diff options
| author | Josh Ferrell <josh@vector35.com> | 2026-04-22 11:31:37 -0400 |
|---|---|---|
| committer | Josh Ferrell <josh@vector35.com> | 2026-04-22 15:46:57 -0400 |
| commit | 4bba210293dc020fbd8ef84f9f1b91676a4c7432 (patch) | |
| tree | 22ff94563babcde476c7552620f509fde1fb390f /view/pe | |
| parent | f93512c43333814a849ea742ad7177811e6720d7 (diff) | |
[PE] Do not create symbols for debugging metadata symbol entries
Diffstat (limited to 'view/pe')
| -rw-r--r-- | view/pe/peview.cpp | 85 |
1 files changed, 65 insertions, 20 deletions
diff --git a/view/pe/peview.cpp b/view/pe/peview.cpp index af8350ca..718822ba 100644 --- a/view/pe/peview.cpp +++ b/view/pe/peview.cpp @@ -1348,7 +1348,7 @@ bool PEView::Init() } vector<pair<BNRelocationInfo, string>> relocs; - + BulkSymbolModification bulkSymbolModification(this); m_symbolQueue = new SymbolQueue(); m_symExternMappingMetadata = new Metadata(KeyValueDataType); @@ -1426,34 +1426,79 @@ bool PEView::Init() // + m_imageBase, e_scnum, e_value); uint8_t baseType = (e_type >> 4) & 0x3; - switch (baseType) + + bool createSymbol = true; + + // Some records are just providing debugging information and we should ignore them + // TODO: can we recover any useful information from the aux records? + // See https://learn.microsoft.com/en-us/windows/win32/debug/pe-format#auxiliary-symbol-records for info provided by aux records + if (e_sclass == IMAGE_SYM_CLASS_EXTERNAL && baseType == IMAGE_SYM_DTYPE_FUNCTION) { - case IMAGE_SYM_DTYPE_NULL: // no derived type - { - if (virtualAddress) - AddPESymbol(DataSymbol, "", symbolName, virtualAddress, binding); - break; - } - case IMAGE_SYM_DTYPE_POINTER: // pointer to base type + // Auxiliary Format 1: Function Definitions + } + else if (e_sclass == IMAGE_SYM_CLASS_FUNCTION) + { + if (symbolName == ".bf" || symbolName == ".ef") { - break; + // Auxiliary Format 2: .bf and .ef Symbols + // This entry is providing information about a function's line numbers and should not have a symbol created + createSymbol = false; } - case IMAGE_SYM_DTYPE_FUNCTION: // function that returns base type + else if (symbolName == ".lf") { - //LogError("%x StorageClass:%u Type:%x NumAux:%x COFF_DT_FCN at %x section:%x %s ", header.coffSymbolTable + (i * 18), e_sclass, e_type, e_numaux, virtualAddress + m_imageBase, e_scnum, symbolName.c_str()); - if (virtualAddress) - AddPESymbol(FunctionSymbol, "", symbolName, virtualAddress, binding); - break; + // This entry is providing information about a function's line numbers and should not have a symbol created + createSymbol = false; } - case IMAGE_SYM_DTYPE_ARRAY: // array of base type + } + else if (e_sclass == IMAGE_SYM_CLASS_EXTERNAL && e_scnum == IMAGE_SYM_UNDEFINED && e_value == 0) + { + // Auxiliary Format 3: Weak Externals + } + else if (e_sclass == IMAGE_SYM_CLASS_FILE && symbolName == ".file") + { + // Auxiliary Format 4: Files + // This entry is providing information about a source file and should not have a symbol created + createSymbol = false; + } + else if (e_sclass == IMAGE_SYM_CLASS_STATIC && + find_if(m_sections.begin(), m_sections.end(), [&symbolName](const PESection& section) { return section.name == symbolName; }) != m_sections.end()) + { + // Auxiliary Format 5: Section Definitions + // This entry is providing information about a section and should not have a symbol created + createSymbol = false; + } + + if (createSymbol) + { + switch (baseType) { - break; + case IMAGE_SYM_DTYPE_NULL: // no derived type + { + if (virtualAddress) + AddPESymbol(DataSymbol, "", symbolName, virtualAddress, binding); + break; + } + case IMAGE_SYM_DTYPE_POINTER: // pointer to base type + { + break; + } + case IMAGE_SYM_DTYPE_FUNCTION: // function that returns base type + { + //LogError("%x StorageClass:%u Type:%x NumAux:%x COFF_DT_FCN at %x section:%x %s ", header.coffSymbolTable + (i * 18), e_sclass, e_type, e_numaux, virtualAddress + m_imageBase, e_scnum, symbolName.c_str()); + if (virtualAddress) + AddPESymbol(FunctionSymbol, "", symbolName, virtualAddress, binding); + break; + } + case IMAGE_SYM_DTYPE_ARRAY: // array of base type + { + break; + } + default: + break; } - default: - break; } - // TODO handle auxiliary entries + // Skip over auxiliary entries i += e_numaux; } } |
