Address review: forwarder split, CreateDelegate guard, API-set docs
- PeHeaderParser: split export forwarders on the FIRST dot (IndexOf), not the last. A forwarder is "Module.Function" and the module name has no extension, so the last-dot split misparsed export names that themselves contain a dot. - PeHeaderParser: document that API-set (api-ms-win-*/ext-ms-*) and ordinal forwarders are unsupported and should be resolved via the OS loader. - RemoteFunction.CreateDelegate now throws InvalidOperationException unless the session is in-process; an external target's address is not host-mapped and a delegate to it would access-violate on invocation. Tests cover both paths. - Reword the SSE-payload comment: the 16-byte scratch sits below the saved return address, which the aligned store leaves intact (it never overwrote it). Tests: 223 passing, 4 skipped. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -79,6 +79,32 @@ public class ModuleFunctionTests
|
||||
Assert.Throws<InvalidOperationException>(() => magic["kernel32"]["NoSuchExport_ZZZ"]);
|
||||
}
|
||||
|
||||
private delegate uint GetCurrentProcessIdDelegate();
|
||||
|
||||
[Fact]
|
||||
public void CreateDelegate_throws_for_external_session()
|
||||
{
|
||||
Load("kernel32.dll");
|
||||
|
||||
// External reader (even to self): the address is not treated as host-mapped, so a
|
||||
// delegate to it is rejected rather than handed back to AV on invocation.
|
||||
using var magic = Magic.Open(Process.GetCurrentProcess());
|
||||
RemoteFunction fn = magic["kernel32"]["GetCurrentProcessId"];
|
||||
|
||||
Assert.Throws<InvalidOperationException>(() => fn.CreateDelegate<GetCurrentProcessIdDelegate>());
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void CreateDelegate_invokes_function_in_process()
|
||||
{
|
||||
Load("kernel32.dll");
|
||||
|
||||
using var magic = Magic.OpenInProcess();
|
||||
var getPid = magic["kernel32"]["GetCurrentProcessId"].CreateDelegate<GetCurrentProcessIdDelegate>();
|
||||
|
||||
Assert.Equal((uint)Process.GetCurrentProcess().Id, getPid());
|
||||
}
|
||||
|
||||
[Fact]
|
||||
public void Resolved_function_executes_via_remote_thread()
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user