build/win32/crashinjectdll/crashinjectdll.cpp

Tue, 06 Jan 2015 21:39:09 +0100

author
Michael Schloh von Bennewitz <michael@schloh.com>
date
Tue, 06 Jan 2015 21:39:09 +0100
branch
TOR_BUG_9701
changeset 8
97036ab72558
permissions
-rw-r--r--

Conditionally force memory storage according to privacy.thirdparty.isolate;
This solves Tor bug #9701, complying with disk avoidance documented in
https://www.torproject.org/projects/torbrowser/design/#disk-avoidance.

     1 /* This Source Code Form is subject to the terms of the Mozilla Public
     2  * License, v. 2.0. If a copy of the MPL was not distributed with this
     3  * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
     5 #include <stdio.h>
     6 #include <windows.h>
     8 // make sure we only ever spawn one thread
     9 DWORD tid = -1;
    11 DWORD WINAPI CrashingThread(
    12   LPVOID lpParameter
    13 )
    14 {
    15   // not a very friendly DLL
    16   volatile int* x = (int *)0x0;
    17   *x = 1;
    18   return 0;
    19 }
    21 BOOL WINAPI DllMain(
    22   HANDLE hinstDLL,
    23   DWORD dwReason,
    24   LPVOID lpvReserved
    25 )
    26 {
    27   if (tid == -1)
    28     // we have to crash on another thread because LoadLibrary() will
    29     // catch memory access errors and return failure to the calling process
    30     CreateThread(
    31                  nullptr,                // default security attributes
    32                  0,                      // use default stack size
    33                  CrashingThread,         // thread function name
    34                  nullptr,                // argument to thread function
    35                  0,                      // use default creation flags
    36                  &tid);                  // returns the thread identifier
    37   return TRUE;
    38 }

mercurial