1 //===- llvm/BinaryFormat/Magic.cpp - File magic identification --*- C++ -*-===//
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
7 //===----------------------------------------------------------------------===//
9 #include "llvm/BinaryFormat/Magic.h"
10 #include "llvm/ADT/StringRef.h"
11 #include "llvm/ADT/Twine.h"
12 #include "llvm/BinaryFormat/COFF.h"
13 #include "llvm/BinaryFormat/ELF.h"
14 #include "llvm/BinaryFormat/MachO.h"
15 #include "llvm/Support/Endian.h"
16 #include "llvm/Support/FileSystem.h"
17 #include "llvm/Support/MemoryBuffer.h"
19 #if !defined(_MSC_VER) && !defined(__MINGW32__)
26 using namespace llvm::support::endian;
27 using namespace llvm::sys::fs;
30 static bool startswith(StringRef Magic, const char (&S)[N]) {
31 return Magic.startswith(StringRef(S, N - 1));
34 /// Identify the magic in magic.
35 file_magic llvm::identify_magic(StringRef Magic) {
37 return file_magic::unknown;
38 switch ((unsigned char)Magic[0]) {
40 // COFF bigobj, CL.exe's LTO object file, or short import library file
41 if (startswith(Magic, "\0\0\xFF\xFF")) {
43 offsetof(COFF::BigObjHeader, UUID) + sizeof(COFF::BigObjMagic);
44 if (Magic.size() < MinSize)
45 return file_magic::coff_import_library;
47 const char *Start = Magic.data() + offsetof(COFF::BigObjHeader, UUID);
48 if (memcmp(Start, COFF::BigObjMagic, sizeof(COFF::BigObjMagic)) == 0)
49 return file_magic::coff_object;
50 if (memcmp(Start, COFF::ClGlObjMagic, sizeof(COFF::BigObjMagic)) == 0)
51 return file_magic::coff_cl_gl_object;
52 return file_magic::coff_import_library;
54 // Windows resource file
55 if (Magic.size() >= sizeof(COFF::WinResMagic) &&
56 memcmp(Magic.data(), COFF::WinResMagic, sizeof(COFF::WinResMagic)) == 0)
57 return file_magic::windows_resource;
58 // 0x0000 = COFF unknown machine type
60 return file_magic::coff_object;
61 if (startswith(Magic, "\0asm"))
62 return file_magic::wasm_object;
68 if (startswith(Magic, "\x01\xDF"))
69 return file_magic::xcoff_object_32;
70 if (startswith(Magic, "\x01\xF7"))
71 return file_magic::xcoff_object_64;
74 case 0xDE: // 0x0B17C0DE = BC wraper
75 if (startswith(Magic, "\xDE\xC0\x17\x0B"))
76 return file_magic::bitcode;
79 if (startswith(Magic, "BC\xC0\xDE"))
80 return file_magic::bitcode;
83 if (startswith(Magic, "!<arch>\n") || startswith(Magic, "!<thin>\n"))
84 return file_magic::archive;
88 if (startswith(Magic, "\177ELF") && Magic.size() >= 18) {
89 bool Data2MSB = Magic[5] == 2;
90 unsigned high = Data2MSB ? 16 : 17;
91 unsigned low = Data2MSB ? 17 : 16;
92 if (Magic[high] == 0) {
95 return file_magic::elf;
97 return file_magic::elf_relocatable;
99 return file_magic::elf_executable;
101 return file_magic::elf_shared_object;
103 return file_magic::elf_core;
106 // It's still some type of ELF file.
107 return file_magic::elf;
112 if (startswith(Magic, "\xCA\xFE\xBA\xBE") ||
113 startswith(Magic, "\xCA\xFE\xBA\xBF")) {
114 // This is complicated by an overlap with Java class files.
115 // See the Mach-O section in /usr/share/file/magic for details.
116 if (Magic.size() >= 8 && Magic[7] < 43)
117 return file_magic::macho_universal_binary;
121 // The two magic numbers for mach-o are:
122 // 0xfeedface - 32-bit mach-o
123 // 0xfeedfacf - 64-bit mach-o
128 if (startswith(Magic, "\xFE\xED\xFA\xCE") ||
129 startswith(Magic, "\xFE\xED\xFA\xCF")) {
132 if (Magic[3] == char(0xCE))
133 MinSize = sizeof(MachO::mach_header);
135 MinSize = sizeof(MachO::mach_header_64);
136 if (Magic.size() >= MinSize)
137 type = Magic[12] << 24 | Magic[13] << 12 | Magic[14] << 8 | Magic[15];
138 } else if (startswith(Magic, "\xCE\xFA\xED\xFE") ||
139 startswith(Magic, "\xCF\xFA\xED\xFE")) {
142 if (Magic[0] == char(0xCE))
143 MinSize = sizeof(MachO::mach_header);
145 MinSize = sizeof(MachO::mach_header_64);
146 if (Magic.size() >= MinSize)
147 type = Magic[15] << 24 | Magic[14] << 12 | Magic[13] << 8 | Magic[12];
153 return file_magic::macho_object;
155 return file_magic::macho_executable;
157 return file_magic::macho_fixed_virtual_memory_shared_lib;
159 return file_magic::macho_core;
161 return file_magic::macho_preload_executable;
163 return file_magic::macho_dynamically_linked_shared_lib;
165 return file_magic::macho_dynamic_linker;
167 return file_magic::macho_bundle;
169 return file_magic::macho_dynamically_linked_shared_lib_stub;
171 return file_magic::macho_dsym_companion;
173 return file_magic::macho_kext_bundle;
177 case 0xF0: // PowerPC Windows
178 case 0x83: // Alpha 32-bit
179 case 0x84: // Alpha 64-bit
180 case 0x66: // MPS R4000 Windows
182 case 0x4c: // 80386 Windows
183 case 0xc4: // ARMNT Windows
184 if (Magic[1] == 0x01)
185 return file_magic::coff_object;
188 case 0x90: // PA-RISC Windows
189 case 0x68: // mc68K Windows
190 if (Magic[1] == 0x02)
191 return file_magic::coff_object;
194 case 'M': // Possible MS-DOS stub on Windows PE file, MSF/PDB file or a
196 if (startswith(Magic, "MZ") && Magic.size() >= 0x3c + 4) {
197 uint32_t off = read32le(Magic.data() + 0x3c);
198 // PE/COFF file, either EXE or DLL.
199 if (Magic.substr(off).startswith(
200 StringRef(COFF::PEMagic, sizeof(COFF::PEMagic))))
201 return file_magic::pecoff_executable;
203 if (Magic.startswith("Microsoft C/C++ MSF 7.00\r\n"))
204 return file_magic::pdb;
205 if (startswith(Magic, "MDMP"))
206 return file_magic::minidump;
209 case 0x64: // x86-64 or ARM64 Windows.
210 if (Magic[1] == char(0x86) || Magic[1] == char(0xaa))
211 return file_magic::coff_object;
214 case 0x2d: // YAML '-'
215 if (startswith(Magic, "--- !tapi") || startswith(Magic, "---\narchs:"))
216 return file_magic::tapi_file;
222 return file_magic::unknown;
225 std::error_code llvm::identify_magic(const Twine &Path, file_magic &Result) {
226 auto FileOrError = MemoryBuffer::getFile(Path, -1LL, false);
228 return FileOrError.getError();
230 std::unique_ptr<MemoryBuffer> FileBuffer = std::move(*FileOrError);
231 Result = identify_magic(FileBuffer->getBuffer());
233 return std::error_code();