Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
[cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' [cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); [cDAC] DAC like entry point by max-charlamb · Pull Request #112653 · dotnet/runtime · GitHub
Skip to content

[cDAC] DAC like entry point - #112653

Closed
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint
Closed

[cDAC] DAC like entry point#112653
max-charlamb wants to merge 8 commits into
dotnet:mainfrom
max-charlamb:cdac-entrypoint

Conversation

@max-charlamb

Copy link
Copy Markdown
Member

No description provided.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @tommcdon
See info in area-owners.md if you want to be subscribed.

Comment on lines +29 to +73
using BinaryReader reader = new(new DataTargetStream(_dataTarget, _baseAddress));

ushort dosMagic = reader.ReadUInt16();
if (dosMagic != 0x5A4D) // "MZ"
return false;

// PE Header offset is at 0x3C in DOS header
reader.BaseStream.Seek(0x3C, SeekOrigin.Begin);
_peSigOffset = reader.ReadUInt32();

// Read PE signature
reader.BaseStream.Seek(_peSigOffset, SeekOrigin.Begin);
uint peSig = reader.ReadUInt32();
if (peSig != 0x00004550) // "PE00"
return false;

// Seek to beginning of opt header and read magic
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
_optHeaderMagic = reader.ReadUInt16();

// Seek back to beginning of opt header and parse
reader.BaseStream.Seek(_peSigOffset + 0x18, SeekOrigin.Begin);
uint rva;
switch (_optHeaderMagic)
{
case 0x10B: // PE32
IMAGE_OPTIONAL_HEADER32 optHeader32 = new(reader);
rva = optHeader32.DataDirectory[0].VirtualAddress;
break;
case 0x20B: // PE32+
IMAGE_OPTIONAL_HEADER64 optHeader64 = new(reader);
rva = optHeader64.DataDirectory[0].VirtualAddress;
break;
// unknown type, invalid
default:
return false;
}

// Seek to export directory and parse
reader.BaseStream.Seek(rva, SeekOrigin.Begin);
_exportDir = new IMAGE_EXPORT_DIRECTORY(reader);

return true;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use System.Reflection.PortableExecutable.PEReader to get to the export directory here?

Something like the following:

usingStreamstream=newDataTargetStream(_dataTarget,_baseAddress);usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(newBinaryReader(stream));returntrue;

This would let you get out of most of the PE decoding.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I saw the PEReader and based some of the code off of it.

My concern is that the PEReader does not have the signature checking semantics I was looking for.

Because the DAC only targets a single platform, it invoked the exact reader for the executable format.

As far as I can tell, using the ICLRDataTarget, we don't know which platform we are targeting. Unless I'm overlooking something, my plan is to run the PEDecoder, ELFDecoder, and MACHODecoder on each target which will be verified using the known signatures.

It looks like the PEDecoder assumes that the PE is a COFF file if the PE DOS magic isn't correct. In this case, I'd want to bail.

privatestaticvoidSkipDosHeader(refPEBinaryReaderreader,outboolisCOFFOnly)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at it again, if the file parses as COFFOnly, the PEHeader won't be available.

I can check if it's valid using that.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unfortunately, the PEReader is not safe to use on non-PE/COFF files. Even if the signatures fail to parse, the PEHeaders.cs will attempt to use the garbage COFFHeader to read an arbitrary number of sections potentially causing stream overrun.

privateImmutableArray<SectionHeader>ReadSectionHeaders(refPEBinaryReaderreader)
{
intnumberOfSections=_coffHeader.NumberOfSections;
if(numberOfSections<0)
{
thrownewBadImageFormatException(SR.InvalidNumberOfSections);
}
varbuilder=ImmutableArray.CreateBuilder<SectionHeader>(numberOfSections);
for(inti=0;i<numberOfSections;i++)
{
builder.Add(newSectionHeader(refreader));
}
returnbuilder.MoveToImmutable();
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dang... Yeah that's not particularly helpful in this case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Opened #112830 to add this fail-fast capability to PEReader; this is not the first time it was desired. In the meantime you can do a minimal signature validation yourself and create the PEReader afterwards:

usingDataTargetStreamstream=new(_dataTarget,_baseAddress);usingBinaryReaderreader=new(stream,Encoding.UTF8,leaveOpen:true);ushortdosMagic=reader.ReadUInt16();if(dosMagic!=0x5A4D)// "MZ"returnfalse;// PE Header offset is at 0x3C in DOS headerreader.BaseStream.Seek(0x3C,SeekOrigin.Begin);uintpeSigOffset=reader.ReadUInt32();// Read PE signaturereader.BaseStream.Seek(peSigOffset,SeekOrigin.Begin);uintpeSig=reader.ReadUInt32();if(peSig!=0x00004550)// "PE00"returnfalse;usingPEReaderreader=new(stream);varexportsDirectory=reader.PEHeaders.PEHeader!.ExportTableDirectory;if(!reader.PEHeaders.TryGetDirectoryOffset(exportsDirectory,outvaroffset)){returnfalse;}stream.Seek(offset,SeekOrigin.Begin);_exportDir=newIMAGE_EXPORT_DIRECTORY(reader);returntrue;


public override long Position { get => _offset; set => _offset = value; }

public override unsafe int Read(byte[] buffer, int offset, int count)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should also override the Read overload that takes a span.

@max-charlamb

Copy link
Copy Markdown
MemberAuthor

Closing in favor of #113899

@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 25, 2025
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-Diagnostics-coreclrenhancementProduct code improvement that does NOT require public API changes/additions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@max-charlamb@jkoritzinsky@teo-tsirpanis@tommcdon