mirror of
https://github.com/goatcorp/Dalamud.git
synced 2026-02-18 05:47:43 +01:00
feat: AsmHook
This commit is contained in:
parent
3fd1637cf0
commit
369d7af8a0
4 changed files with 278 additions and 75 deletions
|
|
@ -1,8 +1,11 @@
|
|||
using System;
|
||||
using System.Collections.Generic;
|
||||
using System.Linq;
|
||||
using System.Runtime.InteropServices;
|
||||
|
||||
using Dalamud.Logging.Internal;
|
||||
using Dalamud.Memory;
|
||||
using Iced.Intel;
|
||||
using Microsoft.Win32;
|
||||
|
||||
namespace Dalamud.Hooking.Internal
|
||||
|
|
@ -83,6 +86,76 @@ namespace Dalamud.Hooking.Internal
|
|||
Originals.Clear();
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Follow a JMP or Jcc instruction to the next logical location.
|
||||
/// </summary>
|
||||
/// <param name="address">Address of the instruction.</param>
|
||||
/// <returns>The address referenced by the jmp.</returns>
|
||||
internal static IntPtr FollowJmp(IntPtr address)
|
||||
{
|
||||
while (true)
|
||||
{
|
||||
var hasOtherHooks = HookManager.Originals.ContainsKey(address);
|
||||
if (hasOtherHooks)
|
||||
{
|
||||
// This address has been hooked already. Do not follow a jmp into a trampoline of our own making.
|
||||
Log.Verbose($"Detected hook trampoline at {address.ToInt64():X}, stopping jump resolution.");
|
||||
return address;
|
||||
}
|
||||
|
||||
var bytes = MemoryHelper.ReadRaw(address, 8);
|
||||
|
||||
var codeReader = new ByteArrayCodeReader(bytes);
|
||||
var decoder = Decoder.Create(64, codeReader);
|
||||
decoder.IP = (ulong)address.ToInt64();
|
||||
decoder.Decode(out var inst);
|
||||
|
||||
if (inst.Mnemonic == Mnemonic.Jmp)
|
||||
{
|
||||
var kind = inst.Op0Kind;
|
||||
|
||||
IntPtr newAddress;
|
||||
switch (inst.Op0Kind)
|
||||
{
|
||||
case OpKind.NearBranch64:
|
||||
case OpKind.NearBranch32:
|
||||
case OpKind.NearBranch16:
|
||||
newAddress = (IntPtr)inst.NearBranchTarget;
|
||||
break;
|
||||
case OpKind.Immediate16:
|
||||
case OpKind.Immediate8to16:
|
||||
case OpKind.Immediate8to32:
|
||||
case OpKind.Immediate8to64:
|
||||
case OpKind.Immediate32to64:
|
||||
case OpKind.Immediate32 when IntPtr.Size == 4:
|
||||
case OpKind.Immediate64:
|
||||
newAddress = (IntPtr)inst.GetImmediate(0);
|
||||
break;
|
||||
case OpKind.Memory when inst.IsIPRelativeMemoryOperand:
|
||||
newAddress = (IntPtr)inst.IPRelativeMemoryAddress;
|
||||
newAddress = Marshal.ReadIntPtr(newAddress);
|
||||
break;
|
||||
case OpKind.Memory:
|
||||
newAddress = (IntPtr)inst.MemoryDisplacement64;
|
||||
newAddress = Marshal.ReadIntPtr(newAddress);
|
||||
break;
|
||||
default:
|
||||
var debugBytes = string.Join(" ", bytes.Take(inst.Length).Select(b => $"{b:X2}"));
|
||||
throw new Exception($"Unknown OpKind {inst.Op0Kind} from {debugBytes}");
|
||||
}
|
||||
|
||||
Log.Verbose($"Resolving assembly jump ({kind}) from {address.ToInt64():X} to {newAddress.ToInt64():X}");
|
||||
address = newAddress;
|
||||
}
|
||||
else
|
||||
{
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
return address;
|
||||
}
|
||||
|
||||
private static unsafe void RevertHooks()
|
||||
{
|
||||
foreach (var (address, originalBytes) in Originals)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue