diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DyldChainedFixupsCommand.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DyldChainedFixupsCommand.java index 3487de4698..856eb89317 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DyldChainedFixupsCommand.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DyldChainedFixupsCommand.java @@ -112,8 +112,9 @@ public class DyldChainedFixupsCommand extends LinkEditDataCommand { try { super.markupRawBinary(header, api, baseAddress, parentModule, monitor, log); - List
addrs = - api.getCurrentProgram().getMemory().locateAddressesForFileOffset(getDataOffset()); + List addrs = api.getCurrentProgram() + .getMemory() + .locateAddressesForFileOffset(getLinkerDataOffset()); if (addrs.size() <= 0) { throw new Exception("Chain Header does not exist in program"); } diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DynamicSymbolTableCommand.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DynamicSymbolTableCommand.java index 0a24a2e396..a86a9158a3 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DynamicSymbolTableCommand.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/DynamicSymbolTableCommand.java @@ -304,6 +304,16 @@ public class DynamicSymbolTableCommand extends LoadCommand { return localRelocations; } + @Override + public int getLinkerDataOffset() { + return indirectsymoff; + } + + @Override + public int getLinkerDataSize() { + return nindirectsyms * Integer.BYTES; + } + @Override public DataType toDataType() throws DuplicateNameException, IOException { StructureDataType struct = new StructureDataType(getCommandName(), 0); diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LinkEditDataCommand.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LinkEditDataCommand.java index ef3246abc4..3ab82117cf 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LinkEditDataCommand.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LinkEditDataCommand.java @@ -57,11 +57,13 @@ public class LinkEditDataCommand extends LoadCommand { this.dataReader.setPointerIndex(dataoff); } - public int getDataOffset() { + @Override + public int getLinkerDataOffset() { return dataoff; } - public int getDataSize() { + @Override + public int getLinkerDataSize() { return datasize; } diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LoadCommand.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LoadCommand.java index 1047dbd915..521932eff7 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LoadCommand.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/LoadCommand.java @@ -85,6 +85,26 @@ public abstract class LoadCommand implements StructConverter { */ public abstract String getCommandName(); + /** + * Gets the file offset of this load command's "linker data". Not all load commands with data + * will have linker data. Linker data typically resides in the __LINKEDIT segment. + * + * @return The file offset of this load command's "linker data", or 0 if it has no linker data + */ + public int getLinkerDataOffset() { + return 0; + } + + /** + * Gets the file size of this load command's "linker data". Not all load commands with data + * will have linker data. Linker data typically resides in the __LINKEDIT segment. + * + * @return The file size of this load command's "linker data", or 0 if it has no linker data + */ + public int getLinkerDataSize() { + return 0; + } + /** * Gets the {@link Address} of this load command's "data" * diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SegmentCommand.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SegmentCommand.java index c2e97d397e..0bcddce7b0 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SegmentCommand.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SegmentCommand.java @@ -116,6 +116,10 @@ public class SegmentCommand extends LoadCommand { return vmsize; } + public void setVMsize(long vmSize) { + vmsize = vmSize; + } + public long getFileOffset() { return fileoff; } @@ -128,6 +132,10 @@ public class SegmentCommand extends LoadCommand { return filesize; } + public void setFileSize(long fileSize) { + filesize = fileSize; + } + /** * Returns a octal model value reflecting the * segment's maximum protection value allowed. diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SymbolTableCommand.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SymbolTableCommand.java index 52561fe172..baa33afa63 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SymbolTableCommand.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/macho/commands/SymbolTableCommand.java @@ -74,12 +74,12 @@ public class SymbolTableCommand extends LoadCommand { List+ * NOTE: We are currently only extracting the Indirect Symbol Table, so zero-out the other + * fields that might point to data. + * + * @param cmd The dynamic symbol table to fix-up + * @throws IOException If there was an IO-related issue performing the fix-up + */ + private void fixupDynamicSymbolTable(DynamicSymbolTableCommand cmd) throws IOException { + long adjustment = getLinkEditAdjustment(cmd); + if (cmd.getTableOfContentsOffset() > 0) { + set(cmd.getStartIndex() + 0x20, 0, 8); + } + if (cmd.getModuleTableOffset() > 0) { + set(cmd.getStartIndex() + 0x28, 0, 8); + } + if (cmd.getReferencedSymbolTableOffset() > 0) { + set(cmd.getStartIndex() + 0x30, 0, 8); + } + if (cmd.getIndirectSymbolTableOffset() > 0) { + fixup(cmd.getStartIndex() + 0x38, adjustment, 4, linkEditSegment); + } + if (cmd.getExternalRelocationOffset() > 0) { + set(cmd.getStartIndex() + 0x40, 0, 8); + } + if (cmd.getLocalRelocationOffset() > 0) { + set(cmd.getStartIndex() + 0x48, 0, 8); + } + } + + /** + * Fixes-up the old DYLD file offsets in the given DYLD Info command so they are correct for + * the newly packed DYLIB. + *
+ * NOTE: We are currently not extracting this load command, so zero-out all the fields. + * + * @param cmd The DYLD Info command to fix-up + * @throws IOException If there was an IO-related issue performing the fix-up + */ + private void fixupDyldInfo(DyldInfoCommand cmd) throws IOException { + if (cmd.getRebaseOffset() > 0) { + set(cmd.getStartIndex() + 0x8, 0, 8); + } + if (cmd.getBindOffset() > 0) { + set(cmd.getStartIndex() + 0x10, 0, 8); + } + if (cmd.getWeakBindOffset() > 0) { + set(cmd.getStartIndex() + 0x18, 0, 8); + } + if (cmd.getLazyBindOffset() > 0) { + set(cmd.getStartIndex() + 0x20, 0, 8); + } + if (cmd.getExportOffset() > 0) { + set(cmd.getStartIndex() + 0x28, 0, 8); + } + } + + /** + * Fixes-up the old DYLD file offsets in the given link edit data command so they are correct + * for the newly packed DYLIB + * + * @param cmd The link edit data command to fix-up + * @throws IOException If there was an IO-related issue performing the fix-up + */ + private void fixupLinkEditData(LinkEditDataCommand cmd) throws IOException { + if (cmd.getLinkerDataOffset() > 0) { + fixup(cmd.getStartIndex() + 0x8, getLinkEditAdjustment(cmd), 4, linkEditSegment); + } + } + + /** + * Gets a value that will need to be added to a DYLD file offset into the __LINKEDIT segment + * to account for our new __LINKEDIT segment being packed * - * @param fileOffset The DYLD file offset to fix-up - * @param adjustment An value to add to the bytes at the given DYLD file offset prior to - * looking them up in the packed DYLIB - * @param size The number of bytes to fix-up (must be 4 or 8) - * @param segment The segment that the value at the file offset is associated with + * @param cmd The target __LINKEDIT {@link LoadCommand} + * @return The adjustment value + */ + private long getLinkEditAdjustment(LoadCommand cmd) { + return packedLinkEditDataStarts.getOrDefault(cmd, 0) - + (cmd.getLinkerDataOffset() - linkEditSegment.getFileOffset()); + } + + /** + * Sets the bytes at the given DYLD file offset to the given value. The provided file + * offset is assumed to map to a field in a load command. + * + * @param fileOffset The DYLD file offset to set + * @param value The new value + * @param size The number of bytes to set (must be 4 or 8) * @throws IOException If there was an IO-related error * @throws IllegalArgumentException if size is an unsupported value */ - public void fixup(long fileOffset, long adjustment, int size, SegmentCommand segment) + private void set(long fileOffset, long value, int size) throws IOException, IllegalArgumentException { if (size != 4 && size != 8) { throw new IllegalArgumentException("Size must be 4 or 8 (got " + size + ")"); } - long value = reader.readUnsignedValue(fileOffset, size); - value += adjustment; try { - byte[] newBytes = toBytes(getPackedOffset(value, segment), size); - SegmentCommand textSegment = header.getSegment(SegmentNames.SEG_TEXT); + byte[] newBytes = toBytes(value, size); System.arraycopy(newBytes, 0, packed, (int) getPackedOffset(fileOffset, textSegment), newBytes.length); } @@ -190,18 +475,37 @@ public class DyldCacheDylibExtractor { /** * Fixes up the bytes at the given DYLD file offset to map to the correct offset in the - * packed DYLIB. The provided file offset is assumed to map to a field in in a load - * command. + * packed DYLIB. The provided file offset is assumed to map to a field in a load command. * * @param fileOffset The DYLD file offset to fix-up + * @param adjustment A value to add to the bytes at the given DYLD file offset prior to + * looking them up in the packed DYLIB * @param size The number of bytes to fix-up (must be 4 or 8) - * @param segment The segment that the file offset is associated with + * @param segment The segment that the value at the file offset is associated with + * @return The newly fixed up value (or the original value if there was a graceful failure) * @throws IOException If there was an IO-related error * @throws IllegalArgumentException if size is an unsupported value */ - public void fixup(long fileOffset, int size, SegmentCommand segment) + private long fixup(long fileOffset, long adjustment, int size, SegmentCommand segment) throws IOException, IllegalArgumentException { - fixup(fileOffset, 0, size, segment); + if (size != 4 && size != 8) { + throw new IllegalArgumentException("Size must be 4 or 8 (got " + size + ")"); + } + long value = reader.readUnsignedValue(fileOffset, size); + long ret = value; + value += adjustment; + + try { + ret = getPackedOffset(value, segment); + byte[] newBytes = toBytes(ret, size); + System.arraycopy(newBytes, 0, packed, + (int) getPackedOffset(fileOffset, textSegment), newBytes.length); + } + catch (NotFoundException e) { + Msg.warn(this, e.getMessage()); + } + + return ret; } /** @@ -260,174 +564,5 @@ public class DyldCacheDylibExtractor { DataConverter converter = LittleEndianDataConverter.INSTANCE; return size == 8 ? converter.getBytes(value) : converter.getBytes((int) value); } - - /** - * Fixes-up the {@link MachHeader} in the newly packed DYLIB - */ - private void fixupMachHeader() { - // Indicate that the new packed DYLIB is no longer in the cache - set(0x18, header.getFlags() & ~MachHeaderFlags.MH_DYLIB_IN_CACHE, 4); - } - - /** - * Fixes-up various fields in the new packed DYLIB's load commands - * - * @throws IOException If there was an IO-related issue performing the fix-up - */ - private void fixupLoadCommands() throws IOException { - // Fixup indices, offsets, etc in the packed DYLIB's load commands - for (LoadCommand cmd : header.getLoadCommands()) { - if (monitor.isCancelled()) { - break; - } - switch (cmd.getCommandType()) { - case LoadCommandTypes.LC_SEGMENT: - fixupSegment((SegmentCommand) cmd, false); - break; - case LoadCommandTypes.LC_SEGMENT_64: - fixupSegment((SegmentCommand) cmd, true); - break; - case LoadCommandTypes.LC_SYMTAB: - fixupSymbolTable((SymbolTableCommand) cmd); - break; - case LoadCommandTypes.LC_DYSYMTAB: - fixupDynamicSymbolTable((DynamicSymbolTableCommand) cmd); - break; - case LoadCommandTypes.LC_DYLD_INFO: - case LoadCommandTypes.LC_DYLD_INFO_ONLY: - fixupDyldInfo((DyldInfoCommand) cmd); - break; - case LoadCommandTypes.LC_CODE_SIGNATURE: - case LoadCommandTypes.LC_SEGMENT_SPLIT_INFO: - case LoadCommandTypes.LC_FUNCTION_STARTS: - case LoadCommandTypes.LC_DATA_IN_CODE: - case LoadCommandTypes.LC_DYLIB_CODE_SIGN_DRS: - case LoadCommandTypes.LC_OPTIMIZATION_HINT: - case LoadCommandTypes.LC_DYLD_EXPORTS_TRIE: - case LoadCommandTypes.LC_DYLD_CHAINED_FIXUPS: - fixupLinkEditData((LinkEditDataCommand) cmd); - break; - } - } - } - - /** - * Fixes-up the old DYLD file offsets in the given segment so they are correct for the newly - * packed DYLIB - * - * @param segment The segment to fix-up - * @param is64bit True if the segment is 64-bit; false if 32-bit - * @throws IOException If there was an IO-related issue performing the fix-up - */ - private void fixupSegment(SegmentCommand segment, boolean is64bit) throws IOException { - long adjustment = packedSegmentAdjustments.getOrDefault(segment, 0); - if (segment.getFileOffset() > 0) { - fixup(segment.getStartIndex() + (is64bit ? 0x28 : 0x20), adjustment, - is64bit ? 8 : 4, segment); - } - long sectionStartIndex = segment.getStartIndex() + (is64bit ? 0x48 : 0x38); - for (Section section : segment.getSections()) { - if (monitor.isCancelled()) { - break; - } - - // For some reason the section file offsets in the iOS 10 DYLD cache do not want - // the adjustment despite the segment needed it. We can expect to see warnings - // in that particular version. - if (section.getOffset() > 0 && section.getSize() > 0) { - fixup(sectionStartIndex + (is64bit ? 0x30 : 0x28), adjustment, 4, segment); - } - if (section.getRelocationOffset() > 0) { - fixup(sectionStartIndex + (is64bit ? 0x38 : 0x30), adjustment, 4, segment); - } - sectionStartIndex += is64bit ? 0x50 : 0x44; - } - } - - /** - * Fixes-up the old DYLD file offsets in the given symbol table so they are correct for the - * newly packed DYLIB - * - * @param cmd The symbol table to fix-up - * @throws IOException If there was an IO-related issue performing the fix-up - */ - private void fixupSymbolTable(SymbolTableCommand cmd) throws IOException { - SegmentCommand segment = header.getSegment(SegmentNames.SEG_LINKEDIT); - if (cmd.getSymbolOffset() > 0) { - fixup(cmd.getStartIndex() + 0x8, 4, segment); - } - if (cmd.getStringTableOffset() > 0) { - fixup(cmd.getStartIndex() + 0x10, 4, segment); - } - } - - /** - * Fixes-up the old DYLD file offsets in the given dynamic symbol table so they are correct for - * the newly packed DYLIB - * - * @param cmd The dynamic symbol table to fix-up - * @throws IOException If there was an IO-related issue performing the fix-up - */ - private void fixupDynamicSymbolTable(DynamicSymbolTableCommand cmd) throws IOException { - SegmentCommand segment = header.getSegment(SegmentNames.SEG_LINKEDIT); - if (cmd.getTableOfContentsOffset() > 0) { - fixup(cmd.getStartIndex() + 0x20, 4, segment); - } - if (cmd.getModuleTableOffset() > 0) { - fixup(cmd.getStartIndex() + 0x28, 4, segment); - } - if (cmd.getReferencedSymbolTableOffset() > 0) { - fixup(cmd.getStartIndex() + 0x30, 4, segment); - } - if (cmd.getIndirectSymbolTableOffset() > 0) { - fixup(cmd.getStartIndex() + 0x38, 4, segment); - } - if (cmd.getExternalRelocationOffset() > 0) { - fixup(cmd.getStartIndex() + 0x40, 4, segment); - } - if (cmd.getLocalRelocationOffset() > 0) { - fixup(cmd.getStartIndex() + 0x48, 4, segment); - } - } - - /** - * Fixes-up the old DYLD file offsets in the given DYLD Info command so they are correct for the - * newly packed DYLIB - * - * @param cmd The DYLD Info command to fix-up - * @throws IOException If there was an IO-related issue performing the fix-up - */ - private void fixupDyldInfo(DyldInfoCommand cmd) throws IOException { - SegmentCommand segment = header.getSegment(SegmentNames.SEG_LINKEDIT); - if (cmd.getRebaseOffset() > 0) { - fixup(cmd.getStartIndex() + 0x8, 4, segment); - } - if (cmd.getBindOffset() > 0) { - fixup(cmd.getStartIndex() + 0x10, 4, segment); - } - if (cmd.getWeakBindOffset() > 0) { - fixup(cmd.getStartIndex() + 0x18, 4, segment); - } - if (cmd.getLazyBindOffset() > 0) { - fixup(cmd.getStartIndex() + 0x20, 4, segment); - } - if (cmd.getExportOffset() > 0) { - fixup(cmd.getStartIndex() + 0x28, 4, segment); - } - } - - /** - * Fixes-up the old DYLD file offsets in the given link edit data command so they are correct - * for the newly packed DYLIB - * - * @param cmd The link edit data command to fix-up - * @throws IOException If there was an IO-related issue performing the fix-up - */ - private void fixupLinkEditData(LinkEditDataCommand cmd) throws IOException { - SegmentCommand segment = header.getSegment(SegmentNames.SEG_LINKEDIT); - if (cmd.getDataOffset() > 0) { - fixup(cmd.getStartIndex() + 0x8, 4, segment); - } - } } }