winevdm: Fix incorrect heap allocation sizes and possible out-of-bounds access in...
[wine.git] / server / hook.c
blob180ddf1071420d301095fd69f8186f19a2c4c52a
1 /*
2 * Server-side window hooks support
4 * Copyright (C) 2002 Alexandre Julliard
5 * Copyright (C) 2005 Dmitry Timoshkov
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
22 #include "config.h"
23 #include "wine/port.h"
25 #include <assert.h>
26 #include <stdarg.h>
27 #include <stdio.h>
29 #include "ntstatus.h"
30 #define WIN32_NO_STATUS
31 #include "windef.h"
32 #include "winbase.h"
33 #include "winuser.h"
34 #include "winternl.h"
36 #include "object.h"
37 #include "process.h"
38 #include "request.h"
39 #include "user.h"
41 struct hook_table;
43 struct hook
45 struct list chain; /* hook chain entry */
46 user_handle_t handle; /* user handle for this hook */
47 struct process *process; /* process the hook is set to */
48 struct thread *thread; /* thread the hook is set to */
49 struct thread *owner; /* owner of the out of context hook */
50 struct hook_table *table; /* hook table that contains this hook */
51 int index; /* hook table index */
52 int event_min;
53 int event_max;
54 int flags;
55 client_ptr_t proc; /* hook function */
56 int unicode; /* is it a unicode hook? */
57 WCHAR *module; /* module name for global hooks */
58 data_size_t module_size;
61 #define WH_WINEVENT (WH_MAXHOOK+1)
63 #define NB_HOOKS (WH_WINEVENT-WH_MINHOOK+1)
64 #define HOOK_ENTRY(p) LIST_ENTRY( (p), struct hook, chain )
66 struct hook_table
68 struct object obj; /* object header */
69 struct list hooks[NB_HOOKS]; /* array of hook chains */
70 int counts[NB_HOOKS]; /* use counts for each hook chain */
73 static void hook_table_dump( struct object *obj, int verbose );
74 static void hook_table_destroy( struct object *obj );
76 static const struct object_ops hook_table_ops =
78 sizeof(struct hook_table), /* size */
79 hook_table_dump, /* dump */
80 no_get_type, /* get_type */
81 no_add_queue, /* add_queue */
82 NULL, /* remove_queue */
83 NULL, /* signaled */
84 NULL, /* satisfied */
85 no_signal, /* signal */
86 no_get_fd, /* get_fd */
87 no_map_access, /* map_access */
88 default_get_sd, /* get_sd */
89 default_set_sd, /* set_sd */
90 no_lookup_name, /* lookup_name */
91 no_open_file, /* open_file */
92 no_close_handle, /* close_handle */
93 hook_table_destroy /* destroy */
97 /* create a new hook table */
98 static struct hook_table *alloc_hook_table(void)
100 struct hook_table *table;
101 int i;
103 if ((table = alloc_object( &hook_table_ops )))
105 for (i = 0; i < NB_HOOKS; i++)
107 list_init( &table->hooks[i] );
108 table->counts[i] = 0;
111 return table;
114 static struct hook_table *get_global_hooks( struct thread *thread )
116 struct hook_table *table;
117 struct desktop *desktop;
119 if (!thread->desktop) return NULL;
120 if (!(desktop = get_thread_desktop( thread, 0 ))) return NULL;
121 table = desktop->global_hooks;
122 release_object( desktop );
123 return table;
126 /* create a new hook and add it to the specified table */
127 static struct hook *add_hook( struct desktop *desktop, struct thread *thread, int index, int global )
129 struct hook *hook;
130 struct hook_table *table = global ? desktop->global_hooks : get_queue_hooks(thread);
132 if (!table)
134 if (!(table = alloc_hook_table())) return NULL;
135 if (global) desktop->global_hooks = table;
136 else set_queue_hooks( thread, table );
138 if (!(hook = mem_alloc( sizeof(*hook) ))) return NULL;
140 if (!(hook->handle = alloc_user_handle( hook, USER_HOOK )))
142 free( hook );
143 return NULL;
145 hook->thread = thread ? (struct thread *)grab_object( thread ) : NULL;
146 hook->table = table;
147 hook->index = index;
148 list_add_head( &table->hooks[index], &hook->chain );
149 if (thread) thread->desktop_users++;
150 return hook;
153 /* free a hook, removing it from its chain */
154 static void free_hook( struct hook *hook )
156 free_user_handle( hook->handle );
157 free( hook->module );
158 if (hook->thread)
160 assert( hook->thread->desktop_users > 0 );
161 hook->thread->desktop_users--;
162 release_object( hook->thread );
164 if (hook->process) release_object( hook->process );
165 release_object( hook->owner );
166 list_remove( &hook->chain );
167 free( hook );
170 /* find a hook from its index and proc */
171 static struct hook *find_hook( struct thread *thread, int index, client_ptr_t proc )
173 struct list *p;
174 struct hook_table *table = get_queue_hooks( thread );
176 if (table)
178 LIST_FOR_EACH( p, &table->hooks[index] )
180 struct hook *hook = HOOK_ENTRY( p );
181 if (hook->proc == proc) return hook;
184 return NULL;
187 /* get the first hook in the chain */
188 static inline struct hook *get_first_hook( struct hook_table *table, int index )
190 struct list *elem = list_head( &table->hooks[index] );
191 return elem ? HOOK_ENTRY( elem ) : NULL;
194 /* check if a given hook should run in the owner thread instead of the current thread */
195 static inline int run_hook_in_owner_thread( struct hook *hook )
197 if ((hook->index == WH_MOUSE_LL - WH_MINHOOK ||
198 hook->index == WH_KEYBOARD_LL - WH_MINHOOK))
199 return hook->owner != current;
200 return 0;
203 /* check if a given hook should run in the current thread */
204 static inline int run_hook_in_current_thread( struct hook *hook )
206 if (hook->process && hook->process != current->process) return 0;
207 if ((hook->flags & WINEVENT_SKIPOWNPROCESS) && hook->process == current->process) return 0;
208 if (hook->thread && hook->thread != current) return 0;
209 if ((hook->flags & WINEVENT_SKIPOWNTHREAD) && hook->thread == current) return 0;
210 /* don't run low-level hooks in debugged processes */
211 if (run_hook_in_owner_thread( hook ) && hook->owner->process->debugger) return 0;
212 return 1;
215 /* find the first non-deleted hook in the chain */
216 static inline struct hook *get_first_valid_hook( struct hook_table *table, int index,
217 int event, user_handle_t win,
218 int object_id, int child_id )
220 struct hook *hook = get_first_hook( table, index );
222 while (hook)
224 if (hook->proc && run_hook_in_current_thread( hook ))
226 if (event >= hook->event_min && event <= hook->event_max)
228 if (hook->flags & WINEVENT_INCONTEXT) return hook;
230 /* only winevent hooks may be out of context */
231 assert(hook->index + WH_MINHOOK == WH_WINEVENT);
232 post_win_event( hook->owner, event, win, object_id, child_id,
233 hook->proc, hook->module, hook->module_size,
234 hook->handle );
237 hook = HOOK_ENTRY( list_next( &table->hooks[index], &hook->chain ) );
239 return hook;
242 /* find the next hook in the chain, skipping the deleted ones */
243 static struct hook *get_next_hook( struct thread *thread, struct hook *hook, int event,
244 user_handle_t win, int object_id, int child_id )
246 struct hook_table *global_hooks, *table = hook->table;
247 int index = hook->index;
249 while ((hook = HOOK_ENTRY( list_next( &table->hooks[index], &hook->chain ) )))
251 if (hook->proc && run_hook_in_current_thread( hook ))
253 if (event >= hook->event_min && event <= hook->event_max)
255 if (hook->flags & WINEVENT_INCONTEXT) return hook;
257 /* only winevent hooks may be out of context */
258 assert(hook->index + WH_MINHOOK == WH_WINEVENT);
259 post_win_event( hook->owner, event, win, object_id, child_id,
260 hook->proc, hook->module, hook->module_size,
261 hook->handle );
265 global_hooks = get_global_hooks( thread );
266 if (global_hooks && table != global_hooks) /* now search through the global table */
268 hook = get_first_valid_hook( global_hooks, index, event, win, object_id, child_id );
270 return hook;
273 static void hook_table_dump( struct object *obj, int verbose )
275 /* struct hook_table *table = (struct hook_table *)obj; */
276 fprintf( stderr, "Hook table\n" );
279 static void hook_table_destroy( struct object *obj )
281 int i;
282 struct hook *hook;
283 struct hook_table *table = (struct hook_table *)obj;
285 for (i = 0; i < NB_HOOKS; i++)
287 while ((hook = get_first_hook( table, i )) != NULL) free_hook( hook );
291 /* remove a hook, freeing it if the chain is not in use */
292 static void remove_hook( struct hook *hook )
294 if (hook->table->counts[hook->index])
295 hook->proc = 0; /* chain is in use, just mark it and return */
296 else
297 free_hook( hook );
300 /* release a hook chain, removing deleted hooks if the use count drops to 0 */
301 static void release_hook_chain( struct hook_table *table, int index )
303 if (!table->counts[index]) /* use count shouldn't already be 0 */
305 set_error( STATUS_INVALID_PARAMETER );
306 return;
308 if (!--table->counts[index])
310 struct hook *hook = get_first_hook( table, index );
311 while (hook)
313 struct hook *next = HOOK_ENTRY( list_next( &table->hooks[hook->index], &hook->chain ) );
314 if (!hook->proc) free_hook( hook );
315 hook = next;
320 /* remove all global hooks owned by a given thread */
321 void remove_thread_hooks( struct thread *thread )
323 struct hook_table *global_hooks = get_global_hooks( thread );
324 int index;
326 if (!global_hooks) return;
328 /* only low-level keyboard/mouse global hooks can be owned by a thread */
329 for (index = WH_KEYBOARD_LL - WH_MINHOOK; index <= WH_MOUSE_LL - WH_MINHOOK; index++)
331 struct hook *hook = get_first_hook( global_hooks, index );
332 while (hook)
334 struct hook *next = HOOK_ENTRY( list_next( &global_hooks->hooks[index], &hook->chain ) );
335 if (hook->thread == thread) remove_hook( hook );
336 hook = next;
341 /* get a bitmap of active hooks in a hook table */
342 static int is_hook_active( struct hook_table *table, int index )
344 struct hook *hook = get_first_hook( table, index );
346 while (hook)
348 if (hook->proc && run_hook_in_current_thread( hook )) return 1;
349 hook = HOOK_ENTRY( list_next( &table->hooks[index], &hook->chain ) );
351 return 0;
354 /* get a bitmap of all active hooks for the current thread */
355 unsigned int get_active_hooks(void)
357 struct hook_table *table = get_queue_hooks( current );
358 struct hook_table *global_hooks = get_global_hooks( current );
359 unsigned int ret = 1 << 31; /* set high bit to indicate that the bitmap is valid */
360 int id;
362 for (id = WH_MINHOOK; id <= WH_WINEVENT; id++)
364 if ((table && is_hook_active( table, id - WH_MINHOOK )) ||
365 (global_hooks && is_hook_active( global_hooks, id - WH_MINHOOK )))
366 ret |= 1 << (id - WH_MINHOOK);
368 return ret;
371 /* return the thread that owns the first global hook */
372 struct thread *get_first_global_hook( int id )
374 struct hook *hook;
375 struct hook_table *global_hooks = get_global_hooks( current );
377 if (!global_hooks) return NULL;
378 if (!(hook = get_first_valid_hook( global_hooks, id - WH_MINHOOK, EVENT_MIN, 0, 0, 0 ))) return NULL;
379 return hook->owner;
382 /* set a window hook */
383 DECL_HANDLER(set_hook)
385 struct process *process = NULL;
386 struct thread *thread = NULL;
387 struct desktop *desktop;
388 struct hook *hook;
389 WCHAR *module;
390 int global;
391 data_size_t module_size = get_req_data_size();
393 if (!req->proc || req->id < WH_MINHOOK || req->id > WH_WINEVENT)
395 set_error( STATUS_INVALID_PARAMETER );
396 return;
399 if (!(desktop = get_thread_desktop( current, DESKTOP_HOOKCONTROL ))) return;
401 if (req->pid && !(process = get_process_from_id( req->pid ))) goto done;
403 if (req->tid)
405 if (!(thread = get_thread_from_id( req->tid ))) goto done;
406 if (process && process != thread->process)
408 set_error( STATUS_INVALID_PARAMETER );
409 goto done;
413 if (req->id == WH_KEYBOARD_LL || req->id == WH_MOUSE_LL)
415 /* low-level hardware hooks are special: always global, but without a module */
416 if (thread)
418 set_error( STATUS_INVALID_PARAMETER );
419 goto done;
421 module = NULL;
422 global = 1;
424 else if (!req->tid)
426 /* out of context hooks do not need a module handle */
427 if (!module_size && (req->flags & WINEVENT_INCONTEXT))
429 set_error( STATUS_INVALID_PARAMETER );
430 goto done;
432 if (!(module = memdup( get_req_data(), module_size ))) goto done;
433 global = 1;
435 else
437 /* module is optional only if hook is in current process */
438 if (!module_size)
440 module = NULL;
441 if (thread->process != current->process)
443 set_error( STATUS_INVALID_PARAMETER );
444 goto done;
447 else if (!(module = memdup( get_req_data(), module_size ))) goto done;
448 global = 0;
451 if ((hook = add_hook( desktop, thread, req->id - WH_MINHOOK, global )))
453 hook->owner = (struct thread *)grab_object( current );
454 hook->process = process ? (struct process *)grab_object( process ) : NULL;
455 hook->event_min = req->event_min;
456 hook->event_max = req->event_max;
457 hook->flags = req->flags;
458 hook->proc = req->proc;
459 hook->unicode = req->unicode;
460 hook->module = module;
461 hook->module_size = module_size;
462 reply->handle = hook->handle;
463 reply->active_hooks = get_active_hooks();
465 else free( module );
467 done:
468 if (process) release_object( process );
469 if (thread) release_object( thread );
470 release_object( desktop );
474 /* remove a window hook */
475 DECL_HANDLER(remove_hook)
477 struct hook *hook;
479 if (req->handle)
481 if (!(hook = get_user_object( req->handle, USER_HOOK )))
483 set_error( STATUS_INVALID_HANDLE );
484 return;
487 else
489 if (!req->proc || req->id < WH_MINHOOK || req->id > WH_WINEVENT)
491 set_error( STATUS_INVALID_PARAMETER );
492 return;
494 if (!(hook = find_hook( current, req->id - WH_MINHOOK, req->proc )))
496 set_error( STATUS_INVALID_PARAMETER );
497 return;
500 remove_hook( hook );
501 reply->active_hooks = get_active_hooks();
505 /* start calling a hook chain */
506 DECL_HANDLER(start_hook_chain)
508 struct hook *hook;
509 struct hook_table *table = get_queue_hooks( current );
510 struct hook_table *global_table = get_global_hooks( current );
512 if (req->id < WH_MINHOOK || req->id > WH_WINEVENT)
514 set_error( STATUS_INVALID_PARAMETER );
515 return;
518 reply->active_hooks = get_active_hooks();
520 if (!table || !(hook = get_first_valid_hook( table, req->id - WH_MINHOOK, req->event,
521 req->window, req->object_id, req->child_id )))
523 /* try global table */
524 if (!global_table || !(hook = get_first_valid_hook( global_table, req->id - WH_MINHOOK, req->event,
525 req->window, req->object_id, req->child_id )))
526 return; /* no hook set */
529 if (run_hook_in_owner_thread( hook ))
531 reply->pid = get_process_id( hook->owner->process );
532 reply->tid = get_thread_id( hook->owner );
534 else
536 reply->pid = 0;
537 reply->tid = 0;
539 reply->proc = hook->proc;
540 reply->handle = hook->handle;
541 reply->unicode = hook->unicode;
542 if (table) table->counts[hook->index]++;
543 if (global_table) global_table->counts[hook->index]++;
544 if (hook->module) set_reply_data( hook->module, hook->module_size );
548 /* finished calling a hook chain */
549 DECL_HANDLER(finish_hook_chain)
551 struct hook_table *table = get_queue_hooks( current );
552 struct hook_table *global_hooks = get_global_hooks( current );
553 int index = req->id - WH_MINHOOK;
555 if (req->id < WH_MINHOOK || req->id > WH_WINEVENT)
557 set_error( STATUS_INVALID_PARAMETER );
558 return;
560 if (table) release_hook_chain( table, index );
561 if (global_hooks) release_hook_chain( global_hooks, index );
565 /* get the hook information */
566 DECL_HANDLER(get_hook_info)
568 struct hook *hook;
570 if (!(hook = get_user_object( req->handle, USER_HOOK ))) return;
571 if (hook->thread && (hook->thread != current))
573 set_error( STATUS_INVALID_HANDLE );
574 return;
576 if (req->get_next && !(hook = get_next_hook( current, hook, req->event, req->window,
577 req->object_id, req->child_id )))
578 return;
580 reply->handle = hook->handle;
581 reply->id = hook->index + WH_MINHOOK;
582 reply->unicode = hook->unicode;
583 if (hook->module) set_reply_data( hook->module, min(hook->module_size,get_reply_max_size()) );
584 if (run_hook_in_owner_thread( hook ))
586 reply->pid = get_process_id( hook->owner->process );
587 reply->tid = get_thread_id( hook->owner );
589 else
591 reply->pid = 0;
592 reply->tid = 0;
594 reply->proc = hook->proc;