Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(225)

Side by Side Diff: chrome_elf/blacklist/blacklist.cc

Issue 174013007: Add UMA stats to record when DLLs are successfully blocked in the Browser. (Closed) Base URL: http://git.chromium.org/chromium/src.git@master
Patch Set: Responding to comments Created 6 years, 9 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright 2013 The Chromium Authors. All rights reserved. 1 // Copyright 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "chrome_elf/blacklist/blacklist.h" 5 #include "chrome_elf/blacklist/blacklist.h"
6 6
7 #include <string.h> 7 #include <string.h>
8 8
9 #include "base/basictypes.h" 9 #include "base/basictypes.h"
10 #include "chrome_elf/blacklist/blacklist_interceptions.h" 10 #include "chrome_elf/blacklist/blacklist_interceptions.h"
(...skipping 10 matching lines...) Expand all
21 21
22 const wchar_t* g_troublesome_dlls[kTroublesomeDllsMaxCount] = { 22 const wchar_t* g_troublesome_dlls[kTroublesomeDllsMaxCount] = {
23 L"datamngr.dll", // Unknown (suspected adware). 23 L"datamngr.dll", // Unknown (suspected adware).
24 L"hk.dll", // Unknown (keystroke logger). 24 L"hk.dll", // Unknown (keystroke logger).
25 L"libsvn_tsvn32.dll", // TortoiseSVN. 25 L"libsvn_tsvn32.dll", // TortoiseSVN.
26 L"lmrn.dll", // Unknown. 26 L"lmrn.dll", // Unknown.
27 // Keep this null pointer here to mark the end of the list. 27 // Keep this null pointer here to mark the end of the list.
28 NULL, 28 NULL,
29 }; 29 };
30 30
31 bool g_blocked_dlls[kTroublesomeDllsMaxCount] = {false};
robertshield 2014/02/25 03:21:40 "= {}" works for bool arrays too.
csharp 2014/02/25 14:45:00 Done.
32 int g_num_blocked_dlls = 0;
33
31 const wchar_t kRegistryBeaconPath[] = L"SOFTWARE\\Google\\Chrome\\BLBeacon"; 34 const wchar_t kRegistryBeaconPath[] = L"SOFTWARE\\Google\\Chrome\\BLBeacon";
32 const wchar_t kBeaconVersion[] = L"version"; 35 const wchar_t kBeaconVersion[] = L"version";
33 const wchar_t kBeaconState[] = L"state"; 36 const wchar_t kBeaconState[] = L"state";
34 37
35 } // namespace blacklist 38 } // namespace blacklist
36 39
37 // Allocate storage for thunks in a page of this module to save on doing 40 // Allocate storage for thunks in a page of this module to save on doing
38 // an extra allocation at run time. 41 // an extra allocation at run time.
39 #pragma section(".crthunk",read,execute) 42 #pragma section(".crthunk",read,execute)
40 __declspec(allocate(".crthunk")) sandbox::ThunkData g_thunk_storage; 43 __declspec(allocate(".crthunk")) sandbox::ThunkData g_thunk_storage;
(...skipping 250 matching lines...) Expand 10 before | Expand all | Expand 10 after
291 for (int i = 0; i < blacklist_size; ++i) { 294 for (int i = 0; i < blacklist_size; ++i) {
292 if (!_wcsicmp(g_troublesome_dlls[i], dll_name)) 295 if (!_wcsicmp(g_troublesome_dlls[i], dll_name))
293 return true; 296 return true;
294 } 297 }
295 298
296 // Copy string to blacklist. 299 // Copy string to blacklist.
297 wchar_t* str_buffer = new wchar_t[wcslen(dll_name) + 1]; 300 wchar_t* str_buffer = new wchar_t[wcslen(dll_name) + 1];
298 wcscpy(str_buffer, dll_name); 301 wcscpy(str_buffer, dll_name);
299 302
300 g_troublesome_dlls[blacklist_size] = str_buffer; 303 g_troublesome_dlls[blacklist_size] = str_buffer;
304 g_blocked_dlls[blacklist_size] = false;
301 return true; 305 return true;
302 } 306 }
303 307
304 bool RemoveDllFromBlacklist(const wchar_t* dll_name) { 308 bool RemoveDllFromBlacklist(const wchar_t* dll_name) {
305 int blacklist_size = BlacklistSize(); 309 int blacklist_size = BlacklistSize();
306 for (int i = 0; i < blacklist_size; ++i) { 310 for (int i = 0; i < blacklist_size; ++i) {
307 if (!_wcsicmp(g_troublesome_dlls[i], dll_name)) { 311 if (!_wcsicmp(g_troublesome_dlls[i], dll_name)) {
308 // Found the thing to remove. Delete it then replace it with the last 312 // Found the thing to remove. Delete it then replace it with the last
309 // element. 313 // element.
310 delete[] g_troublesome_dlls[i]; 314 delete[] g_troublesome_dlls[i];
311 g_troublesome_dlls[i] = g_troublesome_dlls[blacklist_size - 1]; 315 g_troublesome_dlls[i] = g_troublesome_dlls[blacklist_size - 1];
312 g_troublesome_dlls[blacklist_size - 1] = NULL; 316 g_troublesome_dlls[blacklist_size - 1] = NULL;
317
318 // Also update the stats recording if we have blocked this dll or not.
319 if (g_blocked_dlls[i])
320 --g_num_blocked_dlls;
321 g_blocked_dlls[i] = g_blocked_dlls[blacklist_size - 1];
313 return true; 322 return true;
314 } 323 }
315 } 324 }
316 return false; 325 return false;
317 } 326 }
318 327
328 // TODO(csharp): Maybe store these values in the registry so we can
329 // still report them if Chrome crashes early.
330 void SuccessfullyBlocked(const wchar_t** blocked_dlls, int* size) {
331 if (size == NULL)
332 return;
333
334 // If the array isn't valid or big enough, just report the size it needs to
335 // be and return.
336 if (blocked_dlls == NULL && *size < g_num_blocked_dlls) {
337 *size = g_num_blocked_dlls;
robertshield 2014/02/25 03:21:40 The comment on this method states that |size| will
csharp 2014/02/25 14:45:00 Comment is correct, fixed code.
338 return;
339 }
340
341 int strings_to_fill = 0;
342 for (int i = 0;
343 strings_to_fill != g_num_blocked_dlls && g_troublesome_dlls[i];
robertshield 2014/02/25 03:21:40 |strings_to_fill| indexes into |blocked_dlls| and
csharp 2014/02/25 14:45:00 Replaced != with <, also |size| >= |g_num_blocked_
344 ++i) {
robertshield 2014/02/25 03:21:40 I know I said to break here earlier, but if you c
csharp 2014/02/25 14:45:00 git cl format seems to like merging line 342 and 3
345 if (g_blocked_dlls[i]) {
346 blocked_dlls[strings_to_fill] = g_troublesome_dlls[i];
347 ++strings_to_fill;
348 }
349 }
350 }
351
352 void BlockedDll(int blocked_index) {
robertshield 2014/02/25 03:21:40 check |blocked_index| against kTroublesomeDllsMaxC
csharp 2014/02/25 14:45:00 Done.
353 if (!g_blocked_dlls[blocked_index]) {
354 ++g_num_blocked_dlls;
355 g_blocked_dlls[blocked_index] = true;
356 }
357 }
358
319 bool Initialize(bool force) { 359 bool Initialize(bool force) {
320 // Check to see that we found the functions we need in ntdll. 360 // Check to see that we found the functions we need in ntdll.
321 if (!InitializeInterceptImports()) 361 if (!InitializeInterceptImports())
322 return false; 362 return false;
323 363
324 // Check to see if this is a non-browser process, abort if so. 364 // Check to see if this is a non-browser process, abort if so.
325 if (IsNonBrowserProcess()) 365 if (IsNonBrowserProcess())
326 return false; 366 return false;
327 367
328 // Check to see if a beacon is present, abort if so. 368 // Check to see if a beacon is present, abort if so.
(...skipping 115 matching lines...) Expand 10 before | Expand all | Expand 10 after
444 sizeof(g_thunk_storage), 484 sizeof(g_thunk_storage),
445 PAGE_EXECUTE_READ, 485 PAGE_EXECUTE_READ,
446 &old_protect); 486 &old_protect);
447 487
448 RecordSuccessfulThunkSetup(&key); 488 RecordSuccessfulThunkSetup(&key);
449 489
450 return NT_SUCCESS(ret) && page_executable; 490 return NT_SUCCESS(ret) && page_executable;
451 } 491 }
452 492
453 } // namespace blacklist 493 } // namespace blacklist
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698