mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
GP-6913 - try 2 to fix gccexceptionhandler analyzer absptr values
Previous fix was also changing non-address values, which was bad. Bonus fix: bump up max DWARF expression length to allow reading very long exprs found in the example binary (sqlite)
This commit is contained in:
@@ -15,6 +15,7 @@
|
|||||||
*/
|
*/
|
||||||
package ghidra.app.plugin.exceptionhandlers.gcc;
|
package ghidra.app.plugin.exceptionhandlers.gcc;
|
||||||
|
|
||||||
|
import ghidra.app.util.opinion.ElfLoader;
|
||||||
import ghidra.program.model.address.*;
|
import ghidra.program.model.address.*;
|
||||||
import ghidra.program.model.data.*;
|
import ghidra.program.model.data.*;
|
||||||
import ghidra.program.model.listing.Program;
|
import ghidra.program.model.listing.Program;
|
||||||
@@ -230,9 +231,22 @@ abstract class AbstractDwarfEHDecoder implements DwarfEHDecoder {
|
|||||||
|
|
||||||
long offset = decode(context);
|
long offset = decode(context);
|
||||||
|
|
||||||
|
if (appMode == DwarfEHDataApplicationMode.DW_EH_PE_absptr &&
|
||||||
|
prog.getRelocationTable().getRelocations(context.getAddress()).isEmpty()) {
|
||||||
|
offset += getImageBaseAdjustment(prog);
|
||||||
|
}
|
||||||
|
|
||||||
return addrFactory.getAddress(ram.getSpaceID(), offset);
|
return addrFactory.getAddress(ram.getSpaceID(), offset);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private static long getImageBaseAdjustment(Program program) {
|
||||||
|
Long originalImageBase = ElfLoader.getElfOriginalImageBase(program);
|
||||||
|
if (originalImageBase != null) {
|
||||||
|
return program.getImageBase().getOffset() - originalImageBase;
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get the DWARF-encoded integer value as stored by the context
|
* Get the DWARF-encoded integer value as stored by the context
|
||||||
* @param context Stores program location and decode parameters
|
* @param context Stores program location and decode parameters
|
||||||
@@ -245,7 +259,6 @@ abstract class AbstractDwarfEHDecoder implements DwarfEHDecoder {
|
|||||||
long val = doDecode(context);
|
long val = doDecode(context);
|
||||||
|
|
||||||
return resolveRelativeOffset(val, context);
|
return resolveRelativeOffset(val, context);
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private long resolveRelativeOffset(long val, DwarfDecodeContext context)
|
private long resolveRelativeOffset(long val, DwarfDecodeContext context)
|
||||||
@@ -263,8 +276,8 @@ abstract class AbstractDwarfEHDecoder implements DwarfEHDecoder {
|
|||||||
|
|
||||||
switch (appMode) {
|
switch (appMode) {
|
||||||
case DW_EH_PE_absptr:
|
case DW_EH_PE_absptr:
|
||||||
// adjust abs ptr for any changes to imagebase during import
|
// This mode is used for counts, offsets, etc as well as pointer values, so it
|
||||||
val = context.getImageBaseAdjustment() + val;
|
// shouldn't be 'fixed' here by applying imageBaseOffset from Elf loader
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case DW_EH_PE_aligned:
|
case DW_EH_PE_aligned:
|
||||||
|
|||||||
@@ -15,7 +15,6 @@
|
|||||||
*/
|
*/
|
||||||
package ghidra.app.plugin.exceptionhandlers.gcc;
|
package ghidra.app.plugin.exceptionhandlers.gcc;
|
||||||
|
|
||||||
import ghidra.app.util.opinion.ElfLoader;
|
|
||||||
import ghidra.program.model.address.Address;
|
import ghidra.program.model.address.Address;
|
||||||
import ghidra.program.model.listing.Function;
|
import ghidra.program.model.listing.Function;
|
||||||
import ghidra.program.model.listing.Program;
|
import ghidra.program.model.listing.Program;
|
||||||
@@ -30,7 +29,6 @@ public class DwarfDecodeContext {
|
|||||||
private final Address addr;
|
private final Address addr;
|
||||||
private final MemoryBlock ehBlock;
|
private final MemoryBlock ehBlock;
|
||||||
private final Address functionEntryPoint;
|
private final Address functionEntryPoint;
|
||||||
private final long imageBaseAdjustment;
|
|
||||||
|
|
||||||
private Object decodedValue;
|
private Object decodedValue;
|
||||||
private int encodedLength;
|
private int encodedLength;
|
||||||
@@ -95,18 +93,9 @@ public class DwarfDecodeContext {
|
|||||||
this.addr = readAddr;
|
this.addr = readAddr;
|
||||||
this.ehBlock = ehBlock;
|
this.ehBlock = ehBlock;
|
||||||
this.functionEntryPoint = entryPoint;
|
this.functionEntryPoint = entryPoint;
|
||||||
this.imageBaseAdjustment = getImageBaseAdjustment(program);
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private static long getImageBaseAdjustment(Program program) {
|
|
||||||
Long originalImageBase = ElfLoader.getElfOriginalImageBase(program);
|
|
||||||
if (originalImageBase != null) {
|
|
||||||
return program.getImageBase().getOffset() - originalImageBase;
|
|
||||||
}
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Gets the program containing the encoded data.
|
* Gets the program containing the encoded data.
|
||||||
* @return the program
|
* @return the program
|
||||||
@@ -165,12 +154,4 @@ public class DwarfDecodeContext {
|
|||||||
public Address getFunctionEntryPoint() {
|
public Address getFunctionEntryPoint() {
|
||||||
return functionEntryPoint;
|
return functionEntryPoint;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* {@return any adjustment needed to be applied to absolute addresses (because the program's
|
|
||||||
* base address was modified during import)}
|
|
||||||
*/
|
|
||||||
public long getImageBaseAdjustment() {
|
|
||||||
return imageBaseAdjustment;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ import ghidra.app.util.bin.format.dwarf.DWARFRegisterMappings;
|
|||||||
* Use a {@link DWARFExpressionEvaluator} to execute a {@link DWARFExpression}.
|
* Use a {@link DWARFExpressionEvaluator} to execute a {@link DWARFExpression}.
|
||||||
*/
|
*/
|
||||||
public class DWARFExpression {
|
public class DWARFExpression {
|
||||||
public static final int MAX_SANE_EXPR = 256;
|
public static final int MAX_SANE_EXPR = 512;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Deserializes a {@link DWARFExpression} from its raw bytes.
|
* Deserializes a {@link DWARFExpression} from its raw bytes.
|
||||||
|
|||||||
Reference in New Issue
Block a user