Skip to main content

PeFile

Struct PeFile 

Source
pub struct PeFile { /* private fields */ }
Expand description

An owning wrapper around a PE/EFI image (UKI).

Holds the file bytes, parses with goblin on demand, and returns borrowed slices tied to &self. This avoids lifetimes in the public API and side-steps self-referential types.

Implementations§

Source§

impl PeFile

Source

pub fn from_path(path: &Path) -> Result<Self>

Read a PE/EFI image from disk and own its bytes.

Source

pub fn from_bytes(bytes: Vec<u8>) -> Result<Self>

Construct from a caller-provided byte vector.

Source

pub fn image(&self) -> &[u8]

Access the full image buffer (read-only).

Source

pub fn arch_summary(&self) -> Result<(&'static str, bool)>

Return a human-oriented architecture label and PE32+ flag.

Common results:

  • ("x86_64", true) for amd64 UKIs
  • ("aarch64", true) for ARM64 UKIs
  • ("i386", false) for 32-bit x86
Source

pub fn section_info(&self, name: &str) -> Result<Option<(usize, usize)>>

Offset and file size of a named section, if it exists. (file_offset, file_size)

Source

pub fn section_bytes(&self, name: &str) -> Result<Option<&[u8]>>

Borrow raw bytes of a named section (e.g., “.initrd”, “.linux”, “.cmdline”).

Returns Ok(None) if the section is missing or coordinates are invalid.

Source

pub fn read_text(&self, name: &str) -> Result<Option<String>>

Read a section as text (trim at first NUL). Ideal for .cmdline / .osrel.

Source

pub fn is_signed(&self) -> Result<bool>

True if the image contains one or more Attribute Certificates.

Presence indicates a Certificate Table exists; it does not mean the signature is valid. Modifying sections (e.g., .initrd) will typically invalidate verification in Secure Boot.

Source

pub fn certificate_metadata(&self) -> Result<Vec<(u32, u16, u16)>>

Lightweight metadata for each attribute certificate: (length, revision, type).

revision and typ come from the WIN_CERTIFICATE header. The blob itself is usually PKCS#7 SignedData (typ 0x0002).

Source

pub fn certificate_blobs(&self) -> Result<Vec<&[u8]>>

The raw certificate blobs (&[u8]) for each attribute certificate.

Trait Implementations§

Source§

impl Debug for PeFile

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more