From 768f7c78465fb93936e5ca50a0ca712664fe54e7 Mon Sep 17 00:00:00 2001 From: kat Date: Sun, 6 Jul 2025 15:05:01 -0400 Subject: KernelCache rewrite --- view/kernelcache/core/MachO.h | 79 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 79 insertions(+) create mode 100644 view/kernelcache/core/MachO.h (limited to 'view/kernelcache/core/MachO.h') diff --git a/view/kernelcache/core/MachO.h b/view/kernelcache/core/MachO.h new file mode 100644 index 00000000..8c2a7709 --- /dev/null +++ b/view/kernelcache/core/MachO.h @@ -0,0 +1,79 @@ +#pragma once + +// TODO: Including this adds a bunch of binary ninja specific stuff :ugh: +#include "view/macho/machoview.h" + +struct CacheSymbol; + +// Used when reading symbol/string table info. +struct TableInfo +{ + // VM address where the reading will begin. + uint64_t address; + // Number of entries in the table. + uint32_t entries; +}; + +struct KernelCacheMachOHeader +{ + uint64_t textBase = 0; + uint64_t loadCommandOffset = 0; + BinaryNinja::mach_header_64 ident; + // NOTE: This should never be empty. + std::string identifierPrefix; + std::string installName; + + std::vector> entryPoints; + std::vector m_entryPoints; // list of entrypoints + + BinaryNinja::symtab_command symtab; + BinaryNinja::dysymtab_command dysymtab; + BinaryNinja::dyld_info_command dyldInfo; + BinaryNinja::routines_command_64 routines64; + BinaryNinja::function_starts_command functionStarts; + std::vector moduleInitSections; + BinaryNinja::linkedit_data_command exportTrie; + BinaryNinja::linkedit_data_command chainedFixups {}; + + uint64_t relocationBase; + // Section and program headers, internally use 64-bit form as it is a superset of 32-bit + std::vector segments; // only three types of sections __TEXT, __DATA, __IMPORT + BinaryNinja::segment_command_64 linkeditSegment; + std::vector sections; + std::vector sectionNames; + + std::vector symbolStubSections; + std::vector symbolPointerSections; + + std::vector dylibs; + + BinaryNinja::build_version_command buildVersion; + std::vector buildToolVersions; + + std::string exportTriePath; + + bool linkeditPresent = false; + bool dysymPresent = false; + bool dyldInfoPresent = false; + bool exportTriePresent = false; + bool chainedFixupsPresent = false; + bool routinesPresent = false; + bool functionStartsPresent = false; + bool relocatable = false; + + static std::optional ParseHeaderForAddress( + BinaryNinja::Ref bv, uint64_t vmAddress, uint64_t fileAddress, const std::string& imagePath); + + std::vector ReadSymbolTable(BinaryNinja::Ref bv, const TableInfo &symbolInfo, const TableInfo &stringInfo) const; + + bool AddExportTerminalSymbol( + std::vector& symbols, const std::string& symbolName, const uint8_t* current, + const uint8_t* end) const; + + bool ProcessLinkEditTrie(std::vector& symbols, const std::string& currentText, const uint8_t* begin, + const uint8_t* current, const uint8_t* end) const; + + std::vector ReadExportSymbolTrie(BinaryNinja::Ref bv) const; + + std::vector ReadFunctionTable(BinaryNinja::Ref bv) const; +}; -- cgit v1.3.1