pe.h 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595
  1. /*
  2. PE32+ header file
  3. */
  4. #ifndef _PE_H
  5. #define _PE_H
  6. #define IMAGE_DOS_SIGNATURE 0x5A4D // MZ
  7. #define IMAGE_OS2_SIGNATURE 0x454E // NE
  8. #define IMAGE_OS2_SIGNATURE_LE 0x454C // LE
  9. #define IMAGE_NT_SIGNATURE 0x00004550 // PE00
  10. #define IMAGE_EDOS_SIGNATURE 0x44454550 // PEED
  11. typedef struct _IMAGE_DOS_HEADER { // DOS .EXE header
  12. UINT16 e_magic; // Magic number
  13. UINT16 e_cblp; // Bytes on last page of file
  14. UINT16 e_cp; // Pages in file
  15. UINT16 e_crlc; // Relocations
  16. UINT16 e_cparhdr; // Size of header in paragraphs
  17. UINT16 e_minalloc; // Minimum extra paragraphs needed
  18. UINT16 e_maxalloc; // Maximum extra paragraphs needed
  19. UINT16 e_ss; // Initial (relative) SS value
  20. UINT16 e_sp; // Initial SP value
  21. UINT16 e_csum; // Checksum
  22. UINT16 e_ip; // Initial IP value
  23. UINT16 e_cs; // Initial (relative) CS value
  24. UINT16 e_lfarlc; // File address of relocation table
  25. UINT16 e_ovno; // Overlay number
  26. UINT16 e_res[4]; // Reserved words
  27. UINT16 e_oemid; // OEM identifier (for e_oeminfo)
  28. UINT16 e_oeminfo; // OEM information; e_oemid specific
  29. UINT16 e_res2[10]; // Reserved words
  30. UINT32 e_lfanew; // File address of new exe header
  31. } IMAGE_DOS_HEADER, *PIMAGE_DOS_HEADER;
  32. typedef struct _IMAGE_OS2_HEADER { // OS/2 .EXE header
  33. UINT16 ne_magic; // Magic number
  34. UINT8 ne_ver; // Version number
  35. UINT8 ne_rev; // Revision number
  36. UINT16 ne_enttab; // Offset of Entry Table
  37. UINT16 ne_cbenttab; // Number of bytes in Entry Table
  38. UINT32 ne_crc; // Checksum of whole file
  39. UINT16 ne_flags; // Flag UINT16
  40. UINT16 ne_autodata; // Automatic data segment number
  41. UINT16 ne_heap; // Initial heap allocation
  42. UINT16 ne_stack; // Initial stack allocation
  43. UINT32 ne_csip; // Initial CS:IP setting
  44. UINT32 ne_sssp; // Initial SS:SP setting
  45. UINT16 ne_cseg; // Count of file segments
  46. UINT16 ne_cmod; // Entries in Module Reference Table
  47. UINT16 ne_cbnrestab; // Size of non-resident name table
  48. UINT16 ne_segtab; // Offset of Segment Table
  49. UINT16 ne_rsrctab; // Offset of Resource Table
  50. UINT16 ne_restab; // Offset of resident name table
  51. UINT16 ne_modtab; // Offset of Module Reference Table
  52. UINT16 ne_imptab; // Offset of Imported Names Table
  53. UINT32 ne_nrestab; // Offset of Non-resident Names Table
  54. UINT16 ne_cmovent; // Count of movable entries
  55. UINT16 ne_align; // Segment alignment shift count
  56. UINT16 ne_cres; // Count of resource segments
  57. UINT8 ne_exetyp; // Target Operating system
  58. UINT8 ne_flagsothers; // Other .EXE flags
  59. UINT16 ne_pretthunks; // offset to return thunks
  60. UINT16 ne_psegrefbytes; // offset to segment ref. bytes
  61. UINT16 ne_swaparea; // Minimum code swap area size
  62. UINT16 ne_expver; // Expected Windows version number
  63. } IMAGE_OS2_HEADER, *PIMAGE_OS2_HEADER;
  64. //
  65. // File header format.
  66. //
  67. typedef struct _IMAGE_FILE_HEADER {
  68. UINT16 Machine;
  69. UINT16 NumberOfSections;
  70. UINT32 TimeDateStamp;
  71. UINT32 PointerToSymbolTable;
  72. UINT32 NumberOfSymbols;
  73. UINT16 SizeOfOptionalHeader;
  74. UINT16 Characteristics;
  75. } IMAGE_FILE_HEADER, *PIMAGE_FILE_HEADER;
  76. #define IMAGE_SIZEOF_FILE_HEADER 20
  77. #define IMAGE_FILE_RELOCS_STRIPPED 0x0001 // Relocation info stripped from file.
  78. #define IMAGE_FILE_EXECUTABLE_IMAGE 0x0002 // File is executable (i.e. no unresolved externel references).
  79. #define IMAGE_FILE_LINE_NUMS_STRIPPED 0x0004 // Line nunbers stripped from file.
  80. #define IMAGE_FILE_LOCAL_SYMS_STRIPPED 0x0008 // Local symbols stripped from file.
  81. #define IMAGE_FILE_BYTES_REVERSED_LO 0x0080 // Bytes of machine word are reversed.
  82. #define IMAGE_FILE_32BIT_MACHINE 0x0100 // 32 bit word machine.
  83. #define IMAGE_FILE_DEBUG_STRIPPED 0x0200 // Debugging info stripped from file in .DBG file
  84. #define IMAGE_FILE_SYSTEM 0x1000 // System File.
  85. #define IMAGE_FILE_DLL 0x2000 // File is a DLL.
  86. #define IMAGE_FILE_BYTES_REVERSED_HI 0x8000 // Bytes of machine word are reversed.
  87. #define IMAGE_FILE_MACHINE_UNKNOWN 0
  88. #define IMAGE_FILE_MACHINE_I386 0x14c // Intel 386.
  89. #define IMAGE_FILE_MACHINE_R3000 0x162 // MIPS little-endian, 0540 big-endian
  90. #define IMAGE_FILE_MACHINE_R4000 0x166 // MIPS little-endian
  91. #define IMAGE_FILE_MACHINE_ALPHA 0x184 // Alpha_AXP
  92. #define IMAGE_FILE_MACHINE_ARMTHUMB_MIXED 0x1c2 // Arm/Thumb
  93. #define IMAGE_FILE_MACHINE_POWERPC 0x1F0 // IBM PowerPC Little-Endian
  94. #define IMAGE_FILE_MACHINE_IA64 0x200 // IA-64
  95. #define IMAGE_FILE_MACHINE_TAHOE 0x7cc // Intel EM machine
  96. #define IMAGE_FILE_MACHINE_EBC 0xebc // EFI Byte Code
  97. #define IMAGE_FILE_MACHINE_X64 0x8664 // x86_64
  98. //
  99. // Directory format.
  100. //
  101. typedef struct _IMAGE_DATA_DIRECTORY {
  102. UINT32 VirtualAddress;
  103. UINT32 Size;
  104. } IMAGE_DATA_DIRECTORY, *PIMAGE_DATA_DIRECTORY;
  105. #define IMAGE_NUMBEROF_DIRECTORY_ENTRIES 16
  106. //
  107. // Optional header format.
  108. //
  109. typedef struct _IMAGE_OPTIONAL_HEADER {
  110. //
  111. // Standard fields.
  112. //
  113. UINT16 Magic;
  114. UINT8 MajorLinkerVersion;
  115. UINT8 MinorLinkerVersion;
  116. UINT32 SizeOfCode;
  117. UINT32 SizeOfInitializedData;
  118. UINT32 SizeOfUninitializedData;
  119. UINT32 AddressOfEntryPoint;
  120. UINT32 BaseOfCode;
  121. UINT32 BaseOfData;
  122. //
  123. // NT additional fields.
  124. //
  125. UINT32 ImageBase;
  126. UINT32 SectionAlignment;
  127. UINT32 FileAlignment;
  128. UINT16 MajorOperatingSystemVersion;
  129. UINT16 MinorOperatingSystemVersion;
  130. UINT16 MajorImageVersion;
  131. UINT16 MinorImageVersion;
  132. UINT16 MajorSubsystemVersion;
  133. UINT16 MinorSubsystemVersion;
  134. UINT32 Reserved1;
  135. UINT32 SizeOfImage;
  136. UINT32 SizeOfHeaders;
  137. UINT32 CheckSum;
  138. UINT16 Subsystem;
  139. UINT16 DllCharacteristics;
  140. UINT32 SizeOfStackReserve;
  141. UINT32 SizeOfStackCommit;
  142. UINT32 SizeOfHeapReserve;
  143. UINT32 SizeOfHeapCommit;
  144. UINT32 LoaderFlags;
  145. UINT32 NumberOfRvaAndSizes;
  146. IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES];
  147. } IMAGE_OPTIONAL_HEADER, *PIMAGE_OPTIONAL_HEADER;
  148. typedef struct _IMAGE_ROM_OPTIONAL_HEADER {
  149. UINT16 Magic;
  150. UINT8 MajorLinkerVersion;
  151. UINT8 MinorLinkerVersion;
  152. UINT32 SizeOfCode;
  153. UINT32 SizeOfInitializedData;
  154. UINT32 SizeOfUninitializedData;
  155. UINT32 AddressOfEntryPoint;
  156. UINT32 BaseOfCode;
  157. UINT32 BaseOfData;
  158. UINT32 BaseOfBss;
  159. UINT32 GprMask;
  160. UINT32 CprMask[4];
  161. UINT32 GpValue;
  162. } IMAGE_ROM_OPTIONAL_HEADER, *PIMAGE_ROM_OPTIONAL_HEADER;
  163. #define IMAGE_SIZEOF_ROM_OPTIONAL_HEADER 56
  164. #define IMAGE_SIZEOF_STD_OPTIONAL_HEADER 28
  165. #define IMAGE_SIZEOF_NT_OPTIONAL_HEADER 224
  166. #define IMAGE_NT_OPTIONAL_HDR_MAGIC 0x10b
  167. #define IMAGE_ROM_OPTIONAL_HDR_MAGIC 0x107
  168. typedef struct _IMAGE_NT_HEADERS {
  169. UINT32 Signature;
  170. IMAGE_FILE_HEADER FileHeader;
  171. IMAGE_OPTIONAL_HEADER OptionalHeader;
  172. } IMAGE_NT_HEADERS, *PIMAGE_NT_HEADERS;
  173. typedef struct _IMAGE_ROM_HEADERS {
  174. IMAGE_FILE_HEADER FileHeader;
  175. IMAGE_ROM_OPTIONAL_HEADER OptionalHeader;
  176. } IMAGE_ROM_HEADERS, *PIMAGE_ROM_HEADERS;
  177. #define IMAGE_FIRST_SECTION( ntheader ) ((PIMAGE_SECTION_HEADER) \
  178. ((UINT32)ntheader + \
  179. FIELD_OFFSET( IMAGE_NT_HEADERS, OptionalHeader ) + \
  180. ((PIMAGE_NT_HEADERS)(ntheader))->FileHeader.SizeOfOptionalHeader \
  181. ))
  182. // Subsystem Values
  183. #define IMAGE_SUBSYSTEM_UNKNOWN 0 // Unknown subsystem.
  184. #define IMAGE_SUBSYSTEM_NATIVE 1 // Image doesn't require a subsystem.
  185. #define IMAGE_SUBSYSTEM_WINDOWS_GUI 2 // Image runs in the Windows GUI subsystem.
  186. #define IMAGE_SUBSYSTEM_WINDOWS_CUI 3 // Image runs in the Windows character subsystem.
  187. #define IMAGE_SUBSYSTEM_OS2_CUI 5 // image runs in the OS/2 character subsystem.
  188. #define IMAGE_SUBSYSTEM_POSIX_CUI 7 // image run in the Posix character subsystem.
  189. // Directory Entries
  190. #define IMAGE_DIRECTORY_ENTRY_EXPORT 0 // Export Directory
  191. #define IMAGE_DIRECTORY_ENTRY_IMPORT 1 // Import Directory
  192. #define IMAGE_DIRECTORY_ENTRY_RESOURCE 2 // Resource Directory
  193. #define IMAGE_DIRECTORY_ENTRY_EXCEPTION 3 // Exception Directory
  194. #define IMAGE_DIRECTORY_ENTRY_SECURITY 4 // Security Directory
  195. #define IMAGE_DIRECTORY_ENTRY_BASERELOC 5 // Base Relocation Table
  196. #define IMAGE_DIRECTORY_ENTRY_DEBUG 6 // Debug Directory
  197. #define IMAGE_DIRECTORY_ENTRY_COPYRIGHT 7 // Description String
  198. #define IMAGE_DIRECTORY_ENTRY_GLOBALPTR 8 // Machine Value (MIPS GP)
  199. #define IMAGE_DIRECTORY_ENTRY_TLS 9 // TLS Directory
  200. #define IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG 10 // Load Configuration Directory
  201. //
  202. // Section header format.
  203. //
  204. #define IMAGE_SIZEOF_SHORT_NAME 8
  205. typedef struct _IMAGE_SECTION_HEADER {
  206. UINT8 Name[IMAGE_SIZEOF_SHORT_NAME];
  207. union {
  208. UINT32 PhysicalAddress;
  209. UINT32 VirtualSize;
  210. } Misc;
  211. UINT32 VirtualAddress;
  212. UINT32 SizeOfRawData;
  213. UINT32 PointerToRawData;
  214. UINT32 PointerToRelocations;
  215. UINT32 PointerToLinenumbers;
  216. UINT16 NumberOfRelocations;
  217. UINT16 NumberOfLinenumbers;
  218. UINT32 Characteristics;
  219. } IMAGE_SECTION_HEADER, *PIMAGE_SECTION_HEADER;
  220. #define IMAGE_SIZEOF_SECTION_HEADER 40
  221. #define IMAGE_SCN_TYPE_NO_PAD 0x00000008 // Reserved.
  222. #define IMAGE_SCN_CNT_CODE 0x00000020 // Section contains code.
  223. #define IMAGE_SCN_CNT_INITIALIZED_DATA 0x00000040 // Section contains initialized data.
  224. #define IMAGE_SCN_CNT_UNINITIALIZED_DATA 0x00000080 // Section contains uninitialized data.
  225. #define IMAGE_SCN_LNK_OTHER 0x00000100 // Reserved.
  226. #define IMAGE_SCN_LNK_INFO 0x00000200 // Section contains comments or some other type of information.
  227. #define IMAGE_SCN_LNK_REMOVE 0x00000800 // Section contents will not become part of image.
  228. #define IMAGE_SCN_LNK_COMDAT 0x00001000 // Section contents comdat.
  229. #define IMAGE_SCN_ALIGN_1BYTES 0x00100000 //
  230. #define IMAGE_SCN_ALIGN_2BYTES 0x00200000 //
  231. #define IMAGE_SCN_ALIGN_4BYTES 0x00300000 //
  232. #define IMAGE_SCN_ALIGN_8BYTES 0x00400000 //
  233. #define IMAGE_SCN_ALIGN_16BYTES 0x00500000 // Default alignment if no others are specified.
  234. #define IMAGE_SCN_ALIGN_32BYTES 0x00600000 //
  235. #define IMAGE_SCN_ALIGN_64BYTES 0x00700000 //
  236. #define IMAGE_SCN_MEM_DISCARDABLE 0x02000000 // Section can be discarded.
  237. #define IMAGE_SCN_MEM_NOT_CACHED 0x04000000 // Section is not cachable.
  238. #define IMAGE_SCN_MEM_NOT_PAGED 0x08000000 // Section is not pageable.
  239. #define IMAGE_SCN_MEM_SHARED 0x10000000 // Section is shareable.
  240. #define IMAGE_SCN_MEM_EXECUTE 0x20000000 // Section is executable.
  241. #define IMAGE_SCN_MEM_READ 0x40000000 // Section is readable.
  242. #define IMAGE_SCN_MEM_WRITE 0x80000000 // Section is writeable.
  243. //
  244. // Symbol format.
  245. //
  246. #define IMAGE_SIZEOF_SYMBOL 18
  247. //
  248. // Section values.
  249. //
  250. // Symbols have a section number of the section in which they are
  251. // defined. Otherwise, section numbers have the following meanings:
  252. //
  253. #define IMAGE_SYM_UNDEFINED (UINT16)0 // Symbol is undefined or is common.
  254. #define IMAGE_SYM_ABSOLUTE (UINT16)-1 // Symbol is an absolute value.
  255. #define IMAGE_SYM_DEBUG (UINT16)-2 // Symbol is a special debug item.
  256. //
  257. // Type (fundamental) values.
  258. //
  259. #define IMAGE_SYM_TYPE_NULL 0 // no type.
  260. #define IMAGE_SYM_TYPE_VOID 1 //
  261. #define IMAGE_SYM_TYPE_CHAR 2 // type character.
  262. #define IMAGE_SYM_TYPE_SHORT 3 // type short integer.
  263. #define IMAGE_SYM_TYPE_INT 4 //
  264. #define IMAGE_SYM_TYPE_LONG 5 //
  265. #define IMAGE_SYM_TYPE_FLOAT 6 //
  266. #define IMAGE_SYM_TYPE_DOUBLE 7 //
  267. #define IMAGE_SYM_TYPE_STRUCT 8 //
  268. #define IMAGE_SYM_TYPE_UNION 9 //
  269. #define IMAGE_SYM_TYPE_ENUM 10 // enumeration.
  270. #define IMAGE_SYM_TYPE_MOE 11 // member of enumeration.
  271. #define IMAGE_SYM_TYPE_BYTE 12 //
  272. #define IMAGE_SYM_TYPE_WORD 13 //
  273. #define IMAGE_SYM_TYPE_UINT 14 //
  274. #define IMAGE_SYM_TYPE_DWORD 15 //
  275. //
  276. // Type (derived) values.
  277. //
  278. #define IMAGE_SYM_DTYPE_NULL 0 // no derived type.
  279. #define IMAGE_SYM_DTYPE_POINTER 1 // pointer.
  280. #define IMAGE_SYM_DTYPE_FUNCTION 2 // function.
  281. #define IMAGE_SYM_DTYPE_ARRAY 3 // array.
  282. //
  283. // Storage classes.
  284. //
  285. #define IMAGE_SYM_CLASS_END_OF_FUNCTION (BYTE )-1
  286. #define IMAGE_SYM_CLASS_NULL 0
  287. #define IMAGE_SYM_CLASS_AUTOMATIC 1
  288. #define IMAGE_SYM_CLASS_EXTERNAL 2
  289. #define IMAGE_SYM_CLASS_STATIC 3
  290. #define IMAGE_SYM_CLASS_REGISTER 4
  291. #define IMAGE_SYM_CLASS_EXTERNAL_DEF 5
  292. #define IMAGE_SYM_CLASS_LABEL 6
  293. #define IMAGE_SYM_CLASS_UNDEFINED_LABEL 7
  294. #define IMAGE_SYM_CLASS_MEMBER_OF_STRUCT 8
  295. #define IMAGE_SYM_CLASS_ARGUMENT 9
  296. #define IMAGE_SYM_CLASS_STRUCT_TAG 10
  297. #define IMAGE_SYM_CLASS_MEMBER_OF_UNION 11
  298. #define IMAGE_SYM_CLASS_UNION_TAG 12
  299. #define IMAGE_SYM_CLASS_TYPE_DEFINITION 13
  300. #define IMAGE_SYM_CLASS_UNDEFINED_STATIC 14
  301. #define IMAGE_SYM_CLASS_ENUM_TAG 15
  302. #define IMAGE_SYM_CLASS_MEMBER_OF_ENUM 16
  303. #define IMAGE_SYM_CLASS_REGISTER_PARAM 17
  304. #define IMAGE_SYM_CLASS_BIT_FIELD 18
  305. #define IMAGE_SYM_CLASS_BLOCK 100
  306. #define IMAGE_SYM_CLASS_FUNCTION 101
  307. #define IMAGE_SYM_CLASS_END_OF_STRUCT 102
  308. #define IMAGE_SYM_CLASS_FILE 103
  309. // new
  310. #define IMAGE_SYM_CLASS_SECTION 104
  311. #define IMAGE_SYM_CLASS_WEAK_EXTERNAL 105
  312. // type packing constants
  313. #define N_BTMASK 017
  314. #define N_TMASK 060
  315. #define N_TMASK1 0300
  316. #define N_TMASK2 0360
  317. #define N_BTSHFT 4
  318. #define N_TSHIFT 2
  319. // MACROS
  320. //
  321. // Communal selection types.
  322. //
  323. #define IMAGE_COMDAT_SELECT_NODUPLICATES 1
  324. #define IMAGE_COMDAT_SELECT_ANY 2
  325. #define IMAGE_COMDAT_SELECT_SAME_SIZE 3
  326. #define IMAGE_COMDAT_SELECT_EXACT_MATCH 4
  327. #define IMAGE_COMDAT_SELECT_ASSOCIATIVE 5
  328. #define IMAGE_WEAK_EXTERN_SEARCH_NOLIBRARY 1
  329. #define IMAGE_WEAK_EXTERN_SEARCH_LIBRARY 2
  330. #define IMAGE_WEAK_EXTERN_SEARCH_ALIAS 3
  331. //
  332. // Relocation format.
  333. //
  334. typedef struct _IMAGE_RELOCATION {
  335. UINT32 VirtualAddress;
  336. UINT32 SymbolTableIndex;
  337. UINT16 Type;
  338. } IMAGE_RELOCATION;
  339. #define IMAGE_SIZEOF_RELOCATION 10
  340. //
  341. // I386 relocation types.
  342. //
  343. #define IMAGE_REL_I386_ABSOLUTE 0 // Reference is absolute, no relocation is necessary
  344. #define IMAGE_REL_I386_DIR16 01 // Direct 16-bit reference to the symbols virtual address
  345. #define IMAGE_REL_I386_REL16 02 // PC-relative 16-bit reference to the symbols virtual address
  346. #define IMAGE_REL_I386_DIR32 06 // Direct 32-bit reference to the symbols virtual address
  347. #define IMAGE_REL_I386_DIR32NB 07 // Direct 32-bit reference to the symbols virtual address, base not included
  348. #define IMAGE_REL_I386_SEG12 011 // Direct 16-bit reference to the segment-selector bits of a 32-bit virtual address
  349. #define IMAGE_REL_I386_SECTION 012
  350. #define IMAGE_REL_I386_SECREL 013
  351. #define IMAGE_REL_I386_REL32 024 // PC-relative 32-bit reference to the symbols virtual address
  352. //
  353. // MIPS relocation types.
  354. //
  355. #define IMAGE_REL_MIPS_ABSOLUTE 0 // Reference is absolute, no relocation is necessary
  356. #define IMAGE_REL_MIPS_REFHALF 01
  357. #define IMAGE_REL_MIPS_REFWORD 02
  358. #define IMAGE_REL_MIPS_JMPADDR 03
  359. #define IMAGE_REL_MIPS_REFHI 04
  360. #define IMAGE_REL_MIPS_REFLO 05
  361. #define IMAGE_REL_MIPS_GPREL 06
  362. #define IMAGE_REL_MIPS_LITERAL 07
  363. #define IMAGE_REL_MIPS_SECTION 012
  364. #define IMAGE_REL_MIPS_SECREL 013
  365. #define IMAGE_REL_MIPS_REFWORDNB 042
  366. #define IMAGE_REL_MIPS_PAIR 045
  367. //
  368. // Alpha Relocation types.
  369. //
  370. #define IMAGE_REL_ALPHA_ABSOLUTE 0x0
  371. #define IMAGE_REL_ALPHA_REFLONG 0x1
  372. #define IMAGE_REL_ALPHA_REFQUAD 0x2
  373. #define IMAGE_REL_ALPHA_GPREL32 0x3
  374. #define IMAGE_REL_ALPHA_LITERAL 0x4
  375. #define IMAGE_REL_ALPHA_LITUSE 0x5
  376. #define IMAGE_REL_ALPHA_GPDISP 0x6
  377. #define IMAGE_REL_ALPHA_BRADDR 0x7
  378. #define IMAGE_REL_ALPHA_HINT 0x8
  379. #define IMAGE_REL_ALPHA_INLINE_REFLONG 0x9
  380. #define IMAGE_REL_ALPHA_REFHI 0xA
  381. #define IMAGE_REL_ALPHA_REFLO 0xB
  382. #define IMAGE_REL_ALPHA_PAIR 0xC
  383. #define IMAGE_REL_ALPHA_MATCH 0xD
  384. #define IMAGE_REL_ALPHA_SECTION 0xE
  385. #define IMAGE_REL_ALPHA_SECREL 0xF
  386. #define IMAGE_REL_ALPHA_REFLONGNB 0x10
  387. //
  388. // IBM PowerPC relocation types.
  389. //
  390. #define IMAGE_REL_PPC_ABSOLUTE 0x0000 // NOP
  391. #define IMAGE_REL_PPC_ADDR64 0x0001 // 64-bit address
  392. #define IMAGE_REL_PPC_ADDR32 0x0002 // 32-bit address
  393. #define IMAGE_REL_PPC_ADDR24 0x0003 // 26-bit address, shifted left 2 (branch absolute)
  394. #define IMAGE_REL_PPC_ADDR16 0x0004 // 16-bit address
  395. #define IMAGE_REL_PPC_ADDR14 0x0005 // 16-bit address, shifted left 2 (load doubleword)
  396. #define IMAGE_REL_PPC_REL24 0x0006 // 26-bit PC-relative offset, shifted left 2 (branch relative)
  397. #define IMAGE_REL_PPC_REL14 0x0007 // 16-bit PC-relative offset, shifted left 2 (br cond relative)
  398. #define IMAGE_REL_PPC_TOCREL16 0x0008 // 16-bit offset from TOC base
  399. #define IMAGE_REL_PPC_TOCREL14 0x0009 // 16-bit offset from TOC base, shifted left 2 (load doubleword)
  400. #define IMAGE_REL_PPC_ADDR32NB 0x000A // 32-bit addr w/o image base
  401. #define IMAGE_REL_PPC_SECREL 0x000B // va of containing section (as in an image sectionhdr)
  402. #define IMAGE_REL_PPC_SECTION 0x000C // sectionheader number
  403. #define IMAGE_REL_PPC_IFGLUE 0x000D // substitute TOC restore instruction iff symbol is glue code
  404. #define IMAGE_REL_PPC_IMGLUE 0x000E // symbol is glue code; virtual address is TOC restore instruction
  405. #define IMAGE_REL_PPC_TYPEMASK 0x00FF // mask to isolate above values in IMAGE_RELOCATION.Type
  406. // Flag bits in IMAGE_RELOCATION.TYPE
  407. #define IMAGE_REL_PPC_NEG 0x0100 // subtract reloc value rather than adding it
  408. #define IMAGE_REL_PPC_BRTAKEN 0x0200 // fix branch prediction bit to predict branch taken
  409. #define IMAGE_REL_PPC_BRNTAKEN 0x0400 // fix branch prediction bit to predict branch not taken
  410. #define IMAGE_REL_PPC_TOCDEFN 0x0800 // toc slot defined in file (or, data in toc)
  411. //
  412. // Based relocation format.
  413. //
  414. typedef struct _IMAGE_BASE_RELOCATION {
  415. UINT32 VirtualAddress;
  416. UINT32 SizeOfBlock;
  417. // UINT16 TypeOffset[1];
  418. } IMAGE_BASE_RELOCATION, *PIMAGE_BASE_RELOCATION;
  419. #define IMAGE_SIZEOF_BASE_RELOCATION 8
  420. //
  421. // Based relocation types.
  422. //
  423. #define IMAGE_REL_BASED_ABSOLUTE 0
  424. #define IMAGE_REL_BASED_HIGH 1
  425. #define IMAGE_REL_BASED_LOW 2
  426. #define IMAGE_REL_BASED_HIGHLOW 3
  427. #define IMAGE_REL_BASED_HIGHADJ 4
  428. #define IMAGE_REL_BASED_MIPS_JMPADDR 5
  429. #define IMAGE_REL_BASED_IA64_IMM64 9
  430. #define IMAGE_REL_BASED_DIR64 10
  431. //
  432. // Line number format.
  433. //
  434. typedef struct _IMAGE_LINENUMBER {
  435. union {
  436. UINT32 SymbolTableIndex; // Symbol table index of function name if Linenumber is 0.
  437. UINT32 VirtualAddress; // Virtual address of line number.
  438. } Type;
  439. UINT16 Linenumber; // Line number.
  440. } IMAGE_LINENUMBER;
  441. #define IMAGE_SIZEOF_LINENUMBER 6
  442. //
  443. // Archive format.
  444. //
  445. #define IMAGE_ARCHIVE_START_SIZE 8
  446. #define IMAGE_ARCHIVE_START "!<arch>\n"
  447. #define IMAGE_ARCHIVE_END "`\n"
  448. #define IMAGE_ARCHIVE_PAD "\n"
  449. #define IMAGE_ARCHIVE_LINKER_MEMBER "/ "
  450. #define IMAGE_ARCHIVE_LONGNAMES_MEMBER "// "
  451. typedef struct _IMAGE_ARCHIVE_MEMBER_HEADER {
  452. UINT8 Name[16]; // File member name - `/' terminated.
  453. UINT8 Date[12]; // File member date - decimal.
  454. UINT8 UserID[6]; // File member user id - decimal.
  455. UINT8 GroupID[6]; // File member group id - decimal.
  456. UINT8 Mode[8]; // File member mode - octal.
  457. UINT8 Size[10]; // File member size - decimal.
  458. UINT8 EndHeader[2]; // String to end header.
  459. } IMAGE_ARCHIVE_MEMBER_HEADER, *PIMAGE_ARCHIVE_MEMBER_HEADER;
  460. #define IMAGE_SIZEOF_ARCHIVE_MEMBER_HDR 60
  461. //
  462. // DLL support.
  463. //
  464. //
  465. // Export Format
  466. //
  467. typedef struct _IMAGE_EXPORT_DIRECTORY {
  468. UINT32 Characteristics;
  469. UINT32 TimeDateStamp;
  470. UINT16 MajorVersion;
  471. UINT16 MinorVersion;
  472. UINT32 Name;
  473. UINT32 Base;
  474. UINT32 NumberOfFunctions;
  475. UINT32 NumberOfNames;
  476. UINT32 *AddressOfFunctions;
  477. UINT32 *AddressOfNames;
  478. UINT32 *AddressOfNameOrdinals;
  479. } IMAGE_EXPORT_DIRECTORY, *PIMAGE_EXPORT_DIRECTORY;
  480. //
  481. // Import Format
  482. //
  483. typedef struct _IMAGE_IMPORT_BY_NAME {
  484. UINT16 Hint;
  485. UINT8 Name[1];
  486. } IMAGE_IMPORT_BY_NAME, *PIMAGE_IMPORT_BY_NAME;
  487. typedef struct _IMAGE_THUNK_DATA {
  488. union {
  489. UINT32 Function;
  490. UINT32 Ordinal;
  491. PIMAGE_IMPORT_BY_NAME AddressOfData;
  492. } u1;
  493. } IMAGE_THUNK_DATA, *PIMAGE_THUNK_DATA;
  494. #define IMAGE_ORDINAL_FLAG 0x80000000
  495. #define IMAGE_SNAP_BY_ORDINAL(Ordinal) ((Ordinal & IMAGE_ORDINAL_FLAG) != 0)
  496. #define IMAGE_ORDINAL(Ordinal) (Ordinal & 0xffff)
  497. typedef struct _IMAGE_IMPORT_DESCRIPTOR {
  498. UINT32 Characteristics;
  499. UINT32 TimeDateStamp;
  500. UINT32 ForwarderChain;
  501. UINT32 Name;
  502. PIMAGE_THUNK_DATA FirstThunk;
  503. } IMAGE_IMPORT_DESCRIPTOR, *PIMAGE_IMPORT_DESCRIPTOR;
  504. #endif