winedump: Print the machine field from the PDB symbol table.
[wine] / tools / winedump / pe.c
1 /*
2  *      PE dumping utility
3  *
4  *      Copyright 2001 Eric Pouech
5  *
6  * This library is free software; you can redistribute it and/or
7  * modify it under the terms of the GNU Lesser General Public
8  * License as published by the Free Software Foundation; either
9  * version 2.1 of the License, or (at your option) any later version.
10  *
11  * This library is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14  * Lesser General Public License for more details.
15  *
16  * You should have received a copy of the GNU Lesser General Public
17  * License along with this library; if not, write to the Free Software
18  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
19  */
20
21 #include "config.h"
22 #include "wine/port.h"
23
24 #include <stdlib.h>
25 #include <stdarg.h>
26 #include <stdio.h>
27 #ifdef HAVE_UNISTD_H
28 # include <unistd.h>
29 #endif
30 #include <time.h>
31 #ifdef HAVE_SYS_TYPES_H
32 # include <sys/types.h>
33 #endif
34 #ifdef HAVE_SYS_STAT_H
35 # include <sys/stat.h>
36 #endif
37 #ifdef HAVE_SYS_MMAN_H
38 #include <sys/mman.h>
39 #endif
40 #include <fcntl.h>
41
42 #define NONAMELESSUNION
43 #define NONAMELESSSTRUCT
44 #include "windef.h"
45 #include "winbase.h"
46 #include "winedump.h"
47
48 static const IMAGE_NT_HEADERS32*        PE_nt_headers;
49
50 const char *get_machine_str(int mach)
51 {
52     switch (mach)
53     {
54     case IMAGE_FILE_MACHINE_UNKNOWN:    return "Unknown";
55     case IMAGE_FILE_MACHINE_I860:       return "i860";
56     case IMAGE_FILE_MACHINE_I386:       return "i386";
57     case IMAGE_FILE_MACHINE_R3000:      return "R3000";
58     case IMAGE_FILE_MACHINE_R4000:      return "R4000";
59     case IMAGE_FILE_MACHINE_R10000:     return "R10000";
60     case IMAGE_FILE_MACHINE_ALPHA:      return "Alpha";
61     case IMAGE_FILE_MACHINE_POWERPC:    return "PowerPC";
62     case IMAGE_FILE_MACHINE_AMD64:      return "AMD64";
63     case IMAGE_FILE_MACHINE_IA64:       return "IA64";
64     case IMAGE_FILE_MACHINE_ARM:        return "ARM";
65     case IMAGE_FILE_MACHINE_THUMB:      return "ARM Thumb";
66     case IMAGE_FILE_MACHINE_SPARC:      return "SPARC";
67     }
68     return "???";
69 }
70
71 static const void*      RVA(unsigned long rva, unsigned long len)
72 {
73     IMAGE_SECTION_HEADER*       sectHead;
74     int                         i;
75
76     if (rva == 0) return NULL;
77
78     sectHead = IMAGE_FIRST_SECTION(PE_nt_headers);
79     for (i = PE_nt_headers->FileHeader.NumberOfSections - 1; i >= 0; i--)
80     {
81         if (sectHead[i].VirtualAddress <= rva &&
82             rva + len <= (DWORD)sectHead[i].VirtualAddress + sectHead[i].SizeOfRawData)
83         {
84             /* return image import directory offset */
85             return PRD(sectHead[i].PointerToRawData + rva - sectHead[i].VirtualAddress, len);
86         }
87     }
88
89     return NULL;
90 }
91
92 static const IMAGE_NT_HEADERS32 *get_nt_header( void )
93 {
94     const IMAGE_DOS_HEADER *dos;
95     dos = PRD(0, sizeof(*dos));
96     if (!dos) return NULL;
97     return PRD(dos->e_lfanew, sizeof(DWORD) + sizeof(IMAGE_FILE_HEADER));
98 }
99
100 static int is_fake_dll( void )
101 {
102     static const char fakedll_signature[] = "Wine placeholder DLL";
103     const IMAGE_DOS_HEADER *dos;
104
105     dos = PRD(0, sizeof(*dos) + sizeof(fakedll_signature));
106
107     if (dos && dos->e_lfanew >= sizeof(*dos) + sizeof(fakedll_signature) &&
108         !memcmp( dos + 1, fakedll_signature, sizeof(fakedll_signature) )) return TRUE;
109     return FALSE;
110 }
111
112 static const void *get_dir_and_size(unsigned int idx, unsigned int *size)
113 {
114     if(PE_nt_headers->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
115     {
116         const IMAGE_OPTIONAL_HEADER64 *opt = (const IMAGE_OPTIONAL_HEADER64*)&PE_nt_headers->OptionalHeader;
117         if (idx >= opt->NumberOfRvaAndSizes)
118             return NULL;
119         if(size)
120             *size = opt->DataDirectory[idx].Size;
121         return RVA(opt->DataDirectory[idx].VirtualAddress,
122                    opt->DataDirectory[idx].Size);
123     }
124     else
125     {
126         const IMAGE_OPTIONAL_HEADER32 *opt = (const IMAGE_OPTIONAL_HEADER32*)&PE_nt_headers->OptionalHeader;
127         if (idx >= opt->NumberOfRvaAndSizes)
128             return NULL;
129         if(size)
130             *size = opt->DataDirectory[idx].Size;
131         return RVA(opt->DataDirectory[idx].VirtualAddress,
132                    opt->DataDirectory[idx].Size);
133     }
134 }
135
136 static  const void*     get_dir(unsigned idx)
137 {
138     return get_dir_and_size(idx, 0);
139 }
140
141 static const char * const DirectoryNames[16] = {
142     "EXPORT",           "IMPORT",       "RESOURCE",     "EXCEPTION",
143     "SECURITY",         "BASERELOC",    "DEBUG",        "ARCHITECTURE",
144     "GLOBALPTR",        "TLS",          "LOAD_CONFIG",  "Bound IAT",
145     "IAT",              "Delay IAT",    "CLR Header", ""
146 };
147
148 static const char *get_magic_type(WORD magic)
149 {
150     switch(magic) {
151         case IMAGE_NT_OPTIONAL_HDR32_MAGIC:
152             return "32bit";
153         case IMAGE_NT_OPTIONAL_HDR64_MAGIC:
154             return "64bit";
155         case IMAGE_ROM_OPTIONAL_HDR_MAGIC:
156             return "ROM";
157     }
158     return "???";
159 }
160
161 static inline void print_word(const char *title, WORD value)
162 {
163     printf("  %-34s 0x%-4X         %u\n", title, value, value);
164 }
165
166 static inline void print_dword(const char *title, DWORD value)
167 {
168     printf("  %-34s 0x%-8x     %u\n", title, value, value);
169 }
170
171 static inline void print_longlong(const char *title, ULONGLONG value)
172 {
173     printf("  %-34s 0x", title);
174     if(value >> 32)
175         printf("%lx%08lx\n", (unsigned long)(value >> 32), (unsigned long)value);
176     else
177         printf("%lx\n", (unsigned long)value);
178 }
179
180 static inline void print_ver(const char *title, BYTE major, BYTE minor)
181 {
182     printf("  %-34s %u.%02u\n", title, major, minor);
183 }
184
185 static inline void print_subsys(const char *title, WORD value)
186 {
187     const char *str;
188     switch (value)
189     {
190         default:
191         case IMAGE_SUBSYSTEM_UNKNOWN:       str = "Unknown";        break;
192         case IMAGE_SUBSYSTEM_NATIVE:        str = "Native";         break;
193         case IMAGE_SUBSYSTEM_WINDOWS_GUI:   str = "Windows GUI";    break;
194         case IMAGE_SUBSYSTEM_WINDOWS_CUI:   str = "Windows CUI";    break;
195         case IMAGE_SUBSYSTEM_OS2_CUI:       str = "OS/2 CUI";       break;
196         case IMAGE_SUBSYSTEM_POSIX_CUI:     str = "Posix CUI";      break;
197         case IMAGE_SUBSYSTEM_NATIVE_WINDOWS:           str = "native Win9x driver";  break;
198         case IMAGE_SUBSYSTEM_WINDOWS_CE_GUI:           str = "Windows CE GUI";       break;
199         case IMAGE_SUBSYSTEM_EFI_APPLICATION:          str = "EFI application";      break;
200         case IMAGE_SUBSYSTEM_EFI_BOOT_SERVICE_DRIVER:  str = "EFI driver (boot)";    break;
201         case IMAGE_SUBSYSTEM_EFI_RUNTIME_DRIVER:       str = "EFI driver (runtime)"; break;
202         case IMAGE_SUBSYSTEM_EFI_ROM:                  str = "EFI ROM";              break;
203         case IMAGE_SUBSYSTEM_XBOX:                     str = "Xbox application";     break;
204         case IMAGE_SUBSYSTEM_WINDOWS_BOOT_APPLICATION: str = "Boot application";     break;
205     }
206     printf("  %-34s 0x%X (%s)\n", title, value, str);
207 }
208
209 static inline void print_dllflags(const char *title, WORD value)
210 {
211     printf("  %-34s 0x%X\n", title, value);
212 #define X(f,s) if (value & f) printf("    %s\n", s)
213     X(IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE,          "DYNAMIC_BASE");
214     X(IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY,       "FORCE_INTEGRITY");
215     X(IMAGE_DLLCHARACTERISTICS_NX_COMPAT,             "NX_COMPAT");
216     X(IMAGE_DLLCHARACTERISTICS_NO_ISOLATION,          "NO_ISOLATION");
217     X(IMAGE_DLLCHARACTERISTICS_NO_SEH,                "NO_SEH");
218     X(IMAGE_DLLCHARACTERISTICS_NO_BIND,               "NO_BIND");
219     X(IMAGE_DLLCHARACTERISTICS_WDM_DRIVER,            "WDM_DRIVER");
220     X(IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE, "TERMINAL_SERVER_AWARE");
221 #undef X
222 }
223
224 static inline void print_datadirectory(DWORD n, const IMAGE_DATA_DIRECTORY *directory)
225 {
226     unsigned i;
227     printf("Data Directory\n");
228
229     for (i = 0; i < n && i < 16; i++)
230     {
231         printf("  %-12s rva: 0x%-8x  size: 0x%-8x\n",
232                DirectoryNames[i], directory[i].VirtualAddress,
233                directory[i].Size);
234     }
235 }
236
237 static void dump_optional_header32(const IMAGE_OPTIONAL_HEADER32 *image_oh, UINT header_size)
238 {
239     IMAGE_OPTIONAL_HEADER32 oh;
240     const IMAGE_OPTIONAL_HEADER32 *optionalHeader;
241
242     /* in case optional header is missing or partial */
243     memset(&oh, 0, sizeof(oh));
244     memcpy(&oh, image_oh, min(header_size, sizeof(oh)));
245     optionalHeader = &oh;
246
247     print_word("Magic", optionalHeader->Magic);
248     print_ver("linker version",
249               optionalHeader->MajorLinkerVersion, optionalHeader->MinorLinkerVersion);
250     print_dword("size of code", optionalHeader->SizeOfCode);
251     print_dword("size of initialized data", optionalHeader->SizeOfInitializedData);
252     print_dword("size of uninitialized data", optionalHeader->SizeOfUninitializedData);
253     print_dword("entrypoint RVA", optionalHeader->AddressOfEntryPoint);
254     print_dword("base of code", optionalHeader->BaseOfCode);
255     print_dword("base of data", optionalHeader->BaseOfData);
256     print_dword("image base", optionalHeader->ImageBase);
257     print_dword("section align", optionalHeader->SectionAlignment);
258     print_dword("file align", optionalHeader->FileAlignment);
259     print_ver("required OS version",
260               optionalHeader->MajorOperatingSystemVersion, optionalHeader->MinorOperatingSystemVersion);
261     print_ver("image version",
262               optionalHeader->MajorImageVersion, optionalHeader->MinorImageVersion);
263     print_ver("subsystem version",
264               optionalHeader->MajorSubsystemVersion, optionalHeader->MinorSubsystemVersion);
265     print_dword("Win32 Version", optionalHeader->Win32VersionValue);
266     print_dword("size of image", optionalHeader->SizeOfImage);
267     print_dword("size of headers", optionalHeader->SizeOfHeaders);
268     print_dword("checksum", optionalHeader->CheckSum);
269     print_subsys("Subsystem", optionalHeader->Subsystem);
270     print_dllflags("DLL characteristics:", optionalHeader->DllCharacteristics);
271     print_dword("stack reserve size", optionalHeader->SizeOfStackReserve);
272     print_dword("stack commit size", optionalHeader->SizeOfStackCommit);
273     print_dword("heap reserve size", optionalHeader->SizeOfHeapReserve);
274     print_dword("heap commit size", optionalHeader->SizeOfHeapCommit);
275     print_dword("loader flags", optionalHeader->LoaderFlags);
276     print_dword("RVAs & sizes", optionalHeader->NumberOfRvaAndSizes);
277     printf("\n");
278     print_datadirectory(optionalHeader->NumberOfRvaAndSizes, optionalHeader->DataDirectory);
279     printf("\n");
280 }
281
282 static void dump_optional_header64(const IMAGE_OPTIONAL_HEADER64 *image_oh, UINT header_size)
283 {
284     IMAGE_OPTIONAL_HEADER64 oh;
285     const IMAGE_OPTIONAL_HEADER64 *optionalHeader;
286
287     /* in case optional header is missing or partial */
288     memset(&oh, 0, sizeof(oh));
289     memcpy(&oh, image_oh, min(header_size, sizeof(oh)));
290     optionalHeader = &oh;
291
292     print_word("Magic", optionalHeader->Magic);
293     print_ver("linker version",
294               optionalHeader->MajorLinkerVersion, optionalHeader->MinorLinkerVersion);
295     print_dword("size of code", optionalHeader->SizeOfCode);
296     print_dword("size of initialized data", optionalHeader->SizeOfInitializedData);
297     print_dword("size of uninitialized data", optionalHeader->SizeOfUninitializedData);
298     print_dword("entrypoint RVA", optionalHeader->AddressOfEntryPoint);
299     print_dword("base of code", optionalHeader->BaseOfCode);
300     print_longlong("image base", optionalHeader->ImageBase);
301     print_dword("section align", optionalHeader->SectionAlignment);
302     print_dword("file align", optionalHeader->FileAlignment);
303     print_ver("required OS version",
304               optionalHeader->MajorOperatingSystemVersion, optionalHeader->MinorOperatingSystemVersion);
305     print_ver("image version",
306               optionalHeader->MajorImageVersion, optionalHeader->MinorImageVersion);
307     print_ver("subsystem version",
308               optionalHeader->MajorSubsystemVersion, optionalHeader->MinorSubsystemVersion);
309     print_dword("Win32 Version", optionalHeader->Win32VersionValue);
310     print_dword("size of image", optionalHeader->SizeOfImage);
311     print_dword("size of headers", optionalHeader->SizeOfHeaders);
312     print_dword("checksum", optionalHeader->CheckSum);
313     print_subsys("Subsystem", optionalHeader->Subsystem);
314     print_dllflags("DLL characteristics:", optionalHeader->DllCharacteristics);
315     print_longlong("stack reserve size", optionalHeader->SizeOfStackReserve);
316     print_longlong("stack commit size", optionalHeader->SizeOfStackCommit);
317     print_longlong("heap reserve size", optionalHeader->SizeOfHeapReserve);
318     print_longlong("heap commit size", optionalHeader->SizeOfHeapCommit);
319     print_dword("loader flags", optionalHeader->LoaderFlags);
320     print_dword("RVAs & sizes", optionalHeader->NumberOfRvaAndSizes);
321     printf("\n");
322     print_datadirectory(optionalHeader->NumberOfRvaAndSizes, optionalHeader->DataDirectory);
323     printf("\n");
324 }
325
326 void dump_optional_header(const IMAGE_OPTIONAL_HEADER32 *optionalHeader, UINT header_size)
327 {
328     printf("Optional Header (%s)\n", get_magic_type(optionalHeader->Magic));
329
330     switch(optionalHeader->Magic) {
331         case IMAGE_NT_OPTIONAL_HDR32_MAGIC:
332             dump_optional_header32(optionalHeader, header_size);
333             break;
334         case IMAGE_NT_OPTIONAL_HDR64_MAGIC:
335             dump_optional_header64((const IMAGE_OPTIONAL_HEADER64 *)optionalHeader, header_size);
336             break;
337         default:
338             printf("  Unknown optional header magic: 0x%-4X\n", optionalHeader->Magic);
339             break;
340     }
341 }
342
343 void dump_file_header(const IMAGE_FILE_HEADER *fileHeader)
344 {
345     printf("File Header\n");
346
347     printf("  Machine:                      %04X (%s)\n",
348            fileHeader->Machine, get_machine_str(fileHeader->Machine));
349     printf("  Number of Sections:           %d\n", fileHeader->NumberOfSections);
350     printf("  TimeDateStamp:                %08X (%s) offset %lu\n",
351            fileHeader->TimeDateStamp, get_time_str(fileHeader->TimeDateStamp),
352            Offset(&(fileHeader->TimeDateStamp)));
353     printf("  PointerToSymbolTable:         %08X\n", fileHeader->PointerToSymbolTable);
354     printf("  NumberOfSymbols:              %08X\n", fileHeader->NumberOfSymbols);
355     printf("  SizeOfOptionalHeader:         %04X\n", fileHeader->SizeOfOptionalHeader);
356     printf("  Characteristics:              %04X\n", fileHeader->Characteristics);
357 #define X(f,s)  if (fileHeader->Characteristics & f) printf("    %s\n", s)
358     X(IMAGE_FILE_RELOCS_STRIPPED,       "RELOCS_STRIPPED");
359     X(IMAGE_FILE_EXECUTABLE_IMAGE,      "EXECUTABLE_IMAGE");
360     X(IMAGE_FILE_LINE_NUMS_STRIPPED,    "LINE_NUMS_STRIPPED");
361     X(IMAGE_FILE_LOCAL_SYMS_STRIPPED,   "LOCAL_SYMS_STRIPPED");
362     X(IMAGE_FILE_AGGRESIVE_WS_TRIM,     "AGGRESIVE_WS_TRIM");
363     X(IMAGE_FILE_LARGE_ADDRESS_AWARE,   "LARGE_ADDRESS_AWARE");
364     X(IMAGE_FILE_16BIT_MACHINE,         "16BIT_MACHINE");
365     X(IMAGE_FILE_BYTES_REVERSED_LO,     "BYTES_REVERSED_LO");
366     X(IMAGE_FILE_32BIT_MACHINE,         "32BIT_MACHINE");
367     X(IMAGE_FILE_DEBUG_STRIPPED,        "DEBUG_STRIPPED");
368     X(IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP,       "REMOVABLE_RUN_FROM_SWAP");
369     X(IMAGE_FILE_NET_RUN_FROM_SWAP,     "NET_RUN_FROM_SWAP");
370     X(IMAGE_FILE_SYSTEM,                "SYSTEM");
371     X(IMAGE_FILE_DLL,                   "DLL");
372     X(IMAGE_FILE_UP_SYSTEM_ONLY,        "UP_SYSTEM_ONLY");
373     X(IMAGE_FILE_BYTES_REVERSED_HI,     "BYTES_REVERSED_HI");
374 #undef X
375     printf("\n");
376 }
377
378 static  void    dump_pe_header(void)
379 {
380     dump_file_header(&PE_nt_headers->FileHeader);
381     dump_optional_header((const IMAGE_OPTIONAL_HEADER32*)&PE_nt_headers->OptionalHeader, PE_nt_headers->FileHeader.SizeOfOptionalHeader);
382 }
383
384 void dump_section(const IMAGE_SECTION_HEADER *sectHead, const char* strtable)
385 {
386         unsigned offset;
387
388         /* long section name ? */
389         if (strtable && sectHead->Name[0] == '/' &&
390             ((offset = atoi((const char*)sectHead->Name + 1)) < *(const DWORD*)strtable))
391             printf("  %.8s (%s)", sectHead->Name, strtable + offset);
392         else
393             printf("  %-8.8s", sectHead->Name);
394         printf("   VirtSize: 0x%08x  VirtAddr:  0x%08x\n",
395                sectHead->Misc.VirtualSize, sectHead->VirtualAddress);
396         printf("    raw data offs:   0x%08x  raw data size: 0x%08x\n",
397                sectHead->PointerToRawData, sectHead->SizeOfRawData);
398         printf("    relocation offs: 0x%08x  relocations:   0x%08x\n",
399                sectHead->PointerToRelocations, sectHead->NumberOfRelocations);
400         printf("    line # offs:     %-8u  line #'s:      %-8u\n",
401                sectHead->PointerToLinenumbers, sectHead->NumberOfLinenumbers);
402         printf("    characteristics: 0x%08x\n", sectHead->Characteristics);
403         printf("    ");
404 #define X(b,s)  if (sectHead->Characteristics & b) printf("  " s)
405 /* #define IMAGE_SCN_TYPE_REG                   0x00000000 - Reserved */
406 /* #define IMAGE_SCN_TYPE_DSECT                 0x00000001 - Reserved */
407 /* #define IMAGE_SCN_TYPE_NOLOAD                0x00000002 - Reserved */
408 /* #define IMAGE_SCN_TYPE_GROUP                 0x00000004 - Reserved */
409 /* #define IMAGE_SCN_TYPE_NO_PAD                0x00000008 - Reserved */
410 /* #define IMAGE_SCN_TYPE_COPY                  0x00000010 - Reserved */
411
412         X(IMAGE_SCN_CNT_CODE,                   "CODE");
413         X(IMAGE_SCN_CNT_INITIALIZED_DATA,       "INITIALIZED_DATA");
414         X(IMAGE_SCN_CNT_UNINITIALIZED_DATA,     "UNINITIALIZED_DATA");
415
416         X(IMAGE_SCN_LNK_OTHER,                  "LNK_OTHER");
417         X(IMAGE_SCN_LNK_INFO,                   "LNK_INFO");
418 /* #define      IMAGE_SCN_TYPE_OVER             0x00000400 - Reserved */
419         X(IMAGE_SCN_LNK_REMOVE,                 "LNK_REMOVE");
420         X(IMAGE_SCN_LNK_COMDAT,                 "LNK_COMDAT");
421
422 /*                                              0x00002000 - Reserved */
423 /* #define IMAGE_SCN_MEM_PROTECTED              0x00004000 - Obsolete */
424         X(IMAGE_SCN_MEM_FARDATA,                "MEM_FARDATA");
425
426 /* #define IMAGE_SCN_MEM_SYSHEAP                0x00010000 - Obsolete */
427         X(IMAGE_SCN_MEM_PURGEABLE,              "MEM_PURGEABLE");
428         X(IMAGE_SCN_MEM_16BIT,                  "MEM_16BIT");
429         X(IMAGE_SCN_MEM_LOCKED,                 "MEM_LOCKED");
430         X(IMAGE_SCN_MEM_PRELOAD,                "MEM_PRELOAD");
431
432         switch (sectHead->Characteristics & IMAGE_SCN_ALIGN_MASK)
433         {
434 #define X2(b,s) case b: printf("  " s); break
435         X2(IMAGE_SCN_ALIGN_1BYTES,              "ALIGN_1BYTES");
436         X2(IMAGE_SCN_ALIGN_2BYTES,              "ALIGN_2BYTES");
437         X2(IMAGE_SCN_ALIGN_4BYTES,              "ALIGN_4BYTES");
438         X2(IMAGE_SCN_ALIGN_8BYTES,              "ALIGN_8BYTES");
439         X2(IMAGE_SCN_ALIGN_16BYTES,             "ALIGN_16BYTES");
440         X2(IMAGE_SCN_ALIGN_32BYTES,             "ALIGN_32BYTES");
441         X2(IMAGE_SCN_ALIGN_64BYTES,             "ALIGN_64BYTES");
442         X2(IMAGE_SCN_ALIGN_128BYTES,            "ALIGN_128BYTES");
443         X2(IMAGE_SCN_ALIGN_256BYTES,            "ALIGN_256BYTES");
444         X2(IMAGE_SCN_ALIGN_512BYTES,            "ALIGN_512BYTES");
445         X2(IMAGE_SCN_ALIGN_1024BYTES,           "ALIGN_1024BYTES");
446         X2(IMAGE_SCN_ALIGN_2048BYTES,           "ALIGN_2048BYTES");
447         X2(IMAGE_SCN_ALIGN_4096BYTES,           "ALIGN_4096BYTES");
448         X2(IMAGE_SCN_ALIGN_8192BYTES,           "ALIGN_8192BYTES");
449 #undef X2
450         }
451
452         X(IMAGE_SCN_LNK_NRELOC_OVFL,            "LNK_NRELOC_OVFL");
453
454         X(IMAGE_SCN_MEM_DISCARDABLE,            "MEM_DISCARDABLE");
455         X(IMAGE_SCN_MEM_NOT_CACHED,             "MEM_NOT_CACHED");
456         X(IMAGE_SCN_MEM_NOT_PAGED,              "MEM_NOT_PAGED");
457         X(IMAGE_SCN_MEM_SHARED,                 "MEM_SHARED");
458         X(IMAGE_SCN_MEM_EXECUTE,                "MEM_EXECUTE");
459         X(IMAGE_SCN_MEM_READ,                   "MEM_READ");
460         X(IMAGE_SCN_MEM_WRITE,                  "MEM_WRITE");
461 #undef X
462         printf("\n\n");
463 }
464
465 static void dump_sections(const void *base, const void* addr, unsigned num_sect)
466 {
467     const IMAGE_SECTION_HEADER* sectHead = addr;
468     unsigned                    i;
469     const char*                 strtable;
470
471     if (PE_nt_headers->FileHeader.PointerToSymbolTable && PE_nt_headers->FileHeader.NumberOfSymbols)
472     {
473         strtable = (const char*)base +
474             PE_nt_headers->FileHeader.PointerToSymbolTable +
475             PE_nt_headers->FileHeader.NumberOfSymbols * sizeof(IMAGE_SYMBOL);
476     }
477     else strtable = NULL;
478
479     printf("Section Table\n");
480     for (i = 0; i < num_sect; i++, sectHead++)
481     {
482         dump_section(sectHead, strtable);
483
484         if (globals.do_dump_rawdata)
485         {
486             dump_data((const unsigned char *)base + sectHead->PointerToRawData, sectHead->SizeOfRawData, "    " );
487             printf("\n");
488         }
489     }
490 }
491
492 static  void    dump_dir_exported_functions(void)
493 {
494     unsigned int size = 0;
495     const IMAGE_EXPORT_DIRECTORY*exportDir = get_dir_and_size(IMAGE_FILE_EXPORT_DIRECTORY, &size);
496     unsigned int                i;
497     const DWORD*                pFunc;
498     const DWORD*                pName;
499     const WORD*                 pOrdl;
500     DWORD*                      funcs;
501
502     if (!exportDir) return;
503
504     printf("Exports table:\n");
505     printf("\n");
506     printf("  Name:            %s\n", (const char*)RVA(exportDir->Name, sizeof(DWORD)));
507     printf("  Characteristics: %08x\n", exportDir->Characteristics);
508     printf("  TimeDateStamp:   %08X %s\n",
509            exportDir->TimeDateStamp, get_time_str(exportDir->TimeDateStamp));
510     printf("  Version:         %u.%02u\n", exportDir->MajorVersion, exportDir->MinorVersion);
511     printf("  Ordinal base:    %u\n", exportDir->Base);
512     printf("  # of functions:  %u\n", exportDir->NumberOfFunctions);
513     printf("  # of Names:      %u\n", exportDir->NumberOfNames);
514     printf("Addresses of functions: %08X\n", exportDir->AddressOfFunctions);
515     printf("Addresses of name ordinals: %08X\n", exportDir->AddressOfNameOrdinals);
516     printf("Addresses of names: %08X\n", exportDir->AddressOfNames);
517     printf("\n");
518     printf("  Entry Pt  Ordn  Name\n");
519
520     pFunc = RVA(exportDir->AddressOfFunctions, exportDir->NumberOfFunctions * sizeof(DWORD));
521     if (!pFunc) {printf("Can't grab functions' address table\n"); return;}
522     pName = RVA(exportDir->AddressOfNames, exportDir->NumberOfNames * sizeof(DWORD));
523     pOrdl = RVA(exportDir->AddressOfNameOrdinals, exportDir->NumberOfNames * sizeof(WORD));
524
525     funcs = calloc( exportDir->NumberOfFunctions, sizeof(*funcs) );
526     if (!funcs) fatal("no memory");
527
528     for (i = 0; i < exportDir->NumberOfNames; i++) funcs[pOrdl[i]] = pName[i];
529
530     for (i = 0; i < exportDir->NumberOfFunctions; i++)
531     {
532         if (!pFunc[i]) continue;
533         printf("  %08X %5u ", pFunc[i], exportDir->Base + i);
534         if (funcs[i])
535             printf("%s", get_symbol_str((const char*)RVA(funcs[i], sizeof(DWORD))));
536         else
537             printf("<by ordinal>");
538
539         /* check for forwarded function */
540         if ((const char *)RVA(pFunc[i],1) >= (const char *)exportDir &&
541             (const char *)RVA(pFunc[i],1) < (const char *)exportDir + size)
542             printf(" (-> %s)", (const char *)RVA(pFunc[i],1));
543         printf("\n");
544     }
545     free(funcs);
546     printf("\n");
547 }
548
549
550 struct runtime_function
551 {
552     DWORD BeginAddress;
553     DWORD EndAddress;
554     DWORD UnwindData;
555 };
556
557 union handler_data
558 {
559     struct runtime_function chain;
560     DWORD handler;
561 };
562
563 struct opcode
564 {
565     BYTE offset;
566     BYTE code : 4;
567     BYTE info : 4;
568 };
569
570 struct unwind_info
571 {
572     BYTE version : 3;
573     BYTE flags : 5;
574     BYTE prolog;
575     BYTE count;
576     BYTE frame_reg : 4;
577     BYTE frame_offset : 4;
578     struct opcode opcodes[1];  /* count entries */
579     /* followed by union handler_data */
580 };
581
582 #define UWOP_PUSH_NONVOL     0
583 #define UWOP_ALLOC_LARGE     1
584 #define UWOP_ALLOC_SMALL     2
585 #define UWOP_SET_FPREG       3
586 #define UWOP_SAVE_NONVOL     4
587 #define UWOP_SAVE_NONVOL_FAR 5
588 #define UWOP_SAVE_XMM128     8
589 #define UWOP_SAVE_XMM128_FAR 9
590 #define UWOP_PUSH_MACHFRAME  10
591
592 #define UNW_FLAG_EHANDLER  1
593 #define UNW_FLAG_UHANDLER  2
594 #define UNW_FLAG_CHAININFO 4
595
596 static void dump_x86_64_unwind_info( const struct runtime_function *function )
597 {
598     static const char * const reg_names[16] =
599         { "rax", "rcx", "rdx", "rbx", "rsp", "rbp", "rsi", "rdi",
600           "r8",  "r9",  "r10", "r11", "r12", "r13", "r14", "r15" };
601
602     const union handler_data *handler_data;
603     const struct unwind_info *info;
604     unsigned int i, count;
605
606     printf( "\nFunction %08x-%08x:\n", function->BeginAddress, function->EndAddress );
607     if (function->UnwindData & 1)
608     {
609         const struct runtime_function *next = RVA( function->UnwindData & ~1, sizeof(*next) );
610         printf( "  -> function %08x-%08x\n", next->BeginAddress, next->EndAddress );
611         return;
612     }
613     info = RVA( function->UnwindData, sizeof(*info) );
614
615     printf( "  unwind info at %08x\n", function->UnwindData );
616     if (info->version != 1)
617     {
618         printf( "    *** unknown version %u\n", info->version );
619         return;
620     }
621     printf( "    flags %x", info->flags );
622     if (info->flags & UNW_FLAG_EHANDLER) printf( " EHANDLER" );
623     if (info->flags & UNW_FLAG_UHANDLER) printf( " UHANDLER" );
624     if (info->flags & UNW_FLAG_CHAININFO) printf( " CHAININFO" );
625     printf( "\n    prolog 0x%x bytes\n", info->prolog );
626
627     if (info->frame_reg)
628         printf( "    frame register %s offset 0x%x(%%rsp)\n",
629                 reg_names[info->frame_reg], info->frame_offset * 16 );
630
631     for (i = 0; i < info->count; i++)
632     {
633         printf( "      0x%02x: ", info->opcodes[i].offset );
634         switch (info->opcodes[i].code)
635         {
636         case UWOP_PUSH_NONVOL:
637             printf( "push %%%s\n", reg_names[info->opcodes[i].info] );
638             break;
639         case UWOP_ALLOC_LARGE:
640             if (info->opcodes[i].info)
641             {
642                 count = *(const DWORD *)&info->opcodes[i+1];
643                 i += 2;
644             }
645             else
646             {
647                 count = *(const USHORT *)&info->opcodes[i+1] * 8;
648                 i++;
649             }
650             printf( "sub $0x%x,%%rsp\n", count );
651             break;
652         case UWOP_ALLOC_SMALL:
653             count = (info->opcodes[i].info + 1) * 8;
654             printf( "sub $0x%x,%%rsp\n", count );
655             break;
656         case UWOP_SET_FPREG:
657             printf( "lea 0x%x(%%rsp),%s\n",
658                     info->frame_offset * 16, reg_names[info->frame_reg] );
659             break;
660         case UWOP_SAVE_NONVOL:
661             count = *(const USHORT *)&info->opcodes[i+1] * 8;
662             printf( "mov %%%s,0x%x(%%rsp)\n", reg_names[info->opcodes[i].info], count );
663             i++;
664             break;
665         case UWOP_SAVE_NONVOL_FAR:
666             count = *(const DWORD *)&info->opcodes[i+1];
667             printf( "mov %%%s,0x%x(%%rsp)\n", reg_names[info->opcodes[i].info], count );
668             i += 2;
669             break;
670         case UWOP_SAVE_XMM128:
671             count = *(const USHORT *)&info->opcodes[i+1] * 16;
672             printf( "movaps %%xmm%u,0x%x(%%rsp)\n", info->opcodes[i].info, count );
673             i++;
674             break;
675         case UWOP_SAVE_XMM128_FAR:
676             count = *(const DWORD *)&info->opcodes[i+1];
677             printf( "movaps %%xmm%u,0x%x(%%rsp)\n", info->opcodes[i].info, count );
678             i += 2;
679             break;
680         case UWOP_PUSH_MACHFRAME:
681             printf( "PUSH_MACHFRAME %u\n", info->opcodes[i].info );
682             break;
683         default:
684             printf( "*** unknown code %u\n", info->opcodes[i].code );
685             break;
686         }
687     }
688
689     handler_data = (const union handler_data *)&info->opcodes[(info->count + 1) & ~1];
690     if (info->flags & UNW_FLAG_CHAININFO)
691     {
692         printf( "    -> function %08x-%08x\n",
693                 handler_data->chain.BeginAddress, handler_data->chain.EndAddress );
694         return;
695     }
696     if (info->flags & (UNW_FLAG_EHANDLER | UNW_FLAG_UHANDLER))
697         printf( "    handler %08x data at %08x\n", handler_data->handler,
698                 (ULONG)(function->UnwindData + (const char *)(&handler_data->handler + 1) - (const char *)info ));
699 }
700
701 static void dump_dir_exceptions(void)
702 {
703     unsigned int i, size = 0;
704     const struct runtime_function *funcs = get_dir_and_size(IMAGE_FILE_EXCEPTION_DIRECTORY, &size);
705     const IMAGE_FILE_HEADER *file_header = &PE_nt_headers->FileHeader;
706
707     if (!funcs) return;
708
709     if (file_header->Machine == IMAGE_FILE_MACHINE_AMD64)
710     {
711         size /= sizeof(*funcs);
712         printf( "Exception info (%u functions):\n", size );
713         for (i = 0; i < size; i++) dump_x86_64_unwind_info( funcs + i );
714     }
715     else printf( "Exception information not supported for %s binaries\n",
716                  get_machine_str(file_header->Machine));
717 }
718
719
720 static void dump_image_thunk_data64(const IMAGE_THUNK_DATA64 *il)
721 {
722     /* FIXME: This does not properly handle large images */
723     const IMAGE_IMPORT_BY_NAME* iibn;
724     for (; il->u1.Ordinal; il++)
725     {
726         if (IMAGE_SNAP_BY_ORDINAL64(il->u1.Ordinal))
727             printf("  %4u  <by ordinal>\n", (DWORD)IMAGE_ORDINAL64(il->u1.Ordinal));
728         else
729         {
730             iibn = RVA((DWORD)il->u1.AddressOfData, sizeof(DWORD));
731             if (!iibn)
732                 printf("Can't grab import by name info, skipping to next ordinal\n");
733             else
734                 printf("  %4u  %s %x\n", iibn->Hint, iibn->Name, (DWORD)il->u1.AddressOfData);
735         }
736     }
737 }
738
739 static void dump_image_thunk_data32(const IMAGE_THUNK_DATA32 *il, int offset)
740 {
741     const IMAGE_IMPORT_BY_NAME* iibn;
742     for (; il->u1.Ordinal; il++)
743     {
744         if (IMAGE_SNAP_BY_ORDINAL32(il->u1.Ordinal))
745             printf("  %4u  <by ordinal>\n", IMAGE_ORDINAL32(il->u1.Ordinal));
746         else
747         {
748             iibn = RVA((DWORD)il->u1.AddressOfData - offset, sizeof(DWORD));
749             if (!iibn)
750                 printf("Can't grab import by name info, skipping to next ordinal\n");
751             else
752                 printf("  %4u  %s %x\n", iibn->Hint, iibn->Name, (DWORD)il->u1.AddressOfData);
753         }
754     }
755 }
756
757 static  void    dump_dir_imported_functions(void)
758 {
759     const IMAGE_IMPORT_DESCRIPTOR       *importDesc = get_dir(IMAGE_FILE_IMPORT_DIRECTORY);
760     DWORD directorySize;
761
762     if (!importDesc)    return;
763     if(PE_nt_headers->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
764     {
765         const IMAGE_OPTIONAL_HEADER64 *opt = (const IMAGE_OPTIONAL_HEADER64*)&PE_nt_headers->OptionalHeader;
766         directorySize = opt->DataDirectory[IMAGE_FILE_IMPORT_DIRECTORY].Size;
767     }
768     else
769     {
770         const IMAGE_OPTIONAL_HEADER32 *opt = (const IMAGE_OPTIONAL_HEADER32*)&PE_nt_headers->OptionalHeader;
771         directorySize = opt->DataDirectory[IMAGE_FILE_IMPORT_DIRECTORY].Size;
772     }
773
774     printf("Import Table size: %08x\n", directorySize);/* FIXME */
775
776     for (;;)
777     {
778         const IMAGE_THUNK_DATA32*       il;
779
780         if (!importDesc->Name || !importDesc->FirstThunk) break;
781
782         printf("  offset %08lx %s\n", Offset(importDesc), (const char*)RVA(importDesc->Name, sizeof(DWORD)));
783         printf("  Hint/Name Table: %08X\n", (DWORD)importDesc->u.OriginalFirstThunk);
784         printf("  TimeDateStamp:   %08X (%s)\n",
785                importDesc->TimeDateStamp, get_time_str(importDesc->TimeDateStamp));
786         printf("  ForwarderChain:  %08X\n", importDesc->ForwarderChain);
787         printf("  First thunk RVA: %08X\n", (DWORD)importDesc->FirstThunk);
788
789         printf("  Ordn  Name\n");
790
791         il = (importDesc->u.OriginalFirstThunk != 0) ?
792             RVA((DWORD)importDesc->u.OriginalFirstThunk, sizeof(DWORD)) :
793             RVA((DWORD)importDesc->FirstThunk, sizeof(DWORD));
794
795         if (!il)
796             printf("Can't grab thunk data, going to next imported DLL\n");
797         else
798         {
799             if(PE_nt_headers->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
800                 dump_image_thunk_data64((const IMAGE_THUNK_DATA64*)il);
801             else
802                 dump_image_thunk_data32(il, 0);
803             printf("\n");
804         }
805         importDesc++;
806     }
807     printf("\n");
808 }
809
810 static void dump_dir_delay_imported_functions(void)
811 {
812     const struct ImgDelayDescr
813     {
814         DWORD grAttrs;
815         DWORD szName;
816         DWORD phmod;
817         DWORD pIAT;
818         DWORD pINT;
819         DWORD pBoundIAT;
820         DWORD pUnloadIAT;
821         DWORD dwTimeStamp;
822     } *importDesc = get_dir(IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT);
823     DWORD directorySize;
824
825     if (!importDesc) return;
826     if (PE_nt_headers->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
827     {
828         const IMAGE_OPTIONAL_HEADER64 *opt = (const IMAGE_OPTIONAL_HEADER64 *)&PE_nt_headers->OptionalHeader;
829         directorySize = opt->DataDirectory[IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT].Size;
830     }
831     else
832     {
833         const IMAGE_OPTIONAL_HEADER32 *opt = (const IMAGE_OPTIONAL_HEADER32 *)&PE_nt_headers->OptionalHeader;
834         directorySize = opt->DataDirectory[IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT].Size;
835     }
836
837     printf("Delay Import Table size: %08x\n", directorySize); /* FIXME */
838
839     for (;;)
840     {
841         const IMAGE_THUNK_DATA32*       il;
842         int                             offset = (importDesc->grAttrs & 1) ? 0 : PE_nt_headers->OptionalHeader.ImageBase;
843
844         if (!importDesc->szName || !importDesc->pIAT || !importDesc->pINT) break;
845
846         printf("  grAttrs %08x offset %08lx %s\n", importDesc->grAttrs, Offset(importDesc),
847                (const char *)RVA(importDesc->szName - offset, sizeof(DWORD)));
848         printf("  Hint/Name Table: %08x\n", importDesc->pINT);
849         printf("  TimeDateStamp:   %08X (%s)\n",
850                importDesc->dwTimeStamp, get_time_str(importDesc->dwTimeStamp));
851
852         printf("  Ordn  Name\n");
853
854         il = RVA(importDesc->pINT - offset, sizeof(DWORD));
855
856         if (!il)
857             printf("Can't grab thunk data, going to next imported DLL\n");
858         else
859         {
860             if (PE_nt_headers->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
861                 dump_image_thunk_data64((const IMAGE_THUNK_DATA64 *)il);
862             else
863                 dump_image_thunk_data32(il, offset);
864             printf("\n");
865         }
866         importDesc++;
867     }
868     printf("\n");
869 }
870
871 static  void    dump_dir_debug_dir(const IMAGE_DEBUG_DIRECTORY* idd, int idx)
872 {
873     const       char*   str;
874
875     printf("Directory %02u\n", idx + 1);
876     printf("  Characteristics:   %08X\n", idd->Characteristics);
877     printf("  TimeDateStamp:     %08X %s\n",
878            idd->TimeDateStamp, get_time_str(idd->TimeDateStamp));
879     printf("  Version            %u.%02u\n", idd->MajorVersion, idd->MinorVersion);
880     switch (idd->Type)
881     {
882     default:
883     case IMAGE_DEBUG_TYPE_UNKNOWN:      str = "UNKNOWN";        break;
884     case IMAGE_DEBUG_TYPE_COFF:         str = "COFF";           break;
885     case IMAGE_DEBUG_TYPE_CODEVIEW:     str = "CODEVIEW";       break;
886     case IMAGE_DEBUG_TYPE_FPO:          str = "FPO";            break;
887     case IMAGE_DEBUG_TYPE_MISC:         str = "MISC";           break;
888     case IMAGE_DEBUG_TYPE_EXCEPTION:    str = "EXCEPTION";      break;
889     case IMAGE_DEBUG_TYPE_FIXUP:        str = "FIXUP";          break;
890     case IMAGE_DEBUG_TYPE_OMAP_TO_SRC:  str = "OMAP_TO_SRC";    break;
891     case IMAGE_DEBUG_TYPE_OMAP_FROM_SRC:str = "OMAP_FROM_SRC";  break;
892     case IMAGE_DEBUG_TYPE_BORLAND:      str = "BORLAND";        break;
893     case IMAGE_DEBUG_TYPE_RESERVED10:   str = "RESERVED10";     break;
894     }
895     printf("  Type:              %u (%s)\n", idd->Type, str);
896     printf("  SizeOfData:        %u\n", idd->SizeOfData);
897     printf("  AddressOfRawData:  %08X\n", idd->AddressOfRawData);
898     printf("  PointerToRawData:  %08X\n", idd->PointerToRawData);
899
900     switch (idd->Type)
901     {
902     case IMAGE_DEBUG_TYPE_UNKNOWN:
903         break;
904     case IMAGE_DEBUG_TYPE_COFF:
905         dump_coff(idd->PointerToRawData, idd->SizeOfData, 
906                   (const char*)PE_nt_headers + sizeof(DWORD) + sizeof(IMAGE_FILE_HEADER) + PE_nt_headers->FileHeader.SizeOfOptionalHeader);
907         break;
908     case IMAGE_DEBUG_TYPE_CODEVIEW:
909         dump_codeview(idd->PointerToRawData, idd->SizeOfData);
910         break;
911     case IMAGE_DEBUG_TYPE_FPO:
912         dump_frame_pointer_omission(idd->PointerToRawData, idd->SizeOfData);
913         break;
914     case IMAGE_DEBUG_TYPE_MISC:
915     {
916         const IMAGE_DEBUG_MISC* misc = PRD(idd->PointerToRawData, idd->SizeOfData);
917         if (!misc) {printf("Can't get misc debug information\n"); break;}
918         printf("    DataType:          %u (%s)\n",
919                misc->DataType,
920                (misc->DataType == IMAGE_DEBUG_MISC_EXENAME) ? "Exe name" : "Unknown");
921         printf("    Length:            %u\n", misc->Length);
922         printf("    Unicode:           %s\n", misc->Unicode ? "Yes" : "No");
923         printf("    Data:              %s\n", misc->Data);
924     }
925     break;
926     case IMAGE_DEBUG_TYPE_EXCEPTION:
927         break;
928     case IMAGE_DEBUG_TYPE_FIXUP:
929         break;
930     case IMAGE_DEBUG_TYPE_OMAP_TO_SRC:
931         break;
932     case IMAGE_DEBUG_TYPE_OMAP_FROM_SRC:
933         break;
934     case IMAGE_DEBUG_TYPE_BORLAND:
935         break;
936     case IMAGE_DEBUG_TYPE_RESERVED10:
937         break;
938     }
939     printf("\n");
940 }
941
942 static void     dump_dir_debug(void)
943 {
944     const IMAGE_DEBUG_DIRECTORY*debugDir = get_dir(IMAGE_FILE_DEBUG_DIRECTORY);
945     unsigned                    nb_dbg, i;
946
947     if (!debugDir) return;
948     nb_dbg = PE_nt_headers->OptionalHeader.DataDirectory[IMAGE_FILE_DEBUG_DIRECTORY].Size /
949         sizeof(*debugDir);
950     if (!nb_dbg) return;
951
952     printf("Debug Table (%u directories)\n", nb_dbg);
953
954     for (i = 0; i < nb_dbg; i++)
955     {
956         dump_dir_debug_dir(debugDir, i);
957         debugDir++;
958     }
959     printf("\n");
960 }
961
962 static inline void print_clrflags(const char *title, WORD value)
963 {
964     printf("  %-34s 0x%X\n", title, value);
965 #define X(f,s) if (value & f) printf("    %s\n", s)
966     X(COMIMAGE_FLAGS_ILONLY,           "ILONLY");
967     X(COMIMAGE_FLAGS_32BITREQUIRED,    "32BITREQUIRED");
968     X(COMIMAGE_FLAGS_IL_LIBRARY,       "IL_LIBRARY");
969     X(COMIMAGE_FLAGS_STRONGNAMESIGNED, "STRONGNAMESIGNED");
970     X(COMIMAGE_FLAGS_TRACKDEBUGDATA,   "TRACKDEBUGDATA");
971 #undef X
972 }
973
974 static inline void print_clrdirectory(const char *title, const IMAGE_DATA_DIRECTORY *dir)
975 {
976     printf("  %-23s rva: 0x%-8x  size: 0x%-8x\n", title, dir->VirtualAddress, dir->Size);
977 }
978
979 static void dump_dir_clr_header(void)
980 {
981     unsigned int size = 0;
982     const IMAGE_COR20_HEADER *dir = get_dir_and_size(IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR, &size);
983
984     if (!dir) return;
985
986     printf( "CLR Header\n" );
987     print_dword( "Header Size", dir->cb );
988     print_ver( "Required runtime version", dir->MajorRuntimeVersion, dir->MinorRuntimeVersion );
989     print_clrflags( "Flags", dir->Flags );
990     print_dword( "EntryPointToken", dir->EntryPointToken );
991     printf("\n");
992     printf( "CLR Data Directory\n" );
993     print_clrdirectory( "MetaData", &dir->MetaData );
994     print_clrdirectory( "Resources", &dir->Resources );
995     print_clrdirectory( "StrongNameSignature", &dir->StrongNameSignature );
996     print_clrdirectory( "CodeManagerTable", &dir->CodeManagerTable );
997     print_clrdirectory( "VTableFixups", &dir->VTableFixups );
998     print_clrdirectory( "ExportAddressTableJumps", &dir->ExportAddressTableJumps );
999     print_clrdirectory( "ManagedNativeHeader", &dir->ManagedNativeHeader );
1000     printf("\n");
1001 }
1002
1003 static void dump_dir_reloc(void)
1004 {
1005     unsigned int i, size = 0;
1006     const USHORT *relocs;
1007     const IMAGE_BASE_RELOCATION *rel = get_dir_and_size(IMAGE_DIRECTORY_ENTRY_BASERELOC, &size);
1008     const IMAGE_BASE_RELOCATION *end = (const IMAGE_BASE_RELOCATION *)((const char *)rel + size);
1009     static const char * const names[] =
1010     {
1011         "BASED_ABSOLUTE",
1012         "BASED_HIGH",
1013         "BASED_LOW",
1014         "BASED_HIGHLOW",
1015         "BASED_HIGHADJ",
1016         "BASED_MIPS_JMPADDR",
1017         "BASED_SECTION",
1018         "BASED_REL",
1019         "unknown 8",
1020         "BASED_IA64_IMM64",
1021         "BASED_DIR64",
1022         "BASED_HIGH3ADJ",
1023         "unknown 12",
1024         "unknown 13",
1025         "unknown 14",
1026         "unknown 15"
1027     };
1028
1029     if (!rel) return;
1030
1031     printf( "Relocations\n" );
1032     while (rel < end - 1 && rel->SizeOfBlock)
1033     {
1034         printf( "  Page %x\n", rel->VirtualAddress );
1035         relocs = (const USHORT *)(rel + 1);
1036         i = (rel->SizeOfBlock - sizeof(*rel)) / sizeof(USHORT);
1037         while (i--)
1038         {
1039             USHORT offset = *relocs & 0xfff;
1040             int type = *relocs >> 12;
1041             printf( "    off %04x type %s\n", offset, names[type] );
1042             relocs++;
1043         }
1044         rel = (const IMAGE_BASE_RELOCATION *)relocs;
1045     }
1046     printf("\n");
1047 }
1048
1049 static void dump_dir_tls(void)
1050 {
1051     IMAGE_TLS_DIRECTORY64 dir;
1052     const DWORD *callbacks;
1053     const IMAGE_TLS_DIRECTORY32 *pdir = get_dir(IMAGE_FILE_THREAD_LOCAL_STORAGE);
1054
1055     if (!pdir) return;
1056
1057     if(PE_nt_headers->OptionalHeader.Magic == IMAGE_NT_OPTIONAL_HDR64_MAGIC)
1058         memcpy(&dir, pdir, sizeof(dir));
1059     else
1060     {
1061         dir.StartAddressOfRawData = pdir->StartAddressOfRawData;
1062         dir.EndAddressOfRawData = pdir->EndAddressOfRawData;
1063         dir.AddressOfIndex = pdir->AddressOfIndex;
1064         dir.AddressOfCallBacks = pdir->AddressOfCallBacks;
1065         dir.SizeOfZeroFill = pdir->SizeOfZeroFill;
1066         dir.Characteristics = pdir->Characteristics;
1067     }
1068
1069     /* FIXME: This does not properly handle large images */
1070     printf( "Thread Local Storage\n" );
1071     printf( "  Raw data        %08x-%08x (data size %x zero fill size %x)\n",
1072             (DWORD)dir.StartAddressOfRawData, (DWORD)dir.EndAddressOfRawData,
1073             (DWORD)(dir.EndAddressOfRawData - dir.StartAddressOfRawData),
1074             (DWORD)dir.SizeOfZeroFill );
1075     printf( "  Index address   %08x\n", (DWORD)dir.AddressOfIndex );
1076     printf( "  Characteristics %08x\n", dir.Characteristics );
1077     printf( "  Callbacks       %08x -> {", (DWORD)dir.AddressOfCallBacks );
1078     if (dir.AddressOfCallBacks)
1079     {
1080         DWORD   addr = (DWORD)dir.AddressOfCallBacks - PE_nt_headers->OptionalHeader.ImageBase;
1081         while ((callbacks = RVA(addr, sizeof(DWORD))) && *callbacks)
1082         {
1083             printf( " %08x", *callbacks );
1084             addr += sizeof(DWORD);
1085         }
1086     }
1087     printf(" }\n\n");
1088 }
1089
1090 enum FileSig get_kind_dbg(void)
1091 {
1092     const WORD*                pw;
1093
1094     pw = PRD(0, sizeof(WORD));
1095     if (!pw) {printf("Can't get main signature, aborting\n"); return 0;}
1096
1097     if (*pw == 0x4944 /* "DI" */) return SIG_DBG;
1098     return SIG_UNKNOWN;
1099 }
1100
1101 void    dbg_dump(void)
1102 {
1103     const IMAGE_SEPARATE_DEBUG_HEADER*  separateDebugHead;
1104     unsigned                            nb_dbg;
1105     unsigned                            i;
1106     const IMAGE_DEBUG_DIRECTORY*        debugDir;
1107
1108     separateDebugHead = PRD(0, sizeof(*separateDebugHead));
1109     if (!separateDebugHead) {printf("Can't grab the separate header, aborting\n"); return;}
1110
1111     printf ("Signature:          %.2s (0x%4X)\n",
1112             (const char*)&separateDebugHead->Signature, separateDebugHead->Signature);
1113     printf ("Flags:              0x%04X\n", separateDebugHead->Flags);
1114     printf ("Machine:            0x%04X (%s)\n",
1115             separateDebugHead->Machine, get_machine_str(separateDebugHead->Machine));
1116     printf ("Characteristics:    0x%04X\n", separateDebugHead->Characteristics);
1117     printf ("TimeDateStamp:      0x%08X (%s)\n",
1118             separateDebugHead->TimeDateStamp, get_time_str(separateDebugHead->TimeDateStamp));
1119     printf ("CheckSum:           0x%08X\n", separateDebugHead->CheckSum);
1120     printf ("ImageBase:          0x%08X\n", separateDebugHead->ImageBase);
1121     printf ("SizeOfImage:        0x%08X\n", separateDebugHead->SizeOfImage);
1122     printf ("NumberOfSections:   0x%08X\n", separateDebugHead->NumberOfSections);
1123     printf ("ExportedNamesSize:  0x%08X\n", separateDebugHead->ExportedNamesSize);
1124     printf ("DebugDirectorySize: 0x%08X\n", separateDebugHead->DebugDirectorySize);
1125
1126     if (!PRD(sizeof(IMAGE_SEPARATE_DEBUG_HEADER),
1127              separateDebugHead->NumberOfSections * sizeof(IMAGE_SECTION_HEADER)))
1128     {printf("Can't get the sections, aborting\n"); return;}
1129
1130     dump_sections(separateDebugHead, separateDebugHead + 1, separateDebugHead->NumberOfSections);
1131
1132     nb_dbg = separateDebugHead->DebugDirectorySize / sizeof(IMAGE_DEBUG_DIRECTORY);
1133     debugDir = PRD(sizeof(IMAGE_SEPARATE_DEBUG_HEADER) +
1134                    separateDebugHead->NumberOfSections * sizeof(IMAGE_SECTION_HEADER) +
1135                    separateDebugHead->ExportedNamesSize,
1136                    nb_dbg * sizeof(IMAGE_DEBUG_DIRECTORY));
1137     if (!debugDir) {printf("Couldn't get the debug directory info, aborting\n");return;}
1138
1139     printf("Debug Table (%u directories)\n", nb_dbg);
1140
1141     for (i = 0; i < nb_dbg; i++)
1142     {
1143         dump_dir_debug_dir(debugDir, i);
1144         debugDir++;
1145     }
1146 }
1147
1148 static const char *get_resource_type( unsigned int id )
1149 {
1150     static const char * const types[] =
1151     {
1152         NULL,
1153         "CURSOR",
1154         "BITMAP",
1155         "ICON",
1156         "MENU",
1157         "DIALOG",
1158         "STRING",
1159         "FONTDIR",
1160         "FONT",
1161         "ACCELERATOR",
1162         "RCDATA",
1163         "MESSAGETABLE",
1164         "GROUP_CURSOR",
1165         NULL,
1166         "GROUP_ICON",
1167         NULL,
1168         "VERSION",
1169         "DLGINCLUDE",
1170         NULL,
1171         "PLUGPLAY",
1172         "VXD",
1173         "ANICURSOR",
1174         "ANIICON",
1175         "HTML",
1176         "RT_MANIFEST"
1177     };
1178
1179     if ((size_t)id < sizeof(types)/sizeof(types[0])) return types[id];
1180     return NULL;
1181 }
1182
1183 /* dump an ASCII string with proper escaping */
1184 static int dump_strA( const unsigned char *str, size_t len )
1185 {
1186     static const char escapes[32] = ".......abtnvfr.............e....";
1187     char buffer[256];
1188     char *pos = buffer;
1189     int count = 0;
1190
1191     for (; len; str++, len--)
1192     {
1193         if (pos > buffer + sizeof(buffer) - 8)
1194         {
1195             fwrite( buffer, pos - buffer, 1, stdout );
1196             count += pos - buffer;
1197             pos = buffer;
1198         }
1199         if (*str > 127)  /* hex escape */
1200         {
1201             pos += sprintf( pos, "\\x%02x", *str );
1202             continue;
1203         }
1204         if (*str < 32)  /* octal or C escape */
1205         {
1206             if (!*str && len == 1) continue;  /* do not output terminating NULL */
1207             if (escapes[*str] != '.')
1208                 pos += sprintf( pos, "\\%c", escapes[*str] );
1209             else if (len > 1 && str[1] >= '0' && str[1] <= '7')
1210                 pos += sprintf( pos, "\\%03o", *str );
1211             else
1212                 pos += sprintf( pos, "\\%o", *str );
1213             continue;
1214         }
1215         if (*str == '\\') *pos++ = '\\';
1216         *pos++ = *str;
1217     }
1218     fwrite( buffer, pos - buffer, 1, stdout );
1219     count += pos - buffer;
1220     return count;
1221 }
1222
1223 /* dump a Unicode string with proper escaping */
1224 static int dump_strW( const WCHAR *str, size_t len )
1225 {
1226     static const char escapes[32] = ".......abtnvfr.............e....";
1227     char buffer[256];
1228     char *pos = buffer;
1229     int count = 0;
1230
1231     for (; len; str++, len--)
1232     {
1233         if (pos > buffer + sizeof(buffer) - 8)
1234         {
1235             fwrite( buffer, pos - buffer, 1, stdout );
1236             count += pos - buffer;
1237             pos = buffer;
1238         }
1239         if (*str > 127)  /* hex escape */
1240         {
1241             if (len > 1 && str[1] < 128 && isxdigit((char)str[1]))
1242                 pos += sprintf( pos, "\\x%04x", *str );
1243             else
1244                 pos += sprintf( pos, "\\x%x", *str );
1245             continue;
1246         }
1247         if (*str < 32)  /* octal or C escape */
1248         {
1249             if (!*str && len == 1) continue;  /* do not output terminating NULL */
1250             if (escapes[*str] != '.')
1251                 pos += sprintf( pos, "\\%c", escapes[*str] );
1252             else if (len > 1 && str[1] >= '0' && str[1] <= '7')
1253                 pos += sprintf( pos, "\\%03o", *str );
1254             else
1255                 pos += sprintf( pos, "\\%o", *str );
1256             continue;
1257         }
1258         if (*str == '\\') *pos++ = '\\';
1259         *pos++ = *str;
1260     }
1261     fwrite( buffer, pos - buffer, 1, stdout );
1262     count += pos - buffer;
1263     return count;
1264 }
1265
1266 /* dump data for a STRING resource */
1267 static void dump_string_data( const WCHAR *ptr, unsigned int size, unsigned int id, const char *prefix )
1268 {
1269     int i;
1270
1271     for (i = 0; i < 16 && size; i++)
1272     {
1273         unsigned len = *ptr++;
1274
1275         if (len >= size)
1276         {
1277             len = size;
1278             size = 0;
1279         }
1280         else size -= len + 1;
1281
1282         if (len)
1283         {
1284             printf( "%s%04x \"", prefix, (id - 1) * 16 + i );
1285             dump_strW( ptr, len );
1286             printf( "\"\n" );
1287             ptr += len;
1288         }
1289     }
1290 }
1291
1292 /* dump data for a MESSAGETABLE resource */
1293 static void dump_msgtable_data( const void *ptr, unsigned int size, unsigned int id, const char *prefix )
1294 {
1295     const MESSAGE_RESOURCE_DATA *data = ptr;
1296     const MESSAGE_RESOURCE_BLOCK *block = data->Blocks;
1297     unsigned i, j;
1298
1299     for (i = 0; i < data->NumberOfBlocks; i++, block++)
1300     {
1301         const MESSAGE_RESOURCE_ENTRY *entry;
1302
1303         entry = (const MESSAGE_RESOURCE_ENTRY *)((const char *)data + block->OffsetToEntries);
1304         for (j = block->LowId; j <= block->HighId; j++)
1305         {
1306             if (entry->Flags & MESSAGE_RESOURCE_UNICODE)
1307             {
1308                 const WCHAR *str = (const WCHAR *)entry->Text;
1309                 printf( "%s%08x L\"", prefix, j );
1310                 dump_strW( str, strlenW(str) );
1311                 printf( "\"\n" );
1312             }
1313             else
1314             {
1315                 const char *str = (const char *) entry->Text;
1316                 printf( "%s%08x \"", prefix, j );
1317                 dump_strA( entry->Text, strlen(str) );
1318                 printf( "\"\n" );
1319             }
1320             entry = (const MESSAGE_RESOURCE_ENTRY *)((const char *)entry + entry->Length);
1321         }
1322     }
1323 }
1324
1325 static void dump_dir_resource(void)
1326 {
1327     const IMAGE_RESOURCE_DIRECTORY *root = get_dir(IMAGE_FILE_RESOURCE_DIRECTORY);
1328     const IMAGE_RESOURCE_DIRECTORY *namedir;
1329     const IMAGE_RESOURCE_DIRECTORY *langdir;
1330     const IMAGE_RESOURCE_DIRECTORY_ENTRY *e1, *e2, *e3;
1331     const IMAGE_RESOURCE_DIR_STRING_U *string;
1332     const IMAGE_RESOURCE_DATA_ENTRY *data;
1333     int i, j, k;
1334
1335     if (!root) return;
1336
1337     printf( "Resources:" );
1338
1339     for (i = 0; i< root->NumberOfNamedEntries + root->NumberOfIdEntries; i++)
1340     {
1341         e1 = (const IMAGE_RESOURCE_DIRECTORY_ENTRY*)(root + 1) + i;
1342         namedir = (const IMAGE_RESOURCE_DIRECTORY *)((const char *)root + e1->u2.s3.OffsetToDirectory);
1343         for (j = 0; j < namedir->NumberOfNamedEntries + namedir->NumberOfIdEntries; j++)
1344         {
1345             e2 = (const IMAGE_RESOURCE_DIRECTORY_ENTRY*)(namedir + 1) + j;
1346             langdir = (const IMAGE_RESOURCE_DIRECTORY *)((const char *)root + e2->u2.s3.OffsetToDirectory);
1347             for (k = 0; k < langdir->NumberOfNamedEntries + langdir->NumberOfIdEntries; k++)
1348             {
1349                 e3 = (const IMAGE_RESOURCE_DIRECTORY_ENTRY*)(langdir + 1) + k;
1350
1351                 printf( "\n  " );
1352                 if (e1->u1.s1.NameIsString)
1353                 {
1354                     string = (const IMAGE_RESOURCE_DIR_STRING_U*)((const char *)root + e1->u1.s1.NameOffset);
1355                     dump_unicode_str( string->NameString, string->Length );
1356                 }
1357                 else
1358                 {
1359                     const char *type = get_resource_type( e1->u1.s2.Id );
1360                     if (type) printf( "%s", type );
1361                     else printf( "%04x", e1->u1.s2.Id );
1362                 }
1363
1364                 printf( " Name=" );
1365                 if (e2->u1.s1.NameIsString)
1366                 {
1367                     string = (const IMAGE_RESOURCE_DIR_STRING_U*) ((const char *)root + e2->u1.s1.NameOffset);
1368                     dump_unicode_str( string->NameString, string->Length );
1369                 }
1370                 else
1371                     printf( "%04x", e2->u1.s2.Id );
1372
1373                 printf( " Language=%04x:\n", e3->u1.s2.Id );
1374                 data = (const IMAGE_RESOURCE_DATA_ENTRY *)((const char *)root + e3->u2.OffsetToData);
1375                 if (e1->u1.s1.NameIsString)
1376                 {
1377                     dump_data( RVA( data->OffsetToData, data->Size ), data->Size, "    " );
1378                 }
1379                 else switch(e1->u1.s2.Id)
1380                 {
1381                 case 6:
1382                     dump_string_data( RVA( data->OffsetToData, data->Size ), data->Size,
1383                                       e2->u1.s2.Id, "    " );
1384                     break;
1385                 case 11:
1386                     dump_msgtable_data( RVA( data->OffsetToData, data->Size ), data->Size,
1387                                         e2->u1.s2.Id, "    " );
1388                     break;
1389                 default:
1390                     dump_data( RVA( data->OffsetToData, data->Size ), data->Size, "    " );
1391                     break;
1392                 }
1393             }
1394         }
1395     }
1396     printf( "\n\n" );
1397 }
1398
1399 static void dump_debug(void)
1400 {
1401     const char* stabs = NULL;
1402     unsigned    szstabs = 0;
1403     const char* stabstr = NULL;
1404     unsigned    szstr = 0;
1405     unsigned    i;
1406     const IMAGE_SECTION_HEADER* sectHead;
1407
1408     sectHead = (const IMAGE_SECTION_HEADER*)
1409         ((const char*)PE_nt_headers + sizeof(DWORD) +
1410          sizeof(IMAGE_FILE_HEADER) + PE_nt_headers->FileHeader.SizeOfOptionalHeader);
1411
1412     for (i = 0; i < PE_nt_headers->FileHeader.NumberOfSections; i++, sectHead++)
1413     {
1414         if (!strcmp((const char *)sectHead->Name, ".stab"))
1415         {
1416             stabs = RVA(sectHead->VirtualAddress, sectHead->Misc.VirtualSize); 
1417             szstabs = sectHead->Misc.VirtualSize;
1418         }
1419         if (!strncmp((const char *)sectHead->Name, ".stabstr", 8))
1420         {
1421             stabstr = RVA(sectHead->VirtualAddress, sectHead->Misc.VirtualSize);
1422             szstr = sectHead->Misc.VirtualSize;
1423         }
1424     }
1425     if (stabs && stabstr)
1426         dump_stabs(stabs, szstabs, stabstr, szstr);
1427 }
1428
1429 static void dump_symbol_table(void)
1430 {
1431     const IMAGE_SYMBOL* sym;
1432     int                 numsym;
1433
1434     numsym = PE_nt_headers->FileHeader.NumberOfSymbols;
1435     if (!PE_nt_headers->FileHeader.PointerToSymbolTable || !numsym)
1436         return;
1437     sym = PRD(PE_nt_headers->FileHeader.PointerToSymbolTable,
1438                                    sizeof(*sym) * numsym);
1439     if (!sym) return;
1440
1441     dump_coff_symbol_table(sym, numsym, IMAGE_FIRST_SECTION(PE_nt_headers));
1442 }
1443
1444 enum FileSig get_kind_exec(void)
1445 {
1446     const WORD*                pw;
1447     const DWORD*               pdw;
1448     const IMAGE_DOS_HEADER*    dh;
1449
1450     pw = PRD(0, sizeof(WORD));
1451     if (!pw) {printf("Can't get main signature, aborting\n"); return 0;}
1452
1453     if (*pw != IMAGE_DOS_SIGNATURE) return SIG_UNKNOWN;
1454
1455     if ((dh = PRD(0, sizeof(IMAGE_DOS_HEADER))))
1456     {
1457         /* the signature is the first DWORD */
1458         pdw = PRD(dh->e_lfanew, sizeof(DWORD));
1459         if (pdw)
1460         {
1461             if (*pdw == IMAGE_NT_SIGNATURE)                     return SIG_PE;
1462             if (*(const WORD *)pdw == IMAGE_OS2_SIGNATURE)      return SIG_NE;
1463             if (*(const WORD *)pdw == IMAGE_VXD_SIGNATURE)      return SIG_LE;
1464             return SIG_DOS;
1465         }
1466     }
1467     return 0;
1468 }
1469
1470 void pe_dump(void)
1471 {
1472     int all = (globals.dumpsect != NULL) && strcmp(globals.dumpsect, "ALL") == 0;
1473
1474     PE_nt_headers = get_nt_header();
1475     if (is_fake_dll()) printf( "*** This is a Wine fake DLL ***\n\n" );
1476
1477     if (globals.do_dumpheader)
1478     {
1479         dump_pe_header();
1480         /* FIXME: should check ptr */
1481         dump_sections(PRD(0, 1), (const char*)PE_nt_headers + sizeof(DWORD) +
1482                       sizeof(IMAGE_FILE_HEADER) + PE_nt_headers->FileHeader.SizeOfOptionalHeader,
1483                       PE_nt_headers->FileHeader.NumberOfSections);
1484     }
1485     else if (!globals.dumpsect)
1486     {
1487         /* show at least something here */
1488         dump_pe_header();
1489     }
1490
1491     if (globals.dumpsect)
1492     {
1493         if (all || !strcmp(globals.dumpsect, "import"))
1494         {
1495             dump_dir_imported_functions();
1496             dump_dir_delay_imported_functions();
1497         }
1498         if (all || !strcmp(globals.dumpsect, "export"))
1499             dump_dir_exported_functions();
1500         if (all || !strcmp(globals.dumpsect, "debug"))
1501             dump_dir_debug();
1502         if (all || !strcmp(globals.dumpsect, "resource"))
1503             dump_dir_resource();
1504         if (all || !strcmp(globals.dumpsect, "tls"))
1505             dump_dir_tls();
1506         if (all || !strcmp(globals.dumpsect, "clr"))
1507             dump_dir_clr_header();
1508         if (all || !strcmp(globals.dumpsect, "reloc"))
1509             dump_dir_reloc();
1510         if (all || !strcmp(globals.dumpsect, "except"))
1511             dump_dir_exceptions();
1512     }
1513     if (globals.do_symbol_table)
1514         dump_symbol_table();
1515     if (globals.do_debug)
1516         dump_debug();
1517 }
1518
1519 typedef struct _dll_symbol {
1520     size_t      ordinal;
1521     char       *symbol;
1522 } dll_symbol;
1523
1524 static dll_symbol *dll_symbols = NULL;
1525 static dll_symbol *dll_current_symbol = NULL;
1526
1527 /* Compare symbols by ordinal for qsort */
1528 static int symbol_cmp(const void *left, const void *right)
1529 {
1530     return ((const dll_symbol *)left)->ordinal > ((const dll_symbol *)right)->ordinal;
1531 }
1532
1533 /*******************************************************************
1534  *         dll_close
1535  *
1536  * Free resources used by DLL
1537  */
1538 /* FIXME: Not used yet
1539 static void dll_close (void)
1540 {
1541     dll_symbol* ds;
1542
1543     if (!dll_symbols) {
1544         fatal("No symbols");
1545     }
1546     for (ds = dll_symbols; ds->symbol; ds++)
1547         free(ds->symbol);
1548     free (dll_symbols);
1549     dll_symbols = NULL;
1550 }
1551 */
1552
1553 static  void    do_grab_sym( void )
1554 {
1555     const IMAGE_EXPORT_DIRECTORY*exportDir;
1556     unsigned                    i, j;
1557     const DWORD*                pName;
1558     const DWORD*                pFunc;
1559     const WORD*                 pOrdl;
1560     const char*                 ptr;
1561     DWORD*                      map;
1562
1563     PE_nt_headers = get_nt_header();
1564     if (!(exportDir = get_dir(IMAGE_FILE_EXPORT_DIRECTORY))) return;
1565
1566     pName = RVA(exportDir->AddressOfNames, exportDir->NumberOfNames * sizeof(DWORD));
1567     if (!pName) {printf("Can't grab functions' name table\n"); return;}
1568     pOrdl = RVA(exportDir->AddressOfNameOrdinals, exportDir->NumberOfNames * sizeof(WORD));
1569     if (!pOrdl) {printf("Can't grab functions' ordinal table\n"); return;}
1570     pFunc = RVA(exportDir->AddressOfFunctions, exportDir->NumberOfFunctions * sizeof(DWORD));
1571     if (!pFunc) {printf("Can't grab functions' address table\n"); return;}
1572
1573     /* dll_close(); */
1574
1575     if (!(dll_symbols = malloc((exportDir->NumberOfFunctions + 1) * sizeof(dll_symbol))))
1576         fatal ("Out of memory");
1577
1578     /* bit map of used funcs */
1579     map = calloc(((exportDir->NumberOfFunctions + 31) & ~31) / 32, sizeof(DWORD));
1580     if (!map) fatal("no memory");
1581
1582     for (j = 0; j < exportDir->NumberOfNames; j++, pOrdl++)
1583     {
1584         map[*pOrdl / 32] |= 1 << (*pOrdl % 32);
1585         ptr = RVA(*pName++, sizeof(DWORD));
1586         if (!ptr) ptr = "cant_get_function";
1587         dll_symbols[j].symbol = strdup(ptr);
1588         dll_symbols[j].ordinal = exportDir->Base + *pOrdl;
1589         assert(dll_symbols[j].symbol);
1590     }
1591
1592     for (i = 0; i < exportDir->NumberOfFunctions; i++)
1593     {
1594         if (pFunc[i] && !(map[i / 32] & (1 << (i % 32))))
1595         {
1596             char ordinal_text[256];
1597             /* Ordinal only entry */
1598             snprintf (ordinal_text, sizeof(ordinal_text), "%s_%u",
1599                       globals.forward_dll ? globals.forward_dll : OUTPUT_UC_DLL_NAME,
1600                       exportDir->Base + i);
1601             str_toupper(ordinal_text);
1602             dll_symbols[j].symbol = strdup(ordinal_text);
1603             assert(dll_symbols[j].symbol);
1604             dll_symbols[j].ordinal = exportDir->Base + i;
1605             j++;
1606             assert(j <= exportDir->NumberOfFunctions);
1607         }
1608     }
1609     free(map);
1610
1611     if (NORMAL)
1612         printf("%u named symbols in DLL, %u total, %d unique (ordinal base = %d)\n",
1613                exportDir->NumberOfNames, exportDir->NumberOfFunctions, j, exportDir->Base);
1614
1615     qsort( dll_symbols, j, sizeof(dll_symbol), symbol_cmp );
1616
1617     dll_symbols[j].symbol = NULL;
1618
1619     dll_current_symbol = dll_symbols;
1620 }
1621
1622 /*******************************************************************
1623  *         dll_open
1624  *
1625  * Open a DLL and read in exported symbols
1626  */
1627 int dll_open (const char *dll_name)
1628 {
1629     return dump_analysis(dll_name, do_grab_sym, SIG_PE);
1630 }
1631
1632 /*******************************************************************
1633  *         dll_next_symbol
1634  *
1635  * Get next exported symbol from dll
1636  */
1637 int dll_next_symbol (parsed_symbol * sym)
1638 {
1639     if (!dll_current_symbol || !dll_current_symbol->symbol)
1640        return 1;
1641      assert (dll_symbols);
1642     sym->symbol = strdup (dll_current_symbol->symbol);
1643     sym->ordinal = dll_current_symbol->ordinal;
1644     dll_current_symbol++;
1645     return 0;
1646 }