Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

pe

std › formats › pe

PE32+ (64-bit Windows) console executables.

Invoke the header macro first thing in the program’s entry file, before any section statement, so its bytes start the image:

from std.formats.pe import *
from std.x86_64.nasm import *

pe64_executable IMAGE_FILE_MACHINE_AMD64, _start

_start:
    ret

The image is the headers (padded to 512 bytes), then everything after them as one read+execute .text section at RVA 0x1000, padded to 512 bytes at the end. entry is a label in this file or imported from another one. No imports, exports or relocations: a program that calls into Windows DLLs needs more than this provides.

Not verified on Windows: this reproduces the Rust writer it replaced byte for byte, and llvm-readobj accepts its output.

Macros

pe64_executable

The DOS, PE and optional headers plus the .text section header, 368 bytes, padded to 512. entry is the label execution starts at, and the image loads at image_base.

SyntaxParametersResultDescription
pe64_executable machine, entry, image_basemachine: int, entry: int, image_base: int = 0x140000000

Constants

ConstantTypeValueDescription
IMAGE_FILE_MACHINE_AMD640x8664machine for x86-64.