Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| en:docs:tk:formats:newexe [2024/09/22 09:40] – prokushev | en:docs:tk:formats:newexe [2026/05/15 03:41] (current) – prokushev | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== New Executable file format ====== | ||
| + | |||
| + | New Executable (NE) file format used by set of operating system including OS/2, Windows, Multitasking MS-DOS 4 and set of DOS Extenders. It is designed to be store on disk and in-memory usage. In-disk format is same for all OSes, but In-memory usage is mostly specific for Windows systems. | ||
| + | |||
| + | ===== New Executable header ===== | ||
| + | |||
| ^ Offset ^ Size ^ Name ^ Description ^ | ^ Offset ^ Size ^ Name ^ Description ^ | ||
| - | | 00h | WORD | e_magic | + | | 00h | WORD | ne_magic |
| - | | 02h | WORD | e_cblp | + | | On-disk |||| |
| - | | 04h | WORD | e_cp | Number of blocks in the file that are part of the EXE file. If [02-03] is non-zero, only that much of the last block is used. | | + | | 02h | BYTE | ne_ver | Version |
| - | | 06h | WORD | e_crlc | + | | 03h | BYTE | ne_rev |
| - | | 08h | WORD | e_cparhdr | + | | In-memory |
| - | | 0Ah | WORD | e_minalloc | + | | 02h | WORD | count | Usage count |
| - | | 0Ch | WORD | e_maxalloc | + | | 04h | WORD | ne_enttab |
| - | | 0EH | WORD | e_ss | Relative value of the stack segment. This value is added to the segment | + | | On-disk |||| |
| - | | 10h | WORD | e_sp | Initial value of the SP register. | + | | 06h | WORD | ne_cbenttab |
| - | | 12h | WORD | e_csum | + | | In-memory (Windows) |||| |
| - | | 14h | WORD | e_ip | Initial value of the IP register. | + | | 06h | WORD | next | Selector |
| - | | 16h | WORD | e_cs | Initial value of the CS register, relative to the segment | + | | On-disk |
| - | | 18h | WORD | e_lfarlc | + | | 08h | DWORD | ne_crc | 32-bit CRC of entire contents |
| - | | 1Ah | WORD | e_ovno | + | | In-memory |
| - | | 1Ch | WORD | e_res[ERES1WDS] | + | | 08h | WORD | dgroup_entry | Near ptr to segment entry for DGROUP | |
| - | WORD e_oemid; | + | | 0Ah | WORD | fileinfo | Near ptr to file info (OFSTRUCT) |
| - | WORD e_oeminfo; | + | | 0Ch | WORD | ne_flags |
| - | WORD e_res2[ERES2WDS]; | + | | 0Eh | WORD | ne_autodata | Segment |
| - | | + | | 10h | WORD | ne_heap |
| + | | 12h | WORD | ne_stack | Initial size, in bytes, of stack added to the data segment. This value is zero to indicate no initial stack allocation, or when SS is not equal to DS | | ||
| + | | 14h | DWORD | ne_csip | Segment number: | ||
| + | | 18h | DWORD | ne_sssp | Segment number: | ||
| + | ! additional dynamic heap ! | ||
| + | +--------------------------+ <- SP | ||
| + | ! additional stack ! | ||
| + | +--------------------------+ | ||
| + | ! loaded auto data segment ! | ||
| + | +--------------------------+ <- DS, SS </ | ||
| + | | 1Ch | WORD | ne_cseg | ||
| + | | 1Eh | WORD | ne_cmod | ||
| + | | 20h | WORD | ne_cbnrestab | Number | ||
| + | | 22h | WORD | ne_segtab | Segment Table file offset, relative to the beginning of the segmented EXE header | ||
| + | | 24h | WORD | ne_rsrctab | ||
| + | | 26h | WORD | ne_restab | ||
| + | | 28h | WORD | ne_modtab | Module Reference Table file offset, relative to the beginning of the segmented EXE header | ||
| + | | 2Ah | WORD | ne_imptab | ||
| + | | 2Ch | DWORD | ne_nrestab | Non-Resident Name Table offset, relative to the beginning of the file | | ||
| + | | 30h | WORD | ne_cmovent | ||
| + | | 32h | WORD | ne_align | Logical sector alignment shift count, log(base 2) of the segment sector size (default 9) | | ||
| + | | 34h | WORD | ne_cres | ||
| + | | 36h | BYTE | ne_exetyp | Executable type, used by loader. \\ 00h=Unknown (any “new‑format” OS) \\ 01h=OS/2 \\ 02h=Windows \\ 03h=European MS‑DOS 4.x \\ 04h=Windows 386 \\ 05h=BOSS (Borland Operating System Services) \\ 81h=PharLap 286< | ||
| + | | 37h | BYTE | ne_flagsothers | Operating system flags | | ||
| + | | 38h | WORD | ??? | offset to return thunks or start of gangload/ | ||
| + | | 3Ah | WORD | ??? | offset to segment reference thunks or length of gangload/ | ||
| + | | 3Ch | WORD | ??? | minimum code swap area size (Windows) | | ||
| + | | 3Eh | 2 BYTEs | ??? | expected Windows version (minor version first) (Windows)| | ||
| + | ===== Flag word (ne_flags) ===== | ||
| + | ^ Bit(s) ^ Mask ^ Name ^ Description ^ | ||
| + | | 0-1 | - | NOAUTODATA | No an automatic data segment | | ||
| + | | 0 | 0001h | SINGLEDATA | Per-process library data (shared DGROUP) | | ||
| + | | 1 | 0002h | MULTIPLEDATA | Per-instance library data | | ||
| + | | 8 | 0100h | NENOTWINCOMPAT | Not compatible with PM Windowing (full screen only) (OS/2) | | ||
| + | | 9 | 0200h | NEWINCOMPAT | Compatible with PM Windowing (OS/2) | | ||
| + | | 10 | 0300h | NEWINAPI | Uses PM Windowing API (OS/2) | | ||
| + | | 11 | 0800H | FIRSTDISC/ | ||
| + | | 13 | 2000h | LINKERROR | Errors detected at link time, module will not load | | ||
| + | | 14 | 4000h | NENOTMPSAFE | Non-conforming program (valid stack is not maintained) (Windows) Process is not multi‑processor safe (OS/2) | | ||
| + | | 15 | 8000h | LIBRARY | Module is a dynamic‑link library (DLL) | | ||
| - | /* In-disk and In-memory module structure. See 'Windows | + | ===== Operating system flags (ne_flagsothers) ===== |
| + | ^ Bit ^ Mask ^ Name ^ Description ^ | ||
| + | | 0 | 01h | NELONGNAMES | Supports long file names (OS/2) | | ||
| + | | 1 | 02h | NEWINISPROT | Windows 2.x app runs in protected mode (Windows) | | ||
| + | | 2 | 04h | NEWINGETPROPFON | Windows 2.x app gets proportional font (Windows) | | ||
| + | | 3 | 08h | NEGANGLOAD | Contains gangload/ | ||
| + | | 7 | 80h | NEWLOAPPL | WLO application on OS/2 (markwlo.exe) (OS/2) | | ||
| - | struct new_exe { | + | On-disk segment entry |
| - | WORD ne_magic; | + | |
| - | union { | + | |
| - | struct { | + | |
| - | BYTE | + | |
| - | BYTE | + | |
| - | }; | + | |
| - | WORD | + | |
| - | }; | + | |
| - | WORD ne_enttab; | + | |
| - | | + | |
| - | union { | + | |
| - | WORD | + | |
| - | WORD | + | |
| - | }; | + | |
| - | union { | + | |
| - | DWORD | + | |
| - | | + | |
| - | struct { | + | |
| - | WORD dgroup_entry; | + | |
| - | WORD fileinfo; | + | |
| - | }; | + | |
| - | }; | + | |
| - | WORD ne_flags; | + | |
| - | WORD ne_autodata; | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | | + | | 00h | WORD | ns_sector | Logical-sector offset (n byte) to the contents of the segment |
| - | | + | | 02h | WORD | ns_cbseg | Length of the segment in the file, in bytes. |
| - | WORD ne_heap; | + | | 04h | WORD | ns_flags | Flag word | |
| - | | + | | 06h | WORD | ns_minalloc | Minimum |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | DWORD ne_csip; | + | |
| - | DWORD | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | In-memory |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | WORD ne_cseg; | + | |
| - | WORD ne_cmod; | + | |
| - | WORD ne_cbnrestab; | + | |
| - | WORD ne_segtab; | + | |
| - | | + | |
| - | WORD ne_rsrctab; | + | |
| - | | + | |
| - | WORD ne_restab; | + | |
| - | | + | |
| - | WORD ne_modtab; | + | |
| - | | + | |
| - | WORD ne_imptab; | + | |
| - | | + | |
| - | DWORD ne_nrestab; | + | |
| - | | + | |
| - | WORD ne_cmovent; | + | |
| - | WORD ne_align; | + | |
| - | | + | |
| - | WORD ne_cres; | + | |
| - | BYTE ne_exetyp; | + | |
| - | | + | |
| - | BYTE ne_flagsothers; | + | |
| - | char ne_res[NERESBYTES]; | + | |
| - | }; | + | |
| - | // On-disk segment entry | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | struct new_seg { | + | | 00h | WORD | ns1_sector |
| - | WORD ns_sector; | + | | 02h | WORD | ns1_cbseg |
| - | | + | | 04h | WORD | ns1_flags |
| - | | + | | 06h | WORD | ns1_minalloc |
| - | WORD ns_cbseg; | + | | 08h | WORD | ns1_handle |
| - | WORD ns_flags; | + | |
| - | WORD ns_minalloc; | + | |
| - | | + | |
| - | }; | + | |
| - | + | ||
| - | // In-memory segment entry | + | |
| - | struct new_seg1 { | + | |
| - | WORD ns1_sector; | + | |
| - | | + | |
| - | | + | |
| - | WORD ns1_cbseg; | + | |
| - | WORD ns1_flags; | + | |
| - | WORD ns1_minalloc; | + | |
| - | | + | |
| - | WORD ns1_handle; | + | |
| - | }; | + | |
| + | <code c> | ||
| struct new_segdata { | struct new_segdata { | ||
| union { | union { | ||
| Line 135: | Line 104: | ||
| } ns_union; | } ns_union; | ||
| }; | }; | ||
| + | </ | ||
| - | struct new_rlcinfo { | + | Relocation table header |
| - | WORD nr_nreloc; | + | |
| - | }; | + | |
| - | struct new_rlc { | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | | + | | 00h | WORD | nr_nreloc | Number of relocation table entries | |
| - | char nr_flags; | + | |
| - | | + | |
| - | union { | + | |
| - | struct { | + | |
| - | char nr_segno; | + | |
| - | char nr_res; | + | |
| - | WORD nr_entry; | + | |
| - | } nr_intref; | + | |
| - | struct { | + | |
| - | WORD nr_mod; | + | |
| - | WORD nr_proc; | + | |
| - | } nr_import; | + | |
| - | struct { | + | |
| - | WORD nr_ostype; | + | |
| - | WORD nr_osres; | + | |
| - | } nr_osfix; | + | |
| - | } nr_union; | + | |
| - | }; | + | |
| - | #define NR_STYPE(x) | + | Relocation table entry |
| - | #define NR_FLAGS(x) | + | |
| - | #define NR_SOFF(x) | + | |
| - | #define NR_SEGNO(x) | + | |
| - | #define NR_RES(x) | + | |
| - | #define NR_ENTRY(x) | + | |
| - | #define NR_MOD(x) | + | |
| - | #define NR_PROC(x) | + | |
| - | #define NR_OSTYPE(x) | + | |
| - | #define NR_OSRES(x) | + | |
| - | # | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | #define NRSBYT | + | | 00h | char | nr_stype | Source type (0Fh = NRSTYP |
| - | #define NRSSEG | + | | 01h | char | nr_flags | Flags byte (03h = TARGET_MASK): |
| - | #define NRSPTR | + | | 02h | WORD | nr_soff | Offset within this segment of the source chain. If the ADDITIVE flag is set, then target value is added to the source contents, instead of replacing the source and following the chain. The source chain is an 0FFFFh terminated linked list within this segment of all references to the target | |
| - | #define NRSOFF | + | | Internal fixup |||| |
| - | #define NRPTR48 | + | | 04h | char | nr_segno | Segment number (for fixed segment) or 0FFh (for movable segment) | |
| - | #define NROFF32 | + | | 05h | char | nr_res | Reserved (usually zero) | |
| - | #define NRSOFF32 | + | | 06h | WORD | nr_entry | Entry table number (for movable segment) offset segment | |
| + | | Import |||| | ||
| + | | 04h | WORD | nr_mod | ??? | | ||
| + | | 06h | WORD | nr_proc | ??? | | ||
| + | | OS Fixup |||| | ||
| + | | 04h | WORD | nr_ostype | ??? | | ||
| + | | 06h | WORD | nr_osres | ??? | | ||
| - | #define NRADD 0x04 | ||
| - | #define NRRTYP | ||
| - | #define NRRINT | ||
| - | #define NRRORD | ||
| - | #define NRRNAM | ||
| - | #define NRROSF | ||
| - | #define NRICHAIN | ||
| - | #if (EXE386 == 0) | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| + | | 00h | char | rs_len | ??? | | ||
| + | | 01h | char | rs_string[1] | ??? | | ||
| - | #define RS_LEN(x) | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | #define RS_STRING(x) | + | | 00h | WORD | rt_id | ??? | |
| - | #define RS_ALIGN(x) | + | | 02h | WORD | rt_nres | ??? | |
| + | | 04h | DWORD | rt_proc | ??? | | ||
| - | #define RT_ID(x) | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | #define RT_NRES(x) | + | | 00h | WORD | rn_offset | ??? | |
| - | #define RT_PROC(x) | + | | 02h | WORD | rn_length | ??? | |
| + | | 04h | WORD | rn_flags | ??? | | ||
| + | | 06h | WORD | rn_id | ??? | | ||
| + | | 08h | WORD | rn_handle | ??? | | ||
| + | | 0Ah | WORD | rn_usage | ??? | | ||
| - | #define RN_OFFSET(x) | + | ^ Offset ^ Size ^ Name ^ Description ^ |
| - | #define RN_LENGTH(x) | + | | 00h | WORD | rs_align |
| - | #define RN_FLAGS(x) | + | | 02h | struct rsrc_typeinfo |
| - | #define RN_ID(x) | + | |
| - | #define RN_HANDLE(x) | + | |
| - | #define RN_USAGE(x) | + | |
| - | + | ||
| - | #define RSORDID | + | |
| - | + | ||
| - | #define RNMOVE | + | |
| - | #define RNPURE | + | |
| - | #define RNPRELOAD | + | |
| - | #define RNDISCARD | + | |
| - | + | ||
| - | #define NE_FFLAGS_LIBMODULE 0x8000 | + | |
| - | + | ||
| - | struct rsrc_string { | + | |
| - | char rs_len; | + | |
| - | char rs_string[1]; | + | |
| - | }; | + | |
| - | + | ||
| - | struct rsrc_typeinfo { | + | |
| - | | + | |
| - | WORD rt_nres; | + | |
| - | DWORD rt_proc; | + | |
| - | }; | + | |
| - | + | ||
| - | struct rsrc_nameinfo { | + | |
| - | WORD rn_offset; | + | |
| - | WORD rn_length; | + | |
| - | WORD rn_flags; | + | |
| - | WORD rn_id; | + | |
| - | WORD rn_handle; | + | |
| - | WORD rn_usage; | + | |
| - | }; | + | |
| - | + | ||
| - | struct new_rsrc { | + | |
| - | WORD | + | |
| - | struct rsrc_typeinfo | + | |
| - | }; | + | |
| - | + | ||
| - | #endif | + | |
| - | + | ||
| - | #pragma pack(pop) | + | |
| - | + | ||
| - | #ifdef __cplusplus | + | |
| - | } /* extern " | + | |
| - | #endif | + | |
| - | #endif | ||
| + | * Microsoft KB: Q65122: Executable-File Header Format | ||
| + | * Windows SDK 3.1 (MSDN Library, September 1992) | ||




