mirror of
https://dev.lirent.ru/Vatrog/vm-introspection-engine.git
synced 2026-06-18 02:06:36 +03:00
c4419964aa
Three reversing capabilities on the win32 surface plus a pure sig-gen handler:
- vmie_win32_functions enumerates a module's functions from the exception
directory (.pdata RUNTIME_FUNCTION), folding unwind chain continuations into
their primary - authoritative non-leaf boundaries, not prologue heuristics.
- vmie_win32_exports resolves the export table to {name, rva, ordinal,
forwarded}: named functions with no PDB or network. vmie_win32_pdb_ref pulls
the CodeView/RSDS {guid, age, pdb} from the debug directory - the symbol-server
key for any module (full PDB parsing stays out of scope).
- sig_generate (siggen.h) builds a unique masked signature for a code span,
wildcarding the rel/RIP-relative displacement bytes the x86 decoder locates and
growing until it matches the scope exactly once - the dual of sigscan.
The decoder now also reports disp_off/disp_len so a caller can mask the floating
bytes. The MZ/PE walk gains one shared data-directory accessor and one shared
CodeView/RSDS parser; the kernel bootstrap is moved onto both, removing its
private copies - one PE parser in the tree.
62 lines
2.7 KiB
CMake
62 lines
2.7 KiB
CMake
cmake_minimum_required(VERSION 3.18) # find_program(... REQUIRED)
|
|
project(vmi-engine C)
|
|
|
|
set(CMAKE_C_STANDARD 17) # generation B uses no C23 feature
|
|
set(CMAKE_C_STANDARD_REQUIRED ON)
|
|
set(CMAKE_C_EXTENSIONS ON) # deliberate: strnlen (POSIX) + void* arithmetic (GNU)
|
|
|
|
option(VMIE_LTO "Enable LTO" OFF) # build-only; shipped default is -O2, no LTO
|
|
|
|
# ---- host: VMI core as a static library ---------------------------------
|
|
add_library(vmie STATIC
|
|
src/core/gpa.c
|
|
src/engine/gva.c
|
|
src/engine/sigphys.c
|
|
src/engine/win32/host.c
|
|
src/engine/win32/pe.c
|
|
src/engine/win32/proc.c
|
|
src/engine/win32/profile.c
|
|
src/engine/win32/text.c
|
|
src/handlers/scan.c
|
|
src/handlers/sigscan.c
|
|
src/handlers/sigset.c
|
|
src/handlers/codescan.c
|
|
src/handlers/siggen.c
|
|
src/handlers/x86dec.c
|
|
src/handlers/pmap.c
|
|
src/handlers/snapdiff.c)
|
|
target_include_directories(vmie
|
|
PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/include # public API: include/*.h
|
|
PRIVATE ${CMAKE_CURRENT_SOURCE_DIR}/src/core/include # private: core.h
|
|
${CMAKE_CURRENT_SOURCE_DIR}/src/engine/include # private: engine-arch.h, pe.h
|
|
${CMAKE_CURRENT_SOURCE_DIR}/src/engine/win32) # private: engine-win32.h, contract.h
|
|
target_compile_options(vmie PRIVATE -O2 -Wall -Wextra)
|
|
if(VMIE_LTO)
|
|
target_compile_options(vmie PRIVATE -flto)
|
|
target_link_options(vmie PRIVATE -flto)
|
|
endif()
|
|
|
|
# ---- host: CLI demonstrator over the library ----------------------------
|
|
add_executable(vmie_cli src/cli.c)
|
|
target_link_libraries(vmie_cli PRIVATE vmie) # public include/ comes via vmie (PUBLIC)
|
|
target_compile_options(vmie_cli PRIVATE -Wall -Wextra)
|
|
|
|
# ---- host: dump-scan demonstrator (OS-agnostic, no win32) ----------------
|
|
add_executable(vmie_scan src/scan_cli.c)
|
|
target_link_libraries(vmie_scan PRIVATE vmie)
|
|
target_compile_options(vmie_scan PRIVATE -Wall -Wextra)
|
|
|
|
# ---- guest: cross-compile to Windows x86-64 via mingw-w64 ---------------
|
|
find_program(MINGW_CC NAMES x86_64-w64-mingw32-gcc REQUIRED)
|
|
set(VMIE_STARTUP ${CMAKE_CURRENT_BINARY_DIR}/vmie-startup.exe)
|
|
add_custom_command(
|
|
OUTPUT ${VMIE_STARTUP}
|
|
COMMAND ${MINGW_CC} -O2 -Wall -Wextra -static -s
|
|
-I${CMAKE_CURRENT_SOURCE_DIR}/src/engine/win32
|
|
-o ${VMIE_STARTUP} ${CMAKE_CURRENT_SOURCE_DIR}/src/engine/win32/guest.c
|
|
DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/src/engine/win32/guest.c
|
|
${CMAKE_CURRENT_SOURCE_DIR}/src/engine/win32/contract.h
|
|
COMMENT "Cross-compiling vmie-startup.exe (mingw-w64, x86-64)"
|
|
VERBATIM)
|
|
add_custom_target(vmie-startup ALL DEPENDS ${VMIE_STARTUP})
|