LIEF: Library to Instrument Executable Formats Version 2.0.0
Loading...
Searching...
No Matches
ELF/Parser.hpp
Go to the documentation of this file.
1/* Copyright 2017 - 2026 R. Thomas
2 * Copyright 2017 - 2026 Quarkslab
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16#ifndef LIEF_ELF_PARSER_H
17#define LIEF_ELF_PARSER_H
18#include <unordered_map>
19#include <unordered_set>
20
21#include "LIEF/utils.hpp"
22#include "LIEF/visibility.h"
23
25#include "LIEF/errors.hpp"
26
28
29namespace LIEF {
30class BinaryStream;
31
32namespace OAT {
33class Parser;
34}
35namespace ELF {
36
37class Section;
38class Binary;
39class Segment;
40class Symbol;
41class Note;
42class Relocation;
43
46 friend class OAT::Parser;
47
48 public:
49 static constexpr uint32_t NB_MAX_SYMBOLS = 1000000;
50 static constexpr uint32_t DELTA_NB_SYMBOLS = 3000;
51 static constexpr uint32_t NB_MAX_BUCKETS = NB_MAX_SYMBOLS;
52 static constexpr uint32_t NB_MAX_CHAINS = 1000000;
53 static constexpr uint32_t NB_MAX_SEGMENTS = 10000;
54 static constexpr uint32_t NB_MAX_RELOCATIONS = 3000000;
55 static constexpr uint32_t NB_MAX_DYNAMIC_ENTRIES = 1000;
56 static constexpr uint32_t MAX_SEGMENT_SIZE = 3_GB;
57
63
73 static std::unique_ptr<Binary>
74 parse(const std::string& file,
75 const ParserConfig& conf = ParserConfig::all());
76
87 static std::unique_ptr<Binary>
88 parse(const std::vector<uint8_t>& data,
89 const ParserConfig& conf = ParserConfig::all());
90
101 static std::unique_ptr<Binary>
102 parse(std::unique_ptr<BinaryStream> stream,
103 const ParserConfig& conf = ParserConfig::all());
104
111 static std::unique_ptr<Binary>
112 parse_from_memory(uintptr_t address,
113 const ParserConfig& conf = ParserConfig::all());
114
122 static std::unique_ptr<Binary>
123 parse_from_memory(uintptr_t address, size_t size,
124 const ParserConfig& conf = ParserConfig::all());
125
135 static std::unique_ptr<Binary>
136 parse_from_dump(const std::string& filepath, uint64_t addr,
137 const ParserConfig& conf = ParserConfig::all());
138
141 static std::unique_ptr<Binary>
142 parse_from_dump(BinaryStream& stream, uint64_t addr,
143 const ParserConfig& conf = ParserConfig::all());
144
147 static std::unique_ptr<Binary>
148 parse_from_dump(std::unique_ptr<BinaryStream> stream, uint64_t addr,
149 const ParserConfig& conf = ParserConfig::all());
150
151 Parser& operator=(const Parser&) = delete;
152 Parser(const Parser&) = delete;
153
154 ~Parser() override;
155
156 protected:
158 LIEF_LOCAL Parser(std::unique_ptr<BinaryStream> stream, ParserConfig config);
159 LIEF_LOCAL Parser(const std::string& file, ParserConfig config);
160 LIEF_LOCAL Parser(const std::vector<uint8_t>& data, ParserConfig config);
161
162 LIEF_LOCAL ok_error_t init();
163
164 LIEF_LOCAL bool should_swap() const;
165
166 // map, dynamic_symbol.version <----> symbol_version
167 // symbol_version comes from symbol_version table
168 LIEF_LOCAL void link_symbol_version();
169
170 LIEF_LOCAL ok_error_t link_symbol_section(Symbol& sym);
171
172 template<typename ELF_T>
173 LIEF_LOCAL ok_error_t parse_binary();
174
175 template<typename ELF_T>
176 LIEF_LOCAL ok_error_t parse_header();
177
178 template<typename ELF_T>
179 LIEF_LOCAL ok_error_t parse_sections();
180
181 template<typename ELF_T>
182 LIEF_LOCAL ok_error_t parse_segments();
183
184 LIEF_LOCAL uint64_t
185 get_dynamic_string_table(BinaryStream* stream = nullptr) const;
186
188 get_dynamic_string_table_from_segments(BinaryStream* stream = nullptr) const;
189
190 LIEF_LOCAL uint64_t get_dynamic_string_table_from_sections() const;
191
193 template<typename ELF_T>
195 get_numberof_dynamic_symbols(ParserConfig::DYNSYM_COUNT mtd) const;
196
198 template<typename ELF_T>
199 LIEF_LOCAL result<uint32_t> nb_dynsym_hash() const;
200
202 template<typename ELF_T>
203 LIEF_LOCAL result<uint32_t> nb_dynsym_sysv_hash() const;
204
206 template<typename ELF_T>
207 LIEF_LOCAL result<uint32_t> nb_dynsym_gnu_hash() const;
208
210 template<typename ELF_T>
211 LIEF_LOCAL result<uint32_t> nb_dynsym_section() const;
212
214 template<typename ELF_T>
215 LIEF_LOCAL result<uint32_t> nb_dynsym_relocations() const;
216
217 template<typename ELF_T>
218 LIEF_LOCAL ok_error_t parse_dynamic_entries(BinaryStream& stream);
219
220 template<typename ELF_T>
221 LIEF_LOCAL ok_error_t parse_dynamic_symbols(uint64_t offset);
222
232 template<typename ELF_T>
233 LIEF_LOCAL ok_error_t parse_symtab_symbols(const Section& symtab_section,
234 const Section& string_section);
235
239 template<typename ELF_T, typename REL_T>
240 LIEF_LOCAL ok_error_t parse_dynamic_relocations(uint64_t relocations_offset,
241 uint64_t size);
242
248 template<typename ELF_T, typename REL_T>
249 LIEF_LOCAL ok_error_t parse_pltgot_relocations(uint64_t offset, uint64_t size);
250
251
253 template<typename ELF_T>
254 LIEF_LOCAL ok_error_t parse_relative_relocations(uint64_t offset, uint64_t size);
255
257 template<typename ELF_T>
258 LIEF_LOCAL ok_error_t parse_packed_relocations(uint64_t offset, uint64_t size);
259
260 template<typename ELF_T>
261 LIEF_LOCAL ok_error_t process_dynamic_table();
262
265 template<typename ELF_T, typename REL_T>
266 LIEF_LOCAL ok_error_t parse_section_relocations(const Section& section);
267
273 template<typename ELF_T>
274 LIEF_LOCAL ok_error_t parse_symbol_version_requirement(uint64_t offset,
275 uint32_t nb_entries);
276
277
283 template<typename ELF_T>
284 LIEF_LOCAL ok_error_t parse_symbol_version_definition(uint64_t offset,
285 uint32_t nb_entries);
286
287
294 LIEF_LOCAL ok_error_t parse_symbol_version(uint64_t symbol_version_offset);
295
299 template<typename ELF_T>
300 LIEF_LOCAL ok_error_t parse_symbol_gnu_hash(uint64_t offset);
301
303 LIEF_LOCAL ok_error_t parse_notes(uint64_t offset, uint64_t size);
304
305 LIEF_LOCAL std::unique_ptr<Note> get_note(uint32_t type, std::string name,
306 std::vector<uint8_t> desc_bytes);
307
309 LIEF_LOCAL ok_error_t parse_symbol_sysv_hash(uint64_t offset);
310
311 LIEF_LOCAL ok_error_t parse_overlay();
312
313 template<typename ELF_T, typename REL_T>
314 LIEF_LOCAL uint32_t max_relocation_index(uint64_t relocations_offset,
315 uint64_t size) const;
316
318 LIEF_LOCAL static bool check_section_in_segment(const Section& section,
319 const Segment& segment);
320
321 LIEF_LOCAL bool bind_symbol(Relocation& R);
322 LIEF_LOCAL Relocation& insert_relocation(std::unique_ptr<Relocation> R);
323
324 template<class ELF_T>
325 LIEF_LOCAL ok_error_t parse_dyn_table(Segment& pt_dyn);
326
327 std::unique_ptr<BinaryStream> stream_;
328 std::unique_ptr<Binary> binary_;
329 ParserConfig config_;
330 /*
331 * parse_sections() may skip some sections so that
332 * binary_->sections_ is not contiguous based on the index of the sections.
333 *
334 * On the other hand, we need these indexes to bind symbols that
335 * reference sections. That's why we have this unordered_map.
336 */
337 std::unordered_map<size_t, Section*> sections_idx_;
338 uint64_t memory_address_ = 0;
339 std::unordered_set<uint64_t> notes_offset_;
340};
341
342}
343}
344#endif
Class that is used to a read stream of data from different sources.
Definition BinaryStream.hpp:35
Generic interface representing a binary executable.
Definition Abstract/Binary.hpp:60
static std::unique_ptr< Binary > parse_from_dump(const std::string &filepath, uint64_t addr, const ParserConfig &conf=ParserConfig::all())
Parse an ELF binary from a memory dump located on disk.
static std::unique_ptr< Binary > parse_from_dump(BinaryStream &stream, uint64_t addr, const ParserConfig &conf=ParserConfig::all())
Same as parse_from_dump(const std::string&, uint64_t, const ParserConfig&) but the dump is wrapped in...
static constexpr uint32_t NB_MAX_BUCKETS
Definition ELF/Parser.hpp:51
friend class OAT::Parser
Definition ELF/Parser.hpp:46
static constexpr uint32_t NB_MAX_SYMBOLS
Definition ELF/Parser.hpp:49
static std::unique_ptr< Binary > parse(std::unique_ptr< BinaryStream > stream, const ParserConfig &conf=ParserConfig::all())
Parse the ELF binary from the given stream and return a LIEF::ELF::Binary object.
static std::unique_ptr< Binary > parse_from_dump(std::unique_ptr< BinaryStream > stream, uint64_t addr, const ParserConfig &conf=ParserConfig::all())
Same as parse_from_dump(const std::string&, uint64_t, const ParserConfig&) but the dump is wrapped in...
static constexpr uint32_t DELTA_NB_SYMBOLS
Definition ELF/Parser.hpp:50
static constexpr uint32_t NB_MAX_RELOCATIONS
Definition ELF/Parser.hpp:54
static std::unique_ptr< Binary > parse(const std::vector< uint8_t > &data, const ParserConfig &conf=ParserConfig::all())
Parse the given raw data as an ELF binary and return a LIEF::ELF::Binary object.
static std::unique_ptr< Binary > parse_from_memory(uintptr_t address, const ParserConfig &conf=ParserConfig::all())
Parse the ELF binary from the given memory address.
static std::unique_ptr< Binary > parse(const std::string &file, const ParserConfig &conf=ParserConfig::all())
Parse an ELF file and return a LIEF::ELF::Binary object.
static std::unique_ptr< Binary > parse_from_memory(uintptr_t address, size_t size, const ParserConfig &conf=ParserConfig::all())
Parse the ELF binary from the given memory address with the given size.
static constexpr uint32_t NB_MAX_CHAINS
Definition ELF/Parser.hpp:52
~Parser() override
ELF_TYPE
Definition ELF/Parser.hpp:58
@ ELF64
Definition ELF/Parser.hpp:61
@ ELF_UNKNOWN
Definition ELF/Parser.hpp:59
@ ELF32
Definition ELF/Parser.hpp:60
static constexpr uint32_t MAX_SEGMENT_SIZE
Definition ELF/Parser.hpp:56
Parser(const Parser &)=delete
Parser & operator=(const Parser &)=delete
static constexpr uint32_t NB_MAX_SEGMENTS
Definition ELF/Parser.hpp:53
static constexpr uint32_t NB_MAX_DYNAMIC_ENTRIES
Definition ELF/Parser.hpp:55
Class that represents an ELF relocation.
Definition ELF/Relocation.hpp:40
Class which represents an ELF Section.
Definition ELF/Section.hpp:49
Class which represents the ELF segments.
Definition Segment.hpp:49
Class which represents an ELF symbol.
Definition ELF/Symbol.hpp:34
Class to parse an OAT file to produce an OAT::Binary.
Definition OAT/Parser.hpp:40
Main interface to parse an executable regardless of its format.
Definition Abstract/Parser.hpp:31
Class which represents an abstracted Relocation.
Definition Abstract/Relocation.hpp:27
Class which represents an abstracted section.
Definition Abstract/Section.hpp:31
This class represents a symbol in an executable format.
Definition Abstract/Symbol.hpp:30
Opaque structure that is used by LIEF to avoid writing result<void> f(...). Instead,...
Definition errors.hpp:119
Wrapper that contains an Object (T) or an error.
Definition errors.hpp:79
Namespace related to the LIEF's ELF module.
Definition Abstract/Header.hpp:28
Definition ELF/Parser.hpp:32
LIEF namespace.
Definition Abstract/Binary.hpp:41
This structure is used to tweak the ELF Parser (ELF::Parser).
Definition ELF/ParserConfig.hpp:26
DYNSYM_COUNT
Methods that can be used by the LIEF::ELF::Parser to count the number of dynamic symbols.
Definition ELF/ParserConfig.hpp:29
static ParserConfig all()
This returns a ParserConfig object configured to process all the ELF elements.
Definition ELF/ParserConfig.hpp:45
#define LIEF_API
Definition visibility.h:45
#define LIEF_LOCAL
Definition visibility.h:46