1//===- llvm/BinaryFormat/Magic.cpp - File magic identification --*- C++ -*-===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8
9#include "llvm/BinaryFormat/Magic.h"
10#include "llvm/ADT/StringRef.h"
11#include "llvm/ADT/Twine.h"
12#include "llvm/BinaryFormat/COFF.h"
13#include "llvm/BinaryFormat/MachO.h"
14#include "llvm/Support/Endian.h"
15#include "llvm/Support/MemoryBuffer.h"
16
17#if !defined(_MSC_VER) && !defined(__MINGW32__)
18#include <unistd.h>
19#else
20#include <io.h>
21#endif
22
23using namespace llvm;
24using namespace llvm::support::endian;
25using namespace llvm::sys::fs;
26
27template <size_t N>
28static bool startswith(StringRef Magic, const char (&S)[N]) {
29 return Magic.starts_with(Prefix: StringRef(S, N - 1));
30}
31
32/// Identify the magic in magic.
33file_magic llvm::identify_magic(StringRef Magic) {
34 if (Magic.size() < 4)
35 return file_magic::unknown;
36 switch ((unsigned char)Magic[0]) {
37 case 0x00: {
38 // COFF bigobj, CL.exe's LTO object file, or short import library file
39 if (startswith(Magic, S: "\0\0\xFF\xFF")) {
40 size_t MinSize =
41 offsetof(COFF::BigObjHeader, UUID) + sizeof(COFF::BigObjMagic);
42 if (Magic.size() < MinSize)
43 return file_magic::coff_import_library;
44
45 const char *Start = Magic.data() + offsetof(COFF::BigObjHeader, UUID);
46 if (memcmp(s1: Start, s2: COFF::BigObjMagic, n: sizeof(COFF::BigObjMagic)) == 0)
47 return file_magic::coff_object;
48 if (memcmp(s1: Start, s2: COFF::ClGlObjMagic, n: sizeof(COFF::BigObjMagic)) == 0)
49 return file_magic::coff_cl_gl_object;
50 return file_magic::coff_import_library;
51 }
52 // Windows resource file
53 if (Magic.size() >= sizeof(COFF::WinResMagic) &&
54 memcmp(s1: Magic.data(), s2: COFF::WinResMagic, n: sizeof(COFF::WinResMagic)) == 0)
55 return file_magic::windows_resource;
56 // 0x0000 = COFF unknown machine type
57 if (Magic[1] == 0)
58 return file_magic::coff_object;
59 if (startswith(Magic, S: "\0asm"))
60 return file_magic::wasm_object;
61 break;
62 }
63
64 case 0x01:
65 // XCOFF format
66 if (startswith(Magic, S: "\x01\xDF"))
67 return file_magic::xcoff_object_32;
68 if (startswith(Magic, S: "\x01\xF7"))
69 return file_magic::xcoff_object_64;
70 break;
71
72 case 0x03:
73 if (startswith(Magic, S: "\x03\xF0\x00"))
74 return file_magic::goff_object;
75 // SPIR-V format in little-endian mode.
76 if (startswith(Magic, S: "\x03\x02\x23\x07"))
77 return file_magic::spirv_object;
78 break;
79
80 case 0x07: // SPIR-V format in big-endian mode.
81 if (startswith(Magic, S: "\x07\x23\x02\x03"))
82 return file_magic::spirv_object;
83 break;
84
85 case 0x10:
86 if (startswith(Magic, S: "\x10\xFF\x10\xAD"))
87 return file_magic::offload_binary;
88 break;
89
90 case 0xDE: // 0x0B17C0DE = BC wraper
91 if (startswith(Magic, S: "\xDE\xC0\x17\x0B"))
92 return file_magic::bitcode;
93 break;
94 case 'B':
95 if (startswith(Magic, S: "BC\xC0\xDE"))
96 return file_magic::bitcode;
97 break;
98 case 'C':
99 if (startswith(Magic, S: "CCOB"))
100 return file_magic::offload_bundle_compressed;
101 if (startswith(Magic, S: "CPCH"))
102 return file_magic::clang_ast;
103 break;
104 case 0x5A:
105 if (startswith(Magic,
106 S: "\x5A\x4C\x81\x99\x83\x88\x6E\x15")) // "!<arch>\n" in EBCDIC
107 return file_magic::archive;
108 break;
109 case '!':
110 if (startswith(Magic, S: "!<arch>\n") || startswith(Magic, S: "!<thin>\n"))
111 return file_magic::archive;
112 break;
113 case '<':
114 if (startswith(Magic, S: "<bigaf>\n"))
115 return file_magic::archive;
116 break;
117 case '\177':
118 if (startswith(Magic, S: "\177ELF") && Magic.size() >= 18) {
119 bool Data2MSB = Magic[5] == 2;
120 unsigned high = Data2MSB ? 16 : 17;
121 unsigned low = Data2MSB ? 17 : 16;
122 if (Magic[high] == 0) {
123 switch (Magic[low]) {
124 default:
125 return file_magic::elf;
126 case 1:
127 return file_magic::elf_relocatable;
128 case 2:
129 return file_magic::elf_executable;
130 case 3:
131 return file_magic::elf_shared_object;
132 case 4:
133 return file_magic::elf_core;
134 }
135 }
136 // It's still some type of ELF file.
137 return file_magic::elf;
138 }
139 break;
140
141 case 0xCA:
142 if (startswith(Magic, S: "\xCA\xFE\xBA\xBE") ||
143 startswith(Magic, S: "\xCA\xFE\xBA\xBF")) {
144 // This is complicated by an overlap with Java class files.
145 // See the Mach-O section in /usr/share/file/magic for details.
146 if (Magic.size() >= 8 && Magic[7] < 43)
147 return file_magic::macho_universal_binary;
148 }
149 break;
150
151 // The two magic numbers for mach-o are:
152 // 0xfeedface - 32-bit mach-o
153 // 0xfeedfacf - 64-bit mach-o
154 case 0xFE:
155 case 0xCE:
156 case 0xCF: {
157 uint16_t type = 0;
158 if (startswith(Magic, S: "\xFE\xED\xFA\xCE") ||
159 startswith(Magic, S: "\xFE\xED\xFA\xCF")) {
160 /* Native endian */
161 size_t MinSize;
162 if (Magic[3] == char(0xCE))
163 MinSize = sizeof(MachO::mach_header);
164 else
165 MinSize = sizeof(MachO::mach_header_64);
166 if (Magic.size() >= MinSize)
167 type = Magic[12] << 24 | Magic[13] << 12 | Magic[14] << 8 | Magic[15];
168 } else if (startswith(Magic, S: "\xCE\xFA\xED\xFE") ||
169 startswith(Magic, S: "\xCF\xFA\xED\xFE")) {
170 /* Reverse endian */
171 size_t MinSize;
172 if (Magic[0] == char(0xCE))
173 MinSize = sizeof(MachO::mach_header);
174 else
175 MinSize = sizeof(MachO::mach_header_64);
176 if (Magic.size() >= MinSize)
177 type = Magic[15] << 24 | Magic[14] << 12 | Magic[13] << 8 | Magic[12];
178 }
179 switch (type) {
180 default:
181 break;
182 case 1:
183 return file_magic::macho_object;
184 case 2:
185 return file_magic::macho_executable;
186 case 3:
187 return file_magic::macho_fixed_virtual_memory_shared_lib;
188 case 4:
189 return file_magic::macho_core;
190 case 5:
191 return file_magic::macho_preload_executable;
192 case 6:
193 return file_magic::macho_dynamically_linked_shared_lib;
194 case 7:
195 return file_magic::macho_dynamic_linker;
196 case 8:
197 return file_magic::macho_bundle;
198 case 9:
199 return file_magic::macho_dynamically_linked_shared_lib_stub;
200 case 10:
201 return file_magic::macho_dsym_companion;
202 case 11:
203 return file_magic::macho_kext_bundle;
204 case 12:
205 return file_magic::macho_file_set;
206 }
207 break;
208 }
209 case 0xF0: // PowerPC Windows
210 case 0x83: // Alpha 32-bit
211 case 0x84: // Alpha 64-bit
212 case 0x66: // MPS R4000 Windows
213 case 0x50: // mc68K
214 if (startswith(Magic, S: "\x50\xed\x55\xba"))
215 return file_magic::cuda_fatbinary;
216 [[fallthrough]];
217
218 case 0x4c: // 80386 Windows
219 case 0xc4: // ARMNT Windows
220 if (Magic[1] == 0x01)
221 return file_magic::coff_object;
222 [[fallthrough]];
223
224 case 0x90: // PA-RISC Windows
225 case 0x68: // mc68K Windows
226 if (Magic[1] == 0x02)
227 return file_magic::coff_object;
228 break;
229
230 case 'M': // Possible MS-DOS stub on Windows PE file, MSF/PDB file or a
231 // Minidump file.
232 if (startswith(Magic, S: "MZ") && Magic.size() >= 0x3c + 4) {
233 uint32_t off = read32le(P: Magic.data() + 0x3c);
234 // PE/COFF file, either EXE or DLL.
235 if (Magic.substr(Start: off).starts_with(
236 Prefix: StringRef(COFF::PEMagic, sizeof(COFF::PEMagic))))
237 return file_magic::pecoff_executable;
238 }
239 if (Magic.starts_with(Prefix: "Microsoft C/C++ MSF 7.00\r\n"))
240 return file_magic::pdb;
241 if (startswith(Magic, S: "MDMP"))
242 return file_magic::minidump;
243 break;
244
245 case 0x64: // x86-64 or ARM64 Windows.
246 if (Magic[1] == char(0x86) || Magic[1] == char(0xaa))
247 return file_magic::coff_object;
248 break;
249
250 case 0x2d: // YAML '-' MachO TBD.
251 if (startswith(Magic, S: "--- !tapi") || startswith(Magic, S: "---\narchs:"))
252 return file_magic::tapi_file;
253 break;
254 case 0x7b: // JSON '{' MachO TBD.
255 return file_magic::tapi_file;
256 break;
257
258 case 'D': // DirectX container file - DXBC
259 if (startswith(Magic, S: "DXBC"))
260 return file_magic::dxcontainer_object;
261 break;
262
263 case 0x41: // ARM64EC windows
264 if (Magic[1] == char(0xA6))
265 return file_magic::coff_object;
266 break;
267
268 case 0x4e: // ARM64X windows
269 if (Magic[1] == char(0xA6))
270 return file_magic::coff_object;
271 break;
272
273 case '_': {
274 const char OBMagic[] = "__CLANG_OFFLOAD_BUNDLE__";
275 if (Magic.size() >= sizeof(OBMagic) && startswith(Magic, S: OBMagic))
276 return file_magic::offload_bundle;
277 break;
278 }
279
280 default:
281 break;
282 }
283 return file_magic::unknown;
284}
285
286std::error_code llvm::identify_magic(const Twine &Path, file_magic &Result) {
287 auto FileOrError = MemoryBuffer::getFile(Filename: Path, /*IsText=*/false,
288 /*RequiresNullTerminator=*/false);
289 if (!FileOrError)
290 return FileOrError.getError();
291
292 std::unique_ptr<MemoryBuffer> FileBuffer = std::move(*FileOrError);
293 Result = identify_magic(Magic: FileBuffer->getBuffer());
294
295 return std::error_code();
296}
297