Skip to main content

PeBinary

Struct PeBinary 

Source
pub struct PeBinary {
    pub load_address: u64,
    pub sections: Vec<PeSection>,
    pub analysis: PeAnalysis,
    pub architecture: Arch,
    pub is_64: bool,
}
Expand description

A parsed and loaded PE32/PE32+ executable image.

Fields§

§load_address: u64§sections: Vec<PeSection>§analysis: PeAnalysis§architecture: Arch§is_64: bool

Implementations§

Source§

impl PeBinary

Source

pub fn parse(file_bytes: &[u8]) -> Result<Self, PeError>

Parse a PE32/PE32+ executable from raw file bytes.

Trait Implementations§

Source§

impl BinaryFormat for PeBinary

Source§

fn linked_libraries(&self) -> Vec<String>

Import-directory DLL names in first-seen order, deduplicated case-insensitively but reported in their original case.

Source§

fn is_known_read_only(&self, addr: u64) -> bool

A mapped section without IMAGE_SCN_MEM_WRITE is proven read-only. (There is deliberately no is_known_writable override: flipping that predicate would change which constants the folding passes trust, which is a separate question from proving a region immutable.)

Source§

fn load_address(&self) -> u64

The lowest virtual address mapped by this binary image.
Source§

fn architecture(&self) -> Arch

Name of the architecture, should use embedded information from known binary format, or raw values from the blob.
Source§

fn os(&self) -> TargetOs

The operating system this binary targets, inferred from the container format. Defaults to TargetOs::Unknown; PE returns Windows, ELF Linux.
Source§

fn byte_at(&self, addr: u64) -> Option<u8>

Return the byte mapped at addr, or None if the address is unmapped.
Source§

fn bytes_at(&self, addr: u64) -> Option<&[u8]>

Return the contiguous bytes available at addr. Read more
Source§

fn mapped_regions(&self) -> Vec<(u64, Vec<u8>, bool, bool)>

Enumerate the binary’s mapped regions as (start, bytes, executable, writable). Read more
Source§

fn segment_bounds(&self, addr: u64) -> Option<(u64, u64)>

The [start, end) bounds of the mapped region containing addr, if any. Used to key per-segment facts (e.g. executability propositions) so repeated queries in one region collapse to a single entry. Defaults to None for formats that do not expose their segments.
Source§

fn symbol_name(&self, addr: u64) -> Option<&str>

Return the symbol name for the function starting at addr, if the binary format has one (e.g. from an ELF symbol table). Returns None for formats with no symbol information.
Source§

fn is_external_symbol(&self, addr: u64) -> bool

Returns true if addr is an external (imported) function stub, e.g. a PLT thunk. The recursive disassembler will not lift the body of external functions. Defaults to false.
Source§

fn entry_points(&self) -> Vec<u64>

Known entry points into this binary (entrypoint, symbol table functions, etc.). The recursive disassembler should be seeded with these addresses.
Source§

fn entrypoint(&self) -> Option<u64>

The binary’s primary entry point (e.g. the ELF e_entry), if the format designates one. Unlike entry_points, this is the single address where execution begins. Returns None for formats with no distinguished entry.
Source§

fn import_symbol_name(&self, addr: u64) -> Option<&str>

Return the imported symbol whose resolver slot lives at addr, if any. Read more
Source§

fn import_library(&self, addr: u64) -> Option<&str>

Return the name of the library providing the external function stub at addr: the PE import-directory DLL, or the ELF .gnu.version_r soname the symbol’s version requirement points at. None when the format does not record a per-symbol source library (e.g. an unversioned ELF import).
Source§

fn hex_rows( &self, addr: u64, len: usize, width: usize, ) -> Vec<(u64, Vec<Option<u8>>)>

Return rows of bytes suitable for a hex viewer. Read more
Source§

fn contains(&self, addr: u64) -> bool

Return true if addr is mapped by this binary image.
Source§

fn is_executable(&self, addr: u64) -> bool

Return true if addr lies in an executable region of this binary image. Defaults to “mapped” for formats that don’t track per-region permissions; formats with permission information (e.g. ELF segment flags) should override this.
Source§

fn is_known_writable(&self, _addr: u64) -> bool

Return true only if addr lies in a region known to be writable (from the container’s segment flags). Passes that fold a value out of initialized memory use this to refuse mutable memory — e.g. a GOT slot the dynamic linker overwrites at load time. Defaults to false (“not proven writable”); Blob keeps the default.
Source§

fn read_bytes(&self, addr: u64, n: usize) -> Option<Vec<u8>>

Read n bytes at virtual address addr. Read more
Source§

fn read_uint(&self, addr: u64, size: usize) -> Option<u64>

Read a little-endian unsigned integer of size bytes (1..=8) at addr. Read more
Source§

fn read_cstring(&self, addr: u64, max_len: Option<usize>) -> Option<Vec<u8>>

Read a null-terminated C string at virtual address addr, returning the bytes up to (but not including) the null terminator. Read more
Source§

fn read_printable_cstring( &self, addr: u64, max_len: Option<usize>, ) -> Option<Vec<u8>>

Read a null-terminated C string at virtual address addr, requiring every byte before the null terminator to be printable ASCII. Read more
Source§

impl Clone for PeBinary

Source§

fn clone(&self) -> PeBinary

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for PeBinary

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.