mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
GP-0: Certify
This commit is contained in:
@@ -85,18 +85,16 @@ public class DelayImportDescriptor implements StructConverter {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Warn if the INT and IAT declare different numbers of entries.
|
// Warn if the INT and IAT declare different numbers of entries. These are parallel arrays
|
||||||
// These are parallel arrays so a length mismatch is malformed.
|
// so a length mismatch is malformed. The thunk lists include the trailing null terminator,
|
||||||
// The thunk lists include the trailing null terminator, so the
|
// so the import count is size() - 1. This only surfaces the discrepancy; it does not change
|
||||||
// import count is size() - 1. This only surfaces the discrepancy;
|
// import enumeration.
|
||||||
// it does not change import enumeration.
|
if (pIAT != 0 && pINT != 0 && thunksIAT.size() != thunksINT.size()) {
|
||||||
if (pIAT != 0 && pINT != 0 && thunksIAT.size() != thunksINT.size()) {
|
int intCount = Math.max(0, thunksINT.size() - 1);
|
||||||
int intCount = Math.max(0, thunksINT.size() - 1);
|
int iatCount = Math.max(0, thunksIAT.size() - 1);
|
||||||
int iatCount = Math.max(0, thunksIAT.size() - 1);
|
Msg.warn(this, "Delay-load INT/IAT import count mismatch for '%s': INT=%d IAT=%d"
|
||||||
Msg.warn(this, "Delay-load INT/IAT import count mismatch for " +
|
.formatted(dllName != null ? dllName : "unknown DLL", intCount, iatCount));
|
||||||
(dllName != null ? dllName : "unknown DLL") +
|
}
|
||||||
": INT=" + intCount + " IAT=" + iatCount);
|
|
||||||
}
|
|
||||||
|
|
||||||
thunksBoundIAT = readThunks(ntHeader, reader, pBoundIAT, false);
|
thunksBoundIAT = readThunks(ntHeader, reader, pBoundIAT, false);
|
||||||
if (thunksBoundIAT == null) {
|
if (thunksBoundIAT == null) {
|
||||||
|
|||||||
Reference in New Issue
Block a user