2 * Copyright 1994 Eric Youndale & Erik Bos
3 * Copyright 1995 Martin von Löwis
4 * Copyright 1996-98 Marcus Meissner
6 * based on Eric Youndale's pe-test and:
8 * ftp.microsoft.com:/pub/developer/MSDN/CD8/PEFILE.ZIP
10 * ftp.microsoft.com:/developr/MSDN/OctCD/PEFILE.ZIP
13 * Before you start changing something in this file be aware of the following:
15 * - There are several functions called recursively. In a very subtle and
16 * obscure way. DLLs can reference each other recursively etc.
17 * - If you want to enhance, speed up or clean up something in here, think
18 * twice WHY it is implemented in that strange way. There is usually a reason.
19 * Though sometimes it might just be lazyness ;)
20 * - In PE_MapImage, right before fixup_imports() all external and internal
21 * state MUST be correct since this function can be called with the SAME image
22 * AGAIN. (Thats recursion for you.) That means MODREF.module and
24 * - No, you (usually) cannot use Linux mmap() to mmap() the images directly.
26 * The problem is, that there is not direct 1:1 mapping from a diskimage and
27 * a memoryimage. The headers at the start are mapped linear, but the sections
28 * are not. For x86 the sections are 512 byte aligned in file and 4096 byte
29 * aligned in memory. Linux likes them 4096 byte aligned in memory (due to
30 * x86 pagesize, this cannot be fixed without a rather large kernel rewrite)
31 * and 'blocksize' file-aligned (offsets). Since we have 512/1024/2048 (CDROM)
32 * and other byte blocksizes, we can't do this. However, this could be less
33 * difficult to support... (See mm/filemap.c).
43 #include <sys/types.h>
45 #ifdef HAVE_SYS_MMAN_H
63 #include "debugtools.h"
65 DECLARE_DEBUG_CHANNEL(delayhlp
)
66 DECLARE_DEBUG_CHANNEL(fixup
)
67 DECLARE_DEBUG_CHANNEL(module
)
68 DECLARE_DEBUG_CHANNEL(relay
)
69 DECLARE_DEBUG_CHANNEL(segment
)
70 DECLARE_DEBUG_CHANNEL(win32
)
73 /* convert PE image VirtualAddress to Real Address */
74 #define RVA(x) ((unsigned int)load_addr+(unsigned int)(x))
76 #define AdjustPtr(ptr,delta) ((char *)(ptr) + (delta))
78 void dump_exports( HMODULE hModule
)
83 u_long
*function
,*functions
;
85 unsigned int load_addr
= hModule
;
87 DWORD rva_start
= PE_HEADER(hModule
)->OptionalHeader
88 .DataDirectory
[IMAGE_DIRECTORY_ENTRY_EXPORT
].VirtualAddress
;
89 DWORD rva_end
= rva_start
+ PE_HEADER(hModule
)->OptionalHeader
90 .DataDirectory
[IMAGE_DIRECTORY_ENTRY_EXPORT
].Size
;
91 IMAGE_EXPORT_DIRECTORY
*pe_exports
= (IMAGE_EXPORT_DIRECTORY
*)RVA(rva_start
);
93 Module
= (char*)RVA(pe_exports
->Name
);
94 TRACE_(win32
)("*******EXPORT DATA*******\n");
95 TRACE_(win32
)("Module name is %s, %ld functions, %ld names\n",
96 Module
, pe_exports
->NumberOfFunctions
, pe_exports
->NumberOfNames
);
98 ordinal
=(u_short
*) RVA(pe_exports
->AddressOfNameOrdinals
);
99 functions
=function
=(u_long
*) RVA(pe_exports
->AddressOfFunctions
);
100 name
=(u_char
**) RVA(pe_exports
->AddressOfNames
);
102 TRACE_(win32
)(" Ord RVA Addr Name\n" );
103 for (i
=0;i
<pe_exports
->NumberOfFunctions
;i
++, function
++)
105 if (!*function
) continue; /* No such function */
108 DPRINTF( "%4ld %08lx %08x", i
+ pe_exports
->Base
, *function
, RVA(*function
) );
109 /* Check if we have a name for it */
110 for (j
= 0; j
< pe_exports
->NumberOfNames
; j
++)
113 DPRINTF( " %s", (char*)RVA(name
[j
]) );
116 if ((*function
>= rva_start
) && (*function
<= rva_end
))
117 DPRINTF(" (forwarded -> %s)", (char *)RVA(*function
));
123 /* Look up the specified function or ordinal in the exportlist:
125 * - look up the name in the Name list.
126 * - look up the ordinal with that index.
127 * - use the ordinal as offset into the functionlist
128 * If it is a ordinal:
129 * - use ordinal-pe_export->Base as offset into the functionlist
131 FARPROC
PE_FindExportedFunction(
132 WINE_MODREF
*wm
, /* [in] WINE modreference */
133 LPCSTR funcName
, /* [in] function name */
138 u_char
** name
, *ename
;
140 PE_MODREF
*pem
= &(wm
->binfmt
.pe
);
141 IMAGE_EXPORT_DIRECTORY
*exports
= pem
->pe_export
;
142 unsigned int load_addr
= wm
->module
;
143 u_long rva_start
, rva_end
, addr
;
146 if (HIWORD(funcName
))
147 TRACE_(win32
)("(%s)\n",funcName
);
149 TRACE_(win32
)("(%d)\n",(int)funcName
);
151 /* Not a fatal problem, some apps do
152 * GetProcAddress(0,"RegisterPenApp") which triggers this
155 WARN_(win32
)("Module %08x(%s)/MODREF %p doesn't have a exports table.\n",wm
->module
,wm
->modname
,pem
);
158 ordinal
= (u_short
*) RVA(exports
->AddressOfNameOrdinals
);
159 function
= (u_long
*) RVA(exports
->AddressOfFunctions
);
160 name
= (u_char
**) RVA(exports
->AddressOfNames
);
162 rva_start
= PE_HEADER(wm
->module
)->OptionalHeader
163 .DataDirectory
[IMAGE_DIRECTORY_ENTRY_EXPORT
].VirtualAddress
;
164 rva_end
= rva_start
+ PE_HEADER(wm
->module
)->OptionalHeader
165 .DataDirectory
[IMAGE_DIRECTORY_ENTRY_EXPORT
].Size
;
167 if (HIWORD(funcName
)) {
168 for(i
=0; i
<exports
->NumberOfNames
; i
++) {
169 ename
=(char*)RVA(*name
);
170 if(!strcmp(ename
,funcName
))
172 addr
= function
[*ordinal
];
173 if (!addr
) return NULL
;
174 if ((addr
< rva_start
) || (addr
>= rva_end
))
175 return snoop
? SNOOP_GetProcAddress(wm
->module
,ename
,*ordinal
,(FARPROC
)RVA(addr
))
176 : (FARPROC
)RVA(addr
);
177 forward
= (char *)RVA(addr
);
185 if (LOWORD(funcName
)-exports
->Base
> exports
->NumberOfFunctions
) {
186 TRACE_(win32
)(" ordinal %d out of range!\n",
190 addr
= function
[(int)funcName
-exports
->Base
];
191 if (!addr
) return NULL
;
194 for (i
=0;i
<exports
->NumberOfNames
;i
++) {
195 ename
= (char*)RVA(*name
);
196 if (*ordinal
== LOWORD(funcName
)-exports
->Base
)
201 if (i
==exports
->NumberOfNames
)
204 if ((addr
< rva_start
) || (addr
>= rva_end
))
205 return snoop
? SNOOP_GetProcAddress(wm
->module
,ename
,(DWORD
)funcName
-exports
->Base
,(FARPROC
)RVA(addr
))
206 : (FARPROC
)RVA(addr
);
207 forward
= (char *)RVA(addr
);
213 char *end
= strchr(forward
, '.');
215 if (!end
) return NULL
;
216 assert(end
-forward
<256);
217 strncpy(module
, forward
, (end
- forward
));
218 module
[end
-forward
] = 0;
219 if (!(wm
= MODULE_FindModule( module
)))
221 ERR_(win32
)("module not found for forward '%s'\n", forward
);
224 return MODULE_GetProcAddress( wm
->module
, end
+ 1, snoop
);
229 DWORD
fixup_imports( WINE_MODREF
*wm
)
231 IMAGE_IMPORT_DESCRIPTOR
*pe_imp
;
233 unsigned int load_addr
= wm
->module
;
234 int i
,characteristics_detection
=1;
237 assert(wm
->type
==MODULE32_PE
);
238 pem
= &(wm
->binfmt
.pe
);
240 modname
= (char*) RVA(pem
->pe_export
->Name
);
242 modname
= "<unknown>";
244 /* OK, now dump the import list */
245 TRACE_(win32
)("Dumping imports list\n");
247 /* first, count the number of imported non-internal modules */
248 pe_imp
= pem
->pe_import
;
249 if (!pe_imp
) return 0;
251 /* We assume that we have at least one import with !0 characteristics and
252 * detect broken imports with all characteristsics 0 (notably Borland) and
253 * switch the detection off for them.
255 for (i
= 0; pe_imp
->Name
; pe_imp
++) {
256 if (!i
&& !pe_imp
->u
.Characteristics
)
257 characteristics_detection
= 0;
258 if (characteristics_detection
&& !pe_imp
->u
.Characteristics
)
262 if (!i
) return 0; /* no imports */
264 /* Allocate module dependency list */
266 wm
->deps
= HeapAlloc( GetProcessHeap(), 0, i
*sizeof(WINE_MODREF
*) );
268 /* load the imported modules. They are automatically
269 * added to the modref list of the process.
272 for (i
= 0, pe_imp
= pem
->pe_import
; pe_imp
->Name
; pe_imp
++) {
274 IMAGE_IMPORT_BY_NAME
*pe_name
;
275 PIMAGE_THUNK_DATA import_list
,thunk_list
;
276 char *name
= (char *) RVA(pe_imp
->Name
);
278 if (characteristics_detection
&& !pe_imp
->u
.Characteristics
)
281 /* don't use MODULE_Load, Win32 creates new task differently */
282 wmImp
= MODULE_LoadLibraryExA( name
, 0, 0 );
284 char *p
,buffer
[2000];
286 /* GetModuleFileName would use the wrong process, so don't use it */
287 strcpy(buffer
,wm
->shortname
);
288 if (!(p
= strrchr (buffer
, '\\')))
290 strcpy (p
+ 1, name
);
291 wmImp
= MODULE_LoadLibraryExA( buffer
, 0, 0 );
294 ERR_(module
)("Module %s not found\n", name
);
297 wm
->deps
[i
++] = wmImp
;
299 /* FIXME: forwarder entries ... */
301 if (pe_imp
->u
.OriginalFirstThunk
!= 0) { /* original MS style */
302 TRACE_(win32
)("Microsoft style imports used\n");
303 import_list
=(PIMAGE_THUNK_DATA
) RVA(pe_imp
->u
.OriginalFirstThunk
);
304 thunk_list
= (PIMAGE_THUNK_DATA
) RVA(pe_imp
->FirstThunk
);
306 while (import_list
->u1
.Ordinal
) {
307 if (IMAGE_SNAP_BY_ORDINAL(import_list
->u1
.Ordinal
)) {
308 int ordinal
= IMAGE_ORDINAL(import_list
->u1
.Ordinal
);
310 TRACE_(win32
)("--- Ordinal %s,%d\n", name
, ordinal
);
311 thunk_list
->u1
.Function
=MODULE_GetProcAddress(
312 wmImp
->module
, (LPCSTR
)ordinal
, TRUE
314 if (!thunk_list
->u1
.Function
) {
315 ERR_(win32
)("No implementation for %s.%d, setting to 0xdeadbeef\n",
317 thunk_list
->u1
.Function
= (FARPROC
)0xdeadbeef;
319 } else { /* import by name */
320 pe_name
= (PIMAGE_IMPORT_BY_NAME
)RVA(import_list
->u1
.AddressOfData
);
321 TRACE_(win32
)("--- %s %s.%d\n", pe_name
->Name
, name
, pe_name
->Hint
);
322 thunk_list
->u1
.Function
=MODULE_GetProcAddress(
323 wmImp
->module
, pe_name
->Name
, TRUE
325 if (!thunk_list
->u1
.Function
) {
326 ERR_(win32
)("No implementation for %s.%d(%s), setting to 0xdeadbeef\n",
327 name
,pe_name
->Hint
,pe_name
->Name
);
328 thunk_list
->u1
.Function
= (FARPROC
)0xdeadbeef;
334 } else { /* Borland style */
335 TRACE_(win32
)("Borland style imports used\n");
336 thunk_list
= (PIMAGE_THUNK_DATA
) RVA(pe_imp
->FirstThunk
);
337 while (thunk_list
->u1
.Ordinal
) {
338 if (IMAGE_SNAP_BY_ORDINAL(thunk_list
->u1
.Ordinal
)) {
339 /* not sure about this branch, but it seems to work */
340 int ordinal
= IMAGE_ORDINAL(thunk_list
->u1
.Ordinal
);
342 TRACE_(win32
)("--- Ordinal %s.%d\n",name
,ordinal
);
343 thunk_list
->u1
.Function
=MODULE_GetProcAddress(
344 wmImp
->module
, (LPCSTR
) ordinal
, TRUE
346 if (!thunk_list
->u1
.Function
) {
347 ERR_(win32
)("No implementation for %s.%d, setting to 0xdeadbeef\n",
349 thunk_list
->u1
.Function
= (FARPROC
)0xdeadbeef;
352 pe_name
=(PIMAGE_IMPORT_BY_NAME
) RVA(thunk_list
->u1
.AddressOfData
);
353 TRACE_(win32
)("--- %s %s.%d\n",
354 pe_name
->Name
,name
,pe_name
->Hint
);
355 thunk_list
->u1
.Function
=MODULE_GetProcAddress(
356 wmImp
->module
, pe_name
->Name
, TRUE
358 if (!thunk_list
->u1
.Function
) {
359 ERR_(win32
)("No implementation for %s.%d, setting to 0xdeadbeef\n",
360 name
, pe_name
->Hint
);
361 thunk_list
->u1
.Function
= (FARPROC
)0xdeadbeef;
371 static int calc_vma_size( HMODULE hModule
)
374 IMAGE_SECTION_HEADER
*pe_seg
= PE_SECTIONS(hModule
);
376 TRACE_(win32
)("Dump of segment table\n");
377 TRACE_(win32
)(" Name VSz Vaddr SzRaw Fileadr *Reloc *Lineum #Reloc #Linum Char\n");
378 for (i
= 0; i
< PE_HEADER(hModule
)->FileHeader
.NumberOfSections
; i
++)
380 TRACE_(win32
)("%8s: %4.4lx %8.8lx %8.8lx %8.8lx %8.8lx %8.8lx %4.4x %4.4x %8.8lx\n",
382 pe_seg
->Misc
.VirtualSize
,
383 pe_seg
->VirtualAddress
,
384 pe_seg
->SizeOfRawData
,
385 pe_seg
->PointerToRawData
,
386 pe_seg
->PointerToRelocations
,
387 pe_seg
->PointerToLinenumbers
,
388 pe_seg
->NumberOfRelocations
,
389 pe_seg
->NumberOfLinenumbers
,
390 pe_seg
->Characteristics
);
391 vma_size
=MAX(vma_size
, pe_seg
->VirtualAddress
+pe_seg
->SizeOfRawData
);
392 vma_size
=MAX(vma_size
, pe_seg
->VirtualAddress
+pe_seg
->Misc
.VirtualSize
);
398 static void do_relocations( unsigned int load_addr
, IMAGE_BASE_RELOCATION
*r
)
400 int delta
= load_addr
- PE_HEADER(load_addr
)->OptionalHeader
.ImageBase
;
401 int hdelta
= (delta
>> 16) & 0xFFFF;
402 int ldelta
= delta
& 0xFFFF;
407 while(r
->VirtualAddress
)
409 char *page
= (char*) RVA(r
->VirtualAddress
);
410 int count
= (r
->SizeOfBlock
- 8)/2;
412 TRACE_(fixup
)("%x relocations for page %lx\n",
413 count
, r
->VirtualAddress
);
414 /* patching in reverse order */
417 int offset
= r
->TypeOffset
[i
] & 0xFFF;
418 int type
= r
->TypeOffset
[i
] >> 12;
419 TRACE_(fixup
)("patching %x type %x\n", offset
, type
);
422 case IMAGE_REL_BASED_ABSOLUTE
: break;
423 case IMAGE_REL_BASED_HIGH
:
424 *(short*)(page
+offset
) += hdelta
;
426 case IMAGE_REL_BASED_LOW
:
427 *(short*)(page
+offset
) += ldelta
;
429 case IMAGE_REL_BASED_HIGHLOW
:
430 *(int*)(page
+offset
) += delta
;
431 /* FIXME: if this is an exported address, fire up enhanced logic */
433 case IMAGE_REL_BASED_HIGHADJ
:
434 FIXME_(win32
)("Don't know what to do with IMAGE_REL_BASED_HIGHADJ\n");
436 case IMAGE_REL_BASED_MIPS_JMPADDR
:
437 FIXME_(win32
)("Is this a MIPS machine ???\n");
440 FIXME_(win32
)("Unknown fixup type\n");
444 r
= (IMAGE_BASE_RELOCATION
*)((char*)r
+ r
->SizeOfBlock
);
452 /**********************************************************************
454 * Load one PE format DLL/EXE into memory
456 * Unluckily we can't just mmap the sections where we want them, for
457 * (at least) Linux does only support offsets which are page-aligned.
459 * BUT we have to map the whole image anyway, for Win32 programs sometimes
460 * want to access them. (HMODULE32 point to the start of it)
462 HMODULE
PE_LoadImage( HFILE hFile
, OFSTRUCT
*ofs
, LPCSTR
*modName
)
467 IMAGE_NT_HEADERS
*nt
;
468 IMAGE_SECTION_HEADER
*pe_sec
;
469 IMAGE_DATA_DIRECTORY
*dir
;
470 BY_HANDLE_FILE_INFORMATION bhfi
;
471 int i
, rawsize
, lowest_va
, lowest_fa
, vma_size
, file_size
= 0;
472 DWORD load_addr
, aoep
, reloc
= 0;
474 /* Retrieve file size */
475 if ( GetFileInformationByHandle( hFile
, &bhfi
) )
476 file_size
= bhfi
.nFileSizeLow
; /* FIXME: 64 bit */
478 /* Map the PE file somewhere */
479 mapping
= CreateFileMappingA( hFile
, NULL
, PAGE_READONLY
| SEC_COMMIT
,
483 WARN_(win32
)("CreateFileMapping error %ld\n", GetLastError() );
486 hModule
= (HMODULE
)MapViewOfFile( mapping
, FILE_MAP_READ
, 0, 0, 0 );
487 CloseHandle( mapping
);
490 WARN_(win32
)("MapViewOfFile error %ld\n", GetLastError() );
493 nt
= PE_HEADER( hModule
);
495 /* Check signature */
496 if ( nt
->Signature
!= IMAGE_NT_SIGNATURE
)
498 WARN_(win32
)("image doesn't have PE signature, but 0x%08lx\n",
503 /* Check architecture */
504 if ( nt
->FileHeader
.Machine
!= IMAGE_FILE_MACHINE_I386
)
506 MESSAGE("Trying to load PE image for unsupported architecture (");
507 switch (nt
->FileHeader
.Machine
)
509 case IMAGE_FILE_MACHINE_UNKNOWN
: MESSAGE("Unknown"); break;
510 case IMAGE_FILE_MACHINE_I860
: MESSAGE("I860"); break;
511 case IMAGE_FILE_MACHINE_R3000
: MESSAGE("R3000"); break;
512 case IMAGE_FILE_MACHINE_R4000
: MESSAGE("R4000"); break;
513 case IMAGE_FILE_MACHINE_R10000
: MESSAGE("R10000"); break;
514 case IMAGE_FILE_MACHINE_ALPHA
: MESSAGE("Alpha"); break;
515 case IMAGE_FILE_MACHINE_POWERPC
: MESSAGE("PowerPC"); break;
516 default: MESSAGE("Unknown-%04x", nt
->FileHeader
.Machine
); break;
522 /* Find out how large this executeable should be */
523 pe_sec
= PE_SECTIONS( hModule
);
524 rawsize
= 0; lowest_va
= 0x10000; lowest_fa
= 0x10000;
525 for (i
= 0; i
< nt
->FileHeader
.NumberOfSections
; i
++)
527 if (lowest_va
> pe_sec
[i
].VirtualAddress
)
528 lowest_va
= pe_sec
[i
].VirtualAddress
;
529 if (pe_sec
[i
].Characteristics
& IMAGE_SCN_CNT_UNINITIALIZED_DATA
)
531 if (pe_sec
[i
].PointerToRawData
< lowest_fa
)
532 lowest_fa
= pe_sec
[i
].PointerToRawData
;
533 if (pe_sec
[i
].PointerToRawData
+pe_sec
[i
].SizeOfRawData
> rawsize
)
534 rawsize
= pe_sec
[i
].PointerToRawData
+pe_sec
[i
].SizeOfRawData
;
537 /* Check file size */
538 if ( file_size
&& file_size
< rawsize
)
540 ERR_(win32
)("PE module is too small (header: %d, filesize: %d), "
541 "probably truncated download?\n",
542 rawsize
, file_size
);
546 /* Check entrypoint address */
547 aoep
= nt
->OptionalHeader
.AddressOfEntryPoint
;
548 if (aoep
&& (aoep
< lowest_va
))
549 FIXME_(win32
)("WARNING: '%s' has an invalid entrypoint (0x%08lx) "
550 "below the first virtual address (0x%08x) "
551 "(possible Virus Infection or broken binary)!\n",
552 ofs
->szPathName
, aoep
, lowest_va
);
555 /* FIXME: Hack! While we don't really support shared sections yet,
556 * this checks for those special cases where the whole DLL
557 * consists only of shared sections and is mapped into the
558 * shared address space > 2GB. In this case, we assume that
559 * the module got mapped at its base address. Thus we simply
560 * check whether the module has actually been mapped there
561 * and use it, if so. This is needed to get Win95 USER32.DLL
562 * to work (until we support shared sections properly).
565 if ( nt
->OptionalHeader
.ImageBase
& 0x80000000 )
567 HMODULE sharedMod
= (HMODULE
)nt
->OptionalHeader
.ImageBase
;
568 IMAGE_NT_HEADERS
*sharedNt
= (PIMAGE_NT_HEADERS
)
569 ( (LPBYTE
)sharedMod
+ ((LPBYTE
)nt
- (LPBYTE
)hModule
) );
571 /* Well, this check is not really comprehensive,
572 but should be good enough for now ... */
573 if ( !IsBadReadPtr( (LPBYTE
)sharedMod
, sizeof(IMAGE_DOS_HEADER
) )
574 && memcmp( (LPBYTE
)sharedMod
, (LPBYTE
)hModule
, sizeof(IMAGE_DOS_HEADER
) ) == 0
575 && !IsBadReadPtr( sharedNt
, sizeof(IMAGE_NT_HEADERS
) )
576 && memcmp( sharedNt
, nt
, sizeof(IMAGE_NT_HEADERS
) ) == 0 )
578 UnmapViewOfFile( (LPVOID
)hModule
);
584 /* Allocate memory for module */
585 load_addr
= nt
->OptionalHeader
.ImageBase
;
586 vma_size
= calc_vma_size( hModule
);
588 load_addr
= (DWORD
)VirtualAlloc( (void*)load_addr
, vma_size
,
589 MEM_RESERVE
| MEM_COMMIT
,
590 PAGE_EXECUTE_READWRITE
);
593 /* We need to perform base relocations */
594 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_BASERELOC
;
596 reloc
= dir
->VirtualAddress
;
600 "FATAL: Need to relocate %s, but no relocation records present (%s). Try to run that file directly !\n",
602 (nt
->FileHeader
.Characteristics
&IMAGE_FILE_RELOCS_STRIPPED
)?
603 "stripped during link" : "unknown reason" );
607 /* FIXME: If we need to relocate a system DLL (base > 2GB) we should
608 * really make sure that the *new* base address is also > 2GB.
609 * Some DLLs really check the MSB of the module handle :-/
611 if ( nt
->OptionalHeader
.ImageBase
& 0x80000000 )
612 ERR_(win32
)( "Forced to relocate system DLL (base > 2GB). This is not good.\n" );
614 load_addr
= (DWORD
)VirtualAlloc( NULL
, vma_size
,
615 MEM_RESERVE
| MEM_COMMIT
,
616 PAGE_EXECUTE_READWRITE
);
619 TRACE_(win32
)("Load addr is %lx (base %lx), range %x\n",
620 load_addr
, nt
->OptionalHeader
.ImageBase
, vma_size
);
621 TRACE_(segment
)("Loading %s at %lx, range %x\n",
622 ofs
->szPathName
, load_addr
, vma_size
);
624 /* Store the NT header at the load addr */
625 *(PIMAGE_DOS_HEADER
)load_addr
= *(PIMAGE_DOS_HEADER
)hModule
;
626 *PE_HEADER( load_addr
) = *nt
;
627 memcpy( PE_SECTIONS(load_addr
), PE_SECTIONS(hModule
),
628 sizeof(IMAGE_SECTION_HEADER
) * nt
->FileHeader
.NumberOfSections
);
630 /* Copies all stuff up to the first section. Including win32 viruses. */
631 memcpy( load_addr
, hModule
, lowest_fa
);
634 /* Copy sections into module image */
635 pe_sec
= PE_SECTIONS( hModule
);
636 for (i
= 0; i
< nt
->FileHeader
.NumberOfSections
; i
++, pe_sec
++)
638 /* memcpy only non-BSS segments */
639 /* FIXME: this should be done by mmap(..MAP_PRIVATE|MAP_FIXED..)
640 * but it is not possible for (at least) Linux needs
641 * a page-aligned offset.
643 if(!(pe_sec
->Characteristics
& IMAGE_SCN_CNT_UNINITIALIZED_DATA
))
644 memcpy((char*)RVA(pe_sec
->VirtualAddress
),
645 (char*)(hModule
+ pe_sec
->PointerToRawData
),
646 pe_sec
->SizeOfRawData
);
648 /* not needed, memory is zero */
649 if(strcmp(pe_sec
->Name
, ".bss") == 0)
650 memset((void *)RVA(pe_sec
->VirtualAddress
), 0,
651 pe_sec
->Misc
.VirtualSize
?
652 pe_sec
->Misc
.VirtualSize
:
653 pe_sec
->SizeOfRawData
);
657 /* Perform base relocation, if necessary */
659 do_relocations( load_addr
, (IMAGE_BASE_RELOCATION
*)RVA(reloc
) );
661 /* Get module name */
662 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_EXPORT
;
664 *modName
= (LPCSTR
)RVA(((PIMAGE_EXPORT_DIRECTORY
)RVA(dir
->VirtualAddress
))->Name
);
666 /* We don't need the orignal mapping any more */
667 UnmapViewOfFile( (LPVOID
)hModule
);
668 return (HMODULE
)load_addr
;
671 UnmapViewOfFile( (LPVOID
)hModule
);
675 /**********************************************************************
678 * Create WINE_MODREF structure for loaded HMODULE32, link it into
679 * process modref_list, and fixup all imports.
681 * Note: hModule must point to a correctly allocated PE image,
682 * with base relocations applied; the 16-bit dummy module
683 * associated to hModule must already exist.
685 * Note: This routine must always be called in the context of the
686 * process that is to own the module to be created.
688 WINE_MODREF
*PE_CreateModule( HMODULE hModule
,
689 OFSTRUCT
*ofs
, DWORD flags
, BOOL builtin
)
691 DWORD load_addr
= (DWORD
)hModule
; /* for RVA */
692 IMAGE_NT_HEADERS
*nt
= PE_HEADER(hModule
);
693 IMAGE_DATA_DIRECTORY
*dir
;
694 IMAGE_IMPORT_DESCRIPTOR
*pe_import
= NULL
;
695 IMAGE_EXPORT_DIRECTORY
*pe_export
= NULL
;
696 IMAGE_RESOURCE_DIRECTORY
*pe_resource
= NULL
;
702 /* Retrieve DataDirectory entries */
704 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_EXPORT
;
706 pe_export
= (PIMAGE_EXPORT_DIRECTORY
)RVA(dir
->VirtualAddress
);
708 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_IMPORT
;
710 pe_import
= (PIMAGE_IMPORT_DESCRIPTOR
)RVA(dir
->VirtualAddress
);
712 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_RESOURCE
;
714 pe_resource
= (PIMAGE_RESOURCE_DIRECTORY
)RVA(dir
->VirtualAddress
);
716 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_EXCEPTION
;
717 if (dir
->Size
) FIXME_(win32
)("Exception directory ignored\n" );
719 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_SECURITY
;
720 if (dir
->Size
) FIXME_(win32
)("Security directory ignored\n" );
722 /* IMAGE_DIRECTORY_ENTRY_BASERELOC handled in PE_LoadImage */
723 /* IMAGE_DIRECTORY_ENTRY_DEBUG handled by debugger */
725 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_DEBUG
;
726 if (dir
->Size
) TRACE_(win32
)("Debug directory ignored\n" );
728 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_COPYRIGHT
;
729 if (dir
->Size
) FIXME_(win32
)("Copyright string ignored\n" );
731 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_GLOBALPTR
;
732 if (dir
->Size
) FIXME_(win32
)("Global Pointer (MIPS) ignored\n" );
734 /* IMAGE_DIRECTORY_ENTRY_TLS handled in PE_TlsInit */
736 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
;
737 if (dir
->Size
) FIXME_(win32
)("Load Configuration directory ignored\n" );
739 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT
;
740 if (dir
->Size
) TRACE_(win32
)("Bound Import directory ignored\n" );
742 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_IAT
;
743 if (dir
->Size
) TRACE_(win32
)("Import Address Table directory ignored\n" );
745 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT
;
748 TRACE_(win32
)("Delayed import, stub calls LoadLibrary\n" );
750 * Nothing to do here.
755 * This code is useful to observe what the heck is going on.
758 ImgDelayDescr
*pe_delay
= NULL
;
759 pe_delay
= (PImgDelayDescr
)RVA(dir
->VirtualAddress
);
760 TRACE_(delayhlp
)("pe_delay->grAttrs = %08x\n", pe_delay
->grAttrs
);
761 TRACE_(delayhlp
)("pe_delay->szName = %s\n", pe_delay
->szName
);
762 TRACE_(delayhlp
)("pe_delay->phmod = %08x\n", pe_delay
->phmod
);
763 TRACE_(delayhlp
)("pe_delay->pIAT = %08x\n", pe_delay
->pIAT
);
764 TRACE_(delayhlp
)("pe_delay->pINT = %08x\n", pe_delay
->pINT
);
765 TRACE_(delayhlp
)("pe_delay->pBoundIAT = %08x\n", pe_delay
->pBoundIAT
);
766 TRACE_(delayhlp
)("pe_delay->pUnloadIAT = %08x\n", pe_delay
->pUnloadIAT
);
767 TRACE_(delayhlp
)("pe_delay->dwTimeStamp = %08x\n", pe_delay
->dwTimeStamp
);
769 #endif /* ImgDelayDescr */
772 dir
= nt
->OptionalHeader
.DataDirectory
+IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
;
773 if (dir
->Size
) FIXME_(win32
)("Unknown directory 14 ignored\n" );
775 dir
= nt
->OptionalHeader
.DataDirectory
+15;
776 if (dir
->Size
) FIXME_(win32
)("Unknown directory 15 ignored\n" );
779 /* Allocate and fill WINE_MODREF */
781 wm
= (WINE_MODREF
*)HeapAlloc( GetProcessHeap(),
782 HEAP_ZERO_MEMORY
, sizeof(*wm
) );
783 wm
->module
= hModule
;
786 wm
->flags
|= WINE_MODREF_INTERNAL
;
787 if ( flags
& DONT_RESOLVE_DLL_REFERENCES
)
788 wm
->flags
|= WINE_MODREF_DONT_RESOLVE_REFS
;
789 if ( flags
& LOAD_LIBRARY_AS_DATAFILE
)
790 wm
->flags
|= WINE_MODREF_LOAD_AS_DATAFILE
;
792 wm
->type
= MODULE32_PE
;
793 wm
->binfmt
.pe
.pe_export
= pe_export
;
794 wm
->binfmt
.pe
.pe_import
= pe_import
;
795 wm
->binfmt
.pe
.pe_resource
= pe_resource
;
796 wm
->binfmt
.pe
.tlsindex
= -1;
799 modname
= (char *)RVA( pe_export
->Name
);
802 /* try to find out the name from the OFSTRUCT */
804 modname
= ofs
->szPathName
;
805 if ((s
=strrchr(modname
,'\\'))) modname
= s
+1;
807 wm
->modname
= HEAP_strdupA( GetProcessHeap(), 0, modname
);
809 result
= GetLongPathNameA( ofs
->szPathName
, NULL
, 0 );
810 wm
->longname
= (char *)HeapAlloc( GetProcessHeap(), 0, result
+1 );
811 GetLongPathNameA( ofs
->szPathName
, wm
->longname
, result
+1 );
813 wm
->shortname
= HEAP_strdupA( GetProcessHeap(), 0, ofs
->szPathName
);
815 /* Link MODREF into process list */
817 EnterCriticalSection( &PROCESS_Current()->crit_section
);
819 wm
->next
= PROCESS_Current()->modref_list
;
820 PROCESS_Current()->modref_list
= wm
;
821 if ( wm
->next
) wm
->next
->prev
= wm
;
823 if ( !(nt
->FileHeader
.Characteristics
& IMAGE_FILE_DLL
) )
825 if ( PROCESS_Current()->exe_modref
)
826 FIXME_(win32
)("overwriting old exe_modref... arrgh\n" );
827 PROCESS_Current()->exe_modref
= wm
;
830 LeaveCriticalSection( &PROCESS_Current()->crit_section
);
836 dump_exports( hModule
);
841 && !( wm
->flags
& WINE_MODREF_LOAD_AS_DATAFILE
)
842 && !( wm
->flags
& WINE_MODREF_DONT_RESOLVE_REFS
)
843 && fixup_imports( wm
) )
845 /* remove entry from modref chain */
846 EnterCriticalSection( &PROCESS_Current()->crit_section
);
849 PROCESS_Current()->modref_list
= wm
->next
;
851 wm
->prev
->next
= wm
->next
;
853 if ( wm
->next
) wm
->next
->prev
= wm
->prev
;
854 wm
->next
= wm
->prev
= NULL
;
856 LeaveCriticalSection( &PROCESS_Current()->crit_section
);
858 /* FIXME: there are several more dangling references
859 * left. Including dlls loaded by this dll before the
860 * failed one. Unrolling is rather difficult with the
861 * current structure and we can leave it them lying
862 * around with no problems, so we don't care.
863 * As these might reference our wm, we don't free it.
871 /******************************************************************************
872 * The PE Library Loader frontend.
873 * FIXME: handle the flags.
875 WINE_MODREF
*PE_LoadLibraryExA (LPCSTR name
, DWORD flags
, DWORD
*err
)
877 LPCSTR modName
= NULL
;
883 char dllname
[256], *p
;
886 /* Append .DLL to name if no extension present */
887 strcpy( dllname
, name
);
888 if (!(p
= strrchr( dllname
, '.')) || strchr( p
, '/' ) || strchr( p
, '\\'))
889 strcat( dllname
, ".DLL" );
892 hFile
= OpenFile( dllname
, &ofs
, OF_READ
| OF_SHARE_DENY_WRITE
);
893 if ( hFile
!= HFILE_ERROR
)
895 hModule32
= PE_LoadImage( hFile
, &ofs
, &modName
);
896 CloseHandle( hFile
);
899 *err
= ERROR_OUTOFMEMORY
; /* Not entirely right, but good enough */
905 *err
= ERROR_FILE_NOT_FOUND
;
909 /* Create 16-bit dummy module */
910 if ((hModule16
= MODULE_CreateDummyModule( &ofs
, modName
)) < 32)
912 *err
= (DWORD
)hModule16
; /* This should give the correct error */
915 pModule
= (NE_MODULE
*)GlobalLock16( hModule16
);
916 pModule
->flags
= NE_FFLAGS_LIBMODULE
| NE_FFLAGS_SINGLEDATA
| NE_FFLAGS_WIN32
;
917 pModule
->module32
= hModule32
;
919 /* Create 32-bit MODREF */
920 if ( !(wm
= PE_CreateModule( hModule32
, &ofs
, flags
, FALSE
)) )
922 ERR_(win32
)("can't load %s\n",ofs
.szPathName
);
923 FreeLibrary16( hModule16
);
924 *err
= ERROR_OUTOFMEMORY
;
928 if (wm
->binfmt
.pe
.pe_export
)
929 SNOOP_RegisterDLL(wm
->module
,wm
->modname
,wm
->binfmt
.pe
.pe_export
->NumberOfFunctions
);
936 /*****************************************************************************
939 * Unload the library unmapping the image and freeing the modref structure.
941 void PE_UnloadLibrary(WINE_MODREF
*wm
)
943 /* FIXME, do something here */
946 /*****************************************************************************
947 * Load the PE main .EXE. All other loading is done by PE_LoadLibraryExA
948 * FIXME: this function should use PE_LoadLibraryExA, but currently can't
949 * due to the PROCESS_Create stuff.
951 BOOL
PE_CreateProcess( HFILE hFile
, OFSTRUCT
*ofs
, LPCSTR cmd_line
, LPCSTR env
,
952 LPSECURITY_ATTRIBUTES psa
, LPSECURITY_ATTRIBUTES tsa
,
953 BOOL inherit
, DWORD flags
, LPSTARTUPINFOA startup
,
954 LPPROCESS_INFORMATION info
)
956 LPCSTR modName
= NULL
;
962 if ( (hModule32
= PE_LoadImage( hFile
, ofs
, &modName
)) < 32 )
964 SetLastError( hModule32
);
968 if (PE_HEADER(hModule32
)->FileHeader
.Characteristics
& IMAGE_FILE_DLL
)
970 SetLastError( 20 ); /* FIXME: not the right error code */
975 /* Create 16-bit dummy module */
976 if ( (hModule16
= MODULE_CreateDummyModule( ofs
, modName
)) < 32 )
978 SetLastError( hModule16
);
981 pModule
= (NE_MODULE
*)GlobalLock16( hModule16
);
982 pModule
->flags
= NE_FFLAGS_WIN32
;
983 pModule
->module32
= hModule32
;
985 /* Create new process */
986 if ( !PROCESS_Create( pModule
, cmd_line
, env
,
987 psa
, tsa
, inherit
, flags
, startup
, info
) )
990 /* Note: PE_CreateModule and the remaining process initialization will
991 be done in the context of the new process, in TASK_CallToStart */
996 /*********************************************************************
997 * PE_UnloadImage [internal]
999 int PE_UnloadImage( HMODULE hModule
)
1001 FIXME_(win32
)("stub.\n");
1002 /* free resources, image, unmap */
1006 /* Called if the library is loaded or freed.
1007 * NOTE: if a thread attaches a DLL, the current thread will only do
1008 * DLL_PROCESS_ATTACH. Only new created threads do DLL_THREAD_ATTACH
1011 BOOL
PE_InitDLL( WINE_MODREF
*wm
, DWORD type
, LPVOID lpReserved
)
1014 assert( wm
->type
== MODULE32_PE
);
1016 /* Is this a library? And has it got an entrypoint? */
1017 if ((PE_HEADER(wm
->module
)->FileHeader
.Characteristics
& IMAGE_FILE_DLL
) &&
1018 (PE_HEADER(wm
->module
)->OptionalHeader
.AddressOfEntryPoint
)
1020 DLLENTRYPROC entry
= (void*)RVA_PTR( wm
->module
,OptionalHeader
.AddressOfEntryPoint
);
1021 TRACE_(relay
)("CallTo32(entryproc=%p,module=%08x,type=%ld,res=%p)\n",
1022 entry
, wm
->module
, type
, lpReserved
);
1024 retv
= entry( wm
->module
, type
, lpReserved
);
1030 /************************************************************************
1031 * PE_InitTls (internal)
1033 * If included, initialises the thread local storages of modules.
1034 * Pointers in those structs are not RVAs but real pointers which have been
1035 * relocated by do_relocations() already.
1037 void PE_InitTls( void )
1041 IMAGE_NT_HEADERS
*peh
;
1042 DWORD size
,datasize
;
1044 PIMAGE_TLS_DIRECTORY pdir
;
1047 for (wm
= PROCESS_Current()->modref_list
;wm
;wm
=wm
->next
) {
1048 if (wm
->type
!=MODULE32_PE
)
1050 pem
= &(wm
->binfmt
.pe
);
1051 peh
= PE_HEADER(wm
->module
);
1052 delta
= wm
->module
- peh
->OptionalHeader
.ImageBase
;
1053 if (!peh
->OptionalHeader
.DataDirectory
[IMAGE_FILE_THREAD_LOCAL_STORAGE
].VirtualAddress
)
1055 pdir
= (LPVOID
)(wm
->module
+ peh
->OptionalHeader
.
1056 DataDirectory
[IMAGE_FILE_THREAD_LOCAL_STORAGE
].VirtualAddress
);
1059 if ( pem
->tlsindex
== -1 ) {
1060 pem
->tlsindex
= TlsAlloc();
1061 if ((((DWORD
)pdir
->AddressOfIndex
)>peh
->OptionalHeader
.ImageBase
)
1062 &&(((DWORD
)pdir
->AddressOfIndex
)<peh
->OptionalHeader
.ImageBase
+peh
->OptionalHeader
.SizeOfImage
)
1064 *pdir
->AddressOfIndex
=pem
->tlsindex
;
1066 *(LPDWORD
)((((char*)pdir
->AddressOfIndex
)+delta
))=pem
->tlsindex
;
1068 datasize
= pdir
->EndAddressOfRawData
-pdir
->StartAddressOfRawData
;
1069 size
= datasize
+ pdir
->SizeOfZeroFill
;
1070 mem
=VirtualAlloc(0,size
,MEM_RESERVE
|MEM_COMMIT
,PAGE_READWRITE
);
1071 memcpy(mem
,(LPVOID
)pdir
->StartAddressOfRawData
,datasize
);
1072 if (pdir
->AddressOfCallBacks
) {
1073 PIMAGE_TLS_CALLBACK
*cbs
=
1074 (PIMAGE_TLS_CALLBACK
*)pdir
->AddressOfCallBacks
;
1077 FIXME_(win32
)("TLS Callbacks aren't going to be called\n");
1080 TlsSetValue( pem
->tlsindex
, mem
);