Skip to main content

MemoryImage

Struct MemoryImage 

Source
pub struct MemoryImage { /* private fields */ }
Expand description

The initialized memory of a loaded binary, as a set of mapped segments kept sorted by start address.

Implementations§

Source§

impl MemoryImage

Source

pub fn add_segment( &mut self, start: u64, bytes: Vec<u8>, executable: bool, writable: bool, )

Add a mapped region. Segments are kept sorted by start address; callers need not insert in order.

Source

pub fn read_bytes(&self, addr: u64, n: usize) -> Option<Vec<u8>>

Read n bytes starting at addr, all from a single mapped segment. Returns None if any byte in [addr, addr + n) is unmapped.

Source

pub fn read_uint(&self, addr: u64, size: usize) -> Option<u64>

Read a little-endian unsigned integer of size bytes (1..=8) at addr.

Endianness is fixed to little-endian for now (x86/x64); a big-endian / arch-driven variant is a TODO.

Source

pub fn is_executable(&self, addr: u64) -> bool

True if addr lies in an executable mapped region (per the raw segment flag, regardless of whether protections have been established).

Source

pub fn is_known_writable(&self, addr: u64) -> bool

True only if addr is mapped in a region known to be writable: the per-segment protection flags must be established (see protections_known) and the containing segment writable. Before protections are known the segment flags are not authoritative, so this conservatively returns false (“not proven writable”). Callers use it to refuse to treat mutable memory (e.g. a GOT slot the dynamic linker rewrites) as a constant.

Source

pub fn contains(&self, addr: u64) -> bool

True if addr is mapped by any segment.

Source

pub fn segment_bounds(&self, addr: u64) -> Option<(u64, u64)>

The [start, end) bounds of the segment containing addr, if any.

Source

pub fn protections_known(&self) -> bool

Whether the per-segment executable flags are authoritative (the memory_protections pass has run).

Source

pub fn mark_protections_known(&mut self)

Mark the per-segment protection flags as authoritative, so the lifter narrows from the permissive default to the real flags.

Source

pub fn is_empty(&self) -> bool

True if no segments have been loaded yet. Used to make binary memory loading idempotent across fixpoint rounds.

Trait Implementations§

Source§

impl BinaryFormat for MemoryImage

The persistence/test backing of the byte surface: a reloaded .harbinger snapshot (or a qcode!-DSL test that seeded segments) wraps its MemoryImage in an Arc and hands it to PipelineEnv.binary, so passes read initialized memory through one trait regardless of whether a live container format is behind it.

Source§

fn entry_points(&self) -> Vec<u64>

An image records mapped bytes, not entry metadata.

Source§

fn architecture(&self) -> Arch

Images do not record an architecture; x86-64 is the workspace default (mirrors Blob’s placeholder). Consumers of PipelineEnv.binary read bytes and permissions, never the architecture.

Source§

fn is_known_writable(&self, addr: u64) -> bool

Answers straight from the per-segment flag: an image is only ever built from an authoritative container format’s mapped_regions (or a test’s explicit add_segment), so the flags need no separate establishment step. (The inherent MemoryImage::is_known_writable keeps the legacy protections_known gate for its remaining callers.)

Source§

fn is_known_read_only(&self, addr: u64) -> bool

The mirror of is_known_writable: a mapped segment whose recorded flag says “not writable” is proven read-only. The flags come from the container format’s mapped_regions, so this is only as authoritative as the format that filled them.

Source§

fn load_address(&self) -> u64

The lowest virtual address mapped by this binary image.
Source§

fn byte_at(&self, addr: u64) -> Option<u8>

Return the byte mapped at addr, or None if the address is unmapped.
Source§

fn bytes_at(&self, addr: u64) -> Option<&[u8]>

Return the contiguous bytes available at addr. Read more
Source§

fn segment_bounds(&self, addr: u64) -> Option<(u64, u64)>

The [start, end) bounds of the mapped region containing addr, if any. Used to key per-segment facts (e.g. executability propositions) so repeated queries in one region collapse to a single entry. Defaults to None for formats that do not expose their segments.
Source§

fn is_executable(&self, addr: u64) -> bool

Return true if addr lies in an executable region of this binary image. Defaults to “mapped” for formats that don’t track per-region permissions; formats with permission information (e.g. ELF segment flags) should override this.
Source§

fn mapped_regions(&self) -> Vec<(u64, Vec<u8>, bool, bool)>

Enumerate the binary’s mapped regions as (start, bytes, executable, writable). Read more
Source§

fn read_bytes(&self, addr: u64, n: usize) -> Option<Vec<u8>>

Read n bytes at virtual address addr. Read more
Source§

fn read_uint(&self, addr: u64, size: usize) -> Option<u64>

Read a little-endian unsigned integer of size bytes (1..=8) at addr. Read more
Source§

fn entrypoint(&self) -> Option<u64>

The binary’s primary entry point (e.g. the ELF e_entry), if the format designates one. Unlike entry_points, this is the single address where execution begins. Returns None for formats with no distinguished entry.
Source§

fn os(&self) -> TargetOs

The operating system this binary targets, inferred from the container format. Defaults to TargetOs::Unknown; PE returns Windows, ELF Linux.
Source§

fn linked_libraries(&self) -> Vec<String>

Library names this binary links against: ELF DT_NEEDED sonames, PE import-directory DLL names (original case; matching is case-insensitive). Empty when the format has no such notion (Blob).
Source§

fn symbol_name(&self, _addr: u64) -> Option<&str>

Return the symbol name for the function starting at addr, if the binary format has one (e.g. from an ELF symbol table). Returns None for formats with no symbol information.
Source§

fn is_external_symbol(&self, _addr: u64) -> bool

Returns true if addr is an external (imported) function stub, e.g. a PLT thunk. The recursive disassembler will not lift the body of external functions. Defaults to false.
Source§

fn import_library(&self, _addr: u64) -> Option<&str>

Return the name of the library providing the external function stub at addr: the PE import-directory DLL, or the ELF .gnu.version_r soname the symbol’s version requirement points at. None when the format does not record a per-symbol source library (e.g. an unversioned ELF import).
Source§

fn import_symbol_name(&self, _addr: u64) -> Option<&str>

Return the imported symbol whose resolver slot lives at addr, if any. Read more
Source§

fn hex_rows( &self, addr: u64, len: usize, width: usize, ) -> Vec<(u64, Vec<Option<u8>>)>

Return rows of bytes suitable for a hex viewer. Read more
Source§

fn contains(&self, addr: u64) -> bool

Return true if addr is mapped by this binary image.
Source§

fn read_cstring(&self, addr: u64, max_len: Option<usize>) -> Option<Vec<u8>>

Read a null-terminated C string at virtual address addr, returning the bytes up to (but not including) the null terminator. Read more
Source§

fn read_printable_cstring( &self, addr: u64, max_len: Option<usize>, ) -> Option<Vec<u8>>

Read a null-terminated C string at virtual address addr, requiring every byte before the null terminator to be printable ASCII. Read more
Source§

impl Clone for MemoryImage

Source§

fn clone(&self) -> MemoryImage

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for MemoryImage

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for MemoryImage

Source§

fn default() -> MemoryImage

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for MemoryImage

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for MemoryImage

Source§

impl PartialEq for MemoryImage

Source§

fn eq(&self, other: &MemoryImage) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for MemoryImage

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for MemoryImage

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.