1 2#------------------------------------------------------------------------------ 3# $File: coff,v 1.16 2026/04/20 14:53:18 christos Exp $ 4# coff: file(1) magic for Common Object Files not specific to known cpu types or manufactures 5# 6# COFF 7# 8# by Joerg Jenderek at Oct 2015, Feb 2021, Mar 2024 9# https://en.wikipedia.org/wiki/COFF 10# https://de.wikipedia.org/wiki/Common_Object_File_Format 11# http://www.delorie.com/djgpp/doc/coff/filhdr.html 12# https://learn.microsoft.com/en-us/windows/win32/debug/pe-format#coff-file-header-object-and-image 13# https://formats.kaitai.io/uefi_te/index.html 14 15# Display COFF processor type, including MS COFF and PE/COFF 160 name display-coff-processor 17# PE/COFF, DJGPP, i386 COFF executable, MS Windows COFF Intel i386 object file (./intel) 18>0 uleshort 0x014c Intel i386 19>0 uleshort 0x014d Intel i860 20>0 uleshort 0x0160 MIPS R3000 (big-endian) 21>0 uleshort 0x0162 MIPS R3000 22>0 uleshort 0x0166 MIPS R4000 23>0 uleshort 0x0168 MIPS R10000 24>0 uleshort 0x0169 MIPS WCE v2 25>0 uleshort 0x0184 Alpha 32-bit 26>0 uleshort 0x01a2 Hitachi SH3 27>0 uleshort 0x01a3 Hitachi SH3 DSP 28>0 uleshort 0x01a4 Hitachi SH4E 29>0 uleshort 0x01a6 Hitachi SH4 30>0 uleshort 0x01a8 Hitachi SH5 31>0 uleshort 0x01c0 ARMv4 32>0 uleshort 0x01c2 ARMv4T 33>0 uleshort 0x01c4 ARMv7 34>0 uleshort 0x01d3 Matsushita AM33 35# executable (RISC System/6000 V3.1) or obj module (./ibm6000 v 1.15), not PE/COFF 36>0 uleshort 0x01df RISC System/6000 37>0 uleshort 0x01f0 PowerPC 32-bit (little-endian) 38>0 uleshort 0x01f1 PowerPC 32-bit with FPU (little-endian) 39>0 uleshort 0x01f2 PowerPC 64-bit (big-endian) 40>0 uleshort 0x0200 Intel Itanium 41>0 uleshort 0x0266 MIPS16 42>0 uleshort 0x0268 Motorola 68000 43>0 uleshort 0x0284 Alpha 64-bit 44>0 uleshort 0x0290 PA-RISC 45>0 uleshort 0x0366 MIPS with FPU 46>0 uleshort 0x0466 MIPS16 with FPU 47# Hitachi SH big-endian COFF (./hitachi-sh), not PE/COFF 48>0 uleshort 0x0500 Hitachi SH (big-endian) 49>0 uleshort 0x0520 Tricore 50# Hitachi SH little-endian COFF (./hitachi-sh), not PE/COFF 51>0 uleshort 0x0550 Hitachi SH (little-endian) 52>0 uleshort 0x0601 PowerPC 32-bit (big-endian) 53# Windows CE 3.0 Common Executable Format, created by linkcef.exe with /MACHINE:CEF flag 54# https://web.archive.org/web/20000819035046/http://microsoft.com/windows/embedded/ce/downloads/cef.asp 55# https://web.archive.org/web/20000914080342/http://microsoft.com/windows/embedded/ce/developer/applications/appdevelopment/cef2.asp 56# https://web.archive.org/web/20021022055906/http://msdn.microsoft.com/library/en-us/dnce30/html/cef2.asp 57>0 uleshort 0x0cef Common Executable Format 58>0 uleshort 0x0ebc EFI byte code 59>0 uleshort 0x3a64 ARM64 (i386 ABI) 60>0 uleshort 0x5032 RISC-V 32-bit 61>0 uleshort 0x5064 RISC-V 64-bit 62>0 uleshort 0x5128 RISC-V 128-bit 63>0 uleshort 0x6232 LoongArch 32-bit 64>0 uleshort 0x6264 LoongArch 64-bit 65>0 uleshort 0x8664 x86-64 66>0 uleshort 0x9041 Mitsubishi M32R 67>0 uleshort 0xa641 ARM64 (x86-64 ABI) 68>0 uleshort 0xa64e ARM64 (classic + x86-64 ABI) 69# PE/COFF ARM64 classic ABI, ARM COFF (./arm) 70>0 uleshort 0xaa64 ARM64 71# Processor type OMNI is for OMNI VM, for example used by omniprox.dll and can be created by MSVC6.0 CVTRES.EXE with /MACHINE:OMNI flag 72>0 uleshort 0xace1 OMNI VM 73# Processor type CEE can be only in object files (created by older ilasm.exe with /OBJECT flag), not in PE executables 74>0 uleshort 0xc0ee COM+ Execution Engine 75>0 default x Unknown processor 76>>0 uleshort x 0x%04x 77 78# display name+variables+flags of Common Object Files Format (32bit) 79# Maybe used also in adi,att3b,clipper,hitachi-sh,hp,ibm6000,intel, 80# mips,motorola,msdos,osf1,sharc,varied.out,vax 810 name display-coff 82# test for unused flag bits (0x8000,x0080) in f_flags 83# flag bits (0x0800,0x0400,0x0200) now seems to be used in RISC System/6000 V3.1 84>18 uleshort&0x8080 0 85# skip DOCTOR.DAILY READER.NDA REDBOX.ROOT by looking for positive number of sections 86>>2 uleshort >0 87# skip ega80woa.fnt svgafix.fnt HP3FNTS1.DAT HP3FNTS2.DAT INTRO.ACT LEARN.PIF by looking for low number of sections 88>>>2 uleshort <4207 89# f_magic - magic number 90>>>>0 use display-coff-processor 91>>>>0 uleshort x COFF 92# F_EXEC flag bit 93>>>>18 leshort ^0x0002 object file 94!:mime application/x-coff 95!:ext o/obj/lib 96# no cof sample found 97#!:ext cof/o/obj/lib 98>>>>18 leshort &0x0002 executable 99#!:mime application/x-coffexec 100!:mime application/x-coff-executable 101# typically no file name suffix for executables 102!:ext / 103# F_RELFLG flag bit,static object 104>>>>18 leshort &0x0001 \b, no relocation info 105# F_LNNO flag bit 106>>>>18 leshort &0x0004 \b, no line number info 107# F_LSYMS flag bit 108>>>>18 leshort &0x0008 \b, stripped 109>>>>18 leshort ^0x0008 \b, not stripped 110# flags in other COFF versions 111#0x0010 F_FDPR_PROF 112#0x0020 F_FDPR_OPTI 113#0x0040 F_DSA 114# F_AR32WR flag bit 115#>>>>18 leshort &0x0100 \b, 32 bit little endian 116#0x1000 F_DYNLOAD 117#0x2000 F_SHROBJ 118#0x4000 F_LOADONLY 119# f_nscns - number of sections like: 1 2 3 4 5 7 8 9 11 12 15 16 19 20 21 22 26 30 36 40 42 56 80 89 96 124 120>>>>2 uleshort <2 \b, %u section 121>>>>2 uleshort >1 \b, %u sections 122# f_symptr - symbol table pointer, only for not stripped 123# like: 0 0x7c 0xf4 0x104 0x182 0x1c2 0x1c6 0x468 0x948 0x416e 0x149a6 0x1c9d8 0x23a68 0x35120 0x7afa0 124>>>>8 ulelong >0 \b, symbol offset=%#x 125# f_nsyms - number of symbols, only for not stripped 126# like: 0 2 7 9 10 11 20 35 41 63 71 80 105 146 153 158 170 208 294 572 831 1546 127>>>>12 ulelong >0 \b, %d symbols 128# f_opthdr - optional header size. An object file should have a value of 0 129# like: 72 (IBM\HH\HYPERHLP) 130>>>>16 uleshort >0 \b, optional header size %u 131# f_timdat - file time & date stamp 132>>>>4 ledate >0 \b, created %s 133# at offset 20 can be optional header, extra bytes FILHSZ-20 because 134# do not rely on sizeof(FILHDR) to give the correct size for header. 135# or first section header 136# additional variables for other COFF files 137>>>>16 uleshort =0 138# most section names start with point character except samples created by "exotic" compilers 139# first section name s_name[8] like: .text .data .debug$S .drectve .testseg .rsrc .rsrc$01 .pad 140>>>>>(16.s+20) string x \b, 1st section name "%.8s" 141# physical address s_paddr like: 0 142#>>>>>(16.s+28) lelong !0 \b, s_paddr %#8.8x 143# virtual address s_vaddr like: 0 144#>>>>>(16.s+32) lelong !0 \b, s_vaddr %#8.8x 145# section size s_size 146#>>>>>(16.s+36) lelong x \b, s_size %#8.8x 147# file ptr to raw data for section s_scnpt 148#>>>>>(16.s+40) lelong x \b, s_scnpt %#8.8x 149# file ptr to relocation s_relptr like: 0 150#>>>>>(16.s+44) lelong !0 \b, s_relptr %#8.8x 151# file ptr to gp histogram s_lnnoptr like: 0 152#>>>>>(16.s+48) lelong !0 \b, s_lnnoptr %#8.8x 153# number of relocation entries s_nreloc like: 0 1 2 5 6 8 19h 26h 27h 38h 50h 5Fh 89h Dh 1Ch 69h A9h 1DCh 651h 154#>>>>>(16.s+52) uleshort x \b, s_nreloc %#4.4x 155# number of gp histogram entries s_nlnno like: 0 156#>>>>>(16.s+54) uleshort !0 \b, s_nlnno %#4.4x 157# flags s_flags 158#>>>>>(16.s+56) lelong x \b, s_flags %#8.8x 159# second section name s_name[8] like: .bss .data .debug$S .rsrc$01 160>>>>2 uleshort >1 161>>>>>(16.s+60) string x \b, 2nd section name "%.8s" 162# >20 beshort 0407 (impure) 163# >20 beshort 0410 (pure) 164# >20 beshort 0413 (demand paged) 165# >20 beshort 0421 (standalone) 166# >22 leshort >0 - version %d 167# >168 string .lowmem Apple toolbox 168 169# PowerPC COFF object file or executable 1700 leshort 0x01f0 171>16 leshort 0 172>>0 use display-coff 173# can be created by: LINK.EXE /MACHINE:powerpc /ROM 174>16 leshort !0 175>>18 leshort &0x0002 176>>>20 leshort 0x010b 177>>>>0 use display-coff 1780 leshort 0x01f1 179>16 leshort 0 180>>0 use display-coff 1810 leshort 0x01f2 182>16 leshort 0 183>>0 use display-coff 1840 leshort 0x0601 185>16 leshort 0 186>>0 use display-coff 187# can be created by: LINK.EXE /MACHINE:MPPC /ROM 188>16 leshort !0 189>>18 leshort &0x0002 190>>>20 leshort 0x010b 191>>>>0 use display-coff 192 1930 name display-subsystem 194>0 ubyte 0 unknown 195>0 ubyte 1 native 196>0 ubyte 2 windows_gui 197>0 ubyte 3 windows_cui 198>0 ubyte 7 posix_cui 199>0 ubyte 9 windows_ce_gui 200>0 ubyte 10 efi_application 201>0 ubyte 11 efi_boot_service_driver 202>0 ubyte 12 efi_runtime_driver 203>0 ubyte 13 efi_rom 204>0 ubyte 14 xbox 205>0 ubyte 16 windows_boot-application 206>0 default x Unknown subsystem 207>>0 ubyte x %#x 208 209 210# https://formats.kaitai.io/uefi_te/index.html 2110 string VZ TE (Terse Executable) file 212>2 use display-coff-processor 213>4 byte x \b, sections %d 214>5 use display-subsystem 215>6 uleshort x \b, stripped-size %u 216>8 ulelong x \b, entry %#x 217>12 ulelong x \b, base_of_code %#x 218>16 ulequad x \b, image_base %#llx 219