From 6fa0ddbc0374dbe3dc5449ea639c9722483aab7a Mon Sep 17 00:00:00 2001 From: Matthew Duggan Date: Thu, 28 May 2020 14:47:38 +0900 Subject: [PATCH 1/2] Support large (>2^16) offset to exe file NE header This is the case for Phar Lap 286|DOS-Extender exes. --- .../ghidra/app/util/bin/format/ne/EntryTable.java | 4 ++-- .../app/util/bin/format/ne/ImportedNameTable.java | 6 +++--- .../app/util/bin/format/ne/InformationBlock.java | 4 ++-- .../util/bin/format/ne/ModuleReferenceTable.java | 4 ++-- .../app/util/bin/format/ne/NewExecutable.java | 2 +- .../app/util/bin/format/ne/ResidentNameTable.java | 4 ++-- .../app/util/bin/format/ne/ResourceTable.java | 8 ++++---- .../app/util/bin/format/ne/SegmentTable.java | 4 ++-- .../app/util/bin/format/ne/WindowsHeader.java | 14 +++++++------- 9 files changed, 25 insertions(+), 25 deletions(-) diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/EntryTable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/EntryTable.java index 3098e54812..4cf6a23e6b 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/EntryTable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/EntryTable.java @@ -34,9 +34,9 @@ public class EntryTable { * @param index the index where the entry table begins * @param byteCount the length in bytes of the entry table */ - EntryTable(BinaryReader reader, short index, short byteCount) throws IOException { + EntryTable(BinaryReader reader, int index, short byteCount) throws IOException { long oldIndex = reader.getPointerIndex(); - reader.setPointerIndex(Short.toUnsignedInt(index)); + reader.setPointerIndex(index); ArrayList list = new ArrayList(); while (true) { diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ImportedNameTable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ImportedNameTable.java index 9b1e79a763..2ded4a85be 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ImportedNameTable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ImportedNameTable.java @@ -26,14 +26,14 @@ import ghidra.app.util.bin.BinaryReader; */ public class ImportedNameTable { private BinaryReader reader; - private short index; + private int index; /** * Constructs a new imported name table. * @param reader the binary reader * @param index the index where the table begins */ - ImportedNameTable(BinaryReader reader, short index) { + ImportedNameTable(BinaryReader reader, int index) { this.reader = reader; this.index = index; } @@ -48,7 +48,7 @@ public class ImportedNameTable { */ public LengthStringSet getNameAt(short offset) throws IOException { long oldIndex = reader.getPointerIndex(); - int newIndex = Short.toUnsignedInt(index) + Short.toUnsignedInt(offset); + int newIndex = index + Short.toUnsignedInt(offset); reader.setPointerIndex(newIndex); LengthStringSet lss = new LengthStringSet(reader); reader.setPointerIndex(oldIndex); diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/InformationBlock.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/InformationBlock.java index 16683db187..32dfcd6fd1 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/InformationBlock.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/InformationBlock.java @@ -194,10 +194,10 @@ public class InformationBlock { private short ne_swaparea; // Minimum code swap area size private short ne_expver; // Expected windows version number - InformationBlock(BinaryReader reader, short index) + InformationBlock(BinaryReader reader, int index) throws InvalidWindowsHeaderException, IOException { long oldIndex = reader.getPointerIndex(); - reader.setPointerIndex(Short.toUnsignedInt(index)); + reader.setPointerIndex(index); ne_magic = reader.readNextShort(); diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ModuleReferenceTable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ModuleReferenceTable.java index 8175f27240..4311cd7ebf 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ModuleReferenceTable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ModuleReferenceTable.java @@ -36,10 +36,10 @@ public class ModuleReferenceTable { * @param count the count of modules referenced * @param imp the imported name table */ - ModuleReferenceTable(BinaryReader reader, short index, short count, ImportedNameTable imp) + ModuleReferenceTable(BinaryReader reader, int index, short count, ImportedNameTable imp) throws IOException { long oldIndex = reader.getPointerIndex(); - reader.setPointerIndex(Short.toUnsignedInt(index)); + reader.setPointerIndex(index); offsets = new short[Short.toUnsignedInt(count)]; for (short i = 0 ; i < count ; ++i) { diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java index 58f7c48bab..fdb33ad69f 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java @@ -44,7 +44,7 @@ public class NewExecutable { if (dosHeader.isDosSignature()) { try { - winHeader = new WindowsHeader(reader, baseAddr, (short) dosHeader.e_lfanew()); + winHeader = new WindowsHeader(reader, baseAddr, dosHeader.e_lfanew()); } catch (InvalidWindowsHeaderException e) { } diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResidentNameTable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResidentNameTable.java index 61f9fba77c..fe2a080db1 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResidentNameTable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResidentNameTable.java @@ -27,9 +27,9 @@ import ghidra.app.util.bin.BinaryReader; public class ResidentNameTable { private LengthStringOrdinalSet [] names; - ResidentNameTable(BinaryReader reader, short index) throws IOException { + ResidentNameTable(BinaryReader reader, int index) throws IOException { long oldIndex = reader.getPointerIndex(); - reader.setPointerIndex(Short.toUnsignedInt(index)); + reader.setPointerIndex(index); ArrayList list = new ArrayList(); while (true) { diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResourceTable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResourceTable.java index 1eb9f6b518..0816bc7252 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResourceTable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/ResourceTable.java @@ -28,7 +28,7 @@ import ghidra.app.util.bin.BinaryReader; * */ public class ResourceTable { - private short index; + private int index; private short alignmentShiftCount; private ResourceType [] types; private ResourceName [] names; @@ -39,11 +39,11 @@ public class ResourceTable { * @param index the byte index where the Resource Table begins, * (this is relative to the beginning of the file */ - ResourceTable(BinaryReader reader, short index) throws IOException { + ResourceTable(BinaryReader reader, int index) throws IOException { this.index = index; long oldIndex = reader.getPointerIndex(); - reader.setPointerIndex(Short.toUnsignedInt(index)); + reader.setPointerIndex(index); alignmentShiftCount = reader.readNextShort(); @@ -98,7 +98,7 @@ public class ResourceTable { * relative to the beginning of the file. * @return the byte index where the resource table begins */ - public short getIndex() { + public int getIndex() { return index; } } diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/SegmentTable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/SegmentTable.java index 9da5e7b2a2..2abde9ce3e 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/SegmentTable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/SegmentTable.java @@ -28,10 +28,10 @@ import ghidra.program.model.address.SegmentedAddressSpace; public class SegmentTable { private Segment [] segments; - SegmentTable(BinaryReader reader, SegmentedAddress baseAddr, short index, short segmentCount, + SegmentTable(BinaryReader reader, SegmentedAddress baseAddr, int index, short segmentCount, short shiftAlignCount) throws IOException { long oldIndex = reader.getPointerIndex(); - reader.setPointerIndex(Short.toUnsignedInt(index)); + reader.setPointerIndex(index); //create a value of the shift count... shiftAlignCount = (short)(0x01 << shiftAlignCount); diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java index 7411b4cf72..f098f120d4 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java @@ -49,10 +49,10 @@ public class WindowsHeader { * @throws IOException for problems reading the header bytes */ public WindowsHeader(BinaryReader reader, SegmentedAddress baseAddr, - short index) throws InvalidWindowsHeaderException, IOException { + int index) throws InvalidWindowsHeaderException, IOException { this.infoBlock = new InformationBlock(reader, index); - short segTableIndex = (short)(infoBlock.getSegmentTableOffset() + index); + int segTableIndex = infoBlock.getSegmentTableOffset() + index; this.segTable = new SegmentTable(reader, baseAddr, segTableIndex, infoBlock.getSegmentCount(), infoBlock.getSegmentAlignmentShiftCount()); @@ -60,22 +60,22 @@ public class WindowsHeader { //if resource table offset == resident name table offset, then //we do not have any resources... if (infoBlock.getResourceTableOffset() != infoBlock.getResidentNameTableOffset()) { - short rsrcTableIndex = (short)(infoBlock.getResourceTableOffset() + index); + int rsrcTableIndex = infoBlock.getResourceTableOffset() + index; this.rsrcTable = new ResourceTable(reader, rsrcTableIndex); } - short resNameTableIndex = (short)(infoBlock.getResidentNameTableOffset() + index); + int resNameTableIndex = infoBlock.getResidentNameTableOffset() + index; this.resNameTable = new ResidentNameTable(reader, resNameTableIndex); - short impNameTableIndex = (short)(infoBlock.getImportedNamesTableOffset() + index); + int impNameTableIndex = infoBlock.getImportedNamesTableOffset() + index; this.impNameTable = new ImportedNameTable(reader, impNameTableIndex); - short modRefTableIndex = (short)(infoBlock.getModuleReferenceTableOffset() + index); + int modRefTableIndex = infoBlock.getModuleReferenceTableOffset() + index; this.modRefTable = new ModuleReferenceTable(reader, modRefTableIndex, infoBlock.getModuleReferenceTableCount(), impNameTable); - short entryTableIndex = (short)(infoBlock.getEntryTableOffset() + index); + int entryTableIndex = infoBlock.getEntryTableOffset() + index; this.entryTable = new EntryTable(reader, entryTableIndex, infoBlock.getEntryTableSize()); this.nonResNameTable = new NonResidentNameTable(reader, From 0351dc99aa62d99d1a3e67838152e87eab8bd3c1 Mon Sep 17 00:00:00 2001 From: Ryan Kurtz Date: Thu, 5 Mar 2026 13:13:45 -0500 Subject: [PATCH 2/2] GP-6537: Certify --- .../java/ghidra/app/util/bin/format/ne/NewExecutable.java | 4 ++-- .../java/ghidra/app/util/bin/format/ne/WindowsHeader.java | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java index fdb33ad69f..c6767147ff 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/NewExecutable.java @@ -4,9 +4,9 @@ * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at - * + * * http://www.apache.org/licenses/LICENSE-2.0 - * + * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. diff --git a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java index f098f120d4..893cf3b0e8 100644 --- a/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java +++ b/Ghidra/Features/Base/src/main/java/ghidra/app/util/bin/format/ne/WindowsHeader.java @@ -4,9 +4,9 @@ * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at - * + * * http://www.apache.org/licenses/LICENSE-2.0 - * + * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.