correctly handle breakpoints happening before the system breakpoint

This commit is contained in:
Duncan Ogilvie 2017-12-28 21:07:19 +01:00
parent 2dd2cb1e3d
commit 7dc011516d
No known key found for this signature in database
GPG Key ID: FC89E0AAA0C1AAD8
1 changed files with 56 additions and 56 deletions

View File

@ -4,13 +4,17 @@ namespace GleeBug
{ {
void Debugger::exceptionBreakpoint(const EXCEPTION_RECORD & exceptionRecord, const bool firstChance) void Debugger::exceptionBreakpoint(const EXCEPTION_RECORD & exceptionRecord, const bool firstChance)
{ {
if (!mProcess->systemBreakpoint) //handle system breakpoint //check if the breakpoint exists
auto foundInfo = mProcess->breakpoints.find({ BreakpointType::Software, ptr(exceptionRecord.ExceptionAddress) });
if(foundInfo == mProcess->breakpoints.end())
{
if(!mProcess->systemBreakpoint) //handle system breakpoint
{ {
//set internal state //set internal state
mProcess->systemBreakpoint = true; mProcess->systemBreakpoint = true;
mContinueStatus = DBG_CONTINUE; mContinueStatus = DBG_CONTINUE;
//get process DEP policy //get process DEP policy (TODO: what happens if a breakpoint is hit before the system breakpoint?)
#ifndef _WIN64 #ifndef _WIN64
typedef BOOL(WINAPI * GETPROCESSDEPPOLICY)( typedef BOOL(WINAPI * GETPROCESSDEPPOLICY)(
_In_ HANDLE /*hProcess*/, _In_ HANDLE /*hProcess*/,
@ -18,13 +22,13 @@ namespace GleeBug
_Out_ PBOOL /*lpPermanent*/ _Out_ PBOOL /*lpPermanent*/
); );
static auto GPDP = GETPROCESSDEPPOLICY(GetProcAddress(GetModuleHandleW(L"kernel32.dll"), "GetProcessDEPPolicy")); static auto GPDP = GETPROCESSDEPPOLICY(GetProcAddress(GetModuleHandleW(L"kernel32.dll"), "GetProcessDEPPolicy"));
if (GPDP) if(GPDP)
{ {
//If you use mProcess->hProcess GetProcessDEPPolicy will put garbage in bPermanent. //If you use mProcess->hProcess GetProcessDEPPolicy will put garbage in bPermanent.
auto hProcess = OpenProcess(PROCESS_QUERY_INFORMATION, FALSE, mProcess->dwProcessId); auto hProcess = OpenProcess(PROCESS_QUERY_INFORMATION, FALSE, mProcess->dwProcessId);
DWORD lpFlags; DWORD lpFlags;
BOOL bPermanent; BOOL bPermanent;
if (GPDP(hProcess, &lpFlags, &bPermanent)) if(GPDP(hProcess, &lpFlags, &bPermanent))
mProcess->permanentDep = lpFlags != 0 && bPermanent; mProcess->permanentDep = lpFlags != 0 && bPermanent;
CloseHandle(hProcess); CloseHandle(hProcess);
} }
@ -35,12 +39,9 @@ namespace GleeBug
//call the callback //call the callback
cbSystemBreakpoint(); cbSystemBreakpoint();
} }
else
{
//check if the breakpoint exists
auto foundInfo = mProcess->breakpoints.find({ BreakpointType::Software, ptr(exceptionRecord.ExceptionAddress) });
if (foundInfo == mProcess->breakpoints.end())
return; return;
}
const auto info = foundInfo->second; const auto info = foundInfo->second;
//set continue status //set continue status
@ -54,7 +55,7 @@ namespace GleeBug
mThread->StepInternal(std::bind([this, info]() mThread->StepInternal(std::bind([this, info]()
{ {
//only restore the bytes if the breakpoint still exists //only restore the bytes if the breakpoint still exists
if (mProcess->breakpoints.find({ BreakpointType::Software, info.address }) != mProcess->breakpoints.end()) if(mProcess->breakpoints.find({ BreakpointType::Software, info.address }) != mProcess->breakpoints.end())
mProcess->MemWriteUnsafe(info.address, info.internal.software.newbytes, info.internal.software.size); mProcess->MemWriteUnsafe(info.address, info.internal.software.newbytes, info.internal.software.size);
})); }));
@ -63,14 +64,13 @@ namespace GleeBug
//call the user callback //call the user callback
auto foundCallback = mProcess->breakpointCallbacks.find({ BreakpointType::Software, info.address }); auto foundCallback = mProcess->breakpointCallbacks.find({ BreakpointType::Software, info.address });
if (foundCallback != mProcess->breakpointCallbacks.end()) if(foundCallback != mProcess->breakpointCallbacks.end())
foundCallback->second(info); foundCallback->second(info);
//delete the breakpoint if it is singleshoot //delete the breakpoint if it is singleshoot
if (info.singleshoot) if(info.singleshoot)
mProcess->DeleteGenericBreakpoint(info); mProcess->DeleteGenericBreakpoint(info);
} }
}
void Debugger::exceptionSingleStep(const EXCEPTION_RECORD & exceptionRecord, const bool firstChance) void Debugger::exceptionSingleStep(const EXCEPTION_RECORD & exceptionRecord, const bool firstChance)
{ {