pub struct PeBinary {
pub load_address: u64,
pub sections: Vec<PeSection>,
pub analysis: PeAnalysis,
pub architecture: Arch,
pub is_64: bool,
}Expand description
A parsed and loaded PE32/PE32+ executable image.
Fields§
§load_address: u64§sections: Vec<PeSection>§analysis: PeAnalysis§architecture: Arch§is_64: boolImplementations§
Trait Implementations§
Source§impl BinaryFormat for PeBinary
impl BinaryFormat for PeBinary
Source§fn linked_libraries(&self) -> Vec<String>
fn linked_libraries(&self) -> Vec<String>
Import-directory DLL names in first-seen order, deduplicated case-insensitively but reported in their original case.
Source§fn is_known_read_only(&self, addr: u64) -> bool
fn is_known_read_only(&self, addr: u64) -> bool
A mapped section without IMAGE_SCN_MEM_WRITE is proven read-only.
(There is deliberately no is_known_writable override: flipping that
predicate would change which constants the folding passes trust, which is
a separate question from proving a region immutable.)
Source§fn load_address(&self) -> u64
fn load_address(&self) -> u64
The lowest virtual address mapped by this binary image.
Source§fn architecture(&self) -> Arch
fn architecture(&self) -> Arch
Name of the architecture, should use embedded information from known binary
format, or raw values from the blob.
Source§fn os(&self) -> TargetOs
fn os(&self) -> TargetOs
The operating system this binary targets, inferred from the container
format. Defaults to
TargetOs::Unknown; PE returns Windows, ELF Linux.Source§fn byte_at(&self, addr: u64) -> Option<u8>
fn byte_at(&self, addr: u64) -> Option<u8>
Return the byte mapped at
addr, or None if the address is unmapped.Source§fn bytes_at(&self, addr: u64) -> Option<&[u8]>
fn bytes_at(&self, addr: u64) -> Option<&[u8]>
Return the contiguous bytes available at
addr. Read moreSource§fn mapped_regions(&self) -> Vec<(u64, Vec<u8>, bool, bool)>
fn mapped_regions(&self) -> Vec<(u64, Vec<u8>, bool, bool)>
Enumerate the binary’s mapped regions as
(start, bytes, executable, writable). Read moreSource§fn segment_bounds(&self, addr: u64) -> Option<(u64, u64)>
fn segment_bounds(&self, addr: u64) -> Option<(u64, u64)>
The
[start, end) bounds of the mapped region containing addr, if
any. Used to key per-segment facts (e.g. executability propositions)
so repeated queries in one region collapse to a single entry. Defaults
to None for formats that do not expose their segments.Source§fn symbol_name(&self, addr: u64) -> Option<&str>
fn symbol_name(&self, addr: u64) -> Option<&str>
Return the symbol name for the function starting at
addr, if the
binary format has one (e.g. from an ELF symbol table).
Returns None for formats with no symbol information.Source§fn is_external_symbol(&self, addr: u64) -> bool
fn is_external_symbol(&self, addr: u64) -> bool
Returns
true if addr is an external (imported) function stub,
e.g. a PLT thunk. The recursive disassembler will not lift the body
of external functions. Defaults to false.Source§fn entry_points(&self) -> Vec<u64>
fn entry_points(&self) -> Vec<u64>
Known entry points into this binary (entrypoint, symbol table functions, etc.).
The recursive disassembler should be seeded with these addresses.
Source§fn entrypoint(&self) -> Option<u64>
fn entrypoint(&self) -> Option<u64>
The binary’s primary entry point (e.g. the ELF
e_entry), if the format
designates one. Unlike entry_points, this is the single address where
execution begins. Returns None for formats with no distinguished entry.Source§fn import_symbol_name(&self, addr: u64) -> Option<&str>
fn import_symbol_name(&self, addr: u64) -> Option<&str>
Return the imported symbol whose resolver slot lives at
addr, if any. Read moreSource§fn import_library(&self, addr: u64) -> Option<&str>
fn import_library(&self, addr: u64) -> Option<&str>
Return the name of the library providing the external function stub at
addr: the PE import-directory DLL, or the ELF .gnu.version_r soname
the symbol’s version requirement points at. None when the format does
not record a per-symbol source library (e.g. an unversioned ELF import).Source§fn hex_rows(
&self,
addr: u64,
len: usize,
width: usize,
) -> Vec<(u64, Vec<Option<u8>>)>
fn hex_rows( &self, addr: u64, len: usize, width: usize, ) -> Vec<(u64, Vec<Option<u8>>)>
Return rows of bytes suitable for a hex viewer. Read more
Source§fn is_executable(&self, addr: u64) -> bool
fn is_executable(&self, addr: u64) -> bool
Return
true if addr lies in an executable region of this binary
image. Defaults to “mapped” for formats that don’t track per-region
permissions; formats with permission information (e.g. ELF segment
flags) should override this.Source§fn is_known_writable(&self, _addr: u64) -> bool
fn is_known_writable(&self, _addr: u64) -> bool
Return
true only if addr lies in a region known to be writable
(from the container’s segment flags). Passes that fold a value out of
initialized memory use this to refuse mutable memory — e.g. a GOT slot
the dynamic linker overwrites at load time. Defaults to false
(“not proven writable”); Blob keeps the default.Auto Trait Implementations§
impl Freeze for PeBinary
impl RefUnwindSafe for PeBinary
impl Send for PeBinary
impl Sync for PeBinary
impl Unpin for PeBinary
impl UnsafeUnpin for PeBinary
impl UnwindSafe for PeBinary
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more