 sdata
= backtrace_atomic_load_pointer (pp
);
558 sym
= ((struct coff_symbol
*)
559 bsearch (&addr
, sdata
->symbols
, sdata
->count
,
560 sizeof (struct coff_symbol
), coff_symbol_search
));
569 callback (data
, addr
, NULL
, 0, 0);
571 callback (data
, addr
, sym
->name
, sym
->address
, 0);
574 /* Add the backtrace data for one PE/COFF file. Returns 1 on success,
575 0 on failure (in both cases descriptor is closed). */
578 coff_add (struct backtrace_state
*state
, int descriptor
,
579 backtrace_error_callback error_callback
, void *data
,
580 fileline
*fileline_fn
, int *found_sym
, int *found_dwarf
)
582 struct backtrace_view fhdr_view
;
585 b_coff_file_header fhdr
;
587 size_t opt_sects_size
;
588 unsigned int sects_num
;
589 struct backtrace_view sects_view
;
590 int sects_view_valid
;
591 const b_coff_optional_header
*opt_hdr
;
592 const b_coff_section_header
*sects
;
593 struct backtrace_view str_view
;
597 struct backtrace_view syms_view
;
601 unsigned int syms_num
;
603 struct debug_section_info sections
[DEBUG_MAX
];
606 struct backtrace_view debug_view
;
607 int debug_view_valid
;
608 uintptr_t image_base
;
609 struct dwarf_sections dwarf_sections
;
614 sects_view_valid
= 0;
617 debug_view_valid
= 0;
619 /* Map the MS-DOS stub (if any) and extract file header offset. */
620 if (!backtrace_get_view (state
, descriptor
, 0, 0x40, error_callback
,
625 const unsigned char *vptr
= fhdr_view
.data
;
627 if (vptr
[0] == 'M' && vptr
[1] == 'Z')
628 fhdr_off
= coff_read4 (vptr
+ 0x3c);
633 backtrace_release_view (state
, &fhdr_view
, error_callback
, data
);
635 /* Map the coff file header. */
636 if (!backtrace_get_view (state
, descriptor
, fhdr_off
,
637 sizeof (b_coff_file_header
) + 4,
638 error_callback
, data
, &fhdr_view
))
643 const char *magic
= (const char *) fhdr_view
.data
;
644 magic_ok
= memcmp (magic
, "PE\0", 4) == 0;
647 memcpy (&fhdr
, fhdr_view
.data
+ 4, sizeof fhdr
);
651 memcpy (&fhdr
, fhdr_view
.data
, sizeof fhdr
);
652 /* TODO: test fhdr.machine for coff but non-PE platforms. */
655 backtrace_release_view (state
, &fhdr_view
, error_callback
, data
);
659 error_callback (data
, "executable file is not COFF", 0);
663 sects_num
= fhdr
.number_of_sections
;
664 syms_num
= fhdr
.number_of_symbols
;
666 opt_sects_off
= fhdr_off
+ sizeof (fhdr
);
667 opt_sects_size
= (fhdr
.size_of_optional_header
668 + sects_num
* sizeof (b_coff_section_header
));
670 /* To translate PC to file/line when using DWARF, we need to find
671 the .debug_info and .debug_line sections. */
673 /* Read the optional header and the section headers. */
675 if (!backtrace_get_view (state
, descriptor
, opt_sects_off
, opt_sects_size
,
676 error_callback
, data
, §s_view
))
678 sects_view_valid
= 1;
679 opt_hdr
= (const b_coff_optional_header
*) sects_view
.data
;
680 sects
= (const b_coff_section_header
*)
681 (sects_view
.data
+ fhdr
.size_of_optional_header
);
683 if (fhdr
.size_of_optional_header
> sizeof (*opt_hdr
))
685 if (opt_hdr
->magic
== PE_MAGIC
)
686 image_base
= opt_hdr
->u
.pe
.image_base
;
687 else if (opt_hdr
->magic
== PEP_MAGIC
)
688 image_base
= opt_hdr
->u
.pep
.image_base
;
691 error_callback (data
, "bad magic in PE optional header", 0);
698 /* Read the symbol table and the string table. */
700 if (fhdr
.pointer_to_symbol_table
== 0)
702 /* No symbol table, no string table. */
710 /* Symbol table is followed by the string table. The string table
711 starts with its length (on 4 bytes).
712 Map the symbol table and the length of the string table. */
713 syms_off
= fhdr
.pointer_to_symbol_table
;
714 syms_size
= syms_num
* SYM_SZ
;
716 if (!backtrace_get_view (state
, descriptor
, syms_off
, syms_size
+ 4,
717 error_callback
, data
, &syms_view
))
721 str_size
= coff_read4 (syms_view
.data
+ syms_size
);
723 str_off
= syms_off
+ syms_size
;
727 /* Map string table (including the length word). */
729 if (!backtrace_get_view (state
, descriptor
, str_off
, str_size
,
730 error_callback
, data
, &str_view
))
736 memset (sections
, 0, sizeof sections
);
738 /* Look for the symbol table. */
739 for (i
= 0; i
< sects_num
; ++i
)
741 const b_coff_section_header
*s
= sects
+ i
;
742 unsigned int str_off
;
745 if (s
->name
[0] == '/')
747 /* Extended section name. */
748 str_off
= atoi (s
->name
+ 1);
753 for (j
= 0; j
< (int) DEBUG_MAX
; ++j
)
755 const char *dbg_name
= debug_section_names
[j
];
759 match
= coff_long_name_eq (dbg_name
, str_off
, &str_view
);
761 match
= coff_short_name_eq (dbg_name
, s
->name
);
764 sections
[j
].offset
= s
->pointer_to_raw_data
;
765 sections
[j
].size
= s
->virtual_size
<= s
->size_of_raw_data
?
766 s
->virtual_size
: s
->size_of_raw_data
;
774 struct coff_syminfo_data
*sdata
;
776 sdata
= ((struct coff_syminfo_data
*)
777 backtrace_alloc (state
, sizeof *sdata
, error_callback
, data
));
781 if (!coff_initialize_syminfo (state
, image_base
,
783 syms_view
.data
, syms_size
,
784 str_view
.data
, str_size
,
785 error_callback
, data
, sdata
))
787 backtrace_free (state
, sdata
, sizeof *sdata
, error_callback
, data
);
793 coff_add_syminfo_data (state
, sdata
);
796 backtrace_release_view (state
, §s_view
, error_callback
, data
);
797 sects_view_valid
= 0;
800 backtrace_release_view (state
, &syms_view
, error_callback
, data
);
804 /* Read all the debug sections in a single view, since they are
805 probably adjacent in the file. We never release this view. */
809 for (i
= 0; i
< (int) DEBUG_MAX
; ++i
)
813 if (sections
[i
].size
== 0)
815 if (min_offset
== 0 || sections
[i
].offset
< min_offset
)
816 min_offset
= sections
[i
].offset
;
817 end
= sections
[i
].offset
+ sections
[i
].size
;
818 if (end
> max_offset
)
821 if (min_offset
== 0 || max_offset
== 0)
823 if (!backtrace_close (descriptor
, error_callback
, data
))
825 *fileline_fn
= coff_nodebug
;
829 if (!backtrace_get_view (state
, descriptor
, min_offset
,
830 max_offset
- min_offset
,
831 error_callback
, data
, &debug_view
))
833 debug_view_valid
= 1;
835 /* We've read all we need from the executable. */
836 if (!backtrace_close (descriptor
, error_callback
, data
))
840 for (i
= 0; i
< (int) DEBUG_MAX
; ++i
)
842 size_t size
= sections
[i
].size
;
843 dwarf_sections
.size
[i
] = size
;
845 dwarf_sections
.data
[i
] = NULL
;
847 dwarf_sections
.data
[i
] = ((const unsigned char *) debug_view
.data
848 + (sections
[i
].offset
- min_offset
));
851 if (!backtrace_dwarf_add (state
, /* base_address */ 0, &dwarf_sections
,
852 0, /* FIXME: is_bigendian */
854 error_callback
, data
, fileline_fn
,
855 NULL
/* returned fileline_entry */))
863 if (sects_view_valid
)
864 backtrace_release_view (state
, §s_view
, error_callback
, data
);
866 backtrace_release_view (state
, &str_view
, error_callback
, data
);
868 backtrace_release_view (state
, &syms_view
, error_callback
, data
);
869 if (debug_view_valid
)
870 backtrace_release_view (state
, &debug_view
, error_callback
, data
);
871 if (descriptor
!= -1)
872 backtrace_close (descriptor
, error_callback
, data
);
876 /* Initialize the backtrace data we need from an ELF executable. At
877 the ELF level, all we need to do is find the debug info
881 backtrace_initialize (struct backtrace_state
*state
,
882 const char *filename ATTRIBUTE_UNUSED
, int descriptor
,
883 backtrace_error_callback error_callback
,
884 void *data
, fileline
*fileline_fn
)
889 fileline coff_fileline_fn
;
891 ret
= coff_add (state
, descriptor
, error_callback
, data
,
892 &coff_fileline_fn
, &found_sym
, &found_dwarf
);
896 if (!state
->threaded
)
899 state
->syminfo_fn
= coff_syminfo
;
900 else if (state
->syminfo_fn
== NULL
)
901 state
->syminfo_fn
= coff_nosyms
;
906 backtrace_atomic_store_pointer (&state
->syminfo_fn
, coff_syminfo
);
908 (void) __sync_bool_compare_and_swap (&state
->syminfo_fn
, NULL
,
912 if (!state
->threaded
)
914 if (state
->fileline_fn
== NULL
|| state
->fileline_fn
== coff_nodebug
)
915 *fileline_fn
= coff_fileline_fn
;
921 current_fn
= backtrace_atomic_load_pointer (&state
->fileline_fn
);
922 if (current_fn
== NULL
|| current_fn
== coff_nodebug
)
923 *fileline_fn
= coff_fileline_fn
;