Problem in parsing 2 files
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 32/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- cpp
Línea de trabajo
Comienza reproduciendo los fallos con el pe-parse.zip adjunto y sigue ParsePEFromPointer, getDebugDir e IterRsrc para System.Text.Json.dll y ConfKarat.exe. Compara los datos de recursos proporcionados al callback con el recurso de versión visible en los archivos; se considera completado cuando ambos ejecutables se analizan sin el fallo indicado y el recurso de versión esperado se expone correctamente.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Thanks for the great project! I'm trying to use it for reading versions from executables.
I've built it with Qt Creator, gcc, qbs (see my .qbs and .cpp files in the archive): pe-parse.zip
Most EXE and DLL files I've tried were parsed fine but two of them failed:
- System.Text.Json.dll - getDebugDir fails. Since this file has an Authenticode signature of .NET project, it's unlikely that the file is currupt.
- ConfKarat.exe - incorrect version resource is passed to IterRsrc callback. Windows explorer file properties box shows the version. I can also see the version in a hex editor. But res.buf->buf in my code doesn't point to anything containing VS_VERSION_INFO and 0xfeef04bd signature.
Here is my code:
struct MY_VS_FIXEDFILEINFO
{
quint32 dwSignature;
quint32 dwStrucVersion;
quint32 dwFileVersionMS;
quint32 dwFileVersionLS;
quint32 dwProductVersionMS;
quint32 dwProductVersionLS;
quint32 dwFileFlagsMask;
quint32 dwFileFlags;
quint32 dwFileOS;
quint32 dwFileType;
quint32 dwFileSubtype;
quint32 dwFileDateMS;
quint32 dwFileDateLS;
};
int extractVersionFromResourceCallback(void* ptr, const peparse::resource& res)
{
// Skip all resource types execpt RT_VERSION
if(res.type != 16) return 0;
// Find VS_FIXEDFILEINFO in the buffer
auto structSize = sizeof(MY_VS_FIXEDFILEINFO);
for(size_t offset = 0; offset + structSize <= res.size; offset += 4)
{
auto verInfo = (const MY_VS_FIXEDFILEINFO*)(res.buf->buf + offset);
if (verInfo->dwSignature == 0xfeef04bd)
{
QString& result = *(QString*)ptr;
result = QStringLiteral("%1.%2.%3.%4")
.arg(( verInfo->dwFileVersionMS >> 16 ) & 0xffff)
.arg(( verInfo->dwFileVersionMS >> 0 ) & 0xffff)
.arg(( verInfo->dwFileVersionLS >> 16 ) & 0xffff)
.arg(( verInfo->dwFileVersionLS >> 0 ) & 0xffff);
return 1;
}
}
// Maybe there's another version resource we'll understand
return 0;
}
...
// Have to use mutex because pe-parse library uses globals
static QMutex peparseMutex;
QMutexLocker locker(&peparseMutex);
// Try to parse PE
auto peptr = peparse::ParsePEFromPointer((std::uint8_t*)m_data.data(), m_data.size());
if (peptr == nullptr)
{
qWarning() << "Failed to parse PE. Code:" << peparse::GetPEErr() << endl
<< "Error:" << QString::fromStdString(peparse::GetPEErrString()) << endl
<< "Location:" << QString::fromStdString(peparse::GetPEErrLoc());
return QString();
}
// Make sure we cleanup properly
try
{
// Iterate resources
QString result;
peparse::IterRsrc(peptr, extractVersionFromResourceCallback, &result);
DestructParsedPE(peptr);
return result;
}
catch (...)
{
DestructParsedPE(peptr);
throw;
}
- Lenguaje dominante
- C++
- Estrellas
- 913
- Forks
- 171
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de trailofbits/pe-parse
-
failed to install pype with pipAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
trailofbits/pe-parse#216 ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
trailofbits/pe-parse#207 ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
trailofbits/pe-parse#201 ·
-
enhancement help wanted
Dificultad 3/5 1-2 días Aptitud para principiantes 45/100
trailofbits/pe-parse#188 · 1 comentario ·
-
RIIRAbiertodiscussion
Dificultad 5/5 Más de una semana Aptitud para principiantes 18/100
trailofbits/pe-parse#186 · 4 comentarios · 1 reacción ·
Todos los issues de trailofbits/pe-parse
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 72/100
lxqt/qtermwidget#688 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
cpinitiative/usaco-guide#6665 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
mpfaffenberger/privateer_reimagined#658 ·
Los mantenedores suelen responder en 1 día
-
Broken links in the docsAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
microsoft/onnxruntime#33018 ·
Los mantenedores suelen responder en 2 días
-
Type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 2 días