PeSymbolProvider.parseSymbols() recovered zero names from a PE carrying a full
COFF symbol table. It resolved each symbol's section through Symbol.section and
skipped anything where that was None - which lief reports for every PE symbol,
on 0.17.6 and 1.0.0 alike, so the guard rejected the entire table. The 1-based
Symbol.section_idx carries the same information and is populated across the
supported lief range.
Measured on the new fixture: 1 of 2344 functions named before, 2020 of 2354
after, and 1600 of 1665 above the 10-instruction threshold. The function count
moves because USE_SYMBOLS_AS_CANDIDATES is on, so recovered symbols seed
candidates as well as name them. The single name recovered before came from OEP
handling rather than from the symbol table.
The failure was silent - the provider simply contributed nothing - so a corpus
could be built entirely unnamed with nothing to notice. A symbol table holding
FUNCTION entries none of which resolves now logs a warning.
Tests: _MockSymbol gave every symbol a real section object, a shape lief never
produces for PE, so five tests were asserting a contract that does not exist and
stayed green throughout. The stub now models the real one, which turned those
five red until this fix landed. tests/rust_pe_gnu_xored closes the other half of
the gap: none of the bundled PEs had a COFF symbol table at all, cutwail being
packed, njrat .NET and pe_export_label_test a stub. It is a Rust hello-world
built for x86_64-pc-windows-gnu and linked by mingw-w64, our own build rather
than a sample, and the first Rust PE in the corpus.
Closes #229.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>