2009-03-29 07:30:54 +00:00
|
|
|
# This file is part of Metasm, the Ruby assembly manipulation suite
|
2010-09-09 18:19:35 +00:00
|
|
|
# Copyright (C) 2006-2009 Yoann GUILLOT
|
2009-03-29 07:30:54 +00:00
|
|
|
#
|
|
|
|
# Licence is LGPL, see LICENCE in the top-level directory
|
|
|
|
|
|
|
|
#
|
|
|
|
# this exemple illustrates the use of the cparser/preprocessor #factorize functionnality:
|
2010-09-09 18:19:35 +00:00
|
|
|
# it generates code that references to the functions imported by a windows executable
|
|
|
|
# usage: factorize-imports.rb <exe> <exe2> <path to visual studio installation> [<additional func names>... ^<func to exclude>]
|
2009-03-29 07:30:54 +00:00
|
|
|
#
|
|
|
|
|
|
|
|
require 'metasm'
|
|
|
|
include Metasm
|
|
|
|
|
|
|
|
require 'optparse'
|
2010-09-09 18:19:35 +00:00
|
|
|
opts = { :hdrs => [], :defs => {}, :path => [], :exe => [] }
|
2009-03-29 07:30:54 +00:00
|
|
|
OptionParser.new { |opt|
|
|
|
|
opt.on('-o outfile') { |f| opts[:outfile] = f }
|
2010-09-09 18:19:35 +00:00
|
|
|
opt.on('-H additional_header') { |f| opts[:hdrs] << f }
|
|
|
|
opt.on('-e exe', '--exe executable') { |f| opts[:exe] << f }
|
|
|
|
opt.on('-I path', '--includepath path') { |f| opts[:path] << f }
|
|
|
|
opt.on('-D var') { |f| k, v = f.split('=', 2) ; opts[:defs].update k => (v || '') }
|
|
|
|
opt.on('--ddk') { opts[:ddk] = true }
|
|
|
|
opt.on('--vspath path') { |f| opts[:vspath] = f }
|
2009-03-29 07:30:54 +00:00
|
|
|
}.parse!(ARGV)
|
|
|
|
|
2010-09-09 18:19:35 +00:00
|
|
|
ARGV.delete_if { |e|
|
|
|
|
next if not File.file? e
|
|
|
|
opts[:exe] << e
|
|
|
|
}
|
2009-03-29 07:30:54 +00:00
|
|
|
|
2010-09-09 18:19:35 +00:00
|
|
|
if opts[:vspath] ||= ARGV.shift
|
|
|
|
opts[:vspath] = opts[:vspath].tr('\\', '/')
|
|
|
|
opts[:vspath] = opts[:vspath].chop if opts[:vspath][-1] == ?/
|
|
|
|
if opts[:ddk]
|
|
|
|
opts[:path] << (opts[:vspath]+'/ddk') << (opts[:vspath]+'/api') << (opts[:vspath]+'/crt')
|
|
|
|
else
|
|
|
|
opts[:vspath] = opts[:vspath][0...-3] if opts[:vspath][-3..-1] == '/VC'
|
|
|
|
opts[:path] << (opts[:vspath]+'/VC/platformsdk/include') << (opts[:vspath]+'/VC/include')
|
|
|
|
end
|
|
|
|
end
|
2009-03-29 07:30:54 +00:00
|
|
|
|
2010-09-09 18:19:35 +00:00
|
|
|
funcnames = opts[:exe].map { |e|
|
2011-07-19 05:50:17 +00:00
|
|
|
pe = PE.decode_file_header(e) rescue nil
|
|
|
|
|
|
|
|
pe.decode_imports if pe
|
|
|
|
if pe and not pe.imports
|
2010-09-09 18:19:35 +00:00
|
|
|
puts "#{e} has no imports"
|
|
|
|
next
|
|
|
|
end
|
2011-07-19 05:50:17 +00:00
|
|
|
if pe
|
|
|
|
pe.imports.map { |id| id.imports.map { |i| i.name } }
|
|
|
|
else
|
|
|
|
[]
|
|
|
|
end
|
2010-09-09 18:19:35 +00:00
|
|
|
}.flatten.compact.uniq.sort
|
2009-03-29 07:30:54 +00:00
|
|
|
|
|
|
|
ARGV.each { |n|
|
2010-09-09 18:19:35 +00:00
|
|
|
if n[0] == ?! or n[0] == ?- or n[0] == ?^
|
2009-03-29 07:30:54 +00:00
|
|
|
funcnames.delete n[1..-1]
|
|
|
|
else
|
|
|
|
funcnames |= [n]
|
|
|
|
end
|
|
|
|
}
|
2010-09-09 18:19:35 +00:00
|
|
|
exit if funcnames.empty?
|
2009-03-29 07:30:54 +00:00
|
|
|
|
2010-09-09 18:19:35 +00:00
|
|
|
src = <<EOS + opts[:hdrs].to_a.map { |h| "#include <#{h}>\n" }.join
|
|
|
|
#ifdef DDK
|
2009-03-29 07:30:54 +00:00
|
|
|
#define NO_INTERLOCKED_INTRINSICS
|
|
|
|
typedef struct _CONTEXT CONTEXT; // needed by ntddk.h, but this will pollute the factorized output..
|
|
|
|
typedef CONTEXT *PCONTEXT;
|
|
|
|
#define dllimport stdcall // wtff
|
2010-09-09 18:19:35 +00:00
|
|
|
#define SORTPP_PASS // C_ASSERT proprocessor assert..
|
|
|
|
#define _MSC_EXTENSIONS // __volatile stuff
|
2009-03-29 07:30:54 +00:00
|
|
|
#include <ntddk.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
#else
|
|
|
|
#define WIN32_LEAN_AND_MEAN
|
|
|
|
#include <windows.h>
|
|
|
|
#include <winternl.h>
|
|
|
|
#endif
|
|
|
|
EOS
|
|
|
|
|
|
|
|
parser = Ia32.new.new_cparser
|
2010-09-09 18:19:35 +00:00
|
|
|
parser.prepare_visualstudio
|
|
|
|
pp = parser.lexer
|
|
|
|
pp.warn_redefinition = false
|
|
|
|
pp.define('_WIN32_WINNT', '0x0600')
|
|
|
|
pp.define('DDK') if opts[:ddk]
|
|
|
|
pp.define_strong('IN', '__attribute__((in))')
|
|
|
|
pp.define_strong('__in', '__attribute__((in))')
|
|
|
|
pp.define_strong('OUT', '__attribute__((out))')
|
|
|
|
pp.define_strong('__out', '__attribute__((out))')
|
|
|
|
pp.include_search_path = opts[:path]
|
|
|
|
opts[:defs].each { |k, v| pp.define k, v }
|
2009-03-29 07:30:54 +00:00
|
|
|
parser.factorize_init
|
|
|
|
parser.parse src
|
|
|
|
|
2010-09-09 18:19:35 +00:00
|
|
|
|
|
|
|
outfd = (opts[:outfile] ? File.open(opts[:outfile], 'w') : $stdout)
|
|
|
|
|
2009-03-29 07:30:54 +00:00
|
|
|
# delete imports not present in the header files
|
|
|
|
funcnames.delete_if { |f|
|
|
|
|
if not parser.toplevel.symbol[f]
|
|
|
|
puts "// #{f.inspect} is not defined in the headers"
|
2010-09-09 18:19:35 +00:00
|
|
|
outfd.puts "// #{f.inspect} is not defined in the headers" if opts[:outfile]
|
2009-03-29 07:30:54 +00:00
|
|
|
true
|
|
|
|
end
|
|
|
|
}
|
|
|
|
|
2010-09-09 18:19:35 +00:00
|
|
|
parser.parse "void *fnptr[] = { #{funcnames.map { |f| '&'+f }.join(', ')} };"
|
2009-03-29 07:30:54 +00:00
|
|
|
|
|
|
|
outfd.puts parser.factorize_final
|
|
|
|
outfd.close
|