#pragma once // TODO: Including this adds a bunch of binary ninja specific stuff :ugh: #include "view/macho/machoview.h" struct CacheSymbol; // Used when reading symbol/string table info. struct TableInfo { // VM address where the reading will begin. uint64_t address; // Number of entries in the table. uint32_t entries; }; struct KernelCacheMachOHeader { uint64_t textBase = 0; uint64_t loadCommandOffset = 0; BinaryNinja::mach_header_64 ident; // NOTE: This should never be empty. std::string identifierPrefix; std::string installName; std::vector> entryPoints; std::vector m_entryPoints; // list of entrypoints BinaryNinja::symtab_command symtab; BinaryNinja::dysymtab_command dysymtab; BinaryNinja::dyld_info_command dyldInfo; BinaryNinja::routines_command_64 routines64; BinaryNinja::function_starts_command functionStarts; std::vector moduleInitSections; BinaryNinja::linkedit_data_command exportTrie; BinaryNinja::linkedit_data_command chainedFixups {}; uint64_t relocationBase; // Section and program headers, internally use 64-bit form as it is a superset of 32-bit std::vector segments; // only three types of sections __TEXT, __DATA, __IMPORT BinaryNinja::segment_command_64 linkeditSegment; std::vector sections; std::vector sectionNames; std::vector symbolStubSections; std::vector symbolPointerSections; std::vector dylibs; BinaryNinja::build_version_command buildVersion; std::vector buildToolVersions; std::string exportTriePath; bool linkeditPresent = false; bool dysymPresent = false; bool dyldInfoPresent = false; bool exportTriePresent = false; bool chainedFixupsPresent = false; bool routinesPresent = false; bool functionStartsPresent = false; bool relocatable = false; static std::optional ParseHeaderForAddress( BinaryNinja::Ref bv, uint64_t vmAddress, uint64_t fileAddress, const std::string& imagePath); std::vector ReadSymbolTable(BinaryNinja::Ref bv, const TableInfo &symbolInfo, const TableInfo &stringInfo) const; bool AddExportTerminalSymbol( std::vector& symbols, const std::string& symbolName, const uint8_t* current, const uint8_t* end) const; bool ProcessLinkEditTrie(std::vector& symbols, const std::string& currentText, const uint8_t* begin, const uint8_t* current, const uint8_t* end) const; std::vector ReadExportSymbolTrie(BinaryNinja::Ref bv) const; std::vector ReadFunctionTable(BinaryNinja::Ref bv) const; };