bearbecueLe 15/07/2011 à 17:06
NT_TIB *tib = NtCurrentTib();
// here, we could use 'IsBadReadPtr', but unfortunately visual studio dumps
// exception warnings when debugging the app, and the overhead is incredibly high, so we can't afford it.
// same problem with __try {} __except {} blocks.
// quick cull. most of the reads happen within our own stack, except the last frame reads that point outside.
// don't pay the price of ReadProcessMemory() when we can trivially ensure the data is within stack range
if (context->Ebp > hh_ureg(tib->StackLimit) &&
context->Ebp + 2 * sizeof(hh_u32) <= hh_ureg(tib->StackBase))
{
const hh_u32 *regs = (const hh_u32*)context->Ebp;
context->Esp = context->Ebp + 2 * sizeof(hh_u32);
context->Ebp = regs[0];
context->Eip = regs[1];
return true;
}
else
{
hh_u32 ebp = context->Ebp;
HH_ASSERT(hh_ureg(&context->Eip) - hh_ureg(&context->Ebp) == 4); // these two should be contiguous
if (::ReadProcessMemory(::GetCurrentProcess(), (void*)ebp, &context->Ebp, 2 * sizeof(hh_u32), null))
{
context->Esp = ebp + 2 * sizeof(hh_u32);
return true;
}
}
return false;