NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3710 most downloaded on PyPI
Library to instrument executable formats
Last release 2 months ago
12 Jul 2026
Release timing varies
gaps range from 9 days to 4 months
Nearly every release is documented
notes for 36 of 40 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
40 releases · first in 2017
https://lief.re/doc/stable/changelog.html#july-12th-2026
Add support for accessing Enum entries: lief.dwarf.types.Enum.entries() lief::dwarf::types::Enum::entries LIEF::dwarf::types::Enum::entries() lief.dwarf.types.Enum.entries
Add support for reading from or assigning a description ( DW_AT_description ) to a lief.dwarf.Function lief::dwarf::Function lief.dwarf.Function LIEF::dwarf::Function
, lief.dwarf.Variable lief::dwarf::Variable lief.dwarf.Variable LIEF::dwarf::Variable
, or lief.dwarf.LexicalBlock lief::dwarf::LexicalBlock lief.dwarf.LexicalBlock LIEF::dwarf::LexicalBlock
:
lief.dwarf.Function.description() lief::dwarf::Function::description LIEF::dwarf::Function::description() lief.dwarf.Function.description
lief.dwarf.Variable.description() lief::dwarf::Variable::description LIEF::dwarf::Variable::description() lief.dwarf.Variable.description
lief.dwarf.LexicalBlock.description() lief::dwarf::LexicalBlock::description LIEF::dwarf::LexicalBlock::description() lief.dwarf.LexicalBlock.description
Enable the creation of nested lief.dwarf.editor.Function.LexicalBlock lief::dwarf::editor::function::LexicalBlock lief.dwarf.editor.Function.LexicalBlock LIEF::dwarf::editor::Function::LexicalBlock
Add support for generating a C/C++ definition for a whole lief.dwarf.CompilationUnit lief::dwarf::CompilationUnit lief.dwarf.CompilationUnit LIEF::dwarf::CompilationUnit
( lief.dwarf.CompilationUnit.to_decl() lief::dwarf::CompilationUnit::to_decl lief::dwarf::CompilationUnit::to_decl_with_opt lief.dwarf.CompilationUnit.to_decl() LIEF::dwarf::CompilationUnit::to_decl()
). The output of the following to_decl() functions can now be configured through the new lief.DeclOpt lief::DeclOpt lief.DeclOpt LIEF::DeclOpt
structure:
lief.dwarf.Function.to_decl() lief::dwarf::Function::to_decl lief::dwarf::Function::to_decl_with_opt lief.dwarf.Function.to_decl() LIEF::dwarf::Function::to_decl()
lief.dwarf.Variable.to_decl() lief::dwarf::Variable::to_decl lief::dwarf::Variable::to_decl_with_opt lief.dwarf.Variable.to_decl() LIEF::dwarf::Variable::to_decl()
lief.dwarf.Type.to_decl() lief::dwarf::Type::to_decl lief::dwarf::Type::to_decl_with_opt lief.dwarf.Type.to_decl() LIEF::dwarf::Type::to_decl()
lief.dwarf.CompilationUnit.to_decl() lief::dwarf::CompilationUnit::to_decl lief::dwarf::CompilationUnit::to_decl_with_opt lief.dwarf.CompilationUnit.to_decl() LIEF::dwarf::CompilationUnit::to_decl()
import lief dbg = lief . dwarf . load ( "/bin/with_debug" ) opt = lief . DeclOpt () opt . is_cpp = True opt . indentation = 4 for cu in dbg . compilation_units : print ( cu . to_decl ( opt ))
Improve support and the API for LF_ENUM : lief.pdb.types.Enum lief::pdb::types::Enum lief.pdb.types.Enum LIEF::pdb::types::Enum
Improve support and the API for LF_PROCEDURE : lief.pdb.types.Function lief::pdb::types::Function lief.pdb.types.Function LIEF::pdb::types::Function
Improve support and the API for LF_ARRAY : lief.pdb.types.Array lief::pdb::types::Array lief.pdb.types.Array LIEF::pdb::types::Array
Improve support and the API for simple types: lief.pdb.types.Simple lief::pdb::types::Simple lief.pdb.types.Simple LIEF::pdb::types::Simple
Improve support and the API for LF_ONEMETHOD : lief.pdb.types.Method lief::pdb::types::Method lief.pdb.types.Method LIEF::pdb::types::Method
Add support for generating a C/C++ definition for a lief.pdb.Function lief::pdb::Function lief.pdb.Function LIEF::pdb::Function
( lief.pdb.Function.to_decl() lief::pdb::Function::to_decl lief::pdb::Function::to_decl_with_opt lief.pdb.Function.to_decl() LIEF::pdb::Function::to_decl()
) and a lief.pdb.CompilationUnit lief::pdb::CompilationUnit lief.pdb.CompilationUnit LIEF::pdb::CompilationUnit
( lief.pdb.CompilationUnit.to_decl() lief::pdb::CompilationUnit::to_decl lief::pdb::CompilationUnit::to_decl_with_opt lief.pdb.CompilationUnit.to_decl() LIEF::pdb::CompilationUnit::to_decl()
), configurable with the new lief.DeclOpt lief::DeclOpt lief.DeclOpt LIEF::DeclOpt
Add support for DT_AUXILIARY tag: lief.ELF.DynamicEntryAuxiliary lief.ELF.DynamicEntryAuxiliary LIEF::ELF::DynamicEntryAuxiliary lief::elf::dynamic::Auxiliary
( #1159 ).
Add support for DT_FILTER tag: lief.ELF.DynamicEntryFilter lief.ELF.DynamicEntryFilter LIEF::ELF::DynamicEntryFilter lief::elf::dynamic::Filter
Add lief.ELF.parse_from_dump() lief::elf::Binary::parse_from_dump lief.ELF.parse_from_dump() LIEF::ELF::Parser::parse_from_dump()
Add lief.COFF.Section.coff_string lief::coff::Section::coff_string lief.COFF.Section.coff_string LIEF::COFF::Section::coff_string()
Add lief.MachO.FatBinary.create() lief.MachO.FatBinary.create() LIEF::MachO::FatBinary::create()
to create a FAT binary from a list of lief.MachO.Binary lief::macho::Binary lief.MachO.Binary LIEF::MachO::Binary
objects targeting different architectures
Add support for lief.MachO.ThreadLocalVariables lief::macho::ThreadLocalVariables lief.MachO.ThreadLocalVariables LIEF::MachO::ThreadLocalVariables
Add support for editing the runtime tables of the LC_FUNCTION_VARIANTS command and committing the changes on write: lief.MachO.FunctionVariants lief::macho::commands::FunctionVariants lief.MachO.FunctionVariants LIEF::MachO::FunctionVariants
Add a structured parser, editing API and writer for the LC_FUNCTION_VARIANT_FIXUPS command: lief.MachO.FunctionVariantFixups lief::macho::commands::FunctionVariantFixups lief.MachO.FunctionVariantFixups LIEF::MachO::FunctionVariantFixups
Add support for the LC_LAZY_LOAD_DYLIB_INFO command: lief.MachO.LazyLoadDylibInfo lief::macho::commands::LazyLoadDylibInfo lief.MachO.LazyLoadDylibInfo LIEF::MachO::LazyLoadDylibInfo
Add lief.MachO.parse_from_dump() lief::macho::FatBinary::parse_from_dump lief.MachO.parse_from_dump() LIEF::MachO::Parser::parse_from_dump()
Add setters for lief.PE.ImportEntry.iat_value lief::pe::import::ImportEntry::iat_value lief.PE.ImportEntry.iat_value LIEF::PE::ImportEntry::iat_value()
and lief.PE.ImportEntry.ilt_value lief::pe::import::ImportEntry::ilt_value lief.PE.ImportEntry.ilt_value LIEF::PE::ImportEntry::ilt_value()
Add lief.PE.Binary.offset_to_rva() lief::pe::Binary::offset_to_rva lief.PE.Binary.offset_to_rva() LIEF::PE::Binary::offset_to_rva()
to convert a raw offset into a RVA
Add lief.PE.parse_from_dump() lief::pe::Binary::parse_from_dump lief.PE.parse_from_dump() LIEF::PE::Parser::parse_from_dump()
to parse a PE binary from a memory dump
Update lief.Binary.offset_to_virtual_address() lief::generic::Binary::offset_to_virtual_address lief.Binary.offset_to_virtual_address() LIEF::Binary::offset_to_virtual_address()
for PE binaries to return an absolute virtual address instead of a RVA ( #1318 )
Add support for adding an lief.PE.Import lief::pe::import::Import lief.PE.Import LIEF::PE::Import
at a specific position: lief.PE.Binary.add_import() lief::pe::Binary::add_import lief::pe::Binary::add_import_at_pos lief.PE.Binary.add_import() LIEF::PE::Binary::add_import()
( #1298 )
Add support for Objective-C categories ( #1353 ): lief.ObjC.Category lief::objc::Category lief.objc.Category LIEF::objc::Category
, accessible through lief.ObjC.Metadata.categories lief::objc::Metadata::categories lief.objc.Metadata.categories LIEF::objc::Metadata::categories()
Add support for iterating over the operands of MIPS, PowerPC, eBPF and RISC-V instructions ( Register , Immediate , Memory and PCRelative ):
lief.assembly.mips.Instruction.operands() lief::assembly::mips::Instruction::operands lief.assembly.mips.Instruction.operands LIEF::assembly::mips::Instruction::operands()
lief.assembly.powerpc.Instruction.operands() lief::assembly::powerpc::Instruction::operands lief.assembly.powerpc.Instruction.operands LIEF::assembly::powerpc::Instruction::operands()
lief.assembly.ebpf.Instruction.operands() lief::assembly::ebpf::Instruction::operands lief.assembly.ebpf.Instruction.operands LIEF::assembly::ebpf::Instruction::operands()
lief.assembly.riscv.Instruction.operands() lief::assembly::riscv::Instruction::operands lief.assembly.riscv.Instruction.operands LIEF::assembly::riscv::Instruction::operands()
Rust :
Warning The Minimum Supported Rust Version (MSRV) is now 1.85.0 (previously 1.74.0 ).
Add LIEF_LIFETIMEBOUND annotations wrapping [[clang::lifetimebound]] to leverage Clang’s lifetime analysis . This helps detect dangling references at compile time for methods that return references or iterators tied to an object’s lifetime:
// Clang can now warn about this dangling reference: auto & hdr = LIEF :: ELF :: Parser :: parse ( "a.out" ) -> header (); LIEF_INFO ( "{}" , hdr . header_size ()); // /src/src/ELF/Binary.cpp:63:15: error: object whose reference is captured // does not live long enough [-Werror,-Wlifetime-safety-use-after-scope] // 63 | auto& hdr = LIEF::ELF::Parser::parse("a.out")->header(); // | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ // /src/src/ELF/Binary.cpp:63:47: note: destroyed here // 63 | auto& hdr = LIEF::ELF::Parser::parse("a.out")->header(); // | ^ // /src/src/ELF/Binary.cpp:64:19: note: later used here // 64 | LIEF_INFO("{}", hdr.header_size());
Add support for the free-threaded Python builds. The C++ core is now thread-safe with respect to its few static variables, and can be used when the GIL is disabled ( #1255 ):
from concurrent.futures import ThreadPoolExecutor import lief def strip ( path : str ) -> None : binary = lief . ELF . parse ( path ) binary . strip () binary . write ( f " { path } .stripped" ) with ThreadPoolExecutor () as pool : pool . map ( strip , [ "/bin/ls" , "/bin/cat" , "/bin/echo" ])
One column per quarter.
https://lief.re/doc/stable/changelog.html#march-18th-2026
Fix IAT parsing issue by itamarga in PR #1314 )
:ELF:
* Fix alignment for ``PHDR/SHDR`` and improve ``TLS/RELR`` handling (:issue:`1315`)
* Skip ``NOBITS`` sections in layout calculations and improve index retrieval
(related to :issue:`1315`)
:PE:
* Fix IAT parsing issue by :github_user:`itamarga` in PR :pr:`1314`)
See: https://lief.re/doc/stable/changelog.html#march-8th-2026
Fix DyldInfo::show_bindings integer overflow ( #1313 )
https://lief.re/doc/stable/changelog.html#february-21th-2026
Fixed lief.MachO.Binary.virtual_address_to_offset() lief::macho::Binary::virtual_address_to_offset lief.MachO.Binary.virtual_address_to_offset() LIEF::MachO::Binary::virtual_address_to_offset()
to properly handle non-file-backed segments, such as __DATA segments containing only ZEROFILL sections like __bss (by jalopezg-git in PR #1301 , fixing #1299 ).
Bumped various Python backend build dependencies in api/python/build-requirements.txt to support Python 3.14 when compiling from sources ( #1304 ).
https://lief.re/doc/stable/changelog.html#january-24th-2026
Fixed VA/RVA confusion in the PE builder ( #1284 ).
https://lief.re/doc/stable/changelog.html#january-3rd-2026
Fixed major performance issue when parsing certain Mach-O files (by trevor-e , fixing #1262 ).
:Mach-O:
* Differentiate Mach-O FAT magic bytes and Java classes
(by :github_user:`wangmot`, :issue:`1215`).
:Compilation:
* Fixed MinGW compilation for some configurations
(by :github_user:`TheBrokenRail`, :commit:`dabbb72`).
:PE:
* Fixed alignment issue when rebuilding PE relocations (:issue:`1261`).
* Fixed infinite loop when processing v2 dynamic relocations
(by :github_user:`chengyongru`, fixing :issue:`1273`).
:ELF:
* Ensure that added DYN ELF sections are properly aligned
(by :github_user:`schmchrt`, fixing :issue:`1261`).
* Fixed GnuHash null dereference (:issue:`1277`).
:Mach-O:
* Fixed major performance issue when parsing certain Mach-O files
(by :github_user:`trevor-e`, fixing :issue:`1262`).
See: https://lief.re/doc/stable/changelog.html#october-25th-2025
Fixed include issue with the COFF format.
https://lief.re/blog/2025-09-14-lief-0-17-0/
BinaryNinja plugin
Add enum for the latest dyld shared cache version introducing changes in the header layout ( dyld-1284.13 - 2025-04-25 )
uint64_t dynamicDataOffset; uint64_t dynamicDataMaxSize; uint32_t tproMappingsOffset; uint32_t tproMappingsCount; + uint64_t functionVariantInfoAddr; + uint64_t functionVariantInfoSize; + uint64_t prewarmingDataOffset; + uint64_t prewarmingDataSize; };
Add enum for the latest dyld shared cache version introducing changes in the header layout ( dyld-1231.3 - 2024-09-24 )
uint64_t dynamicDataOffset; uint64_t dynamicDataMaxSize; + uint32_t tproMappingsOffset; + uint32_t tproMappingsCount; };
Initial support for lief.MachO.FunctionVariants lief::macho::commands::FunctionVariants lief.MachO.FunctionVariants LIEF::MachO::FunctionVariants
and lief.MachO.FunctionVariantFixups lief::macho::commands::FunctionVariantFixups lief.MachO.FunctionVariantFixups LIEF::MachO::FunctionVariantFixups
commands ( LC_FUNCTION_VARIANTS, LC_FUNCTION_VARIANT_FIXUPS )
Add support for lief.MachO.Note lief::macho::commands::Note lief.MachO.NoteCommand LIEF::MachO::NoteCommand
command ( LC_NOTE )
Add support for lief.MachO.AtomInfo lief::macho::commands::AtomInfo lief.MachO.AtomInfo LIEF::MachO::AtomInfo
command ( LC_ATOM_INFO )
Add support for modifying Mach-O commands that embed variable-length data ( #1204 , #1125 ). See: RPath and Library Path Modification .
Add lief.MachO.Binary.find_library() lief::macho::Binary::find_library lief.MachO.Binary.find_library() LIEF::MachO::Binary::find_library()
To void #define conflicts with Apple SDK, the following enums have been renamed:
Python C++
lief.MachO.FAT_MAGIC + lief.MachO.MAGIC_FAT - lief.MachO.FAT_CIGAM + lief.MachO.CIGAM_FAT - lief.MachO.Symbol.ORIGIN.LC_SYMTAB + lief.MachO.Symbol.ORIGIN.SYMTAB - lief.MachO.Section.TYPE.S_4BYTE_LITERALS + lief.MachO.Section.TYPE.IS_4BYTE_LITERALS - lief.MachO.Section.TYPE.S_8BYTE_LITERALS + lief.MachO.Section.TYPE.IS_8BYTE_LITERALS - lief.MachO.Section.TYPE.S_16BYTE_LITERALS + lief.MachO.Section.TYPE.IS_16BYTE_LITERALS
MACHO_TYPES::MH_MAGIC - MACHO_TYPES::MH_CIGAM - MACHO_TYPES::MH_MAGIC_64 - MACHO_TYPES::MH_CIGAM_64 - MACHO_TYPES::FAT_MAGIC - MACHO_TYPES::FAT_CIGAM + MACHO_TYPES::MAGIC + MACHO_TYPES::CIGAM + MACHO_TYPES::MAGIC_64 + MACHO_TYPES::CIGAM_64 + MACHO_TYPES::MAGIC_FAT + MACHO_TYPES::CIGAM_FAT - Section::TYPE::S_16BYTE_LITERALS + Section::TYPE::IS_16BYTE_LITERALS - Section::TYPE::S_4BYTE_LITERALS + Section::TYPE::IS_4BYTE_LITERALS - Section::TYPE::S_8BYTE_LITERALS + Section::TYPE::IS_8BYTE_LITERALS - Symbol::ORIGIN::LC_SYMTAB + Symbol::ORIGIN::SYMTAB
If an ELF binary uses a custom page size, its value can be defined in the parser configuration: lief.ELF.ParserConfig.page_size lief::elf::ParserConfig::page_size lief.ELF.ParserConfig.page_size LIEF::ELF::ParserConfig::page_size
.
Enhance support for removing segments ( #1233 ): lief.ELF.Binary.remove_segment() lief::elf::Binary::remove_segment lief::elf::Binary::remove_segments_by_type lief.ELF.Binary.remove() void LIEF::ELF::Binary::remove(const Segment &, bool) void LIEF::ELF::Binary::remove(Segment::TYPE, bool)
Add lief.pdb.is_pdb lief::pdb::is_pdb lief.is_pdb() bool LIEF::pdb::is_pdb(const std::std::string &)()
Add support for CodeView symbols: S_COMPILE3, S_COMPILE2, S_BUILDINFO, S_ENVBLOCK . These symbols are exposed through the interface lief.pdb.BuildMetadata lief::pdb::BuildMetadata lief.pdb.BuildMetadata LIEF::pdb::BuildMetadata
, which can be accessed using lief.pdb.CompilationUnit.build_metadata() lief::pdb::CompilationUnit::build_metadata lief.pdb.CompilationUnit.build_metadata LIEF::pdb::CompilationUnit::build_metadata()
. This metadata provides build time information such as:
Module Name : * Linker * Build Metadata: Frontend Version: 0.0.0.0 Backend Version : 14.37.32825.0 Tool Version : Microsoft (R) LINK Language : LINK Target : X64 Environment: cwd: C:\Users\romai\dev\rust\ast-grep exe: C:\Program Files\Microsoft Visual Studio\2022\Community[...] pdb: C:\Users\romai\dev\rust\ast-grep\target\debug\deps\ast_grep.pdb cmd: /NOLOGO /LIBPATH:C:\Users\romai\dev\rust\ast-grep\target[...]
Module Name : std-4ee9ee8805e6ac55.std.ddad90bab7781587-cgu.0.rcgu.o Object : C:\Users\romai\scoop\persist\rustup.rustup\toolchains[...] Build Metadata: Frontend Version: 1.74.0.0 Backend Version : 17004.0.0.0 Tool Version : clang LLVM (rustc version 1.74.0 (79e9716c9 2023-11-13)) Language : RUST Target : X64 Build Info: Current directory: /rustc/79e9716c980570bfd1f666e3b16ac583f0168962 Build tool : C:\a\rust\rust\build\x86_64-pc-windows-msvc\stage1\bin\rustc.exe Source file : library\std\src\lib.rs@\std.ddad90bab7781587-cgu.0 Command line : "-cc1" "--crate-name" "std" "--edition=2021" [...]
Parsing Android OAT files requires to explicitly use lief.OAT.parse()
import lief # Before LIEF 0.17.0 this function returned a lief.OAT.Binary object lief . parse ( "CallDeviceId.oat" ) # Since LIEF 0.17.0 this function returns a lief.ELF.Binary object lief . parse ( "CallDeviceId.oat" ) # Return a lief.OAT.Binary object lief . OAT . parse ( "CallDeviceId.oat" )
Expose lief.abstract.Binary.page_size() lief::generic::Binary::page_size lief.Binary.page_size LIEF::Binary::page_size()
Add lief.abstract.Binary.load_debug_info() lief::generic::Binary::load_debug_info lief.Binary.load_debug_info() LIEF::Binary::load_debug_info()
to attach an external debug file to a lief.abstract.Binary lief::generic::Binary lief.Binary LIEF::Binary
. See these sections for more details: DWARF: Loading an external debug file PDB: Loading an external debug file
Add lief.DebugInfo.find_function_address() lief::generic::DebugInfo::find_function_address lief.DebugInfo.find_function_address() LIEF::DebugInfo::find_function_address()
Add LIEF.dump() lief::dump lief::dump_with_limit lief.dump() LIEF::dump()
:::{admonition} BinaryNinja & Ghidra Plugins :class: tip
LIEF-based plugins for Binary Ninja and Ghidra have been bootstrapped here:
{ref}`Ghidra plugin <plugins-ghidra>`
{ref}`BinaryNinja plugin <plugins-binaryninja>`
::
:::{admonition} LIEF Tools
:class: tip
I initiated a Tools section which aims at providing utilities based on LIEF (mostly CLI):
{ref}`lief-patchelf <tools-lief-patchelf>`
::
```{eval-rst}
Add support for Contextual Assembly Patching
Add enum for the latest dyld shared cache version introducing changes in the header layout (dyld-1284.13 - 2025-04-25)
uint64_t dynamicDataOffset;
uint64_t dynamicDataMaxSize;
uint32_t tproMappingsOffset;
uint32_t tproMappingsCount;
+ uint64_t functionVariantInfoAddr;
+ uint64_t functionVariantInfoSize;
+ uint64_t prewarmingDataOffset;
+ uint64_t prewarmingDataSize;
};
Add enum for the latest dyld shared cache version introducing changes in the header layout (dyld-1231.3 - 2024-09-24)
uint64_t dynamicDataOffset;
uint64_t dynamicDataMaxSize;
+ uint32_t tproMappingsOffset;
+ uint32_t tproMappingsCount;
};
Fix symbol resolution issue: 1127
Please check LIEF 0.17.0 - PE changelog
:github_user:`luadebug` added support for pretty printing OID value and non-roman characters in X509 certificates (see: 1226, 1219)
Initial support for the COFF format: see the COFF section
Initial support for |lief-macho-function-variants-command| and |lief-macho-function-variant-fixups-command| commands (LC_FUNCTION_VARIANTS, LC_FUNCTION_VARIANT_FIXUPS)
Add support for |lief-macho-note-command| command (LC_NOTE)
Add support for |lief-macho-atom-info| command (LC_ATOM_INFO)
Add support for modifying Mach-O commands that embed variable-length data (1204, 1125). See: RPath and Library Path Modification.
# Change library name
for lib in macho.libraries:
lib.name += "/some/path/lib.dylib"
# Change rpath
for rpath in macho.rpaths:
rpath.path += '/a/very/long/path/that/needs/expansion'
Add |lief-macho-binary-find_library|
To void #define conflicts with Apple SDK, the following enums have been renamed:
LIEF newly-inserted sections are now compatible with a strip after the modification of the binary (see: Adding a section/segment)
Enhance support for IA64 architecture.
Introduce lief.ELF.Segment.raw_flags to access the raw (integer) value of the flag
If an ELF binary uses a custom page size, its value can be defined in the parser configuration: |lief-elf-parser-config-page_size|.
Add support for SH4
Add suport for x32/ILP32 ELF binaries (1225)
Add support for S390x
Better endianess support when writing back a binary.
Enhance support for removing segments (1233): |lief-elf-binary-remove-segment|
Enhance support for removing or modifying symbol versions (related to the lief-patchelf initiative)
New doc section: Symbol Versions
New doc section: R[UN]PATH Modification
LIEF extended can now process DWARF debug info in PE binaries
Add support for creating DWARF: DWARF Editor (require extended version >= 0.17.0.2623)
Add |lief-pdb-is_pdb|
Add support for CodeView symbols: S_COMPILE3, S_COMPILE2, S_BUILDINFO, S_ENVBLOCK. These symbols are exposed through the interface |lief-pdb-buildmetadata|, which can be accessed using |lief-pdb-compilationunit-buildmetadata|. This metadata provides build time information such as:
Module Name : * Linker *
Build Metadata:
Frontend Version: 0.0.0.0
Backend Version : 14.37.32825.0
Tool Version : Microsoft (R) LINK
Language : LINK
Target : X64
Environment:
cwd: C:\Users\romai\dev\rust\ast-grep
exe: C:\Program Files\Microsoft Visual Studio\2022\Community\[...]
pdb: C:\Users\romai\dev\rust\ast-grep\target\debug\deps\ast_grep.pdb
cmd: /NOLOGO /LIBPATH:C:\Users\romai\dev\rust\ast-grep\target\[...]
Module Name : std-4ee9ee8805e6ac55.std.ddad90bab7781587-cgu.0.rcgu.o
Object : C:\Users\romai\scoop\persist\rustup\.rustup\toolchains\[...]
Build Metadata:
Frontend Version: 1.74.0.0
Backend Version : 17004.0.0.0
Tool Version : clang LLVM (rustc version 1.74.0 (79e9716c9 2023-11-13))
Language : RUST
Target : X64
Build Info:
Current directory: /rustc/79e9716c980570bfd1f666e3b16ac583f0168962
Build tool : C:\a\rust\rust\build\x86_64-pc-windows-msvc\stage1\bin\rustc.exe
Source file : library\std\src\lib.rs\@\std.ddad90bab7781587-cgu.0
Command line : "-cc1" "--crate-name" "std" "--edition=2021" [...]
Parsing Android OAT files requires to explicitly use lief.OAT.parse
import lief
# Before LIEF 0.17.0 this function returned a lief.OAT.Binary object
lief.parse("CallDeviceId.oat")
# Since LIEF 0.17.0 this function returns a lief.ELF.Binary object
lief.parse("CallDeviceId.oat")
# Return a lief.OAT.Binary object
lief.OAT.parse("CallDeviceId.oat")
Expose |lief-abstract-binary-page_size|
Add |lief-abstract-binary-load_debug_info| to attach an external debug file to a |lief-abstract-binary|. See these sections for more details: DWARF: Loading an external debug file PDB: Loading an external debug file
Add |lief-debug-info-find_function_address|
Fix issue in the Python bindings while trying to access lief.__LIEF_MAIN_COMMIT__
Fix CMake issue with find_package(lief-extended)
Use LLVM 21.1.x
LIEF is now available in vcpkg. Many thanks to :github_user:`luadebug` for this support.
Move to tl-expected 1.2.0
Move to utfcpp 4.0.6
Move to mbedtls 3.6.4
Move to spdlog 1.15.3
Move to nlohmann/json 3.12.0
Upgrade nanobind to version v2.8.x
Add |lief-dump|
```
Python : - Add wheels for Python 3.14 Mach-O : - Fix has_nx ( #1218 ) - Fix #1228 ELF : - Fix #1241 Other : -
#1220
See: https://lief.re/doc/stable/changelog.html#may-29th-2025
See: https://lief.re/doc/stable/changelog.html#may-29th-2025
#1216
See: https://lief.re/doc/stable/changelog.html#april-19th-2025
See: https://lief.re/doc/stable/changelog.html#april-19th-2025
Compared to previous releases, this release adds new pre-compiled packages for:
Modifications on lief.MachO.EncryptionInfo lief::macho::commands::EncryptionInfo lief.MachO.EncryptionInfo LIEF::MachO::EncryptionInfo
Add Python, Rust, SDK packages for Linux Musl i686 ( i686-unknown-linux-musl )
See: https://lief.re/doc/stable/changelog.html#february-23rd-2025
See: https://lief.re/doc/stable/changelog.html#february-23rd-2025
Fix truncated nlist_t.n_type when rewriting a Mach-O binary
See: https://lief.re/doc/stable/changelog.html#february-1st-2025
See: https://lief.re/doc/stable/changelog.html#february-1st-2025
Add support for spdlog compiled with SPDLOG_WCHAR_FILENAMES ( #1147 )
https://lief.re/doc/stable/changelog.html#january-1st-2025
https://lief.re/doc/stable/changelog.html#january-1st-2025
Fix broken aarch64 Python wheel which is related to a toolchain issue ( #1146 )
https://lief.re/doc/stable/changelog.html#december-26th-2024
https://lief.re/doc/stable/changelog.html#december-26th-2024
Fix missing LIEF_API visibility ( e01f92a , #1140 )
:MachO:
* Various fixes from :github_user:`DzenIsRich` & :github_user:`peledins-zimperium`
Thanks to them, Mach-O modification is more reliable.
* Fix issue when building with ``-DLIEF_MACHO=ON`` (see: :issue:`1138`)
:Rust:
* Fix min-rustc version issue (see: :commit:`75a27f0e`)
:Compilation:
* Fix missing ``LIEF_API`` visibility (:commit:`e01f92a0`, :pr:`1140`)
https://lief.re/doc/stable/changelog.html#december-10th-2024
https://lief.re/doc/stable/changelog.html#december-10th-2024
Add LIEF.get_int_from_virtual_address() lief::elf::Binary::get_int_from_virtual_address lief.Binary.get_int_from_virtual_address() LIEF::Binary::get_int_from_virtual_address()
to read an integer value at a specific virtual address
C++
LIEF :: Binary & bin ; uint16_t short_value = bin . get_int_from_virtual_address < uint16_ > ( 0x140002CC8 );
Python
some_bin : lief . Binary = ... long_value = some_bin . get_int_from_virtual_address ( 0x140002CC8 , 4 ) # or long_value = some_bin . get_int_from_virtual_address ( 0x140002CC8 , ctypes . sizeof ( ctypes . c_uint32 ))
Rust
elf : & lief :: elf :: Binary let value : i16 = elf . get_int_from_virtual_address :: < i16 > ( 0x401126 ). unwrap ();
Global code cleaning (especially, lief.Header.ARCHITECTURES lief.Header.ARCHITECTURES LIEF::Header::ARCHITECTURES
and lief.Header.MODES lief.Header.MODES LIEF::Header::MODES
is now more meaningful)
Re-scope lief.ARCHITECTURES into lief.Header.ARCHITECTURES lief.Header.ARCHITECTURES LIEF::Header::ARCHITECTURES
Re-scope lief.MODES into lief.Header.MODES lief.Header.MODES LIEF::Header::MODES
Re-scope lief.OBJECT_TYPES into lief.Header.OBJECT_TYPES lief.Header.OBJECT_TYPES LIEF::Header::OBJECT_TYPES
Re-scope lief.ENDIANNESS into lief.Header.ENDIANNESS lief.Header.ENDIANNESS LIEF::Header::ENDIANNESS
Add helpers to determine the platform targeted by a Mach-O binary:
lief.MachO.Binary.is_ios() lief::macho::Binary::is_ios lief.MachO.Binary.is_ios LIEF::MachO::Binary::is_ios()
lief.MachO.Binary.is_macos() lief::macho::Binary::is_macos lief.MachO.Binary.is_macos LIEF::MachO::Binary::is_macos()
lief.MachO.Binary.platform() lief::macho::Binary::platform lief.MachO.Binary.platform LIEF::MachO::Binary::platform()
Expose an iterator over the stub entries located in __stubs,__auth_stubs,__symbol_stub,__picsymbolstub4 :
lief.MachO.Binary.symbol_stubs() lief::macho::Binary::symbol_stubs lief.MachO.Binary.symbol_stubs LIEF::MachO::Binary::symbol_stubs()
lief.MachO.Stub lief::macho::Stub lief.MachO.Stub LIEF::MachO::Stub
Add support for the LC_SUBCLIENT command: lief.MachO.SubClient lief::macho::commands::SubClient lief.MachO.SubClient LIEF::MachO::SubClient
Add support for the LC_ROUTINE/LC_ROUTINE64 command: lief.MachO.Routine lief::macho::commands::Routine lief.MachO.Routine LIEF::MachO::Routine
Expose an iterator for the indirect symbols in lief.MachO.DynamicSymbolCommand lief::macho::commands::DynamicSymbolCommand lief.MachO.DynamicSymbolCommand LIEF::MachO::DynamicSymbolCommand
Add lief.MachO.Binary.bindings() lief::macho::Binary::bindings lief.MachO.Binary.bindings LIEF::MachO::Binary::bindings()
to iterate over the bindings info located in lief.MachO.DyldInfo lief::macho::commands::DyldInfo lief.MachO.DyldInfo LIEF::MachO::DyldInfo
or lief.MachO.ChainedBindingInfo lief::macho::binding_info::Chained lief.MachO.ChainedBindingInfo LIEF::MachO::ChainedBindingInfo
Add lief.MachO.IndirectBindingInfo lief::macho::binding_info::Indirect lief.MachO.IndirectBindingInfo LIEF::MachO::IndirectBindingInfo
to represent a binding operation inferred from the indirect symbol table.
This can be handy if a Mach-O does not have the commands lief.MachO.DyldInfo lief::macho::commands::DyldInfo lief.MachO.DyldInfo LIEF::MachO::DyldInfo
or lief.MachO.ChainedBindingInfo lief::macho::binding_info::Chained lief.MachO.ChainedBindingInfo LIEF::MachO::ChainedBindingInfo
Add lief.ELF.Relocation.resolve() lief::elf::Relocation::resolve lief::elf::Relocation::resolve_with_base_address lief.ELF.Relocation.resolve() LIEF::ELF::Relocation::resolve()
to resolve the value of relocations
Add support for GNU_PROPERTY_AARCH64_FEATURE_PAUTH GNU property note: lief.ELF.AArch64PAuth lief.ELF.AArch64PAuth LIEF::ELF::AArch64PAuth
.
Add lief.ELF.Binary.is_targeting_android lief::elf::Binary::is_targeting_android lief.ELF.Binary.is_targeting_android LIEF::ELF::Binary::is_targeting_android()
to check if an ELF targets Android
Mutable API are progressively introduced:
ELF:
PE:
MachO:
The header-like generation ( lief.ObjC.Metadata.to_decl() lief::objc::Metadata::to_decl lief.objc.Metadata.to_decl() LIEF::objc::Metadata::to_decl()
) is now including method’s address as a comment:
Before
@interface GCKUIImageHints < NSCopying , NSSecureCoding > { long long _imageType ; NSObject < NSSecureCoding > * _customData ; struct CGSize _imageSize ; } + ( bool ) supportsSecureCoding : ( GCKUIImageHints * ) self : ( SEL ) id ; - ( bool ) isEqual: ( GCKUIImageHints * ) self : ( SEL ) id : ( NSObject * ) arg2 ;
After
@interface GCKUIImageHints < NSCopying , NSSecureCoding > { long long _imageType ; NSObject < NSSecureCoding > * _customData ; struct CGSize _imageSize ; } // Address: 0x00001aa448 + ( bool ) supportsSecureCoding : ( GCKUIImageHints * ) self : ( SEL ) id ; // Address: 0x00001aa5ec - ( bool ) isEqual: ( GCKUIImageHints * ) self : ( SEL ) id : ( NSObject * ) arg2 ;
Fix lief.ObjC.Method.address() lief::objc::Method::address lief.objc.Method.address LIEF::objc::Method::address()
for small methods.
The output of lief.ObjC.Metadata.to_decl() lief::objc::Metadata::to_decl_with_opt lief.objc.Metadata.to_decl() LIEF::objc::Metadata::to_decl()
can now be configured with lief.ObjC.DeclOpt lief::objc::DeclOpt lief.objc.DeclOpt LIEF::objc::DeclOpt
Add lief.dwarf.Function.is_external() lief::dwarf::Function::is_external lief.dwarf.Function.is_external LIEF::dwarf::Function::is_external()
Add lief.dwarf.CompilationUnit.imported_functions() lief::dwarf::CompilationUnit::imported_functions lief.dwarf.CompilationUnit.imported_functions LIEF::dwarf::CompilationUnit::imported_functions()
Add DW_TAG_typedef support Extended :
Rust package is now available
lief.ELF.Symbol.demangled_name() lief::elf::Symbol::demangled_name lief.ELF.Symbol.demangled_name LIEF::ELF::Symbol::demangled_name()
is working on all platforms (not only unix-based builds)
lief.MachO.Symbol.demangled_name() lief::macho::Symbol::demangled_name lief.MachO.Symbol.demangled_name LIEF::MachO::Symbol::demangled_name()
is working on all platforms (not only unix-based builds)
lief.PE.DelayImportEntry.demangled_name() lief::pe::delay_import::DelayImportEntry::demangled_name lief.PE.DelayImportEntry.demangled_name LIEF::PE::DelayImportEntry::demangled_name()
lief.PE.ImportEntry.demangled_name() lief::pe::import::ImportEntry::demangled_name lief.PE.ImportEntry.demangled_name LIEF::PE::ImportEntry::demangled_name()
lief.PE.ExportEntry.demangled_name() lief::pe::export::Entry::demangled_name lief.PE.ExportEntry.demangled_name LIEF::PE::ExportEntry::demangled_name()
pe = lief . PE . parse ( "some.exe" ) if exp := pe . get_export (): for entry in exp . entries : # e.g.void __cdecl Platform::Details::EventSourceUninitialize(void **) print ( entry . demangled_name ) for imp in pe . imports : for entry in imp . entries : # e.g. void __cdecl std::_Xlength_error(char const *) print ( entry . demangled_name )
Add LIEF.demangle() lief::demangle lief.demangle() LIEF::demangle()
to demangle symbols (c.f. #1054 )
Add cross-api menu directive. For instance, this link : lief.dwarf.DebugInfo lief::dwarf::DebugInfo lief.dwarf.DebugInfo LIEF::dwarf::DebugInfo
toggles a menu to access the documentation of DWARF’s debug info for Rust, Python & C++.
See https://lief.re/doc/stable/changelog.html#july-23th-2024
See https://lief.re/doc/stable/changelog.html#july-23th-2024
See: https://lief.re/doc/stable/changelog.html#july-21th-2024
See: https://lief.re/doc/stable/changelog.html#july-21th-2024
Extended :
Note See: https://extended.lief.re and What is LIEF Extended?
Add support to create custom notes ( #1026 ):
elf : lief . ELF . Binary = ... elf += lief . ELF . Note . create ( name = "my-custom-note" , original_type = lief . ELF . Note . TYPE . UNKNOWN , description = list ( b "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed" ), section_name = ".lief.note.custom" ) config = lief . ELF . Builder . config_t () config . notes = True elf . write ( "/tmp/new-binary.elf" , config )
The static_symbols API functions has been renamed in symtab_symbols .
LIEF was naming symbols located in the .symtab sections as static symbols in opposition to the .dynsym symbols. This naming can be confusing since the concept of static symbol in a program is well defined (i.e. static bool my_var ) and not applicable in this case.
Therefore, the xxx_static_symbols API is has been renamed xxx_symtab_symbol.
Authenticode: Add partial support for the following PKCS #7 attributes:
1.2.840.113549.1.9.16.2.47 - SIGNING_CERTIFICATE_V2 ( lief.PE.SigningCertificateV2 )
Move lief.PE.OptionalHeader.computed_checksum to lief.PE.Binary.compute_checksum()
In previous versions of LIEF, lief.PE.OptionalHeader.checksum was re-computed (on purpose) in the parsing phase. On large binaries, this re-computation can have a strong impact on the performances. Thus, this computation has been deferred to a dedicated method lief.PE.Binary.compute_checksum()
pe = lief . PE . parse ( "..." ) # Before: computed = pe . optional_header . computed_checksum # Now: computed = pe . compute_checksum ()
Add lief.disable_leak_warning() to disable Nanobind warning about “leaks”.
Include inheritance diagram for Python API (e.g. lief.ELF.Note )
https://lief-project.github.io/doc/stable/changelog.html#february-11th-2024
https://lief-project.github.io/doc/stable/changelog.html#february-11th-2024
Address #1016 by creating aliases:
Fix regression in iterator’s performances
LIEF v0.14.0: https://lief-project.github.io/doc/stable/changelog.html#january-20-2024
LIEF v0.14.0: https://lief-project.github.io/doc/stable/changelog.html#january-20-2024
Add support for the GNU note properies ( #975 ). Example :
elf = lief . ELF . parse ( "..." ) note = elf . get ( lief . ELF . Note . TYPE . GNU_PROPERTY_TYPE_0 ) aarch64_feat : lief . ELF . AArch64Feature = note . find ( lief . ELF . NoteGnuProperty . Property . TYPE . AARCH64_FEATURES ) if lief . ELF . AArch64Feature . FEATURE . BTI in aarch64_feat . features : print ( "BTI supported" )
See:
Add a lief.ELF.ParserConfig interface that can be used to tweak which parts of the ELF format should be parsed. Example :
config = lief . ELF . ParserConfig () # Skip parsing static and dynamic symbols config . parse_static_symbols = False config . parse_dyn_symbols = False elf = lief . ELF . parse ( "target.elf" , config )
SECTION_CHARACTERISTICS is now scoped within the Section class instead of being globally defined:
DATA_DIRECTORY is now scoped within the DataDirectory class instead of being globally defined:
MACHINE_TYPES and HEADER_CHARACTERISTICS are now scoped within the Header class instead of being globally defined:
SUBSYSTEM and DLL_CHARACTERISTICS are now scoped within the OptionalHeader class instead of being globally defined:
Refactoring of the Debug directory processing: lief.PE.Debug is now the root class of: lief.PE.CodeView / lief.PE.CodeView , lief.PE.Pogo , lief.PE.Repro .
The parsing logic has been cleaned and the tests updated.
Add a lief.PE.ParserConfig interface that can be used to tweak which parts of the PE format should be parsed ( #839 ). Example :
config = lief . PE . ParserConfig () # Skip parsing PE authenticode config . parse_signature = False pe = lief . PE . parse ( "pe.exe" , config )
All the Binary classes now implement classof :
std :: unique_ptr < LIEF :: Binary > bin = LIEF :: Parser :: parse ( "..." ); if ( LIEF :: PE :: Binary :: classof ( bin . get ())) { auto & pe_file = static_cast < LIEF :: PE :: Binary &> ( * bin ); }
The Python documentation for properties now contains the type of the property.
Changelog https://lief-project.github.io/doc/stable/changelog.html#june-17-2023
Changelog https://lief-project.github.io/doc/stable/changelog.html#june-17-2023
PE : Fix authenticode inconsitency ( #932 ) ELF : Fix missing undef ( #929 )
See: https://lief-project.github.io/doc/stable/changelog.html#may-28-2023
See: https://lief-project.github.io/doc/stable/changelog.html#may-28-2023
Fix AArch64 docker image ( #904 )
https://lief-project.github.io/blog/2023-04-09-lief-0-13-0/
https://lief-project.github.io/blog/2023-04-09-lief-0-13-0/
Add support for modifying section-less binaries. The ELF Section objects gain the lief.ELF.Section.as_frame() method which defines the section as a framed section.
A framed section is a section that concretely does not wraps data and can be corrupted. Example :
elf = lief . parse ( "/bin/ssh" ) text = elf . get_section ( ".text" ) . as_frame () # We can now corrupt all the fields of the section text . offset = 0xdeadc0de text . size = 0xffffff text . address = 0x123 elf . write ( "/tmp/out" )
Add API to precisely define how the segments table should be relocated. One might want to enforce a certain ELF layout while adding sections/ segments. It is now possible to call the method: relocate_phdr_table() to define how the segments table should be relocated for welcoming the new sections/segments:
elf = lief . parse ( "..." ) # Enforce a specific relocation type: # The new segments table will be shift at the end # of the file elf . relocate_phdr_table ( Binary . PHDR_RELOC . FILE_END ) # Add sections/segments # [...] elf . write ( "out.elf" )
See:
lief.ELF.Binary.PHDR_RELOC
Add API to get a Section from a specified segment’s name and section’s name. Example :
sec = bin . get_section ( "__DATA" , "__objc_metadata" )
Add API to remove a Section from a specified segment’s name and section’s name. Example :
sec = bin . remove_section ( "__DATA" , "__objc_metadata" )
Move to utfcpp 3.2.1
This is a security fix release:
This is a security fix release:
https://lief-project.github.io/doc/stable/changelog.html#november-1-2022
This release contains several security fixes:
[CVE-2022-38307] Fix a segfault when the Mach-O binary does not have segments (found by CCWANG19 via #764 )
This release contains several security fixes:
- [CVE-2022-38497] Fix ELF core parsing issue ({issue}
766found by {github_user}CCWANG19)- [CVE-2022-38306] Fix a heap overflow found by {github_user}
CCWANG19({issue}763)- Fix a memory issue (found by {github_user}
bladchanvia {issue}806)- [CVE-2022-40923] Fix parsing issue ({issue}
784found by {github_user}bladchan)- [CVE-2022-40922] Fix parsing issue ({issue}
781found by {github_user}bladchan)- [CVE-2022-38307] Fix a segfault when the Mach-O binary does not have segments (found by {github_user}
CCWANG19via {issue}764)
Nothing published for this version
See: https://lief-project.github.io/doc/stable/changelog.html#april-08-2022
See: https://lief-project.github.io/doc/stable/changelog.html#april-08-2022
Nightly builds are now upload to Saleway’s S3 server:
Fix GLIBCXX_USE_CXX11_ABI=1 ABI issue (see: #683 )
Changelog is here: https://lief-project.github.io/doc/latest/changelog.html#march-25-2022
Changelog is here: https://lief-project.github.io/doc/latest/changelog.html#march-25-2022
Enhance the ELF parser to support corner cases described by netspooky in :
Clcanny improved (see #507 and #509 ) the reconstruction of the dynamic symbol table by sorting local symbols and non-exported symbols. It fixes the following warning when parsing a modified binary with readelf
Warning: local symbol 29 found at index >= .dynsym's sh_info value of 1
The API to configure the MachO parser has been redesigned to provide a better granularity
config = lief . MachO . ParserConfig () config . parse_dyld_bindings = False config . parse_dyld_exports = True config . parse_dyld_rebases = False lief . MachO . parse ( "/tmp/big.macho" , config )
Add API to select a Binary from a FatBinary by its architecture. See: lief.MachO.FatBinary.take() .
fat = lief . MachO . parse ( "/bin/ls" ) fit = fat . take ( lief . MachO . CPU_TYPES . x86_64 )
Enable to recompute the RichHeader (issue: #587 )
Add support for PE’s delayed imports. see:
Enable to use a pre-compiled version of spdlog. This feature aims at improving compilation time when developing on LIEF.
One can provide path to spdlog install through:
$ python ./setup.py --spdlog-dir = path/to/lib/cmake/spdlog [ ... ] # or $ cmake -DLIEF_EXTERNAL_SPDLOG = ON -Dspdlog_DIR = path/to/lib/cmake/spdlog ...
New section about how to compile LIEF for debugging/developing. See: Debugging General Design : span : LIEF now exposes Section/Segment’s data through a span interface. As std::span is available in the STL from C++20 and the LIEF public API aims at being C++11 compliant, we expose this span thanks to tcbrindle/span . This new interface enables to avoid copies of std::vector<uint8_t> which can be costly. With this new interface, the original std::vector<uint8_t> can be retrieved as follows:
auto bin = LIEF :: ELF :: Parser :: parse ( "/bin/ls" ); if ( const auto * section = bin -> get_section ( ".text" )) { LIEF :: span < const uint8_t > text_ref = section -> content (); std :: vector < uint8_t > copy = { std :: begin ( text_ref ), std :: end ( text_ref )}; }
In Python, span are wrapped by a read-only memory view . The original list of bytes can be retrieved as follows:
bin = lief . parse ( "/bin/ls" ) section = bin . get_section ( ".text" ) if section is not None : memory_view = section . content list_of_bytes = list ( memory_view )
Exceptions :
Warning We started to refactor the API and the internal design to remove C++ exceptions. These changes are described a the dedicated blog ( LIEF RTTI & Exceptions ) To highlighting the content of the blog for the end users, functions that returned a reference and which threw an exception in the case of a failure are now returning a pointer that is set to nullptr in the case of a failure. If we consider this original code:
LIEF :: MachO :: Binary & bin = ...; try { LIEF :: MachO :: UUIDCommand & cmd = bin . uuid (); std :: cout << cmd << " \n " ; } catch ( const LIEF :: not_found & ) { // ... dedicated processing } // Other option with has_uuid() if ( bin . has_uuid ()) { LIEF :: MachO :: UUIDCommand & cmd = bin . uuid (); std :: cout << cmd << " \n " ; }
It can now be written as:
LIEF :: MachO :: Binary & bin = ...; if ( LIEF :: MachO :: UUIDCommand * cmd = bin . uuid ();) { std :: cout << * cmd << " \n " ; } else { // ... dedicated processing as it is a nullptr } // Other option with has_uuid() if ( bin . has_uuid ()) { // It ensures that it is not a nullptr LIEF :: MachO :: UUIDCommand & cmd = * bin . uuid (); std :: cout << cmd << " \n " ; }
List of the functions that changed
```{eval-rst}
:github_user:`ahaensler` added the support to insert and assign a lief.ELF.SymbolVersionAuxRequirement (see: 670)
Enhance the ELF parser to support corner cases described by netspooky in :
https://tmpout.sh/2/14.html (84 byte aarch64 ELF)
https://tmpout.sh/2/3.html (Some ELF Parser Bugs)
New ELF Builder which is more efficient in terms of speed and in terms of number of segments added when modifying binaries (see: https://lief-project.github.io/blog/2022-01-23-new-elf-builder/)
:github_user:`Clcanny` improved (see 507 and 509) the reconstruction of the dynamic symbol table by sorting local symbols and non-exported symbols. It fixes the following warning when parsing a modified binary with readelf
Warning: local symbol 29 found at index >= .dynsym's sh_info value of 1
Change the layout of the binaries generated by LIEF such as they are compliant with codesign checks
The API to configure the MachO parser has been redesigned to provide a better granularity
config = lief.MachO.ParserConfig()
config.parse_dyld_bindings = False
config.parse_dyld_exports = True
config.parse_dyld_rebases = False
lief.MachO.parse("/tmp/big.macho", config)
:github_user:`LucaMoroSyn` added the support for the LC_FILESET_ENTRY. This command is usually found in kernel cache files
LIEF::MachO::Binary::get_symbol now returns a pointer (instead of a reference). If the symbol can't be found, it returns a nullptr.
Add API to select a ~lief.MachO.Binary from a ~lief.MachO.FatBinary by its architecture. See: lief.MachO.FatBinary.take.
fat = lief.MachO.parse("/bin/ls")
fit = fat.take(lief.MachO.CPU_TYPES.x86_64)
Handle the 0x0D binding opcode (see: 524)
:github_user:`xhochy` fixed performances issues in the Mach-O parser (see 579)
Adding lief.PE.OptionalHeader.computed_checksum that re-computes the lief.PE.OptionalHeader.checksum (c.f. issue 660)
Enable to recompute the ~lief.PE.RichHeader (issue: 587)
~lief.PE.RichHeader.raw
~lief.PE.RichHeader.hash
Add support for PE's delayed imports. see:
~lief.PE.DelayImport / ~lief.PE.DelayImportEntry
~lief.PE.Binary.delay_imports
lief.PE.LoadConfiguration.reserved1 has been aliased to lief.PE.LoadConfiguration.dependent_load_flags
lief.PE.LoadConfiguration.characteristics has been aliased to lief.PE.LoadConfiguration.size
Thanks to :github_user:`gdesmar`, we updated the PE checks to support PE files that have a corrupted lief.PE.OptionalHeader.magic (cf. 644)
:github_user:`DanielFi` added support for DEX's fields (see: 547)
Abstract binary imagebase for PE, ELF and Mach-O (lief.Binary.imagebase)
Add lief.Binary.offset_to_virtual_address
Add PE imports/exports as abstracted symbols
:github_user:`ekilmer` updated and modernized the CMake integration files through the PR: 674
Enable to use a pre-compiled version of spdlog. This feature aims at improving compilation time when developing on LIEF.
One can provide path to spdlog install through:
$ python ./setup.py --spdlog-dir=path/to/lib/cmake/spdlog [...]
# or
$ cmake -DLIEF_EXTERNAL_SPDLOG=ON -Dspdlog_DIR=path/to/lib/cmake/spdlog ...
Enable to feed LIEF's dependencies externally (c.f. lief_third_party)
Replace the keywords and, or, not with &&, || and !.
Upgrade to MbedTLS 3.1.0
Upgrade Catch2 to 2.13.8
The different dependencies can be linked externally (cf. above and lief_third_party)
New section about the errors handling (err_handling) and the upcoming deprecation of the exceptions.
New section about how to compile LIEF for debugging/developing. See: lief_debug
LIEF now exposes Section/Segment's data through a span interface. As std::span is available in the STL from C++20 and the LIEF public API aims at being C++11 compliant, we expose this span thanks to tcbrindle/span. This new interface enables to avoid copies of std::vector<uint8_t> which can be costly. With this new interface, the original std::vector<uint8_t> can be retrieved as follows:
auto bin = LIEF::ELF::Parser::parse("/bin/ls");
if (const auto* section = bin->get_section(".text")) {
LIEF::span<const uint8_t> text_ref = section->content();
std::vector<uint8_t> copy = {std::begin(text_ref), std::end(text_ref)};
}
In Python, span are wrapped by a read-only memory view. The original list of bytes can be retrieved as follows:
bin = lief.parse("/bin/ls")
section = bin.get_section(".text")
if section is not None:
memory_view = section.content
list_of_bytes = list(memory_view)
Warning
We started to refactor the API and the internal design to remove C++ exceptions. These changes are described a the dedicated blog (LIEF RTTI & Exceptions)
To highlighting the content of the blog for the end users, functions that returned a reference and which threw an exception in the case of a failure are now returning a pointer that is set to nullptr in the case of a failure.
If we consider this original code:
LIEF::MachO::Binary& bin = ...;
try {
LIEF::MachO::UUIDCommand& cmd = bin.uuid();
std::cout << cmd << "\n";
} catch (const LIEF::not_found&) {
// ... dedicated processing
}
// Other option with has_uuid()
if (bin.has_uuid()) {
LIEF::MachO::UUIDCommand& cmd = bin.uuid();
std::cout << cmd << "\n";
}
It can now be written as:
LIEF::MachO::Binary& bin = ...;
if (LIEF::MachO::UUIDCommand* cmd = bin.uuid();) {
std::cout << *cmd << "\n";
} else {
// ... dedicated processing as it is a nullptr
}
// Other option with has_uuid()
if (bin.has_uuid()) { // It ensures that it is not a nullptr
LIEF::MachO::UUIDCommand& cmd = *bin.uuid();
std::cout << cmd << "\n";
}
```
Nothing published for this version
Nothing published for this version
Nothing published for this version
See: https://lief.quarkslab.com/doc/stable/changelog.html#february-22-2021
See: https://lief.quarkslab.com/doc/stable/changelog.html#february-22-2021
See: https://lief.quarkslab.com/blog/2021-02-22-lief-0-11-1/
See: https://lief.quarkslab.com/blog/2021-02-22-lief-0-11-1/
See: https://lief.quarkslab.com/doc/stable/changelog.html#v0.11.0
See: https://lief.quarkslab.com/doc/stable/changelog.html#v0.11.0
get_imphash() can now generate the same value as pefile and Virus Total ( #299 )
pe = lief . parse ( "example.exe" ) vt_imphash = lief . PE . get_imphash ( pe , lief . PE . IMPHASH_MODE . PEFILE ) lief_imphash = lief . PE . get_imphash ( pe , lief . PE . IMPHASH_MODE . DEFAULT )
See also lief.PE.IMPHASH_MODE and lief.PE.get_imphash()
FindLIEF.cmake deprecates LIEF_ROOT . You should use LIEF_DIR instead. Logging : We changed the logging interface. The following log levels have been removed:
LOG_UNKNOWN We also moved from an class-interface based to functions.
Example:
lief . logging . disable () lief . logging . enable () lief . logging . set_level ( lief . logging . LEVEL . INFO )
See: lief.logging.set_level()
Note The log functions now output on stderr instead of stdout
```{eval-rst}
:github_user:`mkomet` updated enums related to Android (see: 9dd641d380a5defd0a71a9f42dde2fe9c9cb1dbd)
:github_user:`aeflores` added MIPS relocations support in the ELF parser
Fix ~lief.ELF.Binary.extend on a ELF section (cf. issue 477)
Fix issue when exporting symbols on empty-gnu-hash ELF binary (1381f9a115e6e312ac0ab3deb46a78e481b81796)
Fix reconstruction issue when the binary is prelinked (cf. issue 466)
Add DF_1_PIE flag
Fix parsing issue of the .eh_frame section when the base address is not 0.
:github_user:`JanuszL` enhanced the algorithm that computes the string table. It moves from a N^2 algorithm to a Nlog(N) (1e0c4e81d4a3fd7282713f111193e42f198f8967).
Fix .eh_frame parsing issue (b57f32333a85d0f172206bc5d20aabe2d7942738)
:github_user:`aeflores` fixed parsing issue in ELF relocations (6c53646bb790acf28f2999527eafad30db7d6b69)
Add PT_GNU_PROPERTY enum
Bug fix in the symbols table reconstruction (ELF)
Enhance PE Authenticode. See PE Authenticode
~lief.PE.get_imphash can now generate the same value as pefile and Virus Total (299)
pe = lief.parse("example.exe")
vt_imphash = lief.PE.get_imphash(pe, lief.PE.IMPHASH_MODE.PEFILE)
lief_imphash = lief.PE.get_imphash(pe, lief.PE.IMPHASH_MODE.DEFAULT)
Remove the padding entry (0) from the rich header
lief.PE.LangCodeItem.items now returns a dictionary for which the values are bytes (instead of str object). This change is related to utf-16 support.
:github_user:`kohnakagawa` fixed wrong enums values: c03125045e32a9cd65c613585eb4d0385350c6d2, 6ee808a1e4611d09c6cf0aea82a612be69584db9, cd05f34bae681fc8af4b5e7cc28eaef816802b6f
:github_user:`kohnakagawa` fixed a bug in the PE resources parser (a7254d1ba935783f16effbc7faddf993c57e82f7)
Handle PE forwarded exports (issue 307)
Add API to access either LC_CODE_SIGNATURE or DYLIB_CODE_SIGN_DRS (issue 476)
Fix issue when parsing twice a Mach-O file (issue 479)
Replace easyloggingpp with spdlog 1.8.1
Upgrade frozen to 1.0.0
Upgrade json to 3.7.3
Upgrade pybind11 to 2.6.0
Upgrade mbedtls to 2.16.6
:github_user:`aguinet` updated the bin2lib tutorial with the support of the new glibc versions (7884e57aa1d103f3bd37682e47f412bfe7a3aa34)
Global update and enable to build the documentation out-of-tree
Changing the theme
Add Python 3.9 support
FindLIEF.cmake deprecates LIEF_ROOT. You should use LIEF_DIR instead.
We changed the logging interface. The following log levels have been removed:
LOG_GLOBAL
LOG_FATAL
LOG_VERBOSE
LOG_UNKNOWN
We also moved from an class-interface based to functions.
Example:
lief.logging.disable()
lief.logging.enable()
lief.logging.set_level(lief.logging.LEVEL.INFO)
See: lief.logging.set_level
Note
The log functions now output on stderr instead of stdout
```
- Fix regression in parsing Python bytes - Add Python API to demangle strings: lief.demangle
Add Python API to demangle strings: lief.demangle
ELF : - Add build support for ELF notes - Add coredump support ( 9fc3a8a ) - Enable to bind a relocation with a symbol ( a9f3cb8 ) Example :
Enable to bind a relocation with a symbol ( a9f3cb8 ) Example :
relocation = "..." symbol = lief . ELF . Symbol () symbol . name = "printf123" relocation . symbol = symbol
Enhance Mach-O modifications by exposing an API to:
Add segments See: 406115c
Thanks to lkollar , Linux CI now produces manylinux1-compliant wheels Many thanks to the contributors: recvfrom , pbrunet , mackncheesiest , wisk , nezetic , lkollar , jbremer , DaLynX , 1orenz0 , breadchris , 0xbf00 , unratito , strazzere , aguinetqb , mingwandroid , serge-sans-paille-qb , yrp604 , majin42 , KOLANICH
:ELF:
* Add build support for ELF notes
* Add coredump support (:commit:`9fc3a8a43358f608cf18ddbe341e1d94b13cb9e0`)
* Enable to bind a relocation with a symbol (:commit:`a9f3cb8f9b4a1f2cdaa95eee4568ff0b162f77cd`)
:Example:
.. code-block:: python
relocation = "..."
symbol = lief.ELF.Symbol()
symbol.name = "printf123"
relocation.symbol = symbol
* Add constructors (:commit:`67d924a2206c36cb9979d8b1b194b03b2d592e71`)
* Expose ELF destructors (:commit:`957384cd361c4a485470f877658af2bf052dbe0a`)
* Add ``remove_static_symbol`` (:commit:`c6779702b1fec3c67b0c19a36576830fe18bd9d9`)
* Add support for static relocation writing (:commit:`d1b98d69ade662e2471ce2905bf3fb247dfc3143`)
* Expose function to get strings located in the ``.rodata`` section (:commit:`02f4851c9f0c2bfa6fb4f51dab393a1db83b4851`)
* Export ELF ABI version (:commit:`8d7ec26a93800b0729c2c05be8c55c8318ba3b20`)
:PE:
* Improve PE Authenticode parsing (:commit:`535623de3aa4f8ddc34536331b802e2cbdc44faf`)
* Fix alignment issue when removing a PE section (:commit:`04dddd371080d731fab965b127cb15a91c57d53c`)
* Parse PE debug data directory as a list of debug entries (by :github_user:`1orenz0` - :commit:`fcc75dd87982e52d77a1c7ee7e674741a199e41b`)
* Add support to parse POGO debug entries (by :github_user:`1orenz0` - :commit:`3537440b8d0da6c9c3d00c25f7da8a04f29154d2`)
:Mach-O:
* Enhance Mach-O modifications by exposing an API to:
- Add load commands
- Add sections
- Add segments
See: :commit:`406115c8d097da0b61f00b2bb7b2442322ffc5d1`
* Enable ``write()`` on FAT Mach-O (:commit:`16595316fd588619ea39b942817d6527e0601fbd`)
* Introduce Mach-O Build Version command (:commit:`6f967238fcd369210839605ab08c30d647a09a65`)
* Enable to remove Mach-O symbols (:commit:`616d739da513092e9ab7446654414b0929d5d5cf`)
* Add support for adding ``LC_UNIXTHREAD`` commands in a MachO (by :github_user:`nezetic` - :commit:`64d2597284149441fc734b251648ca917cd816e3`)
:Abstract Layer:
* Expose ``remove_section()`` in the abstract layer (:commit:`918438c6bee52c8421d809bc3b42974165e5fa0b`)
* Expose ``write()`` in the abstract layer (:commit:`af4d48ed2e1f1b96687644f2fc4661fcbdb979a6`)
* Expose API to list functions found in a binary (:commit:`b5a08463ad63811e9e9432812406aadd74ab8c09`)
:Android:
* Add partial support for Android 9 (:commit:`bce9ebe17064b1ca16b00dc14eebb5d5dd440184`)
:Misc:
* :github_user:`lkollar` added support for Python 3.8 in CI (Linux & OSX only)
* Update Pybind11 dependency to ``v2.4.3``
* Enhance Python install
* Thanks to :github_user:`lkollar`, Linux CI now produces **manylinux1-compliant wheels**
Many thanks to the contributors: {github_user}recvfrom, {github_user}pbrunet,
{github_user}mackncheesiest, {github_user}wisk, {github_user}nezetic,
{github_user}lkollar, {github_user}jbremer, {github_user}DaLynX, {github_user}1orenz0,
{github_user}breadchris, {github_user}0xbf00, {github_user}unratito, {github_user}strazzere,
{github_user}aguinetqb, {github_user}mingwandroid, {github_user}serge-sans-paille-qb, {github_user}yrp604,
{github_user}majin42, {github_user}KOLANICH
LIEF 0.9 comes with new formats related to Android: OAT, DEX, VDEX and ART. It also fixes bugs and thanks to yd0b0N , ELF parser now supports big and
LIEF 0.9 comes with new formats related to Android: OAT, DEX, VDEX and ART. It also fixes bugs and thanks to yd0b0N , ELF parser now supports big and little endian binaries. We also completed the JSON serialization of LIEF objects.
Endianness support: e794ac1
Parser now returns a std::unique_ptr instead of a raw pointer: cd1cc45
Use frozen for some internal std::map (If C++14 is supported by the compiler)
illera88 for #118
LIEF 0.9 comes with new formats related to Android: OAT, DEX, VDEX and ART. It also fixes bugs and thanks to {github_user}`yd0b0N`, ELF parser now supports big and little endian binaries. We also completed the JSON serialization of LIEF objects.
### Features
```{eval-rst}
Enable to configure the Mach-O parser for quick parsing: 880b99aeef825786dd65aed286d7c4d23b62f564
Add lief.MachO.EncryptionInfo command: f4e2d81bfe84238d463bdb65297c296635e783b1
Add lief.MachO.RPathCommand command: 196994dc089885ff2f1268e51f5514f7fcbc5cff
Add lief.MachO.DataInCode command: a16e1c4d13c7071fabe6a5a46b6d6c0fd9565b72
Add lief.MachO.SubFramework command: 9e3b5b45f78cc075f2192c245247af00b88b5e3c
Add lief.MachO.SegmentSplitInfo command: 9e3b5b45f78cc075f2192c245247af00b88b5e3c
Add lief.MachO.DyldEnvironment command: 9e3b5b45f78cc075f2192c245247af00b88b5e3c
API to show export-trie, rebase and binding opcodes: 5d56141061bfc27e3c971e9e474dc86fdaf0c6a9
Add PE Code View: eab4a7614fdf6e9a180b1c638903310da0b83118
Add support for .note.android.ident section: d13db18214006ce654b723a882f70c3d7eabd20d
Enable to add unlimited number of dynamic entries: a40da3e3b4b985b18a6e6026d594f524b7bae963
Add support for PPC relocations: 08b514191f661eeabbdf8ecacd1d7dd35a67ca54
Endianness support: e794ac1502ee7636755bd441923368f88525a7d0
```
### API
> - {func}`lief.breakp` and {func}`lief.shell` > - {func}`lief.parse` now support io streams as input > - Parser now returns a std::unique_ptr instead of a raw pointer: {commit}`cd1cc457cf3d63cfc5faa945657887200cedb8b3`
### Misc
Use [frozen](https://github.com/serge-sans-paille/frozen) for some internal std::map (If C++14 is supported by the compiler)
### Acknowledgments
{github_user}`yd0b0N` for {pr}`162` and {pr}`166` (Endianness support and PPC relocations)
{github_user}`0xbf00` for {pr}`128` (LC_RPATH command)
{github_user}`illera88` for {pr}`118`
- [Mach-O] Fix typo on comparison operator - abbc264
[Mach-O] Fix typo on comparison operator - abbc264
abbc264833894973f601f700b3abcc109904f722- [ELF] Increase the upper limit of relocation number - 077bc32
[ELF] Increase the upper limit of relocation number - 077bc32
077bc329bdcc249cb8ed0b8bcb9630e1c9eede94Minor fixes. See changelog
Minor fixes. See changelog
Add assertion on the setuptools version: 62e5825
8db199c04e9e6bcdbda165ab5c42d88218a0beb662e5825e27bb637c2f42f4d05690a100213beb03LIEF version 0.8.0 - Changelog
LIEF version 0.8.0 - Changelog
LIEF 0.8.0 mainly improves the MachO parser and the ELF builder. It comes with Dockerfiles for CentOS and Android . LibFuzzer has also been integrated in the project to enhance the parsers
Global enhancement of the ELF builder:
One can now add multiple Section or Segment into an ELF:
elf = lief . parse ( "/bin/cat" ) for i in range ( 3 ): segment = Segment () segment . type = SEGMENT_TYPES . LOAD segment . content = [ i & 0xFF ] * 0x1000 elf += segment for i in range ( 3 ): section = Section ( "lief_ {:02d} " . format ( i )) section . content = [ i & 0xFF ] * 0x1000 elf += section elf . write ( "foo" )
$ readelf -l ./foo PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040 0x00000000000061f8 0x00000000000061f8 R E 0x8 INTERP 0x0000000000006238 0x0000000000006238 0x0000000000006238 0x000000000000001c 0x000000000000001c R 0x1 [Requesting program interpreter: /lib64/ld-linux-x86-64.so.2] LOAD 0x0000000000000000 0x0000000000000000 0x0000000000000000 0x000000000000d6d4 0x000000000000d6d4 R E 0x200000 LOAD 0x000000000000da90 0x000000000020da90 0x000000000020da90 0x0000000000000630 0x00000000000007d0 RW 0x200000 LOAD 0x000000000000f000 0x000000000040f000 0x000000000040f000 0x0000000000001000 0x0000000000001000 0x1000 LOAD 0x0000000000010000 0x0000000000810000 0x0000000000810000 0x0000000000001000 0x0000000000001000 0x1000 LOAD 0x0000000000011000 0x0000000001011000 0x0000000001011000 0x0000000000001000 0x0000000000001000 0x1000 .... $ readelf -S ./foo ... [27] lief_00 PROGBITS 0000000002012000 00012000 0000000000001000 0000000000000000 0 0 4096 [28] lief_01 PROGBITS 0000000004013000 00013000 0000000000001000 0000000000000000 0 0 4096 [29] lief_02 PROGBITS 0000000008014000 00014000 0000000000001000 0000000000000000 0 0 4096
Warning There are issues with executables statically linked with libraries that use TLS See: #98
One can now add multiple entries in the dynamic table:
elf = lief . parse ( "/bin/cat" ) elf . add_library ( "libfoo.so" ) elf . add ( DynamicEntryRunPath ( "$ORIGIN" )) elf . add ( DynamicEntry ( DYNAMIC_TAGS . INIT , 123 )) elf . add ( DynamicSharedObject ( "libbar.so" )) elf . write ( "foo" )
$ readelf -d foo 0x0000000000000001 (NEEDED) Shared library: [libfoo.so] 0x0000000000000001 (NEEDED) Shared library: [libc.so.6] 0x000000000000000c (INIT) 0x7b 0x000000000000000c (INIT) 0x3600 ... 0x000000000000001d (RUNPATH) Bibliothèque runpath:[$ORIGIN] 0x000000000000000e (SONAME) Bibliothèque soname: [libbar.so]
See b94900c , 1e410e6 for details.
b2d3694 enables modification of the ELF interpreter without length restriction
elf = lief . parse ( "/bin/cat" ) elf . interpreter = "/a/very/long/path/to/another/interpreter" elf . write ( "foo" )
$ readelf -l foo Program Headers: Type Offset VirtAddr PhysAddr FileSiz MemSiz Flags Align PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040 0x00000000000011f8 0x00000000000011f8 R E 0x8 INTERP 0x000000000000a000 0x000000000040a000 0x000000000040a000 0x0000000000001000 0x0000000000001000 R 0x1 [Requesting program interpreter: /a/very/long/path/to/another/interpreter] ....
Enable editing ELF’s notes:
elf = lief . parse ( "/bin/ls" ) build_id = elf [ NOTE_TYPES . BUILD_ID ] build_id . description = [ 0xFF ] * 20 elf . write ( "foo" )
$ readelf -n foo Displaying notes found in: .note.gnu.build-id Owner Data size Description GNU 0x00000014 NT_GNU_BUILD_ID (unique build ID bitstring) Build ID: ffffffffffffffffffffffffffffffffffffffff
Parse the Load Config Table into LoadConfiguration (up to Windows 10 SDK 15002 with hotpatch_table_offset )
from lief import to_json import json pe = lief . parse ( "some.exe" ) loadconfig = to_json ( pe . load_configuration )) # Using the lief.to_json function pprint ( json . loads ( to_json ( loadconfig )))
{ 'characteristics' : 248 , 'code_integrity' : { 'catalog' : 0 , 'catalog_offset' : 0 , 'flags' : 0 , 'reserved' : 0 }, 'critical_section_default_timeout' : 0 , 'csd_version' : 0 , 'editlist' : 0 , ... 'guard_cf_check_function_pointer' : 5368782848 , 'guard_cf_dispatch_function_pointer' : 5368782864 , 'guard_cf_function_count' : 15 , 'guard_cf_function_table' : 5368778752 , 'guard_flags' : 66816 , 'guard_long_jump_target_count' : 0 , 'guard_long_jump_target_table' : 0 , 'guard_rf_failure_routine' : 5368713280 , 'guard_rf_failure_routine_function_pointer' : 5368782880 , ...
The dyld structure is parsed (deeply) into DyldInfo . It includes:
Export trie See: e2b81e0 , 0e972d6 , f7cc518 , 782295b , #67
LC_THREAD and LC_UNIXTHREAD are now parsed into ThreadCommand - 2325783
Fix memory leaks and some performance issues: #94
[Python API] Enhance the access to the abstract layer through the abstract attribute - 0713854
One can now do:
elf = lief . ELF . parse ( "/bin/ls" ) # Could be lief.MachO / lief.PE abstract = elf . abstract # Return the lief.Binary object
Add:
hexagon_flags_list to Header - 730d045
To check if a given flag is set, one can do:
if lief . ELF . ARM_EFLAGS . EABI_VER5 in lief . ELF . Header "yes" else "no"
Add some operators : cbe8354 Logging : Add an API to configure the logger - 4600c2b
Example:
from lief import Logger Logger . disable () Logger . enable () Logger . set_level ( lief . LEVEL . INFO )
See: lief.Logger
Add LibFuzzer - 7a0dc28
recomposer, bearparser, IAT_patcher, PEframe, Manalyze, MachOView, elf-dissector
Manouchehri for #106
LIEF 0.8.0 mainly improves the MachO parser and the ELF builder. It comes with [Dockerfiles](https://github.com/lief-project/Dockerlief) for [CentOS](https://github.com/lief-project/Dockerlief/blob/v0.1.0/dockerlief/dockerfiles/centos.docker) and [Android](https://github.com/lief-project/Dockerlief/blob/v0.1.0/dockerlief/dockerfiles/android.docker).
[LibFuzzer](https://llvm.org/docs/LibFuzzer.html) has also been integrated in the project to enhance the parsers
### Features
```{eval-rst}
~lief.Relocation are now abstracted from the 3 formats - 9503f2fc7b6c14bebd4c220bda4a243d87f14bd1
PIE and NX are abstracted through the ~lief.Binary.is_pie and ~lief.Binary.has_nx properties
Add the lief.Section.search and lief.Section.search_all methods to look for patterns in the section's content.
DT_FLAGS and DT_FLAGS_1 are now parsed into ~lief.ELF.DynamicEntryFlags - 754b8afa2b41993e6c37d2d9003cebdccc641d23
Handle relocations of object files (.o) - 483b8dc2eabee3da29ce5e5ff2e25c2a3c9ca297
Global enhancement of the ELF builder:
One can now add multiple ~lief.ELF.Section or ~lief.ELF.Segment into an ELF:
elf = lief.parse("/bin/cat")
for i in range(3):
segment = Segment()
segment.type = SEGMENT_TYPES.LOAD
segment.content = [i & 0xFF] * 0x1000
elf += segment
for i in range(3):
section = Section("lief_{:02d}".format(i))
section.content = [i & 0xFF] * 0x1000
elf += section
elf.write("foo")
$ readelf -l ./foo
PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040
0x00000000000061f8 0x00000000000061f8 R E 0x8
INTERP 0x0000000000006238 0x0000000000006238 0x0000000000006238
0x000000000000001c 0x000000000000001c R 0x1
[Requesting program interpreter: /lib64/ld-linux-x86-64.so.2]
LOAD 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x000000000000d6d4 0x000000000000d6d4 R E 0x200000
LOAD 0x000000000000da90 0x000000000020da90 0x000000000020da90
0x0000000000000630 0x00000000000007d0 RW 0x200000
LOAD 0x000000000000f000 0x000000000040f000 0x000000000040f000
0x0000000000001000 0x0000000000001000 0x1000
LOAD 0x0000000000010000 0x0000000000810000 0x0000000000810000
0x0000000000001000 0x0000000000001000 0x1000
LOAD 0x0000000000011000 0x0000000001011000 0x0000000001011000
0x0000000000001000 0x0000000000001000 0x1000
....
$ readelf -S ./foo
...
[27] lief_00 PROGBITS 0000000002012000 00012000
0000000000001000 0000000000000000 0 0 4096
[28] lief_01 PROGBITS 0000000004013000 00013000
0000000000001000 0000000000000000 0 0 4096
[29] lief_02 PROGBITS 0000000008014000 00014000
0000000000001000 0000000000000000 0 0 4096
Warning
There are issues with executables statically linked with libraries that use TLS
See: 98
One can now add multiple entries in the dynamic table:
elf = lief.parse("/bin/cat")
elf.add_library("libfoo.so")
elf.add(DynamicEntryRunPath("$ORIGIN"))
elf.add(DynamicEntry(DYNAMIC_TAGS.INIT, 123))
elf.add(DynamicSharedObject("libbar.so"))
elf.write("foo")
$ readelf -d foo
0x0000000000000001 (NEEDED) Shared library: [libfoo.so]
0x0000000000000001 (NEEDED) Shared library: [libc.so.6]
0x000000000000000c (INIT) 0x7b
0x000000000000000c (INIT) 0x3600
...
0x000000000000001d (RUNPATH) Bibliothèque runpath:[$ORIGIN]
0x000000000000000e (SONAME) Bibliothèque soname: [libbar.so]
See b94900ca7f500912bfe249cd534055942e28e34b, 1e410e6c950c391f0d1a3f12cb6f8e4c9fb16539 for details.
b2d36940f60eacfa602c115cb542e11c70b6841c enables modification of the ELF interpreter without length restriction
elf = lief.parse("/bin/cat")
elf.interpreter = "/a/very/long/path/to/another/interpreter"
elf.write("foo")
$ readelf -l foo
Program Headers:
Type Offset VirtAddr PhysAddr
FileSiz MemSiz Flags Align
PHDR 0x0000000000000040 0x0000000000000040 0x0000000000000040
0x00000000000011f8 0x00000000000011f8 R E 0x8
INTERP 0x000000000000a000 0x000000000040a000 0x000000000040a000
0x0000000000001000 0x0000000000001000 R 0x1
[Requesting program interpreter: /a/very/long/path/to/another/interpreter]
....
Enhancement of the dynamic symbols counting - 985d1249b72494a0e62f34042b3c9cbfa0706e90
Enable editing ELF's notes:
elf = lief.parse("/bin/ls")
build_id = elf[NOTE_TYPES.BUILD_ID]
build_id.description = [0xFF] * 20
elf.write("foo")
$ readelf -n foo
Displaying notes found in: .note.gnu.build-id
Owner Data size Description
GNU 0x00000014 NT_GNU_BUILD_ID (unique build ID bitstring)
Build ID: ffffffffffffffffffffffffffffffffffffffff
See commit 3be9dd0ff58ec68cb8813e01d6798c16b42dac22 for more details
Add ~lief.PE.get_imphash and ~lief.PE.resolve_ordinals functions - a89bc6df4f242d7641292acdb184927449d14fff, dfa8e985c0561427a20088750693a004de587b1c
Parse the Load Config Table into ~lief.PE.LoadConfiguration (up to Windows 10 SDK 15002 with hotpatch_table_offset)
from lief import to_json
import json
pe = lief.parse("some.exe")
loadconfig = to_json(pe.load_configuration)) # Using the lief.to_json function
pprint(json.loads(to_json(loadconfig)))
{'characteristics': 248,
'code_integrity': {'catalog': 0,
'catalog_offset': 0,
'flags': 0,
'reserved': 0},
'critical_section_default_timeout': 0,
'csd_version': 0,
'editlist': 0,
...
'guard_cf_check_function_pointer': 5368782848,
'guard_cf_dispatch_function_pointer': 5368782864,
'guard_cf_function_count': 15,
'guard_cf_function_table': 5368778752,
'guard_flags': 66816,
'guard_long_jump_target_count': 0,
'guard_long_jump_target_table': 0,
'guard_rf_failure_routine': 5368713280,
'guard_rf_failure_routine_function_pointer': 5368782880,
...
For details, see commit: 0234e3b8bbb6f6f3490392f8c295fde284a99334
The dyld structure is parsed (deeply) into ~lief.MachO.DyldInfo. It includes:
Binding opcodes
Rebases opcodes
Export trie
See: e2b81e0a8e187cae5f0f115241243a84ee7696b6, 0e972d69ce35731867d82c047eef7eb9ea58e3ec, f7cc518dcfbb0557fd8d396144bf99a222d96705, 782295bfb86d2a12584c5b16a37a26d56d1ee235, 67
Section relocations are now parsed into lief.MachO.Section.relocations - 29c8157ecc3b308bd521cb1daee3c2e3a2cffb28
LC_FUNCTION_STARTS is parsed into ~lief.MachO.FunctionStarts (18d89198a0cc63ff291ae9110f465354c3b8f1e6)
LC_SOURCE_VERSION, LC_VERSION_MIN_MACOSX and LC_VERSION_MIN_IPHONEOS are parsed into ~lief.MachO.SourceVersion and ~lief.MachO.VersionMin (c359778194db874669884aaccb52a4b05546bc07, 0b4bb7d56520cd0ea08bbcb9530e5e0c96ac14ae, 5b993117ed391db18ba775cabefa5f3981b2f1cc, 45)
LC_THREAD and LC_UNIXTHREAD are now parsed into ~lief.MachO.ThreadCommand - 23257830b291c40a3aed92360040f2b0b11ffa72
```
### Fixes
Fix enums conflicts({issue}`32`) - {commit}`66b4cd4550ecf6cf3adb4900e6ad7ac33f1f7f32`
Fix most of the memory leaks: {commit}`88dafa8db6e752393f69d73f68d295e91963b8da`, {commit}`d9b1436730b5d33a753e7dfa4301697a0c676066`, {commit}`554fa153af943b97a16fc4a52ab8459a3d0a9bc7`, {commit}`3602643f5d02a1c78c4de609cc47f193f3a8840f`
```{eval-rst}
Bug Fix when counting dynamic symbols from the GnuHash Table - 9036a2405dc44726f40cb77cab1bcbf371ab7a70
Fix nullptr dereference in resources - e90fe1b6c6f6a605390bcd1026435ce7503e7e6a
Handle encoding issues in the Python API - 8c7ceaf
Sanitize DLL names
Fix 87, 92
Fix memory leaks and some performance issues: 94
```
### API
In the C++ API get_XXX() getters have been renamed into XXX() (e.g. get_header() becomes header()) - {commit}`a4c69f7868da1de5d09aa26e977dedb720e36cbd`, {commit}`e805669865b130057413f456958a471d8f0ac0b1`
```{eval-rst}
lief.Binary gains the ~lief.Binary.format property - 9391238f114fe963890777c2d8b90f2caaa5510c
lief.parse can now takes a list of integers - f330fa887d14d47f0683144430ac9695d3136561
Add ~lief.Binary.has_symbol and ~lief.Binary.get_symbol to lief.Binary - f121af5ca61a22fd83acc5c7094b50ed1cda8226
[Python API] Enhance the access to the abstract layer through the ~lief.Binary.abstract attribute - 07138549a46db87c7b924fd072356030b1d5c6bc
One can now do:
elf = lief.ELF.parse("/bin/ls") # Could be lief.MachO / lief.PE
abstract = elf.abstract # Return the lief.Binary object
Relocation gains the ~lief.ELF.Relocation.purpose property - b7b0bde4d51c54d8d226e5320b1b0d2cc48137c4
Add lief.ELF.Binary.symbols which return an iterator over all symbols (static and dynamic) - af6ab65dc91169627f4fbb87cda92093eb699a1e
Header.sizeof_section_header has been renamed into ~lief.ELF.Header.section_header_size - d96971b0c3f8ff50add349957f571b8daa00708a
Segment.flag has been renamed into ~lief.ELF.Segment.flags - 20a5f666deb89b06b79a1c4418ac938497fb658c
Add:
~lief.ELF.Header.arm_flags_list,
~lief.ELF.Header.mips_flags_list
~lief.ELF.Header.ppc64_flags_list
~lief.ELF.Header.hexagon_flags_list
to ~lief.ELF.Header - 730d045e05dca7ef3cd6a51d1175f280be356c70
To check if a given flag is set, one can do:
>>> if lief.ELF.ARM_EFLAGS.EABI_VER5 in lief.ELF.Header "yes" else "no"
[Python] Segment flags: PF_X, PF_W, PF_X has been renamed into ~lief.ELF.SEGMENT_FLAGS.X, ~lief.ELF.SEGMENT_FLAGS.W, ~lief.ELF.SEGMENT_FLAGS.X - d70ef9ec2c42619434352dbd7b74a835ebad7569
Add lief.ELF.Section.flags_list - 4937b7193a5760df85d0ac1567afc011a22cdb98
Enhancement for ~lief.ELF.DynamicEntryRpath and ~lief.ELF.DynamicEntryRunPath: c375a47da7c4c524e886f9238f8dd51a44501087
Enhancement for ~lief.ELF.DynamicEntryArray: 81440ce00cdfc793161a0dc394ada345307dc24b
Add some operators 3b200b30503847be4779447c76f5207d18daf77f, 43bd06f8f32196454ee2305201f4e27b3a3c8a1e
Add some operators 5666351e07b7bf4a9624033f670d02b8806d2663
lief.MachO.parse can now takes a list of integers - f330fa887d14d47f0683144430ac9695d3136561
lief.MachO.parse now returns a ~lief.MachO.FatBinary instead of a list of ~lief.MachO.Binary. ~lief.MachO.FatBinary has a similar API as a list - 3602643f5d02a1c78c4de609cc47f193f3a8840f
Add some operators: cbe835484751396daffe7f8d238cbb85d66470ab
Add an API to configure the logger - 4600c2ba8d7d17b5965c2b74faeb7e4d2128de17
Example:
from lief import Logger
Logger.disable()
Logger.enable()
Logger.set_level(lief.LEVEL.INFO)
See: lief.Logger
```
### Build system
Add [FindLIEF.cmake](https://github.com/lief-project/LIEF/blob/e8ac976c994f6612e8dcca994032403c2d6f580f/scripts/FindLIEF.cmake) - {commit}`6dd8b10325e832a7520bf5ae3a588b9e022d0345`
Add ASAN, TSAN, USAN, LSAN - {commit}`7f6aeb0d0d74eae886f4b312e12e8f71e1d5da6a`
Add LibFuzzer - {commit}`7a0dc28ea29a30209e944ebcde27f7c0ab234651`
### Documentation
```{eval-rst}
recomposer, bearparser, IAT_patcher, PEframe, Manalyze, MachOView, elf-dissector
```
### Acknowledgments
{github_user}`alvarofe` for {pr}`47`
{github_user}`aguinet` for {pr}`55`, {pr}`61`, {pr}`65`, {pr}`77`
{github_user}`jevinskie` for {pr}`75`
{github_user}`liumuqing` for {pr}`80`
{github_user}`Manouchehri` for {pr}`106`
Your coding agent can read these notes before it upgrades. Set up the MCP server →