Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1657115 > unrolled thread

Binary MOF buffer in WMI is finally decoded!

Started byPali Rohár <pali.rohar@gmail.com>
First post2017-06-04 18:20 +0200
Last post2017-06-06 00:10 +0200
Articles 2 — 1 participant

Back to article view | Back to linux.kernel


Contents

  Binary MOF buffer in WMI is finally decoded! Pali Rohár <pali.rohar@gmail.com> - 2017-06-04 18:20 +0200
    Re: Binary MOF buffer in WMI is finally decoded! Pali Rohár <pali.rohar@gmail.com> - 2017-06-06 00:10 +0200

#1657115 — Binary MOF buffer in WMI is finally decoded!

FromPali Rohár <pali.rohar@gmail.com>
Date2017-06-04 18:20 +0200
SubjectBinary MOF buffer in WMI is finally decoded!
Message-ID<tOGpX-7x8-9@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi!

As already mentioned in RFC: WMI Enhancements thread [1], I looked at 
binary MOF buffer used by WMI which is included in ACPI DSDT table.

That binary MOF buffer contains description of WMI methods and 
structures used by ACPI-WMI. It also contains mapping from human 
readable function names to ACPI-WMI magical numbers used for calling WMI 
methods via ACPI.

Basically in that binary MOF buffer is description of structures used as 
input and output arguments for WMI methods/function calls.

Until now, there were not information nor any parser of those binary MOF 
files (.bmf file). There is some Microsoft proprietary tool which can 
compile text MOF file to binary and vice versa.

I was able to decode that binary MOF format and wrote simple bmfparse 
tool. It is available in git repository [2]. Currently parsing of 
function parameters is not implemented yet.

Binary MOF format is compressed by prehistoric DS-01 algorithm 
(modification of LZ-77) which was used as compression algorithm for 
FAT-16. Maybe you remember DMSDOS or DoubleSpace... After decompression, 
the whole format is so shitty, probably half of data are just lengths of 
sub structures and sub-sub-... structures.

I hope this bmfparse program would help in writing new wmi drivers for 
Linux or inspection of available WMI methods.

Probably we could implement parser of BMOF in kernel and allow 
validation of function parameters or usage of human readable names of 
WMI methods?

[1] - https://www.spinics.net/lists/platform-driver-x86/msg11574.html
[2] - https://github.com/pali/bmfdec

-- 
Pali Rohár
pali.rohar@gmail.com

[toc] | [next] | [standalone]


#1658174

FromPali Rohár <pali.rohar@gmail.com>
Date2017-06-06 00:10 +0200
Message-ID<tP8md-aN-1@gated-at.bofh.it>
In reply to#1657115

[Multipart message — attachments visible in raw view] — view raw

On Sunday 04 June 2017 18:09:21 Pali Rohár wrote:
> Hi!
> 
> As already mentioned in RFC: WMI Enhancements thread [1], I looked at
> binary MOF buffer used by WMI which is included in ACPI DSDT table.
> 
> That binary MOF buffer contains description of WMI methods and
> structures used by ACPI-WMI. It also contains mapping from human
> readable function names to ACPI-WMI magical numbers used for calling
> WMI methods via ACPI.
> 
> Basically in that binary MOF buffer is description of structures used
> as input and output arguments for WMI methods/function calls.
> 
> Until now, there were not information nor any parser of those binary
> MOF files (.bmf file). There is some Microsoft proprietary tool
> which can compile text MOF file to binary and vice versa.
> 
> I was able to decode that binary MOF format and wrote simple bmfparse
> tool. It is available in git repository [2]. Currently parsing of
> function parameters is not implemented yet.
> 
> Binary MOF format is compressed by prehistoric DS-01 algorithm
> (modification of LZ-77) which was used as compression algorithm for
> FAT-16. Maybe you remember DMSDOS or DoubleSpace... After
> decompression, the whole format is so shitty, probably half of data
> are just lengths of sub structures and sub-sub-... structures.
> 
> I hope this bmfparse program would help in writing new wmi drivers
> for Linux or inspection of available WMI methods.
> 
> Probably we could implement parser of BMOF in kernel and allow
> validation of function parameters or usage of human readable names of
> WMI methods?
> 
> [1] - https://www.spinics.net/lists/platform-driver-x86/msg11574.html
> [2] - https://github.com/pali/bmfdec

Small update: function parameters are now decoded too. I fixed some 
problems and added new tool bmf2mof which decompile BMF file back to 
UTF-8 encoded plain text MOF file. It is in git repository:

https://github.com/pali/bmfdec

I run it on more binary WMI MOF buffers and it successfully parsed 
everything.

So if you have some time, I would like you to ask for testing those 
tools if they can parse binary WMI MOF buffers without problems.

As I wrote it by just looking at decompressed dumps without any 
documentation, it does not have to be correct or working... Also there 
are no proper checks for buffer overflows yet.

-- 
Pali Rohár
pali.rohar@gmail.com

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web