JclPeImage.pas 223 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047
  1. {**************************************************************************************************}
  2. { }
  3. { Project JEDI Code Library (JCL) }
  4. { }
  5. { The contents of this file are subject to the Mozilla Public License Version 1.1 (the "License"); }
  6. { you may not use this file except in compliance with the License. You may obtain a copy of the }
  7. { License at http://www.mozilla.org/MPL/ }
  8. { }
  9. { Software distributed under the License is distributed on an "AS IS" basis, WITHOUT WARRANTY OF }
  10. { ANY KIND, either express or implied. See the License for the specific language governing rights }
  11. { and limitations under the License. }
  12. { }
  13. { The Original Code is JclPeImage.pas. }
  14. { }
  15. { The Initial Developer of the Original Code is Petr Vones. Portions created by Petr Vones are }
  16. { Copyright (C) Petr Vones. All Rights Reserved. }
  17. { }
  18. { Contributor(s): }
  19. { Marcel van Brakel }
  20. { Robert Marquardt (marquardt) }
  21. { Uwe Schuster (uschuster) }
  22. { Matthias Thoma (mthoma) }
  23. { Petr Vones (pvones) }
  24. { Hallvard Vassbotn }
  25. { Jean-Fabien Connault (cycocrew) }
  26. { }
  27. {**************************************************************************************************}
  28. { }
  29. { This unit contains various classes and support routines to read the contents of portable }
  30. { executable (PE) files. You can use these classes to, for example examine the contents of the }
  31. { imports section of an executable. In addition the unit contains support for Borland specific }
  32. { structures and name unmangling. }
  33. { }
  34. {**************************************************************************************************}
  35. { }
  36. { Last modified: $Date:: $ }
  37. { Revision: $Rev:: $ }
  38. { Author: $Author:: $ }
  39. { }
  40. {**************************************************************************************************}
  41. unit JclPeImage;
  42. {$I jcl.inc}
  43. {$I windowsonly.inc}
  44. interface
  45. uses
  46. {$IFDEF UNITVERSIONING}
  47. JclUnitVersioning,
  48. {$ENDIF UNITVERSIONING}
  49. {$IFDEF HAS_UNITSCOPE}
  50. Winapi.Windows, System.Classes, System.SysUtils, System.TypInfo, System.Contnrs,
  51. {$ELSE ~HAS_UNITSCOPE}
  52. Windows, Classes, SysUtils, TypInfo, Contnrs,
  53. {$ENDIF ~HAS_UNITSCOPE}
  54. JclBase, JclDateTime, JclFileUtils, JclWin32;
  55. type
  56. // Smart name compare function
  57. TJclSmartCompOption = (scSimpleCompare, scIgnoreCase);
  58. TJclSmartCompOptions = set of TJclSmartCompOption;
  59. function PeStripFunctionAW(const FunctionName: string): string;
  60. function PeSmartFunctionNameSame(const ComparedName, FunctionName: string;
  61. Options: TJclSmartCompOptions = []): Boolean;
  62. type
  63. // Base list
  64. EJclPeImageError = class(EJclError);
  65. TJclPeImage = class;
  66. TJclPeImageClass = class of TJclPeImage;
  67. TJclPeImageBaseList = class(TObjectList)
  68. private
  69. FImage: TJclPeImage;
  70. public
  71. constructor Create(AImage: TJclPeImage);
  72. property Image: TJclPeImage read FImage;
  73. end;
  74. // Images cache
  75. TJclPeImagesCache = class(TObject)
  76. private
  77. FList: TStringList;
  78. function GetCount: Integer;
  79. function GetImages(const FileName: TFileName): TJclPeImage;
  80. protected
  81. function GetPeImageClass: TJclPeImageClass; virtual;
  82. public
  83. constructor Create;
  84. destructor Destroy; override;
  85. procedure Clear;
  86. property Images[const FileName: TFileName]: TJclPeImage read GetImages; default;
  87. property Count: Integer read GetCount;
  88. end;
  89. // Import section related classes
  90. TJclPeImportSort = (isName, isOrdinal, isHint, isLibImport);
  91. TJclPeImportLibSort = (ilName, ilIndex);
  92. TJclPeImportKind = (ikImport, ikDelayImport, ikBoundImport);
  93. TJclPeResolveCheck = (icNotChecked, icResolved, icUnresolved);
  94. TJclPeLinkerProducer = (lrBorland, lrMicrosoft);
  95. // lrBorland -> Delphi PE files
  96. // lrMicrosoft -> MSVC and BCB PE files
  97. TJclPeImportLibItem = class;
  98. // Created from a IMAGE_THUNK_DATA64 or IMAGE_THUNK_DATA32 record
  99. TJclPeImportFuncItem = class(TObject)
  100. private
  101. FOrdinal: Word; // word in 32/64
  102. FHint: Word;
  103. FImportLib: TJclPeImportLibItem;
  104. FIndirectImportName: Boolean;
  105. FName: string;
  106. FResolveCheck: TJclPeResolveCheck;
  107. function GetIsByOrdinal: Boolean;
  108. protected
  109. procedure SetName(const Value: string);
  110. procedure SetIndirectImportName(const Value: string);
  111. procedure SetResolveCheck(Value: TJclPeResolveCheck);
  112. public
  113. constructor Create(AImportLib: TJclPeImportLibItem; AOrdinal: Word;
  114. AHint: Word; const AName: string);
  115. property Ordinal: Word read FOrdinal;
  116. property Hint: Word read FHint;
  117. property ImportLib: TJclPeImportLibItem read FImportLib;
  118. property IndirectImportName: Boolean read FIndirectImportName;
  119. property IsByOrdinal: Boolean read GetIsByOrdinal;
  120. property Name: string read FName;
  121. property ResolveCheck: TJclPeResolveCheck read FResolveCheck;
  122. end;
  123. // Created from a IMAGE_IMPORT_DESCRIPTOR
  124. TJclPeImportLibItem = class(TJclPeImageBaseList)
  125. private
  126. FImportDescriptor: Pointer;
  127. FImportDirectoryIndex: Integer;
  128. FImportKind: TJclPeImportKind;
  129. FLastSortType: TJclPeImportSort;
  130. FLastSortDescending: Boolean;
  131. FName: string;
  132. FSorted: Boolean;
  133. FUseRVA: Boolean;
  134. FTotalResolveCheck: TJclPeResolveCheck;
  135. FThunk: Pointer;
  136. FThunkData: Pointer;
  137. function GetCount: Integer;
  138. function GetFileName: TFileName;
  139. function GetItems(Index: TJclListSize): TJclPeImportFuncItem;
  140. function GetName: string;
  141. function GetThunkData32: PImageThunkData32;
  142. function GetThunkData64: PImageThunkData64;
  143. protected
  144. procedure CheckImports(ExportImage: TJclPeImage);
  145. procedure CreateList;
  146. procedure SetImportDirectoryIndex(Value: Integer);
  147. procedure SetImportKind(Value: TJclPeImportKind);
  148. procedure SetSorted(Value: Boolean);
  149. procedure SetThunk(Value: Pointer);
  150. public
  151. constructor Create(AImage: TJclPeImage; AImportDescriptor: Pointer;
  152. AImportKind: TJclPeImportKind; const AName: string; AThunk: Pointer; AUseRVA: Boolean = True);
  153. procedure SortList(SortType: TJclPeImportSort; Descending: Boolean = False);
  154. property Count: Integer read GetCount;
  155. property FileName: TFileName read GetFileName;
  156. property ImportDescriptor: Pointer read FImportDescriptor;
  157. property ImportDirectoryIndex: Integer read FImportDirectoryIndex;
  158. property ImportKind: TJclPeImportKind read FImportKind;
  159. property Items[Index: TJclListSize]: TJclPeImportFuncItem read GetItems; default;
  160. property Name: string read GetName;
  161. property OriginalName: string read FName;
  162. // use the following properties
  163. // property ThunkData: PImageThunkData
  164. property ThunkData32: PImageThunkData32 read GetThunkData32;
  165. property ThunkData64: PImageThunkData64 read GetThunkData64;
  166. property TotalResolveCheck: TJclPeResolveCheck read FTotalResolveCheck;
  167. end;
  168. TJclPeImportList = class(TJclPeImageBaseList)
  169. private
  170. FAllItemsList: TList;
  171. FFilterModuleName: string;
  172. FLastAllSortType: TJclPeImportSort;
  173. FLastAllSortDescending: Boolean;
  174. FLinkerProducer: TJclPeLinkerProducer;
  175. FParallelImportTable: array of Pointer;
  176. FUniqueNamesList: TStringList;
  177. function GetAllItemCount: Integer;
  178. function GetAllItems(Index: Integer): TJclPeImportFuncItem;
  179. function GetItems(Index: TJclListSize): TJclPeImportLibItem;
  180. function GetUniqueLibItemCount: Integer;
  181. function GetUniqueLibItems(Index: Integer): TJclPeImportLibItem;
  182. function GetUniqueLibNames(Index: Integer): string;
  183. function GetUniqueLibItemFromName(const Name: string): TJclPeImportLibItem;
  184. procedure SetFilterModuleName(const Value: string);
  185. protected
  186. procedure CreateList;
  187. procedure RefreshAllItems;
  188. public
  189. constructor Create(AImage: TJclPeImage);
  190. destructor Destroy; override;
  191. procedure CheckImports(PeImageCache: TJclPeImagesCache = nil);
  192. function MakeBorlandImportTableForMappedImage: Boolean;
  193. function SmartFindName(const CompareName, LibName: string; Options: TJclSmartCompOptions = []): TJclPeImportFuncItem;
  194. procedure SortAllItemsList(SortType: TJclPeImportSort; Descending: Boolean = False);
  195. procedure SortList(SortType: TJclPeImportLibSort);
  196. procedure TryGetNamesForOrdinalImports;
  197. property AllItems[Index: Integer]: TJclPeImportFuncItem read GetAllItems;
  198. property AllItemCount: Integer read GetAllItemCount;
  199. property FilterModuleName: string read FFilterModuleName write SetFilterModuleName;
  200. property Items[Index: TJclListSize]: TJclPeImportLibItem read GetItems; default;
  201. property LinkerProducer: TJclPeLinkerProducer read FLinkerProducer;
  202. property UniqueLibItemCount: Integer read GetUniqueLibItemCount;
  203. property UniqueLibItemFromName[const Name: string]: TJclPeImportLibItem read GetUniqueLibItemFromName;
  204. property UniqueLibItems[Index: Integer]: TJclPeImportLibItem read GetUniqueLibItems;
  205. property UniqueLibNames[Index: Integer]: string read GetUniqueLibNames;
  206. end;
  207. // Export section related classes
  208. TJclPeExportSort = (esName, esOrdinal, esHint, esAddress, esForwarded, esAddrOrFwd, esSection);
  209. TJclPeExportFuncList = class;
  210. // Created from a IMAGE_EXPORT_DIRECTORY
  211. TJclPeExportFuncItem = class(TObject)
  212. private
  213. FAddress: DWORD;
  214. FExportList: TJclPeExportFuncList;
  215. FForwardedName: string;
  216. FForwardedDotPos: string;
  217. FHint: Word;
  218. FName: string;
  219. FOrdinal: Word;
  220. FResolveCheck: TJclPeResolveCheck;
  221. function GetAddressOrForwardStr: string;
  222. function GetForwardedFuncName: string;
  223. function GetForwardedLibName: string;
  224. function GetForwardedFuncOrdinal: DWORD;
  225. function GetIsExportedVariable: Boolean;
  226. function GetIsForwarded: Boolean;
  227. function GetSectionName: string;
  228. function GetMappedAddress: Pointer;
  229. protected
  230. procedure SetResolveCheck(Value: TJclPeResolveCheck);
  231. public
  232. constructor Create(AExportList: TJclPeExportFuncList; const AName, AForwardedName: string;
  233. AAddress: DWORD; AHint: Word; AOrdinal: Word; AResolveCheck: TJclPeResolveCheck);
  234. property Address: DWORD read FAddress;
  235. property AddressOrForwardStr: string read GetAddressOrForwardStr;
  236. property IsExportedVariable: Boolean read GetIsExportedVariable;
  237. property IsForwarded: Boolean read GetIsForwarded;
  238. property ForwardedName: string read FForwardedName;
  239. property ForwardedLibName: string read GetForwardedLibName;
  240. property ForwardedFuncOrdinal: DWORD read GetForwardedFuncOrdinal;
  241. property ForwardedFuncName: string read GetForwardedFuncName;
  242. property Hint: Word read FHint;
  243. property MappedAddress: Pointer read GetMappedAddress;
  244. property Name: string read FName;
  245. property Ordinal: Word read FOrdinal;
  246. property ResolveCheck: TJclPeResolveCheck read FResolveCheck;
  247. property SectionName: string read GetSectionName;
  248. end;
  249. TJclPeExportFuncList = class(TJclPeImageBaseList)
  250. private
  251. FAnyForwards: Boolean;
  252. FBase: DWORD;
  253. FExportDir: PImageExportDirectory;
  254. FForwardedLibsList: TStringList;
  255. FFunctionCount: DWORD;
  256. FLastSortType: TJclPeExportSort;
  257. FLastSortDescending: Boolean;
  258. FSorted: Boolean;
  259. FTotalResolveCheck: TJclPeResolveCheck;
  260. function GetForwardedLibsList: TStrings;
  261. function GetItems(Index: TJclListSize): TJclPeExportFuncItem;
  262. function GetItemFromAddress(Address: DWORD): TJclPeExportFuncItem;
  263. function GetItemFromOrdinal(Ordinal: DWORD): TJclPeExportFuncItem;
  264. function GetItemFromName(const Name: string): TJclPeExportFuncItem;
  265. function GetName: string;
  266. protected
  267. function CanPerformFastNameSearch: Boolean;
  268. procedure CreateList;
  269. property LastSortType: TJclPeExportSort read FLastSortType;
  270. property LastSortDescending: Boolean read FLastSortDescending;
  271. property Sorted: Boolean read FSorted;
  272. public
  273. constructor Create(AImage: TJclPeImage);
  274. destructor Destroy; override;
  275. procedure CheckForwards(PeImageCache: TJclPeImagesCache = nil);
  276. class function ItemName(Item: TJclPeExportFuncItem): string;
  277. function OrdinalValid(Ordinal: DWORD): Boolean;
  278. procedure PrepareForFastNameSearch;
  279. function SmartFindName(const CompareName: string; Options: TJclSmartCompOptions = []): TJclPeExportFuncItem;
  280. procedure SortList(SortType: TJclPeExportSort; Descending: Boolean = False);
  281. property AnyForwards: Boolean read FAnyForwards;
  282. property Base: DWORD read FBase;
  283. property ExportDir: PImageExportDirectory read FExportDir;
  284. property ForwardedLibsList: TStrings read GetForwardedLibsList;
  285. property FunctionCount: DWORD read FFunctionCount;
  286. property Items[Index: TJclListSize]: TJclPeExportFuncItem read GetItems; default;
  287. property ItemFromAddress[Address: DWORD]: TJclPeExportFuncItem read GetItemFromAddress;
  288. property ItemFromName[const Name: string]: TJclPeExportFuncItem read GetItemFromName;
  289. property ItemFromOrdinal[Ordinal: DWORD]: TJclPeExportFuncItem read GetItemFromOrdinal;
  290. property Name: string read GetName;
  291. property TotalResolveCheck: TJclPeResolveCheck read FTotalResolveCheck;
  292. end;
  293. // Resource section related classes
  294. TJclPeResourceKind = (
  295. rtUnknown0,
  296. rtCursorEntry,
  297. rtBitmap,
  298. rtIconEntry,
  299. rtMenu,
  300. rtDialog,
  301. rtString,
  302. rtFontDir,
  303. rtFont,
  304. rtAccelerators,
  305. rtRCData,
  306. rtMessageTable,
  307. rtCursor,
  308. rtUnknown13,
  309. rtIcon,
  310. rtUnknown15,
  311. rtVersion,
  312. rtDlgInclude,
  313. rtUnknown18,
  314. rtPlugPlay,
  315. rtVxd,
  316. rtAniCursor,
  317. rtAniIcon,
  318. rtHmtl,
  319. rtManifest,
  320. rtUserDefined);
  321. TJclPeResourceList = class;
  322. TJclPeResourceItem = class;
  323. TJclPeResourceRawStream = class(TCustomMemoryStream)
  324. public
  325. constructor Create(AResourceItem: TJclPeResourceItem);
  326. function Write(const Buffer; Count: Longint): Longint; override;
  327. end;
  328. TJclPeResourceItem = class(TObject)
  329. private
  330. FEntry: PImageResourceDirectoryEntry;
  331. FImage: TJclPeImage;
  332. FList: TJclPeResourceList;
  333. FLevel: Byte;
  334. FParentItem: TJclPeResourceItem;
  335. FNameCache: string;
  336. function GetDataEntry: PImageResourceDataEntry;
  337. function GetIsDirectory: Boolean;
  338. function GetIsName: Boolean;
  339. function GetLangID: LANGID;
  340. function GetList: TJclPeResourceList;
  341. function GetName: string;
  342. function GetParameterName: string;
  343. function GetRawEntryData: Pointer;
  344. function GetRawEntryDataSize: Integer;
  345. function GetResourceType: TJclPeResourceKind;
  346. function GetResourceTypeStr: string;
  347. protected
  348. function OffsetToRawData(Ofs: DWORD): TJclAddr;
  349. function Level1Item: TJclPeResourceItem;
  350. function SubDirData: PImageResourceDirectory;
  351. public
  352. constructor Create(AImage: TJclPeImage; AParentItem: TJclPeResourceItem;
  353. AEntry: PImageResourceDirectoryEntry);
  354. destructor Destroy; override;
  355. function CompareName(AName: PChar): Boolean;
  356. property DataEntry: PImageResourceDataEntry read GetDataEntry;
  357. property Entry: PImageResourceDirectoryEntry read FEntry;
  358. property Image: TJclPeImage read FImage;
  359. property IsDirectory: Boolean read GetIsDirectory;
  360. property IsName: Boolean read GetIsName;
  361. property LangID: LANGID read GetLangID;
  362. property List: TJclPeResourceList read GetList;
  363. property Level: Byte read FLevel;
  364. property Name: string read GetName;
  365. property ParameterName: string read GetParameterName;
  366. property ParentItem: TJclPeResourceItem read FParentItem;
  367. property RawEntryData: Pointer read GetRawEntryData;
  368. property RawEntryDataSize: Integer read GetRawEntryDataSize;
  369. property ResourceType: TJclPeResourceKind read GetResourceType;
  370. property ResourceTypeStr: string read GetResourceTypeStr;
  371. end;
  372. TJclPeResourceList = class(TJclPeImageBaseList)
  373. private
  374. FDirectory: PImageResourceDirectory;
  375. FParentItem: TJclPeResourceItem;
  376. function GetItems(Index: TJclListSize): TJclPeResourceItem;
  377. protected
  378. procedure CreateList(AParentItem: TJclPeResourceItem);
  379. public
  380. constructor Create(AImage: TJclPeImage; AParentItem: TJclPeResourceItem;
  381. ADirectory: PImageResourceDirectory);
  382. function FindName(const Name: string): TJclPeResourceItem;
  383. property Directory: PImageResourceDirectory read FDirectory;
  384. property Items[Index: TJclListSize]: TJclPeResourceItem read GetItems; default;
  385. property ParentItem: TJclPeResourceItem read FParentItem;
  386. end;
  387. TJclPeRootResourceList = class(TJclPeResourceList)
  388. private
  389. FManifestContent: TStringList;
  390. function GetManifestContent: TStrings;
  391. public
  392. destructor Destroy; override;
  393. function FindResource(ResourceType: TJclPeResourceKind;
  394. const ResourceName: string = ''): TJclPeResourceItem; overload;
  395. function FindResource(const ResourceType: PChar;
  396. const ResourceName: PChar = nil): TJclPeResourceItem; overload;
  397. function ListResourceNames(ResourceType: TJclPeResourceKind; const Strings: TStrings): Boolean;
  398. property ManifestContent: TStrings read GetManifestContent;
  399. end;
  400. // Relocation section related classes
  401. TJclPeRelocation = record
  402. Address: Word;
  403. RelocType: Byte;
  404. VirtualAddress: DWORD;
  405. end;
  406. TJclPeRelocEntry = class(TObject)
  407. private
  408. FChunk: PImageBaseRelocation;
  409. FCount: Integer;
  410. function GetRelocations(Index: Integer): TJclPeRelocation;
  411. function GetSize: DWORD;
  412. function GetVirtualAddress: DWORD;
  413. public
  414. constructor Create(AChunk: PImageBaseRelocation; ACount: Integer);
  415. property Count: Integer read FCount;
  416. property Relocations[Index: Integer]: TJclPeRelocation read GetRelocations; default;
  417. property Size: DWORD read GetSize;
  418. property VirtualAddress: DWORD read GetVirtualAddress;
  419. end;
  420. TJclPeRelocList = class(TJclPeImageBaseList)
  421. private
  422. FAllItemCount: Integer;
  423. function GetItems(Index: TJclListSize): TJclPeRelocEntry;
  424. function GetAllItems(Index: Integer): TJclPeRelocation;
  425. protected
  426. procedure CreateList;
  427. public
  428. constructor Create(AImage: TJclPeImage);
  429. property AllItems[Index: Integer]: TJclPeRelocation read GetAllItems;
  430. property AllItemCount: Integer read FAllItemCount;
  431. property Items[Index: TJclListSize]: TJclPeRelocEntry read GetItems; default;
  432. end;
  433. // Debug section related classes
  434. TJclPeDebugList = class(TJclPeImageBaseList)
  435. private
  436. function GetItems(Index: TJclListSize): TImageDebugDirectory;
  437. function IsTD32DebugInfo(DebugDir: PImageDebugDirectory): Boolean;
  438. protected
  439. procedure CreateList;
  440. public
  441. constructor Create(AImage: TJclPeImage);
  442. property Items[Index: TJclListSize]: TImageDebugDirectory read GetItems; default;
  443. end;
  444. // Certificates section related classes
  445. TJclPeCertificate = class(TObject)
  446. private
  447. FData: Pointer;
  448. FHeader: TWinCertificate;
  449. public
  450. constructor Create(AHeader: TWinCertificate; AData: Pointer);
  451. property Data: Pointer read FData;
  452. property Header: TWinCertificate read FHeader;
  453. end;
  454. TJclPeCertificateList = class(TJclPeImageBaseList)
  455. private
  456. function GetItems(Index: TJclListSize): TJclPeCertificate;
  457. protected
  458. procedure CreateList;
  459. public
  460. constructor Create(AImage: TJclPeImage);
  461. property Items[Index: TJclListSize]: TJclPeCertificate read GetItems; default;
  462. end;
  463. // Common Language Runtime section related classes
  464. TJclPeCLRHeader = class(TObject)
  465. private
  466. FHeader: TImageCor20Header;
  467. FImage: TJclPeImage;
  468. function GetVersionString: string;
  469. function GetHasMetadata: Boolean;
  470. protected
  471. procedure ReadHeader;
  472. public
  473. constructor Create(AImage: TJclPeImage);
  474. property HasMetadata: Boolean read GetHasMetadata;
  475. property Header: TImageCor20Header read FHeader;
  476. property VersionString: string read GetVersionString;
  477. property Image: TJclPeImage read FImage;
  478. end;
  479. // PE Image
  480. TJclPeHeader = (
  481. JclPeHeader_Signature,
  482. JclPeHeader_Machine,
  483. JclPeHeader_NumberOfSections,
  484. JclPeHeader_TimeDateStamp,
  485. JclPeHeader_PointerToSymbolTable,
  486. JclPeHeader_NumberOfSymbols,
  487. JclPeHeader_SizeOfOptionalHeader,
  488. JclPeHeader_Characteristics,
  489. JclPeHeader_Magic,
  490. JclPeHeader_LinkerVersion,
  491. JclPeHeader_SizeOfCode,
  492. JclPeHeader_SizeOfInitializedData,
  493. JclPeHeader_SizeOfUninitializedData,
  494. JclPeHeader_AddressOfEntryPoint,
  495. JclPeHeader_BaseOfCode,
  496. JclPeHeader_BaseOfData,
  497. JclPeHeader_ImageBase,
  498. JclPeHeader_SectionAlignment,
  499. JclPeHeader_FileAlignment,
  500. JclPeHeader_OperatingSystemVersion,
  501. JclPeHeader_ImageVersion,
  502. JclPeHeader_SubsystemVersion,
  503. JclPeHeader_Win32VersionValue,
  504. JclPeHeader_SizeOfImage,
  505. JclPeHeader_SizeOfHeaders,
  506. JclPeHeader_CheckSum,
  507. JclPeHeader_Subsystem,
  508. JclPeHeader_DllCharacteristics,
  509. JclPeHeader_SizeOfStackReserve,
  510. JclPeHeader_SizeOfStackCommit,
  511. JclPeHeader_SizeOfHeapReserve,
  512. JclPeHeader_SizeOfHeapCommit,
  513. JclPeHeader_LoaderFlags,
  514. JclPeHeader_NumberOfRvaAndSizes);
  515. TJclLoadConfig = (
  516. JclLoadConfig_Characteristics, { TODO : rename to Size? }
  517. JclLoadConfig_TimeDateStamp,
  518. JclLoadConfig_Version,
  519. JclLoadConfig_GlobalFlagsClear,
  520. JclLoadConfig_GlobalFlagsSet,
  521. JclLoadConfig_CriticalSectionDefaultTimeout,
  522. JclLoadConfig_DeCommitFreeBlockThreshold,
  523. JclLoadConfig_DeCommitTotalFreeThreshold,
  524. JclLoadConfig_LockPrefixTable,
  525. JclLoadConfig_MaximumAllocationSize,
  526. JclLoadConfig_VirtualMemoryThreshold,
  527. JclLoadConfig_ProcessHeapFlags,
  528. JclLoadConfig_ProcessAffinityMask,
  529. JclLoadConfig_CSDVersion,
  530. JclLoadConfig_Reserved1,
  531. JclLoadConfig_EditList,
  532. JclLoadConfig_Reserved { TODO : extend to the new fields? }
  533. );
  534. TJclPeFileProperties = record
  535. Size: DWORD;
  536. CreationTime: TDateTime;
  537. LastAccessTime: TDateTime;
  538. LastWriteTime: TDateTime;
  539. Attributes: Integer;
  540. end;
  541. TJclPeImageStatus = (stNotLoaded, stOk, stNotPE, stNotSupported, stNotFound, stError);
  542. TJclPeTarget = (taUnknown, taWin32, taWin64);
  543. TJclPeImage = class(TObject)
  544. private
  545. FAttachedImage: Boolean;
  546. FCertificateList: TJclPeCertificateList;
  547. FCLRHeader: TJclPeCLRHeader;
  548. FDebugList: TJclPeDebugList;
  549. FFileName: TFileName;
  550. FImageSections: TStringList;
  551. FLoadedImage: TLoadedImage;
  552. FExportList: TJclPeExportFuncList;
  553. FImportList: TJclPeImportList;
  554. FNoExceptions: Boolean;
  555. FReadOnlyAccess: Boolean;
  556. FRelocationList: TJclPeRelocList;
  557. FResourceList: TJclPeRootResourceList;
  558. FResourceVA: TJclAddr;
  559. FStatus: TJclPeImageStatus;
  560. FTarget: TJclPeTarget;
  561. FVersionInfo: TJclFileVersionInfo;
  562. FStringTable: TStringList;
  563. function GetCertificateList: TJclPeCertificateList;
  564. function GetCLRHeader: TJclPeCLRHeader;
  565. function GetDebugList: TJclPeDebugList;
  566. function GetDescription: string;
  567. function GetDirectories(Directory: Word): TImageDataDirectory;
  568. function GetDirectoryExists(Directory: Word): Boolean;
  569. function GetExportList: TJclPeExportFuncList;
  570. function GetFileProperties: TJclPeFileProperties;
  571. function GetImageSectionCount: Integer;
  572. function GetImageSectionHeaders(Index: Integer): TImageSectionHeader;
  573. function GetImageSectionNames(Index: Integer): string;
  574. function GetImageSectionNameFromRva(const Rva: DWORD): string;
  575. function GetImportList: TJclPeImportList;
  576. function GetHeaderValues(Index: TJclPeHeader): string;
  577. function GetLoadConfigValues(Index: TJclLoadConfig): string;
  578. function GetMappedAddress: TJclAddr;
  579. function GetOptionalHeader32: TImageOptionalHeader32;
  580. function GetOptionalHeader64: TImageOptionalHeader64;
  581. function GetRelocationList: TJclPeRelocList;
  582. function GetResourceList: TJclPeRootResourceList;
  583. function GetUnusedHeaderBytes: TImageDataDirectory;
  584. function GetVersionInfo: TJclFileVersionInfo;
  585. function GetVersionInfoAvailable: Boolean;
  586. procedure ReadImageSections;
  587. procedure ReadStringTable;
  588. procedure SetFileName(const Value: TFileName);
  589. function GetStringTableCount: Integer;
  590. function GetStringTableItem(Index: Integer): string;
  591. function GetImageSectionFullNames(Index: Integer): string;
  592. protected
  593. procedure AfterOpen; dynamic;
  594. procedure CheckNotAttached;
  595. procedure Clear; dynamic;
  596. function ExpandModuleName(const ModuleName: string): TFileName;
  597. procedure RaiseStatusException;
  598. function ResourceItemCreate(AEntry: PImageResourceDirectoryEntry;
  599. AParentItem: TJclPeResourceItem): TJclPeResourceItem; virtual;
  600. function ResourceListCreate(ADirectory: PImageResourceDirectory;
  601. AParentItem: TJclPeResourceItem): TJclPeResourceList; virtual;
  602. property NoExceptions: Boolean read FNoExceptions;
  603. public
  604. constructor Create(ANoExceptions: Boolean = False); virtual;
  605. destructor Destroy; override;
  606. procedure AttachLoadedModule(const Handle: HMODULE);
  607. function CalculateCheckSum: DWORD;
  608. function DirectoryEntryToData(Directory: Word): Pointer;
  609. function GetSectionHeader(const SectionName: string; out Header: PImageSectionHeader): Boolean;
  610. function GetSectionName(Header: PImageSectionHeader): string;
  611. function GetNameInStringTable(Offset: ULONG): string;
  612. function IsBrokenFormat: Boolean;
  613. function IsCLR: Boolean;
  614. function IsSystemImage: Boolean;
  615. // RVA are always DWORD
  616. function RawToVa(Raw: DWORD): Pointer; overload;
  617. function RvaToSection(Rva: DWORD): PImageSectionHeader; overload;
  618. function RvaToVa(Rva: DWORD): Pointer; overload;
  619. function ImageAddressToRva(Address: DWORD): DWORD;
  620. function StatusOK: Boolean;
  621. procedure TryGetNamesForOrdinalImports;
  622. function VerifyCheckSum: Boolean;
  623. class function DebugTypeNames(DebugType: DWORD): string;
  624. class function DirectoryNames(Directory: Word): string;
  625. class function ExpandBySearchPath(const ModuleName, BasePath: string): TFileName;
  626. class function HeaderNames(Index: TJclPeHeader): string;
  627. class function LoadConfigNames(Index: TJclLoadConfig): string;
  628. class function ShortSectionInfo(Characteristics: DWORD): string;
  629. class function DateTimeToStamp(const DateTime: TDateTime): DWORD;
  630. class function StampToDateTime(TimeDateStamp: DWORD): TDateTime;
  631. property AttachedImage: Boolean read FAttachedImage;
  632. property CertificateList: TJclPeCertificateList read GetCertificateList;
  633. property CLRHeader: TJclPeCLRHeader read GetCLRHeader;
  634. property DebugList: TJclPeDebugList read GetDebugList;
  635. property Description: string read GetDescription;
  636. property Directories[Directory: Word]: TImageDataDirectory read GetDirectories;
  637. property DirectoryExists[Directory: Word]: Boolean read GetDirectoryExists;
  638. property ExportList: TJclPeExportFuncList read GetExportList;
  639. property FileName: TFileName read FFileName write SetFileName;
  640. property FileProperties: TJclPeFileProperties read GetFileProperties;
  641. property HeaderValues[Index: TJclPeHeader]: string read GetHeaderValues;
  642. property ImageSectionCount: Integer read GetImageSectionCount;
  643. property ImageSectionHeaders[Index: Integer]: TImageSectionHeader read GetImageSectionHeaders;
  644. property ImageSectionNames[Index: Integer]: string read GetImageSectionNames;
  645. property ImageSectionFullNames[Index: Integer]: string read GetImageSectionFullNames;
  646. property ImageSectionNameFromRva[const Rva: DWORD]: string read GetImageSectionNameFromRva;
  647. property ImportList: TJclPeImportList read GetImportList;
  648. property LoadConfigValues[Index: TJclLoadConfig]: string read GetLoadConfigValues;
  649. property LoadedImage: TLoadedImage read FLoadedImage;
  650. property MappedAddress: TJclAddr read GetMappedAddress;
  651. property StringTableCount: Integer read GetStringTableCount;
  652. property StringTable[Index: Integer]: string read GetStringTableItem;
  653. // use the following properties
  654. // property OptionalHeader: TImageOptionalHeader
  655. property OptionalHeader32: TImageOptionalHeader32 read GetOptionalHeader32;
  656. property OptionalHeader64: TImageOptionalHeader64 read GetOptionalHeader64;
  657. property ReadOnlyAccess: Boolean read FReadOnlyAccess write FReadOnlyAccess;
  658. property RelocationList: TJclPeRelocList read GetRelocationList;
  659. property ResourceVA: TJclAddr read FResourceVA;
  660. property ResourceList: TJclPeRootResourceList read GetResourceList;
  661. property Status: TJclPeImageStatus read FStatus;
  662. property Target: TJclPeTarget read FTarget;
  663. property UnusedHeaderBytes: TImageDataDirectory read GetUnusedHeaderBytes;
  664. property VersionInfo: TJclFileVersionInfo read GetVersionInfo;
  665. property VersionInfoAvailable: Boolean read GetVersionInfoAvailable;
  666. end;
  667. {$IFDEF BORLAND}
  668. TJclPeBorImage = class;
  669. TJclPeBorImagesCache = class(TJclPeImagesCache)
  670. private
  671. function GetImages(const FileName: TFileName): TJclPeBorImage;
  672. protected
  673. function GetPeImageClass: TJclPeImageClass; override;
  674. public
  675. property Images[const FileName: TFileName]: TJclPeBorImage read GetImages; default;
  676. end;
  677. // Borland Delphi PE Image specific information
  678. TJclPePackageInfo = class(TObject)
  679. private
  680. FAvailable: Boolean;
  681. FContains: TStringList;
  682. FDcpName: string;
  683. FRequires: TStringList;
  684. FFlags: Integer;
  685. FDescription: string;
  686. FEnsureExtension: Boolean;
  687. FSorted: Boolean;
  688. function GetContains: TStrings;
  689. function GetContainsCount: Integer;
  690. function GetContainsFlags(Index: Integer): Byte;
  691. function GetContainsNames(Index: Integer): string;
  692. function GetRequires: TStrings;
  693. function GetRequiresCount: Integer;
  694. function GetRequiresNames(Index: Integer): string;
  695. protected
  696. procedure ReadPackageInfo(ALibHandle: THandle);
  697. procedure SetDcpName(const Value: string);
  698. public
  699. constructor Create(ALibHandle: THandle);
  700. destructor Destroy; override;
  701. class function PackageModuleTypeToString(Flags: Cardinal): string;
  702. class function PackageOptionsToString(Flags: Cardinal): string;
  703. class function ProducerToString(Flags: Cardinal): string;
  704. class function UnitInfoFlagsToString(UnitFlags: Byte): string;
  705. property Available: Boolean read FAvailable;
  706. property Contains: TStrings read GetContains;
  707. property ContainsCount: Integer read GetContainsCount;
  708. property ContainsNames[Index: Integer]: string read GetContainsNames;
  709. property ContainsFlags[Index: Integer]: Byte read GetContainsFlags;
  710. property Description: string read FDescription;
  711. property DcpName: string read FDcpName;
  712. property EnsureExtension: Boolean read FEnsureExtension write FEnsureExtension;
  713. property Flags: Integer read FFlags;
  714. property Requires: TStrings read GetRequires;
  715. property RequiresCount: Integer read GetRequiresCount;
  716. property RequiresNames[Index: Integer]: string read GetRequiresNames;
  717. property Sorted: Boolean read FSorted write FSorted;
  718. end;
  719. TJclPeBorForm = class(TObject)
  720. private
  721. FFormFlags: TFilerFlags;
  722. FFormClassName: string;
  723. FFormObjectName: string;
  724. FFormPosition: Integer;
  725. FResItem: TJclPeResourceItem;
  726. function GetDisplayName: string;
  727. public
  728. constructor Create(AResItem: TJclPeResourceItem; AFormFlags: TFilerFlags;
  729. AFormPosition: Integer; const AFormClassName, AFormObjectName: string);
  730. procedure ConvertFormToText(const Stream: TStream); overload;
  731. procedure ConvertFormToText(const Strings: TStrings); overload;
  732. property FormClassName: string read FFormClassName;
  733. property FormFlags: TFilerFlags read FFormFlags;
  734. property FormObjectName: string read FFormObjectName;
  735. property FormPosition: Integer read FFormPosition;
  736. property DisplayName: string read GetDisplayName;
  737. property ResItem: TJclPeResourceItem read FResItem;
  738. end;
  739. TJclPeBorImage = class(TJclPeImage)
  740. private
  741. FForms: TObjectList;
  742. FIsPackage: Boolean;
  743. FIsBorlandImage: Boolean;
  744. FLibHandle: THandle;
  745. FPackageInfo: TJclPePackageInfo;
  746. FPackageInfoSorted: Boolean;
  747. FPackageCompilerVersion: Integer;
  748. function GetFormCount: Integer;
  749. function GetForms(Index: Integer): TJclPeBorForm;
  750. function GetFormFromName(const FormClassName: string): TJclPeBorForm;
  751. function GetLibHandle: THandle;
  752. function GetPackageCompilerVersion: Integer;
  753. function GetPackageInfo: TJclPePackageInfo;
  754. protected
  755. procedure AfterOpen; override;
  756. procedure Clear; override;
  757. procedure CreateFormsList;
  758. public
  759. constructor Create(ANoExceptions: Boolean = False); override;
  760. destructor Destroy; override;
  761. function DependedPackages(List: TStrings; FullPathName, Descriptions: Boolean): Boolean;
  762. function FreeLibHandle: Boolean;
  763. property Forms[Index: Integer]: TJclPeBorForm read GetForms;
  764. property FormCount: Integer read GetFormCount;
  765. property FormFromName[const FormClassName: string]: TJclPeBorForm read GetFormFromName;
  766. property IsBorlandImage: Boolean read FIsBorlandImage;
  767. property IsPackage: Boolean read FIsPackage;
  768. property LibHandle: THandle read GetLibHandle;
  769. property PackageCompilerVersion: Integer read GetPackageCompilerVersion;
  770. property PackageInfo: TJclPePackageInfo read GetPackageInfo;
  771. property PackageInfoSorted: Boolean read FPackageInfoSorted write FPackageInfoSorted;
  772. end;
  773. {$ENDIF BORLAND}
  774. // Threaded function search
  775. TJclPeNameSearchOption = (seImports, seDelayImports, seBoundImports, seExports);
  776. TJclPeNameSearchOptions = set of TJclPeNameSearchOption;
  777. TJclPeNameSearchNotifyEvent = procedure (Sender: TObject; PeImage: TJclPeImage;
  778. var Process: Boolean) of object;
  779. TJclPeNameSearchFoundEvent = procedure (Sender: TObject; const FileName: TFileName;
  780. const FunctionName: string; Option: TJclPeNameSearchOption) of object;
  781. TJclPeNameSearch = class(TThread)
  782. private
  783. F_FileName: TFileName;
  784. F_FunctionName: string;
  785. F_Option: TJclPeNameSearchOption;
  786. F_Process: Boolean;
  787. FFunctionName: string;
  788. FOptions: TJclPeNameSearchOptions;
  789. FPath: string;
  790. FPeImage: TJclPeImage;
  791. FOnFound: TJclPeNameSearchFoundEvent;
  792. FOnProcessFile: TJclPeNameSearchNotifyEvent;
  793. protected
  794. function CompareName(const FunctionName, ComparedName: string): Boolean; virtual;
  795. procedure DoFound;
  796. procedure DoProcessFile;
  797. procedure Execute; override;
  798. public
  799. constructor Create(const FunctionName, Path: string; Options: TJclPeNameSearchOptions = [seImports, seExports]);
  800. procedure Start;
  801. property OnFound: TJclPeNameSearchFoundEvent read FOnFound write FOnFound;
  802. property OnProcessFile: TJclPeNameSearchNotifyEvent read FOnProcessFile write FOnProcessFile;
  803. end;
  804. // PE Image miscellaneous functions
  805. type
  806. TJclRebaseImageInfo32 = record
  807. OldImageSize: DWORD;
  808. OldImageBase: TJclAddr32;
  809. NewImageSize: DWORD;
  810. NewImageBase: TJclAddr32;
  811. end;
  812. TJclRebaseImageInfo64 = record
  813. OldImageSize: DWORD;
  814. OldImageBase: TJclAddr64;
  815. NewImageSize: DWORD;
  816. NewImageBase: TJclAddr64;
  817. end;
  818. // renamed
  819. // TJclRebaseImageInfo = TJclRebaseImageInfo32;
  820. { Image validity }
  821. function IsValidPeFile(const FileName: TFileName): Boolean;
  822. // use PeGetNtHeaders32 for backward compatibility
  823. // function PeGetNtHeaders(const FileName: TFileName; out NtHeaders: TImageNtHeaders): Boolean;
  824. function PeGetNtHeaders32(const FileName: TFileName; out NtHeaders: TImageNtHeaders32): Boolean;
  825. function PeGetNtHeaders64(const FileName: TFileName; out NtHeaders: TImageNtHeaders64): Boolean;
  826. { Image modifications }
  827. function PeCreateNameHintTable(const FileName: TFileName): Boolean;
  828. // use PeRebaseImage32
  829. //function PeRebaseImage(const ImageName: TFileName; NewBase: DWORD = 0; TimeStamp: DWORD = 0;
  830. // MaxNewSize: DWORD = 0): TJclRebaseImageInfo;
  831. function PeRebaseImage32(const ImageName: TFileName; NewBase: TJclAddr32 = 0; TimeStamp: DWORD = 0;
  832. MaxNewSize: DWORD = 0): TJclRebaseImageInfo32;
  833. function PeRebaseImage64(const ImageName: TFileName; NewBase: TJclAddr64 = 0; TimeStamp: DWORD = 0;
  834. MaxNewSize: DWORD = 0): TJclRebaseImageInfo64;
  835. function PeUpdateLinkerTimeStamp(const FileName: TFileName; const Time: TDateTime): Boolean;
  836. function PeReadLinkerTimeStamp(const FileName: TFileName): TDateTime;
  837. function PeInsertSection(const FileName: TFileName; SectionStream: TStream; SectionName: string): Boolean;
  838. { Image Checksum }
  839. function PeVerifyCheckSum(const FileName: TFileName): Boolean;
  840. function PeClearCheckSum(const FileName: TFileName): Boolean;
  841. function PeUpdateCheckSum(const FileName: TFileName): Boolean;
  842. // Various simple PE Image searching and listing routines
  843. { Exports searching }
  844. function PeDoesExportFunction(const FileName: TFileName; const FunctionName: string;
  845. Options: TJclSmartCompOptions = []): Boolean;
  846. function PeIsExportFunctionForwardedEx(const FileName: TFileName; const FunctionName: string;
  847. out ForwardedName: string; Options: TJclSmartCompOptions = []): Boolean;
  848. function PeIsExportFunctionForwarded(const FileName: TFileName; const FunctionName: string;
  849. Options: TJclSmartCompOptions = []): Boolean;
  850. { Imports searching }
  851. function PeDoesImportFunction(const FileName: TFileName; const FunctionName: string;
  852. const LibraryName: string = ''; Options: TJclSmartCompOptions = []): Boolean;
  853. function PeDoesImportLibrary(const FileName: TFileName; const LibraryName: string;
  854. Recursive: Boolean = False): Boolean;
  855. { Imports listing }
  856. function PeImportedLibraries(const FileName: TFileName; const LibrariesList: TStrings;
  857. Recursive: Boolean = False; FullPathName: Boolean = False): Boolean;
  858. function PeImportedFunctions(const FileName: TFileName; const FunctionsList: TStrings;
  859. const LibraryName: string = ''; IncludeLibNames: Boolean = False): Boolean;
  860. { Exports listing }
  861. function PeExportedFunctions(const FileName: TFileName; const FunctionsList: TStrings): Boolean;
  862. function PeExportedNames(const FileName: TFileName; const FunctionsList: TStrings): Boolean;
  863. function PeExportedVariables(const FileName: TFileName; const FunctionsList: TStrings): Boolean;
  864. { Resources listing }
  865. function PeResourceKindNames(const FileName: TFileName; ResourceType: TJclPeResourceKind;
  866. const NamesList: TStrings): Boolean;
  867. { Borland packages specific }
  868. {$IFDEF BORLAND}
  869. function PeBorFormNames(const FileName: TFileName; const NamesList: TStrings): Boolean;
  870. function PeBorDependedPackages(const FileName: TFileName; PackagesList: TStrings;
  871. FullPathName, Descriptions: Boolean): Boolean;
  872. {$ENDIF BORLAND}
  873. // Missing imports checking routines
  874. function PeFindMissingImports(const FileName: TFileName; MissingImportsList: TStrings): Boolean; overload;
  875. function PeFindMissingImports(RequiredImportsList, MissingImportsList: TStrings): Boolean; overload;
  876. function PeCreateRequiredImportList(const FileName: TFileName; RequiredImportsList: TStrings): Boolean;
  877. // Mapped or loaded image related routines
  878. // use PeMapImgNtHeaders32
  879. // function PeMapImgNtHeaders(const BaseAddress: Pointer): PImageNtHeaders;
  880. function PeMapImgNtHeaders32(const BaseAddress: Pointer): PImageNtHeaders32; overload;
  881. function PeMapImgNtHeaders32(Stream: TStream; const BasePosition: Int64; out NtHeaders32: TImageNtHeaders32): Int64; overload;
  882. function PeMapImgNtHeaders64(const BaseAddress: Pointer): PImageNtHeaders64; overload;
  883. function PeMapImgNtHeaders64(Stream: TStream; const BasePosition: Int64; out NtHeaders64: TImageNtHeaders64): Int64; overload;
  884. function PeMapImgLibraryName(const BaseAddress: Pointer): string;
  885. function PeMapImgLibraryName32(const BaseAddress: Pointer): string;
  886. function PeMapImgLibraryName64(const BaseAddress: Pointer): string;
  887. function PeMapImgSize(const BaseAddress: Pointer): DWORD; overload;
  888. function PeMapImgSize(Stream: TStream; const BasePosition: Int64): DWORD; overload;
  889. function PeMapImgSize32(const BaseAddress: Pointer): DWORD; overload;
  890. function PeMapImgSize32(Stream: TStream; const BasePosition: Int64): DWORD; overload;
  891. function PeMapImgSize64(const BaseAddress: Pointer): DWORD; overload;
  892. function PeMapImgSize64(Stream: TStream; const BasePosition: Int64): DWORD; overload;
  893. function PeMapImgTarget(const BaseAddress: Pointer): TJclPeTarget; overload;
  894. function PeMapImgTarget(Stream: TStream; const BasePosition: Int64): TJclPeTarget; overload;
  895. type
  896. TImageSectionHeaderArray = array of TImageSectionHeader;
  897. // use PeMapImgSections32
  898. // function PeMapImgSections(NtHeaders: PImageNtHeaders): PImageSectionHeader;
  899. function PeMapImgSections32(NtHeaders: PImageNtHeaders32): PImageSectionHeader; overload;
  900. function PeMapImgSections32(Stream: TStream; const NtHeaders32Position: Int64; const NtHeaders32: TImageNtHeaders32;
  901. out ImageSectionHeaders: TImageSectionHeaderArray): Int64; overload;
  902. function PeMapImgSections64(NtHeaders: PImageNtHeaders64): PImageSectionHeader; overload;
  903. function PeMapImgSections64(Stream: TStream; const NtHeaders64Position: Int64; const NtHeaders64: TImageNtHeaders64;
  904. out ImageSectionHeaders: TImageSectionHeaderArray): Int64; overload;
  905. // use PeMapImgFindSection32
  906. // function PeMapImgFindSection(NtHeaders: PImageNtHeaders;
  907. // const SectionName: string): PImageSectionHeader;
  908. function PeMapImgFindSection32(NtHeaders: PImageNtHeaders32;
  909. const SectionName: string): PImageSectionHeader;
  910. function PeMapImgFindSection64(NtHeaders: PImageNtHeaders64;
  911. const SectionName: string): PImageSectionHeader;
  912. function PeMapImgFindSection(const ImageSectionHeaders: TImageSectionHeaderArray;
  913. const SectionName: string): SizeInt;
  914. function PeMapImgFindSectionFromModule(const BaseAddress: Pointer;
  915. const SectionName: string): PImageSectionHeader;
  916. function PeMapImgExportedVariables(const Module: HMODULE; const VariablesList: TStrings): Boolean;
  917. function PeMapImgResolvePackageThunk(Address: Pointer): Pointer;
  918. function PeMapFindResource(const Module: HMODULE; const ResourceType: PChar;
  919. const ResourceName: string): Pointer;
  920. type
  921. TJclPeSectionStream = class(TCustomMemoryStream)
  922. private
  923. FInstance: HMODULE;
  924. FSectionHeader: TImageSectionHeader;
  925. procedure Initialize(Instance: HMODULE; const ASectionName: string);
  926. public
  927. constructor Create(Instance: HMODULE; const ASectionName: string);
  928. function Write(const Buffer; Count: Longint): Longint; override;
  929. property Instance: HMODULE read FInstance;
  930. property SectionHeader: TImageSectionHeader read FSectionHeader;
  931. end;
  932. // API hooking classes
  933. type
  934. TJclPeMapImgHookItem = class(TObject)
  935. private
  936. FBaseAddress: Pointer;
  937. FFunctionName: string;
  938. FModuleName: string;
  939. FNewAddress: Pointer;
  940. FOriginalAddress: Pointer;
  941. FList: TObjectList;
  942. protected
  943. function InternalUnhook: Boolean;
  944. public
  945. constructor Create(AList: TObjectList; const AFunctionName: string;
  946. const AModuleName: string; ABaseAddress, ANewAddress, AOriginalAddress: Pointer);
  947. destructor Destroy; override;
  948. function Unhook: Boolean;
  949. property BaseAddress: Pointer read FBaseAddress;
  950. property FunctionName: string read FFunctionName;
  951. property ModuleName: string read FModuleName;
  952. property NewAddress: Pointer read FNewAddress;
  953. property OriginalAddress: Pointer read FOriginalAddress;
  954. end;
  955. TJclPeMapImgHooks = class(TObjectList)
  956. private
  957. function GetItems(Index: TJclListSize): TJclPeMapImgHookItem;
  958. function GetItemFromOriginalAddress(OriginalAddress: Pointer): TJclPeMapImgHookItem;
  959. function GetItemFromNewAddress(NewAddress: Pointer): TJclPeMapImgHookItem;
  960. public
  961. function HookImport(Base: Pointer; const ModuleName: string;
  962. const FunctionName: string; NewAddress: Pointer; var OriginalAddress: Pointer): Boolean;
  963. class function IsWin9xDebugThunk(P: Pointer): Boolean;
  964. class function ReplaceImport(Base: Pointer; const ModuleName: string; FromProc, ToProc: Pointer): Boolean;
  965. class function SystemBase: Pointer;
  966. procedure UnhookAll;
  967. function UnhookByNewAddress(NewAddress: Pointer): Boolean;
  968. procedure UnhookByBaseAddress(BaseAddress: Pointer);
  969. property Items[Index: TJclListSize]: TJclPeMapImgHookItem read GetItems; default;
  970. property ItemFromOriginalAddress[OriginalAddress: Pointer]: TJclPeMapImgHookItem read GetItemFromOriginalAddress;
  971. property ItemFromNewAddress[NewAddress: Pointer]: TJclPeMapImgHookItem read GetItemFromNewAddress;
  972. end;
  973. // Image access under a debbuger
  974. function PeDbgImgNtHeaders32(ProcessHandle: THandle; BaseAddress: TJclAddr32;
  975. var NtHeaders: TImageNtHeaders32): Boolean;
  976. // TODO 64 bit version
  977. //function PeDbgImgNtHeaders64(ProcessHandle: THandle; BaseAddress: TJclAddr64;
  978. // var NtHeaders: TImageNtHeaders64): Boolean;
  979. function PeDbgImgLibraryName32(ProcessHandle: THandle; BaseAddress: TJclAddr32;
  980. var Name: string): Boolean;
  981. //function PeDbgImgLibraryName64(ProcessHandle: THandle; BaseAddress: TJclAddr64;
  982. // var Name: string): Boolean;
  983. // Borland BPL packages name unmangling
  984. type
  985. TJclBorUmSymbolKind = (skData, skFunction, skConstructor, skDestructor, skRTTI, skVTable);
  986. TJclBorUmSymbolModifier = (smQualified, smLinkProc);
  987. TJclBorUmSymbolModifiers = set of TJclBorUmSymbolModifier;
  988. TJclBorUmDescription = record
  989. Kind: TJclBorUmSymbolKind;
  990. Modifiers: TJclBorUmSymbolModifiers;
  991. end;
  992. TJclBorUmResult = (urOk, urNotMangled, urMicrosoft, urError);
  993. TJclPeUmResult = (umNotMangled, umBorland, umMicrosoft);
  994. function PeBorUnmangleName(const Name: string; out Unmangled: string;
  995. out Description: TJclBorUmDescription; out BasePos: Integer): TJclBorUmResult; overload;
  996. function PeBorUnmangleName(const Name: string; out Unmangled: string;
  997. out Description: TJclBorUmDescription): TJclBorUmResult; overload;
  998. function PeBorUnmangleName(const Name: string; out Unmangled: string): TJclBorUmResult; overload;
  999. function PeBorUnmangleName(const Name: string): string; overload;
  1000. function PeIsNameMangled(const Name: string): TJclPeUmResult;
  1001. function UndecorateSymbolName(const DecoratedName: string; out UnMangled: string; Flags: DWORD): Boolean;
  1002. function PeUnmangleName(const Name: string; out Unmangled: string): TJclPeUmResult;
  1003. {$IFDEF UNITVERSIONING}
  1004. const
  1005. UnitVersioning: TUnitVersionInfo = (
  1006. RCSfile: '$URL$';
  1007. Revision: '$Revision$';
  1008. Date: '$Date$';
  1009. LogPath: 'JCL\source\windows';
  1010. Extra: '';
  1011. Data: nil
  1012. );
  1013. {$ENDIF UNITVERSIONING}
  1014. implementation
  1015. uses
  1016. {$IFDEF HAS_UNITSCOPE}
  1017. System.RTLConsts,
  1018. System.Types, // for inlining TList.Remove
  1019. {$IFDEF HAS_UNIT_CHARACTER}
  1020. System.Character,
  1021. {$ENDIF HAS_UNIT_CHARACTER}
  1022. {$ELSE ~HAS_UNITSCOPE}
  1023. RTLConsts,
  1024. {$IFDEF HAS_UNIT_CHARACTER}
  1025. Character,
  1026. {$ENDIF HAS_UNIT_CHARACTER}
  1027. {$ENDIF ~HAS_UNITSCOPE}
  1028. JclLogic, JclResources, JclSysUtils, JclAnsiStrings, JclStrings, JclStringConversions, JclTD32;
  1029. const
  1030. MANIFESTExtension = '.manifest';
  1031. DebugSectionName = '.debug';
  1032. ReadOnlySectionName = '.rdata';
  1033. BinaryExtensionLibrary = '.dll';
  1034. {$IFDEF BORLAND}
  1035. CompilerExtensionDCP = '.dcp';
  1036. BinaryExtensionPackage = '.bpl';
  1037. PackageInfoResName = 'PACKAGEINFO';
  1038. DescriptionResName = 'DESCRIPTION';
  1039. PackageOptionsResName = 'PACKAGEOPTIONS';
  1040. DVclAlResName = 'DVCLAL';
  1041. {$ENDIF BORLAND}
  1042. // Helper routines
  1043. function AddFlagTextRes(var Text: string; const FlagText: PResStringRec; const Value, Mask: Cardinal): Boolean;
  1044. begin
  1045. Result := (Value and Mask <> 0);
  1046. if Result then
  1047. begin
  1048. if Length(Text) > 0 then
  1049. Text := Text + ', ';
  1050. Text := Text + LoadResString(FlagText);
  1051. end;
  1052. end;
  1053. function CompareResourceName(T1, T2: PChar): Boolean;
  1054. var
  1055. Long1, Long2: LongRec;
  1056. begin
  1057. {$IFDEF CPU64}
  1058. Long1 := LongRec(Int64Rec(T1).Lo);
  1059. Long2 := LongRec(Int64Rec(T2).Lo);
  1060. if (Int64Rec(T1).Hi = 0) and (Int64Rec(T2).Hi = 0) and (Long1.Hi = 0) and (Long2.Hi = 0) then
  1061. {$ENDIF CPU64}
  1062. {$IFDEF CPU32}
  1063. Long1 := LongRec(T1);
  1064. Long2 := LongRec(T2);
  1065. if (Long1.Hi = 0) or (Long2.Hi = 0) then
  1066. {$ENDIF CPU32}
  1067. Result := Long1.Lo = Long2.Lo
  1068. else
  1069. Result := (StrIComp(T1, T2) = 0);
  1070. end;
  1071. function CreatePeImage(const FileName: TFileName): TJclPeImage;
  1072. begin
  1073. Result := TJclPeImage.Create(True);
  1074. Result.FileName := FileName;
  1075. end;
  1076. function InternalImportedLibraries(const FileName: TFileName;
  1077. Recursive, FullPathName: Boolean; ExternalCache: TJclPeImagesCache): TStringList;
  1078. var
  1079. Cache: TJclPeImagesCache;
  1080. procedure ProcessLibraries(const AFileName: TFileName);
  1081. var
  1082. I: Integer;
  1083. S: TFileName;
  1084. ImportLib: TJclPeImportLibItem;
  1085. begin
  1086. with Cache[AFileName].ImportList do
  1087. for I := 0 to Count - 1 do
  1088. begin
  1089. ImportLib := Items[I];
  1090. if FullPathName then
  1091. S := ImportLib.FileName
  1092. else
  1093. S := TFileName(ImportLib.Name);
  1094. if Result.IndexOf(S) = -1 then
  1095. begin
  1096. Result.Add(S);
  1097. if Recursive then
  1098. ProcessLibraries(ImportLib.FileName);
  1099. end;
  1100. end;
  1101. end;
  1102. begin
  1103. if ExternalCache = nil then
  1104. Cache := TJclPeImagesCache.Create
  1105. else
  1106. Cache := ExternalCache;
  1107. try
  1108. Result := TStringList.Create;
  1109. try
  1110. Result.Sorted := True;
  1111. Result.Duplicates := dupIgnore;
  1112. ProcessLibraries(FileName);
  1113. except
  1114. FreeAndNil(Result);
  1115. raise;
  1116. end;
  1117. finally
  1118. if ExternalCache = nil then
  1119. Cache.Free;
  1120. end;
  1121. end;
  1122. // Smart name compare function
  1123. function PeStripFunctionAW(const FunctionName: string): string;
  1124. var
  1125. L: Integer;
  1126. begin
  1127. Result := FunctionName;
  1128. L := Length(Result);
  1129. if (L > 1) then
  1130. case Result[L] of
  1131. 'A', 'W':
  1132. if CharIsValidIdentifierLetter(Result[L - 1]) then
  1133. Delete(Result, L, 1);
  1134. end;
  1135. end;
  1136. function PeSmartFunctionNameSame(const ComparedName, FunctionName: string;
  1137. Options: TJclSmartCompOptions): Boolean;
  1138. var
  1139. S: string;
  1140. begin
  1141. if scIgnoreCase in Options then
  1142. Result := CompareText(FunctionName, ComparedName) = 0
  1143. else
  1144. Result := (FunctionName = ComparedName);
  1145. if (not Result) and not (scSimpleCompare in Options) then
  1146. begin
  1147. if Length(FunctionName) > 0 then
  1148. begin
  1149. S := PeStripFunctionAW(FunctionName);
  1150. if scIgnoreCase in Options then
  1151. Result := CompareText(S, ComparedName) = 0
  1152. else
  1153. Result := (S = ComparedName);
  1154. end
  1155. else
  1156. Result := False;
  1157. end;
  1158. end;
  1159. //=== { TJclPeImagesCache } ==================================================
  1160. constructor TJclPeImagesCache.Create;
  1161. begin
  1162. inherited Create;
  1163. FList := TStringList.Create;
  1164. FList.Sorted := True;
  1165. FList.Duplicates := dupIgnore;
  1166. end;
  1167. destructor TJclPeImagesCache.Destroy;
  1168. begin
  1169. Clear;
  1170. FreeAndNil(FList);
  1171. inherited Destroy;
  1172. end;
  1173. procedure TJclPeImagesCache.Clear;
  1174. var
  1175. I: Integer;
  1176. begin
  1177. with FList do
  1178. for I := 0 to Count - 1 do
  1179. Objects[I].Free;
  1180. FList.Clear;
  1181. end;
  1182. function TJclPeImagesCache.GetCount: Integer;
  1183. begin
  1184. Result := FList.Count;
  1185. end;
  1186. function TJclPeImagesCache.GetImages(const FileName: TFileName): TJclPeImage;
  1187. var
  1188. I: Integer;
  1189. begin
  1190. I := FList.IndexOf(FileName);
  1191. if I = -1 then
  1192. begin
  1193. Result := GetPeImageClass.Create(True);
  1194. Result.FileName := FileName;
  1195. FList.AddObject(FileName, Result);
  1196. end
  1197. else
  1198. Result := TJclPeImage(FList.Objects[I]);
  1199. end;
  1200. function TJclPeImagesCache.GetPeImageClass: TJclPeImageClass;
  1201. begin
  1202. Result := TJclPeImage;
  1203. end;
  1204. //=== { TJclPeImageBaseList } ================================================
  1205. constructor TJclPeImageBaseList.Create(AImage: TJclPeImage);
  1206. begin
  1207. inherited Create(True);
  1208. FImage := AImage;
  1209. end;
  1210. // Import sort functions
  1211. function ImportSortByName(Item1, Item2: Pointer): Integer;
  1212. begin
  1213. Result := CompareStr(TJclPeImportFuncItem(Item1).Name, TJclPeImportFuncItem(Item2).Name);
  1214. if Result = 0 then
  1215. Result := CompareStr(TJclPeImportFuncItem(Item1).ImportLib.Name, TJclPeImportFuncItem(Item2).ImportLib.Name);
  1216. if Result = 0 then
  1217. Result := TJclPeImportFuncItem(Item1).Ordinal - TJclPeImportFuncItem(Item2).Ordinal;
  1218. end;
  1219. function ImportSortByNameDESC(Item1, Item2: Pointer): Integer;
  1220. begin
  1221. Result := ImportSortByName(Item2, Item1);
  1222. end;
  1223. function ImportSortByHint(Item1, Item2: Pointer): Integer;
  1224. begin
  1225. Result := TJclPeImportFuncItem(Item1).Hint - TJclPeImportFuncItem(Item2).Hint;
  1226. end;
  1227. function ImportSortByHintDESC(Item1, Item2: Pointer): Integer;
  1228. begin
  1229. Result := ImportSortByHint(Item2, Item1);
  1230. end;
  1231. function ImportSortByDll(Item1, Item2: Pointer): Integer;
  1232. begin
  1233. Result := CompareStr(TJclPeImportFuncItem(Item1).ImportLib.Name,
  1234. TJclPeImportFuncItem(Item2).ImportLib.Name);
  1235. if Result = 0 then
  1236. Result := ImportSortByName(Item1, Item2);
  1237. end;
  1238. function ImportSortByDllDESC(Item1, Item2: Pointer): Integer;
  1239. begin
  1240. Result := ImportSortByDll(Item2, Item1);
  1241. end;
  1242. function ImportSortByOrdinal(Item1, Item2: Pointer): Integer;
  1243. begin
  1244. Result := CompareStr(TJclPeImportFuncItem(Item1).ImportLib.Name,
  1245. TJclPeImportFuncItem(Item2).ImportLib.Name);
  1246. if Result = 0 then
  1247. Result := TJclPeImportFuncItem(Item1).Ordinal - TJclPeImportFuncItem(Item2).Ordinal;
  1248. end;
  1249. function ImportSortByOrdinalDESC(Item1, Item2: Pointer): Integer;
  1250. begin
  1251. Result := ImportSortByOrdinal(Item2, Item1);
  1252. end;
  1253. function GetImportSortFunction(SortType: TJclPeImportSort; Descending: Boolean): TListSortCompare;
  1254. const
  1255. SortFunctions: array [TJclPeImportSort, Boolean] of TListSortCompare =
  1256. ((ImportSortByName, ImportSortByNameDESC),
  1257. (ImportSortByOrdinal, ImportSortByOrdinalDESC),
  1258. (ImportSortByHint, ImportSortByHintDESC),
  1259. (ImportSortByDll, ImportSortByDllDESC)
  1260. );
  1261. begin
  1262. Result := SortFunctions[SortType, Descending];
  1263. end;
  1264. function ImportLibSortByIndex(Item1, Item2: Pointer): Integer;
  1265. begin
  1266. Result := TJclPeImportLibItem(Item1).ImportDirectoryIndex -
  1267. TJclPeImportLibItem(Item2).ImportDirectoryIndex;
  1268. end;
  1269. function ImportLibSortByName(Item1, Item2: Pointer): Integer;
  1270. begin
  1271. Result := AnsiCompareStr(TJclPeImportLibItem(Item1).Name, TJclPeImportLibItem(Item2).Name);
  1272. if Result = 0 then
  1273. Result := ImportLibSortByIndex(Item1, Item2);
  1274. end;
  1275. function GetImportLibSortFunction(SortType: TJclPeImportLibSort): TListSortCompare;
  1276. const
  1277. SortFunctions: array [TJclPeImportLibSort] of TListSortCompare =
  1278. (ImportLibSortByName, ImportLibSortByIndex);
  1279. begin
  1280. Result := SortFunctions[SortType];
  1281. end;
  1282. //=== { TJclPeImportFuncItem } ===============================================
  1283. constructor TJclPeImportFuncItem.Create(AImportLib: TJclPeImportLibItem;
  1284. AOrdinal: Word; AHint: Word; const AName: string);
  1285. begin
  1286. inherited Create;
  1287. FImportLib := AImportLib;
  1288. FOrdinal := AOrdinal;
  1289. FHint := AHint;
  1290. FName := AName;
  1291. FResolveCheck := icNotChecked;
  1292. FIndirectImportName := False;
  1293. end;
  1294. function TJclPeImportFuncItem.GetIsByOrdinal: Boolean;
  1295. begin
  1296. Result := FOrdinal <> 0;
  1297. end;
  1298. procedure TJclPeImportFuncItem.SetIndirectImportName(const Value: string);
  1299. begin
  1300. FName := Value;
  1301. FIndirectImportName := True;
  1302. end;
  1303. procedure TJclPeImportFuncItem.SetName(const Value: string);
  1304. begin
  1305. FName := Value;
  1306. FIndirectImportName := False;
  1307. end;
  1308. procedure TJclPeImportFuncItem.SetResolveCheck(Value: TJclPeResolveCheck);
  1309. begin
  1310. FResolveCheck := Value;
  1311. end;
  1312. //=== { TJclPeImportLibItem } ================================================
  1313. constructor TJclPeImportLibItem.Create(AImage: TJclPeImage;
  1314. AImportDescriptor: Pointer; AImportKind: TJclPeImportKind; const AName: string;
  1315. AThunk: Pointer; AUseRVA: Boolean = True);
  1316. begin
  1317. inherited Create(AImage);
  1318. FTotalResolveCheck := icNotChecked;
  1319. FImportDescriptor := AImportDescriptor;
  1320. FImportKind := AImportKind;
  1321. FName := AName;
  1322. FThunk := AThunk;
  1323. FThunkData := AThunk;
  1324. FUseRVA := AUseRVA;
  1325. end;
  1326. procedure TJclPeImportLibItem.CheckImports(ExportImage: TJclPeImage);
  1327. var
  1328. I: Integer;
  1329. ExportList: TJclPeExportFuncList;
  1330. begin
  1331. if ExportImage.StatusOK then
  1332. begin
  1333. FTotalResolveCheck := icResolved;
  1334. ExportList := ExportImage.ExportList;
  1335. for I := 0 to Count - 1 do
  1336. begin
  1337. with Items[I] do
  1338. if IsByOrdinal then
  1339. begin
  1340. if ExportList.OrdinalValid(Ordinal) then
  1341. SetResolveCheck(icResolved)
  1342. else
  1343. begin
  1344. SetResolveCheck(icUnresolved);
  1345. Self.FTotalResolveCheck := icUnresolved;
  1346. end;
  1347. end
  1348. else
  1349. begin
  1350. if ExportList.ItemFromName[Items[I].Name] <> nil then
  1351. SetResolveCheck(icResolved)
  1352. else
  1353. begin
  1354. SetResolveCheck(icUnresolved);
  1355. Self.FTotalResolveCheck := icUnresolved;
  1356. end;
  1357. end;
  1358. end;
  1359. end
  1360. else
  1361. begin
  1362. FTotalResolveCheck := icUnresolved;
  1363. for I := 0 to Count - 1 do
  1364. Items[I].SetResolveCheck(icUnresolved);
  1365. end;
  1366. end;
  1367. procedure TJclPeImportLibItem.CreateList;
  1368. procedure CreateList32;
  1369. var
  1370. Thunk32: PImageThunkData32;
  1371. OrdinalName: PImageImportByName;
  1372. Ordinal, Hint: Word;
  1373. Name: PAnsiChar;
  1374. ImportName: string;
  1375. AddressOfData: DWORD;
  1376. begin
  1377. Thunk32 := PImageThunkData32(FThunk);
  1378. while Thunk32^.Function_ <> 0 do
  1379. begin
  1380. Ordinal := 0;
  1381. Hint := 0;
  1382. Name := nil;
  1383. if Thunk32^.Ordinal and IMAGE_ORDINAL_FLAG32 = 0 then
  1384. begin
  1385. case ImportKind of
  1386. ikImport, ikBoundImport:
  1387. begin
  1388. OrdinalName := PImageImportByName(Image.RvaToVa(Thunk32^.AddressOfData));
  1389. if OrdinalName <> nil then
  1390. begin
  1391. Hint := OrdinalName.Hint;
  1392. Name := OrdinalName.Name;
  1393. end;
  1394. end;
  1395. ikDelayImport:
  1396. begin
  1397. AddressOfData := Thunk32^.AddressOfData;
  1398. if not FUseRVA then
  1399. AddressOfData := Image.ImageAddressToRva(AddressOfData);
  1400. OrdinalName := PImageImportByName(Image.RvaToVa(AddressOfData));
  1401. if OrdinalName <> nil then
  1402. begin
  1403. Hint := OrdinalName.Hint;
  1404. Name := OrdinalName.Name;
  1405. end;
  1406. end;
  1407. end;
  1408. end
  1409. else
  1410. Ordinal := IMAGE_ORDINAL32(Thunk32^.Ordinal);
  1411. if (Ordinal <> 0) or (Hint <> 0) or (Name <> nil) then
  1412. begin
  1413. if not TryUTF8ToString(Name, ImportName) then
  1414. ImportName := string(Name);
  1415. Add(TJclPeImportFuncItem.Create(Self, Ordinal, Hint, ImportName));
  1416. end;
  1417. Inc(Thunk32);
  1418. end;
  1419. end;
  1420. procedure CreateList64;
  1421. var
  1422. Thunk64: PImageThunkData64;
  1423. OrdinalName: PImageImportByName;
  1424. Ordinal, Hint: Word;
  1425. Name: PAnsiChar;
  1426. ImportName: string;
  1427. begin
  1428. Thunk64 := PImageThunkData64(FThunk);
  1429. while Thunk64^.Function_ <> 0 do
  1430. begin
  1431. Ordinal := 0;
  1432. Hint := 0;
  1433. Name := nil;
  1434. if Thunk64^.Ordinal and IMAGE_ORDINAL_FLAG64 = 0 then
  1435. begin
  1436. case ImportKind of
  1437. ikImport, ikBoundImport:
  1438. begin
  1439. OrdinalName := PImageImportByName(Image.RvaToVa(Thunk64^.AddressOfData));
  1440. if OrdinalName <> nil then
  1441. begin
  1442. Hint := OrdinalName.Hint;
  1443. Name := OrdinalName.Name;
  1444. end;
  1445. end;
  1446. ikDelayImport:
  1447. begin
  1448. OrdinalName := PImageImportByName(Image.RvaToVa(Thunk64^.AddressOfData));
  1449. if OrdinalName <> nil then
  1450. begin
  1451. Hint := OrdinalName.Hint;
  1452. Name := OrdinalName.Name;
  1453. end;
  1454. end;
  1455. end;
  1456. end
  1457. else
  1458. Ordinal := IMAGE_ORDINAL64(Thunk64^.Ordinal);
  1459. if (Ordinal <> 0) or (Hint <> 0) or (Name <> nil) then
  1460. begin
  1461. if not TryUTF8ToString(Name, ImportName) then
  1462. ImportName := string(Name);
  1463. Add(TJclPeImportFuncItem.Create(Self, Ordinal, Hint, ImportName));
  1464. end;
  1465. Inc(Thunk64);
  1466. end;
  1467. end;
  1468. begin
  1469. if FThunk = nil then
  1470. Exit;
  1471. case Image.Target of
  1472. taWin32:
  1473. CreateList32;
  1474. taWin64:
  1475. CreateList64;
  1476. end;
  1477. FThunk := nil;
  1478. end;
  1479. function TJclPeImportLibItem.GetCount: Integer;
  1480. begin
  1481. if FThunk <> nil then
  1482. CreateList;
  1483. Result := inherited Count;
  1484. end;
  1485. function TJclPeImportLibItem.GetFileName: TFileName;
  1486. begin
  1487. Result := Image.ExpandModuleName(Name);
  1488. end;
  1489. function TJclPeImportLibItem.GetItems(Index: TJclListSize): TJclPeImportFuncItem;
  1490. begin
  1491. Result := TJclPeImportFuncItem(Get(Index));
  1492. end;
  1493. function TJclPeImportLibItem.GetName: string;
  1494. begin
  1495. Result := AnsiLowerCase(OriginalName);
  1496. end;
  1497. function TJclPeImportLibItem.GetThunkData32: PImageThunkData32;
  1498. begin
  1499. if Image.Target = taWin32 then
  1500. Result := FThunkData
  1501. else
  1502. Result := nil;
  1503. end;
  1504. function TJclPeImportLibItem.GetThunkData64: PImageThunkData64;
  1505. begin
  1506. if Image.Target = taWin64 then
  1507. Result := FThunkData
  1508. else
  1509. Result := nil;
  1510. end;
  1511. procedure TJclPeImportLibItem.SetImportDirectoryIndex(Value: Integer);
  1512. begin
  1513. FImportDirectoryIndex := Value;
  1514. end;
  1515. procedure TJclPeImportLibItem.SetImportKind(Value: TJclPeImportKind);
  1516. begin
  1517. FImportKind := Value;
  1518. end;
  1519. procedure TJclPeImportLibItem.SetSorted(Value: Boolean);
  1520. begin
  1521. FSorted := Value;
  1522. end;
  1523. procedure TJclPeImportLibItem.SetThunk(Value: Pointer);
  1524. begin
  1525. FThunk := Value;
  1526. FThunkData := Value;
  1527. end;
  1528. procedure TJclPeImportLibItem.SortList(SortType: TJclPeImportSort; Descending: Boolean);
  1529. begin
  1530. if not FSorted or (SortType <> FLastSortType) or (Descending <> FLastSortDescending) then
  1531. begin
  1532. GetCount; // create list if it wasn't created
  1533. Sort(GetImportSortFunction(SortType, Descending));
  1534. FLastSortType := SortType;
  1535. FLastSortDescending := Descending;
  1536. FSorted := True;
  1537. end;
  1538. end;
  1539. //=== { TJclPeImportList } ===================================================
  1540. constructor TJclPeImportList.Create(AImage: TJclPeImage);
  1541. begin
  1542. inherited Create(AImage);
  1543. FAllItemsList := TList.Create;
  1544. FAllItemsList.Capacity := 256;
  1545. FUniqueNamesList := TStringList.Create;
  1546. FUniqueNamesList.Sorted := True;
  1547. FUniqueNamesList.Duplicates := dupIgnore;
  1548. FLastAllSortType := isName;
  1549. FLastAllSortDescending := False;
  1550. CreateList;
  1551. end;
  1552. destructor TJclPeImportList.Destroy;
  1553. var
  1554. I: Integer;
  1555. begin
  1556. FreeAndNil(FAllItemsList);
  1557. FreeAndNil(FUniqueNamesList);
  1558. for I := 0 to Length(FparallelImportTable) - 1 do
  1559. FreeMem(FparallelImportTable[I]);
  1560. inherited Destroy;
  1561. end;
  1562. procedure TJclPeImportList.CheckImports(PeImageCache: TJclPeImagesCache);
  1563. var
  1564. I: Integer;
  1565. ExportPeImage: TJclPeImage;
  1566. begin
  1567. Image.CheckNotAttached;
  1568. if PeImageCache <> nil then
  1569. ExportPeImage := nil // to make the compiler happy
  1570. else
  1571. ExportPeImage := TJclPeImage.Create(True);
  1572. try
  1573. for I := 0 to Count - 1 do
  1574. if Items[I].TotalResolveCheck = icNotChecked then
  1575. begin
  1576. if PeImageCache <> nil then
  1577. ExportPeImage := PeImageCache[Items[I].FileName]
  1578. else
  1579. ExportPeImage.FileName := Items[I].FileName;
  1580. ExportPeImage.ExportList.PrepareForFastNameSearch;
  1581. Items[I].CheckImports(ExportPeImage);
  1582. end;
  1583. finally
  1584. if PeImageCache = nil then
  1585. ExportPeImage.Free;
  1586. end;
  1587. end;
  1588. procedure TJclPeImportList.CreateList;
  1589. procedure CreateDelayImportList32(DelayImportDesc: PImgDelayDescrV1);
  1590. const
  1591. ATTRS_RVA = 1;
  1592. var
  1593. LibItem: TJclPeImportLibItem;
  1594. UTF8Name: TUTF8String;
  1595. LibName: string;
  1596. P, Thunk: Pointer;
  1597. UseRVA: Boolean;
  1598. begin
  1599. // 2010, XE use addresses whereas XE2 and newer use the RVA mode
  1600. while DelayImportDesc^.szName <> nil do
  1601. begin
  1602. UseRVA := DelayImportDesc^.grAttrs and ATTRS_RVA <> 0;
  1603. Thunk := DelayImportDesc^.pINT;
  1604. P := DelayImportDesc^.szName;
  1605. if not UseRVA then
  1606. begin
  1607. Thunk := Pointer(Image.ImageAddressToRva(DWORD(DelayImportDesc^.pINT)));
  1608. P := Pointer(Image.ImageAddressToRva(DWORD(DelayImportDesc^.szName)));
  1609. end;
  1610. UTF8Name := PAnsiChar(Image.RvaToVa(DWORD(P)));
  1611. if not TryUTF8ToString(UTF8Name, LibName) then
  1612. LibName := string(UTF8Name);
  1613. LibItem := TJclPeImportLibItem.Create(Image, DelayImportDesc, ikDelayImport,
  1614. LibName, Image.RvaToVa(DWORD(Thunk)), UseRVA);
  1615. Add(LibItem);
  1616. FUniqueNamesList.AddObject(AnsiLowerCase(LibItem.Name), LibItem);
  1617. Inc(DelayImportDesc);
  1618. end;
  1619. end;
  1620. procedure CreateDelayImportList64(DelayImportDesc: PImgDelayDescrV2);
  1621. var
  1622. LibItem: TJclPeImportLibItem;
  1623. UTF8Name: TUTF8String;
  1624. LibName: string;
  1625. begin
  1626. // 64 bit always uses RVA mode
  1627. while DelayImportDesc^.rvaDLLName <> 0 do
  1628. begin
  1629. UTF8Name := PAnsiChar(Image.RvaToVa(DelayImportDesc^.rvaDLLName));
  1630. if not TryUTF8ToString(UTF8Name, LibName) then
  1631. LibName := string(UTF8Name);
  1632. LibItem := TJclPeImportLibItem.Create(Image, DelayImportDesc, ikDelayImport,
  1633. LibName, Image.RvaToVa(DelayImportDesc^.rvaINT));
  1634. Add(LibItem);
  1635. FUniqueNamesList.AddObject(AnsiLowerCase(LibItem.Name), LibItem);
  1636. Inc(DelayImportDesc);
  1637. end;
  1638. end;
  1639. var
  1640. ImportDesc: PImageImportDescriptor;
  1641. LibItem: TJclPeImportLibItem;
  1642. UTF8Name: TUTF8String;
  1643. LibName, ModuleName: string;
  1644. DelayImportDesc: Pointer;
  1645. BoundImports, BoundImport: PImageBoundImportDescriptor;
  1646. S: string;
  1647. I: Integer;
  1648. Thunk: Pointer;
  1649. begin
  1650. SetCapacity(100);
  1651. with Image do
  1652. begin
  1653. if not StatusOK then
  1654. Exit;
  1655. ImportDesc := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_IMPORT);
  1656. if ImportDesc <> nil then
  1657. while ImportDesc^.Name <> 0 do
  1658. begin
  1659. if ImportDesc^.Union.Characteristics = 0 then
  1660. begin
  1661. if AttachedImage then // Borland images doesn't have two parallel arrays
  1662. Thunk := nil // see MakeBorlandImportTableForMappedImage method
  1663. else
  1664. Thunk := RvaToVa(ImportDesc^.FirstThunk);
  1665. FLinkerProducer := lrBorland;
  1666. end
  1667. else
  1668. begin
  1669. Thunk := RvaToVa(ImportDesc^.Union.Characteristics);
  1670. FLinkerProducer := lrMicrosoft;
  1671. end;
  1672. UTF8Name := PAnsiChar(RvaToVa(ImportDesc^.Name));
  1673. if not TryUTF8ToString(UTF8Name, LibName) then
  1674. LibName := string(UTF8Name);
  1675. LibItem := TJclPeImportLibItem.Create(Image, ImportDesc, ikImport, LibName, Thunk);
  1676. Add(LibItem);
  1677. FUniqueNamesList.AddObject(AnsiLowerCase(LibItem.Name), LibItem);
  1678. Inc(ImportDesc);
  1679. end;
  1680. DelayImportDesc := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT);
  1681. if DelayImportDesc <> nil then
  1682. begin
  1683. try
  1684. case Target of
  1685. taWin32:
  1686. CreateDelayImportList32(DelayImportDesc);
  1687. taWin64:
  1688. CreateDelayImportList64(DelayImportDesc);
  1689. end;
  1690. except
  1691. on E: EAccessViolation do // Mantis #6177. Some users seem to have module loaded that is broken
  1692. ; // ignore
  1693. end;
  1694. end;
  1695. BoundImports := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT);
  1696. if BoundImports <> nil then
  1697. begin
  1698. BoundImport := BoundImports;
  1699. while BoundImport^.OffsetModuleName <> 0 do
  1700. begin
  1701. UTF8Name := PAnsiChar(TJclAddr(BoundImports) + BoundImport^.OffsetModuleName);
  1702. if not TryUTF8ToString(UTF8Name, ModuleName) then
  1703. ModuleName := string(UTF8Name);
  1704. S := AnsiLowerCase(ModuleName);
  1705. I := FUniqueNamesList.IndexOf(S);
  1706. if I >= 0 then
  1707. TJclPeImportLibItem(FUniqueNamesList.Objects[I]).SetImportKind(ikBoundImport);
  1708. for I := 1 to BoundImport^.NumberOfModuleForwarderRefs do
  1709. Inc(PImageBoundForwarderRef(BoundImport)); // skip forward information
  1710. Inc(BoundImport);
  1711. end;
  1712. end;
  1713. end;
  1714. for I := 0 to Count - 1 do
  1715. Items[I].SetImportDirectoryIndex(I);
  1716. end;
  1717. function TJclPeImportList.GetAllItemCount: Integer;
  1718. begin
  1719. Result := FAllItemsList.Count;
  1720. if Result = 0 then // we haven't created the list yet -> create unsorted list
  1721. begin
  1722. RefreshAllItems;
  1723. Result := FAllItemsList.Count;
  1724. end;
  1725. end;
  1726. function TJclPeImportList.GetAllItems(Index: Integer): TJclPeImportFuncItem;
  1727. begin
  1728. Result := TJclPeImportFuncItem(FAllItemsList[Index]);
  1729. end;
  1730. function TJclPeImportList.GetItems(Index: TJclListSize): TJclPeImportLibItem;
  1731. begin
  1732. Result := TJclPeImportLibItem(Get(Index));
  1733. end;
  1734. function TJclPeImportList.GetUniqueLibItemCount: Integer;
  1735. begin
  1736. Result := FUniqueNamesList.Count;
  1737. end;
  1738. function TJclPeImportList.GetUniqueLibItemFromName(const Name: string): TJclPeImportLibItem;
  1739. var
  1740. I: Integer;
  1741. begin
  1742. I := FUniqueNamesList.IndexOf(Name);
  1743. if I = -1 then
  1744. Result := nil
  1745. else
  1746. Result := TJclPeImportLibItem(FUniqueNamesList.Objects[I]);
  1747. end;
  1748. function TJclPeImportList.GetUniqueLibItems(Index: Integer): TJclPeImportLibItem;
  1749. begin
  1750. Result := TJclPeImportLibItem(FUniqueNamesList.Objects[Index]);
  1751. end;
  1752. function TJclPeImportList.GetUniqueLibNames(Index: Integer): string;
  1753. begin
  1754. Result := FUniqueNamesList[Index];
  1755. end;
  1756. function TJclPeImportList.MakeBorlandImportTableForMappedImage: Boolean;
  1757. var
  1758. FileImage: TJclPeImage;
  1759. I, TableSize: Integer;
  1760. begin
  1761. if Image.AttachedImage and (LinkerProducer = lrBorland) and
  1762. (Length(FParallelImportTable) = 0) then
  1763. begin
  1764. FileImage := TJclPeImage.Create(True);
  1765. try
  1766. FileImage.FileName := Image.FileName;
  1767. Result := FileImage.StatusOK;
  1768. if Result then
  1769. begin
  1770. SetLength(FParallelImportTable, FileImage.ImportList.Count);
  1771. for I := 0 to FileImage.ImportList.Count - 1 do
  1772. begin
  1773. Assert(Items[I].ImportKind = ikImport); // Borland doesn't have Delay load or Bound imports
  1774. TableSize := (FileImage.ImportList[I].Count + 1);
  1775. case Image.Target of
  1776. taWin32:
  1777. begin
  1778. TableSize := TableSize * SizeOf(TImageThunkData32);
  1779. GetMem(FParallelImportTable[I], TableSize);
  1780. System.Move(FileImage.ImportList[I].ThunkData32^, FParallelImportTable[I]^, TableSize);
  1781. Items[I].SetThunk(FParallelImportTable[I]);
  1782. end;
  1783. taWin64:
  1784. begin
  1785. TableSize := TableSize * SizeOf(TImageThunkData64);
  1786. GetMem(FParallelImportTable[I], TableSize);
  1787. System.Move(FileImage.ImportList[I].ThunkData64^, FParallelImportTable[I]^, TableSize);
  1788. Items[I].SetThunk(FParallelImportTable[I]);
  1789. end;
  1790. end;
  1791. end;
  1792. end;
  1793. finally
  1794. FileImage.Free;
  1795. end;
  1796. end
  1797. else
  1798. Result := True;
  1799. end;
  1800. procedure TJclPeImportList.RefreshAllItems;
  1801. var
  1802. L, I: Integer;
  1803. LibItem: TJclPeImportLibItem;
  1804. begin
  1805. FAllItemsList.Clear;
  1806. for L := 0 to Count - 1 do
  1807. begin
  1808. LibItem := Items[L];
  1809. if (Length(FFilterModuleName) = 0) or (AnsiCompareText(LibItem.Name, FFilterModuleName) = 0) then
  1810. for I := 0 to LibItem.Count - 1 do
  1811. FAllItemsList.Add(LibItem[I]);
  1812. end;
  1813. end;
  1814. procedure TJclPeImportList.SetFilterModuleName(const Value: string);
  1815. begin
  1816. if (FFilterModuleName <> Value) or (FAllItemsList.Count = 0) then
  1817. begin
  1818. FFilterModuleName := Value;
  1819. RefreshAllItems;
  1820. FAllItemsList.Sort(GetImportSortFunction(FLastAllSortType, FLastAllSortDescending));
  1821. end;
  1822. end;
  1823. function TJclPeImportList.SmartFindName(const CompareName, LibName: string;
  1824. Options: TJclSmartCompOptions): TJclPeImportFuncItem;
  1825. var
  1826. L, I: Integer;
  1827. LibItem: TJclPeImportLibItem;
  1828. begin
  1829. Result := nil;
  1830. for L := 0 to Count - 1 do
  1831. begin
  1832. LibItem := Items[L];
  1833. if (Length(LibName) = 0) or (AnsiCompareText(LibItem.Name, LibName) = 0) then
  1834. for I := 0 to LibItem.Count - 1 do
  1835. if PeSmartFunctionNameSame(CompareName, LibItem[I].Name, Options) then
  1836. begin
  1837. Result := LibItem[I];
  1838. Break;
  1839. end;
  1840. end;
  1841. end;
  1842. procedure TJclPeImportList.SortAllItemsList(SortType: TJclPeImportSort; Descending: Boolean);
  1843. begin
  1844. GetAllItemCount; // create list if it wasn't created
  1845. FAllItemsList.Sort(GetImportSortFunction(SortType, Descending));
  1846. FLastAllSortType := SortType;
  1847. FLastAllSortDescending := Descending;
  1848. end;
  1849. procedure TJclPeImportList.SortList(SortType: TJclPeImportLibSort);
  1850. begin
  1851. Sort(GetImportLibSortFunction(SortType));
  1852. end;
  1853. procedure TJclPeImportList.TryGetNamesForOrdinalImports;
  1854. var
  1855. LibNamesList: TStringList;
  1856. L, I: Integer;
  1857. LibPeDump: TJclPeImage;
  1858. procedure TryGetNames(const ModuleName: string);
  1859. var
  1860. Item: TJclPeImportFuncItem;
  1861. I, L: Integer;
  1862. ImportLibItem: TJclPeImportLibItem;
  1863. ExportItem: TJclPeExportFuncItem;
  1864. ExportList: TJclPeExportFuncList;
  1865. begin
  1866. if Image.AttachedImage then
  1867. LibPeDump.AttachLoadedModule(GetModuleHandle(PChar(ModuleName)))
  1868. else
  1869. LibPeDump.FileName := Image.ExpandModuleName(ModuleName);
  1870. if not LibPeDump.StatusOK then
  1871. Exit;
  1872. ExportList := LibPeDump.ExportList;
  1873. for L := 0 to Count - 1 do
  1874. begin
  1875. ImportLibItem := Items[L];
  1876. if AnsiCompareText(ImportLibItem.Name, ModuleName) = 0 then
  1877. begin
  1878. for I := 0 to ImportLibItem.Count - 1 do
  1879. begin
  1880. Item := ImportLibItem[I];
  1881. if Item.IsByOrdinal then
  1882. begin
  1883. ExportItem := ExportList.ItemFromOrdinal[Item.Ordinal];
  1884. if (ExportItem <> nil) and (ExportItem.Name <> '') then
  1885. Item.SetIndirectImportName(ExportItem.Name);
  1886. end;
  1887. end;
  1888. ImportLibItem.SetSorted(False);
  1889. end;
  1890. end;
  1891. end;
  1892. begin
  1893. LibNamesList := TStringList.Create;
  1894. try
  1895. LibNamesList.Sorted := True;
  1896. LibNamesList.Duplicates := dupIgnore;
  1897. for L := 0 to Count - 1 do
  1898. with Items[L] do
  1899. for I := 0 to Count - 1 do
  1900. if Items[I].IsByOrdinal then
  1901. LibNamesList.Add(AnsiUpperCase(Name));
  1902. LibPeDump := TJclPeImage.Create(True);
  1903. try
  1904. for I := 0 to LibNamesList.Count - 1 do
  1905. TryGetNames(LibNamesList[I]);
  1906. finally
  1907. LibPeDump.Free;
  1908. end;
  1909. SortAllItemsList(FLastAllSortType, FLastAllSortDescending);
  1910. finally
  1911. LibNamesList.Free;
  1912. end;
  1913. end;
  1914. //=== { TJclPeExportFuncItem } ===============================================
  1915. constructor TJclPeExportFuncItem.Create(AExportList: TJclPeExportFuncList;
  1916. const AName, AForwardedName: string; AAddress: DWORD; AHint: Word;
  1917. AOrdinal: Word; AResolveCheck: TJclPeResolveCheck);
  1918. var
  1919. DotPos: Integer;
  1920. begin
  1921. inherited Create;
  1922. FExportList := AExportList;
  1923. FName := AName;
  1924. FForwardedName := AForwardedName;
  1925. FAddress := AAddress;
  1926. FHint := AHint;
  1927. FOrdinal := AOrdinal;
  1928. FResolveCheck := AResolveCheck;
  1929. DotPos := AnsiPos('.', ForwardedName);
  1930. if DotPos > 0 then
  1931. FForwardedDotPos := Copy(ForwardedName, DotPos + 1, Length(ForwardedName) - DotPos)
  1932. else
  1933. FForwardedDotPos := '';
  1934. end;
  1935. function TJclPeExportFuncItem.GetAddressOrForwardStr: string;
  1936. begin
  1937. if IsForwarded then
  1938. Result := ForwardedName
  1939. else
  1940. FmtStr(Result, '%.8x', [Address]);
  1941. end;
  1942. function TJclPeExportFuncItem.GetForwardedFuncName: string;
  1943. begin
  1944. if (Length(FForwardedDotPos) > 0) and (FForwardedDotPos[1] <> '#') then
  1945. Result := FForwardedDotPos
  1946. else
  1947. Result := '';
  1948. end;
  1949. function TJclPeExportFuncItem.GetForwardedFuncOrdinal: DWORD;
  1950. begin
  1951. if (Length(FForwardedDotPos) > 0) and (FForwardedDotPos[1] = '#') then
  1952. Result := StrToIntDef(FForwardedDotPos, 0)
  1953. else
  1954. Result := 0;
  1955. end;
  1956. function TJclPeExportFuncItem.GetForwardedLibName: string;
  1957. begin
  1958. if Length(FForwardedDotPos) = 0 then
  1959. Result := ''
  1960. else
  1961. Result := AnsiLowerCase(Copy(FForwardedName, 1, Length(FForwardedName) - Length(FForwardedDotPos) - 1)) + BinaryExtensionLibrary;
  1962. end;
  1963. function TJclPeExportFuncItem.GetIsExportedVariable: Boolean;
  1964. begin
  1965. case FExportList.Image.Target of
  1966. taWin32:
  1967. begin
  1968. {$IFDEF DELPHI64_TEMPORARY}
  1969. System.Error(rePlatformNotImplemented);//there is no BaseOfData in the 32-bit header for Win64
  1970. Result := False;
  1971. {$ELSE ~DELPHI64_TEMPORARY}
  1972. Result := (Address >= FExportList.Image.OptionalHeader32.BaseOfData);
  1973. {$ENDIF ~DELPHI64_TEMPORARY}
  1974. end;
  1975. taWin64:
  1976. Result := False;
  1977. // TODO equivalent for 64-bit modules
  1978. //Result := (Address >= FExportList.Image.OptionalHeader64.BaseOfData);
  1979. else
  1980. Result := False;
  1981. end;
  1982. end;
  1983. function TJclPeExportFuncItem.GetIsForwarded: Boolean;
  1984. begin
  1985. Result := Length(FForwardedName) <> 0;
  1986. end;
  1987. function TJclPeExportFuncItem.GetMappedAddress: Pointer;
  1988. begin
  1989. Result := FExportList.Image.RvaToVa(FAddress);
  1990. end;
  1991. function TJclPeExportFuncItem.GetSectionName: string;
  1992. begin
  1993. if IsForwarded then
  1994. Result := ''
  1995. else
  1996. with FExportList.Image do
  1997. Result := ImageSectionNameFromRva[Address];
  1998. end;
  1999. procedure TJclPeExportFuncItem.SetResolveCheck(Value: TJclPeResolveCheck);
  2000. begin
  2001. FResolveCheck := Value;
  2002. end;
  2003. // Export sort functions
  2004. function ExportSortByName(Item1, Item2: Pointer): Integer;
  2005. begin
  2006. Result := CompareStr(TJclPeExportFuncItem(Item1).Name, TJclPeExportFuncItem(Item2).Name);
  2007. end;
  2008. function ExportSortByNameDESC(Item1, Item2: Pointer): Integer;
  2009. begin
  2010. Result := ExportSortByName(Item2, Item1);
  2011. end;
  2012. function ExportSortByOrdinal(Item1, Item2: Pointer): Integer;
  2013. begin
  2014. Result := TJclPeExportFuncItem(Item1).Ordinal - TJclPeExportFuncItem(Item2).Ordinal;
  2015. end;
  2016. function ExportSortByOrdinalDESC(Item1, Item2: Pointer): Integer;
  2017. begin
  2018. Result := ExportSortByOrdinal(Item2, Item1);
  2019. end;
  2020. function ExportSortByHint(Item1, Item2: Pointer): Integer;
  2021. begin
  2022. Result := TJclPeExportFuncItem(Item1).Hint - TJclPeExportFuncItem(Item2).Hint;
  2023. end;
  2024. function ExportSortByHintDESC(Item1, Item2: Pointer): Integer;
  2025. begin
  2026. Result := ExportSortByHint(Item2, Item1);
  2027. end;
  2028. function ExportSortByAddress(Item1, Item2: Pointer): Integer;
  2029. begin
  2030. Result := INT_PTR(TJclPeExportFuncItem(Item1).Address) - INT_PTR(TJclPeExportFuncItem(Item2).Address);
  2031. if Result = 0 then
  2032. Result := ExportSortByName(Item1, Item2);
  2033. end;
  2034. function ExportSortByAddressDESC(Item1, Item2: Pointer): Integer;
  2035. begin
  2036. Result := ExportSortByAddress(Item2, Item1);
  2037. end;
  2038. function ExportSortByForwarded(Item1, Item2: Pointer): Integer;
  2039. begin
  2040. Result := CompareStr(TJclPeExportFuncItem(Item1).ForwardedName, TJclPeExportFuncItem(Item2).ForwardedName);
  2041. if Result = 0 then
  2042. Result := ExportSortByName(Item1, Item2);
  2043. end;
  2044. function ExportSortByForwardedDESC(Item1, Item2: Pointer): Integer;
  2045. begin
  2046. Result := ExportSortByForwarded(Item2, Item1);
  2047. end;
  2048. function ExportSortByAddrOrFwd(Item1, Item2: Pointer): Integer;
  2049. begin
  2050. Result := CompareStr(TJclPeExportFuncItem(Item1).AddressOrForwardStr, TJclPeExportFuncItem(Item2).AddressOrForwardStr);
  2051. end;
  2052. function ExportSortByAddrOrFwdDESC(Item1, Item2: Pointer): Integer;
  2053. begin
  2054. Result := ExportSortByAddrOrFwd(Item2, Item1);
  2055. end;
  2056. function ExportSortBySection(Item1, Item2: Pointer): Integer;
  2057. begin
  2058. Result := CompareStr(TJclPeExportFuncItem(Item1).SectionName, TJclPeExportFuncItem(Item2).SectionName);
  2059. if Result = 0 then
  2060. Result := ExportSortByName(Item1, Item2);
  2061. end;
  2062. function ExportSortBySectionDESC(Item1, Item2: Pointer): Integer;
  2063. begin
  2064. Result := ExportSortBySection(Item2, Item1);
  2065. end;
  2066. //=== { TJclPeExportFuncList } ===============================================
  2067. constructor TJclPeExportFuncList.Create(AImage: TJclPeImage);
  2068. begin
  2069. inherited Create(AImage);
  2070. FTotalResolveCheck := icNotChecked;
  2071. CreateList;
  2072. end;
  2073. destructor TJclPeExportFuncList.Destroy;
  2074. begin
  2075. FreeAndNil(FForwardedLibsList);
  2076. inherited Destroy;
  2077. end;
  2078. function TJclPeExportFuncList.CanPerformFastNameSearch: Boolean;
  2079. begin
  2080. Result := FSorted and (FLastSortType = esName) and not FLastSortDescending;
  2081. end;
  2082. procedure TJclPeExportFuncList.CheckForwards(PeImageCache: TJclPeImagesCache);
  2083. var
  2084. I: Integer;
  2085. FullFileName: TFileName;
  2086. ForwardPeImage: TJclPeImage;
  2087. ModuleResolveCheck: TJclPeResolveCheck;
  2088. procedure PerformCheck(const ModuleName: string);
  2089. var
  2090. I: Integer;
  2091. Item: TJclPeExportFuncItem;
  2092. EL: TJclPeExportFuncList;
  2093. begin
  2094. EL := ForwardPeImage.ExportList;
  2095. EL.PrepareForFastNameSearch;
  2096. ModuleResolveCheck := icResolved;
  2097. for I := 0 to Count - 1 do
  2098. begin
  2099. Item := Items[I];
  2100. if (not Item.IsForwarded) or (Item.ResolveCheck <> icNotChecked) or
  2101. (Item.ForwardedLibName <> ModuleName) then
  2102. Continue;
  2103. if EL.ItemFromName[Item.ForwardedFuncName] = nil then
  2104. begin
  2105. Item.SetResolveCheck(icUnresolved);
  2106. ModuleResolveCheck := icUnresolved;
  2107. end
  2108. else
  2109. Item.SetResolveCheck(icResolved);
  2110. end;
  2111. end;
  2112. begin
  2113. if not AnyForwards then
  2114. Exit;
  2115. FTotalResolveCheck := icResolved;
  2116. if PeImageCache <> nil then
  2117. ForwardPeImage := nil // to make the compiler happy
  2118. else
  2119. ForwardPeImage := TJclPeImage.Create(True);
  2120. try
  2121. for I := 0 to ForwardedLibsList.Count - 1 do
  2122. begin
  2123. FullFileName := Image.ExpandModuleName(ForwardedLibsList[I]);
  2124. if PeImageCache <> nil then
  2125. ForwardPeImage := PeImageCache[FullFileName]
  2126. else
  2127. ForwardPeImage.FileName := FullFileName;
  2128. if ForwardPeImage.StatusOK then
  2129. PerformCheck(ForwardedLibsList[I])
  2130. else
  2131. ModuleResolveCheck := icUnresolved;
  2132. FForwardedLibsList.Objects[I] := Pointer(ModuleResolveCheck);
  2133. if ModuleResolveCheck = icUnresolved then
  2134. FTotalResolveCheck := icUnresolved;
  2135. end;
  2136. finally
  2137. if PeImageCache = nil then
  2138. ForwardPeImage.Free;
  2139. end;
  2140. end;
  2141. procedure TJclPeExportFuncList.CreateList;
  2142. var
  2143. Functions: Pointer;
  2144. Address, NameCount: DWORD;
  2145. NameOrdinals: PWORD;
  2146. Names: PDWORD;
  2147. I: Integer;
  2148. ExportItem: TJclPeExportFuncItem;
  2149. ExportVABegin, ExportVAEnd: DWORD;
  2150. UTF8Name: TUTF8String;
  2151. ForwardedName, ExportName: string;
  2152. begin
  2153. with Image do
  2154. begin
  2155. if not StatusOK then
  2156. Exit;
  2157. with Directories[IMAGE_DIRECTORY_ENTRY_EXPORT] do
  2158. begin
  2159. ExportVABegin := VirtualAddress;
  2160. ExportVAEnd := VirtualAddress + TJclAddr(Size);
  2161. end;
  2162. FExportDir := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_EXPORT);
  2163. if FExportDir <> nil then
  2164. begin
  2165. FBase := FExportDir^.Base;
  2166. FFunctionCount := FExportDir^.NumberOfFunctions;
  2167. Functions := RvaToVa(FExportDir^.AddressOfFunctions);
  2168. NameOrdinals := RvaToVa(FExportDir^.AddressOfNameOrdinals);
  2169. Names := RvaToVa(FExportDir^.AddressOfNames);
  2170. NameCount := FExportDir^.NumberOfNames;
  2171. Count := FExportDir^.NumberOfFunctions;
  2172. for I := 0 to Count - 1 do
  2173. begin
  2174. Address := PDWORD(TJclAddr(Functions) + TJclAddr(I) * SizeOf(DWORD))^;
  2175. if (Address >= ExportVABegin) and (Address <= ExportVAEnd) then
  2176. begin
  2177. FAnyForwards := True;
  2178. UTF8Name := PAnsiChar(RvaToVa(Address));
  2179. if not TryUTF8ToString(UTF8Name, ForwardedName) then
  2180. ForwardedName := string(UTF8Name);
  2181. end
  2182. else
  2183. ForwardedName := '';
  2184. ExportItem := TJclPeExportFuncItem.Create(Self, '',
  2185. ForwardedName, Address, $FFFF, TJclAddr(I) + FBase, icNotChecked);
  2186. List{$IFNDEF RTL230_UP}^{$ENDIF !RTL230_UP}[I] := ExportItem;
  2187. end;
  2188. if NameCount > 0 then
  2189. begin
  2190. for I := 0 to NameCount - 1 do
  2191. begin
  2192. // named function
  2193. UTF8Name := PAnsiChar(RvaToVa(Names^));
  2194. if not TryUTF8ToString(UTF8Name, ExportName) then
  2195. ExportName := string(UTF8Name);
  2196. ExportItem := TJclPeExportFuncItem(List{$IFNDEF RTL230_UP}^{$ENDIF !RTL230_UP}[NameOrdinals^]);
  2197. ExportItem.FName := ExportName;
  2198. ExportItem.FHint := I;
  2199. Inc(NameOrdinals);
  2200. Inc(Names);
  2201. end;
  2202. end;
  2203. end;
  2204. end;
  2205. end;
  2206. function TJclPeExportFuncList.GetForwardedLibsList: TStrings;
  2207. var
  2208. I: Integer;
  2209. begin
  2210. if FForwardedLibsList = nil then
  2211. begin
  2212. FForwardedLibsList := TStringList.Create;
  2213. FForwardedLibsList.Sorted := True;
  2214. FForwardedLibsList.Duplicates := dupIgnore;
  2215. if FAnyForwards then
  2216. for I := 0 to Count - 1 do
  2217. with Items[I] do
  2218. if IsForwarded then
  2219. FForwardedLibsList.AddObject(ForwardedLibName, Pointer(icNotChecked));
  2220. end;
  2221. Result := FForwardedLibsList;
  2222. end;
  2223. function TJclPeExportFuncList.GetItemFromAddress(Address: DWORD): TJclPeExportFuncItem;
  2224. var
  2225. I: Integer;
  2226. begin
  2227. Result := nil;
  2228. for I := 0 to Count - 1 do
  2229. if Items[I].Address = Address then
  2230. begin
  2231. Result := Items[I];
  2232. Break;
  2233. end;
  2234. end;
  2235. function TJclPeExportFuncList.GetItemFromName(const Name: string): TJclPeExportFuncItem;
  2236. var
  2237. L, H, I, C: Integer;
  2238. B: Boolean;
  2239. begin
  2240. Result := nil;
  2241. if CanPerformFastNameSearch then
  2242. begin
  2243. L := 0;
  2244. H := Count - 1;
  2245. B := False;
  2246. while L <= H do
  2247. begin
  2248. I := (L + H) shr 1;
  2249. C := CompareStr(Items[I].Name, Name);
  2250. if C < 0 then
  2251. L := I + 1
  2252. else
  2253. begin
  2254. H := I - 1;
  2255. if C = 0 then
  2256. begin
  2257. B := True;
  2258. L := I;
  2259. end;
  2260. end;
  2261. end;
  2262. if B then
  2263. Result := Items[L];
  2264. end
  2265. else
  2266. for I := 0 to Count - 1 do
  2267. if Items[I].Name = Name then
  2268. begin
  2269. Result := Items[I];
  2270. Break;
  2271. end;
  2272. end;
  2273. function TJclPeExportFuncList.GetItemFromOrdinal(Ordinal: DWORD): TJclPeExportFuncItem;
  2274. var
  2275. I: Integer;
  2276. begin
  2277. Result := nil;
  2278. for I := 0 to Count - 1 do
  2279. if Items[I].Ordinal = Ordinal then
  2280. begin
  2281. Result := Items[I];
  2282. Break;
  2283. end;
  2284. end;
  2285. function TJclPeExportFuncList.GetItems(Index: TJclListSize): TJclPeExportFuncItem;
  2286. begin
  2287. Result := TJclPeExportFuncItem(Get(Index));
  2288. end;
  2289. function TJclPeExportFuncList.GetName: string;
  2290. var
  2291. UTF8ExportName: TUTF8String;
  2292. begin
  2293. if (FExportDir = nil) or (FExportDir^.Name = 0) then
  2294. Result := ''
  2295. else
  2296. begin
  2297. UTF8ExportName := PAnsiChar(Image.RvaToVa(FExportDir^.Name));
  2298. if not TryUTF8ToString(UTF8ExportName, Result) then
  2299. Result := string(UTF8ExportName);
  2300. end;
  2301. end;
  2302. class function TJclPeExportFuncList.ItemName(Item: TJclPeExportFuncItem): string;
  2303. begin
  2304. if Item = nil then
  2305. Result := ''
  2306. else
  2307. Result := Item.Name;
  2308. end;
  2309. function TJclPeExportFuncList.OrdinalValid(Ordinal: DWORD): Boolean;
  2310. begin
  2311. Result := (FExportDir <> nil) and (Ordinal >= Base) and
  2312. (Ordinal < FunctionCount + Base);
  2313. end;
  2314. procedure TJclPeExportFuncList.PrepareForFastNameSearch;
  2315. begin
  2316. if not CanPerformFastNameSearch then
  2317. SortList(esName, False);
  2318. end;
  2319. function TJclPeExportFuncList.SmartFindName(const CompareName: string;
  2320. Options: TJclSmartCompOptions): TJclPeExportFuncItem;
  2321. var
  2322. I: Integer;
  2323. begin
  2324. Result := nil;
  2325. for I := 0 to Count - 1 do
  2326. begin
  2327. if PeSmartFunctionNameSame(CompareName, Items[I].Name, Options) then
  2328. begin
  2329. Result := Items[I];
  2330. Break;
  2331. end;
  2332. end;
  2333. end;
  2334. procedure TJclPeExportFuncList.SortList(SortType: TJclPeExportSort; Descending: Boolean);
  2335. const
  2336. SortFunctions: array [TJclPeExportSort, Boolean] of TListSortCompare =
  2337. ((ExportSortByName, ExportSortByNameDESC),
  2338. (ExportSortByOrdinal, ExportSortByOrdinalDESC),
  2339. (ExportSortByHint, ExportSortByHintDESC),
  2340. (ExportSortByAddress, ExportSortByAddressDESC),
  2341. (ExportSortByForwarded, ExportSortByForwardedDESC),
  2342. (ExportSortByAddrOrFwd, ExportSortByAddrOrFwdDESC),
  2343. (ExportSortBySection, ExportSortBySectionDESC)
  2344. );
  2345. begin
  2346. if not FSorted or (SortType <> FLastSortType) or (Descending <> FLastSortDescending) then
  2347. begin
  2348. Sort(SortFunctions[SortType, Descending]);
  2349. FLastSortType := SortType;
  2350. FLastSortDescending := Descending;
  2351. FSorted := True;
  2352. end;
  2353. end;
  2354. //=== { TJclPeResourceRawStream } ============================================
  2355. constructor TJclPeResourceRawStream.Create(AResourceItem: TJclPeResourceItem);
  2356. begin
  2357. Assert(not AResourceItem.IsDirectory);
  2358. inherited Create;
  2359. SetPointer(AResourceItem.RawEntryData, AResourceItem.RawEntryDataSize);
  2360. end;
  2361. function TJclPeResourceRawStream.Write(const Buffer; Count: Integer): Longint;
  2362. begin
  2363. raise EJclPeImageError.CreateRes(@RsPeReadOnlyStream);
  2364. end;
  2365. //=== { TJclPeResourceItem } =================================================
  2366. constructor TJclPeResourceItem.Create(AImage: TJclPeImage;
  2367. AParentItem: TJclPeResourceItem; AEntry: PImageResourceDirectoryEntry);
  2368. begin
  2369. inherited Create;
  2370. FImage := AImage;
  2371. FEntry := AEntry;
  2372. FParentItem := AParentItem;
  2373. if AParentItem = nil then
  2374. FLevel := 1
  2375. else
  2376. FLevel := AParentItem.Level + 1;
  2377. end;
  2378. destructor TJclPeResourceItem.Destroy;
  2379. begin
  2380. FreeAndNil(FList);
  2381. inherited Destroy;
  2382. end;
  2383. function TJclPeResourceItem.CompareName(AName: PChar): Boolean;
  2384. var
  2385. P: PChar;
  2386. begin
  2387. if IsName then
  2388. P := PChar(Name)
  2389. else
  2390. P := PChar(FEntry^.Name and $FFFF); // Integer encoded in a PChar
  2391. Result := CompareResourceName(AName, P);
  2392. end;
  2393. function TJclPeResourceItem.GetDataEntry: PImageResourceDataEntry;
  2394. begin
  2395. if GetIsDirectory then
  2396. Result := nil
  2397. else
  2398. Result := PImageResourceDataEntry(OffsetToRawData(FEntry^.OffsetToData));
  2399. end;
  2400. function TJclPeResourceItem.GetIsDirectory: Boolean;
  2401. begin
  2402. Result := FEntry^.OffsetToData and IMAGE_RESOURCE_DATA_IS_DIRECTORY <> 0;
  2403. end;
  2404. function TJclPeResourceItem.GetIsName: Boolean;
  2405. begin
  2406. Result := FEntry^.Name and IMAGE_RESOURCE_NAME_IS_STRING <> 0;
  2407. end;
  2408. function TJclPeResourceItem.GetLangID: LANGID;
  2409. begin
  2410. if IsDirectory then
  2411. begin
  2412. GetList;
  2413. if FList.Count = 1 then
  2414. Result := StrToIntDef(FList[0].Name, 0)
  2415. else
  2416. Result := 0;
  2417. end
  2418. else
  2419. Result := StrToIntDef(Name, 0);
  2420. end;
  2421. function TJclPeResourceItem.GetList: TJclPeResourceList;
  2422. begin
  2423. if not IsDirectory then
  2424. begin
  2425. if Image.NoExceptions then
  2426. begin
  2427. Result := nil;
  2428. Exit;
  2429. end
  2430. else
  2431. raise EJclPeImageError.CreateRes(@RsPeNotResDir);
  2432. end;
  2433. if FList = nil then
  2434. FList := FImage.ResourceListCreate(SubDirData, Self);
  2435. Result := FList;
  2436. end;
  2437. function TJclPeResourceItem.GetName: string;
  2438. begin
  2439. if IsName then
  2440. begin
  2441. if FNameCache = '' then
  2442. begin
  2443. with PImageResourceDirStringU(OffsetToRawData(FEntry^.Name))^ do
  2444. FNameCache := WideCharLenToString(NameString, Length);
  2445. StrResetLength(FNameCache);
  2446. end;
  2447. Result := FNameCache;
  2448. end
  2449. else
  2450. Result := IntToStr(FEntry^.Name and $FFFF);
  2451. end;
  2452. function TJclPeResourceItem.GetParameterName: string;
  2453. begin
  2454. if IsName then
  2455. Result := Name
  2456. else
  2457. Result := Format('#%d', [FEntry^.Name and $FFFF]);
  2458. end;
  2459. function TJclPeResourceItem.GetRawEntryData: Pointer;
  2460. begin
  2461. if GetIsDirectory then
  2462. Result := nil
  2463. else
  2464. Result := FImage.RvaToVa(GetDataEntry^.OffsetToData);
  2465. end;
  2466. function TJclPeResourceItem.GetRawEntryDataSize: Integer;
  2467. begin
  2468. if GetIsDirectory then
  2469. Result := -1
  2470. else
  2471. Result := PImageResourceDataEntry(OffsetToRawData(FEntry^.OffsetToData))^.Size;
  2472. end;
  2473. function TJclPeResourceItem.GetResourceType: TJclPeResourceKind;
  2474. begin
  2475. with Level1Item do
  2476. begin
  2477. if FEntry^.Name < Cardinal(High(TJclPeResourceKind)) then
  2478. Result := TJclPeResourceKind(FEntry^.Name)
  2479. else
  2480. Result := rtUserDefined
  2481. end;
  2482. end;
  2483. function TJclPeResourceItem.GetResourceTypeStr: string;
  2484. begin
  2485. with Level1Item do
  2486. begin
  2487. if FEntry^.Name < Cardinal(High(TJclPeResourceKind)) then
  2488. Result := Copy(GetEnumName(TypeInfo(TJclPeResourceKind), Ord(FEntry^.Name)), 3, 30)
  2489. else
  2490. Result := Name;
  2491. end;
  2492. end;
  2493. function TJclPeResourceItem.Level1Item: TJclPeResourceItem;
  2494. begin
  2495. Result := Self;
  2496. while Result.FParentItem <> nil do
  2497. Result := Result.FParentItem;
  2498. end;
  2499. function TJclPeResourceItem.OffsetToRawData(Ofs: DWORD): TJclAddr;
  2500. begin
  2501. Result := (Ofs and $7FFFFFFF) + Image.ResourceVA;
  2502. end;
  2503. function TJclPeResourceItem.SubDirData: PImageResourceDirectory;
  2504. begin
  2505. Result := Pointer(OffsetToRawData(FEntry^.OffsetToData));
  2506. end;
  2507. //=== { TJclPeResourceList } =================================================
  2508. constructor TJclPeResourceList.Create(AImage: TJclPeImage;
  2509. AParentItem: TJclPeResourceItem; ADirectory: PImageResourceDirectory);
  2510. begin
  2511. inherited Create(AImage);
  2512. FDirectory := ADirectory;
  2513. FParentItem := AParentItem;
  2514. CreateList(AParentItem);
  2515. end;
  2516. procedure TJclPeResourceList.CreateList(AParentItem: TJclPeResourceItem);
  2517. var
  2518. Entry: PImageResourceDirectoryEntry;
  2519. DirItem: TJclPeResourceItem;
  2520. I: Integer;
  2521. begin
  2522. if FDirectory = nil then
  2523. Exit;
  2524. Entry := Pointer(TJclAddr(FDirectory) + SizeOf(TImageResourceDirectory));
  2525. for I := 1 to DWORD(FDirectory^.NumberOfNamedEntries) + DWORD(FDirectory^.NumberOfIdEntries) do
  2526. begin
  2527. DirItem := Image.ResourceItemCreate(Entry, AParentItem);
  2528. Add(DirItem);
  2529. Inc(Entry);
  2530. end;
  2531. end;
  2532. function TJclPeResourceList.FindName(const Name: string): TJclPeResourceItem;
  2533. var
  2534. I: Integer;
  2535. begin
  2536. Result := nil;
  2537. for I := 0 to Count - 1 do
  2538. if StrSame(Items[I].Name, Name) then
  2539. begin
  2540. Result := Items[I];
  2541. Break;
  2542. end;
  2543. end;
  2544. function TJclPeResourceList.GetItems(Index: TJclListSize): TJclPeResourceItem;
  2545. begin
  2546. Result := TJclPeResourceItem(Get(Index));
  2547. end;
  2548. //=== { TJclPeRootResourceList } =============================================
  2549. destructor TJclPeRootResourceList.Destroy;
  2550. begin
  2551. FreeAndNil(FManifestContent);
  2552. inherited Destroy;
  2553. end;
  2554. function TJclPeRootResourceList.FindResource(ResourceType: TJclPeResourceKind;
  2555. const ResourceName: string): TJclPeResourceItem;
  2556. var
  2557. I: Integer;
  2558. TypeItem: TJclPeResourceItem;
  2559. begin
  2560. Result := nil;
  2561. TypeItem := nil;
  2562. for I := 0 to Count - 1 do
  2563. begin
  2564. if Items[I].ResourceType = ResourceType then
  2565. begin
  2566. TypeItem := Items[I];
  2567. Break;
  2568. end;
  2569. end;
  2570. if TypeItem <> nil then
  2571. if ResourceName = '' then
  2572. Result := TypeItem
  2573. else
  2574. with TypeItem.List do
  2575. for I := 0 to Count - 1 do
  2576. if Items[I].Name = ResourceName then
  2577. begin
  2578. Result := Items[I];
  2579. Break;
  2580. end;
  2581. end;
  2582. function TJclPeRootResourceList.FindResource(const ResourceType: PChar;
  2583. const ResourceName: PChar): TJclPeResourceItem;
  2584. var
  2585. I: Integer;
  2586. TypeItem: TJclPeResourceItem;
  2587. begin
  2588. Result := nil;
  2589. TypeItem := nil;
  2590. for I := 0 to Count - 1 do
  2591. if Items[I].CompareName(ResourceType) then
  2592. begin
  2593. TypeItem := Items[I];
  2594. Break;
  2595. end;
  2596. if TypeItem <> nil then
  2597. if ResourceName = nil then
  2598. Result := TypeItem
  2599. else
  2600. with TypeItem.List do
  2601. for I := 0 to Count - 1 do
  2602. if Items[I].CompareName(ResourceName) then
  2603. begin
  2604. Result := Items[I];
  2605. Break;
  2606. end;
  2607. end;
  2608. function TJclPeRootResourceList.GetManifestContent: TStrings;
  2609. var
  2610. ManifestFileName: string;
  2611. ResItem: TJclPeResourceItem;
  2612. ResStream: TJclPeResourceRawStream;
  2613. begin
  2614. if FManifestContent = nil then
  2615. begin
  2616. FManifestContent := TStringList.Create;
  2617. ResItem := FindResource(RT_MANIFEST, CREATEPROCESS_MANIFEST_RESOURCE_ID);
  2618. if ResItem = nil then
  2619. begin
  2620. ManifestFileName := Image.FileName + MANIFESTExtension;
  2621. if FileExists(ManifestFileName) then
  2622. FManifestContent.LoadFromFile(ManifestFileName);
  2623. end
  2624. else
  2625. begin
  2626. ResStream := TJclPeResourceRawStream.Create(ResItem.List[0]);
  2627. try
  2628. FManifestContent.LoadFromStream(ResStream);
  2629. finally
  2630. ResStream.Free;
  2631. end;
  2632. end;
  2633. end;
  2634. Result := FManifestContent;
  2635. end;
  2636. function TJclPeRootResourceList.ListResourceNames(ResourceType: TJclPeResourceKind;
  2637. const Strings: TStrings): Boolean;
  2638. var
  2639. ResTypeItem, TempItem: TJclPeResourceItem;
  2640. I: Integer;
  2641. begin
  2642. ResTypeItem := FindResource(ResourceType, '');
  2643. Result := (ResTypeItem <> nil);
  2644. if Result then
  2645. begin
  2646. Strings.BeginUpdate;
  2647. try
  2648. with ResTypeItem.List do
  2649. for I := 0 to Count - 1 do
  2650. begin
  2651. TempItem := Items[I];
  2652. Strings.AddObject(TempItem.Name, Pointer(TempItem.IsName));
  2653. end;
  2654. finally
  2655. Strings.EndUpdate;
  2656. end;
  2657. end;
  2658. end;
  2659. //=== { TJclPeRelocEntry } ===================================================
  2660. constructor TJclPeRelocEntry.Create(AChunk: PImageBaseRelocation; ACount: Integer);
  2661. begin
  2662. inherited Create;
  2663. FChunk := AChunk;
  2664. FCount := ACount;
  2665. end;
  2666. function TJclPeRelocEntry.GetRelocations(Index: Integer): TJclPeRelocation;
  2667. var
  2668. Temp: Word;
  2669. begin
  2670. Temp := PWord(TJclAddr(FChunk) + SizeOf(TImageBaseRelocation) + DWORD(Index) * SizeOf(Word))^;
  2671. Result.Address := Temp and $0FFF;
  2672. Result.RelocType := (Temp and $F000) shr 12;
  2673. Result.VirtualAddress := TJclAddr(Result.Address) + VirtualAddress;
  2674. end;
  2675. function TJclPeRelocEntry.GetSize: DWORD;
  2676. begin
  2677. Result := FChunk^.SizeOfBlock;
  2678. end;
  2679. function TJclPeRelocEntry.GetVirtualAddress: DWORD;
  2680. begin
  2681. Result := FChunk^.VirtualAddress;
  2682. end;
  2683. //=== { TJclPeRelocList } ====================================================
  2684. constructor TJclPeRelocList.Create(AImage: TJclPeImage);
  2685. begin
  2686. inherited Create(AImage);
  2687. CreateList;
  2688. end;
  2689. procedure TJclPeRelocList.CreateList;
  2690. var
  2691. Chunk: PImageBaseRelocation;
  2692. Item: TJclPeRelocEntry;
  2693. RelocCount: Integer;
  2694. begin
  2695. with Image do
  2696. begin
  2697. if not StatusOK then
  2698. Exit;
  2699. Chunk := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_BASERELOC);
  2700. if Chunk = nil then
  2701. Exit;
  2702. FAllItemCount := 0;
  2703. while Chunk^.SizeOfBlock <> 0 do
  2704. begin
  2705. RelocCount := (Chunk^.SizeOfBlock - SizeOf(TImageBaseRelocation)) div SizeOf(Word);
  2706. Item := TJclPeRelocEntry.Create(Chunk, RelocCount);
  2707. Inc(FAllItemCount, RelocCount);
  2708. Add(Item);
  2709. Chunk := Pointer(TJclAddr(Chunk) + Chunk^.SizeOfBlock);
  2710. end;
  2711. end;
  2712. end;
  2713. function TJclPeRelocList.GetAllItems(Index: Integer): TJclPeRelocation;
  2714. var
  2715. I, N, C: Integer;
  2716. begin
  2717. N := Index;
  2718. for I := 0 to Count - 1 do
  2719. begin
  2720. C := Items[I].Count;
  2721. Dec(N, C);
  2722. if N < 0 then
  2723. begin
  2724. Result := Items[I][N + C];
  2725. Break;
  2726. end;
  2727. end;
  2728. end;
  2729. function TJclPeRelocList.GetItems(Index: TJclListSize): TJclPeRelocEntry;
  2730. begin
  2731. Result := TJclPeRelocEntry(Get(Index));
  2732. end;
  2733. //=== { TJclPeDebugList } ====================================================
  2734. constructor TJclPeDebugList.Create(AImage: TJclPeImage);
  2735. begin
  2736. inherited Create(AImage);
  2737. OwnsObjects := False;
  2738. CreateList;
  2739. end;
  2740. function TJclPeDebugList.IsTD32DebugInfo(DebugDir: PImageDebugDirectory): Boolean;
  2741. var
  2742. Base: Pointer;
  2743. begin
  2744. Base := Image.RvaToVa(DebugDir^.AddressOfRawData);
  2745. Result := TJclTD32InfoParser.IsTD32DebugInfoValid(Base, DebugDir^.SizeOfData);
  2746. end;
  2747. procedure TJclPeDebugList.CreateList;
  2748. var
  2749. DebugImageDir: TImageDataDirectory;
  2750. DebugDir: PImageDebugDirectory;
  2751. Header: PImageSectionHeader;
  2752. FormatCount, I: Integer;
  2753. begin
  2754. with Image do
  2755. begin
  2756. if not StatusOK then
  2757. Exit;
  2758. DebugImageDir := Directories[IMAGE_DIRECTORY_ENTRY_DEBUG];
  2759. if DebugImageDir.VirtualAddress = 0 then
  2760. Exit;
  2761. if GetSectionHeader(DebugSectionName, Header) and
  2762. (Header^.VirtualAddress = DebugImageDir.VirtualAddress) and
  2763. (IsTD32DebugInfo(RvaToVa(DebugImageDir.VirtualAddress))) then
  2764. begin
  2765. // TD32 debug image directory is broken...size should be in bytes, not count.
  2766. FormatCount := DebugImageDir.Size;
  2767. end
  2768. else
  2769. begin
  2770. FormatCount := DebugImageDir.Size div SizeOf(TImageDebugDirectory);
  2771. end;
  2772. DebugDir := RvaToVa(DebugImageDir.VirtualAddress);
  2773. for I := 1 to FormatCount do
  2774. begin
  2775. Add(TObject(DebugDir));
  2776. Inc(DebugDir);
  2777. end;
  2778. end;
  2779. end;
  2780. function TJclPeDebugList.GetItems(Index: TJclListSize): TImageDebugDirectory;
  2781. begin
  2782. Result := PImageDebugDirectory(Get(Index))^;
  2783. end;
  2784. //=== { TJclPeCertificate } ==================================================
  2785. constructor TJclPeCertificate.Create(AHeader: TWinCertificate; AData: Pointer);
  2786. begin
  2787. inherited Create;
  2788. FHeader := AHeader;
  2789. FData := AData;
  2790. end;
  2791. //=== { TJclPeCertificateList } ==============================================
  2792. constructor TJclPeCertificateList.Create(AImage: TJclPeImage);
  2793. begin
  2794. inherited Create(AImage);
  2795. CreateList;
  2796. end;
  2797. procedure TJclPeCertificateList.CreateList;
  2798. var
  2799. Directory: TImageDataDirectory;
  2800. CertPtr: PChar;
  2801. TotalSize: Integer;
  2802. Item: TJclPeCertificate;
  2803. begin
  2804. Directory := Image.Directories[IMAGE_DIRECTORY_ENTRY_SECURITY];
  2805. if Directory.VirtualAddress = 0 then
  2806. Exit;
  2807. CertPtr := Image.RawToVa(Directory.VirtualAddress); // Security directory is a raw offset
  2808. TotalSize := Directory.Size;
  2809. while TotalSize >= SizeOf(TWinCertificate) do
  2810. begin
  2811. Item := TJclPeCertificate.Create(PWinCertificate(CertPtr)^, CertPtr + SizeOf(TWinCertificate));
  2812. Dec(TotalSize, Item.Header.dwLength);
  2813. Add(Item);
  2814. end;
  2815. end;
  2816. function TJclPeCertificateList.GetItems(Index: TJclListSize): TJclPeCertificate;
  2817. begin
  2818. Result := TJclPeCertificate(Get(Index));
  2819. end;
  2820. //=== { TJclPeCLRHeader } ====================================================
  2821. constructor TJclPeCLRHeader.Create(AImage: TJclPeImage);
  2822. begin
  2823. FImage := AImage;
  2824. ReadHeader;
  2825. end;
  2826. function TJclPeCLRHeader.GetHasMetadata: Boolean;
  2827. const
  2828. METADATA_SIGNATURE = $424A5342; // Reference: Partition II Metadata.doc - 23.2.1 Metadata root
  2829. begin
  2830. with Header.MetaData do
  2831. Result := (VirtualAddress <> 0) and (PDWORD(FImage.RvaToVa(VirtualAddress))^ = METADATA_SIGNATURE);
  2832. end;
  2833. { TODO -cDOC : "Flier Lu" <flier_lu att yahoo dott com dott cn> }
  2834. function TJclPeCLRHeader.GetVersionString: string;
  2835. begin
  2836. Result := FormatVersionString(Header.MajorRuntimeVersion, Header.MinorRuntimeVersion);
  2837. end;
  2838. procedure TJclPeCLRHeader.ReadHeader;
  2839. var
  2840. HeaderPtr: PImageCor20Header;
  2841. begin
  2842. HeaderPtr := Image.DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR);
  2843. if (HeaderPtr <> nil) and (HeaderPtr^.cb >= SizeOf(TImageCor20Header)) then
  2844. FHeader := HeaderPtr^;
  2845. end;
  2846. //=== { TJclPeImage } ========================================================
  2847. constructor TJclPeImage.Create(ANoExceptions: Boolean);
  2848. begin
  2849. FNoExceptions := ANoExceptions;
  2850. FReadOnlyAccess := True;
  2851. FImageSections := TStringList.Create;
  2852. FStringTable := TStringList.Create;
  2853. end;
  2854. destructor TJclPeImage.Destroy;
  2855. begin
  2856. Clear;
  2857. FreeAndNil(FImageSections);
  2858. FStringTable.Free;
  2859. inherited Destroy;
  2860. end;
  2861. procedure TJclPeImage.AfterOpen;
  2862. begin
  2863. end;
  2864. procedure TJclPeImage.AttachLoadedModule(const Handle: HMODULE);
  2865. procedure AttachLoadedModule32;
  2866. var
  2867. NtHeaders: PImageNtHeaders32;
  2868. begin
  2869. NtHeaders := PeMapImgNtHeaders32(Pointer(Handle));
  2870. if NtHeaders = nil then
  2871. FStatus := stNotPE
  2872. else
  2873. begin
  2874. FStatus := stOk;
  2875. FAttachedImage := True;
  2876. FFileName := GetModulePath(Handle);
  2877. // OF: possible loss of data
  2878. FLoadedImage.ModuleName := PAnsiChar(AnsiString(FFileName));
  2879. FLoadedImage.hFile := INVALID_HANDLE_VALUE;
  2880. FLoadedImage.MappedAddress := Pointer(Handle);
  2881. FLoadedImage.FileHeader := PImageNtHeaders(NtHeaders);
  2882. FLoadedImage.NumberOfSections := NtHeaders^.FileHeader.NumberOfSections;
  2883. FLoadedImage.Sections := PeMapImgSections32(NtHeaders);
  2884. FLoadedImage.LastRvaSection := FLoadedImage.Sections;
  2885. FLoadedImage.Characteristics := NtHeaders^.FileHeader.Characteristics;
  2886. FLoadedImage.fSystemImage := (FLoadedImage.Characteristics and IMAGE_FILE_SYSTEM <> 0);
  2887. FLoadedImage.fDOSImage := False;
  2888. FLoadedImage.SizeOfImage := NtHeaders^.OptionalHeader.SizeOfImage;
  2889. ReadImageSections;
  2890. ReadStringTable;
  2891. AfterOpen;
  2892. end;
  2893. RaiseStatusException;
  2894. end;
  2895. procedure AttachLoadedModule64;
  2896. var
  2897. NtHeaders: PImageNtHeaders64;
  2898. begin
  2899. NtHeaders := PeMapImgNtHeaders64(Pointer(Handle));
  2900. if NtHeaders = nil then
  2901. FStatus := stNotPE
  2902. else
  2903. begin
  2904. FStatus := stOk;
  2905. FAttachedImage := True;
  2906. FFileName := GetModulePath(Handle);
  2907. // OF: possible loss of data
  2908. FLoadedImage.ModuleName := PAnsiChar(AnsiString(FFileName));
  2909. FLoadedImage.hFile := INVALID_HANDLE_VALUE;
  2910. FLoadedImage.MappedAddress := Pointer(Handle);
  2911. FLoadedImage.FileHeader := PImageNtHeaders(NtHeaders);
  2912. FLoadedImage.NumberOfSections := NtHeaders^.FileHeader.NumberOfSections;
  2913. FLoadedImage.Sections := PeMapImgSections64(NtHeaders);
  2914. FLoadedImage.LastRvaSection := FLoadedImage.Sections;
  2915. FLoadedImage.Characteristics := NtHeaders^.FileHeader.Characteristics;
  2916. FLoadedImage.fSystemImage := (FLoadedImage.Characteristics and IMAGE_FILE_SYSTEM <> 0);
  2917. FLoadedImage.fDOSImage := False;
  2918. FLoadedImage.SizeOfImage := NtHeaders^.OptionalHeader.SizeOfImage;
  2919. ReadImageSections;
  2920. ReadStringTable;
  2921. AfterOpen;
  2922. end;
  2923. RaiseStatusException;
  2924. end;
  2925. begin
  2926. Clear;
  2927. if Handle = 0 then
  2928. Exit;
  2929. FTarget := PeMapImgTarget(Pointer(Handle));
  2930. case Target of
  2931. taWin32:
  2932. AttachLoadedModule32;
  2933. taWin64:
  2934. AttachLoadedModule64;
  2935. taUnknown:
  2936. FStatus := stNotSupported;
  2937. end;
  2938. end;
  2939. function TJclPeImage.CalculateCheckSum: DWORD;
  2940. var
  2941. C: DWORD;
  2942. begin
  2943. if StatusOK then
  2944. begin
  2945. CheckNotAttached;
  2946. if CheckSumMappedFile(FLoadedImage.MappedAddress, FLoadedImage.SizeOfImage,
  2947. C, Result) = nil then
  2948. RaiseLastOSError;
  2949. end
  2950. else
  2951. Result := 0;
  2952. end;
  2953. procedure TJclPeImage.CheckNotAttached;
  2954. begin
  2955. if FAttachedImage then
  2956. raise EJclPeImageError.CreateRes(@RsPeNotAvailableForAttached);
  2957. end;
  2958. procedure TJclPeImage.Clear;
  2959. begin
  2960. FImageSections.Clear;
  2961. FStringTable.Clear;
  2962. FreeAndNil(FCertificateList);
  2963. FreeAndNil(FCLRHeader);
  2964. FreeAndNil(FDebugList);
  2965. FreeAndNil(FImportList);
  2966. FreeAndNil(FExportList);
  2967. FreeAndNil(FRelocationList);
  2968. FreeAndNil(FResourceList);
  2969. FreeAndNil(FVersionInfo);
  2970. if not FAttachedImage and StatusOK then
  2971. UnMapAndLoad(FLoadedImage);
  2972. ResetMemory(FLoadedImage, SizeOf(FLoadedImage));
  2973. FStatus := stNotLoaded;
  2974. FAttachedImage := False;
  2975. end;
  2976. class function TJclPeImage.DateTimeToStamp(const DateTime: TDateTime): DWORD;
  2977. begin
  2978. Result := Round((DateTime - UnixTimeStart) * SecsPerDay);
  2979. end;
  2980. class function TJclPeImage.DebugTypeNames(DebugType: DWORD): string;
  2981. begin
  2982. case DebugType of
  2983. IMAGE_DEBUG_TYPE_UNKNOWN:
  2984. Result := LoadResString(@RsPeDEBUG_UNKNOWN);
  2985. IMAGE_DEBUG_TYPE_COFF:
  2986. Result := LoadResString(@RsPeDEBUG_COFF);
  2987. IMAGE_DEBUG_TYPE_CODEVIEW:
  2988. Result := LoadResString(@RsPeDEBUG_CODEVIEW);
  2989. IMAGE_DEBUG_TYPE_FPO:
  2990. Result := LoadResString(@RsPeDEBUG_FPO);
  2991. IMAGE_DEBUG_TYPE_MISC:
  2992. Result := LoadResString(@RsPeDEBUG_MISC);
  2993. IMAGE_DEBUG_TYPE_EXCEPTION:
  2994. Result := LoadResString(@RsPeDEBUG_EXCEPTION);
  2995. IMAGE_DEBUG_TYPE_FIXUP:
  2996. Result := LoadResString(@RsPeDEBUG_FIXUP);
  2997. IMAGE_DEBUG_TYPE_OMAP_TO_SRC:
  2998. Result := LoadResString(@RsPeDEBUG_OMAP_TO_SRC);
  2999. IMAGE_DEBUG_TYPE_OMAP_FROM_SRC:
  3000. Result := LoadResString(@RsPeDEBUG_OMAP_FROM_SRC);
  3001. else
  3002. Result := LoadResString(@RsPeDEBUG_UNKNOWN);
  3003. end;
  3004. end;
  3005. function TJclPeImage.DirectoryEntryToData(Directory: Word): Pointer;
  3006. var
  3007. Size: DWORD;
  3008. begin
  3009. Size := 0;
  3010. Result := ImageDirectoryEntryToData(FLoadedImage.MappedAddress, FAttachedImage, Directory, Size);
  3011. end;
  3012. class function TJclPeImage.DirectoryNames(Directory: Word): string;
  3013. begin
  3014. case Directory of
  3015. IMAGE_DIRECTORY_ENTRY_EXPORT:
  3016. Result := LoadResString(@RsPeImg_00);
  3017. IMAGE_DIRECTORY_ENTRY_IMPORT:
  3018. Result := LoadResString(@RsPeImg_01);
  3019. IMAGE_DIRECTORY_ENTRY_RESOURCE:
  3020. Result := LoadResString(@RsPeImg_02);
  3021. IMAGE_DIRECTORY_ENTRY_EXCEPTION:
  3022. Result := LoadResString(@RsPeImg_03);
  3023. IMAGE_DIRECTORY_ENTRY_SECURITY:
  3024. Result := LoadResString(@RsPeImg_04);
  3025. IMAGE_DIRECTORY_ENTRY_BASERELOC:
  3026. Result := LoadResString(@RsPeImg_05);
  3027. IMAGE_DIRECTORY_ENTRY_DEBUG:
  3028. Result := LoadResString(@RsPeImg_06);
  3029. IMAGE_DIRECTORY_ENTRY_COPYRIGHT:
  3030. Result := LoadResString(@RsPeImg_07);
  3031. IMAGE_DIRECTORY_ENTRY_GLOBALPTR:
  3032. Result := LoadResString(@RsPeImg_08);
  3033. IMAGE_DIRECTORY_ENTRY_TLS:
  3034. Result := LoadResString(@RsPeImg_09);
  3035. IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG:
  3036. Result := LoadResString(@RsPeImg_10);
  3037. IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT:
  3038. Result := LoadResString(@RsPeImg_11);
  3039. IMAGE_DIRECTORY_ENTRY_IAT:
  3040. Result := LoadResString(@RsPeImg_12);
  3041. IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT:
  3042. Result := LoadResString(@RsPeImg_13);
  3043. IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR:
  3044. Result := LoadResString(@RsPeImg_14);
  3045. else
  3046. Result := Format(LoadResString(@RsPeImg_Reserved), [Directory]);
  3047. end;
  3048. end;
  3049. class function TJclPeImage.ExpandBySearchPath(const ModuleName, BasePath: string): TFileName;
  3050. var
  3051. FullName: array [0..MAX_PATH] of Char;
  3052. FilePart: PChar;
  3053. begin
  3054. Result := PathAddSeparator(ExtractFilePath(BasePath)) + ModuleName;
  3055. if FileExists(Result) then
  3056. Exit;
  3057. FilePart := nil;
  3058. if SearchPath(nil, PChar(ModuleName), nil, Length(FullName), FullName, FilePart) = 0 then
  3059. Result := ModuleName
  3060. else
  3061. Result := FullName;
  3062. end;
  3063. function TJclPeImage.ExpandModuleName(const ModuleName: string): TFileName;
  3064. begin
  3065. Result := ExpandBySearchPath(ModuleName, ExtractFilePath(FFileName));
  3066. end;
  3067. function TJclPeImage.GetCertificateList: TJclPeCertificateList;
  3068. begin
  3069. if FCertificateList = nil then
  3070. FCertificateList := TJclPeCertificateList.Create(Self);
  3071. Result := FCertificateList;
  3072. end;
  3073. function TJclPeImage.GetCLRHeader: TJclPeCLRHeader;
  3074. begin
  3075. if FCLRHeader = nil then
  3076. FCLRHeader := TJclPeCLRHeader.Create(Self);
  3077. Result := FCLRHeader;
  3078. end;
  3079. function TJclPeImage.GetDebugList: TJclPeDebugList;
  3080. begin
  3081. if FDebugList = nil then
  3082. FDebugList := TJclPeDebugList.Create(Self);
  3083. Result := FDebugList;
  3084. end;
  3085. function TJclPeImage.GetDescription: string;
  3086. var
  3087. UTF8DescriptionName: TUTF8String;
  3088. begin
  3089. if DirectoryExists[IMAGE_DIRECTORY_ENTRY_COPYRIGHT] then
  3090. begin
  3091. UTF8DescriptionName := PAnsiChar(DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_COPYRIGHT));
  3092. if not TryUTF8ToString(UTF8DescriptionName, Result) then
  3093. Result := string(UTF8DescriptionName);
  3094. end
  3095. else
  3096. Result := '';
  3097. end;
  3098. function TJclPeImage.GetDirectories(Directory: Word): TImageDataDirectory;
  3099. begin
  3100. if StatusOK then
  3101. begin
  3102. case Target of
  3103. taWin32:
  3104. Result := PImageNtHeaders32(FLoadedImage.FileHeader)^.OptionalHeader.DataDirectory[Directory];
  3105. taWin64:
  3106. Result := PImageNtHeaders64(FLoadedImage.FileHeader)^.OptionalHeader.DataDirectory[Directory];
  3107. else
  3108. Result.VirtualAddress := 0;
  3109. Result.Size := 0;
  3110. end
  3111. end
  3112. else
  3113. begin
  3114. Result.VirtualAddress := 0;
  3115. Result.Size := 0;
  3116. end;
  3117. end;
  3118. function TJclPeImage.GetDirectoryExists(Directory: Word): Boolean;
  3119. begin
  3120. Result := (Directories[Directory].VirtualAddress <> 0);
  3121. end;
  3122. function TJclPeImage.GetExportList: TJclPeExportFuncList;
  3123. begin
  3124. if FExportList = nil then
  3125. FExportList := TJclPeExportFuncList.Create(Self);
  3126. Result := FExportList;
  3127. end;
  3128. function TJclPeImage.GetFileProperties: TJclPeFileProperties;
  3129. var
  3130. FileAttributesEx: WIN32_FILE_ATTRIBUTE_DATA;
  3131. Size: TJclULargeInteger;
  3132. begin
  3133. ResetMemory(Result, SizeOf(Result));
  3134. if GetFileAttributesEx(PChar(FileName), GetFileExInfoStandard, @FileAttributesEx) then
  3135. begin
  3136. Size.LowPart := FileAttributesEx.nFileSizeLow;
  3137. Size.HighPart := FileAttributesEx.nFileSizeHigh;
  3138. Result.Size := Size.QuadPart;
  3139. Result.CreationTime := FileTimeToLocalDateTime(FileAttributesEx.ftCreationTime);
  3140. Result.LastAccessTime := FileTimeToLocalDateTime(FileAttributesEx.ftLastAccessTime);
  3141. Result.LastWriteTime := FileTimeToLocalDateTime(FileAttributesEx.ftLastWriteTime);
  3142. Result.Attributes := FileAttributesEx.dwFileAttributes;
  3143. end;
  3144. end;
  3145. function TJclPeImage.GetHeaderValues(Index: TJclPeHeader): string;
  3146. function GetMachineString(Value: DWORD): string;
  3147. begin
  3148. case Value of
  3149. IMAGE_FILE_MACHINE_UNKNOWN:
  3150. Result := LoadResString(@RsPeMACHINE_UNKNOWN);
  3151. IMAGE_FILE_MACHINE_I386:
  3152. Result := LoadResString(@RsPeMACHINE_I386);
  3153. IMAGE_FILE_MACHINE_R3000:
  3154. Result := LoadResString(@RsPeMACHINE_R3000);
  3155. IMAGE_FILE_MACHINE_R4000:
  3156. Result := LoadResString(@RsPeMACHINE_R4000);
  3157. IMAGE_FILE_MACHINE_R10000:
  3158. Result := LoadResString(@RsPeMACHINE_R10000);
  3159. IMAGE_FILE_MACHINE_WCEMIPSV2:
  3160. Result := LoadResString(@RsPeMACHINE_WCEMIPSV2);
  3161. IMAGE_FILE_MACHINE_ALPHA:
  3162. Result := LoadResString(@RsPeMACHINE_ALPHA);
  3163. IMAGE_FILE_MACHINE_SH3:
  3164. Result := LoadResString(@RsPeMACHINE_SH3); // SH3 little-endian
  3165. IMAGE_FILE_MACHINE_SH3DSP:
  3166. Result := LoadResString(@RsPeMACHINE_SH3DSP);
  3167. IMAGE_FILE_MACHINE_SH3E:
  3168. Result := LoadResString(@RsPeMACHINE_SH3E); // SH3E little-endian
  3169. IMAGE_FILE_MACHINE_SH4:
  3170. Result := LoadResString(@RsPeMACHINE_SH4); // SH4 little-endian
  3171. IMAGE_FILE_MACHINE_SH5:
  3172. Result := LoadResString(@RsPeMACHINE_SH5); // SH5
  3173. IMAGE_FILE_MACHINE_ARM:
  3174. Result := LoadResString(@RsPeMACHINE_ARM); // ARM Little-Endian
  3175. IMAGE_FILE_MACHINE_THUMB:
  3176. Result := LoadResString(@RsPeMACHINE_THUMB);
  3177. IMAGE_FILE_MACHINE_AM33:
  3178. Result := LoadResString(@RsPeMACHINE_AM33);
  3179. IMAGE_FILE_MACHINE_POWERPC:
  3180. Result := LoadResString(@RsPeMACHINE_POWERPC);
  3181. IMAGE_FILE_MACHINE_POWERPCFP:
  3182. Result := LoadResString(@RsPeMACHINE_POWERPCFP);
  3183. IMAGE_FILE_MACHINE_IA64:
  3184. Result := LoadResString(@RsPeMACHINE_IA64); // Intel 64
  3185. IMAGE_FILE_MACHINE_MIPS16:
  3186. Result := LoadResString(@RsPeMACHINE_MIPS16); // MIPS
  3187. IMAGE_FILE_MACHINE_ALPHA64:
  3188. Result := LoadResString(@RsPeMACHINE_AMPHA64); // ALPHA64
  3189. //IMAGE_FILE_MACHINE_AXP64
  3190. IMAGE_FILE_MACHINE_MIPSFPU:
  3191. Result := LoadResString(@RsPeMACHINE_MIPSFPU); // MIPS
  3192. IMAGE_FILE_MACHINE_MIPSFPU16:
  3193. Result := LoadResString(@RsPeMACHINE_MIPSFPU16); // MIPS
  3194. IMAGE_FILE_MACHINE_TRICORE:
  3195. Result := LoadResString(@RsPeMACHINE_TRICORE); // Infineon
  3196. IMAGE_FILE_MACHINE_CEF:
  3197. Result := LoadResString(@RsPeMACHINE_CEF);
  3198. IMAGE_FILE_MACHINE_EBC:
  3199. Result := LoadResString(@RsPeMACHINE_EBC); // EFI Byte Code
  3200. IMAGE_FILE_MACHINE_AMD64:
  3201. Result := LoadResString(@RsPeMACHINE_AMD64); // AMD64 (K8)
  3202. IMAGE_FILE_MACHINE_M32R:
  3203. Result := LoadResString(@RsPeMACHINE_M32R); // M32R little-endian
  3204. IMAGE_FILE_MACHINE_CEE:
  3205. Result := LoadResString(@RsPeMACHINE_CEE);
  3206. else
  3207. Result := Format('[%.8x]', [Value]);
  3208. end;
  3209. end;
  3210. function GetSubsystemString(Value: DWORD): string;
  3211. begin
  3212. case Value of
  3213. IMAGE_SUBSYSTEM_UNKNOWN:
  3214. Result := LoadResString(@RsPeSUBSYSTEM_UNKNOWN);
  3215. IMAGE_SUBSYSTEM_NATIVE:
  3216. Result := LoadResString(@RsPeSUBSYSTEM_NATIVE);
  3217. IMAGE_SUBSYSTEM_WINDOWS_GUI:
  3218. Result := LoadResString(@RsPeSUBSYSTEM_WINDOWS_GUI);
  3219. IMAGE_SUBSYSTEM_WINDOWS_CUI:
  3220. Result := LoadResString(@RsPeSUBSYSTEM_WINDOWS_CUI);
  3221. IMAGE_SUBSYSTEM_OS2_CUI:
  3222. Result := LoadResString(@RsPeSUBSYSTEM_OS2_CUI);
  3223. IMAGE_SUBSYSTEM_POSIX_CUI:
  3224. Result := LoadResString(@RsPeSUBSYSTEM_POSIX_CUI);
  3225. IMAGE_SUBSYSTEM_RESERVED8:
  3226. Result := LoadResString(@RsPeSUBSYSTEM_RESERVED8);
  3227. else
  3228. Result := Format('[%.8x]', [Value]);
  3229. end;
  3230. end;
  3231. function GetHeaderValues32(Index: TJclPeHeader): string;
  3232. var
  3233. OptionalHeader: TImageOptionalHeader32;
  3234. begin
  3235. OptionalHeader := OptionalHeader32;
  3236. case Index of
  3237. JclPeHeader_Magic:
  3238. Result := IntToHex(OptionalHeader.Magic, 4);
  3239. JclPeHeader_LinkerVersion:
  3240. Result := FormatVersionString(OptionalHeader.MajorLinkerVersion, OptionalHeader.MinorLinkerVersion);
  3241. JclPeHeader_SizeOfCode:
  3242. Result := IntToHex(OptionalHeader.SizeOfCode, 8);
  3243. JclPeHeader_SizeOfInitializedData:
  3244. Result := IntToHex(OptionalHeader.SizeOfInitializedData, 8);
  3245. JclPeHeader_SizeOfUninitializedData:
  3246. Result := IntToHex(OptionalHeader.SizeOfUninitializedData, 8);
  3247. JclPeHeader_AddressOfEntryPoint:
  3248. Result := IntToHex(OptionalHeader.AddressOfEntryPoint, 8);
  3249. JclPeHeader_BaseOfCode:
  3250. Result := IntToHex(OptionalHeader.BaseOfCode, 8);
  3251. JclPeHeader_BaseOfData:
  3252. {$IFDEF DELPHI64_TEMPORARY}
  3253. System.Error(rePlatformNotImplemented);
  3254. {$ELSE ~DELPHI64_TEMPORARY}
  3255. Result := IntToHex(OptionalHeader.BaseOfData, 8);
  3256. {$ENDIF ~DELPHI64_TEMPORARY}
  3257. JclPeHeader_ImageBase:
  3258. Result := IntToHex(OptionalHeader.ImageBase, 8);
  3259. JclPeHeader_SectionAlignment:
  3260. Result := IntToHex(OptionalHeader.SectionAlignment, 8);
  3261. JclPeHeader_FileAlignment:
  3262. Result := IntToHex(OptionalHeader.FileAlignment, 8);
  3263. JclPeHeader_OperatingSystemVersion:
  3264. Result := FormatVersionString(OptionalHeader.MajorOperatingSystemVersion, OptionalHeader.MinorOperatingSystemVersion);
  3265. JclPeHeader_ImageVersion:
  3266. Result := FormatVersionString(OptionalHeader.MajorImageVersion, OptionalHeader.MinorImageVersion);
  3267. JclPeHeader_SubsystemVersion:
  3268. Result := FormatVersionString(OptionalHeader.MajorSubsystemVersion, OptionalHeader.MinorSubsystemVersion);
  3269. JclPeHeader_Win32VersionValue:
  3270. Result := IntToHex(OptionalHeader.Win32VersionValue, 8);
  3271. JclPeHeader_SizeOfImage:
  3272. Result := IntToHex(OptionalHeader.SizeOfImage, 8);
  3273. JclPeHeader_SizeOfHeaders:
  3274. Result := IntToHex(OptionalHeader.SizeOfHeaders, 8);
  3275. JclPeHeader_CheckSum:
  3276. Result := IntToHex(OptionalHeader.CheckSum, 8);
  3277. JclPeHeader_Subsystem:
  3278. Result := GetSubsystemString(OptionalHeader.Subsystem);
  3279. JclPeHeader_DllCharacteristics:
  3280. Result := IntToHex(OptionalHeader.DllCharacteristics, 4);
  3281. JclPeHeader_SizeOfStackReserve:
  3282. Result := IntToHex(OptionalHeader.SizeOfStackReserve, 8);
  3283. JclPeHeader_SizeOfStackCommit:
  3284. Result := IntToHex(OptionalHeader.SizeOfStackCommit, 8);
  3285. JclPeHeader_SizeOfHeapReserve:
  3286. Result := IntToHex(OptionalHeader.SizeOfHeapReserve, 8);
  3287. JclPeHeader_SizeOfHeapCommit:
  3288. Result := IntToHex(OptionalHeader.SizeOfHeapCommit, 8);
  3289. JclPeHeader_LoaderFlags:
  3290. Result := IntToHex(OptionalHeader.LoaderFlags, 8);
  3291. JclPeHeader_NumberOfRvaAndSizes:
  3292. Result := IntToHex(OptionalHeader.NumberOfRvaAndSizes, 8);
  3293. end;
  3294. end;
  3295. function GetHeaderValues64(Index: TJclPeHeader): string;
  3296. var
  3297. OptionalHeader: TImageOptionalHeader64;
  3298. begin
  3299. OptionalHeader := OptionalHeader64;
  3300. case Index of
  3301. JclPeHeader_Magic:
  3302. Result := IntToHex(OptionalHeader.Magic, 4);
  3303. JclPeHeader_LinkerVersion:
  3304. Result := FormatVersionString(OptionalHeader.MajorLinkerVersion, OptionalHeader.MinorLinkerVersion);
  3305. JclPeHeader_SizeOfCode:
  3306. Result := IntToHex(OptionalHeader.SizeOfCode, 8);
  3307. JclPeHeader_SizeOfInitializedData:
  3308. Result := IntToHex(OptionalHeader.SizeOfInitializedData, 8);
  3309. JclPeHeader_SizeOfUninitializedData:
  3310. Result := IntToHex(OptionalHeader.SizeOfUninitializedData, 8);
  3311. JclPeHeader_AddressOfEntryPoint:
  3312. Result := IntToHex(OptionalHeader.AddressOfEntryPoint, 8);
  3313. JclPeHeader_BaseOfCode:
  3314. Result := IntToHex(OptionalHeader.BaseOfCode, 8);
  3315. JclPeHeader_BaseOfData:
  3316. Result := ''; // IntToHex(OptionalHeader.BaseOfData, 8);
  3317. JclPeHeader_ImageBase:
  3318. Result := IntToHex(OptionalHeader.ImageBase, 16);
  3319. JclPeHeader_SectionAlignment:
  3320. Result := IntToHex(OptionalHeader.SectionAlignment, 8);
  3321. JclPeHeader_FileAlignment:
  3322. Result := IntToHex(OptionalHeader.FileAlignment, 8);
  3323. JclPeHeader_OperatingSystemVersion:
  3324. Result := FormatVersionString(OptionalHeader.MajorOperatingSystemVersion, OptionalHeader.MinorOperatingSystemVersion);
  3325. JclPeHeader_ImageVersion:
  3326. Result := FormatVersionString(OptionalHeader.MajorImageVersion, OptionalHeader.MinorImageVersion);
  3327. JclPeHeader_SubsystemVersion:
  3328. Result := FormatVersionString(OptionalHeader.MajorSubsystemVersion, OptionalHeader.MinorSubsystemVersion);
  3329. JclPeHeader_Win32VersionValue:
  3330. Result := IntToHex(OptionalHeader.Win32VersionValue, 8);
  3331. JclPeHeader_SizeOfImage:
  3332. Result := IntToHex(OptionalHeader.SizeOfImage, 8);
  3333. JclPeHeader_SizeOfHeaders:
  3334. Result := IntToHex(OptionalHeader.SizeOfHeaders, 8);
  3335. JclPeHeader_CheckSum:
  3336. Result := IntToHex(OptionalHeader.CheckSum, 8);
  3337. JclPeHeader_Subsystem:
  3338. Result := GetSubsystemString(OptionalHeader.Subsystem);
  3339. JclPeHeader_DllCharacteristics:
  3340. Result := IntToHex(OptionalHeader.DllCharacteristics, 4);
  3341. JclPeHeader_SizeOfStackReserve:
  3342. Result := IntToHex(OptionalHeader.SizeOfStackReserve, 16);
  3343. JclPeHeader_SizeOfStackCommit:
  3344. Result := IntToHex(OptionalHeader.SizeOfStackCommit, 16);
  3345. JclPeHeader_SizeOfHeapReserve:
  3346. Result := IntToHex(OptionalHeader.SizeOfHeapReserve, 16);
  3347. JclPeHeader_SizeOfHeapCommit:
  3348. Result := IntToHex(OptionalHeader.SizeOfHeapCommit, 16);
  3349. JclPeHeader_LoaderFlags:
  3350. Result := IntToHex(OptionalHeader.LoaderFlags, 8);
  3351. JclPeHeader_NumberOfRvaAndSizes:
  3352. Result := IntToHex(OptionalHeader.NumberOfRvaAndSizes, 8);
  3353. end;
  3354. end;
  3355. begin
  3356. if StatusOK then
  3357. with FLoadedImage.FileHeader^ do
  3358. case Index of
  3359. JclPeHeader_Signature:
  3360. Result := IntToHex(Signature, 8);
  3361. JclPeHeader_Machine:
  3362. Result := GetMachineString(FileHeader.Machine);
  3363. JclPeHeader_NumberOfSections:
  3364. Result := IntToHex(FileHeader.NumberOfSections, 4);
  3365. JclPeHeader_TimeDateStamp:
  3366. Result := IntToHex(FileHeader.TimeDateStamp, 8);
  3367. JclPeHeader_PointerToSymbolTable:
  3368. Result := IntToHex(FileHeader.PointerToSymbolTable, 8);
  3369. JclPeHeader_NumberOfSymbols:
  3370. Result := IntToHex(FileHeader.NumberOfSymbols, 8);
  3371. JclPeHeader_SizeOfOptionalHeader:
  3372. Result := IntToHex(FileHeader.SizeOfOptionalHeader, 4);
  3373. JclPeHeader_Characteristics:
  3374. Result := IntToHex(FileHeader.Characteristics, 4);
  3375. JclPeHeader_Magic..JclPeHeader_NumberOfRvaAndSizes:
  3376. case Target of
  3377. taWin32:
  3378. Result := GetHeaderValues32(Index);
  3379. taWin64:
  3380. Result := GetHeaderValues64(Index);
  3381. //taUnknown:
  3382. else
  3383. Result := '';
  3384. end;
  3385. else
  3386. Result := '';
  3387. end
  3388. else
  3389. Result := '';
  3390. end;
  3391. function TJclPeImage.GetImageSectionCount: Integer;
  3392. begin
  3393. Result := FImageSections.Count;
  3394. end;
  3395. function TJclPeImage.GetImageSectionFullNames(Index: Integer): string;
  3396. var
  3397. Offset: Integer;
  3398. begin
  3399. Result := ImageSectionNames[Index];
  3400. if (Length(Result) > 0) and (Result[1] = '/') and TryStrToInt(Copy(Result, 2, MaxInt), Offset) then
  3401. Result := GetNameInStringTable(Offset);
  3402. end;
  3403. function TJclPeImage.GetImageSectionHeaders(Index: Integer): TImageSectionHeader;
  3404. begin
  3405. Result := PImageSectionHeader(FImageSections.Objects[Index])^;
  3406. end;
  3407. function TJclPeImage.GetImageSectionNameFromRva(const Rva: DWORD): string;
  3408. begin
  3409. Result := GetSectionName(RvaToSection(Rva));
  3410. end;
  3411. function TJclPeImage.GetImageSectionNames(Index: Integer): string;
  3412. begin
  3413. Result := FImageSections[Index];
  3414. end;
  3415. function TJclPeImage.GetImportList: TJclPeImportList;
  3416. begin
  3417. if FImportList = nil then
  3418. FImportList := TJclPeImportList.Create(Self);
  3419. Result := FImportList;
  3420. end;
  3421. function TJclPeImage.GetLoadConfigValues(Index: TJclLoadConfig): string;
  3422. function GetLoadConfigValues32(Index: TJclLoadConfig): string;
  3423. var
  3424. LoadConfig: PIMAGE_LOAD_CONFIG_DIRECTORY32;
  3425. begin
  3426. LoadConfig := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG);
  3427. if LoadConfig <> nil then
  3428. with LoadConfig^ do
  3429. case Index of
  3430. JclLoadConfig_Characteristics:
  3431. Result := IntToHex(Size, 8);
  3432. JclLoadConfig_TimeDateStamp:
  3433. Result := IntToHex(TimeDateStamp, 8);
  3434. JclLoadConfig_Version:
  3435. Result := FormatVersionString(MajorVersion, MinorVersion);
  3436. JclLoadConfig_GlobalFlagsClear:
  3437. Result := IntToHex(GlobalFlagsClear, 8);
  3438. JclLoadConfig_GlobalFlagsSet:
  3439. Result := IntToHex(GlobalFlagsSet, 8);
  3440. JclLoadConfig_CriticalSectionDefaultTimeout:
  3441. Result := IntToHex(CriticalSectionDefaultTimeout, 8);
  3442. JclLoadConfig_DeCommitFreeBlockThreshold:
  3443. Result := IntToHex(DeCommitFreeBlockThreshold, 8);
  3444. JclLoadConfig_DeCommitTotalFreeThreshold:
  3445. Result := IntToHex(DeCommitTotalFreeThreshold, 8);
  3446. JclLoadConfig_LockPrefixTable:
  3447. Result := IntToHex(LockPrefixTable, 8);
  3448. JclLoadConfig_MaximumAllocationSize:
  3449. Result := IntToHex(MaximumAllocationSize, 8);
  3450. JclLoadConfig_VirtualMemoryThreshold:
  3451. Result := IntToHex(VirtualMemoryThreshold, 8);
  3452. JclLoadConfig_ProcessHeapFlags:
  3453. Result := IntToHex(ProcessHeapFlags, 8);
  3454. JclLoadConfig_ProcessAffinityMask:
  3455. Result := IntToHex(ProcessAffinityMask, 8);
  3456. JclLoadConfig_CSDVersion:
  3457. Result := IntToHex(CSDVersion, 4);
  3458. JclLoadConfig_Reserved1:
  3459. Result := IntToHex(Reserved1, 4);
  3460. JclLoadConfig_EditList:
  3461. Result := IntToHex(EditList, 8);
  3462. JclLoadConfig_Reserved:
  3463. Result := LoadResString(@RsPeReserved);
  3464. end;
  3465. end;
  3466. function GetLoadConfigValues64(Index: TJclLoadConfig): string;
  3467. var
  3468. LoadConfig: PIMAGE_LOAD_CONFIG_DIRECTORY64;
  3469. begin
  3470. LoadConfig := DirectoryEntryToData(IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG);
  3471. if LoadConfig <> nil then
  3472. with LoadConfig^ do
  3473. case Index of
  3474. JclLoadConfig_Characteristics:
  3475. Result := IntToHex(Size, 8);
  3476. JclLoadConfig_TimeDateStamp:
  3477. Result := IntToHex(TimeDateStamp, 8);
  3478. JclLoadConfig_Version:
  3479. Result := FormatVersionString(MajorVersion, MinorVersion);
  3480. JclLoadConfig_GlobalFlagsClear:
  3481. Result := IntToHex(GlobalFlagsClear, 8);
  3482. JclLoadConfig_GlobalFlagsSet:
  3483. Result := IntToHex(GlobalFlagsSet, 8);
  3484. JclLoadConfig_CriticalSectionDefaultTimeout:
  3485. Result := IntToHex(CriticalSectionDefaultTimeout, 8);
  3486. JclLoadConfig_DeCommitFreeBlockThreshold:
  3487. Result := IntToHex(DeCommitFreeBlockThreshold, 16);
  3488. JclLoadConfig_DeCommitTotalFreeThreshold:
  3489. Result := IntToHex(DeCommitTotalFreeThreshold, 16);
  3490. JclLoadConfig_LockPrefixTable:
  3491. Result := IntToHex(LockPrefixTable, 16);
  3492. JclLoadConfig_MaximumAllocationSize:
  3493. Result := IntToHex(MaximumAllocationSize, 16);
  3494. JclLoadConfig_VirtualMemoryThreshold:
  3495. Result := IntToHex(VirtualMemoryThreshold, 16);
  3496. JclLoadConfig_ProcessHeapFlags:
  3497. Result := IntToHex(ProcessHeapFlags, 8);
  3498. JclLoadConfig_ProcessAffinityMask:
  3499. Result := IntToHex(ProcessAffinityMask, 16);
  3500. JclLoadConfig_CSDVersion:
  3501. Result := IntToHex(CSDVersion, 4);
  3502. JclLoadConfig_Reserved1:
  3503. Result := IntToHex(Reserved1, 4);
  3504. JclLoadConfig_EditList:
  3505. Result := IntToHex(EditList, 16);
  3506. JclLoadConfig_Reserved:
  3507. Result := LoadResString(@RsPeReserved);
  3508. end;
  3509. end;
  3510. begin
  3511. Result := '';
  3512. case Target of
  3513. taWin32:
  3514. Result := GetLoadConfigValues32(Index);
  3515. taWin64:
  3516. Result := GetLoadConfigValues64(Index);
  3517. end;
  3518. end;
  3519. function TJclPeImage.GetMappedAddress: TJclAddr;
  3520. begin
  3521. if StatusOK then
  3522. Result := TJclAddr(LoadedImage.MappedAddress)
  3523. else
  3524. Result := 0;
  3525. end;
  3526. function TJclPeImage.GetNameInStringTable(Offset: ULONG): string;
  3527. var
  3528. Index: Integer;
  3529. begin
  3530. Dec(Offset, SizeOf(ULONG));
  3531. Index := 0;
  3532. while (Offset > 0) and (Index < FStringTable.Count) do
  3533. begin
  3534. Dec(Offset, Length(FStringTable[Index]) + 1);
  3535. if Offset > 0 then
  3536. Inc(Index);
  3537. end;
  3538. if Offset = 0 then
  3539. Result := FStringTable[Index]
  3540. else
  3541. Result := '';
  3542. end;
  3543. function TJclPeImage.GetOptionalHeader32: TImageOptionalHeader32;
  3544. begin
  3545. if Target = taWin32 then
  3546. Result := PImageNtHeaders32(FLoadedImage.FileHeader)^.OptionalHeader
  3547. else
  3548. ZeroMemory(@Result, SizeOf(Result));
  3549. end;
  3550. function TJclPeImage.GetOptionalHeader64: TImageOptionalHeader64;
  3551. begin
  3552. if Target = taWin64 then
  3553. Result := PImageNtHeaders64(FLoadedImage.FileHeader)^.OptionalHeader
  3554. else
  3555. ZeroMemory(@Result, SizeOf(Result));
  3556. end;
  3557. function TJclPeImage.GetRelocationList: TJclPeRelocList;
  3558. begin
  3559. if FRelocationList = nil then
  3560. FRelocationList := TJclPeRelocList.Create(Self);
  3561. Result := FRelocationList;
  3562. end;
  3563. function TJclPeImage.GetResourceList: TJclPeRootResourceList;
  3564. begin
  3565. if FResourceList = nil then
  3566. begin
  3567. FResourceVA := Directories[IMAGE_DIRECTORY_ENTRY_RESOURCE].VirtualAddress;
  3568. if FResourceVA <> 0 then
  3569. FResourceVA := TJclAddr(RvaToVa(FResourceVA));
  3570. FResourceList := TJclPeRootResourceList.Create(Self, nil, PImageResourceDirectory(FResourceVA));
  3571. end;
  3572. Result := FResourceList;
  3573. end;
  3574. function TJclPeImage.GetSectionHeader(const SectionName: string;
  3575. out Header: PImageSectionHeader): Boolean;
  3576. var
  3577. I: Integer;
  3578. begin
  3579. I := FImageSections.IndexOf(SectionName);
  3580. if I = -1 then
  3581. begin
  3582. Header := nil;
  3583. Result := False;
  3584. end
  3585. else
  3586. begin
  3587. Header := PImageSectionHeader(FImageSections.Objects[I]);
  3588. Result := True;
  3589. end;
  3590. end;
  3591. function TJclPeImage.GetSectionName(Header: PImageSectionHeader): string;
  3592. var
  3593. I: Integer;
  3594. begin
  3595. I := FImageSections.IndexOfObject(TObject(Header));
  3596. if I = -1 then
  3597. Result := ''
  3598. else
  3599. Result := FImageSections[I];
  3600. end;
  3601. function TJclPeImage.GetStringTableCount: Integer;
  3602. begin
  3603. Result := FStringTable.Count;
  3604. end;
  3605. function TJclPeImage.GetStringTableItem(Index: Integer): string;
  3606. begin
  3607. Result := FStringTable[Index];
  3608. end;
  3609. function TJclPeImage.GetUnusedHeaderBytes: TImageDataDirectory;
  3610. begin
  3611. CheckNotAttached;
  3612. Result.Size := 0;
  3613. Result.VirtualAddress := GetImageUnusedHeaderBytes(FLoadedImage, Result.Size);
  3614. if Result.VirtualAddress = 0 then
  3615. RaiseLastOSError;
  3616. end;
  3617. function TJclPeImage.GetVersionInfo: TJclFileVersionInfo;
  3618. var
  3619. VersionInfoResource: TJclPeResourceItem;
  3620. begin
  3621. if (FVersionInfo = nil) and VersionInfoAvailable then
  3622. begin
  3623. VersionInfoResource := ResourceList.FindResource(rtVersion, '1').List[0];
  3624. with VersionInfoResource do
  3625. try
  3626. FVersionInfo := TJclFileVersionInfo.Attach(RawEntryData, RawEntryDataSize);
  3627. except
  3628. FreeAndNil(FVersionInfo);
  3629. end;
  3630. end;
  3631. Result := FVersionInfo;
  3632. end;
  3633. function TJclPeImage.GetVersionInfoAvailable: Boolean;
  3634. begin
  3635. Result := StatusOK and (ResourceList.FindResource(rtVersion, '1') <> nil);
  3636. end;
  3637. class function TJclPeImage.HeaderNames(Index: TJclPeHeader): string;
  3638. begin
  3639. case Index of
  3640. JclPeHeader_Signature:
  3641. Result := LoadResString(@RsPeSignature);
  3642. JclPeHeader_Machine:
  3643. Result := LoadResString(@RsPeMachine);
  3644. JclPeHeader_NumberOfSections:
  3645. Result := LoadResString(@RsPeNumberOfSections);
  3646. JclPeHeader_TimeDateStamp:
  3647. Result := LoadResString(@RsPeTimeDateStamp);
  3648. JclPeHeader_PointerToSymbolTable:
  3649. Result := LoadResString(@RsPePointerToSymbolTable);
  3650. JclPeHeader_NumberOfSymbols:
  3651. Result := LoadResString(@RsPeNumberOfSymbols);
  3652. JclPeHeader_SizeOfOptionalHeader:
  3653. Result := LoadResString(@RsPeSizeOfOptionalHeader);
  3654. JclPeHeader_Characteristics:
  3655. Result := LoadResString(@RsPeCharacteristics);
  3656. JclPeHeader_Magic:
  3657. Result := LoadResString(@RsPeMagic);
  3658. JclPeHeader_LinkerVersion:
  3659. Result := LoadResString(@RsPeLinkerVersion);
  3660. JclPeHeader_SizeOfCode:
  3661. Result := LoadResString(@RsPeSizeOfCode);
  3662. JclPeHeader_SizeOfInitializedData:
  3663. Result := LoadResString(@RsPeSizeOfInitializedData);
  3664. JclPeHeader_SizeOfUninitializedData:
  3665. Result := LoadResString(@RsPeSizeOfUninitializedData);
  3666. JclPeHeader_AddressOfEntryPoint:
  3667. Result := LoadResString(@RsPeAddressOfEntryPoint);
  3668. JclPeHeader_BaseOfCode:
  3669. Result := LoadResString(@RsPeBaseOfCode);
  3670. JclPeHeader_BaseOfData:
  3671. Result := LoadResString(@RsPeBaseOfData);
  3672. JclPeHeader_ImageBase:
  3673. Result := LoadResString(@RsPeImageBase);
  3674. JclPeHeader_SectionAlignment:
  3675. Result := LoadResString(@RsPeSectionAlignment);
  3676. JclPeHeader_FileAlignment:
  3677. Result := LoadResString(@RsPeFileAlignment);
  3678. JclPeHeader_OperatingSystemVersion:
  3679. Result := LoadResString(@RsPeOperatingSystemVersion);
  3680. JclPeHeader_ImageVersion:
  3681. Result := LoadResString(@RsPeImageVersion);
  3682. JclPeHeader_SubsystemVersion:
  3683. Result := LoadResString(@RsPeSubsystemVersion);
  3684. JclPeHeader_Win32VersionValue:
  3685. Result := LoadResString(@RsPeWin32VersionValue);
  3686. JclPeHeader_SizeOfImage:
  3687. Result := LoadResString(@RsPeSizeOfImage);
  3688. JclPeHeader_SizeOfHeaders:
  3689. Result := LoadResString(@RsPeSizeOfHeaders);
  3690. JclPeHeader_CheckSum:
  3691. Result := LoadResString(@RsPeCheckSum);
  3692. JclPeHeader_Subsystem:
  3693. Result := LoadResString(@RsPeSubsystem);
  3694. JclPeHeader_DllCharacteristics:
  3695. Result := LoadResString(@RsPeDllCharacteristics);
  3696. JclPeHeader_SizeOfStackReserve:
  3697. Result := LoadResString(@RsPeSizeOfStackReserve);
  3698. JclPeHeader_SizeOfStackCommit:
  3699. Result := LoadResString(@RsPeSizeOfStackCommit);
  3700. JclPeHeader_SizeOfHeapReserve:
  3701. Result := LoadResString(@RsPeSizeOfHeapReserve);
  3702. JclPeHeader_SizeOfHeapCommit:
  3703. Result := LoadResString(@RsPeSizeOfHeapCommit);
  3704. JclPeHeader_LoaderFlags:
  3705. Result := LoadResString(@RsPeLoaderFlags);
  3706. JclPeHeader_NumberOfRvaAndSizes:
  3707. Result := LoadResString(@RsPeNumberOfRvaAndSizes);
  3708. else
  3709. Result := '';
  3710. end;
  3711. end;
  3712. function TJclPeImage.IsBrokenFormat: Boolean;
  3713. function IsBrokenFormat32: Boolean;
  3714. var
  3715. OptionalHeader: TImageOptionalHeader32;
  3716. begin
  3717. OptionalHeader := OptionalHeader32;
  3718. Result := not ((OptionalHeader.AddressOfEntryPoint = 0) or IsCLR);
  3719. if Result then
  3720. begin
  3721. Result := (ImageSectionCount = 0);
  3722. if not Result then
  3723. with ImageSectionHeaders[0] do
  3724. Result := (VirtualAddress <> OptionalHeader.BaseOfCode) or (SizeOfRawData = 0) or
  3725. (OptionalHeader.AddressOfEntryPoint > VirtualAddress + Misc.VirtualSize) or
  3726. (Characteristics and (IMAGE_SCN_CNT_CODE or IMAGE_SCN_MEM_WRITE) <> IMAGE_SCN_CNT_CODE);
  3727. end;
  3728. end;
  3729. function IsBrokenFormat64: Boolean;
  3730. var
  3731. OptionalHeader: TImageOptionalHeader64;
  3732. begin
  3733. OptionalHeader := OptionalHeader64;
  3734. Result := not ((OptionalHeader.AddressOfEntryPoint = 0) or IsCLR);
  3735. if Result then
  3736. begin
  3737. Result := (ImageSectionCount = 0);
  3738. if not Result then
  3739. with ImageSectionHeaders[0] do
  3740. Result := (VirtualAddress <> OptionalHeader.BaseOfCode) or (SizeOfRawData = 0) or
  3741. (OptionalHeader.AddressOfEntryPoint > VirtualAddress + Misc.VirtualSize) or
  3742. (Characteristics and (IMAGE_SCN_CNT_CODE or IMAGE_SCN_MEM_WRITE) <> IMAGE_SCN_CNT_CODE);
  3743. end;
  3744. end;
  3745. begin
  3746. case Target of
  3747. taWin32:
  3748. Result := IsBrokenFormat32;
  3749. taWin64:
  3750. Result := IsBrokenFormat64;
  3751. //taUnknown:
  3752. else
  3753. Result := False; // don't know how to check it
  3754. end;
  3755. end;
  3756. function TJclPeImage.IsCLR: Boolean;
  3757. begin
  3758. Result := DirectoryExists[IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR] and CLRHeader.HasMetadata;
  3759. end;
  3760. function TJclPeImage.IsSystemImage: Boolean;
  3761. begin
  3762. Result := StatusOK and FLoadedImage.fSystemImage;
  3763. end;
  3764. class function TJclPeImage.LoadConfigNames(Index: TJclLoadConfig): string;
  3765. begin
  3766. case Index of
  3767. JclLoadConfig_Characteristics:
  3768. Result := LoadResString(@RsPeCharacteristics);
  3769. JclLoadConfig_TimeDateStamp:
  3770. Result := LoadResString(@RsPeTimeDateStamp);
  3771. JclLoadConfig_Version:
  3772. Result := LoadResString(@RsPeVersion);
  3773. JclLoadConfig_GlobalFlagsClear:
  3774. Result := LoadResString(@RsPeGlobalFlagsClear);
  3775. JclLoadConfig_GlobalFlagsSet:
  3776. Result := LoadResString(@RsPeGlobalFlagsSet);
  3777. JclLoadConfig_CriticalSectionDefaultTimeout:
  3778. Result := LoadResString(@RsPeCriticalSectionDefaultTimeout);
  3779. JclLoadConfig_DeCommitFreeBlockThreshold:
  3780. Result := LoadResString(@RsPeDeCommitFreeBlockThreshold);
  3781. JclLoadConfig_DeCommitTotalFreeThreshold:
  3782. Result := LoadResString(@RsPeDeCommitTotalFreeThreshold);
  3783. JclLoadConfig_LockPrefixTable:
  3784. Result := LoadResString(@RsPeLockPrefixTable);
  3785. JclLoadConfig_MaximumAllocationSize:
  3786. Result := LoadResString(@RsPeMaximumAllocationSize);
  3787. JclLoadConfig_VirtualMemoryThreshold:
  3788. Result := LoadResString(@RsPeVirtualMemoryThreshold);
  3789. JclLoadConfig_ProcessHeapFlags:
  3790. Result := LoadResString(@RsPeProcessHeapFlags);
  3791. JclLoadConfig_ProcessAffinityMask:
  3792. Result := LoadResString(@RsPeProcessAffinityMask);
  3793. JclLoadConfig_CSDVersion:
  3794. Result := LoadResString(@RsPeCSDVersion);
  3795. JclLoadConfig_Reserved1:
  3796. Result := LoadResString(@RsPeReserved);
  3797. JclLoadConfig_EditList:
  3798. Result := LoadResString(@RsPeEditList);
  3799. JclLoadConfig_Reserved:
  3800. Result := LoadResString(@RsPeReserved);
  3801. else
  3802. Result := '';
  3803. end;
  3804. end;
  3805. procedure TJclPeImage.RaiseStatusException;
  3806. begin
  3807. if not FNoExceptions then
  3808. case FStatus of
  3809. stNotPE:
  3810. raise EJclPeImageError.CreateRes(@RsPeNotPE);
  3811. stNotFound:
  3812. raise EJclPeImageError.CreateResFmt(@RsPeCantOpen, [FFileName]);
  3813. stNotSupported:
  3814. raise EJclPeImageError.CreateRes(@RsPeUnknownTarget);
  3815. stError:
  3816. RaiseLastOSError;
  3817. end;
  3818. end;
  3819. function TJclPeImage.RawToVa(Raw: DWORD): Pointer;
  3820. begin
  3821. Result := Pointer(TJclAddr(FLoadedImage.MappedAddress) + Raw);
  3822. end;
  3823. procedure TJclPeImage.ReadImageSections;
  3824. var
  3825. I: Integer;
  3826. Header: PImageSectionHeader;
  3827. UTF8Name: TUTF8String;
  3828. SectionName: string;
  3829. begin
  3830. if not StatusOK then
  3831. Exit;
  3832. Header := FLoadedImage.Sections;
  3833. for I := 0 to FLoadedImage.NumberOfSections - 1 do
  3834. begin
  3835. SetLength(UTF8Name, IMAGE_SIZEOF_SHORT_NAME);
  3836. Move(Header.Name[0], UTF8Name[1], IMAGE_SIZEOF_SHORT_NAME * SizeOf(AnsiChar));
  3837. StrResetLength(UTF8Name);
  3838. if not TryUTF8ToString(UTF8Name, SectionName) then
  3839. SectionName := string(UTF8Name);
  3840. FImageSections.AddObject(SectionName, Pointer(Header));
  3841. Inc(Header);
  3842. end;
  3843. end;
  3844. procedure TJclPeImage.ReadStringTable;
  3845. var
  3846. SymbolTable: DWORD;
  3847. StringTablePtr: PAnsiChar;
  3848. Ptr: PAnsiChar;
  3849. ByteSize: ULONG;
  3850. Start: PAnsiChar;
  3851. StringEntry: AnsiString;
  3852. begin
  3853. SymbolTable := LoadedImage.FileHeader.FileHeader.PointerToSymbolTable;
  3854. if SymbolTable = 0 then
  3855. Exit;
  3856. StringTablePtr := PAnsiChar(LoadedImage.MappedAddress) +
  3857. SymbolTable +
  3858. (LoadedImage.FileHeader.FileHeader.NumberOfSymbols * SizeOf(IMAGE_SYMBOL));
  3859. ByteSize := PULONG(StringTablePtr)^;
  3860. Ptr := StringTablePtr + SizeOf(ByteSize);
  3861. while Ptr < StringTablePtr + ByteSize do
  3862. begin
  3863. Start := Ptr;
  3864. while (Ptr^ <> #0) and (Ptr < StringTablePtr + ByteSize) do
  3865. Inc(Ptr);
  3866. if Start <> Ptr then
  3867. begin
  3868. SetLength(StringEntry, Ptr - Start);
  3869. Move(Start^, StringEntry[1], Ptr - Start);
  3870. FStringTable.Add(string(StringEntry));
  3871. end;
  3872. Inc(Ptr); // to skip the #0 character
  3873. end;
  3874. end;
  3875. function TJclPeImage.ResourceItemCreate(AEntry: PImageResourceDirectoryEntry;
  3876. AParentItem: TJclPeResourceItem): TJclPeResourceItem;
  3877. begin
  3878. Result := TJclPeResourceItem.Create(Self, AParentItem, AEntry);
  3879. end;
  3880. function TJclPeImage.ResourceListCreate(ADirectory: PImageResourceDirectory;
  3881. AParentItem: TJclPeResourceItem): TJclPeResourceList;
  3882. begin
  3883. Result := TJclPeResourceList.Create(Self, AParentItem, ADirectory);
  3884. end;
  3885. function TJclPeImage.RvaToSection(Rva: DWORD): PImageSectionHeader;
  3886. var
  3887. I: Integer;
  3888. SectionHeader: PImageSectionHeader;
  3889. EndRVA: DWORD;
  3890. begin
  3891. Result := ImageRvaToSection(FLoadedImage.FileHeader, FLoadedImage.MappedAddress, Rva);
  3892. if Result = nil then
  3893. for I := 0 to FImageSections.Count - 1 do
  3894. begin
  3895. SectionHeader := PImageSectionHeader(FImageSections.Objects[I]);
  3896. if SectionHeader^.SizeOfRawData = 0 then
  3897. EndRVA := SectionHeader^.Misc.VirtualSize
  3898. else
  3899. EndRVA := SectionHeader^.SizeOfRawData;
  3900. Inc(EndRVA, SectionHeader^.VirtualAddress);
  3901. if (SectionHeader^.VirtualAddress <= Rva) and (EndRVA >= Rva) then
  3902. begin
  3903. Result := SectionHeader;
  3904. Break;
  3905. end;
  3906. end;
  3907. end;
  3908. function TJclPeImage.RvaToVa(Rva: DWORD): Pointer;
  3909. begin
  3910. if FAttachedImage then
  3911. Result := Pointer(TJclAddr(FLoadedImage.MappedAddress) + Rva)
  3912. else
  3913. Result := ImageRvaToVa(FLoadedImage.FileHeader, FLoadedImage.MappedAddress, Rva, nil);
  3914. end;
  3915. function TJclPeImage.ImageAddressToRva(Address: DWORD): DWORD;
  3916. var
  3917. ImageBase32: DWORD;
  3918. ImageBase64: Int64;
  3919. begin
  3920. case Target of
  3921. taWin32:
  3922. begin
  3923. ImageBase32 := PImageNtHeaders32(FLoadedImage.FileHeader)^.OptionalHeader.ImageBase;
  3924. Result := Address - ImageBase32;
  3925. end;
  3926. taWin64:
  3927. begin
  3928. ImageBase64 := PImageNtHeaders64(FLoadedImage.FileHeader)^.OptionalHeader.ImageBase;
  3929. Result := DWORD(Address - ImageBase64);
  3930. end;
  3931. //taUnknown:
  3932. else
  3933. Result := 0;
  3934. end;
  3935. end;
  3936. procedure TJclPeImage.SetFileName(const Value: TFileName);
  3937. begin
  3938. if FFileName <> Value then
  3939. begin
  3940. Clear;
  3941. FFileName := Value;
  3942. if FFileName = '' then
  3943. Exit;
  3944. // OF: possible loss of data
  3945. if MapAndLoad(PAnsiChar(AnsiString(FFileName)), nil, FLoadedImage, True, FReadOnlyAccess) then
  3946. begin
  3947. FTarget := PeMapImgTarget(FLoadedImage.MappedAddress);
  3948. if FTarget <> taUnknown then
  3949. begin
  3950. FStatus := stOk;
  3951. ReadImageSections;
  3952. ReadStringTable;
  3953. AfterOpen;
  3954. end
  3955. else
  3956. FStatus := stNotSupported;
  3957. end
  3958. else
  3959. case GetLastError of
  3960. ERROR_SUCCESS:
  3961. FStatus := stNotPE;
  3962. ERROR_FILE_NOT_FOUND:
  3963. FStatus := stNotFound;
  3964. else
  3965. FStatus := stError;
  3966. end;
  3967. RaiseStatusException;
  3968. end;
  3969. end;
  3970. class function TJclPeImage.ShortSectionInfo(Characteristics: DWORD): string;
  3971. type
  3972. TSectionCharacteristics = packed record
  3973. Mask: DWORD;
  3974. InfoChar: Char;
  3975. end;
  3976. const
  3977. Info: array [1..8] of TSectionCharacteristics = (
  3978. (Mask: IMAGE_SCN_CNT_CODE; InfoChar: 'C'),
  3979. (Mask: IMAGE_SCN_MEM_EXECUTE; InfoChar: 'E'),
  3980. (Mask: IMAGE_SCN_MEM_READ; InfoChar: 'R'),
  3981. (Mask: IMAGE_SCN_MEM_WRITE; InfoChar: 'W'),
  3982. (Mask: IMAGE_SCN_CNT_INITIALIZED_DATA; InfoChar: 'I'),
  3983. (Mask: IMAGE_SCN_CNT_UNINITIALIZED_DATA; InfoChar: 'U'),
  3984. (Mask: IMAGE_SCN_MEM_SHARED; InfoChar: 'S'),
  3985. (Mask: IMAGE_SCN_MEM_DISCARDABLE; InfoChar: 'D')
  3986. );
  3987. var
  3988. I: Integer;
  3989. begin
  3990. SetLength(Result, High(Info));
  3991. Result := '';
  3992. for I := Low(Info) to High(Info) do
  3993. with Info[I] do
  3994. if (Characteristics and Mask) = Mask then
  3995. Result := Result + InfoChar;
  3996. end;
  3997. function TJclPeImage.StatusOK: Boolean;
  3998. begin
  3999. Result := (FStatus = stOk);
  4000. end;
  4001. class function TJclPeImage.StampToDateTime(TimeDateStamp: DWORD): TDateTime;
  4002. begin
  4003. Result := TimeDateStamp / SecsPerDay + UnixTimeStart
  4004. end;
  4005. procedure TJclPeImage.TryGetNamesForOrdinalImports;
  4006. begin
  4007. if StatusOK then
  4008. begin
  4009. GetImportList;
  4010. FImportList.TryGetNamesForOrdinalImports;
  4011. end;
  4012. end;
  4013. function TJclPeImage.VerifyCheckSum: Boolean;
  4014. function VerifyCheckSum32: Boolean;
  4015. var
  4016. OptionalHeader: TImageOptionalHeader32;
  4017. begin
  4018. OptionalHeader := OptionalHeader32;
  4019. Result := StatusOK and ((OptionalHeader.CheckSum = 0) or (CalculateCheckSum = OptionalHeader.CheckSum));
  4020. end;
  4021. function VerifyCheckSum64: Boolean;
  4022. var
  4023. OptionalHeader: TImageOptionalHeader64;
  4024. begin
  4025. OptionalHeader := OptionalHeader64;
  4026. Result := StatusOK and ((OptionalHeader.CheckSum = 0) or (CalculateCheckSum = OptionalHeader.CheckSum));
  4027. end;
  4028. begin
  4029. CheckNotAttached;
  4030. case Target of
  4031. taWin32:
  4032. Result := VerifyCheckSum32;
  4033. taWin64:
  4034. Result := VerifyCheckSum64;
  4035. //taUnknown: ;
  4036. else
  4037. Result := True;
  4038. end;
  4039. end;
  4040. {$IFDEF BORLAND}
  4041. //=== { TJclPeBorImagesCache } ===============================================
  4042. function TJclPeBorImagesCache.GetImages(const FileName: TFileName): TJclPeBorImage;
  4043. begin
  4044. Result := TJclPeBorImage(inherited Images[FileName]);
  4045. end;
  4046. function TJclPeBorImagesCache.GetPeImageClass: TJclPeImageClass;
  4047. begin
  4048. Result := TJclPeBorImage;
  4049. end;
  4050. //=== { TJclPePackageInfo } ==================================================
  4051. constructor TJclPePackageInfo.Create(ALibHandle: THandle);
  4052. begin
  4053. FContains := TStringList.Create;
  4054. FRequires := TStringList.Create;
  4055. FEnsureExtension := True;
  4056. FSorted := True;
  4057. ReadPackageInfo(ALibHandle);
  4058. end;
  4059. destructor TJclPePackageInfo.Destroy;
  4060. begin
  4061. FreeAndNil(FContains);
  4062. FreeAndNil(FRequires);
  4063. inherited Destroy;
  4064. end;
  4065. function TJclPePackageInfo.GetContains: TStrings;
  4066. begin
  4067. Result := FContains;
  4068. end;
  4069. function TJclPePackageInfo.GetContainsCount: Integer;
  4070. begin
  4071. Result := Contains.Count;
  4072. end;
  4073. function TJclPePackageInfo.GetContainsFlags(Index: Integer): Byte;
  4074. begin
  4075. Result := Byte(Contains.Objects[Index]);
  4076. end;
  4077. function TJclPePackageInfo.GetContainsNames(Index: Integer): string;
  4078. begin
  4079. Result := Contains[Index];
  4080. end;
  4081. function TJclPePackageInfo.GetRequires: TStrings;
  4082. begin
  4083. Result := FRequires;
  4084. end;
  4085. function TJclPePackageInfo.GetRequiresCount: Integer;
  4086. begin
  4087. Result := Requires.Count;
  4088. end;
  4089. function TJclPePackageInfo.GetRequiresNames(Index: Integer): string;
  4090. begin
  4091. Result := Requires[Index];
  4092. if FEnsureExtension then
  4093. StrEnsureSuffix(BinaryExtensionPackage, Result);
  4094. end;
  4095. class function TJclPePackageInfo.PackageModuleTypeToString(Flags: Cardinal): string;
  4096. begin
  4097. case Flags and pfModuleTypeMask of
  4098. pfExeModule, pfModuleTypeMask:
  4099. Result := LoadResString(@RsPePkgExecutable);
  4100. pfPackageModule:
  4101. Result := LoadResString(@RsPePkgPackage);
  4102. pfLibraryModule:
  4103. Result := LoadResString(@PsPePkgLibrary);
  4104. else
  4105. Result := '';
  4106. end;
  4107. end;
  4108. class function TJclPePackageInfo.PackageOptionsToString(Flags: Cardinal): string;
  4109. begin
  4110. Result := '';
  4111. AddFlagTextRes(Result, @RsPePkgNeverBuild, Flags, pfNeverBuild);
  4112. AddFlagTextRes(Result, @RsPePkgDesignOnly, Flags, pfDesignOnly);
  4113. AddFlagTextRes(Result, @RsPePkgRunOnly, Flags, pfRunOnly);
  4114. AddFlagTextRes(Result, @RsPePkgIgnoreDupUnits, Flags, pfIgnoreDupUnits);
  4115. end;
  4116. class function TJclPePackageInfo.ProducerToString(Flags: Cardinal): string;
  4117. begin
  4118. case Flags and pfProducerMask of
  4119. pfV3Produced:
  4120. Result := LoadResString(@RsPePkgV3Produced);
  4121. pfProducerUndefined:
  4122. Result := LoadResString(@RsPePkgProducerUndefined);
  4123. pfBCB4Produced:
  4124. Result := LoadResString(@RsPePkgBCB4Produced);
  4125. pfDelphi4Produced:
  4126. Result := LoadResString(@RsPePkgDelphi4Produced);
  4127. else
  4128. Result := '';
  4129. end;
  4130. end;
  4131. procedure PackageInfoProc(const Name: string; NameType: TNameType; AFlags: Byte; Param: Pointer);
  4132. begin
  4133. with TJclPePackageInfo(Param) do
  4134. case NameType of
  4135. ntContainsUnit:
  4136. Contains.AddObject(Name, Pointer(AFlags));
  4137. ntRequiresPackage:
  4138. Requires.Add(Name);
  4139. ntDcpBpiName:
  4140. SetDcpName(Name);
  4141. end;
  4142. end;
  4143. procedure TJclPePackageInfo.ReadPackageInfo(ALibHandle: THandle);
  4144. var
  4145. DescrResInfo: HRSRC;
  4146. DescrResData: HGLOBAL;
  4147. begin
  4148. FAvailable := FindResource(ALibHandle, PackageInfoResName, RT_RCDATA) <> 0;
  4149. if FAvailable then
  4150. begin
  4151. GetPackageInfo(ALibHandle, Self, FFlags, PackageInfoProc);
  4152. if FDcpName = '' then
  4153. FDcpName := PathExtractFileNameNoExt(GetModulePath(ALibHandle)) + CompilerExtensionDCP;
  4154. if FSorted then
  4155. begin
  4156. FContains.Sort;
  4157. FRequires.Sort;
  4158. end;
  4159. end;
  4160. DescrResInfo := FindResource(ALibHandle, DescriptionResName, RT_RCDATA);
  4161. if DescrResInfo <> 0 then
  4162. begin
  4163. DescrResData := LoadResource(ALibHandle, DescrResInfo);
  4164. if DescrResData <> 0 then
  4165. begin
  4166. FDescription := WideCharLenToString(LockResource(DescrResData),
  4167. SizeofResource(ALibHandle, DescrResInfo));
  4168. StrResetLength(FDescription);
  4169. end;
  4170. end;
  4171. end;
  4172. procedure TJclPePackageInfo.SetDcpName(const Value: string);
  4173. begin
  4174. FDcpName := Value;
  4175. end;
  4176. class function TJclPePackageInfo.UnitInfoFlagsToString(UnitFlags: Byte): string;
  4177. begin
  4178. Result := '';
  4179. AddFlagTextRes(Result, @RsPePkgMain, UnitFlags, ufMainUnit);
  4180. AddFlagTextRes(Result, @RsPePkgPackage, UnitFlags, ufPackageUnit);
  4181. AddFlagTextRes(Result, @RsPePkgWeak, UnitFlags, ufWeakUnit);
  4182. AddFlagTextRes(Result, @RsPePkgOrgWeak, UnitFlags, ufOrgWeakUnit);
  4183. AddFlagTextRes(Result, @RsPePkgImplicit, UnitFlags, ufImplicitUnit);
  4184. end;
  4185. //=== { TJclPeBorForm } ======================================================
  4186. constructor TJclPeBorForm.Create(AResItem: TJclPeResourceItem;
  4187. AFormFlags: TFilerFlags; AFormPosition: Integer;
  4188. const AFormClassName, AFormObjectName: string);
  4189. begin
  4190. inherited Create;
  4191. FResItem := AResItem;
  4192. FFormFlags := AFormFlags;
  4193. FFormPosition := AFormPosition;
  4194. FFormClassName := AFormClassName;
  4195. FFormObjectName := AFormObjectName;
  4196. end;
  4197. procedure TJclPeBorForm.ConvertFormToText(const Stream: TStream);
  4198. var
  4199. SourceStream: TJclPeResourceRawStream;
  4200. begin
  4201. SourceStream := TJclPeResourceRawStream.Create(ResItem);
  4202. try
  4203. ObjectBinaryToText(SourceStream, Stream);
  4204. finally
  4205. SourceStream.Free;
  4206. end;
  4207. end;
  4208. procedure TJclPeBorForm.ConvertFormToText(const Strings: TStrings);
  4209. var
  4210. TempStream: TMemoryStream;
  4211. begin
  4212. TempStream := TMemoryStream.Create;
  4213. try
  4214. ConvertFormToText(TempStream);
  4215. TempStream.Seek(0, soFromBeginning);
  4216. Strings.LoadFromStream(TempStream);
  4217. finally
  4218. TempStream.Free;
  4219. end;
  4220. end;
  4221. function TJclPeBorForm.GetDisplayName: string;
  4222. begin
  4223. if FFormObjectName <> '' then
  4224. Result := FFormObjectName + ': '
  4225. else
  4226. Result := '';
  4227. Result := Result + FFormClassName;
  4228. end;
  4229. //=== { TJclPeBorImage } =====================================================
  4230. constructor TJclPeBorImage.Create(ANoExceptions: Boolean);
  4231. begin
  4232. FForms := TObjectList.Create(True);
  4233. FPackageInfoSorted := True;
  4234. inherited Create(ANoExceptions);
  4235. end;
  4236. destructor TJclPeBorImage.Destroy;
  4237. begin
  4238. inherited Destroy;
  4239. FreeAndNil(FForms);
  4240. end;
  4241. procedure TJclPeBorImage.AfterOpen;
  4242. var
  4243. HasDVCLAL, HasPACKAGEINFO, HasPACKAGEOPTIONS: Boolean;
  4244. begin
  4245. inherited AfterOpen;
  4246. if StatusOK then
  4247. with ResourceList do
  4248. begin
  4249. HasDVCLAL := (FindResource(rtRCData, DVclAlResName) <> nil);
  4250. HasPACKAGEINFO := (FindResource(rtRCData, PackageInfoResName) <> nil);
  4251. HasPACKAGEOPTIONS := (FindResource(rtRCData, PackageOptionsResName) <> nil);
  4252. FIsPackage := HasPACKAGEINFO and HasPACKAGEOPTIONS;
  4253. FIsBorlandImage := HasDVCLAL or FIsPackage;
  4254. end;
  4255. end;
  4256. procedure TJclPeBorImage.Clear;
  4257. begin
  4258. FForms.Clear;
  4259. FreeAndNil(FPackageInfo);
  4260. FreeLibHandle;
  4261. inherited Clear;
  4262. FIsBorlandImage := False;
  4263. FIsPackage := False;
  4264. FPackageCompilerVersion := 0;
  4265. end;
  4266. procedure TJclPeBorImage.CreateFormsList;
  4267. var
  4268. ResTypeItem: TJclPeResourceItem;
  4269. I: Integer;
  4270. procedure ProcessListItem(DfmResItem: TJclPeResourceItem);
  4271. const
  4272. FilerSignature: array [1..4] of AnsiChar = string('TPF0');
  4273. var
  4274. SourceStream: TJclPeResourceRawStream;
  4275. Reader: TReader;
  4276. FormFlags: TFilerFlags;
  4277. FormPosition: Integer;
  4278. ClassName, FormName: string;
  4279. begin
  4280. SourceStream := TJclPeResourceRawStream.Create(DfmResItem);
  4281. try
  4282. if (SourceStream.Size > SizeOf(FilerSignature)) and
  4283. (PInteger(SourceStream.Memory)^ = Integer(FilerSignature)) then
  4284. begin
  4285. Reader := TReader.Create(SourceStream, 4096);
  4286. try
  4287. Reader.ReadSignature;
  4288. Reader.ReadPrefix(FormFlags, FormPosition);
  4289. ClassName := Reader.ReadStr;
  4290. FormName := Reader.ReadStr;
  4291. FForms.Add(TJclPeBorForm.Create(DfmResItem, FormFlags, FormPosition,
  4292. ClassName, FormName));
  4293. finally
  4294. Reader.Free;
  4295. end;
  4296. end;
  4297. finally
  4298. SourceStream.Free;
  4299. end;
  4300. end;
  4301. begin
  4302. if StatusOK then
  4303. with ResourceList do
  4304. begin
  4305. ResTypeItem := FindResource(rtRCData, '');
  4306. if ResTypeItem <> nil then
  4307. with ResTypeItem.List do
  4308. for I := 0 to Count - 1 do
  4309. ProcessListItem(Items[I].List[0]);
  4310. end;
  4311. end;
  4312. function TJclPeBorImage.DependedPackages(List: TStrings; FullPathName, Descriptions: Boolean): Boolean;
  4313. var
  4314. ImportList: TStringList;
  4315. I: Integer;
  4316. Name: string;
  4317. begin
  4318. Result := IsBorlandImage;
  4319. if not Result then
  4320. Exit;
  4321. ImportList := InternalImportedLibraries(FileName, True, FullPathName, nil);
  4322. List.BeginUpdate;
  4323. try
  4324. for I := 0 to ImportList.Count - 1 do
  4325. begin
  4326. Name := ImportList[I];
  4327. if StrSame(ExtractFileExt(Name), BinaryExtensionPackage) then
  4328. begin
  4329. if Descriptions then
  4330. List.Add(Name + '=' + GetPackageDescription(PChar(Name)))
  4331. else
  4332. List.Add(Name);
  4333. end;
  4334. end;
  4335. finally
  4336. ImportList.Free;
  4337. List.EndUpdate;
  4338. end;
  4339. end;
  4340. function TJclPeBorImage.FreeLibHandle: Boolean;
  4341. begin
  4342. if FLibHandle <> 0 then
  4343. begin
  4344. Result := FreeLibrary(FLibHandle);
  4345. FLibHandle := 0;
  4346. end
  4347. else
  4348. Result := True;
  4349. end;
  4350. function TJclPeBorImage.GetFormCount: Integer;
  4351. begin
  4352. if FForms.Count = 0 then
  4353. CreateFormsList;
  4354. Result := FForms.Count;
  4355. end;
  4356. function TJclPeBorImage.GetFormFromName(const FormClassName: string): TJclPeBorForm;
  4357. var
  4358. I: Integer;
  4359. begin
  4360. Result := nil;
  4361. for I := 0 to FormCount - 1 do
  4362. if StrSame(FormClassName, Forms[I].FormClassName) then
  4363. begin
  4364. Result := Forms[I];
  4365. Break;
  4366. end;
  4367. end;
  4368. function TJclPeBorImage.GetForms(Index: Integer): TJclPeBorForm;
  4369. begin
  4370. Result := TJclPeBorForm(FForms[Index]);
  4371. end;
  4372. function TJclPeBorImage.GetLibHandle: THandle;
  4373. begin
  4374. if StatusOK and (FLibHandle = 0) then
  4375. begin
  4376. FLibHandle := LoadLibraryEx(PChar(FileName), 0, LOAD_LIBRARY_AS_DATAFILE);
  4377. if FLibHandle = 0 then
  4378. RaiseLastOSError;
  4379. end;
  4380. Result := FLibHandle;
  4381. end;
  4382. function TJclPeBorImage.GetPackageCompilerVersion: Integer;
  4383. var
  4384. I: Integer;
  4385. ImportName: string;
  4386. function CheckName: Boolean;
  4387. begin
  4388. Result := False;
  4389. ImportName := AnsiUpperCase(ImportName);
  4390. if StrSame(ExtractFileExt(ImportName), BinaryExtensionPackage) then
  4391. begin
  4392. ImportName := PathExtractFileNameNoExt(ImportName);
  4393. if (Length(ImportName) = 5) and
  4394. CharIsDigit(ImportName[4]) and CharIsDigit(ImportName[5]) and
  4395. ((Pos('RTL', ImportName) = 1) or (Pos('VCL', ImportName) = 1)) then
  4396. begin
  4397. FPackageCompilerVersion := StrToIntDef(Copy(ImportName, 4, 2), 0);
  4398. Result := True;
  4399. end;
  4400. end;
  4401. end;
  4402. begin
  4403. if (FPackageCompilerVersion = 0) and IsPackage then
  4404. begin
  4405. with ImportList do
  4406. for I := 0 to UniqueLibItemCount - 1 do
  4407. begin
  4408. ImportName := UniqueLibNames[I];
  4409. if CheckName then
  4410. Break;
  4411. end;
  4412. if FPackageCompilerVersion = 0 then
  4413. begin
  4414. ImportName := ExtractFileName(FileName);
  4415. CheckName;
  4416. end;
  4417. end;
  4418. Result := FPackageCompilerVersion;
  4419. end;
  4420. function TJclPeBorImage.GetPackageInfo: TJclPePackageInfo;
  4421. begin
  4422. if StatusOK and (FPackageInfo = nil) then
  4423. begin
  4424. GetLibHandle;
  4425. FPackageInfo := TJclPePackageInfo.Create(FLibHandle);
  4426. FPackageInfo.Sorted := FPackageInfoSorted;
  4427. FreeLibHandle;
  4428. end;
  4429. Result := FPackageInfo;
  4430. end;
  4431. {$ENDIF BORLAND}
  4432. //=== { TJclPeNameSearch } ===================================================
  4433. constructor TJclPeNameSearch.Create(const FunctionName, Path: string; Options: TJclPeNameSearchOptions);
  4434. begin
  4435. inherited Create(True);
  4436. FFunctionName := FunctionName;
  4437. FOptions := Options;
  4438. FPath := Path;
  4439. FreeOnTerminate := True;
  4440. end;
  4441. function TJclPeNameSearch.CompareName(const FunctionName, ComparedName: string): Boolean;
  4442. begin
  4443. Result := PeSmartFunctionNameSame(ComparedName, FunctionName, [scIgnoreCase]);
  4444. end;
  4445. procedure TJclPeNameSearch.DoFound;
  4446. begin
  4447. if Assigned(FOnFound) then
  4448. FOnFound(Self, F_FileName, F_FunctionName, F_Option);
  4449. end;
  4450. procedure TJclPeNameSearch.DoProcessFile;
  4451. begin
  4452. if Assigned(FOnProcessFile) then
  4453. FOnProcessFile(Self, FPeImage, F_Process);
  4454. end;
  4455. procedure TJclPeNameSearch.Execute;
  4456. var
  4457. PathList: TStringList;
  4458. I: Integer;
  4459. function CompareNameAndNotify(const S: string): Boolean;
  4460. begin
  4461. Result := CompareName(S, FFunctionName);
  4462. if Result and not Terminated then
  4463. begin
  4464. F_FunctionName := S;
  4465. Synchronize(DoFound);
  4466. end;
  4467. end;
  4468. procedure ProcessDirectorySearch(const DirName: string);
  4469. var
  4470. Se: TSearchRec;
  4471. SearchResult: Integer;
  4472. ImportList: TJclPeImportList;
  4473. ExportList: TJclPeExportFuncList;
  4474. I: Integer;
  4475. begin
  4476. SearchResult := FindFirst(DirName, faArchive + faReadOnly, Se);
  4477. try
  4478. while not Terminated and (SearchResult = 0) do
  4479. begin
  4480. F_FileName := PathAddSeparator(ExtractFilePath(DirName)) + Se.Name;
  4481. F_Process := True;
  4482. FPeImage.FileName := F_FileName;
  4483. if Assigned(FOnProcessFile) then
  4484. Synchronize(DoProcessFile);
  4485. if F_Process and FPeImage.StatusOK then
  4486. begin
  4487. if seExports in FOptions then
  4488. begin
  4489. ExportList := FPeImage.ExportList;
  4490. F_Option := seExports;
  4491. for I := 0 to ExportList.Count - 1 do
  4492. begin
  4493. if Terminated then
  4494. Break;
  4495. CompareNameAndNotify(ExportList[I].Name);
  4496. end;
  4497. end;
  4498. if FOptions * [seImports, seDelayImports, seBoundImports] <> [] then
  4499. begin
  4500. ImportList := FPeImage.ImportList;
  4501. FPeImage.TryGetNamesForOrdinalImports;
  4502. for I := 0 to ImportList.AllItemCount - 1 do
  4503. with ImportList.AllItems[I] do
  4504. begin
  4505. if Terminated then
  4506. Break;
  4507. case ImportLib.ImportKind of
  4508. ikImport:
  4509. if seImports in FOptions then
  4510. begin
  4511. F_Option := seImports;
  4512. CompareNameAndNotify(Name);
  4513. end;
  4514. ikDelayImport:
  4515. if seDelayImports in FOptions then
  4516. begin
  4517. F_Option := seDelayImports;
  4518. CompareNameAndNotify(Name);
  4519. end;
  4520. ikBoundImport:
  4521. if seDelayImports in FOptions then
  4522. begin
  4523. F_Option := seBoundImports;
  4524. CompareNameAndNotify(Name);
  4525. end;
  4526. end;
  4527. end;
  4528. end;
  4529. end;
  4530. SearchResult := FindNext(Se);
  4531. end;
  4532. finally
  4533. FindClose(Se);
  4534. end;
  4535. end;
  4536. begin
  4537. FPeImage := TJclPeImage.Create(True);
  4538. PathList := TStringList.Create;
  4539. try
  4540. PathList.Sorted := True;
  4541. PathList.Duplicates := dupIgnore;
  4542. StrToStrings(FPath, ';', PathList);
  4543. for I := 0 to PathList.Count - 1 do
  4544. ProcessDirectorySearch(PathAddSeparator(Trim(PathList[I])) + '*.*');
  4545. finally
  4546. PathList.Free;
  4547. FPeImage.Free;
  4548. end;
  4549. end;
  4550. procedure TJclPeNameSearch.Start;
  4551. begin
  4552. {$IFDEF RTL210_UP}
  4553. Suspended := False;
  4554. {$ELSE ~RTL210_UP}
  4555. Resume;
  4556. {$ENDIF ~RTL210_UP}
  4557. end;
  4558. //=== PE Image miscellaneous functions =======================================
  4559. function IsValidPeFile(const FileName: TFileName): Boolean;
  4560. var
  4561. NtHeaders: TImageNtHeaders32;
  4562. begin
  4563. Result := PeGetNtHeaders32(FileName, NtHeaders);
  4564. end;
  4565. function InternalGetNtHeaders32(const FileName: TFileName; out NtHeaders): Boolean;
  4566. var
  4567. FileHandle: THandle;
  4568. Mapping: TJclFileMapping;
  4569. View: TJclFileMappingView;
  4570. HeadersPtr: PImageNtHeaders32;
  4571. begin
  4572. Result := False;
  4573. ResetMemory(NtHeaders, SizeOf(TImageNtHeaders32));
  4574. FileHandle := FileOpen(FileName, fmOpenRead or fmShareDenyWrite);
  4575. if FileHandle = INVALID_HANDLE_VALUE then
  4576. Exit;
  4577. try
  4578. if GetSizeOfFile(FileHandle) >= SizeOf(TImageDosHeader) then
  4579. begin
  4580. Mapping := TJclFileMapping.Create(FileHandle, '', PAGE_READONLY, 0, nil);
  4581. try
  4582. View := TJclFileMappingView.Create(Mapping, FILE_MAP_READ, 0, 0);
  4583. HeadersPtr := PeMapImgNtHeaders32(View.Memory);
  4584. if HeadersPtr <> nil then
  4585. begin
  4586. Result := True;
  4587. TImageNtHeaders32(NtHeaders) := HeadersPtr^;
  4588. end;
  4589. finally
  4590. Mapping.Free;
  4591. end;
  4592. end;
  4593. finally
  4594. FileClose(FileHandle);
  4595. end;
  4596. end;
  4597. function PeGetNtHeaders32(const FileName: TFileName; out NtHeaders: TImageNtHeaders32): Boolean;
  4598. begin
  4599. Result := InternalGetNtHeaders32(FileName, NtHeaders);
  4600. end;
  4601. function PeGetNtHeaders64(const FileName: TFileName; out NtHeaders: TImageNtHeaders64): Boolean;
  4602. var
  4603. FileHandle: THandle;
  4604. Mapping: TJclFileMapping;
  4605. View: TJclFileMappingView;
  4606. HeadersPtr: PImageNtHeaders64;
  4607. begin
  4608. Result := False;
  4609. ResetMemory(NtHeaders, SizeOf(NtHeaders));
  4610. FileHandle := FileOpen(FileName, fmOpenRead or fmShareDenyWrite);
  4611. if FileHandle = INVALID_HANDLE_VALUE then
  4612. Exit;
  4613. try
  4614. if GetSizeOfFile(FileHandle) >= SizeOf(TImageDosHeader) then
  4615. begin
  4616. Mapping := TJclFileMapping.Create(FileHandle, '', PAGE_READONLY, 0, nil);
  4617. try
  4618. View := TJclFileMappingView.Create(Mapping, FILE_MAP_READ, 0, 0);
  4619. HeadersPtr := PeMapImgNtHeaders64(View.Memory);
  4620. if HeadersPtr <> nil then
  4621. begin
  4622. Result := True;
  4623. NtHeaders := HeadersPtr^;
  4624. end;
  4625. finally
  4626. Mapping.Free;
  4627. end;
  4628. end;
  4629. finally
  4630. FileClose(FileHandle);
  4631. end;
  4632. end;
  4633. function PeCreateNameHintTable(const FileName: TFileName): Boolean;
  4634. var
  4635. PeImage, ExportsImage: TJclPeImage;
  4636. I: Integer;
  4637. ImportItem: TJclPeImportLibItem;
  4638. Thunk32: PImageThunkData32;
  4639. Thunk64: PImageThunkData64;
  4640. OrdinalName: PImageImportByName;
  4641. ExportItem: TJclPeExportFuncItem;
  4642. Cache: TJclPeImagesCache;
  4643. ImageBase32: TJclAddr32;
  4644. ImageBase64: TJclAddr64;
  4645. UTF8Name: TUTF8String;
  4646. ExportName: string;
  4647. begin
  4648. Cache := TJclPeImagesCache.Create;
  4649. try
  4650. PeImage := TJclPeImage.Create(False);
  4651. try
  4652. PeImage.ReadOnlyAccess := False;
  4653. PeImage.FileName := FileName;
  4654. Result := PeImage.ImportList.Count > 0;
  4655. for I := 0 to PeImage.ImportList.Count - 1 do
  4656. begin
  4657. ImportItem := PeImage.ImportList[I];
  4658. if ImportItem.ImportKind = ikBoundImport then
  4659. Continue;
  4660. ExportsImage := Cache[ImportItem.FileName];
  4661. ExportsImage.ExportList.PrepareForFastNameSearch;
  4662. case PEImage.Target of
  4663. taWin32:
  4664. begin
  4665. Thunk32 := ImportItem.ThunkData32;
  4666. ImageBase32 := PeImage.OptionalHeader32.ImageBase;
  4667. while Thunk32^.Function_ <> 0 do
  4668. begin
  4669. if Thunk32^.Ordinal and IMAGE_ORDINAL_FLAG32 = 0 then
  4670. begin
  4671. case ImportItem.ImportKind of
  4672. ikImport:
  4673. OrdinalName := PImageImportByName(PeImage.RvaToVa(Thunk32^.AddressOfData));
  4674. ikDelayImport:
  4675. OrdinalName := PImageImportByName(PeImage.RvaToVa(Thunk32^.AddressOfData - ImageBase32));
  4676. else
  4677. OrdinalName := nil;
  4678. end;
  4679. UTF8Name := PAnsiChar(@OrdinalName.Name);
  4680. if not TryUTF8ToString(UTF8Name, ExportName) then
  4681. ExportName := string(UTF8Name);
  4682. ExportItem := ExportsImage.ExportList.ItemFromName[ExportName];
  4683. if ExportItem <> nil then
  4684. OrdinalName.Hint := ExportItem.Hint
  4685. else
  4686. OrdinalName.Hint := 0;
  4687. end;
  4688. Inc(Thunk32);
  4689. end;
  4690. end;
  4691. taWin64:
  4692. begin
  4693. Thunk64 := ImportItem.ThunkData64;
  4694. ImageBase64 := PeImage.OptionalHeader64.ImageBase;
  4695. while Thunk64^.Function_ <> 0 do
  4696. begin
  4697. if Thunk64^.Ordinal and IMAGE_ORDINAL_FLAG64 = 0 then
  4698. begin
  4699. case ImportItem.ImportKind of
  4700. ikImport:
  4701. OrdinalName := PImageImportByName(PeImage.RvaToVa(Thunk64^.AddressOfData));
  4702. ikDelayImport:
  4703. OrdinalName := PImageImportByName(PeImage.RvaToVa(Thunk64^.AddressOfData - ImageBase64));
  4704. else
  4705. OrdinalName := nil;
  4706. end;
  4707. UTF8Name := PAnsiChar(@OrdinalName.Name);
  4708. if not TryUTF8ToString(UTF8Name, ExportName) then
  4709. ExportName := string(UTF8Name);
  4710. ExportItem := ExportsImage.ExportList.ItemFromName[ExportName];
  4711. if ExportItem <> nil then
  4712. OrdinalName.Hint := ExportItem.Hint
  4713. else
  4714. OrdinalName.Hint := 0;
  4715. end;
  4716. Inc(Thunk64);
  4717. end;
  4718. end;
  4719. end;
  4720. end;
  4721. finally
  4722. PeImage.Free;
  4723. end;
  4724. finally
  4725. Cache.Free;
  4726. end;
  4727. end;
  4728. function PeRebaseImage32(const ImageName: TFileName; NewBase: TJclAddr32;
  4729. TimeStamp, MaxNewSize: DWORD): TJclRebaseImageInfo32;
  4730. function CalculateBaseAddress: TJclAddr32;
  4731. var
  4732. FirstChar: Char;
  4733. ModuleName: string;
  4734. begin
  4735. ModuleName := ExtractFileName(ImageName);
  4736. if Length(ModuleName) > 0 then
  4737. FirstChar := UpCase(ModuleName[1])
  4738. else
  4739. FirstChar := NativeNull;
  4740. if not CharIsUpper(FirstChar) then
  4741. FirstChar := 'A';
  4742. Result := $60000000 + (((Ord(FirstChar) - Ord('A')) div 3) * $1000000);
  4743. end;
  4744. {$IFDEF CPU64}
  4745. {$IFNDEF DELPHI64_TEMPORARY}
  4746. var
  4747. NewIB, OldIB: QWord;
  4748. {$ENDIF CPU64}
  4749. {$ENDIF ~DELPHI64_TEMPORARY}
  4750. begin
  4751. if NewBase = 0 then
  4752. NewBase := CalculateBaseAddress;
  4753. with Result do
  4754. begin
  4755. NewImageBase := NewBase;
  4756. // OF: possible loss of data
  4757. {$IFDEF CPU32}
  4758. Win32Check(ReBaseImage(PAnsiChar(AnsiString(ImageName)), nil, True, False, False, MaxNewSize,
  4759. OldImageSize, OldImageBase, NewImageSize, NewImageBase, TimeStamp));
  4760. {$ENDIF CPU32}
  4761. {$IFDEF CPU64}
  4762. {$IFDEF DELPHI64_TEMPORARY}
  4763. System.Error(rePlatformNotImplemented);
  4764. {$ELSE ~DELPHI64_TEMPORARY}
  4765. NewIB := NewImageBase;
  4766. OldIB := OldImageBase;
  4767. Win32Check(ReBaseImage(PAnsiChar(AnsiString(ImageName)), nil, True, False, False, MaxNewSize,
  4768. OldImageSize, OldIB, NewImageSize, NewIB, TimeStamp));
  4769. NewImageBase := NewIB;
  4770. OldImageBase := OldIB;
  4771. {$ENDIF ~DELPHI64_TEMPORARY}
  4772. {$ENDIF CPU64}
  4773. end;
  4774. end;
  4775. function PeRebaseImage64(const ImageName: TFileName; NewBase: TJclAddr64;
  4776. TimeStamp, MaxNewSize: DWORD): TJclRebaseImageInfo64;
  4777. function CalculateBaseAddress: TJclAddr64;
  4778. var
  4779. FirstChar: Char;
  4780. ModuleName: string;
  4781. begin
  4782. ModuleName := ExtractFileName(ImageName);
  4783. if Length(ModuleName) > 0 then
  4784. FirstChar := UpCase(ModuleName[1])
  4785. else
  4786. FirstChar := NativeNull;
  4787. if not CharIsUpper(FirstChar) then
  4788. FirstChar := 'A';
  4789. Result := $60000000 + (((Ord(FirstChar) - Ord('A')) div 3) * $1000000);
  4790. Result := Result shl 32;
  4791. end;
  4792. begin
  4793. if NewBase = 0 then
  4794. NewBase := CalculateBaseAddress;
  4795. with Result do
  4796. begin
  4797. NewImageBase := NewBase;
  4798. // OF: possible loss of data
  4799. Win32Check(ReBaseImage64(PAnsiChar(AnsiString(ImageName)), nil, True, False, False, MaxNewSize,
  4800. OldImageSize, OldImageBase, NewImageSize, NewImageBase, TimeStamp));
  4801. end;
  4802. end;
  4803. function PeUpdateLinkerTimeStamp(const FileName: TFileName; const Time: TDateTime): Boolean;
  4804. var
  4805. Mapping: TJclFileMapping;
  4806. View: TJclFileMappingView;
  4807. Headers: PImageNtHeaders32; // works with 64-bit binaries too
  4808. // only the optional field differs
  4809. begin
  4810. Mapping := TJclFileMapping.Create(FileName, fmOpenReadWrite, '', PAGE_READWRITE, 0, nil);
  4811. try
  4812. View := TJclFileMappingView.Create(Mapping, FILE_MAP_WRITE, 0, 0);
  4813. Headers := PeMapImgNtHeaders32(View.Memory);
  4814. Result := (Headers <> nil);
  4815. if Result then
  4816. Headers^.FileHeader.TimeDateStamp := TJclPeImage.DateTimeToStamp(Time);
  4817. finally
  4818. Mapping.Free;
  4819. end;
  4820. end;
  4821. function PeReadLinkerTimeStamp(const FileName: TFileName): TDateTime;
  4822. var
  4823. Mapping: TJclFileMappingStream;
  4824. Headers: PImageNtHeaders32; // works with 64-bit binaries too
  4825. // only the optional field differs
  4826. begin
  4827. Mapping := TJclFileMappingStream.Create(FileName, fmOpenRead or fmShareDenyWrite);
  4828. try
  4829. Headers := PeMapImgNtHeaders32(Mapping.Memory);
  4830. if Headers <> nil then
  4831. Result := TJclPeImage.StampToDateTime(Headers^.FileHeader.TimeDateStamp)
  4832. else
  4833. Result := -1;
  4834. finally
  4835. Mapping.Free;
  4836. end;
  4837. end;
  4838. { TODO -cHelp : Author: Uwe Schuster(just a generic version of JclDebug.InsertDebugDataIntoExecutableFile) }
  4839. function PeInsertSection(const FileName: TFileName; SectionStream: TStream; SectionName: string): Boolean;
  4840. procedure RoundUpToAlignment(var Value: DWORD; Alignment: DWORD);
  4841. begin
  4842. if (Value mod Alignment) <> 0 then
  4843. Value := ((Value div Alignment) + 1) * Alignment;
  4844. end;
  4845. function PeInsertSection32(ImageStream: TMemoryStream): Boolean;
  4846. var
  4847. NtHeaders: PImageNtHeaders32;
  4848. Sections, LastSection, NewSection: PImageSectionHeader;
  4849. VirtualAlignedSize: DWORD;
  4850. I, X, NeedFill: Integer;
  4851. SectionDataSize: Integer;
  4852. UTF8Name: TUTF8String;
  4853. begin
  4854. Result := True;
  4855. try
  4856. SectionDataSize := SectionStream.Size;
  4857. NtHeaders := PeMapImgNtHeaders32(ImageStream.Memory);
  4858. Assert(NtHeaders <> nil);
  4859. Sections := PeMapImgSections32(NtHeaders);
  4860. Assert(Sections <> nil);
  4861. // Check whether there is not a section with the name already. If so, return True (#0000069)
  4862. if PeMapImgFindSection32(NtHeaders, SectionName) <> nil then
  4863. begin
  4864. Result := True;
  4865. Exit;
  4866. end;
  4867. LastSection := Sections;
  4868. Inc(LastSection, NtHeaders^.FileHeader.NumberOfSections - 1);
  4869. NewSection := LastSection;
  4870. Inc(NewSection);
  4871. // Increase the number of sections
  4872. Inc(NtHeaders^.FileHeader.NumberOfSections);
  4873. ResetMemory(NewSection^, SizeOf(TImageSectionHeader));
  4874. // JCLDEBUG Virtual Address
  4875. NewSection^.VirtualAddress := LastSection^.VirtualAddress + LastSection^.Misc.VirtualSize;
  4876. RoundUpToAlignment(NewSection^.VirtualAddress, NtHeaders^.OptionalHeader.SectionAlignment);
  4877. // JCLDEBUG Physical Offset
  4878. NewSection^.PointerToRawData := LastSection^.PointerToRawData + LastSection^.SizeOfRawData;
  4879. RoundUpToAlignment(NewSection^.PointerToRawData, NtHeaders^.OptionalHeader.FileAlignment);
  4880. // JCLDEBUG Section name
  4881. if not TryStringToUTF8(SectionName, UTF8Name) then
  4882. UTF8Name := TUTF8String(SectionName);
  4883. StrPLCopyA(PAnsiChar(@NewSection^.Name), UTF8Name, IMAGE_SIZEOF_SHORT_NAME);
  4884. // JCLDEBUG Characteristics flags
  4885. NewSection^.Characteristics := IMAGE_SCN_MEM_READ or IMAGE_SCN_CNT_INITIALIZED_DATA;
  4886. // Size of virtual data area
  4887. NewSection^.Misc.VirtualSize := SectionDataSize;
  4888. VirtualAlignedSize := SectionDataSize;
  4889. RoundUpToAlignment(VirtualAlignedSize, NtHeaders^.OptionalHeader.SectionAlignment);
  4890. // Update Size of Image
  4891. Inc(NtHeaders^.OptionalHeader.SizeOfImage, VirtualAlignedSize);
  4892. // Raw data size
  4893. NewSection^.SizeOfRawData := SectionDataSize;
  4894. RoundUpToAlignment(NewSection^.SizeOfRawData, NtHeaders^.OptionalHeader.FileAlignment);
  4895. // Update Initialized data size
  4896. Inc(NtHeaders^.OptionalHeader.SizeOfInitializedData, NewSection^.SizeOfRawData);
  4897. // Fill data to alignment
  4898. NeedFill := INT_PTR(NewSection^.SizeOfRawData) - SectionDataSize;
  4899. // Note: Delphi linker seems to generate incorrect (unaligned) size of
  4900. // the executable when adding TD32 debug data so the position could be
  4901. // behind the size of the file then.
  4902. ImageStream.Seek(NewSection^.PointerToRawData, soBeginning);
  4903. ImageStream.CopyFrom(SectionStream, 0);
  4904. X := 0;
  4905. for I := 1 to NeedFill do
  4906. ImageStream.WriteBuffer(X, 1);
  4907. except
  4908. Result := False;
  4909. end;
  4910. end;
  4911. function PeInsertSection64(ImageStream: TMemoryStream): Boolean;
  4912. var
  4913. NtHeaders: PImageNtHeaders64;
  4914. Sections, LastSection, NewSection: PImageSectionHeader;
  4915. VirtualAlignedSize: DWORD;
  4916. I, X, NeedFill: Integer;
  4917. SectionDataSize: Integer;
  4918. UTF8Name: TUTF8String;
  4919. begin
  4920. Result := True;
  4921. try
  4922. SectionDataSize := SectionStream.Size;
  4923. NtHeaders := PeMapImgNtHeaders64(ImageStream.Memory);
  4924. Assert(NtHeaders <> nil);
  4925. Sections := PeMapImgSections64(NtHeaders);
  4926. Assert(Sections <> nil);
  4927. // Check whether there is not a section with the name already. If so, return True (#0000069)
  4928. if PeMapImgFindSection64(NtHeaders, SectionName) <> nil then
  4929. begin
  4930. Result := True;
  4931. Exit;
  4932. end;
  4933. LastSection := Sections;
  4934. Inc(LastSection, NtHeaders^.FileHeader.NumberOfSections - 1);
  4935. NewSection := LastSection;
  4936. Inc(NewSection);
  4937. // Increase the number of sections
  4938. Inc(NtHeaders^.FileHeader.NumberOfSections);
  4939. ResetMemory(NewSection^, SizeOf(TImageSectionHeader));
  4940. // JCLDEBUG Virtual Address
  4941. NewSection^.VirtualAddress := LastSection^.VirtualAddress + LastSection^.Misc.VirtualSize;
  4942. RoundUpToAlignment(NewSection^.VirtualAddress, NtHeaders^.OptionalHeader.SectionAlignment);
  4943. // JCLDEBUG Physical Offset
  4944. NewSection^.PointerToRawData := LastSection^.PointerToRawData + LastSection^.SizeOfRawData;
  4945. RoundUpToAlignment(NewSection^.PointerToRawData, NtHeaders^.OptionalHeader.FileAlignment);
  4946. // JCLDEBUG Section name
  4947. if not TryStringToUTF8(SectionName, UTF8Name) then
  4948. UTF8Name := TUTF8String(SectionName);
  4949. StrPLCopyA(PAnsiChar(@NewSection^.Name), UTF8Name, IMAGE_SIZEOF_SHORT_NAME);
  4950. // JCLDEBUG Characteristics flags
  4951. NewSection^.Characteristics := IMAGE_SCN_MEM_READ or IMAGE_SCN_CNT_INITIALIZED_DATA;
  4952. // Size of virtual data area
  4953. NewSection^.Misc.VirtualSize := SectionDataSize;
  4954. VirtualAlignedSize := SectionDataSize;
  4955. RoundUpToAlignment(VirtualAlignedSize, NtHeaders^.OptionalHeader.SectionAlignment);
  4956. // Update Size of Image
  4957. Inc(NtHeaders^.OptionalHeader.SizeOfImage, VirtualAlignedSize);
  4958. // Raw data size
  4959. NewSection^.SizeOfRawData := SectionDataSize;
  4960. RoundUpToAlignment(NewSection^.SizeOfRawData, NtHeaders^.OptionalHeader.FileAlignment);
  4961. // Update Initialized data size
  4962. Inc(NtHeaders^.OptionalHeader.SizeOfInitializedData, NewSection^.SizeOfRawData);
  4963. // Fill data to alignment
  4964. NeedFill := INT_PTR(NewSection^.SizeOfRawData) - SectionDataSize;
  4965. // Note: Delphi linker seems to generate incorrect (unaligned) size of
  4966. // the executable when adding TD32 debug data so the position could be
  4967. // behind the size of the file then.
  4968. ImageStream.Seek(NewSection^.PointerToRawData, soBeginning);
  4969. ImageStream.CopyFrom(SectionStream, 0);
  4970. X := 0;
  4971. for I := 1 to NeedFill do
  4972. ImageStream.WriteBuffer(X, 1);
  4973. except
  4974. Result := False;
  4975. end;
  4976. end;
  4977. var
  4978. ImageStream: TMemoryStream;
  4979. begin
  4980. Result := Assigned(SectionStream) and (SectionName <> '');
  4981. if not Result then
  4982. Exit;
  4983. ImageStream := TMemoryStream.Create;
  4984. try
  4985. ImageStream.LoadFromFile(FileName);
  4986. case PeMapImgTarget(ImageStream.Memory) of
  4987. taWin32:
  4988. Result := PeInsertSection32(ImageStream);
  4989. taWin64:
  4990. Result := PeInsertSection64(ImageStream);
  4991. //taUnknown:
  4992. else
  4993. Result := False;
  4994. end;
  4995. if Result then
  4996. ImageStream.SaveToFile(FileName);
  4997. finally
  4998. ImageStream.Free;
  4999. end;
  5000. end;
  5001. function PeVerifyCheckSum(const FileName: TFileName): Boolean;
  5002. begin
  5003. with CreatePeImage(FileName) do
  5004. try
  5005. Result := VerifyCheckSum;
  5006. finally
  5007. Free;
  5008. end;
  5009. end;
  5010. function PeClearCheckSum(const FileName: TFileName): Boolean;
  5011. function PeClearCheckSum32(ModuleAddress: Pointer): Boolean;
  5012. var
  5013. Headers: PImageNtHeaders32;
  5014. begin
  5015. Headers := PeMapImgNtHeaders32(ModuleAddress);
  5016. Result := (Headers <> nil);
  5017. if Result then
  5018. Headers^.OptionalHeader.CheckSum := 0;
  5019. end;
  5020. function PeClearCheckSum64(ModuleAddress: Pointer): Boolean;
  5021. var
  5022. Headers: PImageNtHeaders64;
  5023. begin
  5024. Headers := PeMapImgNtHeaders64(ModuleAddress);
  5025. Result := (Headers <> nil);
  5026. if Result then
  5027. Headers^.OptionalHeader.CheckSum := 0;
  5028. end;
  5029. var
  5030. Mapping: TJclFileMapping;
  5031. View: TJclFileMappingView;
  5032. begin
  5033. Mapping := TJclFileMapping.Create(FileName, fmOpenReadWrite, '', PAGE_READWRITE, 0, nil);
  5034. try
  5035. View := TJclFileMappingView.Create(Mapping, FILE_MAP_WRITE, 0, 0);
  5036. case PeMapImgTarget(View.Memory) of
  5037. taWin32:
  5038. Result := PeClearCheckSum32(View.Memory);
  5039. taWin64:
  5040. Result := PeClearCheckSum64(View.Memory);
  5041. //taUnknown:
  5042. else
  5043. Result := False;
  5044. end;
  5045. finally
  5046. Mapping.Free;
  5047. end;
  5048. end;
  5049. function PeUpdateCheckSum(const FileName: TFileName): Boolean;
  5050. var
  5051. LI: TLoadedImage;
  5052. begin
  5053. LI.ModuleName := nil;
  5054. // OF: possible loss of data
  5055. Result := MapAndLoad(PAnsiChar(AnsiString(FileName)), nil, LI, True, False);
  5056. if Result then
  5057. Result := UnMapAndLoad(LI);
  5058. end;
  5059. // Various simple PE Image searching and listing routines
  5060. function PeDoesExportFunction(const FileName: TFileName; const FunctionName: string;
  5061. Options: TJclSmartCompOptions): Boolean;
  5062. begin
  5063. with CreatePeImage(FileName) do
  5064. try
  5065. Result := StatusOK and Assigned(ExportList.SmartFindName(FunctionName, Options));
  5066. finally
  5067. Free;
  5068. end;
  5069. end;
  5070. function PeIsExportFunctionForwardedEx(const FileName: TFileName; const FunctionName: string;
  5071. out ForwardedName: string; Options: TJclSmartCompOptions): Boolean;
  5072. var
  5073. ExportItem: TJclPeExportFuncItem;
  5074. begin
  5075. with CreatePeImage(FileName) do
  5076. try
  5077. Result := StatusOK;
  5078. if Result then
  5079. begin
  5080. ExportItem := ExportList.SmartFindName(FunctionName, Options);
  5081. if ExportItem <> nil then
  5082. begin
  5083. Result := ExportItem.IsForwarded;
  5084. ForwardedName := ExportItem.ForwardedName;
  5085. end
  5086. else
  5087. begin
  5088. Result := False;
  5089. ForwardedName := '';
  5090. end;
  5091. end;
  5092. finally
  5093. Free;
  5094. end;
  5095. end;
  5096. function PeIsExportFunctionForwarded(const FileName: TFileName; const FunctionName: string;
  5097. Options: TJclSmartCompOptions): Boolean;
  5098. var
  5099. Dummy: string;
  5100. begin
  5101. Result := PeIsExportFunctionForwardedEx(FileName, FunctionName, Dummy, Options);
  5102. end;
  5103. function PeDoesImportFunction(const FileName: TFileName; const FunctionName: string;
  5104. const LibraryName: string; Options: TJclSmartCompOptions): Boolean;
  5105. begin
  5106. with CreatePeImage(FileName) do
  5107. try
  5108. Result := StatusOK;
  5109. if Result then
  5110. with ImportList do
  5111. begin
  5112. TryGetNamesForOrdinalImports;
  5113. Result := SmartFindName(FunctionName, LibraryName, Options) <> nil;
  5114. end;
  5115. finally
  5116. Free;
  5117. end;
  5118. end;
  5119. function PeDoesImportLibrary(const FileName: TFileName; const LibraryName: string;
  5120. Recursive: Boolean): Boolean;
  5121. var
  5122. SL: TStringList;
  5123. begin
  5124. with CreatePeImage(FileName) do
  5125. try
  5126. Result := StatusOK;
  5127. if Result then
  5128. begin
  5129. SL := InternalImportedLibraries(FileName, Recursive, False, nil);
  5130. try
  5131. Result := SL.IndexOf(LibraryName) > -1;
  5132. finally
  5133. SL.Free;
  5134. end;
  5135. end;
  5136. finally
  5137. Free;
  5138. end;
  5139. end;
  5140. function PeImportedLibraries(const FileName: TFileName; const LibrariesList: TStrings;
  5141. Recursive, FullPathName: Boolean): Boolean;
  5142. var
  5143. SL: TStringList;
  5144. begin
  5145. with CreatePeImage(FileName) do
  5146. try
  5147. Result := StatusOK;
  5148. if Result then
  5149. begin
  5150. SL := InternalImportedLibraries(FileName, Recursive, FullPathName, nil);
  5151. try
  5152. LibrariesList.Assign(SL);
  5153. finally
  5154. SL.Free;
  5155. end;
  5156. end;
  5157. finally
  5158. Free;
  5159. end;
  5160. end;
  5161. function PeImportedFunctions(const FileName: TFileName; const FunctionsList: TStrings;
  5162. const LibraryName: string; IncludeLibNames: Boolean): Boolean;
  5163. var
  5164. I: Integer;
  5165. begin
  5166. with CreatePeImage(FileName) do
  5167. try
  5168. Result := StatusOK;
  5169. if Result then
  5170. with ImportList do
  5171. begin
  5172. TryGetNamesForOrdinalImports;
  5173. FunctionsList.BeginUpdate;
  5174. try
  5175. for I := 0 to AllItemCount - 1 do
  5176. with AllItems[I] do
  5177. if ((Length(LibraryName) = 0) or StrSame(ImportLib.Name, LibraryName)) and
  5178. (Name <> '') then
  5179. begin
  5180. if IncludeLibNames then
  5181. FunctionsList.Add(ImportLib.Name + '=' + Name)
  5182. else
  5183. FunctionsList.Add(Name);
  5184. end;
  5185. finally
  5186. FunctionsList.EndUpdate;
  5187. end;
  5188. end;
  5189. finally
  5190. Free;
  5191. end;
  5192. end;
  5193. function PeExportedFunctions(const FileName: TFileName; const FunctionsList: TStrings): Boolean;
  5194. var
  5195. I: Integer;
  5196. begin
  5197. with CreatePeImage(FileName) do
  5198. try
  5199. Result := StatusOK;
  5200. if Result then
  5201. begin
  5202. FunctionsList.BeginUpdate;
  5203. try
  5204. with ExportList do
  5205. for I := 0 to Count - 1 do
  5206. with Items[I] do
  5207. if not IsExportedVariable then
  5208. FunctionsList.Add(Name);
  5209. finally
  5210. FunctionsList.EndUpdate;
  5211. end;
  5212. end;
  5213. finally
  5214. Free;
  5215. end;
  5216. end;
  5217. function PeExportedNames(const FileName: TFileName; const FunctionsList: TStrings): Boolean;
  5218. var
  5219. I: Integer;
  5220. begin
  5221. with CreatePeImage(FileName) do
  5222. try
  5223. Result := StatusOK;
  5224. if Result then
  5225. begin
  5226. FunctionsList.BeginUpdate;
  5227. try
  5228. with ExportList do
  5229. for I := 0 to Count - 1 do
  5230. FunctionsList.Add(Items[I].Name);
  5231. finally
  5232. FunctionsList.EndUpdate;
  5233. end;
  5234. end;
  5235. finally
  5236. Free;
  5237. end;
  5238. end;
  5239. function PeExportedVariables(const FileName: TFileName; const FunctionsList: TStrings): Boolean;
  5240. var
  5241. I: Integer;
  5242. begin
  5243. with CreatePeImage(FileName) do
  5244. try
  5245. Result := StatusOK;
  5246. if Result then
  5247. begin
  5248. FunctionsList.BeginUpdate;
  5249. try
  5250. with ExportList do
  5251. for I := 0 to Count - 1 do
  5252. with Items[I] do
  5253. if IsExportedVariable then
  5254. FunctionsList.AddObject(Name, Pointer(Address));
  5255. finally
  5256. FunctionsList.EndUpdate;
  5257. end;
  5258. end;
  5259. finally
  5260. Free;
  5261. end;
  5262. end;
  5263. function PeResourceKindNames(const FileName: TFileName; ResourceType: TJclPeResourceKind;
  5264. const NamesList: TStrings): Boolean;
  5265. begin
  5266. with CreatePeImage(FileName) do
  5267. try
  5268. Result := StatusOK and ResourceList.ListResourceNames(ResourceType, NamesList);
  5269. finally
  5270. Free;
  5271. end;
  5272. end;
  5273. {$IFDEF BORLAND}
  5274. function PeBorFormNames(const FileName: TFileName; const NamesList: TStrings): Boolean;
  5275. var
  5276. I: Integer;
  5277. BorImage: TJclPeBorImage;
  5278. BorForm: TJclPeBorForm;
  5279. begin
  5280. BorImage := TJclPeBorImage.Create(True);
  5281. try
  5282. BorImage.FileName := FileName;
  5283. Result := BorImage.IsBorlandImage;
  5284. if Result then
  5285. begin
  5286. NamesList.BeginUpdate;
  5287. try
  5288. for I := 0 to BorImage.FormCount - 1 do
  5289. begin
  5290. BorForm := BorImage.Forms[I];
  5291. NamesList.AddObject(BorForm.DisplayName, Pointer(BorForm.ResItem.RawEntryDataSize));
  5292. end;
  5293. finally
  5294. NamesList.EndUpdate;
  5295. end;
  5296. end;
  5297. finally
  5298. BorImage.Free;
  5299. end;
  5300. end;
  5301. function PeBorDependedPackages(const FileName: TFileName; PackagesList: TStrings;
  5302. FullPathName, Descriptions: Boolean): Boolean;
  5303. var
  5304. BorImage: TJclPeBorImage;
  5305. begin
  5306. BorImage := TJclPeBorImage.Create(True);
  5307. try
  5308. BorImage.FileName := FileName;
  5309. Result := BorImage.DependedPackages(PackagesList, FullPathName, Descriptions);
  5310. finally
  5311. BorImage.Free;
  5312. end;
  5313. end;
  5314. {$ENDIF BORLAND}
  5315. // Missing imports checking routines
  5316. function PeFindMissingImports(const FileName: TFileName; MissingImportsList: TStrings): Boolean;
  5317. var
  5318. Cache: TJclPeImagesCache;
  5319. FileImage, LibImage: TJclPeImage;
  5320. L, I: Integer;
  5321. LibItem: TJclPeImportLibItem;
  5322. List: TStringList;
  5323. begin
  5324. Result := False;
  5325. List := nil;
  5326. Cache := TJclPeImagesCache.Create;
  5327. try
  5328. List := TStringList.Create;
  5329. List.Duplicates := dupIgnore;
  5330. List.Sorted := True;
  5331. FileImage := Cache[FileName];
  5332. if FileImage.StatusOK then
  5333. begin
  5334. for L := 0 to FileImage.ImportList.Count - 1 do
  5335. begin
  5336. LibItem := FileImage.ImportList[L];
  5337. LibImage := Cache[LibItem.FileName];
  5338. if LibImage.StatusOK then
  5339. begin
  5340. LibImage.ExportList.PrepareForFastNameSearch;
  5341. for I := 0 to LibItem.Count - 1 do
  5342. if LibImage.ExportList.ItemFromName[LibItem[I].Name] = nil then
  5343. List.Add(LibItem.Name + '=' + LibItem[I].Name);
  5344. end
  5345. else
  5346. List.Add(LibItem.Name + '=');
  5347. end;
  5348. MissingImportsList.Assign(List);
  5349. Result := List.Count > 0;
  5350. end;
  5351. finally
  5352. List.Free;
  5353. Cache.Free;
  5354. end;
  5355. end;
  5356. function PeFindMissingImports(RequiredImportsList, MissingImportsList: TStrings): Boolean;
  5357. var
  5358. Cache: TJclPeImagesCache;
  5359. LibImage: TJclPeImage;
  5360. I, SepPos: Integer;
  5361. List: TStringList;
  5362. S, LibName, ImportName: string;
  5363. begin
  5364. List := nil;
  5365. Cache := TJclPeImagesCache.Create;
  5366. try
  5367. List := TStringList.Create;
  5368. List.Duplicates := dupIgnore;
  5369. List.Sorted := True;
  5370. for I := 0 to RequiredImportsList.Count - 1 do
  5371. begin
  5372. S := RequiredImportsList[I];
  5373. SepPos := Pos('=', S);
  5374. if SepPos = 0 then
  5375. Continue;
  5376. LibName := StrLeft(S, SepPos - 1);
  5377. LibImage := Cache[LibName];
  5378. if LibImage.StatusOK then
  5379. begin
  5380. LibImage.ExportList.PrepareForFastNameSearch;
  5381. ImportName := StrRestOf(S, SepPos + 1);
  5382. if LibImage.ExportList.ItemFromName[ImportName] = nil then
  5383. List.Add(LibName + '=' + ImportName);
  5384. end
  5385. else
  5386. List.Add(LibName + '=');
  5387. end;
  5388. MissingImportsList.Assign(List);
  5389. Result := List.Count > 0;
  5390. finally
  5391. List.Free;
  5392. Cache.Free;
  5393. end;
  5394. end;
  5395. function PeCreateRequiredImportList(const FileName: TFileName; RequiredImportsList: TStrings): Boolean;
  5396. begin
  5397. Result := PeImportedFunctions(FileName, RequiredImportsList, '', True);
  5398. end;
  5399. // Mapped or loaded image related functions
  5400. function PeMapImgNtHeaders32(const BaseAddress: Pointer): PImageNtHeaders32;
  5401. begin
  5402. Result := nil;
  5403. if IsBadReadPtr(BaseAddress, SizeOf(TImageDosHeader)) then
  5404. Exit;
  5405. if (PImageDosHeader(BaseAddress)^.e_magic <> IMAGE_DOS_SIGNATURE) or
  5406. (PImageDosHeader(BaseAddress)^._lfanew = 0) then
  5407. Exit;
  5408. Result := PImageNtHeaders32(TJclAddr(BaseAddress) + DWORD(PImageDosHeader(BaseAddress)^._lfanew));
  5409. if IsBadReadPtr(Result, SizeOf(TImageNtHeaders32)) or
  5410. (Result^.Signature <> IMAGE_NT_SIGNATURE) then
  5411. Result := nil
  5412. end;
  5413. function PeMapImgNtHeaders32(Stream: TStream; const BasePosition: Int64; out NtHeaders32: TImageNtHeaders32): Int64;
  5414. var
  5415. ImageDosHeader: TImageDosHeader;
  5416. begin
  5417. ResetMemory(NtHeaders32, SizeOf(NtHeaders32));
  5418. Result := -1;
  5419. if (Stream.Seek(BasePosition, soBeginning) <> BasePosition) or
  5420. (Stream.Read(ImageDosHeader, SizeOf(ImageDosHeader)) <> SizeOf(ImageDosHeader)) then
  5421. raise EJclPeImageError.CreateRes(@SReadError);
  5422. if (ImageDosHeader.e_magic <> IMAGE_DOS_SIGNATURE) or
  5423. (ImageDosHeader._lfanew = 0) then
  5424. Exit;
  5425. Result := BasePosition + DWORD(ImageDosHeader._lfanew);
  5426. if (Stream.Seek(Result, soBeginning) <> Result) or
  5427. (Stream.Read(NtHeaders32, SizeOf(NtHeaders32)) <> SizeOf(NtHeaders32)) then
  5428. raise EJclPeImageError.CreateRes(@SReadError);
  5429. if NtHeaders32.Signature <> IMAGE_NT_SIGNATURE then
  5430. Result := -1;
  5431. end;
  5432. function PeMapImgNtHeaders64(const BaseAddress: Pointer): PImageNtHeaders64;
  5433. begin
  5434. Result := nil;
  5435. if IsBadReadPtr(BaseAddress, SizeOf(TImageDosHeader)) then
  5436. Exit;
  5437. if (PImageDosHeader(BaseAddress)^.e_magic <> IMAGE_DOS_SIGNATURE) or
  5438. (PImageDosHeader(BaseAddress)^._lfanew = 0) then
  5439. Exit;
  5440. Result := PImageNtHeaders64(TJclAddr(BaseAddress) + DWORD(PImageDosHeader(BaseAddress)^._lfanew));
  5441. if IsBadReadPtr(Result, SizeOf(TImageNtHeaders64)) or
  5442. (Result^.Signature <> IMAGE_NT_SIGNATURE) then
  5443. Result := nil
  5444. end;
  5445. function PeMapImgNtHeaders64(Stream: TStream; const BasePosition: Int64; out NtHeaders64: TImageNtHeaders64): Int64;
  5446. var
  5447. ImageDosHeader: TImageDosHeader;
  5448. begin
  5449. ResetMemory(NtHeaders64, SizeOf(NtHeaders64));
  5450. Result := -1;
  5451. if (Stream.Seek(BasePosition, soBeginning) <> BasePosition) or
  5452. (Stream.Read(ImageDosHeader, SizeOf(ImageDosHeader)) <> SizeOf(ImageDosHeader)) then
  5453. raise EJclPeImageError.CreateRes(@SReadError);
  5454. if (ImageDosHeader.e_magic <> IMAGE_DOS_SIGNATURE) or
  5455. (ImageDosHeader._lfanew = 0) then
  5456. Exit;
  5457. Result := BasePosition + DWORD(ImageDosHeader._lfanew);
  5458. if (Stream.Seek(Result, soBeginning) <> Result) or
  5459. (Stream.Read(NtHeaders64, SizeOf(NtHeaders64)) <> SizeOf(NtHeaders64)) then
  5460. raise EJclPeImageError.CreateRes(@SReadError);
  5461. if NtHeaders64.Signature <> IMAGE_NT_SIGNATURE then
  5462. Result := -1;
  5463. end;
  5464. function PeMapImgSize(const BaseAddress: Pointer): DWORD;
  5465. begin
  5466. case PeMapImgTarget(BaseAddress) of
  5467. taWin32:
  5468. Result := PeMapImgSize32(BaseAddress);
  5469. taWin64:
  5470. Result := PeMapImgSize64(BaseAddress);
  5471. //taUnknown:
  5472. else
  5473. Result := 0;
  5474. end;
  5475. end;
  5476. function PeMapImgSize(Stream: TStream; const BasePosition: Int64): DWORD;
  5477. begin
  5478. case PeMapImgTarget(Stream, BasePosition) of
  5479. taWin32:
  5480. Result := PeMapImgSize32(Stream, BasePosition);
  5481. taWin64:
  5482. Result := PeMapImgSize64(Stream, BasePosition);
  5483. //taUnknown:
  5484. else
  5485. Result := 0;
  5486. end;
  5487. end;
  5488. function PeMapImgSize32(const BaseAddress: Pointer): DWORD;
  5489. var
  5490. NtHeaders32: PImageNtHeaders32;
  5491. begin
  5492. Result := 0;
  5493. NtHeaders32 := PeMapImgNtHeaders32(BaseAddress);
  5494. if Assigned(NtHeaders32) then
  5495. Result := NtHeaders32^.OptionalHeader.SizeOfImage;
  5496. end;
  5497. function PeMapImgSize32(Stream: TStream; const BasePosition: Int64): DWORD;
  5498. var
  5499. NtHeaders32: TImageNtHeaders32;
  5500. begin
  5501. Result := 0;
  5502. if PeMapImgNtHeaders32(Stream, BasePosition, NtHeaders32) <> -1 then
  5503. Result := NtHeaders32.OptionalHeader.SizeOfImage;
  5504. end;
  5505. function PeMapImgSize64(const BaseAddress: Pointer): DWORD;
  5506. var
  5507. NtHeaders64: PImageNtHeaders64;
  5508. begin
  5509. Result := 0;
  5510. NtHeaders64 := PeMapImgNtHeaders64(BaseAddress);
  5511. if Assigned(NtHeaders64) then
  5512. Result := NtHeaders64^.OptionalHeader.SizeOfImage;
  5513. end;
  5514. function PeMapImgSize64(Stream: TStream; const BasePosition: Int64): DWORD;
  5515. var
  5516. NtHeaders64: TImageNtHeaders64;
  5517. begin
  5518. Result := 0;
  5519. if PeMapImgNtHeaders64(Stream, BasePosition, NtHeaders64) <> -1 then
  5520. Result := NtHeaders64.OptionalHeader.SizeOfImage;
  5521. end;
  5522. function PeMapImgLibraryName(const BaseAddress: Pointer): string;
  5523. begin
  5524. case PeMapImgTarget(BaseAddress) of
  5525. taWin32:
  5526. Result := PeMapImgLibraryName32(BaseAddress);
  5527. taWin64:
  5528. Result := PeMapImgLibraryName64(BaseAddress);
  5529. //taUnknown:
  5530. else
  5531. Result := '';
  5532. end;
  5533. end;
  5534. function PeMapImgLibraryName32(const BaseAddress: Pointer): string;
  5535. var
  5536. NtHeaders: PImageNtHeaders32;
  5537. DataDir: TImageDataDirectory;
  5538. ExportDir: PImageExportDirectory;
  5539. UTF8Name: TUTF8String;
  5540. begin
  5541. Result := '';
  5542. NtHeaders := PeMapImgNtHeaders32(BaseAddress);
  5543. if NtHeaders = nil then
  5544. Exit;
  5545. DataDir := NtHeaders^.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT];
  5546. if DataDir.Size = 0 then
  5547. Exit;
  5548. ExportDir := PImageExportDirectory(TJclAddr(BaseAddress) + DataDir.VirtualAddress);
  5549. if IsBadReadPtr(ExportDir, SizeOf(TImageExportDirectory)) or (ExportDir^.Name = 0) then
  5550. Exit;
  5551. UTF8Name := PAnsiChar(TJclAddr(BaseAddress) + ExportDir^.Name);
  5552. if not TryUTF8ToString(UTF8Name, Result) then
  5553. Result := string(UTF8Name);
  5554. end;
  5555. function PeMapImgLibraryName64(const BaseAddress: Pointer): string;
  5556. var
  5557. NtHeaders: PImageNtHeaders64;
  5558. DataDir: TImageDataDirectory;
  5559. ExportDir: PImageExportDirectory;
  5560. UTF8Name: TUTF8String;
  5561. begin
  5562. Result := '';
  5563. NtHeaders := PeMapImgNtHeaders64(BaseAddress);
  5564. if NtHeaders = nil then
  5565. Exit;
  5566. DataDir := NtHeaders^.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT];
  5567. if DataDir.Size = 0 then
  5568. Exit;
  5569. ExportDir := PImageExportDirectory(TJclAddr(BaseAddress) + DataDir.VirtualAddress);
  5570. if IsBadReadPtr(ExportDir, SizeOf(TImageExportDirectory)) or (ExportDir^.Name = 0) then
  5571. Exit;
  5572. UTF8Name := PAnsiChar(TJclAddr(BaseAddress) + ExportDir^.Name);
  5573. if not TryUTF8ToString(UTF8Name, Result) then
  5574. Result := string(UTF8Name);
  5575. end;
  5576. function PeMapImgTarget(const BaseAddress: Pointer): TJclPeTarget;
  5577. var
  5578. ImageNtHeaders: PImageNtHeaders32;
  5579. begin
  5580. Result := taUnknown;
  5581. ImageNtHeaders := PeMapImgNtHeaders32(BaseAddress);
  5582. if Assigned(ImageNtHeaders) then
  5583. case ImageNtHeaders.FileHeader.Machine of
  5584. IMAGE_FILE_MACHINE_I386:
  5585. Result := taWin32;
  5586. IMAGE_FILE_MACHINE_AMD64:
  5587. Result := taWin64;
  5588. end;
  5589. end;
  5590. function PeMapImgTarget(Stream: TStream; const BasePosition: Int64): TJclPeTarget;
  5591. var
  5592. ImageNtHeaders: TImageNtHeaders32;
  5593. begin
  5594. Result := taUnknown;
  5595. if PeMapImgNtHeaders32(Stream, BasePosition, ImageNtHeaders) <> -1 then
  5596. begin
  5597. case ImageNtHeaders.FileHeader.Machine of
  5598. IMAGE_FILE_MACHINE_I386:
  5599. Result := taWin32;
  5600. IMAGE_FILE_MACHINE_AMD64:
  5601. Result := taWin64;
  5602. end;
  5603. end;
  5604. end;
  5605. function PeMapImgSections32(NtHeaders: PImageNtHeaders32): PImageSectionHeader;
  5606. begin
  5607. if NtHeaders = nil then
  5608. Result := nil
  5609. else
  5610. Result := PImageSectionHeader(TJclAddr(@NtHeaders^.OptionalHeader) +
  5611. NtHeaders^.FileHeader.SizeOfOptionalHeader);
  5612. end;
  5613. function PeMapImgSections32(Stream: TStream; const NtHeaders32Position: Int64; const NtHeaders32: TImageNtHeaders32;
  5614. out ImageSectionHeaders: TImageSectionHeaderArray): Int64;
  5615. var
  5616. SectionSize: Integer;
  5617. begin
  5618. if NtHeaders32Position = -1 then
  5619. begin
  5620. SetLength(ImageSectionHeaders, 0);
  5621. Result := -1;
  5622. end
  5623. else
  5624. begin
  5625. SetLength(ImageSectionHeaders, NtHeaders32.FileHeader.NumberOfSections);
  5626. Result := NtHeaders32Position + SizeOf(NtHeaders32.Signature) + SizeOf(NtHeaders32.FileHeader) + NtHeaders32.FileHeader.SizeOfOptionalHeader;
  5627. SectionSize := SizeOf(ImageSectionHeaders[0]) * Length(ImageSectionHeaders);
  5628. if (Stream.Seek(Result, soBeginning) <> Result) or
  5629. (Stream.Read(ImageSectionHeaders[0], SectionSize) <> SectionSize) then
  5630. raise EJclPeImageError.CreateRes(@SReadError);
  5631. end;
  5632. end;
  5633. function PeMapImgSections64(NtHeaders: PImageNtHeaders64): PImageSectionHeader;
  5634. begin
  5635. if NtHeaders = nil then
  5636. Result := nil
  5637. else
  5638. Result := PImageSectionHeader(TJclAddr(@NtHeaders^.OptionalHeader) +
  5639. NtHeaders^.FileHeader.SizeOfOptionalHeader);
  5640. end;
  5641. function PeMapImgSections64(Stream: TStream; const NtHeaders64Position: Int64; const NtHeaders64: TImageNtHeaders64;
  5642. out ImageSectionHeaders: TImageSectionHeaderArray): Int64;
  5643. var
  5644. SectionSize: Integer;
  5645. begin
  5646. if NtHeaders64Position = -1 then
  5647. begin
  5648. SetLength(ImageSectionHeaders, 0);
  5649. Result := -1;
  5650. end
  5651. else
  5652. begin
  5653. SetLength(ImageSectionHeaders, NtHeaders64.FileHeader.NumberOfSections);
  5654. Result := NtHeaders64Position + SizeOf(NtHeaders64.Signature) + SizeOf(NtHeaders64.FileHeader) + NtHeaders64.FileHeader.SizeOfOptionalHeader;
  5655. SectionSize := SizeOf(ImageSectionHeaders[0]) * Length(ImageSectionHeaders);
  5656. if (Stream.Seek(Result, soBeginning) <> Result) or
  5657. (Stream.Read(ImageSectionHeaders[0], SectionSize) <> SectionSize) then
  5658. raise EJclPeImageError.CreateRes(@SReadError);
  5659. end;
  5660. end;
  5661. function PeMapImgFindSection32(NtHeaders: PImageNtHeaders32;
  5662. const SectionName: string): PImageSectionHeader;
  5663. var
  5664. Header: PImageSectionHeader;
  5665. I: Integer;
  5666. P: PAnsiChar;
  5667. UTF8Name: TUTF8String;
  5668. begin
  5669. Result := nil;
  5670. if NtHeaders <> nil then
  5671. begin
  5672. if not TryStringToUTF8(SectionName, UTF8Name) then
  5673. UTF8Name := TUTF8String(SectionName);
  5674. P := PAnsiChar(UTF8Name);
  5675. Header := PeMapImgSections32(NtHeaders);
  5676. for I := 1 to NtHeaders^.FileHeader.NumberOfSections do
  5677. if StrLCompA(PAnsiChar(@Header^.Name), P, IMAGE_SIZEOF_SHORT_NAME) = 0 then
  5678. begin
  5679. Result := Header;
  5680. Break;
  5681. end
  5682. else
  5683. Inc(Header);
  5684. end;
  5685. end;
  5686. function PeMapImgFindSection64(NtHeaders: PImageNtHeaders64;
  5687. const SectionName: string): PImageSectionHeader;
  5688. var
  5689. Header: PImageSectionHeader;
  5690. I: Integer;
  5691. P: PAnsiChar;
  5692. UTF8Name: TUTF8String;
  5693. begin
  5694. Result := nil;
  5695. if NtHeaders <> nil then
  5696. begin
  5697. if not TryStringToUTF8(SectionName, UTF8Name) then
  5698. UTF8Name := TUTF8String(SectionName);
  5699. P := PAnsiChar(UTF8Name);
  5700. Header := PeMapImgSections64(NtHeaders);
  5701. for I := 1 to NtHeaders^.FileHeader.NumberOfSections do
  5702. if StrLCompA(PAnsiChar(@Header^.Name), P, IMAGE_SIZEOF_SHORT_NAME) = 0 then
  5703. begin
  5704. Result := Header;
  5705. Break;
  5706. end
  5707. else
  5708. Inc(Header);
  5709. end;
  5710. end;
  5711. function PeMapImgFindSection(const ImageSectionHeaders: TImageSectionHeaderArray;
  5712. const SectionName: string): SizeInt;
  5713. var
  5714. P: PAnsiChar;
  5715. UTF8Name: TUTF8String;
  5716. begin
  5717. if Length(ImageSectionHeaders) > 0 then
  5718. begin
  5719. if not TryStringToUTF8(SectionName, UTF8Name) then
  5720. UTF8Name := TUTF8String(SectionName);
  5721. P := PAnsiChar(UTF8Name);
  5722. for Result := Low(ImageSectionHeaders) to High(ImageSectionHeaders) do
  5723. if StrLCompA(PAnsiChar(@ImageSectionHeaders[Result].Name), P, IMAGE_SIZEOF_SHORT_NAME) = 0 then
  5724. Exit;
  5725. end;
  5726. Result := -1;
  5727. end;
  5728. function PeMapImgFindSectionFromModule(const BaseAddress: Pointer;
  5729. const SectionName: string): PImageSectionHeader;
  5730. function PeMapImgFindSectionFromModule32(const BaseAddress: Pointer;
  5731. const SectionName: string): PImageSectionHeader;
  5732. var
  5733. NtHeaders32: PImageNtHeaders32;
  5734. begin
  5735. Result := nil;
  5736. NtHeaders32 := PeMapImgNtHeaders32(BaseAddress);
  5737. if Assigned(NtHeaders32) then
  5738. Result := PeMapImgFindSection32(NtHeaders32, SectionName);
  5739. end;
  5740. function PeMapImgFindSectionFromModule64(const BaseAddress: Pointer;
  5741. const SectionName: string): PImageSectionHeader;
  5742. var
  5743. NtHeaders64: PImageNtHeaders64;
  5744. begin
  5745. Result := nil;
  5746. NtHeaders64 := PeMapImgNtHeaders64(BaseAddress);
  5747. if Assigned(NtHeaders64) then
  5748. Result := PeMapImgFindSection64(NtHeaders64, SectionName);
  5749. end;
  5750. begin
  5751. case PeMapImgTarget(BaseAddress) of
  5752. taWin32:
  5753. Result := PeMapImgFindSectionFromModule32(BaseAddress, SectionName);
  5754. taWin64:
  5755. Result := PeMapImgFindSectionFromModule64(BaseAddress, SectionName);
  5756. //taUnknown:
  5757. else
  5758. Result := nil;
  5759. end;
  5760. end;
  5761. function PeMapImgExportedVariables(const Module: HMODULE; const VariablesList: TStrings): Boolean;
  5762. var
  5763. I: Integer;
  5764. begin
  5765. with TJclPeImage.Create(True) do
  5766. try
  5767. AttachLoadedModule(Module);
  5768. Result := StatusOK;
  5769. if Result then
  5770. begin
  5771. VariablesList.BeginUpdate;
  5772. try
  5773. with ExportList do
  5774. for I := 0 to Count - 1 do
  5775. with Items[I] do
  5776. if IsExportedVariable then
  5777. VariablesList.AddObject(Name, MappedAddress);
  5778. finally
  5779. VariablesList.EndUpdate;
  5780. end;
  5781. end;
  5782. finally
  5783. Free;
  5784. end;
  5785. end;
  5786. function PeMapImgResolvePackageThunk(Address: Pointer): Pointer;
  5787. {$IFDEF BORLAND}
  5788. const
  5789. JmpInstructionCode = $25FF;
  5790. type
  5791. PPackageThunk = ^TPackageThunk;
  5792. TPackageThunk = packed record
  5793. JmpInstruction: Word;
  5794. {$IFDEF CPU32}
  5795. JmpAddress: PPointer;
  5796. {$ENDIF CPU32}
  5797. {$IFDEF CPU64}
  5798. JmpOffset: Int32;
  5799. {$ENDIF CPU64}
  5800. end;
  5801. begin
  5802. if not IsCompiledWithPackages then
  5803. Result := Address
  5804. else
  5805. if not IsBadReadPtr(Address, SizeOf(TPackageThunk)) and
  5806. (PPackageThunk(Address)^.JmpInstruction = JmpInstructionCode) then
  5807. {$IFDEF CPU32}
  5808. Result := PPackageThunk(Address)^.JmpAddress^
  5809. {$ENDIF CPU32}
  5810. {$IFDEF CPU64}
  5811. Result := PPointer(PByte(Address) + SizeOf(TPackageThunk) +
  5812. PPackageThunk(Address)^.JmpOffset)^
  5813. {$ENDIF CPU64}
  5814. else
  5815. Result := nil;
  5816. end;
  5817. {$ENDIF BORLAND}
  5818. {$IFDEF FPC}
  5819. begin
  5820. Result := Address;
  5821. end;
  5822. {$ENDIF FPC}
  5823. function PeMapFindResource(const Module: HMODULE; const ResourceType: PChar;
  5824. const ResourceName: string): Pointer;
  5825. var
  5826. ResItem: TJclPeResourceItem;
  5827. begin
  5828. Result := nil;
  5829. with TJclPeImage.Create(True) do
  5830. try
  5831. AttachLoadedModule(Module);
  5832. if StatusOK then
  5833. begin
  5834. ResItem := ResourceList.FindResource(ResourceType, PChar(ResourceName));
  5835. if (ResItem <> nil) and ResItem.IsDirectory then
  5836. Result := ResItem.List[0].RawEntryData;
  5837. end;
  5838. finally
  5839. Free;
  5840. end;
  5841. end;
  5842. //=== { TJclPeSectionStream } ================================================
  5843. constructor TJclPeSectionStream.Create(Instance: HMODULE; const ASectionName: string);
  5844. begin
  5845. inherited Create;
  5846. Initialize(Instance, ASectionName);
  5847. end;
  5848. procedure TJclPeSectionStream.Initialize(Instance: HMODULE; const ASectionName: string);
  5849. var
  5850. Header: PImageSectionHeader;
  5851. NtHeaders32: PImageNtHeaders32;
  5852. NtHeaders64: PImageNtHeaders64;
  5853. DataSize: Integer;
  5854. begin
  5855. FInstance := Instance;
  5856. case PeMapImgTarget(Pointer(Instance)) of
  5857. taWin32:
  5858. begin
  5859. NtHeaders32 := PeMapImgNtHeaders32(Pointer(Instance));
  5860. if NtHeaders32 = nil then
  5861. raise EJclPeImageError.CreateRes(@RsPeNotPE);
  5862. Header := PeMapImgFindSection32(NtHeaders32, ASectionName);
  5863. end;
  5864. taWin64:
  5865. begin
  5866. NtHeaders64 := PeMapImgNtHeaders64(Pointer(Instance));
  5867. if NtHeaders64 = nil then
  5868. raise EJclPeImageError.CreateRes(@RsPeNotPE);
  5869. Header := PeMapImgFindSection64(NtHeaders64, ASectionName);
  5870. end;
  5871. //toUnknown:
  5872. else
  5873. raise EJclPeImageError.CreateRes(@RsPeUnknownTarget);
  5874. end;
  5875. if Header = nil then
  5876. raise EJclPeImageError.CreateResFmt(@RsPeSectionNotFound, [ASectionName]);
  5877. // Borland and Microsoft seems to have swapped the meaning of this items.
  5878. DataSize := Min(Header^.SizeOfRawData, Header^.Misc.VirtualSize);
  5879. SetPointer(Pointer(FInstance + Header^.VirtualAddress), DataSize);
  5880. FSectionHeader := Header^;
  5881. end;
  5882. function TJclPeSectionStream.Write(const Buffer; Count: Integer): Longint;
  5883. begin
  5884. raise EJclPeImageError.CreateRes(@RsPeReadOnlyStream);
  5885. end;
  5886. //=== { TJclPeMapImgHookItem } ===============================================
  5887. constructor TJclPeMapImgHookItem.Create(AList: TObjectList;
  5888. const AFunctionName: string; const AModuleName: string;
  5889. ABaseAddress, ANewAddress, AOriginalAddress: Pointer);
  5890. begin
  5891. inherited Create;
  5892. FList := AList;
  5893. FFunctionName := AFunctionName;
  5894. FModuleName := AModuleName;
  5895. FBaseAddress := ABaseAddress;
  5896. FNewAddress := ANewAddress;
  5897. FOriginalAddress := AOriginalAddress;
  5898. end;
  5899. destructor TJclPeMapImgHookItem.Destroy;
  5900. begin
  5901. if FBaseAddress <> nil then
  5902. InternalUnhook;
  5903. inherited Destroy;
  5904. end;
  5905. function TJclPeMapImgHookItem.InternalUnhook: Boolean;
  5906. var
  5907. Buf: TMemoryBasicInformation;
  5908. begin
  5909. Buf.AllocationBase := nil;
  5910. if (VirtualQuery(FBaseAddress, Buf, SizeOf(Buf)) = SizeOf(Buf)) and (Buf.State and MEM_FREE = 0) then
  5911. Result := TJclPeMapImgHooks.ReplaceImport(FBaseAddress, ModuleName, NewAddress, OriginalAddress)
  5912. else
  5913. Result := True; // PE image is not available anymore (DLL got unloaded)
  5914. if Result then
  5915. FBaseAddress := nil;
  5916. end;
  5917. function TJclPeMapImgHookItem.Unhook: Boolean;
  5918. begin
  5919. Result := InternalUnhook;
  5920. if Result then
  5921. FList.Remove(Self);
  5922. end;
  5923. //=== { TJclPeMapImgHooks } ==================================================
  5924. type
  5925. PWin9xDebugThunk32 = ^TWin9xDebugThunk32;
  5926. TWin9xDebugThunk32 = packed record
  5927. PUSH: Byte; // PUSH instruction opcode ($68)
  5928. Addr: DWORD; // The actual address of the DLL routine
  5929. JMP: Byte; // JMP instruction opcode ($E9)
  5930. Rel: DWORD; // Relative displacement (a Kernel32 address)
  5931. end;
  5932. function TJclPeMapImgHooks.GetItemFromNewAddress(NewAddress: Pointer): TJclPeMapImgHookItem;
  5933. var
  5934. I: Integer;
  5935. begin
  5936. Result := nil;
  5937. for I := 0 to Count - 1 do
  5938. if Items[I].NewAddress = NewAddress then
  5939. begin
  5940. Result := Items[I];
  5941. Break;
  5942. end;
  5943. end;
  5944. function TJclPeMapImgHooks.GetItemFromOriginalAddress(OriginalAddress: Pointer): TJclPeMapImgHookItem;
  5945. var
  5946. I: Integer;
  5947. begin
  5948. Result := nil;
  5949. for I := 0 to Count - 1 do
  5950. if Items[I].OriginalAddress = OriginalAddress then
  5951. begin
  5952. Result := Items[I];
  5953. Break;
  5954. end;
  5955. end;
  5956. function TJclPeMapImgHooks.GetItems(Index: TJclListSize): TJclPeMapImgHookItem;
  5957. begin
  5958. Result := TJclPeMapImgHookItem(Get(Index));
  5959. end;
  5960. function TJclPeMapImgHooks.HookImport(Base: Pointer; const ModuleName: string;
  5961. const FunctionName: string; NewAddress: Pointer; var OriginalAddress: Pointer): Boolean;
  5962. var
  5963. ModuleHandle: THandle;
  5964. OriginalItem: TJclPeMapImgHookItem;
  5965. UTF8Name: TUTF8String;
  5966. begin
  5967. ModuleHandle := GetModuleHandle(PChar(ModuleName));
  5968. Result := (ModuleHandle <> 0);
  5969. if not Result then
  5970. begin
  5971. SetLastError(ERROR_MOD_NOT_FOUND);
  5972. Exit;
  5973. end;
  5974. if not TryStringToUTF8(FunctionName, UTF8Name) then
  5975. UTF8Name := TUTF8String(FunctionName);
  5976. OriginalAddress := GetProcAddress(ModuleHandle, PAnsiChar(UTF8Name));
  5977. Result := (OriginalAddress <> nil);
  5978. if not Result then
  5979. begin
  5980. SetLastError(ERROR_PROC_NOT_FOUND);
  5981. Exit;
  5982. end;
  5983. OriginalItem := ItemFromOriginalAddress[OriginalAddress];
  5984. Result := ((OriginalItem = nil) or (OriginalItem.ModuleName = ModuleName)) and
  5985. (NewAddress <> nil) and (OriginalAddress <> NewAddress);
  5986. if not Result then
  5987. begin
  5988. SetLastError(ERROR_ALREADY_EXISTS);
  5989. Exit;
  5990. end;
  5991. if Result then
  5992. Result := ReplaceImport(Base, ModuleName, OriginalAddress, NewAddress);
  5993. if Result then
  5994. begin
  5995. Add(TJclPeMapImgHookItem.Create(Self, FunctionName, ModuleName, Base,
  5996. NewAddress, OriginalAddress));
  5997. end
  5998. else
  5999. SetLastError(ERROR_INVALID_PARAMETER);
  6000. end;
  6001. class function TJclPeMapImgHooks.IsWin9xDebugThunk(P: Pointer): Boolean;
  6002. begin
  6003. with PWin9xDebugThunk32(P)^ do
  6004. Result := (PUSH = $68) and (JMP = $E9);
  6005. end;
  6006. class function TJclPeMapImgHooks.ReplaceImport(Base: Pointer; const ModuleName: string;
  6007. FromProc, ToProc: Pointer): Boolean;
  6008. var
  6009. {$IFDEF CPU32}
  6010. FromProcDebugThunk32, ImportThunk32: PWin9xDebugThunk32;
  6011. IsThunked: Boolean;
  6012. NtHeader: PImageNtHeaders32;
  6013. ImportEntry: PImageThunkData32;
  6014. {$ENDIF CPU32}
  6015. {$IFDEF CPU64}
  6016. NtHeader: PImageNtHeaders64;
  6017. ImportEntry: PImageThunkData64;
  6018. {$ENDIF CPU64}
  6019. ImportDir: TImageDataDirectory;
  6020. ImportDesc: PImageImportDescriptor;
  6021. CurrName, RefName: PAnsiChar;
  6022. FoundProc: Boolean;
  6023. WrittenBytes: Cardinal;
  6024. UTF8Name: TUTF8String;
  6025. begin
  6026. Result := False;
  6027. {$IFDEF CPU32}
  6028. FromProcDebugThunk32 := PWin9xDebugThunk32(FromProc);
  6029. IsThunked := (Win32Platform <> VER_PLATFORM_WIN32_NT) and IsWin9xDebugThunk(FromProcDebugThunk32);
  6030. NtHeader := PeMapImgNtHeaders32(Base);
  6031. {$ENDIF CPU32}
  6032. {$IFDEF CPU64}
  6033. NtHeader := PeMapImgNtHeaders64(Base);
  6034. {$ENDIF CPU64}
  6035. if NtHeader = nil then
  6036. Exit;
  6037. ImportDir := NtHeader.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT];
  6038. if ImportDir.VirtualAddress = 0 then
  6039. Exit;
  6040. ImportDesc := PImageImportDescriptor(TJclAddr(Base) + ImportDir.VirtualAddress);
  6041. if not TryStringToUTF8(ModuleName, UTF8Name) then
  6042. UTF8Name := TUTF8String(ModuleName);
  6043. RefName := PAnsiChar(UTF8Name);
  6044. while ImportDesc^.Name <> 0 do
  6045. begin
  6046. CurrName := PAnsiChar(Base) + ImportDesc^.Name;
  6047. if StrICompA(CurrName, RefName) = 0 then
  6048. begin
  6049. {$IFDEF CPU32}
  6050. ImportEntry := PImageThunkData32(TJclAddr(Base) + ImportDesc^.FirstThunk);
  6051. {$ENDIF CPU32}
  6052. {$IFDEF CPU64}
  6053. ImportEntry := PImageThunkData64(TJclAddr(Base) + ImportDesc^.FirstThunk);
  6054. {$ENDIF CPU64}
  6055. while ImportEntry^.Function_ <> 0 do
  6056. begin
  6057. {$IFDEF CPU32}
  6058. if IsThunked then
  6059. begin
  6060. ImportThunk32 := PWin9xDebugThunk32(ImportEntry^.Function_);
  6061. FoundProc := IsWin9xDebugThunk(ImportThunk32) and (ImportThunk32^.Addr = FromProcDebugThunk32^.Addr);
  6062. end
  6063. else
  6064. {$ENDIF CPU32}
  6065. FoundProc := Pointer(ImportEntry^.Function_) = FromProc;
  6066. if FoundProc then
  6067. Result := WriteProtectedMemory(@ImportEntry^.Function_, @ToProc, SizeOf(ToProc), WrittenBytes);
  6068. Inc(ImportEntry);
  6069. end;
  6070. end;
  6071. Inc(ImportDesc);
  6072. end;
  6073. end;
  6074. class function TJclPeMapImgHooks.SystemBase: Pointer;
  6075. begin
  6076. Result := Pointer(SystemTObjectInstance);
  6077. end;
  6078. procedure TJclPeMapImgHooks.UnhookAll;
  6079. var
  6080. I: Integer;
  6081. begin
  6082. I := 0;
  6083. while I < Count do
  6084. if not Items[I].Unhook then
  6085. Inc(I);
  6086. end;
  6087. function TJclPeMapImgHooks.UnhookByNewAddress(NewAddress: Pointer): Boolean;
  6088. var
  6089. Item: TJclPeMapImgHookItem;
  6090. begin
  6091. Item := ItemFromNewAddress[NewAddress];
  6092. Result := (Item <> nil) and Item.Unhook;
  6093. end;
  6094. procedure TJclPeMapImgHooks.UnhookByBaseAddress(BaseAddress: Pointer);
  6095. var
  6096. I: Integer;
  6097. begin
  6098. for I := Count - 1 downto 0 do
  6099. if Items[I].BaseAddress = BaseAddress then
  6100. Items[I].Unhook;
  6101. end;
  6102. // Image access under a debbuger
  6103. {$IFDEF USE_64BIT_TYPES}
  6104. function InternalReadProcMem(ProcessHandle: THandle; Address: DWORD;
  6105. Buffer: Pointer; Size: SIZE_T): Boolean;
  6106. var
  6107. BR: SIZE_T;
  6108. {$ELSE}
  6109. function InternalReadProcMem(ProcessHandle: THandle; Address: DWORD;
  6110. Buffer: Pointer; Size: Integer): Boolean;
  6111. var
  6112. BR: DWORD;
  6113. {$ENDIF}
  6114. begin
  6115. BR := 0;
  6116. Result := ReadProcessMemory(ProcessHandle, Pointer(Address), Buffer, Size, BR);
  6117. end;
  6118. // TODO: 64 bit version
  6119. function PeDbgImgNtHeaders32(ProcessHandle: THandle; BaseAddress: TJclAddr32;
  6120. var NtHeaders: TImageNtHeaders32): Boolean;
  6121. var
  6122. DosHeader: TImageDosHeader;
  6123. begin
  6124. Result := False;
  6125. ResetMemory(NtHeaders, SizeOf(NtHeaders));
  6126. ResetMemory(DosHeader, SizeOf(DosHeader));
  6127. if not InternalReadProcMem(ProcessHandle, TJclAddr32(BaseAddress), @DosHeader, SizeOf(DosHeader)) then
  6128. Exit;
  6129. if DosHeader.e_magic <> IMAGE_DOS_SIGNATURE then
  6130. Exit;
  6131. Result := InternalReadProcMem(ProcessHandle, TJclAddr32(BaseAddress) + TJclAddr32(DosHeader._lfanew),
  6132. @NtHeaders, SizeOf(TImageNtHeaders32));
  6133. end;
  6134. // TODO: 64 bit version
  6135. function PeDbgImgLibraryName32(ProcessHandle: THandle; BaseAddress: TJclAddr32;
  6136. var Name: string): Boolean;
  6137. var
  6138. NtHeaders32: TImageNtHeaders32;
  6139. DataDir: TImageDataDirectory;
  6140. ExportDir: TImageExportDirectory;
  6141. UTF8Name: TUTF8String;
  6142. begin
  6143. Name := '';
  6144. NtHeaders32.Signature := 0;
  6145. Result := PeDbgImgNtHeaders32(ProcessHandle, BaseAddress, NtHeaders32);
  6146. if not Result then
  6147. Exit;
  6148. DataDir := NtHeaders32.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT];
  6149. if DataDir.Size = 0 then
  6150. Exit;
  6151. if not InternalReadProcMem(ProcessHandle, TJclAddr(BaseAddress) + DataDir.VirtualAddress,
  6152. @ExportDir, SizeOf(ExportDir)) then
  6153. Exit;
  6154. if ExportDir.Name = 0 then
  6155. Exit;
  6156. SetLength(UTF8Name, MAX_PATH);
  6157. if InternalReadProcMem(ProcessHandle, TJclAddr(BaseAddress) + ExportDir.Name, PAnsiChar(UTF8Name), MAX_PATH) then
  6158. begin
  6159. StrResetLength(UTF8Name);
  6160. if not TryUTF8ToString(UTF8Name, Name) then
  6161. Name := string(UTF8Name);
  6162. end
  6163. else
  6164. Name := '';
  6165. end;
  6166. // Borland BPL packages name unmangling
  6167. {$IFDEF CPU64}
  6168. function PeBorUnmangleName(const Name: string; out Unmangled: string;
  6169. out Description: TJclBorUmDescription; out BasePos: Integer): TJclBorUmResult;
  6170. var
  6171. CurPos: Integer;
  6172. EndPos: Integer;
  6173. Len: Integer;
  6174. PrevBasePos: Integer;
  6175. begin
  6176. if (Length(Name) > 3) and (Name[1] = '_') and (Name[2] = 'Z') and (Name[3] = 'N') then
  6177. begin
  6178. Result := urOk;
  6179. CurPos := 4;
  6180. BasePos := 0;
  6181. PrevBasePos := 0;
  6182. while CurPos < Length(Name) do
  6183. begin
  6184. EndPos := CurPos;
  6185. while CharInSet(Name[EndPos], ['0'..'9']) do
  6186. Inc(EndPos);
  6187. if not TryStrToInt(Copy(Name, CurPos, EndPos - CurPos), Len) then
  6188. Break;
  6189. BasePos := PrevBasePos;
  6190. PrevBasePos := Length(Unmangled);
  6191. if Unmangled <> '' then
  6192. Unmangled := Unmangled + '.';
  6193. Unmangled := Unmangled + Copy(Name, EndPos, Len);
  6194. CurPos := EndPos + Len;
  6195. end;
  6196. if BasePos = 0 then
  6197. BasePos := PrevBasePos + 2
  6198. else
  6199. BasePos := BasePos + 2;
  6200. Description.Kind := skFunction;
  6201. Description.Modifiers := [];
  6202. end
  6203. else
  6204. Result := urNotMangled;
  6205. end;
  6206. {$ENDIF CPU64}
  6207. {$IFDEF CPU32}
  6208. function PeBorUnmangleName(const Name: string; out Unmangled: string;
  6209. out Description: TJclBorUmDescription; out BasePos: Integer): TJclBorUmResult;
  6210. var
  6211. NameP, NameU, NameUFirst: PAnsiChar;
  6212. QualifierFound, LinkProcFound: Boolean;
  6213. UTF8Unmangled, UTF8Name: TUTF8String;
  6214. procedure MarkQualifier;
  6215. begin
  6216. if not QualifierFound then
  6217. begin
  6218. QualifierFound := True;
  6219. BasePos := NameU - NameUFirst + 2;
  6220. end;
  6221. end;
  6222. procedure ReadSpecialSymbol;
  6223. var
  6224. SymbolLength: Integer;
  6225. begin
  6226. SymbolLength := 0;
  6227. while CharIsDigit(Char(NameP^)) do
  6228. begin
  6229. SymbolLength := SymbolLength * 10 + Ord(NameP^) - 48;
  6230. Inc(NameP);
  6231. end;
  6232. while (SymbolLength > 0) and (NameP^ <> #0) do
  6233. begin
  6234. if NameP^ = '@' then
  6235. begin
  6236. MarkQualifier;
  6237. NameU^ := '.';
  6238. end
  6239. else
  6240. NameU^ := NameP^;
  6241. Inc(NameP);
  6242. Inc(NameU);
  6243. Dec(SymbolLength);
  6244. end;
  6245. end;
  6246. procedure ReadRTTI;
  6247. begin
  6248. if StrLCompA(NameP, '$xp$', 4) = 0 then
  6249. begin
  6250. Inc(NameP, 4);
  6251. Description.Kind := skRTTI;
  6252. QualifierFound := False;
  6253. ReadSpecialSymbol;
  6254. if QualifierFound then
  6255. Include(Description.Modifiers, smQualified);
  6256. end
  6257. else
  6258. Result := urError;
  6259. end;
  6260. procedure ReadNameSymbol;
  6261. begin
  6262. if NameP^ = '@' then
  6263. begin
  6264. LinkProcFound := True;
  6265. Inc(NameP);
  6266. end;
  6267. while CharIsValidIdentifierLetter(Char(NameP^)) do
  6268. begin
  6269. NameU^ := NameP^;
  6270. Inc(NameP);
  6271. Inc(NameU);
  6272. end;
  6273. end;
  6274. procedure ReadName;
  6275. begin
  6276. Description.Kind := skData;
  6277. QualifierFound := False;
  6278. LinkProcFound := False;
  6279. repeat
  6280. ReadNameSymbol;
  6281. if LinkProcFound and not QualifierFound then
  6282. LinkProcFound := False;
  6283. case NameP^ of
  6284. '@':
  6285. case (NameP + 1)^ of
  6286. #0:
  6287. begin
  6288. Description.Kind := skVTable;
  6289. Break;
  6290. end;
  6291. '$':
  6292. begin
  6293. if (NameP + 2)^ = 'b' then
  6294. begin
  6295. case (NameP + 3)^ of
  6296. 'c':
  6297. Description.Kind := skConstructor;
  6298. 'd':
  6299. Description.Kind := skDestructor;
  6300. end;
  6301. Inc(NameP, 6);
  6302. end
  6303. else
  6304. Description.Kind := skFunction;
  6305. Break; // no parameters unmangling yet
  6306. end;
  6307. else
  6308. MarkQualifier;
  6309. NameU^ := '.';
  6310. Inc(NameU);
  6311. Inc(NameP);
  6312. end;
  6313. '$':
  6314. begin
  6315. Description.Kind := skFunction;
  6316. Break; // no parameters unmangling yet
  6317. end;
  6318. else
  6319. Break;
  6320. end;
  6321. until False;
  6322. if QualifierFound then
  6323. Include(Description.Modifiers, smQualified);
  6324. if LinkProcFound then
  6325. Include(Description.Modifiers, smLinkProc);
  6326. end;
  6327. begin
  6328. if not TryStringToUTF8(Name, UTF8Name) then
  6329. UTF8Name := TUTF8String(Name);
  6330. NameP := PAnsiChar(UTF8Name);
  6331. Result := urError;
  6332. case NameP^ of
  6333. '@':
  6334. Result := urOk;
  6335. '?':
  6336. Result := urMicrosoft;
  6337. '_', 'A'..'Z', 'a'..'z':
  6338. Result := urNotMangled;
  6339. end;
  6340. if Result <> urOk then
  6341. Exit;
  6342. Inc(NameP);
  6343. SetLength(UTF8UnMangled, 1024);
  6344. NameU := PAnsiChar(UTF8UnMangled);
  6345. NameUFirst := NameU;
  6346. Description.Modifiers := [];
  6347. BasePos := 1;
  6348. case NameP^ of
  6349. '$':
  6350. ReadRTTI;
  6351. '_', 'A'..'Z', 'a'..'z':
  6352. ReadName;
  6353. else
  6354. Result := urError;
  6355. end;
  6356. NameU^ := #0;
  6357. SetLength(UTF8Unmangled, StrLenA(PAnsiChar(UTF8Unmangled))); // SysUtils prefix due to compiler bug
  6358. if not TryUTF8ToString(UTF8Unmangled, Unmangled) then
  6359. Unmangled := string(UTF8Unmangled);
  6360. end;
  6361. {$ENDIF CPU32}
  6362. function PeBorUnmangleName(const Name: string; out Unmangled: string;
  6363. out Description: TJclBorUmDescription): TJclBorUmResult;
  6364. var
  6365. BasePos: Integer;
  6366. begin
  6367. Result := PeBorUnmangleName(Name, Unmangled, Description, BasePos);
  6368. end;
  6369. function PeBorUnmangleName(const Name: string; out Unmangled: string): TJclBorUmResult;
  6370. var
  6371. Description: TJclBorUmDescription;
  6372. BasePos: Integer;
  6373. begin
  6374. Result := PeBorUnmangleName(Name, Unmangled, Description, BasePos);
  6375. end;
  6376. function PeBorUnmangleName(const Name: string): string;
  6377. var
  6378. Unmangled: string;
  6379. Description: TJclBorUmDescription;
  6380. BasePos: Integer;
  6381. begin
  6382. if PeBorUnmangleName(Name, Unmangled, Description, BasePos) = urOk then
  6383. Result := Unmangled
  6384. else
  6385. Result := '';
  6386. end;
  6387. function PeIsNameMangled(const Name: string): TJclPeUmResult; {$IFDEF SUPPORTS_INLINE}inline;{$ENDIF}
  6388. begin
  6389. Result := umNotMangled;
  6390. if Length(Name) > 0 then
  6391. case Name[1] of
  6392. '@':
  6393. Result := umBorland;
  6394. '?':
  6395. Result := umMicrosoft;
  6396. {$IFDEF CPU64}
  6397. '_':
  6398. if (Length(Name) > 3) and (Name[2] = 'Z') and (Name[3] = 'N') then
  6399. Result := umBorland;
  6400. {$ENDIF CPU64}
  6401. end;
  6402. end;
  6403. type
  6404. TUndecorateSymbolNameA = function (DecoratedName: PAnsiChar;
  6405. UnDecoratedName: PAnsiChar; UndecoratedLength: DWORD; Flags: DWORD): DWORD; stdcall;
  6406. // 'imagehlp.dll' 'UnDecorateSymbolName'
  6407. TUndecorateSymbolNameW = function (DecoratedName: PWideChar;
  6408. UnDecoratedName: PWideChar; UndecoratedLength: DWORD; Flags: DWORD): DWORD; stdcall;
  6409. // 'imagehlp.dll' 'UnDecorateSymbolNameW'
  6410. var
  6411. UndecorateSymbolNameA: TUndecorateSymbolNameA = nil;
  6412. UndecorateSymbolNameAFailed: Boolean = False;
  6413. UndecorateSymbolNameW: TUndecorateSymbolNameW = nil;
  6414. UndecorateSymbolNameWFailed: Boolean = False;
  6415. function UndecorateSymbolName(const DecoratedName: string; out UnMangled: string; Flags: DWORD): Boolean;
  6416. const
  6417. ModuleName = 'imagehlp.dll';
  6418. BufferSize = 512;
  6419. var
  6420. ModuleHandle: HMODULE;
  6421. WideBuffer: WideString;
  6422. AnsiBuffer: AnsiString;
  6423. Res: DWORD;
  6424. begin
  6425. Result := False;
  6426. if ((not Assigned(UndecorateSymbolNameA)) and (not UndecorateSymbolNameAFailed)) or
  6427. ((not Assigned(UndecorateSymbolNameW)) and (not UndecorateSymbolNameWFailed)) then
  6428. begin
  6429. ModuleHandle := GetModuleHandle(ModuleName);
  6430. if ModuleHandle = 0 then
  6431. begin
  6432. ModuleHandle := SafeLoadLibrary(ModuleName);
  6433. if ModuleHandle = 0 then
  6434. Exit;
  6435. end;
  6436. UndecorateSymbolNameA := GetProcAddress(ModuleHandle, 'UnDecorateSymbolName');
  6437. UndecorateSymbolNameAFailed := not Assigned(UndecorateSymbolNameA);
  6438. UndecorateSymbolNameW := GetProcAddress(ModuleHandle, 'UnDecorateSymbolNameW');
  6439. UndecorateSymbolNameWFailed := not Assigned(UndecorateSymbolNameW);
  6440. end;
  6441. if Assigned(UndecorateSymbolNameW) then
  6442. begin
  6443. SetLength(WideBuffer, BufferSize);
  6444. Res := UnDecorateSymbolNameW(PWideChar({$IFNDEF UNICODE}WideString{$ENDIF}(DecoratedName)), PWideChar(WideBuffer), BufferSize, Flags);
  6445. if Res > 0 then
  6446. begin
  6447. StrResetLength(WideBuffer);
  6448. UnMangled := string(WideBuffer);
  6449. Result := True;
  6450. end;
  6451. end
  6452. else
  6453. if Assigned(UndecorateSymbolNameA) then
  6454. begin
  6455. SetLength(AnsiBuffer, BufferSize);
  6456. Res := UnDecorateSymbolNameA(PAnsiChar(AnsiString(DecoratedName)), PAnsiChar(AnsiBuffer), BufferSize, Flags);
  6457. if Res > 0 then
  6458. begin
  6459. StrResetLength(AnsiBuffer);
  6460. UnMangled := string(AnsiBuffer);
  6461. Result := True;
  6462. end;
  6463. end;
  6464. // For some functions UnDecorateSymbolName returns 'long'
  6465. if Result and (UnMangled = 'long') then
  6466. UnMangled := DecoratedName;
  6467. end;
  6468. function PeUnmangleName(const Name: string; out Unmangled: string): TJclPeUmResult;
  6469. begin
  6470. Result := umNotMangled;
  6471. case PeBorUnmangleName(Name, Unmangled) of
  6472. urOk:
  6473. Result := umBorland;
  6474. urMicrosoft:
  6475. if UndecorateSymbolName(Name, Unmangled, UNDNAME_NAME_ONLY) then
  6476. Result := umMicrosoft;
  6477. end;
  6478. if Result = umNotMangled then
  6479. Unmangled := Name;
  6480. end;
  6481. {$IFDEF UNITVERSIONING}
  6482. initialization
  6483. RegisterUnitVersion(HInstance, UnitVersioning);
  6484. finalization
  6485. UnregisterUnitVersion(HInstance);
  6486. {$ENDIF UNITVERSIONING}
  6487. end.