2007-03-22 10:30:00 -07:00
|
|
|
/* -*- Mode: C++; tab-width: 4; indent-tabs-mode: nil; c-basic-offset: 4 -*- */
|
2012-05-21 04:12:37 -07:00
|
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
2007-03-22 10:30:00 -07:00
|
|
|
|
|
|
|
|
2010-06-04 00:53:02 -07:00
|
|
|
#if defined(_WIN32) && (defined(_M_IX86) || defined(_M_X64))
|
2007-03-22 10:30:00 -07:00
|
|
|
// This is the .cpp file where the globals live
|
|
|
|
#define DHW_IMPLEMENT_GLOBALS
|
|
|
|
#include <stdio.h>
|
|
|
|
#include "prtypes.h"
|
|
|
|
#include "prprf.h"
|
|
|
|
#include "prlog.h"
|
|
|
|
#include "plstr.h"
|
|
|
|
#include "prlock.h"
|
|
|
|
#include "nscore.h"
|
|
|
|
#include "nsDebugHelpWin32.h"
|
|
|
|
#else
|
2010-06-04 00:53:02 -07:00
|
|
|
#error "nsDebugHelpWin32.cpp should only be built in Win32 x86/x64 builds"
|
2007-03-22 10:30:00 -07:00
|
|
|
#endif
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
/***************************************************************************/
|
|
|
|
|
|
|
|
|
|
|
|
PRLock* DHWImportHooker::gLock = nsnull;
|
|
|
|
DHWImportHooker* DHWImportHooker::gHooks = nsnull;
|
|
|
|
GETPROCADDRESS DHWImportHooker::gRealGetProcAddress = nsnull;
|
|
|
|
|
|
|
|
|
2011-09-28 23:19:26 -07:00
|
|
|
static bool
|
2007-03-22 10:30:00 -07:00
|
|
|
dhwEnsureImageHlpInitialized()
|
|
|
|
{
|
2011-09-28 23:19:26 -07:00
|
|
|
static bool gInitialized = false;
|
|
|
|
static bool gTried = false;
|
2007-03-22 10:30:00 -07:00
|
|
|
|
|
|
|
if (!gInitialized && !gTried) {
|
2011-10-17 07:59:28 -07:00
|
|
|
gTried = true;
|
2007-03-22 10:30:00 -07:00
|
|
|
HMODULE module = ::LoadLibrary("DBGHELP.DLL");
|
|
|
|
if (!module) {
|
|
|
|
DWORD dw = GetLastError();
|
|
|
|
printf("DumpStack Error: DBGHELP.DLL wasn't found. GetLastError() returned 0x%8.8X\n"
|
|
|
|
" This DLL is needed for succeessfully implementing trace-malloc.\n"
|
|
|
|
" This dll ships by default on Win2k. Disabling trace-malloc functionality.\n"
|
|
|
|
, dw);
|
2011-10-17 07:59:28 -07:00
|
|
|
return false;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
#define INIT_PROC(typename_, name_) \
|
|
|
|
dhw##name_ = (typename_) ::GetProcAddress(module, #name_); \
|
2011-10-17 07:59:28 -07:00
|
|
|
if(!dhw##name_) return false;
|
2007-03-22 10:30:00 -07:00
|
|
|
|
2010-06-04 00:53:02 -07:00
|
|
|
#ifdef _WIN64
|
|
|
|
INIT_PROC(ENUMERATELOADEDMODULES64, EnumerateLoadedModules64);
|
|
|
|
#else
|
2007-03-22 10:30:00 -07:00
|
|
|
INIT_PROC(ENUMERATELOADEDMODULES, EnumerateLoadedModules);
|
2010-06-04 00:53:02 -07:00
|
|
|
#endif
|
2007-03-22 10:30:00 -07:00
|
|
|
INIT_PROC(IMAGEDIRECTORYENTRYTODATA, ImageDirectoryEntryToData);
|
|
|
|
|
|
|
|
#undef INIT_PROC
|
|
|
|
|
2011-10-17 07:59:28 -07:00
|
|
|
gInitialized = true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
return gInitialized;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
DHWImportHooker&
|
|
|
|
DHWImportHooker::getGetProcAddressHooker()
|
|
|
|
{
|
|
|
|
static DHWImportHooker gGetProcAddress("Kernel32.dll", "GetProcAddress",
|
|
|
|
(PROC)DHWImportHooker::GetProcAddress);
|
|
|
|
return gGetProcAddress;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
DHWImportHooker&
|
|
|
|
DHWImportHooker::getLoadLibraryWHooker()
|
|
|
|
{
|
|
|
|
static DHWImportHooker gLoadLibraryW("Kernel32.dll", "LoadLibraryW",
|
|
|
|
(PROC)DHWImportHooker::LoadLibraryW);
|
|
|
|
return gLoadLibraryW;
|
|
|
|
}
|
|
|
|
|
|
|
|
DHWImportHooker&
|
|
|
|
DHWImportHooker::getLoadLibraryExWHooker()
|
|
|
|
{
|
|
|
|
static DHWImportHooker gLoadLibraryExW("Kernel32.dll", "LoadLibraryExW",
|
|
|
|
(PROC)DHWImportHooker::LoadLibraryExW);
|
|
|
|
return gLoadLibraryExW;
|
|
|
|
}
|
|
|
|
|
|
|
|
DHWImportHooker&
|
|
|
|
DHWImportHooker::getLoadLibraryAHooker()
|
|
|
|
{
|
|
|
|
static DHWImportHooker gLoadLibraryA("Kernel32.dll", "LoadLibraryA",
|
|
|
|
(PROC)DHWImportHooker::LoadLibraryA);
|
|
|
|
return gLoadLibraryA;
|
|
|
|
}
|
|
|
|
|
|
|
|
DHWImportHooker&
|
|
|
|
DHWImportHooker::getLoadLibraryExAHooker()
|
|
|
|
{
|
|
|
|
static DHWImportHooker gLoadLibraryExA("Kernel32.dll", "LoadLibraryExA",
|
|
|
|
(PROC)DHWImportHooker::LoadLibraryExA);
|
|
|
|
return gLoadLibraryExA;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
static HMODULE ThisModule()
|
|
|
|
{
|
|
|
|
MEMORY_BASIC_INFORMATION info;
|
|
|
|
return VirtualQuery(ThisModule, &info, sizeof(info)) ?
|
|
|
|
(HMODULE) info.AllocationBase : nsnull;
|
|
|
|
}
|
|
|
|
|
|
|
|
DHWImportHooker::DHWImportHooker(const char* aModuleName,
|
|
|
|
const char* aFunctionName,
|
|
|
|
PROC aHook,
|
2011-09-28 23:19:26 -07:00
|
|
|
bool aExcludeOurModule /* = false */)
|
2007-03-22 10:30:00 -07:00
|
|
|
: mNext(nsnull),
|
|
|
|
mModuleName(aModuleName),
|
|
|
|
mFunctionName(aFunctionName),
|
|
|
|
mOriginal(nsnull),
|
|
|
|
mHook(aHook),
|
|
|
|
mIgnoreModule(aExcludeOurModule ? ThisModule() : nsnull),
|
2011-10-17 07:59:28 -07:00
|
|
|
mHooking(true)
|
2007-03-22 10:30:00 -07:00
|
|
|
{
|
|
|
|
//printf("DHWImportHooker hooking %s, function %s\n",aModuleName, aFunctionName);
|
|
|
|
|
|
|
|
if(!gLock)
|
|
|
|
gLock = PR_NewLock();
|
|
|
|
PR_Lock(gLock);
|
|
|
|
|
|
|
|
dhwEnsureImageHlpInitialized(); // for the extra ones we care about.
|
|
|
|
|
|
|
|
if(!gRealGetProcAddress)
|
|
|
|
gRealGetProcAddress = ::GetProcAddress;
|
|
|
|
|
|
|
|
mOriginal = gRealGetProcAddress(::GetModuleHandleA(aModuleName),
|
|
|
|
aFunctionName),
|
|
|
|
|
|
|
|
mNext = gHooks;
|
|
|
|
gHooks = this;
|
|
|
|
|
|
|
|
PatchAllModules();
|
|
|
|
|
|
|
|
PR_Unlock(gLock);
|
|
|
|
}
|
|
|
|
|
|
|
|
DHWImportHooker::~DHWImportHooker()
|
|
|
|
{
|
|
|
|
PR_Lock(gLock);
|
|
|
|
|
2011-10-17 07:59:28 -07:00
|
|
|
mHooking = false;
|
2007-03-22 10:30:00 -07:00
|
|
|
PatchAllModules();
|
|
|
|
|
2007-09-27 09:27:12 -07:00
|
|
|
for (DHWImportHooker **cur = &gHooks;
|
|
|
|
(PR_ASSERT(*cur), *cur); /* assert that we find this */
|
|
|
|
cur = &(*cur)->mNext)
|
2007-03-22 10:30:00 -07:00
|
|
|
{
|
2007-09-27 09:27:12 -07:00
|
|
|
if (*cur == this)
|
2007-03-22 10:30:00 -07:00
|
|
|
{
|
2007-09-27 09:27:12 -07:00
|
|
|
*cur = mNext;
|
|
|
|
break;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if(!gHooks)
|
|
|
|
{
|
|
|
|
PRLock* theLock = gLock;
|
|
|
|
gLock = nsnull;
|
|
|
|
PR_Unlock(theLock);
|
|
|
|
PR_DestroyLock(theLock);
|
|
|
|
}
|
|
|
|
if (gLock)
|
|
|
|
PR_Unlock(gLock);
|
|
|
|
}
|
|
|
|
|
2010-06-04 00:53:02 -07:00
|
|
|
#ifdef _WIN64
|
|
|
|
static BOOL CALLBACK ModuleEnumCallback(PCSTR ModuleName,
|
|
|
|
DWORD64 ModuleBase,
|
|
|
|
ULONG ModuleSize,
|
|
|
|
PVOID UserContext)
|
|
|
|
#else
|
2008-02-03 11:34:31 -08:00
|
|
|
static BOOL CALLBACK ModuleEnumCallback(PCSTR ModuleName,
|
2007-03-22 10:30:00 -07:00
|
|
|
ULONG ModuleBase,
|
|
|
|
ULONG ModuleSize,
|
|
|
|
PVOID UserContext)
|
2010-06-04 00:53:02 -07:00
|
|
|
#endif
|
2007-03-22 10:30:00 -07:00
|
|
|
{
|
|
|
|
//printf("Module Name %s\n",ModuleName);
|
|
|
|
DHWImportHooker* self = (DHWImportHooker*) UserContext;
|
|
|
|
HMODULE aModule = (HMODULE) ModuleBase;
|
|
|
|
return self->PatchOneModule(aModule, ModuleName);
|
|
|
|
}
|
|
|
|
|
2011-09-28 23:19:26 -07:00
|
|
|
bool
|
2007-03-22 10:30:00 -07:00
|
|
|
DHWImportHooker::PatchAllModules()
|
|
|
|
{
|
2008-02-03 11:51:14 -08:00
|
|
|
// Need to cast to PENUMLOADED_MODULES_CALLBACK because the
|
|
|
|
// constness of the first parameter of PENUMLOADED_MODULES_CALLBACK
|
|
|
|
// varies over SDK versions (from non-const to const over time).
|
2008-02-03 11:59:07 -08:00
|
|
|
// See bug 391848 and bug 415426.
|
2010-06-04 00:53:02 -07:00
|
|
|
#ifdef _WIN64
|
|
|
|
return dhwEnumerateLoadedModules64(::GetCurrentProcess(),
|
|
|
|
(PENUMLOADED_MODULES_CALLBACK64)ModuleEnumCallback, this);
|
|
|
|
#else
|
2007-03-22 10:30:00 -07:00
|
|
|
return dhwEnumerateLoadedModules(::GetCurrentProcess(),
|
2008-02-03 11:51:14 -08:00
|
|
|
(PENUMLOADED_MODULES_CALLBACK)ModuleEnumCallback, this);
|
2010-06-04 00:53:02 -07:00
|
|
|
#endif
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
2011-09-28 23:19:26 -07:00
|
|
|
bool
|
2007-03-22 10:30:00 -07:00
|
|
|
DHWImportHooker::PatchOneModule(HMODULE aModule, const char* name)
|
|
|
|
{
|
|
|
|
if(aModule == mIgnoreModule)
|
|
|
|
{
|
2011-10-17 07:59:28 -07:00
|
|
|
return true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// do the fun stuff...
|
|
|
|
|
|
|
|
PIMAGE_IMPORT_DESCRIPTOR desc;
|
|
|
|
uint32 size;
|
|
|
|
|
|
|
|
desc = (PIMAGE_IMPORT_DESCRIPTOR)
|
2011-10-17 07:59:28 -07:00
|
|
|
dhwImageDirectoryEntryToData(aModule, true,
|
2007-03-22 10:30:00 -07:00
|
|
|
IMAGE_DIRECTORY_ENTRY_IMPORT, &size);
|
|
|
|
|
|
|
|
if(!desc)
|
|
|
|
{
|
2011-10-17 07:59:28 -07:00
|
|
|
return true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
for(; desc->Name; desc++)
|
|
|
|
{
|
|
|
|
const char* entryModuleName = (const char*)
|
|
|
|
((char*)aModule + desc->Name);
|
|
|
|
if(!lstrcmpi(entryModuleName, mModuleName))
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if(!desc->Name)
|
|
|
|
{
|
2011-10-17 07:59:28 -07:00
|
|
|
return true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
PIMAGE_THUNK_DATA thunk = (PIMAGE_THUNK_DATA)
|
|
|
|
((char*) aModule + desc->FirstThunk);
|
|
|
|
|
|
|
|
for(; thunk->u1.Function; thunk++)
|
|
|
|
{
|
|
|
|
PROC original;
|
|
|
|
PROC replacement;
|
|
|
|
|
|
|
|
if(mHooking)
|
|
|
|
{
|
|
|
|
original = mOriginal;
|
|
|
|
replacement = mHook;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
original = mHook;
|
|
|
|
replacement = mOriginal;
|
|
|
|
}
|
|
|
|
|
|
|
|
PROC* ppfn = (PROC*) &thunk->u1.Function;
|
|
|
|
if(*ppfn == original)
|
|
|
|
{
|
|
|
|
DWORD dwDummy;
|
|
|
|
VirtualProtect(ppfn, sizeof(ppfn), PAGE_EXECUTE_READWRITE, &dwDummy);
|
|
|
|
BOOL result = WriteProcessMemory(GetCurrentProcess(),
|
|
|
|
ppfn, &replacement, sizeof(replacement), nsnull);
|
|
|
|
if (!result) //failure
|
|
|
|
{
|
|
|
|
printf("failure name %s func %x\n",name,*ppfn);
|
|
|
|
DWORD error = GetLastError();
|
2011-10-17 07:59:28 -07:00
|
|
|
return true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
// printf("success name %s func %x\n",name,*ppfn);
|
|
|
|
DWORD filler = result+1;
|
|
|
|
return result;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
2011-10-17 07:59:28 -07:00
|
|
|
return true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
2011-09-28 23:19:26 -07:00
|
|
|
bool
|
2007-03-22 10:30:00 -07:00
|
|
|
DHWImportHooker::ModuleLoaded(HMODULE aModule, DWORD flags)
|
|
|
|
{
|
|
|
|
//printf("ModuleLoaded\n");
|
|
|
|
if(aModule && !(flags & LOAD_LIBRARY_AS_DATAFILE))
|
|
|
|
{
|
|
|
|
PR_Lock(gLock);
|
|
|
|
// We don't know that the newly loaded module didn't drag in implicitly
|
|
|
|
// linked modules, so we patch everything in sight.
|
|
|
|
for(DHWImportHooker* cur = gHooks; cur; cur = cur->mNext)
|
|
|
|
cur->PatchAllModules();
|
|
|
|
PR_Unlock(gLock);
|
|
|
|
}
|
2011-10-17 07:59:28 -07:00
|
|
|
return true;
|
2007-03-22 10:30:00 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// static
|
|
|
|
HMODULE WINAPI
|
|
|
|
DHWImportHooker::LoadLibraryW(PCWSTR path)
|
|
|
|
{
|
|
|
|
//wprintf(L"LoadLibraryW %s\n",path);
|
|
|
|
DHW_DECLARE_FUN_TYPE(HMODULE, __stdcall, LOADLIBRARYW_, (PCWSTR));
|
|
|
|
HMODULE hmod = DHW_ORIGINAL(LOADLIBRARYW_, getLoadLibraryWHooker())(path);
|
|
|
|
ModuleLoaded(hmod, 0);
|
|
|
|
return hmod;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
// static
|
|
|
|
HMODULE WINAPI
|
|
|
|
DHWImportHooker::LoadLibraryExW(PCWSTR path, HANDLE file, DWORD flags)
|
|
|
|
{
|
|
|
|
//wprintf(L"LoadLibraryExW %s\n",path);
|
|
|
|
DHW_DECLARE_FUN_TYPE(HMODULE, __stdcall, LOADLIBRARYEXW_, (PCWSTR, HANDLE, DWORD));
|
|
|
|
HMODULE hmod = DHW_ORIGINAL(LOADLIBRARYEXW_, getLoadLibraryExWHooker())(path, file, flags);
|
|
|
|
ModuleLoaded(hmod, flags);
|
|
|
|
return hmod;
|
|
|
|
}
|
|
|
|
|
|
|
|
// static
|
|
|
|
HMODULE WINAPI
|
|
|
|
DHWImportHooker::LoadLibraryA(PCSTR path)
|
|
|
|
{
|
|
|
|
//printf("LoadLibraryA %s\n",path);
|
|
|
|
|
|
|
|
DHW_DECLARE_FUN_TYPE(HMODULE, __stdcall, LOADLIBRARYA_, (PCSTR));
|
|
|
|
HMODULE hmod = DHW_ORIGINAL(LOADLIBRARYA_, getLoadLibraryAHooker())(path);
|
|
|
|
ModuleLoaded(hmod, 0);
|
|
|
|
return hmod;
|
|
|
|
}
|
|
|
|
|
|
|
|
// static
|
|
|
|
HMODULE WINAPI
|
|
|
|
DHWImportHooker::LoadLibraryExA(PCSTR path, HANDLE file, DWORD flags)
|
|
|
|
{
|
|
|
|
//printf("LoadLibraryExA %s\n",path);
|
|
|
|
DHW_DECLARE_FUN_TYPE(HMODULE, __stdcall, LOADLIBRARYEXA_, (PCSTR, HANDLE, DWORD));
|
|
|
|
HMODULE hmod = DHW_ORIGINAL(LOADLIBRARYEXA_, getLoadLibraryExAHooker())(path, file, flags);
|
|
|
|
ModuleLoaded(hmod, flags);
|
|
|
|
return hmod;
|
|
|
|
}
|
|
|
|
// static
|
|
|
|
FARPROC WINAPI
|
|
|
|
DHWImportHooker::GetProcAddress(HMODULE aModule, PCSTR aFunctionName)
|
|
|
|
{
|
|
|
|
FARPROC pfn = gRealGetProcAddress(aModule, aFunctionName);
|
|
|
|
|
|
|
|
if(pfn)
|
|
|
|
{
|
|
|
|
PR_Lock(gLock);
|
|
|
|
for(DHWImportHooker* cur = gHooks; cur; cur = cur->mNext)
|
|
|
|
{
|
|
|
|
if(pfn == cur->mOriginal)
|
|
|
|
{
|
|
|
|
pfn = cur->mHook;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
PR_Unlock(gLock);
|
|
|
|
}
|
|
|
|
return pfn;
|
|
|
|
}
|
|
|
|
|
|
|
|
|