xref: /llvm-project/llvm/lib/BinaryFormat/Magic.cpp (revision 3062a1469da0569e714aa4634b29345f6d8c874c)
1 //===- llvm/BinaryFormat/Magic.cpp - File magic identification --*- C++ -*-===//
2 //
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6 //
7 //===----------------------------------------------------------------------===//
8 
9 #include "llvm/BinaryFormat/Magic.h"
10 #include "llvm/ADT/StringRef.h"
11 #include "llvm/ADT/Twine.h"
12 #include "llvm/BinaryFormat/COFF.h"
13 #include "llvm/BinaryFormat/ELF.h"
14 #include "llvm/BinaryFormat/MachO.h"
15 #include "llvm/Support/Endian.h"
16 #include "llvm/Support/FileSystem.h"
17 #include "llvm/Support/MemoryBuffer.h"
18 
19 #if !defined(_MSC_VER) && !defined(__MINGW32__)
20 #include <unistd.h>
21 #else
22 #include <io.h>
23 #endif
24 
25 using namespace llvm;
26 using namespace llvm::support::endian;
27 using namespace llvm::sys::fs;
28 
29 template <size_t N>
30 static bool startswith(StringRef Magic, const char (&S)[N]) {
31   return Magic.startswith(StringRef(S, N - 1));
32 }
33 
34 /// Identify the magic in magic.
35 file_magic llvm::identify_magic(StringRef Magic) {
36   if (Magic.size() < 4)
37     return file_magic::unknown;
38   switch ((unsigned char)Magic[0]) {
39   case 0x00: {
40     // COFF bigobj, CL.exe's LTO object file, or short import library file
41     if (startswith(Magic, "\0\0\xFF\xFF")) {
42       size_t MinSize =
43           offsetof(COFF::BigObjHeader, UUID) + sizeof(COFF::BigObjMagic);
44       if (Magic.size() < MinSize)
45         return file_magic::coff_import_library;
46 
47       const char *Start = Magic.data() + offsetof(COFF::BigObjHeader, UUID);
48       if (memcmp(Start, COFF::BigObjMagic, sizeof(COFF::BigObjMagic)) == 0)
49         return file_magic::coff_object;
50       if (memcmp(Start, COFF::ClGlObjMagic, sizeof(COFF::BigObjMagic)) == 0)
51         return file_magic::coff_cl_gl_object;
52       return file_magic::coff_import_library;
53     }
54     // Windows resource file
55     if (Magic.size() >= sizeof(COFF::WinResMagic) &&
56         memcmp(Magic.data(), COFF::WinResMagic, sizeof(COFF::WinResMagic)) == 0)
57       return file_magic::windows_resource;
58     // 0x0000 = COFF unknown machine type
59     if (Magic[1] == 0)
60       return file_magic::coff_object;
61     if (startswith(Magic, "\0asm"))
62       return file_magic::wasm_object;
63     break;
64   }
65 
66   case 0x01:
67     // XCOFF format
68     if (startswith(Magic, "\x01\xDF"))
69       return file_magic::xcoff_object_32;
70     if (startswith(Magic, "\x01\xF7"))
71       return file_magic::xcoff_object_64;
72     break;
73 
74   case 0x03:
75     if (startswith(Magic, "\x03\xF0\x00"))
76       return file_magic::goff_object;
77     break;
78 
79   case 0xDE: // 0x0B17C0DE = BC wraper
80     if (startswith(Magic, "\xDE\xC0\x17\x0B"))
81       return file_magic::bitcode;
82     break;
83   case 'B':
84     if (startswith(Magic, "BC\xC0\xDE"))
85       return file_magic::bitcode;
86     break;
87   case '!':
88     if (startswith(Magic, "!<arch>\n") || startswith(Magic, "!<thin>\n"))
89       return file_magic::archive;
90     break;
91   case '<':
92     if (startswith(Magic, "<bigaf>\n"))
93       return file_magic::archive;
94     break;
95   case '\177':
96     if (startswith(Magic, "\177ELF") && Magic.size() >= 18) {
97       bool Data2MSB = Magic[5] == 2;
98       unsigned high = Data2MSB ? 16 : 17;
99       unsigned low = Data2MSB ? 17 : 16;
100       if (Magic[high] == 0) {
101         switch (Magic[low]) {
102         default:
103           return file_magic::elf;
104         case 1:
105           return file_magic::elf_relocatable;
106         case 2:
107           return file_magic::elf_executable;
108         case 3:
109           return file_magic::elf_shared_object;
110         case 4:
111           return file_magic::elf_core;
112         }
113       }
114       // It's still some type of ELF file.
115       return file_magic::elf;
116     }
117     break;
118 
119   case 0xCA:
120     if (startswith(Magic, "\xCA\xFE\xBA\xBE") ||
121         startswith(Magic, "\xCA\xFE\xBA\xBF")) {
122       // This is complicated by an overlap with Java class files.
123       // See the Mach-O section in /usr/share/file/magic for details.
124       if (Magic.size() >= 8 && Magic[7] < 43)
125         return file_magic::macho_universal_binary;
126     }
127     break;
128 
129   // The two magic numbers for mach-o are:
130   // 0xfeedface - 32-bit mach-o
131   // 0xfeedfacf - 64-bit mach-o
132   case 0xFE:
133   case 0xCE:
134   case 0xCF: {
135     uint16_t type = 0;
136     if (startswith(Magic, "\xFE\xED\xFA\xCE") ||
137         startswith(Magic, "\xFE\xED\xFA\xCF")) {
138       /* Native endian */
139       size_t MinSize;
140       if (Magic[3] == char(0xCE))
141         MinSize = sizeof(MachO::mach_header);
142       else
143         MinSize = sizeof(MachO::mach_header_64);
144       if (Magic.size() >= MinSize)
145         type = Magic[12] << 24 | Magic[13] << 12 | Magic[14] << 8 | Magic[15];
146     } else if (startswith(Magic, "\xCE\xFA\xED\xFE") ||
147                startswith(Magic, "\xCF\xFA\xED\xFE")) {
148       /* Reverse endian */
149       size_t MinSize;
150       if (Magic[0] == char(0xCE))
151         MinSize = sizeof(MachO::mach_header);
152       else
153         MinSize = sizeof(MachO::mach_header_64);
154       if (Magic.size() >= MinSize)
155         type = Magic[15] << 24 | Magic[14] << 12 | Magic[13] << 8 | Magic[12];
156     }
157     switch (type) {
158     default:
159       break;
160     case 1:
161       return file_magic::macho_object;
162     case 2:
163       return file_magic::macho_executable;
164     case 3:
165       return file_magic::macho_fixed_virtual_memory_shared_lib;
166     case 4:
167       return file_magic::macho_core;
168     case 5:
169       return file_magic::macho_preload_executable;
170     case 6:
171       return file_magic::macho_dynamically_linked_shared_lib;
172     case 7:
173       return file_magic::macho_dynamic_linker;
174     case 8:
175       return file_magic::macho_bundle;
176     case 9:
177       return file_magic::macho_dynamically_linked_shared_lib_stub;
178     case 10:
179       return file_magic::macho_dsym_companion;
180     case 11:
181       return file_magic::macho_kext_bundle;
182     }
183     break;
184   }
185   case 0xF0: // PowerPC Windows
186   case 0x83: // Alpha 32-bit
187   case 0x84: // Alpha 64-bit
188   case 0x66: // MPS R4000 Windows
189   case 0x50: // mc68K
190   case 0x4c: // 80386 Windows
191   case 0xc4: // ARMNT Windows
192     if (Magic[1] == 0x01)
193       return file_magic::coff_object;
194     LLVM_FALLTHROUGH;
195 
196   case 0x90: // PA-RISC Windows
197   case 0x68: // mc68K Windows
198     if (Magic[1] == 0x02)
199       return file_magic::coff_object;
200     break;
201 
202   case 'M': // Possible MS-DOS stub on Windows PE file, MSF/PDB file or a
203             // Minidump file.
204     if (startswith(Magic, "MZ") && Magic.size() >= 0x3c + 4) {
205       uint32_t off = read32le(Magic.data() + 0x3c);
206       // PE/COFF file, either EXE or DLL.
207       if (Magic.substr(off).startswith(
208               StringRef(COFF::PEMagic, sizeof(COFF::PEMagic))))
209         return file_magic::pecoff_executable;
210     }
211     if (Magic.startswith("Microsoft C/C++ MSF 7.00\r\n"))
212       return file_magic::pdb;
213     if (startswith(Magic, "MDMP"))
214       return file_magic::minidump;
215     break;
216 
217   case 0x64: // x86-64 or ARM64 Windows.
218     if (Magic[1] == char(0x86) || Magic[1] == char(0xaa))
219       return file_magic::coff_object;
220     break;
221 
222   case 0x2d: // YAML '-'
223     if (startswith(Magic, "--- !tapi") || startswith(Magic, "---\narchs:"))
224       return file_magic::tapi_file;
225     break;
226 
227   default:
228     break;
229   }
230   return file_magic::unknown;
231 }
232 
233 std::error_code llvm::identify_magic(const Twine &Path, file_magic &Result) {
234   auto FileOrError = MemoryBuffer::getFile(Path, /*IsText=*/false,
235                                            /*RequiresNullTerminator=*/false);
236   if (!FileOrError)
237     return FileOrError.getError();
238 
239   std::unique_ptr<MemoryBuffer> FileBuffer = std::move(*FileOrError);
240   Result = identify_magic(FileBuffer->getBuffer());
241 
242   return std::error_code();
243 }
244