Skip to content

Commit be2c44c

Browse files
ChrisDentonrami3l
authored andcommitted
Windows: Load DLLs from system32
1 parent 745473d commit be2c44c

File tree

2 files changed

+61
-0
lines changed

2 files changed

+61
-0
lines changed

build.rs

+40
Original file line numberDiff line numberDiff line change
@@ -27,4 +27,44 @@ fn main() {
2727
}
2828
let target = env::var("TARGET").unwrap();
2929
println!("cargo:rustc-env=TARGET={target}");
30+
31+
// Set linker options specific to Windows MSVC.
32+
let target_os = env::var("CARGO_CFG_TARGET_OS");
33+
let target_env = env::var("CARGO_CFG_TARGET_ENV");
34+
if !(target_os.as_deref() == Ok("windows") && target_env.as_deref() == Ok("msvc")) {
35+
return;
36+
}
37+
38+
// # Only search system32 for DLLs
39+
//
40+
// This applies to DLLs loaded at load time. However, this setting is ignored
41+
// before Windows 10 RS1 (aka 1601).
42+
// https://learn.microsoft.com/en-us/cpp/build/reference/dependentloadflag?view=msvc-170
43+
println!("cargo:cargo:rustc-link-arg-bin=rustup-init=/DEPENDENTLOADFLAG:0x800");
44+
45+
// # Delay load
46+
//
47+
// Delay load dlls that are not "known DLLs"[1].
48+
// Known DLLs are always loaded from the system directory whereas other DLLs
49+
// are loaded from the application directory. By delay loading the latter
50+
// we can ensure they are instead loaded from the system directory.
51+
// [1]: https://learn.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order#factors-that-affect-searching
52+
//
53+
// This will work on all supported Windows versions but it relies on
54+
// us using `SetDefaultDllDirectories` before any libraries are loaded.
55+
// See also: src/bin/rustup-init.rs
56+
let delay_load_dlls = ["bcrypt", "powrprof", "secur32"];
57+
for dll in delay_load_dlls {
58+
println!("cargo:rustc-link-arg-bin=rustup-init=/delayload:{dll}.dll");
59+
}
60+
// When using delayload, it's necessary to also link delayimp.lib
61+
// https://learn.microsoft.com/en-us/cpp/build/reference/dependentloadflag?view=msvc-170
62+
println!("cargo:rustc-link-arg-bin=rustup-init=delayimp.lib");
63+
64+
// # Turn linker warnings into errors
65+
//
66+
// Rust hides linker warnings meaning mistakes may go unnoticed.
67+
// Turning them into errors forces them to be displayed (and the build to fail).
68+
// If we do want to ignore specific warnings then `/IGNORE:` should be used.
69+
println!("cargo:cargo:rustc-link-arg-bin=rustup-init=/WX");
3070
}

src/bin/rustup-init.rs

+21
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,9 @@ use rustup::is_proxyable_tools;
2929
use rustup::utils::utils;
3030

3131
fn main() {
32+
#[cfg(windows)]
33+
pre_rustup_main_init();
34+
3235
let process = OSProcess::default();
3336
with(process.into(), || match maybe_trace_rustup() {
3437
Err(e) => {
@@ -163,3 +166,21 @@ fn do_recursion_guard() -> Result<()> {
163166

164167
Ok(())
165168
}
169+
170+
/// Windows pre-main security mitigations.
171+
///
172+
/// This attempts to defend against malicious DLLs that may sit alongside
173+
/// rustup-init in the user's download folder.
174+
#[cfg(windows)]
175+
pub fn pre_rustup_main_init() {
176+
use winapi::um::libloaderapi::{SetDefaultDllDirectories, LOAD_LIBRARY_SEARCH_SYSTEM32};
177+
// Default to loading delay loaded DLLs from the system directory.
178+
// For DLLs loaded at load time, this relies on the `delayload` linker flag.
179+
// This is only necessary prior to Windows 10 RS1. See build.rs for details.
180+
unsafe {
181+
let result = SetDefaultDllDirectories(LOAD_LIBRARY_SEARCH_SYSTEM32);
182+
// SetDefaultDllDirectories should never fail if given valid arguments.
183+
// But just to be safe and to catch mistakes, assert that it succeeded.
184+
assert_ne!(result, 0);
185+
}
186+
}

0 commit comments

Comments
 (0)