chore: Apply code formatting on entire codebase for consistent style

This commit is contained in:
icex2
2023-04-06 15:39:53 +02:00
committed by icex2
parent a1a849aef3
commit 031836ef0e
186 changed files with 2446 additions and 1979 deletions
+4 -7
View File
@@ -10,11 +10,8 @@
/* This does not handle escaped double quotes inside args correctly yet */
static HRESULT args_push(
int *argc,
char ***argv,
const char *begin,
const char *end)
static HRESULT
args_push(int *argc, char ***argv, const char *begin, const char *end)
{
int tmp_argc;
char **tmp_argv;
@@ -70,7 +67,7 @@ HRESULT args_recover(int *argc_out, char ***argv_out)
argv = NULL;
quote = false;
for (begin = pos = GetCommandLine() ; *pos ; pos++) {
for (begin = pos = GetCommandLine(); *pos; pos++) {
switch (*pos) {
case '"':
if (!quote) {
@@ -129,7 +126,7 @@ void args_free(int argc, char **argv)
{
int i;
for (i = 0 ; i < argc ; i++) {
for (i = 0; i < argc; i++) {
free(argv[i]);
}
+50 -31
View File
@@ -1,5 +1,5 @@
#include <windows.h>
#include <unknwn.h>
#include <windows.h>
#include <assert.h>
#include <stdint.h>
@@ -8,63 +8,84 @@
#include "hook/com-proxy.h"
static void com_proxy_free(struct com_proxy *proxy);
static HRESULT STDMETHODCALLTYPE com_proxy_query_interface(
IUnknown *unk,
REFIID iid,
void **iface);
static HRESULT STDMETHODCALLTYPE
com_proxy_query_interface(IUnknown *unk, REFIID iid, void **iface);
static ULONG STDMETHODCALLTYPE com_proxy_addref(IUnknown *unk);
static ULONG STDMETHODCALLTYPE com_proxy_release(IUnknown *unk);
#ifdef __amd64
/***** 64-BIT TRAMPOLINE *****/
/***** 64-BIT TRAMPOLINE *****/
#define SLOT_OFFSET 0x0A
static const uint8_t com_proxy_tramp[] = {
/* mov rcx, [rcx+8] ; Get this->real */
0x48, 0x8B, 0x49, 0x08,
0x48,
0x8B,
0x49,
0x08,
/* mov rax, [rcx] ; Get this->vtbl */
0x48, 0x8B, 0x01,
0x48,
0x8B,
0x01,
/* mov rax, [rax+XX] ; Get vtbl->slot_XX */
0x48, 0x8B, 0x80, -1, -1, -1, -1,
0x48,
0x8B,
0x80,
-1,
-1,
-1,
-1,
/* jmp rax ; Continue to slot_XX */
0xFF, 0xE0,
0xFF,
0xE0,
};
#else
/***** 32-BIT TRAMPOLINE *****/
/***** 32-BIT TRAMPOLINE *****/
#define SLOT_OFFSET 0x0F
static const uint8_t com_proxy_tramp[] = {
/* mov eax, [esp+4] ; Get this */
0x8B, 0x44, 0x24, 0x04,
0x8B,
0x44,
0x24,
0x04,
/* mov eax, [eax+4] ; Get this->real */
0x8B, 0x40, 0x04,
0x8B,
0x40,
0x04,
/* mov [esp+4], eax ; Replace this with this->real on stack */
0x89, 0x44, 0x24, 0x04,
0x89,
0x44,
0x24,
0x04,
/* mov ecx, [eax] ; Get this->vtbl */
0x8B, 0x08,
0x8B,
0x08,
/* mov ecx, [ecx+XX] ; Get vtbl->slot_XX */
0x8B, 0x89, -1, -1, -1, -1,
0x8B,
0x89,
-1,
-1,
-1,
-1,
/* jmp ecx ; Continue to slot_XX */
0xFF, 0xE1
};
0xFF,
0xE1};
#endif
HRESULT com_proxy_wrap(
struct com_proxy **out,
void *real,
size_t vtbl_size)
HRESULT com_proxy_wrap(struct com_proxy **out, void *real, size_t vtbl_size)
{
struct com_proxy *proxy;
void **vtbl;
@@ -97,10 +118,10 @@ HRESULT com_proxy_wrap(
nslots = vtbl_size / sizeof(void *);
proxy->tramps = VirtualAlloc(
NULL,
sizeof(com_proxy_tramp) * nslots,
MEM_RESERVE | MEM_COMMIT,
PAGE_EXECUTE_READWRITE);
NULL,
sizeof(com_proxy_tramp) * nslots,
MEM_RESERVE | MEM_COMMIT,
PAGE_EXECUTE_READWRITE);
if (proxy->tramps == NULL) {
hr = E_OUTOFMEMORY;
@@ -119,7 +140,7 @@ HRESULT com_proxy_wrap(
/* Populate trampoline code for remaining vtbl entries */
for (i = 3 /* Skip IUnknown */ ; i < nslots ; i++) {
for (i = 3 /* Skip IUnknown */; i < nslots; i++) {
cur_tramp = proxy->tramps + i * sizeof(com_proxy_tramp);
/* Copy template */
@@ -160,10 +181,8 @@ static void com_proxy_free(struct com_proxy *proxy)
free(proxy);
}
static HRESULT STDMETHODCALLTYPE com_proxy_query_interface(
IUnknown *unk,
REFIID iid,
void **iface)
static HRESULT STDMETHODCALLTYPE
com_proxy_query_interface(IUnknown *unk, REFIID iid, void **iface)
{
struct com_proxy *proxy;
IUnknown *obj;
+1 -4
View File
@@ -49,7 +49,4 @@ struct com_proxy {
unless you provide a custom QueryInterface implementation to prevent them
from doing so. */
HRESULT com_proxy_wrap(
struct com_proxy **out,
void *real,
size_t vtbl_size);
HRESULT com_proxy_wrap(struct com_proxy **out, void *real, size_t vtbl_size);
+20 -29
View File
@@ -72,13 +72,12 @@ static HRESULT(STDCALL *real_DrawPrimitiveUP)(
UINT stride);
static HRESULT(STDCALL *real_Reset)(
IDirect3DDevice9 *self,
D3DPRESENT_PARAMETERS *pp);
IDirect3DDevice9 *self, D3DPRESENT_PARAMETERS *pp);
static HRESULT (STDCALL *real_SetViewport)(
static HRESULT(STDCALL *real_SetViewport)(
IDirect3DDevice9 *self, const D3DVIEWPORT9 *pViewport);
static HRESULT (STDCALL *real_SetVertexShader)(
static HRESULT(STDCALL *real_SetVertexShader)(
IDirect3DDevice9 *self, IDirect3DVertexShader9 *pShader);
/* ------------------------------------------------------------------------------------------------------------------
@@ -146,15 +145,14 @@ static HRESULT STDCALL my_DrawPrimitiveUP(
const void *data,
UINT stride);
static HRESULT STDCALL my_Reset(
IDirect3DDevice9 *self,
D3DPRESENT_PARAMETERS *pp);
static HRESULT STDCALL
my_Reset(IDirect3DDevice9 *self, D3DPRESENT_PARAMETERS *pp);
static HRESULT STDCALL my_SetViewport(
IDirect3DDevice9 *self, const D3DVIEWPORT9 *pViewport);
static HRESULT STDCALL
my_SetViewport(IDirect3DDevice9 *self, const D3DVIEWPORT9 *pViewport);
static HRESULT STDCALL my_SetVertexShader(
IDirect3DDevice9 *self, IDirect3DVertexShader9 *pShader);
static HRESULT STDCALL
my_SetVertexShader(IDirect3DDevice9 *self, IDirect3DVertexShader9 *pShader);
/* ------------------------------------------------------------------------------------------------------------------
*/
@@ -214,8 +212,7 @@ hook_d3d9_irp_handler_real_dev_set_render_state(struct hook_d3d9_irp *irp);
static HRESULT
hook_d3d9_irp_handler_real_dev_draw_primitive_up(struct hook_d3d9_irp *irp);
static HRESULT
hook_d3d9_irp_handler_real_dev_reset(struct hook_d3d9_irp *irp);
static HRESULT hook_d3d9_irp_handler_real_dev_reset(struct hook_d3d9_irp *irp);
static HRESULT
hook_d3d9_irp_handler_real_dev_set_viewport(struct hook_d3d9_irp *irp);
@@ -247,8 +244,7 @@ static const hook_d3d9_irp_handler_t hook_d3d9_irp_real_handlers[] = {
hook_d3d9_irp_handler_real_dev_set_render_state,
[HOOK_D3D9_IRP_OP_DEV_DRAW_PRIMITIVE_UP] =
hook_d3d9_irp_handler_real_dev_draw_primitive_up,
[HOOK_D3D9_IRP_OP_DEV_RESET] =
hook_d3d9_irp_handler_real_dev_reset,
[HOOK_D3D9_IRP_OP_DEV_RESET] = hook_d3d9_irp_handler_real_dev_reset,
[HOOK_D3D9_IRP_OP_DEV_SET_VIEWPORT] =
hook_d3d9_irp_handler_real_dev_set_viewport,
[HOOK_D3D9_IRP_OP_DEV_SET_VERTEX_SHADER] =
@@ -523,8 +519,8 @@ static HRESULT STDCALL my_DrawPrimitiveUP(
return hr;
}
static HRESULT STDCALL my_SetViewport(
IDirect3DDevice9 *self, const D3DVIEWPORT9 *pViewport)
static HRESULT STDCALL
my_SetViewport(IDirect3DDevice9 *self, const D3DVIEWPORT9 *pViewport)
{
struct hook_d3d9_irp irp;
HRESULT hr;
@@ -540,8 +536,8 @@ static HRESULT STDCALL my_SetViewport(
return hr;
}
static HRESULT STDCALL my_SetVertexShader(
IDirect3DDevice9 *self, IDirect3DVertexShader9 *pShader)
static HRESULT STDCALL
my_SetVertexShader(IDirect3DDevice9 *self, IDirect3DVertexShader9 *pShader)
{
struct hook_d3d9_irp irp;
HRESULT hr;
@@ -557,9 +553,8 @@ static HRESULT STDCALL my_SetVertexShader(
return hr;
}
static HRESULT STDCALL my_Reset(
IDirect3DDevice9 *self,
D3DPRESENT_PARAMETERS *pp)
static HRESULT STDCALL
my_Reset(IDirect3DDevice9 *self, D3DPRESENT_PARAMETERS *pp)
{
struct hook_d3d9_irp irp;
HRESULT hr;
@@ -827,14 +822,11 @@ hook_d3d9_irp_handler_real_dev_draw_primitive_up(struct hook_d3d9_irp *irp)
irp->args.dev_draw_primitive_up.stride);
}
static HRESULT
hook_d3d9_irp_handler_real_dev_reset(struct hook_d3d9_irp *irp)
static HRESULT hook_d3d9_irp_handler_real_dev_reset(struct hook_d3d9_irp *irp)
{
log_assert(irp);
return real_Reset(
irp->args.dev_reset.self,
irp->args.dev_reset.pp);
return real_Reset(irp->args.dev_reset.self, irp->args.dev_reset.pp);
}
static HRESULT
@@ -843,8 +835,7 @@ hook_d3d9_irp_handler_real_dev_set_viewport(struct hook_d3d9_irp *irp)
log_assert(irp);
return real_SetViewport(
irp->args.dev_set_viewport.self,
irp->args.dev_set_viewport.pViewport);
irp->args.dev_set_viewport.self, irp->args.dev_set_viewport.pViewport);
}
static HRESULT
+22 -11
View File
@@ -12,17 +12,28 @@ uint32_t hr_to_win32_error(HRESULT hr)
return HRESULT_CODE(hr);
} else {
switch (hr) {
case E_ABORT: return ERROR_OPERATION_ABORTED;
case E_ACCESSDENIED: return ERROR_ACCESS_DENIED;
case E_FAIL: return ERROR_GEN_FAILURE;
case E_HANDLE: return ERROR_INVALID_HANDLE;
case E_INVALIDARG: return ERROR_INVALID_PARAMETER;
case E_NOINTERFACE: return ERROR_INVALID_FUNCTION;
case E_NOTIMPL: return ERROR_NOT_SUPPORTED;
case E_OUTOFMEMORY: return ERROR_OUTOFMEMORY;
case E_POINTER: return ERROR_INVALID_ADDRESS;
case E_UNEXPECTED: return ERROR_INTERNAL_ERROR;
default: return ERROR_INTERNAL_ERROR;
case E_ABORT:
return ERROR_OPERATION_ABORTED;
case E_ACCESSDENIED:
return ERROR_ACCESS_DENIED;
case E_FAIL:
return ERROR_GEN_FAILURE;
case E_HANDLE:
return ERROR_INVALID_HANDLE;
case E_INVALIDARG:
return ERROR_INVALID_PARAMETER;
case E_NOINTERFACE:
return ERROR_INVALID_FUNCTION;
case E_NOTIMPL:
return ERROR_NOT_SUPPORTED;
case E_OUTOFMEMORY:
return ERROR_OUTOFMEMORY;
case E_POINTER:
return ERROR_INVALID_ADDRESS;
case E_UNEXPECTED:
return ERROR_INTERNAL_ERROR;
default:
return ERROR_INTERNAL_ERROR;
}
}
}
+6 -6
View File
@@ -95,7 +95,7 @@ HRESULT iobuf_read_be16(struct const_iobuf *src, uint16_t *out)
return HRESULT_FROM_WIN32(ERROR_INSUFFICIENT_BUFFER);
}
value = src->bytes[src->pos++] << 8;
value = src->bytes[src->pos++] << 8;
value |= src->bytes[src->pos++];
*out = value;
@@ -114,7 +114,7 @@ HRESULT iobuf_read_be32(struct const_iobuf *src, uint32_t *out)
return HRESULT_FROM_WIN32(ERROR_INSUFFICIENT_BUFFER);
}
value = src->bytes[src->pos++] << 24;
value = src->bytes[src->pos++] << 24;
value |= src->bytes[src->pos++] << 16;
value |= src->bytes[src->pos++] << 8;
value |= src->bytes[src->pos++];
@@ -135,7 +135,7 @@ HRESULT iobuf_read_be64(struct const_iobuf *src, uint64_t *out)
return HRESULT_FROM_WIN32(ERROR_INSUFFICIENT_BUFFER);
}
value = ((uint64_t) src->bytes[src->pos++]) << 56;
value = ((uint64_t) src->bytes[src->pos++]) << 56;
value |= ((uint64_t) src->bytes[src->pos++]) << 48;
value |= ((uint64_t) src->bytes[src->pos++]) << 40;
value |= ((uint64_t) src->bytes[src->pos++]) << 32;
@@ -160,7 +160,7 @@ HRESULT iobuf_read_le16(struct const_iobuf *src, uint16_t *out)
return HRESULT_FROM_WIN32(ERROR_INSUFFICIENT_BUFFER);
}
value = src->bytes[src->pos++];
value = src->bytes[src->pos++];
value |= src->bytes[src->pos++] << 8;
*out = value;
@@ -179,7 +179,7 @@ HRESULT iobuf_read_le32(struct const_iobuf *src, uint32_t *out)
return HRESULT_FROM_WIN32(ERROR_INSUFFICIENT_BUFFER);
}
value = src->bytes[src->pos++];
value = src->bytes[src->pos++];
value |= src->bytes[src->pos++] << 8;
value |= src->bytes[src->pos++] << 16;
value |= src->bytes[src->pos++] << 24;
@@ -200,7 +200,7 @@ HRESULT iobuf_read_le64(struct const_iobuf *src, uint64_t *out)
return HRESULT_FROM_WIN32(ERROR_INSUFFICIENT_BUFFER);
}
value = ((uint64_t) src->bytes[src->pos++]);
value = ((uint64_t) src->bytes[src->pos++]);
value |= ((uint64_t) src->bytes[src->pos++]) << 8;
value |= ((uint64_t) src->bytes[src->pos++]) << 16;
value |= ((uint64_t) src->bytes[src->pos++]) << 24;
+240 -251
View File
@@ -4,9 +4,9 @@
#undef WIN32_NO_STATUS
#include <winternl.h>
#include <winnt.h>
#include <devioctl.h>
#include <ntstatus.h>
#include <winnt.h>
#include <assert.h>
#include <stdbool.h>
@@ -21,10 +21,8 @@
/* Helpers */
static void iohook_init(void);
static BOOL iohook_overlapped_result(
uint32_t *syncout,
OVERLAPPED *ovl,
uint32_t value);
static BOOL
iohook_overlapped_result(uint32_t *syncout, OVERLAPPED *ovl, uint32_t value);
static HRESULT iohook_invoke_real(struct irp *irp);
static HRESULT iohook_invoke_real_open(struct irp *irp);
@@ -41,171 +39,175 @@ static HRESULT iohook_invoke_real_ioctl(struct irp *irp);
static BOOL WINAPI iohook_CloseHandle(HANDLE fd);
static HANDLE WINAPI iohook_CreateFileW(
const wchar_t *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile);
const wchar_t *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile);
static HANDLE WINAPI iohook_CreateFileA(
const char *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile);
const char *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile);
static BOOL WINAPI iohook_ReadFile(
HANDLE hFile,
void *lpBuffer,
uint32_t nNumberOfBytesToRead,
uint32_t *lpNumberOfBytesRead,
OVERLAPPED *lpOverlapped);
HANDLE hFile,
void *lpBuffer,
uint32_t nNumberOfBytesToRead,
uint32_t *lpNumberOfBytesRead,
OVERLAPPED *lpOverlapped);
static BOOL WINAPI iohook_WriteFile(
HANDLE hFile,
const void *lpBuffer,
uint32_t nNumberOfBytesToWrite,
uint32_t *lpNumberOfBytesWritten,
OVERLAPPED *lpOverlapped);
HANDLE hFile,
const void *lpBuffer,
uint32_t nNumberOfBytesToWrite,
uint32_t *lpNumberOfBytesWritten,
OVERLAPPED *lpOverlapped);
static DWORD WINAPI iohook_SetFilePointer(
HANDLE hFile,
int32_t lDistanceToMove,
int32_t *lpDistanceToMoveHigh,
uint32_t dwMoveMethod);
HANDLE hFile,
int32_t lDistanceToMove,
int32_t *lpDistanceToMoveHigh,
uint32_t dwMoveMethod);
static BOOL WINAPI iohook_SetFilePointerEx(
HANDLE hFile,
int64_t liDistanceToMove,
uint64_t *lpNewFilePointer,
uint32_t dwMoveMethod);
HANDLE hFile,
int64_t liDistanceToMove,
uint64_t *lpNewFilePointer,
uint32_t dwMoveMethod);
static BOOL WINAPI iohook_FlushFileBuffers(HANDLE hFile);
static BOOL WINAPI iohook_DeviceIoControl(
HANDLE hFile,
uint32_t dwIoControlCode,
void *lpInBuffer,
uint32_t nInBufferSize,
void *lpOutBuffer,
uint32_t nOutBufferSize,
uint32_t *lpBytesReturned,
OVERLAPPED *lpOverlapped);
HANDLE hFile,
uint32_t dwIoControlCode,
void *lpInBuffer,
uint32_t nInBufferSize,
void *lpOutBuffer,
uint32_t nOutBufferSize,
uint32_t *lpBytesReturned,
OVERLAPPED *lpOverlapped);
/* Links */
static BOOL (WINAPI *next_CloseHandle)(HANDLE fd);
static BOOL(WINAPI *next_CloseHandle)(HANDLE fd);
static HANDLE (WINAPI *next_CreateFileA)(
const char *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile);
static HANDLE(WINAPI *next_CreateFileA)(
const char *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile);
static HANDLE (WINAPI *next_CreateFileW)(
const wchar_t *filename,
uint32_t access,
uint32_t share,
SECURITY_ATTRIBUTES *sa,
uint32_t creation,
uint32_t flags,
HANDLE tmpl);
static HANDLE(WINAPI *next_CreateFileW)(
const wchar_t *filename,
uint32_t access,
uint32_t share,
SECURITY_ATTRIBUTES *sa,
uint32_t creation,
uint32_t flags,
HANDLE tmpl);
static BOOL (WINAPI *next_DeviceIoControl)(
HANDLE fd,
uint32_t code,
void *in_bytes,
uint32_t in_nbytes,
void *out_bytes,
uint32_t out_nbytes,
uint32_t *out_returned,
OVERLAPPED *ovl);
static BOOL(WINAPI *next_DeviceIoControl)(
HANDLE fd,
uint32_t code,
void *in_bytes,
uint32_t in_nbytes,
void *out_bytes,
uint32_t out_nbytes,
uint32_t *out_returned,
OVERLAPPED *ovl);
static BOOL (WINAPI *next_ReadFile)(
HANDLE fd,
void *buf,
uint32_t nbytes,
uint32_t *nread,
OVERLAPPED *ovl);
static BOOL(WINAPI *next_ReadFile)(
HANDLE fd, void *buf, uint32_t nbytes, uint32_t *nread, OVERLAPPED *ovl);
static BOOL (WINAPI *next_WriteFile)(
HANDLE fd,
const void *buf,
uint32_t nbytes,
uint32_t *nwrit,
OVERLAPPED *ovl);
static BOOL(WINAPI *next_WriteFile)(
HANDLE fd,
const void *buf,
uint32_t nbytes,
uint32_t *nwrit,
OVERLAPPED *ovl);
static DWORD (WINAPI *next_SetFilePointer)(
HANDLE hFile,
int32_t lDistanceToMove,
int32_t *lpDistanceToMoveHigh,
uint32_t dwMoveMethod);
static DWORD(WINAPI *next_SetFilePointer)(
HANDLE hFile,
int32_t lDistanceToMove,
int32_t *lpDistanceToMoveHigh,
uint32_t dwMoveMethod);
static BOOL (WINAPI *next_SetFilePointerEx)(
HANDLE hFile,
int64_t liDistanceToMove,
uint64_t *lpNewFilePointer,
uint32_t dwMoveMethod);
static BOOL(WINAPI *next_SetFilePointerEx)(
HANDLE hFile,
int64_t liDistanceToMove,
uint64_t *lpNewFilePointer,
uint32_t dwMoveMethod);
static BOOL (WINAPI *next_FlushFileBuffers)(HANDLE fd);
static BOOL(WINAPI *next_FlushFileBuffers)(HANDLE fd);
/* Hook symbol table */
static const struct hook_symbol iohook_kernel32_syms[] = {
{
.name = "CloseHandle",
.patch = iohook_CloseHandle,
.link = (void *) &next_CloseHandle,
}, {
.name = "CreateFileA",
.patch = iohook_CreateFileA,
.link = (void *) &next_CreateFileA,
}, {
.name = "CreateFileW",
.patch = iohook_CreateFileW,
.link = (void *) &next_CreateFileW,
}, {
.name = "DeviceIoControl",
.patch = iohook_DeviceIoControl,
.link = (void *) &next_DeviceIoControl,
}, {
.name = "ReadFile",
.patch = iohook_ReadFile,
.link = (void *) &next_ReadFile,
}, {
.name = "WriteFile",
.patch = iohook_WriteFile,
.link = (void *) &next_WriteFile,
}, {
.name = "SetFilePointer",
.patch = iohook_SetFilePointer,
.link = (void *) &next_SetFilePointer,
}, {
.name = "SetFilePointerEx",
.patch = iohook_SetFilePointerEx,
.link = (void *) &next_SetFilePointerEx,
}, {
.name = "FlushFileBuffers",
.patch = iohook_FlushFileBuffers,
.link = (void *) &next_FlushFileBuffers,
.name = "CloseHandle",
.patch = iohook_CloseHandle,
.link = (void *) &next_CloseHandle,
},
{
.name = "CreateFileA",
.patch = iohook_CreateFileA,
.link = (void *) &next_CreateFileA,
},
{
.name = "CreateFileW",
.patch = iohook_CreateFileW,
.link = (void *) &next_CreateFileW,
},
{
.name = "DeviceIoControl",
.patch = iohook_DeviceIoControl,
.link = (void *) &next_DeviceIoControl,
},
{
.name = "ReadFile",
.patch = iohook_ReadFile,
.link = (void *) &next_ReadFile,
},
{
.name = "WriteFile",
.patch = iohook_WriteFile,
.link = (void *) &next_WriteFile,
},
{
.name = "SetFilePointer",
.patch = iohook_SetFilePointer,
.link = (void *) &next_SetFilePointer,
},
{
.name = "SetFilePointerEx",
.patch = iohook_SetFilePointerEx,
.link = (void *) &next_SetFilePointerEx,
},
{
.name = "FlushFileBuffers",
.patch = iohook_FlushFileBuffers,
.link = (void *) &next_FlushFileBuffers,
},
};
static const iohook_fn_t iohook_real_handlers[] = {
[IRP_OP_OPEN] = iohook_invoke_real_open,
[IRP_OP_CLOSE] = iohook_invoke_real_close,
[IRP_OP_READ] = iohook_invoke_real_read,
[IRP_OP_WRITE] = iohook_invoke_real_write,
[IRP_OP_SEEK] = iohook_invoke_real_seek,
[IRP_OP_FSYNC] = iohook_invoke_real_fsync,
[IRP_OP_IOCTL] = iohook_invoke_real_ioctl,
[IRP_OP_OPEN] = iohook_invoke_real_open,
[IRP_OP_CLOSE] = iohook_invoke_real_close,
[IRP_OP_READ] = iohook_invoke_real_read,
[IRP_OP_WRITE] = iohook_invoke_real_write,
[IRP_OP_SEEK] = iohook_invoke_real_seek,
[IRP_OP_FSYNC] = iohook_invoke_real_fsync,
[IRP_OP_IOCTL] = iohook_invoke_real_ioctl,
};
static bool iohook_initted;
@@ -233,10 +235,10 @@ static void iohook_init(void)
/* Splice iohook into IAT entries referencing Win32 I/O APIs */
hook_table_apply(
NULL,
"kernel32.dll",
iohook_kernel32_syms,
_countof(iohook_kernel32_syms));
NULL,
"kernel32.dll",
iohook_kernel32_syms,
_countof(iohook_kernel32_syms));
/* Here be dragons:
@@ -268,15 +270,12 @@ static void iohook_init(void)
kernel32 = GetModuleHandleW(L"kernel32.dll");
if (next_CreateFileW == NULL) {
next_CreateFileW = (void *) GetProcAddress(
kernel32,
"CreateFileW");
next_CreateFileW = (void *) GetProcAddress(kernel32, "CreateFileW");
}
if (next_SetFilePointerEx == NULL) {
next_SetFilePointerEx = (void *) GetProcAddress(
kernel32,
"SetFilePointerEx");
next_SetFilePointerEx =
(void *) GetProcAddress(kernel32, "SetFilePointerEx");
}
LeaveCriticalSection(&iohook_lock);
@@ -288,13 +287,13 @@ HANDLE iohook_open_dummy_fd(void)
iohook_init();
return next_CreateFileW(
L"NUL",
GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
FILE_FLAG_OVERLAPPED,
NULL);
L"NUL",
GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
FILE_FLAG_OVERLAPPED,
NULL);
}
HRESULT iohook_open_nul_fd(HANDLE *out)
@@ -307,13 +306,13 @@ HRESULT iohook_open_nul_fd(HANDLE *out)
iohook_init();
fd = next_CreateFileW(
L"NUL",
GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
FILE_FLAG_OVERLAPPED,
NULL);
L"NUL",
GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE,
NULL,
OPEN_EXISTING,
FILE_FLAG_OVERLAPPED,
NULL);
if (fd == NULL) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -351,10 +350,8 @@ HRESULT iohook_push_handler(iohook_fn_t fn)
return hr;
}
static BOOL iohook_overlapped_result(
uint32_t *syncout,
OVERLAPPED *ovl,
uint32_t value)
static BOOL
iohook_overlapped_result(uint32_t *syncout, OVERLAPPED *ovl, uint32_t value)
{
if (ovl != NULL) {
ovl->Internal = STATUS_SUCCESS;
@@ -429,13 +426,13 @@ static HRESULT iohook_invoke_real_open(struct irp *irp)
assert(irp != NULL);
fd = next_CreateFileW(
irp->open_filename,
irp->open_access,
irp->open_share,
irp->open_sa,
irp->open_creation,
irp->open_flags,
irp->open_tmpl);
irp->open_filename,
irp->open_access,
irp->open_share,
irp->open_sa,
irp->open_creation,
irp->open_flags,
irp->open_tmpl);
if (fd == INVALID_HANDLE_VALUE) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -469,11 +466,11 @@ static HRESULT iohook_invoke_real_read(struct irp *irp)
assert(irp != NULL);
ok = next_ReadFile(
irp->fd,
&irp->read.bytes[irp->read.pos],
irp->read.nbytes - irp->read.pos,
&nread,
irp->ovl);
irp->fd,
&irp->read.bytes[irp->read.pos],
irp->read.nbytes - irp->read.pos,
&nread,
irp->ovl);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -492,11 +489,11 @@ static HRESULT iohook_invoke_real_write(struct irp *irp)
assert(irp != NULL);
ok = next_WriteFile(
irp->fd,
&irp->write.bytes[irp->write.pos],
irp->write.nbytes - irp->write.pos,
&nwrit,
irp->ovl);
irp->fd,
&irp->write.bytes[irp->write.pos],
irp->write.nbytes - irp->write.pos,
&nwrit,
irp->ovl);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -514,10 +511,7 @@ static HRESULT iohook_invoke_real_seek(struct irp *irp)
assert(irp != NULL);
ok = next_SetFilePointerEx(
irp->fd,
irp->seek_offset,
&irp->seek_pos,
irp->seek_origin);
irp->fd, irp->seek_offset, &irp->seek_pos, irp->seek_origin);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -556,14 +550,14 @@ static HRESULT iohook_invoke_real_ioctl(struct irp *irp)
assert(irp->read.pos == 0);
ok = next_DeviceIoControl(
irp->fd,
irp->ioctl,
(void *) irp->write.bytes, // Cast off const
irp->write.nbytes,
irp->read.bytes,
irp->read.nbytes,
&nread,
irp->ovl);
irp->fd,
irp->ioctl,
(void *) irp->write.bytes, // Cast off const
irp->write.nbytes,
irp->read.bytes,
irp->read.nbytes,
&nread,
irp->ovl);
/* Must be propagated even if there is an error, see
iohook_DeviceIoControl. */
@@ -578,13 +572,13 @@ static HRESULT iohook_invoke_real_ioctl(struct irp *irp)
}
static HANDLE WINAPI iohook_CreateFileA(
const char *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile)
const char *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile)
{
wchar_t *wfilename;
int nchars;
@@ -616,12 +610,13 @@ static HANDLE WINAPI iohook_CreateFileA(
}
fd = iohook_CreateFileW(
wfilename,
dwDesiredAccess,
dwShareMode,
lpSecurityAttributes,
dwCreationDisposition, dwFlagsAndAttributes,
hTemplateFile);
wfilename,
dwDesiredAccess,
dwShareMode,
lpSecurityAttributes,
dwCreationDisposition,
dwFlagsAndAttributes,
hTemplateFile);
end:
free(wfilename);
@@ -630,13 +625,13 @@ end:
}
static HANDLE WINAPI iohook_CreateFileW(
const wchar_t *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile)
const wchar_t *lpFileName,
uint32_t dwDesiredAccess,
uint32_t dwShareMode,
SECURITY_ATTRIBUTES *lpSecurityAttributes,
uint32_t dwCreationDisposition,
uint32_t dwFlagsAndAttributes,
HANDLE hTemplateFile)
{
struct irp irp;
HRESULT hr;
@@ -696,11 +691,11 @@ static BOOL WINAPI iohook_CloseHandle(HANDLE hFile)
}
static BOOL WINAPI iohook_ReadFile(
HANDLE hFile,
void *lpBuffer,
uint32_t nNumberOfBytesToRead,
uint32_t *lpNumberOfBytesRead,
OVERLAPPED *lpOverlapped)
HANDLE hFile,
void *lpBuffer,
uint32_t nNumberOfBytesToRead,
uint32_t *lpNumberOfBytesRead,
OVERLAPPED *lpOverlapped)
{
struct irp irp;
HRESULT hr;
@@ -738,17 +733,15 @@ static BOOL WINAPI iohook_ReadFile(
assert(irp.read.pos <= irp.read.nbytes);
return iohook_overlapped_result(
lpNumberOfBytesRead,
lpOverlapped,
irp.read.pos);
lpNumberOfBytesRead, lpOverlapped, irp.read.pos);
}
static BOOL WINAPI iohook_WriteFile(
HANDLE hFile,
const void *lpBuffer,
uint32_t nNumberOfBytesToWrite,
uint32_t *lpNumberOfBytesWritten,
OVERLAPPED *lpOverlapped)
HANDLE hFile,
const void *lpBuffer,
uint32_t nNumberOfBytesToWrite,
uint32_t *lpNumberOfBytesWritten,
OVERLAPPED *lpOverlapped)
{
struct irp irp;
HRESULT hr;
@@ -786,16 +779,14 @@ static BOOL WINAPI iohook_WriteFile(
assert(irp.write.pos <= irp.write.nbytes);
return iohook_overlapped_result(
lpNumberOfBytesWritten,
lpOverlapped,
irp.write.pos);
lpNumberOfBytesWritten, lpOverlapped, irp.write.pos);
}
static DWORD WINAPI iohook_SetFilePointer(
HANDLE hFile,
int32_t lDistanceToMove,
int32_t *lpDistanceToMoveHigh,
uint32_t dwMoveMethod)
HANDLE hFile,
int32_t lDistanceToMove,
int32_t *lpDistanceToMoveHigh,
uint32_t dwMoveMethod)
{
struct irp irp;
HRESULT hr;
@@ -816,10 +807,10 @@ static DWORD WINAPI iohook_SetFilePointer(
with sign-extension vs zero-extension here. */
if (lpDistanceToMoveHigh != NULL) {
irp.seek_offset = ((( int64_t) *lpDistanceToMoveHigh) << 32) |
((uint64_t) lDistanceToMove ) ;
irp.seek_offset = (((int64_t) *lpDistanceToMoveHigh) << 32) |
((uint64_t) lDistanceToMove);
} else {
irp.seek_offset = ( int64_t) lDistanceToMove;
irp.seek_offset = (int64_t) lDistanceToMove;
}
hr = iohook_invoke_next(&irp);
@@ -838,10 +829,10 @@ static DWORD WINAPI iohook_SetFilePointer(
}
static BOOL WINAPI iohook_SetFilePointerEx(
HANDLE hFile,
int64_t liDistanceToMove,
uint64_t *lpNewFilePointer,
uint32_t dwMoveMethod)
HANDLE hFile,
int64_t liDistanceToMove,
uint64_t *lpNewFilePointer,
uint32_t dwMoveMethod)
{
struct irp irp;
HRESULT hr;
@@ -902,14 +893,14 @@ static BOOL WINAPI iohook_FlushFileBuffers(HANDLE hFile)
}
static BOOL WINAPI iohook_DeviceIoControl(
HANDLE hFile,
uint32_t dwIoControlCode,
void *lpInBuffer,
uint32_t nInBufferSize,
void *lpOutBuffer,
uint32_t nOutBufferSize,
uint32_t *lpBytesReturned,
OVERLAPPED *lpOverlapped)
HANDLE hFile,
uint32_t dwIoControlCode,
void *lpInBuffer,
uint32_t nInBufferSize,
void *lpOutBuffer,
uint32_t nOutBufferSize,
uint32_t *lpBytesReturned,
OVERLAPPED *lpOverlapped)
{
struct irp irp;
HRESULT hr;
@@ -963,7 +954,5 @@ static BOOL WINAPI iohook_DeviceIoControl(
}
return iohook_overlapped_result(
lpBytesReturned,
lpOverlapped,
irp.read.pos);
lpBytesReturned, lpOverlapped, irp.read.pos);
}
+2 -2
View File
@@ -41,9 +41,9 @@ typedef HRESULT (*iohook_fn_t)(struct irp *irp);
HANDLE iohook_open_dummy_fd(void)
#ifdef __GNUC__
__attribute__((deprecated("Use iohook_open_nul_fd instead")))
__attribute__((deprecated("Use iohook_open_nul_fd instead")))
#endif
;
;
HRESULT iohook_open_nul_fd(HANDLE *fd);
HRESULT iohook_push_handler(iohook_fn_t fn);
+19 -24
View File
@@ -94,10 +94,7 @@ const pe_iid_t *pe_iid_get_next(HMODULE pe, const pe_iid_t *iid)
}
HRESULT pe_iid_get_iat_entry(
HMODULE pe,
const pe_iid_t *iid,
size_t n,
struct pe_iat_entry *entry)
HMODULE pe, const pe_iid_t *iid, size_t n, struct pe_iat_entry *entry)
{
const IMAGE_IMPORT_BY_NAME *import;
intptr_t *import_rvas;
@@ -153,7 +150,7 @@ void *pe_get_export(HMODULE pe, const char *name, uint16_t ord)
target_rvas = pe_offsetc(pe, ied->AddressOfFunctions);
if (name != NULL) {
for (i = 0 ; i < ied->NumberOfNames ; i++) {
for (i = 0; i < ied->NumberOfNames; i++) {
if (name_rvas[i] == 0) {
/* Ordinal-only export, cannot match against this */
continue;
@@ -196,11 +193,7 @@ HRESULT pe_patch(void *dest, const void *src, size_t nbytes)
assert(dest != NULL);
assert(src != NULL);
ok = VirtualProtect(
dest,
nbytes,
PAGE_EXECUTE_READWRITE,
&old_protect);
ok = VirtualProtect(dest, nbytes, PAGE_EXECUTE_READWRITE, &old_protect);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -208,11 +201,7 @@ HRESULT pe_patch(void *dest, const void *src, size_t nbytes)
memcpy(dest, src, nbytes);
ok = VirtualProtect(
dest,
nbytes,
old_protect,
&old_protect);
ok = VirtualProtect(dest, nbytes, old_protect, &old_protect);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -252,7 +241,8 @@ const pe_thunk_t *pe_thunk_get_next(const pe_thunk_t *thunk)
return thunk_next;
}
void *pe_thunk_get_resolved_function(HMODULE target_pe, HMODULE import_pe, const pe_thunk_t *thunk)
void *pe_thunk_get_resolved_function(
HMODULE target_pe, HMODULE import_pe, const pe_thunk_t *thunk)
{
void *addr;
@@ -262,11 +252,12 @@ void *pe_thunk_get_resolved_function(HMODULE target_pe, HMODULE import_pe, const
if (thunk->u1.AddressOfData != 0) {
if (IMAGE_SNAP_BY_ORDINAL(thunk->u1.Ordinal)) {
LPCSTR functionOrdinal = (LPCSTR)IMAGE_ORDINAL(thunk->u1.Ordinal);
addr = (void *)GetProcAddress(import_pe, functionOrdinal);
LPCSTR functionOrdinal = (LPCSTR) IMAGE_ORDINAL(thunk->u1.Ordinal);
addr = (void *) GetProcAddress(import_pe, functionOrdinal);
} else {
PIMAGE_IMPORT_BY_NAME functionName = pe_offset(target_pe, thunk->u1.AddressOfData);
addr = (void *)GetProcAddress(import_pe, functionName->Name);
PIMAGE_IMPORT_BY_NAME functionName =
pe_offset(target_pe, thunk->u1.AddressOfData);
addr = (void *) GetProcAddress(import_pe, functionName->Name);
}
} else {
addr = NULL;
@@ -277,7 +268,8 @@ void *pe_thunk_get_resolved_function(HMODULE target_pe, HMODULE import_pe, const
void pe_resolve_imports(HMODULE target_pe)
{
for (const pe_iid_t *iid = pe_iid_get_first(target_pe); iid != NULL; iid = pe_iid_get_next(target_pe, iid)) {
for (const pe_iid_t *iid = pe_iid_get_first(target_pe); iid != NULL;
iid = pe_iid_get_next(target_pe, iid)) {
const char *iid_name;
HMODULE imported_pe;
@@ -285,13 +277,16 @@ void pe_resolve_imports(HMODULE target_pe)
imported_pe = LoadLibraryA(iid_name);
assert(imported_pe != NULL);
for (const pe_thunk_t *thunk = pe_thunk_get_first(target_pe, iid); thunk != NULL; thunk = pe_thunk_get_next(thunk)) {
for (const pe_thunk_t *thunk = pe_thunk_get_first(target_pe, iid);
thunk != NULL;
thunk = pe_thunk_get_next(thunk)) {
void *addr;
addr = pe_thunk_get_resolved_function(target_pe, imported_pe, thunk);
addr =
pe_thunk_get_resolved_function(target_pe, imported_pe, thunk);
if (addr != NULL) {
pe_patch((void*)&thunk->u1.Function, &addr, sizeof(PDWORD));
pe_patch((void *) &thunk->u1.Function, &addr, sizeof(PDWORD));
}
}
}
+2 -5
View File
@@ -9,7 +9,7 @@
typedef IMAGE_IMPORT_DESCRIPTOR pe_iid_t;
typedef IMAGE_THUNK_DATA pe_thunk_t;
typedef DWORD (CALLBACK *dll_entry_t)(HMODULE self, DWORD reason, void *ctx);
typedef DWORD(CALLBACK *dll_entry_t)(HMODULE self, DWORD reason, void *ctx);
struct pe_iat_entry {
const char *name;
@@ -21,10 +21,7 @@ const pe_iid_t *pe_iid_get_first(HMODULE pe);
const char *pe_iid_get_name(HMODULE pe, const pe_iid_t *iid);
const pe_iid_t *pe_iid_get_next(HMODULE pe, const pe_iid_t *iid);
HRESULT pe_iid_get_iat_entry(
HMODULE pe,
const pe_iid_t *iid,
size_t n,
struct pe_iat_entry *entry);
HMODULE pe, const pe_iid_t *iid, size_t n, struct pe_iat_entry *entry);
void *pe_get_export(HMODULE pe, const char *name, uint16_t ord);
void *pe_get_entry_point(HMODULE pe);
HRESULT pe_patch(void *dest, const void *src, size_t nbytes);
+11 -24
View File
@@ -12,24 +12,18 @@
#include "hook/pe.h"
#include "hook/process.h"
static bool thread_match_startup(
const CONTEXT *ctx,
void *ntstart,
void *exe_entry)
static bool
thread_match_startup(const CONTEXT *ctx, void *ntstart, void *exe_entry)
{
#ifdef _M_AMD64
return ctx->Rip == (DWORD64) ntstart &&
ctx->Rcx == (DWORD64) exe_entry;
return ctx->Rip == (DWORD64) ntstart && ctx->Rcx == (DWORD64) exe_entry;
#else
return ctx->Eip == (DWORD) ntstart &&
ctx->Eax == (DWORD) exe_entry;
return ctx->Eip == (DWORD) ntstart && ctx->Eax == (DWORD) exe_entry;
#endif
}
static void thread_patch_startup(
process_entry_t new_entry,
process_entry_t *orig_entry,
CONTEXT *ctx)
process_entry_t new_entry, process_entry_t *orig_entry, CONTEXT *ctx)
{
#ifdef _M_AMD64
*orig_entry = (void *) ctx->Rcx;
@@ -41,9 +35,7 @@ static void thread_patch_startup(
}
static HRESULT process_hijack_try_thread(
process_entry_t new_entry,
process_entry_t *orig_entry,
DWORD thread_id)
process_entry_t new_entry, process_entry_t *orig_entry, DWORD thread_id)
{
CONTEXT ctx;
HMODULE exe;
@@ -85,10 +77,8 @@ static HRESULT process_hijack_try_thread(
goto end;
}
thread = OpenThread(
THREAD_GET_CONTEXT | THREAD_SET_CONTEXT,
FALSE,
thread_id);
thread =
OpenThread(THREAD_GET_CONTEXT | THREAD_SET_CONTEXT, FALSE, thread_id);
if (thread == NULL) {
hr = HRESULT_FROM_WIN32(GetLastError());
@@ -134,9 +124,8 @@ end:
return hr;
}
HRESULT process_hijack_startup(
process_entry_t new_entry,
process_entry_t *orig_entry)
HRESULT
process_hijack_startup(process_entry_t new_entry, process_entry_t *orig_entry)
{
THREADENTRY32 thread;
HANDLE snap;
@@ -175,9 +164,7 @@ HRESULT process_hijack_startup(
}
hr = process_hijack_try_thread(
new_entry,
orig_entry,
thread.th32ThreadID);
new_entry, orig_entry, thread.th32ThreadID);
if (hr == S_OK) {
/* Main thread successfully hijacked, finish up */
+3 -4
View File
@@ -2,8 +2,7 @@
#include <windows.h>
typedef DWORD (CALLBACK *process_entry_t)(void);
typedef DWORD(CALLBACK *process_entry_t)(void);
HRESULT process_hijack_startup(
process_entry_t new_entry,
process_entry_t *orig_entry);
HRESULT
process_hijack_startup(process_entry_t new_entry, process_entry_t *orig_entry);
+24 -38
View File
@@ -13,36 +13,27 @@ static const char apiset_prefix[] = "api-ms-win-core-";
static const size_t apiset_prefix_len = sizeof(apiset_prefix) - 1;
static void hook_table_apply_to_all(
const char *depname,
const struct hook_symbol *syms,
size_t nsyms);
const char *depname, const struct hook_symbol *syms, size_t nsyms);
static void hook_table_apply_to_iid(
HMODULE target,
const pe_iid_t *iid,
const struct hook_symbol *syms,
size_t nsyms);
HMODULE target,
const pe_iid_t *iid,
const struct hook_symbol *syms,
size_t nsyms);
static bool hook_table_match_module(
HMODULE target,
const char *iid_name,
const char *depname);
HMODULE target, const char *iid_name, const char *depname);
static bool hook_table_match_proc(
const struct pe_iat_entry *iate,
const struct hook_symbol *sym);
const struct pe_iat_entry *iate, const struct hook_symbol *sym);
static void hook_table_apply_to_all(
const char *depname,
const struct hook_symbol *syms,
size_t nsyms)
const char *depname, const struct hook_symbol *syms, size_t nsyms)
{
const peb_dll_t *dll;
HMODULE pe;
for ( dll = peb_dll_get_first() ;
dll != NULL ;
dll = peb_dll_get_next(dll)) {
for (dll = peb_dll_get_first(); dll != NULL; dll = peb_dll_get_next(dll)) {
pe = peb_dll_get_base(dll);
if (pe == NULL) {
@@ -54,10 +45,10 @@ static void hook_table_apply_to_all(
}
void hook_table_apply(
HMODULE target,
const char *depname,
const struct hook_symbol *syms,
size_t nsyms)
HMODULE target,
const char *depname,
const struct hook_symbol *syms,
size_t nsyms)
{
const pe_iid_t *iid;
const char *iid_name;
@@ -71,9 +62,8 @@ void hook_table_apply(
hook_table_apply_to_all(depname, syms, nsyms);
} else {
for ( iid = pe_iid_get_first(target) ;
iid != NULL ;
iid = pe_iid_get_next(target, iid)) {
for (iid = pe_iid_get_first(target); iid != NULL;
iid = pe_iid_get_next(target, iid)) {
iid_name = pe_iid_get_name(target, iid);
if (hook_table_match_module(target, iid_name, depname)) {
@@ -84,10 +74,10 @@ void hook_table_apply(
}
static void hook_table_apply_to_iid(
HMODULE target,
const pe_iid_t *iid,
const struct hook_symbol *syms,
size_t nsyms)
HMODULE target,
const pe_iid_t *iid,
const struct hook_symbol *syms,
size_t nsyms)
{
struct pe_iat_entry iate;
size_t i;
@@ -97,7 +87,7 @@ static void hook_table_apply_to_iid(
i = 0;
while (pe_iid_get_iat_entry(target, iid, i++, &iate) == S_OK) {
for (j = 0 ; j < nsyms ; j++) {
for (j = 0; j < nsyms; j++) {
sym = &syms[j];
if (hook_table_match_proc(&iate, sym)) {
@@ -112,9 +102,7 @@ static void hook_table_apply_to_iid(
}
static bool hook_table_match_module(
HMODULE target,
const char *iid_name,
const char *depname)
HMODULE target, const char *iid_name, const char *depname)
{
HMODULE kernel32;
int result;
@@ -163,12 +151,10 @@ static bool hook_table_match_module(
}
static bool hook_table_match_proc(
const struct pe_iat_entry *iate,
const struct hook_symbol *sym)
const struct pe_iat_entry *iate, const struct hook_symbol *sym)
{
if ( sym->name != NULL &&
iate->name != NULL &&
strcmp(sym->name, iate->name) == 0) {
if (sym->name != NULL && iate->name != NULL &&
strcmp(sym->name, iate->name) == 0) {
return true;
}
+8 -8
View File
@@ -13,13 +13,13 @@ struct hook_symbol {
};
void hook_table_apply(
HMODULE target,
const char *depname,
const struct hook_symbol *syms,
size_t nsyms);
HMODULE target,
const char *depname,
const struct hook_symbol *syms,
size_t nsyms);
void hook_table_revert(
HMODULE target,
const char *depname,
const struct hook_symbol *syms,
size_t nsyms);
HMODULE target,
const char *depname,
const struct hook_symbol *syms,
size_t nsyms);