Skip to content

Fix ELF core register sections and PE64 creation ##bin - #26940

Open
trufae wants to merge 2 commits into
masterfrom
fix-core-register-sections-pe64-create
Open

trufae wants to merge 2 commits into
masterfrom
fix-core-register-sections-pe64-create

Conversation

@trufae

@trufae trufae commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator
  • Mark this if you consider it ready to merge
  • I've added tests (optional)
  • I wrote some lines in the book (optional)

Fix the two expected failures encountered while validating the OSS Scanner enrollment: ELF: core sections with reg name and create pe x86-64.

Two commits:

  • Expose ELF core .reg, .reg2, and .reg-xstate sections, with thread IDs and aliases for the first thread. Share bounded note parsing with register-state extraction, check note owners and descriptor lengths, and correct the i386 register-set size.
  • Add the PE64 creation callback and share the writer with PE32. Honor the requested bitness, emit complete aligned headers and sections, and map optional data into a writable data section. Previously, pe64 could not create a file and pe -b 64 silently emitted PE32.

Remove both BROKEN markers. Check actual register-section names, offsets and sizes, and generated PE architecture, header magic, entry-point bytes and data mapping. Add malformed-note and multiple-thread coverage. PE output now uses standard file/section alignment rather than the former overlapping 125-byte layout.

The existing core disassembly expectation loses segment metadata comments because radare2 suppresses them when sections are present; register values and instructions are unchanged.

Validation:

  • Root make -j4 and installation succeeded.
  • r2r -u -L -C test db/formats/elf db/formats/pe: 771 passed, 0 failed, 0 broken, 2 skipped.
  • All 14 focused core-note and PE-creation tests pass.
  • Independently checked ELF register-section offsets and generated PE64 headers with objdump.
  • git diff --check passes.

Validation ran on Linux; generated PE files were parsed, not executed on Windows.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant