ReactOS 0.4.17-dev-966-gf06eace
integrity.c File Reference
#include <stdarg.h>
#include "windef.h"
#include "winbase.h"
#include "winerror.h"
#include "winternl.h"
#include "winnt.h"
#include "winver.h"
#include "imagehlp.h"
#include "wine/debug.h"
Include dependency graph for integrity.c:

Go to the source code of this file.

Macros

#define HDR_FAIL   -1
 
#define HDR_NT32   0
 
#define HDR_NT64   1
 

Functions

 WINE_DEFAULT_DEBUG_CHANNEL (imagehlp)
 
static int IMAGEHLP_GetNTHeaders (HANDLE handle, DWORD *pe_offset, IMAGE_NT_HEADERS32 *nt32, IMAGE_NT_HEADERS64 *nt64)
 
static BOOL IMAGEHLP_GetSecurityDirOffset (HANDLE handle, DWORD *pdwOfs, DWORD *pdwSize)
 
static BOOL IMAGEHLP_SetSecurityDirOffset (HANDLE handle, DWORD dwOfs, DWORD dwSize)
 
static BOOL IMAGEHLP_GetCertificateOffset (HANDLE handle, DWORD num, DWORD *pdwOfs, DWORD *pdwSize)
 
static BOOL IMAGEHLP_RecalculateChecksum (HANDLE handle)
 
BOOL WINAPI ImageAddCertificate (HANDLE FileHandle, LPWIN_CERTIFICATE Certificate, PDWORD Index)
 
BOOL WINAPI ImageEnumerateCertificates (HANDLE handle, WORD TypeFilter, PDWORD CertificateCount, PDWORD Indices, DWORD IndexCount)
 
BOOL WINAPI ImageGetCertificateData (HANDLE handle, DWORD Index, LPWIN_CERTIFICATE Certificate, PDWORD RequiredLength)
 
BOOL WINAPI ImageGetCertificateHeader (HANDLE handle, DWORD index, LPWIN_CERTIFICATE pCert)
 
static DWORD IMAGEHLP_GetSectionOffset (IMAGE_SECTION_HEADER *hdr, DWORD num_sections, LPCSTR section, PDWORD size, PDWORD base)
 
static BOOL IMAGEHLP_ReportSectionFromOffset (DWORD offset, DWORD size, BYTE *map, DWORD fileSize, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
 
static BOOL IMAGEHLP_ReportSection (IMAGE_SECTION_HEADER *section_headers, DWORD num_sections, LPCSTR section, BYTE *map, DWORD fileSize, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
 
static BOOL IMAGEHLP_ReportCodeSections (IMAGE_SECTION_HEADER *hdr, DWORD num_sections, BYTE *map, DWORD fileSize, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
 
static BOOL IMAGEHLP_ReportImportSection (IMAGE_SECTION_HEADER *hdr, DWORD num_sections, BYTE *map, DWORD fileSize, DWORD DigestLevel, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
 
BOOL WINAPI ImageGetDigestStream (HANDLE FileHandle, DWORD DigestLevel, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
 
BOOL WINAPI ImageRemoveCertificate (HANDLE FileHandle, DWORD Index)
 

Macro Definition Documentation

◆ HDR_FAIL

#define HDR_FAIL   -1

Definition at line 43 of file integrity.c.

◆ HDR_NT32

#define HDR_NT32   0

Definition at line 44 of file integrity.c.

◆ HDR_NT64

#define HDR_NT64   1

Definition at line 45 of file integrity.c.

Function Documentation

◆ ImageAddCertificate()

BOOL WINAPI ImageAddCertificate ( HANDLE  FileHandle,
LPWIN_CERTIFICATE  Certificate,
PDWORD  Index 
)

Definition at line 381 of file integrity.c.

383{
384 DWORD size = 0, count = 0, offset = 0, sd_VirtualAddr = 0, index = 0;
386 const size_t cert_hdr_size = sizeof hdr - sizeof hdr.bCertificate;
387 BOOL r;
388
389 TRACE("(%p, %p, %p)\n", FileHandle, Certificate, Index);
390
391 r = IMAGEHLP_GetSecurityDirOffset(FileHandle, &sd_VirtualAddr, &size);
392
393 /* If we've already got a security directory, find the end of it */
394 if ((r) && (sd_VirtualAddr != 0))
395 {
396 /* Check if the security directory is at the end of the file.
397 If not, we should probably relocate it. */
398 if (GetFileSize(FileHandle, NULL) != sd_VirtualAddr + size)
399 {
400 FIXME("Security directory already present but not located at EOF, not adding certificate\n");
401
403 return FALSE;
404 }
405
406 while (offset < size)
407 {
408 /* read the length of the current certificate */
409 count = SetFilePointer (FileHandle, sd_VirtualAddr + offset,
411
413 return FALSE;
414
415 r = ReadFile(FileHandle, &hdr, cert_hdr_size, &count, NULL);
416
417 if (!r)
418 return FALSE;
419
420 if (count != cert_hdr_size)
421 return FALSE;
422
423 /* check the certificate is not too big or too small */
424 if (hdr.dwLength < cert_hdr_size)
425 return FALSE;
426
427 if (hdr.dwLength > (size-offset))
428 return FALSE;
429
430 /* next certificate */
431 offset += hdr.dwLength;
432
433 /* padded out to the nearest 8-byte boundary */
434 if (hdr.dwLength % 8)
435 offset += 8 - (hdr.dwLength % 8);
436
437 index++;
438 }
439
440 count = SetFilePointer (FileHandle, sd_VirtualAddr + offset, NULL, FILE_BEGIN);
441
443 return FALSE;
444 }
445 else
446 {
447 sd_VirtualAddr = SetFilePointer(FileHandle, 0, NULL, FILE_END);
448
449 if (sd_VirtualAddr == INVALID_SET_FILE_POINTER)
450 return FALSE;
451 }
452
453 /* Write the certificate to the file */
455
456 if (!r)
457 return FALSE;
458
459 /* Pad out if necessary */
460 if (Certificate->dwLength % 8)
461 {
462 char null[8];
463
464 ZeroMemory(null, 8);
465 WriteFile(FileHandle, null, 8 - (Certificate->dwLength % 8), &count, NULL);
466
467 size += 8 - (Certificate->dwLength % 8);
468 }
469
470 size += Certificate->dwLength;
471
472 /* Update the security directory offset and size */
473 if (!IMAGEHLP_SetSecurityDirOffset(FileHandle, sd_VirtualAddr, size))
474 return FALSE;
475
477 return FALSE;
478
479 if(Index)
480 *Index = index;
481 return TRUE;
482}
#define index(s, c)
Definition: various.h:29
int null(void)
Definition: ftp.c:1794
#define FIXME(fmt,...)
Definition: precomp.h:53
#define NULL
Definition: types.h:112
#define TRUE
Definition: types.h:120
#define FALSE
Definition: types.h:117
#define FILE_BEGIN
Definition: compat.h:761
#define INVALID_SET_FILE_POINTER
Definition: compat.h:732
#define ReadFile(a, b, c, d, e)
Definition: compat.h:742
#define SetFilePointer
Definition: compat.h:743
#define SetLastError(x)
Definition: compat.h:752
#define ERROR_NOT_SUPPORTED
Definition: compat.h:100
static BOOL IMAGEHLP_RecalculateChecksum(HANDLE handle)
Definition: integrity.c:296
static BOOL IMAGEHLP_GetSecurityDirOffset(HANDLE handle, DWORD *pdwOfs, DWORD *pdwSize)
Definition: integrity.c:147
static BOOL IMAGEHLP_SetSecurityDirOffset(HANDLE handle, DWORD dwOfs, DWORD dwSize)
Definition: integrity.c:178
DWORD WINAPI GetFileSize(HANDLE hFile, LPDWORD lpFileSizeHigh)
Definition: fileinfo.c:331
BOOL WINAPI WriteFile(_In_ HANDLE hFile, _In_reads_bytes_opt_(nNumberOfBytesToWrite) LPCVOID lpBuffer, _In_ DWORD nNumberOfBytesToWrite, _Out_opt_ LPDWORD lpNumberOfBytesWritten, _Inout_opt_ LPOVERLAPPED lpOverlapped)
Definition: rw.c:25
static const WCHAR Certificate[]
Definition: register.c:76
unsigned int BOOL
Definition: ntddk_ex.h:94
unsigned long DWORD
Definition: ntddk_ex.h:95
_Must_inspect_result_ _In_opt_ PFLT_INSTANCE _Out_ PHANDLE FileHandle
Definition: fltkernel.h:1231
GLuint GLuint GLsizei count
Definition: gl.h:1545
GLdouble GLdouble GLdouble r
Definition: gl.h:2055
GLsizeiptr size
Definition: glext.h:5919
GLintptr offset
Definition: glext.h:5920
GLuint index
Definition: glext.h:6031
char hdr[14]
Definition: iptest.cpp:33
#define ZeroMemory
Definition: minwinbase.h:31
#define TRACE(s)
Definition: solgame.cpp:4
_In_ WDFCOLLECTION _In_ ULONG Index
#define FILE_END
Definition: winbase.h:117

Referenced by test_add_certificate(), and WINTRUST_PutSignedMsgToPEFile().

◆ ImageEnumerateCertificates()

BOOL WINAPI ImageEnumerateCertificates ( HANDLE  handle,
WORD  TypeFilter,
PDWORD  CertificateCount,
PDWORD  Indices,
DWORD  IndexCount 
)

Definition at line 487 of file integrity.c.

490{
491 DWORD size, count, offset, sd_VirtualAddr, index;
493 const size_t cert_hdr_size = sizeof hdr - sizeof hdr.bCertificate;
494 BOOL r;
495
496 TRACE("%p %hd %p %p %ld\n",
497 handle, TypeFilter, CertificateCount, Indices, IndexCount);
498
499 r = IMAGEHLP_GetSecurityDirOffset( handle, &sd_VirtualAddr, &size );
500 if( !r )
501 return FALSE;
502
503 offset = 0;
504 index = 0;
505 *CertificateCount = 0;
506 while( offset < size )
507 {
508 /* read the length of the current certificate */
509 count = SetFilePointer( handle, sd_VirtualAddr + offset,
510 NULL, FILE_BEGIN );
512 return FALSE;
513 r = ReadFile( handle, &hdr, cert_hdr_size, &count, NULL );
514 if( !r )
515 return FALSE;
516 if( count != cert_hdr_size )
517 return FALSE;
518
519 TRACE("Size = %08lx id = %08hx\n",
520 hdr.dwLength, hdr.wCertificateType );
521
522 /* check the certificate is not too big or too small */
523 if( hdr.dwLength < cert_hdr_size )
524 return FALSE;
525 if( hdr.dwLength > (size-offset) )
526 return FALSE;
527
528 if( (TypeFilter == CERT_SECTION_TYPE_ANY) ||
529 (TypeFilter == hdr.wCertificateType) )
530 {
531 (*CertificateCount)++;
532 if(Indices && *CertificateCount <= IndexCount)
533 *Indices++ = index;
534 }
535
536 /* next certificate */
537 offset += hdr.dwLength;
538
539 /* padded out to the nearest 8-byte boundary */
540 if (hdr.dwLength % 8)
541 offset += 8 - (hdr.dwLength % 8);
542
543 index++;
544 }
545
546 return TRUE;
547}
#define CERT_SECTION_TYPE_ANY
Definition: imagehlp.h:47

Referenced by ImageRemoveCertificate(), and test_remove_certificate().

◆ ImageGetCertificateData()

BOOL WINAPI ImageGetCertificateData ( HANDLE  handle,
DWORD  Index,
LPWIN_CERTIFICATE  Certificate,
PDWORD  RequiredLength 
)

Definition at line 554 of file integrity.c.

557{
558 DWORD r, offset, ofs, size, count;
559
560 TRACE("%p %ld %p %p\n", handle, Index, Certificate, RequiredLength);
561
562 if( !RequiredLength)
563 {
565 return FALSE;
566 }
567
569 return FALSE;
570
571 if( *RequiredLength < size )
572 {
575 return FALSE;
576 }
577
578 if( !Certificate )
579 {
581 return FALSE;
582 }
583
585
588 return FALSE;
589
591 if( !r )
592 return FALSE;
593 if( count != size )
594 return FALSE;
595
596 TRACE("OK\n");
598
599 return TRUE;
600}
#define NO_ERROR
Definition: dderror.h:5
#define ERROR_INSUFFICIENT_BUFFER
Definition: dderror.h:10
#define ERROR_INVALID_PARAMETER
Definition: compat.h:101
static BOOL IMAGEHLP_GetCertificateOffset(HANDLE handle, DWORD num, DWORD *pdwOfs, DWORD *pdwSize)
Definition: integrity.c:239
_In_ ULONG _Out_opt_ PULONG RequiredLength
Definition: wmifuncs.h:30

Referenced by test_get_certificate(), and WINTRUST_GetSignedMsgFromPEFile().

◆ ImageGetCertificateHeader()

BOOL WINAPI ImageGetCertificateHeader ( HANDLE  handle,
DWORD  index,
LPWIN_CERTIFICATE  pCert 
)

Definition at line 605 of file integrity.c.

607{
608 DWORD r, offset, ofs, size, count;
609 const size_t cert_hdr_size = sizeof *pCert - sizeof pCert->bCertificate;
610
611 TRACE("%p %ld %p\n", handle, index, pCert);
612
614 return FALSE;
615
616 if( size < cert_hdr_size )
617 return FALSE;
618
621 return FALSE;
622
623 r = ReadFile( handle, pCert, cert_hdr_size, &count, NULL );
624 if( !r )
625 return FALSE;
626 if( count != cert_hdr_size )
627 return FALSE;
628
629 TRACE("OK\n");
630
631 return TRUE;
632}
BYTE bCertificate[ANYSIZE_ARRAY]
Definition: wintrust.h:619

Referenced by WINTRUST_GetSignedMsgFromPEFile().

◆ ImageGetDigestStream()

BOOL WINAPI ImageGetDigestStream ( HANDLE  FileHandle,
DWORD  DigestLevel,
DIGEST_FUNCTION  DigestFunction,
DIGEST_HANDLE  DigestHandle 
)

Definition at line 782 of file integrity.c.

785{
786 DWORD error = 0;
787 BOOL ret = FALSE;
788 DWORD offset, size, num_sections, fileSize;
790 BYTE *map = NULL;
791 IMAGE_DOS_HEADER *dos_hdr;
792 IMAGE_NT_HEADERS *nt_hdr;
794
795 TRACE("(%p, %ld, %p, %p)\n", FileHandle, DigestLevel, DigestFunction,
796 DigestHandle);
797
798 /* Get the file size */
799 if( !FileHandle )
800 goto invalid_parameter;
801 fileSize = GetFileSize( FileHandle, NULL );
802 if(fileSize == INVALID_FILE_SIZE )
803 goto invalid_parameter;
804
805 /* map file */
807 if( hMap == INVALID_HANDLE_VALUE )
808 goto invalid_parameter;
809 map = MapViewOfFile( hMap, FILE_MAP_COPY, 0, 0, 0 );
810 if( !map )
811 goto invalid_parameter;
812
813 /* Read the file header */
814 if( fileSize < sizeof(IMAGE_DOS_HEADER) )
815 goto invalid_parameter;
816 dos_hdr = (IMAGE_DOS_HEADER *)map;
817
818 if( dos_hdr->e_magic != IMAGE_DOS_SIGNATURE )
819 goto invalid_parameter;
820 offset = dos_hdr->e_lfanew;
821 if( !offset || offset > fileSize )
822 goto invalid_parameter;
823 ret = DigestFunction( DigestHandle, map, offset );
824 if( !ret )
825 goto end;
826
827 /* Read the NT header */
828 if( offset + sizeof(IMAGE_NT_HEADERS) > fileSize )
829 goto invalid_parameter;
830 nt_hdr = (IMAGE_NT_HEADERS *)(map + offset);
831 if( nt_hdr->Signature != IMAGE_NT_SIGNATURE )
832 goto invalid_parameter;
833 /* It's clear why the checksum is cleared, but why only these size headers?
834 */
836 nt_hdr->OptionalHeader.SizeOfImage = 0;
837 nt_hdr->OptionalHeader.CheckSum = 0;
838 size = sizeof(nt_hdr->Signature) + sizeof(nt_hdr->FileHeader) +
840 ret = DigestFunction( DigestHandle, map + offset, size );
841 if( !ret )
842 goto end;
843
844 /* Read the section headers */
845 offset += size;
846 num_sections = nt_hdr->FileHeader.NumberOfSections;
847 size = num_sections * sizeof(IMAGE_SECTION_HEADER);
848 if( offset + size > fileSize )
849 goto invalid_parameter;
850 ret = DigestFunction( DigestHandle, map + offset, size );
851 if( !ret )
852 goto end;
853
856 map, fileSize, DigestFunction, DigestHandle );
857 IMAGEHLP_ReportSection( section_headers, num_sections, ".data",
858 map, fileSize, DigestFunction, DigestHandle );
859 IMAGEHLP_ReportSection( section_headers, num_sections, ".rdata",
860 map, fileSize, DigestFunction, DigestHandle );
862 map, fileSize, DigestLevel, DigestFunction, DigestHandle );
863 if( DigestLevel & CERT_PE_IMAGE_DIGEST_DEBUG_INFO )
864 IMAGEHLP_ReportSection( section_headers, num_sections, ".debug",
865 map, fileSize, DigestFunction, DigestHandle );
866 if( DigestLevel & CERT_PE_IMAGE_DIGEST_RESOURCES )
867 IMAGEHLP_ReportSection( section_headers, num_sections, ".rsrc",
868 map, fileSize, DigestFunction, DigestHandle );
869
870end:
871 if( map )
873 if( hMap != INVALID_HANDLE_VALUE )
874 CloseHandle( hMap );
875 if( error )
877 return ret;
878
879invalid_parameter:
881 goto end;
882}
Definition: _map.h:48
#define CloseHandle
Definition: compat.h:739
#define PAGE_READONLY
Definition: compat.h:138
#define UnmapViewOfFile
Definition: compat.h:746
#define INVALID_HANDLE_VALUE
Definition: compat.h:731
#define CreateFileMappingW(a, b, c, d, e, f)
Definition: compat.h:744
#define MapViewOfFile
Definition: compat.h:745
static BOOL IMAGEHLP_ReportCodeSections(IMAGE_SECTION_HEADER *hdr, DWORD num_sections, BYTE *map, DWORD fileSize, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
Definition: integrity.c:693
static BOOL IMAGEHLP_ReportImportSection(IMAGE_SECTION_HEADER *hdr, DWORD num_sections, BYTE *map, DWORD fileSize, DWORD DigestLevel, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
Definition: integrity.c:713
static BOOL IMAGEHLP_ReportSection(IMAGE_SECTION_HEADER *section_headers, DWORD num_sections, LPCSTR section, BYTE *map, DWORD fileSize, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
Definition: integrity.c:676
return ret
Definition: mutex.c:147
GLuint GLuint end
Definition: gl.h:1545
#define CERT_PE_IMAGE_DIGEST_DEBUG_INFO
Definition: imagehlp.h:43
#define CERT_PE_IMAGE_DIGEST_RESOURCES
Definition: imagehlp.h:44
#define error(str)
Definition: mkdosfs.c:1605
static IMAGE_SECTION_HEADER section_headers[]
Definition: data.c:95
#define IMAGE_NT_SIGNATURE
Definition: pedump.c:93
#define IMAGE_DOS_SIGNATURE
Definition: pedump.c:89
struct _IMAGE_SECTION_HEADER IMAGE_SECTION_HEADER
WORD SizeOfOptionalHeader
Definition: ntddk_ex.h:127
IMAGE_OPTIONAL_HEADER32 OptionalHeader
Definition: ntddk_ex.h:184
IMAGE_FILE_HEADER FileHeader
Definition: ntddk_ex.h:183
#define FILE_MAP_COPY
Definition: winbase.h:156
#define INVALID_FILE_SIZE
Definition: winbase.h:528
unsigned char BYTE
Definition: xxhash.c:193

Referenced by test_get_digest_stream().

◆ IMAGEHLP_GetCertificateOffset()

static BOOL IMAGEHLP_GetCertificateOffset ( HANDLE  handle,
DWORD  num,
DWORD *  pdwOfs,
DWORD *  pdwSize 
)
static

Definition at line 239 of file integrity.c.

241{
242 DWORD size, count, offset, len, sd_VirtualAddr;
243 BOOL r;
244
245 r = IMAGEHLP_GetSecurityDirOffset( handle, &sd_VirtualAddr, &size );
246 if( !r )
247 return FALSE;
248
249 offset = 0;
250 /* take the n'th certificate */
251 while( 1 )
252 {
253 /* read the length of the current certificate */
254 count = SetFilePointer( handle, sd_VirtualAddr + offset,
255 NULL, FILE_BEGIN );
257 return FALSE;
258 r = ReadFile( handle, &len, sizeof len, &count, NULL );
259 if( !r )
260 return FALSE;
261 if( count != sizeof len )
262 return FALSE;
263
264 /* check the certificate is not too big or too small */
265 if( len < sizeof len )
266 return FALSE;
267 if( len > (size-offset) )
268 return FALSE;
269 if( !num-- )
270 break;
271
272 /* calculate the offset of the next certificate */
273 offset += len;
274
275 /* padded out to the nearest 8-byte boundary */
276 if( len % 8 )
277 offset += 8 - (len % 8);
278
279 if( offset >= size )
280 return FALSE;
281 }
282
283 *pdwOfs = sd_VirtualAddr + offset;
284 *pdwSize = len;
285
286 TRACE("len = %lx addr = %lx\n", len, sd_VirtualAddr + offset);
287
288 return TRUE;
289}
GLuint GLuint num
Definition: glext.h:9618
GLenum GLsizei len
Definition: glext.h:6722

Referenced by ImageGetCertificateData(), ImageGetCertificateHeader(), and ImageRemoveCertificate().

◆ IMAGEHLP_GetNTHeaders()

static int IMAGEHLP_GetNTHeaders ( HANDLE  handle,
DWORD *  pe_offset,
IMAGE_NT_HEADERS32 *  nt32,
IMAGE_NT_HEADERS64 *  nt64 
)
static

Definition at line 53 of file integrity.c.

54{
55 IMAGE_DOS_HEADER dos_hdr;
57 BOOL r;
58
59 TRACE("handle %p\n", handle);
60
61 if ((!nt32) || (!nt64))
62 return HDR_FAIL;
63
64 /* read the DOS header */
66
68 return HDR_FAIL;
69
70 count = 0;
71
72 r = ReadFile(handle, &dos_hdr, sizeof dos_hdr, &count, NULL);
73
74 if (!r)
75 return HDR_FAIL;
76
77 if (count != sizeof dos_hdr)
78 return HDR_FAIL;
79
80 /* verify magic number of 'MZ' */
81 if (dos_hdr.e_magic != IMAGE_DOS_SIGNATURE)
82 return HDR_FAIL;
83
84 if (pe_offset != NULL)
85 *pe_offset = dos_hdr.e_lfanew;
86
87 /* read the PE header */
89
91 return HDR_FAIL;
92
93 count = 0;
94
95 r = ReadFile(handle, nt32, sizeof(IMAGE_NT_HEADERS32), &count, NULL);
96
97 if (!r)
98 return HDR_FAIL;
99
100 if (count != sizeof(IMAGE_NT_HEADERS32))
101 return HDR_FAIL;
102
103 /* verify NT signature */
104 if (nt32->Signature != IMAGE_NT_SIGNATURE)
105 return HDR_FAIL;
106
107 /* check if we have a 32-bit or 64-bit executable */
108 switch (nt32->OptionalHeader.Magic)
109 {
111 return HDR_NT32;
112
114 /* Re-read as 64-bit */
115
117
119 return HDR_FAIL;
120
121 count = 0;
122
123 r = ReadFile(handle, nt64, sizeof(IMAGE_NT_HEADERS64), &count, NULL);
124
125 if (!r)
126 return HDR_FAIL;
127
128 if (count != sizeof(IMAGE_NT_HEADERS64))
129 return HDR_FAIL;
130
131 /* verify NT signature */
132 if (nt64->Signature != IMAGE_NT_SIGNATURE)
133 return HDR_FAIL;
134
135 return HDR_NT64;
136 }
137
138 return HDR_FAIL;
139}
#define HDR_FAIL
Definition: integrity.c:43
#define HDR_NT64
Definition: integrity.c:45
#define HDR_NT32
Definition: integrity.c:44
#define IMAGE_NT_OPTIONAL_HDR32_MAGIC
Definition: ntimage.h:376
#define IMAGE_NT_OPTIONAL_HDR64_MAGIC
Definition: ntimage.h:377

Referenced by IMAGEHLP_GetSecurityDirOffset(), IMAGEHLP_RecalculateChecksum(), and IMAGEHLP_SetSecurityDirOffset().

◆ IMAGEHLP_GetSectionOffset()

static DWORD IMAGEHLP_GetSectionOffset ( IMAGE_SECTION_HEADER *  hdr,
DWORD  num_sections,
LPCSTR  section,
PDWORD  size,
PDWORD  base 
)
static

Definition at line 639 of file integrity.c.

641{
642 DWORD i, offset = 0;
643
644 for( i = 0; !offset && i < num_sections; i++, hdr++ )
645 {
646 if( !memcmp( hdr->Name, section, strlen(section) ) )
647 {
648 offset = hdr->PointerToRawData;
649 if( size )
650 *size = hdr->SizeOfRawData;
651 if( base )
652 *base = hdr->VirtualAddress;
653 }
654 }
655 return offset;
656}
_ACRTIMP int __cdecl memcmp(const void *, const void *, size_t)
Definition: string.c:2807
_ACRTIMP size_t __cdecl strlen(const char *)
Definition: string.c:1597
GLsizei GLenum const GLvoid GLsizei GLenum GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLint GLint GLint GLshort GLshort GLshort GLubyte GLubyte GLubyte GLuint GLuint GLuint GLushort GLushort GLushort GLbyte GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLfloat GLint GLint GLint GLint GLshort GLshort GLshort GLshort GLubyte GLubyte GLubyte GLubyte GLuint GLuint GLuint GLuint GLushort GLushort GLushort GLushort GLboolean const GLdouble const GLfloat const GLint const GLshort const GLbyte const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLdouble const GLfloat const GLfloat const GLint const GLint const GLshort const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort GLenum GLenum GLenum GLfloat GLenum GLint GLenum GLenum GLenum GLfloat GLenum GLenum GLint GLenum GLfloat GLenum GLint GLint GLushort GLenum GLenum GLfloat GLenum GLenum GLint GLfloat const GLubyte GLenum GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLint GLint GLsizei GLsizei GLint GLenum GLenum const GLvoid GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLenum const GLdouble GLenum GLenum const GLfloat GLenum GLenum const GLint GLsizei GLuint GLfloat GLuint GLbitfield GLfloat GLint GLuint GLboolean GLenum GLfloat GLenum GLbitfield GLenum GLfloat GLfloat GLint GLint const GLfloat GLenum GLfloat GLfloat GLint GLint GLfloat GLfloat GLint GLint const GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat const GLdouble const GLfloat const GLdouble const GLfloat GLint i
Definition: glfuncs.h:248
Definition: parser.c:56

Referenced by IMAGEHLP_ReportImportSection(), and IMAGEHLP_ReportSection().

◆ IMAGEHLP_GetSecurityDirOffset()

static BOOL IMAGEHLP_GetSecurityDirOffset ( HANDLE  handle,
DWORD *  pdwOfs,
DWORD *  pdwSize 
)
static

Definition at line 147 of file integrity.c.

149{
150 IMAGE_NT_HEADERS32 nt_hdr32;
151 IMAGE_NT_HEADERS64 nt_hdr64;
153 int ret;
154
155 ret = IMAGEHLP_GetNTHeaders(handle, NULL, &nt_hdr32, &nt_hdr64);
156
157 if (ret == HDR_NT32)
159 else if (ret == HDR_NT64)
161 else
162 return FALSE;
163
164 TRACE("ret = %d size = %lx addr = %lx\n", ret, sd->Size, sd->VirtualAddress);
165
166 *pdwSize = sd->Size;
167 *pdwOfs = sd->VirtualAddress;
168
169 return TRUE;
170}
static int IMAGEHLP_GetNTHeaders(HANDLE handle, DWORD *pe_offset, IMAGE_NT_HEADERS32 *nt32, IMAGE_NT_HEADERS64 *nt64)
Definition: integrity.c:53
static const WCHAR sd[]
Definition: suminfo.c:432
IMAGE_OPTIONAL_HEADER64 OptionalHeader
Definition: ntimage.h:396
IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES]
Definition: ntimage.h:370
IMAGE_DATA_DIRECTORY DataDirectory[IMAGE_NUMBEROF_DIRECTORY_ENTRIES]
Definition: ntddk_ex.h:178
#define IMAGE_FILE_SECURITY_DIRECTORY
Definition: winnt_old.h:676

Referenced by ImageAddCertificate(), ImageEnumerateCertificates(), IMAGEHLP_GetCertificateOffset(), and ImageRemoveCertificate().

◆ IMAGEHLP_RecalculateChecksum()

static BOOL IMAGEHLP_RecalculateChecksum ( HANDLE  handle)
static

Definition at line 296 of file integrity.c.

297{
298 DWORD FileLength, count, HeaderSum, pe_offset, nt_hdr_size;
299 IMAGE_NT_HEADERS32 nt_hdr32;
300 IMAGE_NT_HEADERS64 nt_hdr64;
302 HANDLE hMapping;
303 DWORD *CheckSum;
304 void *nt_hdr;
305 int ret;
306 BOOL r;
307
308 TRACE("handle %p\n", handle);
309
310 ret = IMAGEHLP_GetNTHeaders(handle, &pe_offset, &nt_hdr32, &nt_hdr64);
311
312 if (ret == HDR_NT32)
313 {
314 CheckSum = &nt_hdr32.OptionalHeader.CheckSum;
315
316 nt_hdr = &nt_hdr32;
317 nt_hdr_size = sizeof(IMAGE_NT_HEADERS32);
318 }
319 else if (ret == HDR_NT64)
320 {
321 CheckSum = &nt_hdr64.OptionalHeader.CheckSum;
322
323 nt_hdr = &nt_hdr64;
324 nt_hdr_size = sizeof(IMAGE_NT_HEADERS64);
325 }
326 else
327 return FALSE;
328
329 hMapping = CreateFileMappingW(handle, NULL, PAGE_READONLY, 0, 0, NULL);
330
331 if (!hMapping)
332 return FALSE;
333
334 BaseAddress = MapViewOfFile(hMapping, FILE_MAP_READ, 0, 0, 0);
335
336 if (!BaseAddress)
337 {
338 CloseHandle(hMapping);
339 return FALSE;
340 }
341
343
344 *CheckSum = 0;
345 CheckSumMappedFile(BaseAddress, FileLength, &HeaderSum, CheckSum);
346
348 CloseHandle(hMapping);
349
350 if (*CheckSum)
351 {
352 /* write the header back again */
353 count = SetFilePointer(handle, pe_offset, NULL, FILE_BEGIN);
354
356 return FALSE;
357
358 count = 0;
359
360 r = WriteFile(handle, nt_hdr, nt_hdr_size, &count, NULL);
361
362 if (!r)
363 return FALSE;
364
365 if (count != nt_hdr_size)
366 return FALSE;
367
368 return TRUE;
369 }
370
371 return FALSE;
372}
#define FILE_MAP_READ
Definition: compat.h:776
struct _IMAGE_NT_HEADERS IMAGE_NT_HEADERS32
PIMAGE_NT_HEADERS WINAPI CheckSumMappedFile(LPVOID BaseAddress, DWORD FileLength, LPDWORD HeaderSum, LPDWORD CheckSum)
Definition: modify.c:164
_Out_ PNDIS_HANDLE _Out_ PUINT FileLength
Definition: ndis.h:3228
_In_ HANDLE _Outptr_result_bytebuffer_ ViewSize _Pre_valid_ PVOID * BaseAddress
Definition: mmfuncs.h:408
struct _IMAGE_NT_HEADERS64 IMAGE_NT_HEADERS64

Referenced by ImageAddCertificate(), and ImageRemoveCertificate().

◆ IMAGEHLP_ReportCodeSections()

static BOOL IMAGEHLP_ReportCodeSections ( IMAGE_SECTION_HEADER *  hdr,
DWORD  num_sections,
BYTE *  map,
DWORD  fileSize,
DIGEST_FUNCTION  DigestFunction,
DIGEST_HANDLE  DigestHandle 
)
static

Definition at line 693 of file integrity.c.

695{
696 DWORD i;
697 BOOL ret = TRUE;
698
699 for( i = 0; ret && i < num_sections; i++, hdr++ )
700 {
701 if( hdr->Characteristics & IMAGE_SCN_CNT_CODE )
702 ret = IMAGEHLP_ReportSectionFromOffset( hdr->PointerToRawData,
703 hdr->SizeOfRawData, map, fileSize, DigestFunction, DigestHandle );
704 }
705 return ret;
706}
static BOOL IMAGEHLP_ReportSectionFromOffset(DWORD offset, DWORD size, BYTE *map, DWORD fileSize, DIGEST_FUNCTION DigestFunction, DIGEST_HANDLE DigestHandle)
Definition: integrity.c:661
#define IMAGE_SCN_CNT_CODE
Definition: ntimage.h:230

Referenced by ImageGetDigestStream().

◆ IMAGEHLP_ReportImportSection()

static BOOL IMAGEHLP_ReportImportSection ( IMAGE_SECTION_HEADER *  hdr,
DWORD  num_sections,
BYTE *  map,
DWORD  fileSize,
DWORD  DigestLevel,
DIGEST_FUNCTION  DigestFunction,
DIGEST_HANDLE  DigestHandle 
)
static

Definition at line 713 of file integrity.c.

716{
717 BOOL ret = FALSE;
719
720 /* Get import data */
721 offset = IMAGEHLP_GetSectionOffset( hdr, num_sections, ".idata", &size,
722 &base );
723 if( !offset )
724 return FALSE;
725
726 /* If CERT_PE_IMAGE_DIGEST_ALL_IMPORT_INFO is set, the entire
727 * section is reported. Otherwise, the debug info section is
728 * decoded and reported piecemeal. See tests. However, I haven't been
729 * able to figure out how the native implementation decides which values
730 * to report. Either it's buggy or my understanding is flawed.
731 */
732 if( DigestLevel & CERT_PE_IMAGE_DIGEST_ALL_IMPORT_INFO )
734 DigestFunction, DigestHandle );
735 else
736 {
737 FIXME("not supported except for CERT_PE_IMAGE_DIGEST_ALL_IMPORT_INFO\n");
739 ret = FALSE;
740 }
741
742 return ret;
743}
static DWORD IMAGEHLP_GetSectionOffset(IMAGE_SECTION_HEADER *hdr, DWORD num_sections, LPCSTR section, PDWORD size, PDWORD base)
Definition: integrity.c:639
#define CERT_PE_IMAGE_DIGEST_ALL_IMPORT_INFO
Definition: imagehlp.h:45

Referenced by ImageGetDigestStream().

◆ IMAGEHLP_ReportSection()

static BOOL IMAGEHLP_ReportSection ( IMAGE_SECTION_HEADER *  section_headers,
DWORD  num_sections,
LPCSTR  section,
BYTE *  map,
DWORD  fileSize,
DIGEST_FUNCTION  DigestFunction,
DIGEST_HANDLE  DigestHandle 
)
static

Definition at line 676 of file integrity.c.

679{
680 DWORD offset, size = 0;
681
683 &size, NULL );
684 if( !offset )
685 return FALSE;
687 DigestFunction, DigestHandle );
688}

Referenced by ImageGetDigestStream().

◆ IMAGEHLP_ReportSectionFromOffset()

static BOOL IMAGEHLP_ReportSectionFromOffset ( DWORD  offset,
DWORD  size,
BYTE *  map,
DWORD  fileSize,
DIGEST_FUNCTION  DigestFunction,
DIGEST_HANDLE  DigestHandle 
)
static

Definition at line 661 of file integrity.c.

663{
664 if( offset + size > fileSize )
665 {
667 return FALSE;
668 }
669 return DigestFunction( DigestHandle, map + offset, size );
670}

Referenced by IMAGEHLP_ReportCodeSections(), IMAGEHLP_ReportImportSection(), and IMAGEHLP_ReportSection().

◆ IMAGEHLP_SetSecurityDirOffset()

static BOOL IMAGEHLP_SetSecurityDirOffset ( HANDLE  handle,
DWORD  dwOfs,
DWORD  dwSize 
)
static

Definition at line 178 of file integrity.c.

180{
181 IMAGE_NT_HEADERS32 nt_hdr32;
182 IMAGE_NT_HEADERS64 nt_hdr64;
184 int ret, nt_hdr_size = 0;
185 DWORD pe_offset;
186 void *nt_hdr;
187 DWORD count;
188 BOOL r;
189
190 ret = IMAGEHLP_GetNTHeaders(handle, &pe_offset, &nt_hdr32, &nt_hdr64);
191
192 if (ret == HDR_NT32)
193 {
195
196 nt_hdr = &nt_hdr32;
197 nt_hdr_size = sizeof(IMAGE_NT_HEADERS32);
198 }
199 else if (ret == HDR_NT64)
200 {
202
203 nt_hdr = &nt_hdr64;
204 nt_hdr_size = sizeof(IMAGE_NT_HEADERS64);
205 }
206 else
207 return FALSE;
208
209 sd->Size = dwSize;
210 sd->VirtualAddress = dwOfs;
211
212 TRACE("size = %lx addr = %lx\n", sd->Size, sd->VirtualAddress);
213
214 /* write the header back again */
215 count = SetFilePointer(handle, pe_offset, NULL, FILE_BEGIN);
216
218 return FALSE;
219
220 count = 0;
221
222 r = WriteFile(handle, nt_hdr, nt_hdr_size, &count, NULL);
223
224 if (!r)
225 return FALSE;
226
227 if (count != nt_hdr_size)
228 return FALSE;
229
230 return TRUE;
231}
PSDBQUERYRESULT_VISTA PVOID DWORD * dwSize
Definition: env.c:56

Referenced by ImageAddCertificate(), and ImageRemoveCertificate().

◆ ImageRemoveCertificate()

BOOL WINAPI ImageRemoveCertificate ( HANDLE  FileHandle,
DWORD  Index 
)

Definition at line 887 of file integrity.c.

888{
889 DWORD size = 0, count = 0, sd_VirtualAddr = 0, offset = 0;
890 DWORD data_size = 0, cert_size = 0, cert_size_padded = 0, ret = 0;
891 LPVOID cert_data;
892 BOOL r;
893
894 TRACE("(%p, %ld)\n", FileHandle, Index);
895
897
898 if ((!r) || (count == 0))
899 return FALSE;
900
901 if ((!IMAGEHLP_GetSecurityDirOffset(FileHandle, &sd_VirtualAddr, &size)) ||
903 return FALSE;
904
905 /* Ignore any padding we have, too */
906 if (cert_size % 8)
907 cert_size_padded = cert_size + (8 - (cert_size % 8));
908 else
909 cert_size_padded = cert_size;
910
911 data_size = size - (offset - sd_VirtualAddr) - cert_size_padded;
912
913 if (data_size == 0)
914 {
915 ret = SetFilePointer(FileHandle, sd_VirtualAddr, NULL, FILE_BEGIN);
916
918 return FALSE;
919 }
920 else
921 {
922 cert_data = HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, data_size);
923
924 if (!cert_data)
925 return FALSE;
926
927 ret = SetFilePointer(FileHandle, offset + cert_size_padded, NULL, FILE_BEGIN);
928
930 goto error;
931
932 /* Read any subsequent certificates */
933 r = ReadFile(FileHandle, cert_data, data_size, &count, NULL);
934
935 if ((!r) || (count != data_size))
936 goto error;
937
939
940 /* Write them one index back */
941 r = WriteFile(FileHandle, cert_data, data_size, &count, NULL);
942
943 if ((!r) || (count != data_size))
944 goto error;
945
946 HeapFree(GetProcessHeap(), 0, cert_data);
947 }
948
949 /* If security directory is at end of file, trim the file */
950 if (GetFileSize(FileHandle, NULL) == sd_VirtualAddr + size)
952
953 if (count == 1)
955 else
956 r = IMAGEHLP_SetSecurityDirOffset(FileHandle, sd_VirtualAddr, size - cert_size_padded);
957
958 if (!r)
959 return FALSE;
960
962 return FALSE;
963
964 return TRUE;
965
966error:
967 HeapFree(GetProcessHeap(), 0, cert_data);
968 return FALSE;
969}
#define GetProcessHeap()
Definition: compat.h:736
#define HeapAlloc
Definition: compat.h:733
#define HeapFree(x, y, z)
Definition: compat.h:735
#define HEAP_ZERO_MEMORY
Definition: compat.h:134
BOOL WINAPI ImageEnumerateCertificates(HANDLE handle, WORD TypeFilter, PDWORD CertificateCount, PDWORD Indices, DWORD IndexCount)
Definition: integrity.c:487
BOOL WINAPI SetEndOfFile(HANDLE hFile)
Definition: fileinfo.c:989

Referenced by test_remove_certificate().

◆ WINE_DEFAULT_DEBUG_CHANNEL()

WINE_DEFAULT_DEBUG_CHANNEL ( imagehlp  )