Release 980712
[wine] / if1632 / snoop.c
1 /*
2  * 386-specific Win16 dll<->dll snooping functions
3  *
4  * Copyright 1998 Marcus Meissner
5  */
6
7 #ifdef __i386__
8
9 #include <assert.h>
10 #include "windows.h"
11 #include "winbase.h"
12 #include "winnt.h"
13 #include "heap.h"
14 #include "global.h"
15 #include "selectors.h"
16 #include "stackframe.h"
17 #include "snoop.h"
18 #include "debugstr.h"
19 #include "debug.h"
20
21 #pragma pack(1)
22
23 void WINAPI SNOOP16_Entry(CONTEXT *context);
24 void WINAPI SNOOP16_Return(CONTEXT *context);
25 extern void CallFrom16_p_regs_();
26
27 /* Generic callfrom16_p_regs function entry.
28  *      pushw %bp                       0x55
29  *      pushl $DOS3Call                 DWORD fun32
30  *      .byte 0x9a                      0x9a
31  *      .long CallFrom16_p_regs_        DWORD addr
32  *      .long 0x90900023                WORD seg;nop;nop
33  */
34
35 typedef struct tagSNOOP16_FUN {
36         /* code part */
37         BYTE            lcall;          /* 0x9a call absolute with segment */
38         DWORD           snr;
39         /* unreached */
40         int             nrofargs;
41         FARPROC16       origfun;
42         char            *name;
43 } SNOOP16_FUN;
44
45 typedef struct tagSNOOP16_DLL {
46         HMODULE16       hmod;
47         HANDLE16        funhandle;
48         SNOOP16_FUN     *funs;
49         LPCSTR          name;
50         struct tagSNOOP16_DLL   *next;
51 } SNOOP16_DLL;
52
53 typedef struct tagSNOOP16_RETURNENTRY {
54         /* code part */
55         BYTE            lcall;          /* 0x9a call absolute with segment */
56         DWORD           snr;
57         /* unreached */
58         FARPROC16       origreturn;
59         SNOOP16_DLL     *dll;
60         DWORD           ordinal;
61         WORD            origSP;
62         WORD            *args;          /* saved args across a stdcall */
63 } SNOOP16_RETURNENTRY;
64
65 typedef struct tagSNOOP16_RETURNENTRIES {
66         SNOOP16_RETURNENTRY entry[65500/sizeof(SNOOP16_RETURNENTRY)];
67         HANDLE16        rethandle;
68         struct tagSNOOP16_RETURNENTRIES *next;
69 } SNOOP16_RETURNENTRIES;
70
71 typedef struct tagSNOOP16_RELAY {
72         /* code part */
73         BYTE            prefix;         /* 0x66 , 32bit prefix */
74         BYTE            pushbp;         /* 0x55 */
75         BYTE            pushl;          /* 0x68 */
76         DWORD           realfun;        /* SNOOP16_Return */
77         BYTE            lcall;          /* 0x9a call absolute with segment */
78         DWORD           callfromregs;
79         WORD            seg;
80         /* unreached */
81 } SNOOP16_RELAY;
82
83 #pragma pack(4)
84
85 static  SNOOP16_DLL             *firstdll = NULL;
86 static  SNOOP16_RETURNENTRIES   *firstrets = NULL;
87 static  SNOOP16_RELAY           *snr;
88 static  HANDLE16                xsnr = 0;
89
90 void
91 SNOOP16_RegisterDLL(NE_MODULE *pModule,LPCSTR name) {
92         SNOOP16_DLL     **dll = &(firstdll);
93         char            *s;
94
95         if (!TRACE_ON(snoop)) return;
96         if (!snr) {
97                 xsnr=GLOBAL_Alloc(GMEM_ZEROINIT,2*sizeof(*snr),0,TRUE,TRUE,FALSE);
98                 snr = GlobalLock16(xsnr);
99                 snr[0].prefix   = 0x66;
100                 snr[0].pushbp   = 0x55;
101                 snr[0].pushl    = 0x68;
102                 snr[0].realfun  = (DWORD)SNOOP16_Entry;
103                 snr[0].lcall    = 0x9a;
104                 snr[0].callfromregs = (DWORD)CallFrom16_p_regs_;
105                 GET_CS(snr[0].seg);
106                 snr[1].prefix   = 0x66;
107                 snr[1].pushbp   = 0x55;
108                 snr[1].pushl    = 0x68;
109                 snr[1].realfun  = (DWORD)SNOOP16_Return;
110                 snr[1].lcall    = 0x9a;
111                 snr[1].callfromregs = (DWORD)CallFrom16_p_regs_;
112                 GET_CS(snr[1].seg);
113         }
114         while (*dll) {
115                 if ((*dll)->hmod == pModule->self)
116                         return; /* already registered */
117                 dll = &((*dll)->next);
118         }
119         *dll = (SNOOP16_DLL*)HeapAlloc(SystemHeap,HEAP_ZERO_MEMORY,sizeof(SNOOP16_DLL));
120         (*dll)->next    = NULL;
121         (*dll)->hmod    = pModule->self;
122         if ((s=strrchr(name,'\\')))
123                 name = s+1;
124         (*dll)->name    = HEAP_strdupA(SystemHeap,0,name);
125         if ((s=strrchr((*dll)->name,'.')))
126                 *s='\0';
127         (*dll)->funhandle = GlobalHandleToSel(GLOBAL_Alloc(GMEM_ZEROINIT,65535,0,TRUE,FALSE,FALSE));
128         (*dll)->funs = GlobalLock16((*dll)->funhandle);
129         if (!(*dll)->funs) {
130                 HeapFree(SystemHeap,0,*dll);
131                 FIXME(snoop,"out of memory\n");
132                 return;
133         }
134         memset((*dll)->funs,0,65535);
135 }
136
137 FARPROC16
138 SNOOP16_GetProcAddress16(HMODULE16 hmod,DWORD ordinal,FARPROC16 origfun) {
139         SNOOP16_DLL                     *dll = firstdll;
140         SNOOP16_FUN                     *fun;
141         NE_MODULE                       *pModule = NE_GetPtr(hmod);
142         unsigned char                   *cpnt;
143         char                            name[200];
144
145         if (!TRACE_ON(snoop) || !pModule || !HIWORD(origfun))
146                 return origfun;
147         if (!*(LPBYTE)PTR_SEG_TO_LIN(origfun)) /* 0x00 is an imposs. opcode, poss. dataref. */
148                 return origfun;
149         while (dll) {
150                 if (hmod == dll->hmod)
151                         break;
152                 dll=dll->next;
153         }
154         if (!dll)       /* probably internal */
155                 return origfun;
156         if (ordinal>65535/sizeof(SNOOP16_FUN))
157                 return origfun;
158         fun = dll->funs+ordinal;
159         /* already done? */
160         fun->lcall      = 0x9a;
161         fun->snr        = MAKELONG(0,xsnr);
162         fun->origfun    = origfun;
163         if (fun->name)
164                 return (FARPROC16)(SEGPTR)MAKELONG(((char*)fun-(char*)dll->funs),dll->funhandle);
165         cpnt = (unsigned char *)pModule + pModule->name_table;
166         while (*cpnt) {
167                 cpnt += *cpnt + 1 + sizeof(WORD);
168                 if (*(WORD*)(cpnt+*cpnt+1) == ordinal) {
169                         sprintf(name,"%.*s",*cpnt,cpnt+1);
170                         break;
171                 }
172         }
173         /* Now search the non-resident names table */
174
175         if (!*cpnt && pModule->nrname_handle) {
176                 cpnt = (char *)GlobalLock16( pModule->nrname_handle );
177                 while (*cpnt) {
178                         cpnt += *cpnt + 1 + sizeof(WORD);
179                         if (*(WORD*)(cpnt+*cpnt+1) == ordinal) {
180                                     sprintf(name,"%.*s",*cpnt,cpnt+1);
181                                     break;
182                         }
183                 }
184         }
185         if (*cpnt)
186                 fun->name = HEAP_strdupA(SystemHeap,0,name);
187         else
188                 fun->name = HEAP_strdupA(SystemHeap,0,"");
189         /* more magic. do not try to snoop thunk data entries (MMSYSTEM) */
190         if (strchr(fun->name,'_')) {
191                 char *s=strchr(fun->name,'_');
192
193                 if (!strncasecmp(s,"_thunkdata",10)) {
194                         HeapFree(SystemHeap,0,fun->name);
195                         fun->name = NULL;
196                         return origfun;
197                 }
198         }
199         fun->lcall      = 0x9a;
200         fun->snr        = MAKELONG(0,xsnr);
201         fun->origfun    = origfun;
202         fun->nrofargs   = -1;
203         return (FARPROC16)(SEGPTR)MAKELONG(((char*)fun-(char*)dll->funs),dll->funhandle);
204 }
205
206 #define CALLER1REF (*(DWORD*)(PTR_SEG_OFF_TO_LIN(SS_reg(context),SP_reg(context)+4)))
207 void WINAPI SNOOP16_Entry(CONTEXT *context) {
208         DWORD           ordinal=0;
209         DWORD           entry=(DWORD)PTR_SEG_OFF_TO_LIN(CS_reg(context),IP_reg(context))-5;
210         WORD            xcs = CS_reg(context);
211         SNOOP16_DLL     *dll = firstdll;
212         SNOOP16_FUN     *fun = NULL;
213         SNOOP16_RETURNENTRIES   **rets = &firstrets;
214         SNOOP16_RETURNENTRY     *ret;
215         int             i,max;
216
217         while (dll) {
218                 if (xcs == dll->funhandle) {
219                         fun = (SNOOP16_FUN*)entry;
220                         ordinal = fun-dll->funs;
221                         break;
222                 }
223                 dll=dll->next;
224         }
225         if (!dll) {
226                 FIXME(snoop,"entrypoint 0x%08lx not found\n",entry);
227                 return; /* oops */
228         }
229         /* guess cdecl ... */
230         if (fun->nrofargs<0) {
231                 /* Typical cdecl return frame is:
232                  *      add esp, xxxxxxxx 
233                  * which has (for xxxxxxxx up to 255 the opcode "83 C4 xx".
234                  */
235                 LPBYTE  reteip = (LPBYTE)PTR_SEG_TO_LIN(CALLER1REF);
236
237                 if ((reteip[0]==0x83)&&(reteip[1]==0xc4))
238                         fun->nrofargs=reteip[2]/2;
239         }
240
241         while (*rets) {
242                 for (i=0;i<sizeof((*rets)->entry)/sizeof((*rets)->entry[0]);i++)
243                         if (!(*rets)->entry[i].origreturn)
244                                 break;
245                 if (i!=sizeof((*rets)->entry)/sizeof((*rets)->entry[0]))
246                         break;
247                 rets = &((*rets)->next);
248         }
249         if (!*rets) {
250                 HANDLE16        hand = GlobalHandleToSel(GLOBAL_Alloc(GMEM_ZEROINIT,65535,0,TRUE,FALSE,FALSE));
251                 *rets = GlobalLock16(hand);
252                 memset(*rets,0,65535);
253                 (*rets)->rethandle = hand;
254                 i = 0;  /* entry 0 is free */
255         }
256         ret = &((*rets)->entry[i]);
257         ret->lcall      = 0x9a;
258         ret->snr        = MAKELONG(sizeof(SNOOP16_RELAY),xsnr);
259         ret->origreturn = (FARPROC16)CALLER1REF;
260         CALLER1REF      = MAKELONG((char*)&(ret->lcall)-(char*)((*rets)->entry),(*rets)->rethandle);
261         ret->dll        = dll;
262         ret->args       = NULL;
263         ret->ordinal    = ordinal;
264         ret->origSP     = SP_reg(context);
265
266         IP_reg(context)= LOWORD(fun->origfun);
267         CS_reg(context)= HIWORD(fun->origfun);
268
269         DPRINTF("Call %s.%ld: %s(",dll->name,ordinal,fun->name);
270         if (fun->nrofargs>0) {
271                 max = fun->nrofargs; if (max>16) max=16;
272                 for (i=max;i--;)
273                         DPRINTF("%04x%s",*(WORD*)(PTR_SEG_OFF_TO_LIN(SS_reg(context),SP_reg(context))+8+sizeof(WORD)*i),i?",":"");
274                 if (max!=fun->nrofargs)
275                         DPRINTF(" ...");
276         } else if (fun->nrofargs<0) {
277                 DPRINTF("<unknown, check return>");
278                 ret->args = HeapAlloc(SystemHeap,0,16*sizeof(WORD));
279                 memcpy(ret->args,(LPBYTE)(PTR_SEG_OFF_TO_LIN(SS_reg(context),SP_reg(context))+8),sizeof(WORD)*16);
280         }
281         DPRINTF(") ret=%04x:%04x\n",HIWORD((DWORD)(*rets)->entry[i].origreturn),LOWORD((DWORD)(*rets)->entry[i].origreturn));
282 }
283
284 void WINAPI SNOOP16_Return(CONTEXT *context) {
285         SNOOP16_RETURNENTRY     *ret = (SNOOP16_RETURNENTRY*)(PTR_SEG_OFF_TO_LIN(CS_reg(context),IP_reg(context))-5);
286
287         /* We haven't found out the nrofargs yet. If we called a cdecl
288          * function it is too late anyway and we can just set '0' (which 
289          * will be the difference between orig and current SP
290          * If pascal -> everything ok.
291          */
292         if (ret->dll->funs[ret->ordinal].nrofargs<0)
293                 ret->dll->funs[ret->ordinal].nrofargs=(SP_reg(context)-ret->origSP-4)/2;
294         IP_reg(context) = LOWORD(ret->origreturn);
295         CS_reg(context) = HIWORD(ret->origreturn);
296         if (ret->args) {
297                 int     i,max;
298
299                 DPRINTF("Ret  %s.%ld: %s(",ret->dll->name,ret->ordinal,ret->dll->funs[ret->ordinal].name);
300                 max = ret->dll->funs[ret->ordinal].nrofargs;
301                 if (max>16) max=16;
302
303                 for (i=max;i--;)
304                         DPRINTF("%04x%s",ret->args[i],i?",":"");
305                 DPRINTF(") retval = %04x:%04x ret=%04x:%04x\n",
306                         DX_reg(context),AX_reg(context),HIWORD(ret->origreturn),LOWORD(ret->origreturn)
307                 );
308                 HeapFree(SystemHeap,0,ret->args);
309                 ret->args = NULL;
310         } else
311                 DPRINTF("Ret  %s.%ld: %s() retval = %04x:%04x ret=%04x:%04x\n",
312                         ret->dll->name,ret->ordinal,ret->dll->funs[ret->ordinal].name,
313                         DX_reg(context),AX_reg(context),HIWORD(ret->origreturn),LOWORD(ret->origreturn)
314                 );
315         ret->origreturn = NULL; /* mark as empty */
316 }
317 #else   /* !__i386__ */
318 void SNOOP16_RegisterDLL(NE_MODULE *pModule,LPCSTR name) {
319         FIXME(snoop,"snooping works only on i386 for now.\n");
320         return;
321 }
322
323 FARPROC16 SNOOP16_GetProcAddress16(HMODULE16 hmod,DWORD ordinal,FARPROC16 origfun) {
324         return origfun;
325 }
326 #endif  /* !__i386__ */
327
328 void
329 SNOOP16_Init() {
330         fnSNOOP16_GetProcAddress16=SNOOP16_GetProcAddress16;
331         fnSNOOP16_RegisterDLL=SNOOP16_RegisterDLL;
332 }