mirror of
https://github.com/wiiu-env/FunctionPatcherModule.git
synced 2026-08-29 12:15:29 -05:00
Avoid jump data heap corruption by flushing the whole heap
This commit is contained in:
@@ -1,4 +1,11 @@
|
||||
#include "CThread.h"
|
||||
#include "globals.h"
|
||||
#include "logger.h"
|
||||
|
||||
|
||||
#include <coreinit/cache.h>
|
||||
#include <coreinit/core.h>
|
||||
#include <coreinit/memexpheap.h>
|
||||
#include <coreinit/memorymap.h>
|
||||
#include <kernel/kernel.h>
|
||||
|
||||
@@ -25,4 +32,92 @@ bool ReadFromPhysicalAddress(uint32_t srcPhys, uint32_t *out) {
|
||||
DCFlushRange((void *) ¤tInstruction, 4);
|
||||
*out = currentInstruction;
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
bool CheckMemExpHeapBlock(MEMExpHeap *heap, MEMExpHeapBlockList *block, uint32_t tag, const char *listName, uint32_t &totalSizeOut) {
|
||||
MEMExpHeapBlock *prevBlock = nullptr;
|
||||
for (auto *cur = block->head; cur != nullptr; cur = cur->next) {
|
||||
if (cur->prev != prevBlock) {
|
||||
DEBUG_FUNCTION_LINE_ERR("[Exp Heap Check] \"%s\" prev is invalid. expected %p actual %p", listName, prevBlock, cur->prev);
|
||||
|
||||
return false;
|
||||
}
|
||||
if (cur < heap->header.dataStart || cur > heap->header.dataEnd || ((uint32_t) cur + sizeof(MEMExpHeapBlock) + cur->blockSize) > (uint32_t) heap->header.dataEnd) {
|
||||
DEBUG_FUNCTION_LINE_ERR("[Exp Heap Check] Block is not inside heap. block: %p size %d; heap start %p heap end %p", cur, sizeof(MEMExpHeapBlock) + cur->blockSize, heap->header.dataStart, heap->header.dataEnd);
|
||||
|
||||
return false;
|
||||
}
|
||||
if (cur->tag != tag) {
|
||||
DEBUG_FUNCTION_LINE_ERR("[%p][%d][Exp Heap Check] Invalid block tag expected %04X, actual %04X", &cur->tag, OSGetCoreId(), tag, cur->tag);
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
totalSizeOut = totalSizeOut + cur->blockSize + (cur->attribs >> 8 & 0x7fffff) + sizeof(MEMExpHeapBlock);
|
||||
prevBlock = cur;
|
||||
}
|
||||
if (prevBlock != block->tail) {
|
||||
DEBUG_FUNCTION_LINE_ERR("[Exp Heap Check] \"%s\" tail is unexpected! expected %p, actual %p", listName, heap->usedList.tail, prevBlock);
|
||||
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
bool CheckMemExpHeapCore(MEMExpHeap *heap) {
|
||||
uint32_t totalSize = 0;
|
||||
#pragma GCC diagnostic ignored "-Waddress-of-packed-member"
|
||||
if (!CheckMemExpHeapBlock(heap, &heap->usedList, 0x5544, "used", totalSize)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
#pragma GCC diagnostic ignored "-Waddress-of-packed-member"
|
||||
if (!CheckMemExpHeapBlock(heap, &heap->freeList, 0x4652, "free", totalSize)) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (totalSize != (uint32_t) heap->header.dataEnd - (uint32_t) heap->header.dataStart) {
|
||||
DEBUG_FUNCTION_LINE_ERR("[Exp Heap Check] heap size is unexpected! expected %08X, actual %08X", (uint32_t) heap->header.dataEnd - (uint32_t) heap->header.dataStart, totalSize);
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
bool CheckMemExpHeap(MEMExpHeap *heap) {
|
||||
|
||||
OSMemoryBarrier();
|
||||
if (heap->header.tag != MEM_EXPANDED_HEAP_TAG) {
|
||||
DEBUG_FUNCTION_LINE_ERR("[Exp Heap Check] Invalid heap handle. - %08X", heap->header.tag);
|
||||
return false;
|
||||
}
|
||||
|
||||
if (heap->header.flags & MEM_HEAP_FLAG_USE_LOCK) {
|
||||
#pragma GCC diagnostic ignored "-Waddress-of-packed-member"
|
||||
OSUninterruptibleSpinLock_Acquire(&(heap->header).lock);
|
||||
}
|
||||
|
||||
auto result = CheckMemExpHeapCore(heap);
|
||||
|
||||
if (heap->header.flags & MEM_HEAP_FLAG_USE_LOCK) {
|
||||
#pragma GCC diagnostic ignored "-Waddress-of-packed-member"
|
||||
OSUninterruptibleSpinLock_Release(&(heap->header).lock);
|
||||
}
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
static void CheckMemExpHeapJumpDataCallback(CThread *, void *) {
|
||||
if (gJumpHeapHandle != nullptr) {
|
||||
if (!CheckMemExpHeap(reinterpret_cast<MEMExpHeap *>(gJumpHeapHandle))) {
|
||||
OSFatal("FunctionPatcherModule: Corrupted heap");
|
||||
} else {
|
||||
DEBUG_FUNCTION_LINE_VERBOSE("JumpData heap has no curruption. Checked on core %d", OSGetCoreId());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
void CheckMemExpHeapJumpData() {
|
||||
CThread::runOnAllCores(CheckMemExpHeapJumpDataCallback, nullptr, 0, 16, 0x1000);
|
||||
}
|
||||
|
||||
@@ -12,3 +12,5 @@ std::shared_ptr<T> make_shared_nothrow(Args &&...args) noexcept(noexcept(T(std::
|
||||
}
|
||||
|
||||
bool ReadFromPhysicalAddress(uint32_t srcPhys, uint32_t *out);
|
||||
|
||||
void CheckMemExpHeapJumpData();
|
||||
Reference in New Issue
Block a user