00001
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
#include "ntrtlp.h"
00024
00025
00026
00027
00028
00029
00030 #define SWAP_SHORT(_dst,_src) \
00031
((((unsigned char *)_dst)[1] = ((unsigned char *)_src)[0]), \
00032
(((unsigned char *)_dst)[0] = ((unsigned char *)_src)[1]))
00033
00034 #define SWAP_INT(_dst,_src) \
00035
((((unsigned char *)_dst)[3] = ((unsigned char *)_src)[0]), \
00036
(((unsigned char *)_dst)[2] = ((unsigned char *)_src)[1]), \
00037
(((unsigned char *)_dst)[1] = ((unsigned char *)_src)[2]), \
00038
(((unsigned char *)_dst)[0] = ((unsigned char *)_src)[3]))
00039
00040 #define SWAP_LONG_LONG(_dst,_src) \
00041
((((unsigned char *)_dst)[7] = ((unsigned char *)_src)[0]), \
00042
(((unsigned char *)_dst)[6] = ((unsigned char *)_src)[1]), \
00043
(((unsigned char *)_dst)[5] = ((unsigned char *)_src)[2]), \
00044
(((unsigned char *)_dst)[4] = ((unsigned char *)_src)[3]), \
00045
(((unsigned char *)_dst)[3] = ((unsigned char *)_src)[4]), \
00046
(((unsigned char *)_dst)[2] = ((unsigned char *)_src)[5]), \
00047
(((unsigned char *)_dst)[1] = ((unsigned char *)_src)[6]), \
00048
(((unsigned char *)_dst)[0] = ((unsigned char *)_src)[7]))
00049
00050
00051
00052
00053 #define LDRP_RELOCATION_INCREMENT 0x1
00054
00055
00056
00057
00058 #define LDRP_RELOCATION_FINAL 0x2
00059
00060
#if defined(NTOS_KERNEL_RUNTIME)
00061
#if defined(ALLOC_PRAGMA)
00062
00063 ULONG
00064
LdrDoubleRelocateImage (
00065 IN PVOID NewBase,
00066 IN PVOID CurrentBase,
00067 IN PUCHAR LoaderName,
00068 IN ULONG Success,
00069 IN ULONG Conflict,
00070 IN ULONG Invalid
00071 );
00072
00073 PIMAGE_BASE_RELOCATION
00074 LdrpProcessVolatileRelocationBlock(
00075 IN ULONG_PTR VA,
00076 IN ULONG SizeOfBlock,
00077 IN PUSHORT NextOffset,
00078 IN LONG_PTR Diff,
00079 IN LONG_PTR OldDiff,
00080 IN ULONG_PTR OldBase
00081 );
00082
00083
#pragma alloc_text(PAGE,LdrRelocateImage)
00084
#pragma alloc_text(PAGE,LdrProcessRelocationBlock)
00085
#pragma alloc_text(INIT,LdrDoubleRelocateImage)
00086
#pragma alloc_text(INIT,LdrpProcessVolatileRelocationBlock)
00087
#endif
00088
#endif
00089
00090 ULONG
00091 LdrRelocateImage (
00092 IN PVOID NewBase,
00093 IN PUCHAR LoaderName,
00094 IN ULONG Success,
00095 IN ULONG Conflict,
00096 IN ULONG Invalid
00097 )
00098
00099
00100
00101
00102
00103
00104
00105
00106
00107
00108
00109
00110
00111
00112
00113
00114
00115
00116
00117
00118
00119
00120
00121
00122
00123
00124
00125
00126 {
00127 LONG_PTR Diff;
00128 ULONG TotalCountBytes;
00129 ULONG_PTR VA;
00130 ULONG_PTR OldBase;
00131 ULONG SizeOfBlock;
00132 PUCHAR FixupVA;
00133
USHORT Offset;
00134
PUSHORT NextOffset;
00135 PIMAGE_NT_HEADERS NtHeaders;
00136 PIMAGE_BASE_RELOCATION NextBlock;
00137
00138
RTL_PAGED_CODE();
00139
00140 NtHeaders =
RtlImageNtHeader( NewBase );
00141
if ( NtHeaders ) {
00142 OldBase = NtHeaders->OptionalHeader.ImageBase;
00143 }
00144
else {
00145
return Invalid;
00146 }
00147
00148
00149
00150
00151
00152 NextBlock = (PIMAGE_BASE_RELOCATION)
RtlImageDirectoryEntryToData(
00153 NewBase,
TRUE, IMAGE_DIRECTORY_ENTRY_BASERELOC, &TotalCountBytes);
00154
00155
if (!NextBlock || !TotalCountBytes) {
00156
00157
00158
00159
00160
00161
#if DBG
00162
DbgPrint(
"%s: Image can't be relocated, no fixup information.\n", LoaderName);
00163
#endif // DBG
00164
return Conflict;
00165 }
00166
00167
00168
00169
00170
00171
00172
while (TotalCountBytes) {
00173 SizeOfBlock = NextBlock->SizeOfBlock;
00174 TotalCountBytes -= SizeOfBlock;
00175 SizeOfBlock -=
sizeof(IMAGE_BASE_RELOCATION);
00176 SizeOfBlock /=
sizeof(
USHORT);
00177 NextOffset = (
PUSHORT)((PCHAR)NextBlock +
sizeof(IMAGE_BASE_RELOCATION));
00178
00179 VA = (ULONG_PTR)NewBase + NextBlock->VirtualAddress;
00180 Diff = (PCHAR)NewBase - (PCHAR)OldBase;
00181
00182
if ( !(NextBlock =
LdrProcessRelocationBlock(VA,SizeOfBlock,NextOffset,Diff)) ) {
00183
#if DBG
00184
DbgPrint(
"%s: Unknown base relocation type\n", LoaderName);
00185
#endif
00186
return Invalid;
00187 }
00188 }
00189
00190
return Success;
00191 }
00192
00193 PIMAGE_BASE_RELOCATION
00194 LdrProcessRelocationBlock(
00195 IN ULONG_PTR VA,
00196 IN ULONG SizeOfBlock,
00197 IN PUSHORT NextOffset,
00198 IN LONG_PTR Diff
00199 )
00200 {
00201 PUCHAR FixupVA;
00202
USHORT Offset;
00203 LONG Temp;
00204 LONG TempOrig;
00205 ULONG Temp32;
00206 ULONGLONG Value64;
00207 LONGLONG Temp64;
00208 LONG_PTR ActualDiff;
00209
00210
RTL_PAGED_CODE();
00211
00212
while (SizeOfBlock--) {
00213
00214
Offset = *NextOffset & (
USHORT)0xfff;
00215 FixupVA = (PUCHAR)(VA +
Offset);
00216
00217
00218
00219
00220
00221
switch ((*NextOffset) >> 12) {
00222
00223
case IMAGE_REL_BASED_HIGHLOW :
00224
00225
00226
00227
00228 *(LONG UNALIGNED *)FixupVA += (ULONG) Diff;
00229
break;
00230
00231
case IMAGE_REL_BASED_HIGH :
00232
00233
00234
00235 Temp = *(
PUSHORT)FixupVA << 16;
00236 Temp += (ULONG) Diff;
00237 *(
PUSHORT)FixupVA = (
USHORT)(Temp >> 16);
00238
break;
00239
00240
case IMAGE_REL_BASED_HIGHADJ :
00241
00242
00243
00244
00245
00246
#if defined(NTOS_KERNEL_RUNTIME)
00247
00248
00249
00250
00251
if (
Offset &
LDRP_RELOCATION_FINAL) {
00252 ++NextOffset;
00253 --SizeOfBlock;
00254
break;
00255 }
00256
#endif
00257
00258 Temp = *(
PUSHORT)FixupVA << 16;
00259
#if defined(BLDR_KERNEL_RUNTIME)
00260
TempOrig = Temp;
00261
#endif
00262
++NextOffset;
00263 --SizeOfBlock;
00264 Temp += (LONG)(*(
PSHORT)NextOffset);
00265 Temp += (ULONG) Diff;
00266 Temp += 0x8000;
00267 *(
PUSHORT)FixupVA = (
USHORT)(Temp >> 16);
00268
00269
#if defined(BLDR_KERNEL_RUNTIME)
00270
ActualDiff = ((((ULONG_PTR)(Temp - TempOrig)) >> 16) -
00271 (((ULONG_PTR)Diff) >> 16 ));
00272
00273
if (ActualDiff == 1) {
00274
00275
00276
00277
00278 *(NextOffset - 1) |=
LDRP_RELOCATION_INCREMENT;
00279 }
00280
else if (ActualDiff != 0) {
00281
00282
00283
00284 *(NextOffset - 1) |=
LDRP_RELOCATION_FINAL;
00285 }
00286
#endif
00287
00288
break;
00289
00290
case IMAGE_REL_BASED_LOW :
00291
00292
00293
00294 Temp = *(
PSHORT)FixupVA;
00295 Temp += (ULONG) Diff;
00296 *(
PUSHORT)FixupVA = (
USHORT)Temp;
00297
break;
00298
00299
case IMAGE_REL_BASED_IA64_IMM64:
00300
00301
00302
00303
00304
00305
00306 FixupVA = (PUCHAR)((ULONG_PTR)FixupVA & ~(15));
00307 Value64 = (ULONGLONG)0;
00308
00309
00310
00311
00312
00313
00314 EXT_IMM64(Value64,
00315 (PULONG)FixupVA + EMARCH_ENC_I17_IMM7B_INST_WORD_X,
00316 EMARCH_ENC_I17_IMM7B_SIZE_X,
00317 EMARCH_ENC_I17_IMM7B_INST_WORD_POS_X,
00318 EMARCH_ENC_I17_IMM7B_VAL_POS_X);
00319 EXT_IMM64(Value64,
00320 (PULONG)FixupVA + EMARCH_ENC_I17_IMM9D_INST_WORD_X,
00321 EMARCH_ENC_I17_IMM9D_SIZE_X,
00322 EMARCH_ENC_I17_IMM9D_INST_WORD_POS_X,
00323 EMARCH_ENC_I17_IMM9D_VAL_POS_X);
00324 EXT_IMM64(Value64,
00325 (PULONG)FixupVA + EMARCH_ENC_I17_IMM5C_INST_WORD_X,
00326 EMARCH_ENC_I17_IMM5C_SIZE_X,
00327 EMARCH_ENC_I17_IMM5C_INST_WORD_POS_X,
00328 EMARCH_ENC_I17_IMM5C_VAL_POS_X);
00329 EXT_IMM64(Value64,
00330 (PULONG)FixupVA + EMARCH_ENC_I17_IC_INST_WORD_X,
00331 EMARCH_ENC_I17_IC_SIZE_X,
00332 EMARCH_ENC_I17_IC_INST_WORD_POS_X,
00333 EMARCH_ENC_I17_IC_VAL_POS_X);
00334 EXT_IMM64(Value64,
00335 (PULONG)FixupVA + EMARCH_ENC_I17_IMM41a_INST_WORD_X,
00336 EMARCH_ENC_I17_IMM41a_SIZE_X,
00337 EMARCH_ENC_I17_IMM41a_INST_WORD_POS_X,
00338 EMARCH_ENC_I17_IMM41a_VAL_POS_X);
00339
00340
00341
00342
00343
00344 Value64+=Diff;
00345
00346
00347
00348
00349
00350 INS_IMM64(Value64,
00351 ((PULONG)FixupVA + EMARCH_ENC_I17_IMM7B_INST_WORD_X),
00352 EMARCH_ENC_I17_IMM7B_SIZE_X,
00353 EMARCH_ENC_I17_IMM7B_INST_WORD_POS_X,
00354 EMARCH_ENC_I17_IMM7B_VAL_POS_X);
00355 INS_IMM64(Value64,
00356 ((PULONG)FixupVA + EMARCH_ENC_I17_IMM9D_INST_WORD_X),
00357 EMARCH_ENC_I17_IMM9D_SIZE_X,
00358 EMARCH_ENC_I17_IMM9D_INST_WORD_POS_X,
00359 EMARCH_ENC_I17_IMM9D_VAL_POS_X);
00360 INS_IMM64(Value64,
00361 ((PULONG)FixupVA + EMARCH_ENC_I17_IMM5C_INST_WORD_X),
00362 EMARCH_ENC_I17_IMM5C_SIZE_X,
00363 EMARCH_ENC_I17_IMM5C_INST_WORD_POS_X,
00364 EMARCH_ENC_I17_IMM5C_VAL_POS_X);
00365 INS_IMM64(Value64,
00366 ((PULONG)FixupVA + EMARCH_ENC_I17_IC_INST_WORD_X),
00367 EMARCH_ENC_I17_IC_SIZE_X,
00368 EMARCH_ENC_I17_IC_INST_WORD_POS_X,
00369 EMARCH_ENC_I17_IC_VAL_POS_X);
00370 INS_IMM64(Value64,
00371 ((PULONG)FixupVA + EMARCH_ENC_I17_IMM41a_INST_WORD_X),
00372 EMARCH_ENC_I17_IMM41a_SIZE_X,
00373 EMARCH_ENC_I17_IMM41a_INST_WORD_POS_X,
00374 EMARCH_ENC_I17_IMM41a_VAL_POS_X);
00375 INS_IMM64(Value64,
00376 ((PULONG)FixupVA + EMARCH_ENC_I17_IMM41b_INST_WORD_X),
00377 EMARCH_ENC_I17_IMM41b_SIZE_X,
00378 EMARCH_ENC_I17_IMM41b_INST_WORD_POS_X,
00379 EMARCH_ENC_I17_IMM41b_VAL_POS_X);
00380 INS_IMM64(Value64,
00381 ((PULONG)FixupVA + EMARCH_ENC_I17_IMM41c_INST_WORD_X),
00382 EMARCH_ENC_I17_IMM41c_SIZE_X,
00383 EMARCH_ENC_I17_IMM41c_INST_WORD_POS_X,
00384 EMARCH_ENC_I17_IMM41c_VAL_POS_X);
00385 INS_IMM64(Value64,
00386 ((PULONG)FixupVA + EMARCH_ENC_I17_SIGN_INST_WORD_X),
00387 EMARCH_ENC_I17_SIGN_SIZE_X,
00388 EMARCH_ENC_I17_SIGN_INST_WORD_POS_X,
00389 EMARCH_ENC_I17_SIGN_VAL_POS_X);
00390
break;
00391
00392
case IMAGE_REL_BASED_DIR64:
00393
00394 *(ULONG_PTR UNALIGNED *)FixupVA += Diff;
00395
00396
break;
00397
00398
case IMAGE_REL_BASED_MIPS_JMPADDR :
00399
00400
00401
00402 Temp = (*(PULONG)FixupVA & 0x3ffffff) << 2;
00403 Temp += (ULONG) Diff;
00404 *(PULONG)FixupVA = (*(PULONG)FixupVA & ~0x3ffffff) |
00405 ((Temp >> 2) & 0x3ffffff);
00406
00407
break;
00408
00409
case IMAGE_REL_BASED_ABSOLUTE :
00410
00411
00412
00413
break;
00414
00415
case IMAGE_REL_BASED_SECTION :
00416
00417
00418
00419
break;
00420
00421
case IMAGE_REL_BASED_REL32 :
00422
00423
00424
00425
break;
00426
00427
case IMAGE_REL_BASED_HIGH3ADJ :
00428
00429
00430
00431
00432
00433
00434 Temp64 = *(
PUSHORT)FixupVA << 16;
00435 ++NextOffset;
00436 --SizeOfBlock;
00437 Temp64 += (LONG)((
SHORT)NextOffset[1]);
00438 Temp64 <<= 16;
00439 Temp64 += (LONG)((
USHORT)NextOffset[0]);
00440 Temp64 += Diff;
00441 Temp64 += 0x8000;
00442 Temp64 >>=16;
00443 Temp64 += 0x8000;
00444 *(
PUSHORT)FixupVA = (
USHORT)(Temp64 >> 16);
00445 ++NextOffset;
00446 --SizeOfBlock;
00447
break;
00448
00449
default :
00450
00451
00452
00453
00454
return (PIMAGE_BASE_RELOCATION)
NULL;
00455 }
00456 ++NextOffset;
00457 }
00458
return (PIMAGE_BASE_RELOCATION)NextOffset;
00459 }
00460
00461
#if defined(NTOS_KERNEL_RUNTIME)
00462
00463 ULONG
00464
LdrDoubleRelocateImage (
00465 IN PVOID NewBase,
00466 IN PVOID CurrentBase,
00467 IN PUCHAR LoaderName,
00468 IN ULONG Success,
00469 IN ULONG Conflict,
00470 IN ULONG Invalid
00471 )
00472
00473
00474
00475
00476
00477
00478
00479
00480
00481
00482
00483
00484
00485
00486
00487
00488
00489
00490
00491
00492
00493
00494
00495
00496
00497
00498
00499
00500
00501
00502
00503
00504
00505
00506
00507
00508 {
00509 LONG_PTR Diff;
00510 LONG_PTR OldDiff;
00511 ULONG TotalCountBytes;
00512 ULONG_PTR VA;
00513 ULONG_PTR OldBase;
00514 ULONG SizeOfBlock;
00515 PUCHAR FixupVA;
00516
USHORT Offset;
00517
PUSHORT NextOffset;
00518 PIMAGE_NT_HEADERS NtHeaders;
00519 PIMAGE_BASE_RELOCATION NextBlock;
00520
00521
RTL_PAGED_CODE();
00522
00523 NtHeaders =
RtlImageNtHeader( NewBase );
00524
00525 OldBase = NtHeaders->OptionalHeader.ImageBase;
00526 OldDiff = (PCHAR)CurrentBase - (PCHAR)OldBase;
00527
00528
00529
00530
00531
00532 NextBlock = (PIMAGE_BASE_RELOCATION)
RtlImageDirectoryEntryToData(
00533 NewBase, TRUE, IMAGE_DIRECTORY_ENTRY_BASERELOC, &TotalCountBytes);
00534
00535
if (!NextBlock || !TotalCountBytes) {
00536
00537
00538
00539
00540
00541
#if DBG
00542
DbgPrint(
"%s: Image can't be relocated, no fixup information.\n", LoaderName);
00543
#endif // DBG
00544
return Conflict;
00545 }
00546
00547
00548
00549
00550
00551
00552 Diff = (PCHAR)NewBase - (PCHAR)OldBase;
00553
00554
while (TotalCountBytes) {
00555 SizeOfBlock = NextBlock->SizeOfBlock;
00556 TotalCountBytes -= SizeOfBlock;
00557 SizeOfBlock -=
sizeof(IMAGE_BASE_RELOCATION);
00558 SizeOfBlock /=
sizeof(
USHORT);
00559 NextOffset = (
PUSHORT)((PCHAR)NextBlock +
sizeof(IMAGE_BASE_RELOCATION));
00560
00561 VA = (ULONG_PTR)NewBase + NextBlock->VirtualAddress;
00562
00563
if ( !(NextBlock = LdrpProcessVolatileRelocationBlock(VA,SizeOfBlock,NextOffset,Diff, OldDiff, OldBase)) ) {
00564
#if DBG
00565
DbgPrint(
"%s: Unknown base relocation type\n", LoaderName);
00566
#endif
00567
return Invalid;
00568 }
00569 }
00570
00571
return Success;
00572 }
00573
00574 PIMAGE_BASE_RELOCATION
00575 LdrpProcessVolatileRelocationBlock(
00576 IN ULONG_PTR VA,
00577 IN ULONG SizeOfBlock,
00578 IN PUSHORT NextOffset,
00579 IN LONG_PTR Diff,
00580 IN LONG_PTR OldDiff,
00581 IN ULONG_PTR OldBase
00582 )
00583
00584
00585
00586
00587
00588
00589
00590
00591
00592
00593
00594
00595
00596
00597
00598
00599
00600
00601
00602
00603
00604
00605
00606
00607 {
00608 PUCHAR FixupVA;
00609
USHORT Offset;
00610 LONG Temp;
00611 ULONG Temp32;
00612
USHORT TempShort1;
00613
USHORT TempShort2;
00614 ULONGLONG Value64;
00615 LONGLONG Temp64;
00616
USHORT RelocationType;
00617 IN PVOID CurrentBase;
00618
00619
RTL_PAGED_CODE();
00620
00621 CurrentBase = (PVOID)((ULONG_PTR)OldDiff + OldBase);
00622
00623
while (SizeOfBlock--) {
00624
00625
Offset = *NextOffset & (
USHORT)0xfff;
00626 FixupVA = (PUCHAR)(VA +
Offset);
00627
00628
00629
00630
00631
00632
switch ((*NextOffset) >> 12) {
00633
00634
case IMAGE_REL_BASED_HIGHADJ :
00635
00636
00637
00638
00639
00640
00641
00642
00643
00644
00645 FixupVA = (PUCHAR)((LONG_PTR)FixupVA & (LONG_PTR)~(
LDRP_RELOCATION_FINAL |
LDRP_RELOCATION_INCREMENT));
00646 Temp = *(
PUSHORT)(FixupVA) << 16;
00647
00648 ++NextOffset;
00649 --SizeOfBlock;
00650
00651
00652 Temp -= ((LONG)(*(
PSHORT)NextOffset) + (
USHORT)OldDiff + 0x8000) & ~0xFFFF;
00653
00654 Temp -= (LONG)(OldDiff & ~0xffff);
00655
00656 Temp += (LONG)(*(
PSHORT)NextOffset);
00657 Temp += (ULONG) Diff;
00658 Temp += 0x8000;
00659 *(
PUSHORT)FixupVA = (
USHORT)(Temp >> 16);
00660
00661
00662
00663
00664 *(NextOffset - 1) |=
LDRP_RELOCATION_FINAL;
00665
break;
00666
00667
case IMAGE_REL_BASED_HIGH3ADJ :
00668
00669
00670
00671
00672
00673 TempShort1 = *(NextOffset + 1);
00674 TempShort2 = *(NextOffset + 2);
00675
00676 Temp64 = (LONGLONG)((TempShort2 << 16) + TempShort1);
00677 Temp64 -= (LONGLONG)OldBase;
00678 Temp64 += (LONGLONG)CurrentBase;
00679
00680 TempShort1 = (
USHORT)Temp64;
00681 TempShort2 = (
USHORT)(Temp64 >> 16);
00682
00683 *(NextOffset + 1) = TempShort1;
00684 *(NextOffset + 2) = TempShort2;
00685
00686 ++NextOffset;
00687 --SizeOfBlock;
00688 ++NextOffset;
00689 --SizeOfBlock;
00690
00691
break;
00692
00693
default :
00694
break;
00695 }
00696 ++NextOffset;
00697 }
00698
return (PIMAGE_BASE_RELOCATION)NextOffset;
00699 }
00700
00701
#endif