qemu-e2k/contrib
Viktor Prutyanov d399d6b179 contrib/elf2dmp: add PE name check and Windows Server 2022 support
Since its inception elf2dmp has checked MZ signatures within an
address space above IDT[0] interrupt vector and took first PE image
found as Windows Kernel.
But in Windows Server 2022 memory dump this address space range is
full of invalid PE fragments and the tool must check that PE image
is 'ntoskrnl.exe' actually.
So, introduce additional validation by checking image name from
Export Directory against 'ntoskrnl.exe'.

Signed-off-by: Viktor Prutyanov <viktor@daynix.com>
Tested-by: Yuri Benditovich <yuri.benditovich@daynix.com>
Reviewed-by: Annie Li <annie.li@oracle.com>
Message-id: 20230222211246.883679-4-viktor@daynix.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2023-03-21 13:19:07 +00:00
..
elf2dmp contrib/elf2dmp: add PE name check and Windows Server 2022 support 2023-03-21 13:19:07 +00:00
gitdm contrib/gitdm: add Idan to IBM's group map 2023-03-10 15:54:43 +00:00
ivshmem-client
ivshmem-server
plugins Drop more useless casts from void * to pointer 2022-12-14 16:19:35 +01:00
rdmacm-mux
systemd
vhost-user-blk contrib/vhost-user-blk: Replace lseek64 with lseek 2022-12-21 07:32:24 -05:00
vhost-user-gpu
vhost-user-input
vhost-user-scsi