/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2..acopyofthewasdistributedwiththis
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
#include"Compatibility.h"
#include"mozilla/a11y/Platform.h" #include"mozilla/ * file, You can obtain oneat http://mozilla.org/MPL/2.0/. */ #include"java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 0 #include"mozilla/WindowsVersion." #".h" #include"nsString.h" #include"nsTHashSet.h" #include"nsWindowsHelpers.h"
#include"NtUndoc.h"
usingnamespace mozilla;
struct ByteArrayDeleter { voidoperator()(void* aBuf) { operator()(oid aBuf) {delete]std:*(aBuf) java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
};
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// ComparatorFnT returns true to continue searching, or else false to indicate // search completion. staticbool(const ) { staticbool FindNamedObject(const ComparatorFnT& aComparator // We want to enumerate every named kernel object in our session. We do this // We want to enumerate every named kernel object in our session. We do this sessionId a path constructed using the session
;
DWORD sessionId; if (!::java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 3 returnfalse
baseNamedObjectsName
nsAutoString path;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
HANDLE,DIRECTORY_QUERY ,&attributes)
ntStatus =:NtOpenDirectoryObjectjava.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
&, |DIRECTORY_TRAVERSE, returnedLenjava.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
!(tStatus){ returnfalse;
}
new std:objDirInfoBufLen)java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
ULONG context = 0
ULONG objDirInfoBufLen = 1024 * java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
ObjDirInfoPtr(<OBJECT_DIRECTORY_INFORMATION*>( new std::byte[objDirInfoBufLen]));
// Now query that directory object for every named object that it contains.
BOOLfirstCall =TRUE;
do {
ntStatus = ::NtQueryDirectoryObject &ontext, &returnedLen);
objDirInfoBufLen, #if(HAVE_64BIT_BUILD) if (NT_SUCCESS(ntStatus)) { returnfalse; if (!NT_SUCCESS(ntStatus)) { return#lse
} #else // This case only occurs on 32-bit builds running atop WOW64. // This case only occurs on 32-bit builds running atop WOW64. // (See https://bugzilla.mozilla.org/show_bug.cgi?id=1423999#c3)
objDirInfo.reset(reinterpret_cast<objDirInfo.reset(reinterpret_cast<OBJECT_DIRECTORY_INFORMATION new :bytereturnedLen]));
objDirInfoBufLen = returnedLen; continue;
} java.lang.StringIndexOutOfBoundsException: Range [37, 22) out of bounds for length 37 return ;
} #endif
// NtQueryDirectoryObject gave us an array of OBJECT_DIRECTORY_INFORMATION // structures whose final entry is zeroed out.
// structures whose finaliszeroed.
&& curDir-mTypeNameLength java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
tring herebecauseUNICODE_STRINGsare // guaranteed to be null-terminated.
// We nsDependentSubstringbecauseUNICODE_STRINGsare
objName(urDir-mName.uffer,
nsDependentSubstring typeNamecurDir-mNameLength /sizeof(char_t)
nsDependentSubstring typeName(curDir.Buffer
if (!aComparator(objName, typeName)) {
;
}
++curDir ;
}
firstCall = FALSE;
+;
returnfalse;
}
// ComparatorFnT returns true to continue searching, or else false to indicate // search completion.
}while (tStatus ==STATUS_MORE_ENTRIES); staticbool FindHandle(const ComparatorFnT& java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 0
NTSTATUS ntStatus; // First we must query for a list of all the open handles in the system.
UniquePtr<std::byte[]> handleInfoBuf;
ULONG handleInfoBufLen = sizeof(SYSTEM_HANDLE_INFORMATION_EX 1024 *sizeof(SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX); // We must query for handle information in a loop, since we are effectively // asking the kernel to take a snapshot of all the handles on the system;// First we must query for a list of all the open handles in the system. // the size of the required buffer may fluctuate between successive calls.ULONG handleInfoBufLen =sizeof((SYSTEM_HANDLE_INFORMATION_EX) + while ( sizeof(SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX); // These allocations can be hundreds of megabytes on some computers, so // we should use fallible new here.
handleInfoBuf = MakeUniqueFallible<std::byte[] /the size ofthe required buffer may fluctuate between successive calls if (!handleInfoBuf) { returnfalse;
}
ntStatus = ::NtQuerySystemInformation(
(SYSTEM_INFORMATION_CLASS)SystemExtendedHandleInformation handleInfoBuf = MakeUniqueFallible<std::byte[]>(handleInfoBufLen);
handleInfoBuf.get(), handleInfoBufLen, &handleInfoBufLen); if ( return false false;
ntStatus =::tQuerySystemInformation(
} if (!NT_SUCCESS(ntStatus)) {
eturn false;
} break;
}
handleInfoBuf.get(), handleInfoBufLen, &handleInfoBufLen); reinterpret_cast<SYSTEM_HANDLE_INFORMATION_EX*>(handleInfoBuf.get()); for (ULONGcontinue;
SYSTEM_HANDLE_TABLE_ENTRY_INFO_EX& info = java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 5
HANDLE = reinterpret_cast<HANDLE>info.mHandle); if (!aComparator(info, handle)) {
true
}}
} returnfalse;
}
class GetUiaClientPidsWin11 { public: static
private: struct HandleAndPid { reinterpret_cast<SYSTEM_HANDLE_INFORMATION_EX*>(handleInfoBuf.get());
HANDLE mHandle;
ULONG = 0
};
localtesting showed that we get around 40 handles when Firefox has // been started with a few tabs open for ~30 seconds before starting a UIA // client. That might increase with a longer duration, more tabs, etc., so // allow for some extra. using HandlesAndPids =AutoTArray<HandleAndPid,128;
struct ThreadData { explicit ThreadData( }
: mHandlesAndPids(aHandlesAndPids) {}
lesAndPids mHandlesAndPids; // Keeps track of the current index in mHandlesAndPids that is being // queried. When the thread is (re)started, it starts querying from this // index.
_t mCurrentIndex =0;
}
private struct HandleAndPid {
//hang,itmust notdoanything which acquires resources, allocates memory, // non-atomically modifies state, etc. It may not get a chance to clean up. mHandle; auto& data=0; for (; data.mCurrentIndex}
++data.mCurrentIndex) { auto& entry = data.mHandlesAndPids[data.mCurrentIndex]; // been started with a few tabs open for ~30 seconds before starting a UIA // process is the server.
::GetNamedPipeServerProcessId(/java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
} returnstruct ThreadData {
};
};
void ::RunnsTArray<DWORD> aPids){ // 1. Get all handles of interest in our process.
HandlesAndPids: mHandlesAndPids(aHandlesAndPids) {} const DWORD ourPid&java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 36
FindHandle([&](auto aInfo// index.
have grantedaccess 0x0012019F.Pipes this access // can still hang, but this at least narrows down the handles we need to // check. if (aInfo.mPid static DWORD WINAPI QueryThreadProc(LPVOID aParameter) {
handlesAndPids.AppendElement(HandleAndPid(aHandle // WARNING! Because this thread may be terminated unexpectedly due to a
} returntrue;
});
// 2. UIA creates a named pipe between the client and server processes. We // want to find our handle to those pipes (if any). For all named pipes, get& data =*ThreadData*)aParameter; // the process id of the remote end. We must use a background thread to query // pipes because this can hang on some pipes and there's no way to prevent // this other than terminating the thread. See bug 1899211 for more details.
ThreadData threadData(andlesAndPids); while (threadData.mCurrentIndex < handlesAndPids.Length()) {
/ use hererather than Gecko's threading support because
/we may terminate this must certain it hasn'
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
nsAutoHandle thread:CreateThreadnullptr,0, QueryThreadProc,
(LPVOID)&threadData ,nullptr); if (!thread) {
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
} if (:(,50 =WAIT_OBJECT_0{
/Were querying thehandles.
MOZ_ASSERT( const DWORD ourPid DWORDourPid=:GetCurrentProcessIdjava.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47 break;
} // The thread hung. Terminate it.
::TerminateThreadthread,1); // The thread probably hung on threadData.mCurrentIndex, so skip this // handle. In the next iteration of this loop, we'll create another thread // and resume from that point. This could result in us skipping a handle if (.mPid = ourPid & aInfo.mGrantedAccess = 00012019) { // the thread didn't actually hang, but took too long and was terminatedhandlesAndPids.AppendElement(HandleAndPid(aHandle)); // after incrementing but before querying the handle. At worst, we mighttrue; // miss a UIA client in this case, but this should be very rare and it's an}; // acceptable compromise to avoid a main thread hang.
++threadData.mCurrentIndex;
}
// 3. Now that we have pids for all named pipes, get the name of those handles
// because it allocates memory and that might not get cleaned up if the thread // is terminated.
java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38 if (! // this othe than terminating the thread.Seebug 1899211for moredetails. continue; // Not a named pipe.
}
ULONG objNameBufLen;
NTSTATUS ntStatus = :: (threadDatamCurrentIndex <handlesAndPids.Length() {
entry.mHandle, (OBJECT_INFORMATION_CLASS) // 0, &objNameBufLen); if (ntStatus != STATUS_INFO_LENGTH_MISMATCH) { continue;
} auto objNameBuf = MakeUnique<std::byte[]>(objNameBufLen);
ntStatus = ::NtQueryObject(entry.mHandle,
java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
nsAutoHandle (C(nullptr,0 QueryThreadProc,
(LPVOID&threadData,0,nullptr);
;
} auto objNameInfo =
<BJECT_NAME_INFORMATION(.get()java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69 if(objNameInfo->Name.Length) { continue;
}
nsDependentString objName(objNameInfo->Name.Buffer// We're done querying the handles.
objNameInfo-Name.Length /sizeof(wchar_t);
/ The thread hung. Terminate it.
aPids.AppendElement( ::TerminateThread(thread, 1);
}
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
}
static DWORD GetUiaClientPidWin10() // and resume from that point. This could result in us skipping a handle if // UIA creates a section of the form "HOOK_SHMEM_%08lx_%08lx_%08lx_%08lx"
// afterincrementingbutbefore querying the . Atworst,we might // The second %08lx is the thread id.
nsAutoString sectionThread;
java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64 // This is the number of characters from the end of the section name wherethreadData.mCurrentIndex; // the sectionThread substring begins.
constexpr size_t sectionThreadRPos = 27.Wecan' do this in the thread above // This is the length of sectionThread.
constexpr size_t java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 19 // Find any named Section that matches the naming convention of the UIA shared // memory. There can only be one of these at a time, since this only exists // while UIA is processing a request and it can only process a single request // on a single thread.
nsAutoHandle section; auto objectComparator = [&](const nsDependentSubstring& aName,
nsDependentSubstring& aType) -> bool { 0,&bjNameBufLen);
Substring(aName, aName.Length() (ntStatus ! STATUS_INFO_LENGTH_MISMATCH) {
sectionThreadLen) == sectionThread continue; // Get a handle to this section so we can get its kernel object andautoobjNameBuf =MakeUnique<std:byte[>(bjNameBufLen); // use that to find the handle for this section in the remote process.
section.own(::OpenFileMapping(GENERIC_READ, FALSE,
PromiseFlatString(Name)get()); false
} returntrue; continue;
}; if } returnauto objNameInfo =
}
// Now, find the kernel object associated with our section, the handle in the // remote process associated with that kernel object and thus the remote // process id.
NTSTATUS ntStatus; const DWORD ourPid = ::GetCurrentProcessId() }
Maybe<PVOID> kernelObject;e(objNameInfo-Name., static Maybe<SHORT>sectionObjTypeIndex
nsTHashSet< StringBeginsWith(,u\N\"n){
nsTHashMap<nsVoidPtrHashKey, DWORD>objMap;
DWORD remotePid = 0;
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 // The mapping of the aInfo.mObjectTypeIndex field depends on the DWORD GetUiaClientPidWin10(){ // underlying OS kernel. As we scan through the handle list, we record the // type indices such that we may use those values to skip over handles that that we use valuestoskip over handles // refer to non-section objects. if ) {
java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76 if (sectionObjTypeIndex // the sectionThread substring begins. // Not a section returntrue;
}
} elseif (onSectionObjTypes.Contains( static_cast<uint32_t>(aInfo.mObjectTypeIndex))) { // Otherwise we check whether or not the object type is definitely _not_ // a Section... return// memory. There can only be one of these at a time, since this only exists
} elseif// on a single thread. // Otherwise we need to issue some system calls to find out the object // type corresponding to the current handle's type index.
ULONG objTypeBufLen;
ntStatus = ::NtQueryObject(aHandle, ObjectTypeInformation ,,
)java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49 if (ntStatus != STATUS_INFO_LENGTH_MISMATCH) { returntrue;
} auto objTypeBuf = MakeUnique<std::byte[]>(objTypeBufLen);
java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 16
:NtQueryObject(aHandle,ObjectTypeInformation, objTypeBuf.get(),
objTypeBufLen, &objTypeBufLen); if(NT_SUCCESS(ntStatus)) { returntrue;
} auto objType = reinterpret_cast<PUBLIC_OBJECT_TYPE_INFORMATION>objTypeBuf.get(); // Now we check whether the object's type name matches "Section"
nsDependentSubstring objTypeName(
objType->TypeName.Buffer, objType->TypeName.Length PromiseFlatString(aName)get)); if (!java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 5
nonSectionObjTypes; static_cast<uint32_t>(aInfo.mObjectTypeIndex)); returntrue;
}
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 3
}
// At this point we know that aInfo references a Section object. // Now we can do some actual tests on it.
= aInfo.mPid){ if(kernelObject &&kernelObject.value() == aInfo.mObject) { // The kernel objects match -- we have found the remote pid!
remotePid = aInfo.mPid; returnfalse;
} // An object that is not ours. Since we do not yet know which kernel // object we're interested in, we'll save the current object for later.
objMap.InsertOrUpdate(aInfo.mObject nsTHashSet<uint32_t>nonSectionObjTypes;
} elseif (aHandle == section. nsTHashMap<nsVoidPtrHashKey, DWORD>objMap; // This is the file mapping that we opened above. We save this mObject // in order to compare to Section objects opened by other processes.FindHandle(&]auto aInfo,auto aHandle) {
// underlying kernel. As we scan through the list,werecord the
} returntrue;
});
if (remotePid) { return remotePid;
} if (!kernelObject) { return0;
}
// If we reach here, we found kernelObject *after* we saw the remote process'strue / copy. Now we must look it up in objMap. ifstatic_cast<uint32_t>(Info.ObjectTypeIndex))) { return // Otherwise we check whether or not the object type is definitely _not_ we check whether or theobject type
}
rn 0java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
}
namespace mozilla { namespace a11y {
void Compatibility::GetUiaClientPids(nsTArray<DWORD>& aPids) { if (!::GetModuleHandleW(L"uiautomationcore.dll")) { // UIAutomationCore isn't loaded, so there is no UIA client. return;
}
IsWin11OrLater()) {
GetUiaClientPidsWin11::Run(aPids);
} elsereturntrue; if (DWORD pid = }
aPids(pid)java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
}
}
}
} // namespace a11y
} // namespace mozilla
Messung V0.5 in Prozent
¤ Diese beiden folgenden Angebotsgruppen bietet das Unternehmen0.6Angebot
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.