Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

windows/security: explicit LOAD_LIBRARY_SEARCH_SYSTEM32 for system32 dll

未关闭
#1,717 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
65/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
java

调研方向

首先定位 W32APIOptions 以及加载 system32 DLL 的接口,然后检查当前如何使用 OPTION_OPEN_FLAGS 和 LOAD_WITH_ALTERED_SEARCH_PATH。在 Windows 上复现通过相对路径加载的情况,并验证 system32 DLL 能够使用 LOAD_LIBRARY_SEARCH_SYSTEM32 加载,同时不会破坏其他原生接口。

由索引模型根据 Issue 内容生成。

描述

We recently stumpled upon dll loading issues of wtsapi32.dll with prior modification of dll search path via SetDefaultDllDirectories resulting exact same issue as in https://github.com/java-native-access/jna/pull/1614

calling LoadLibraryEx(relative_path, ..., LOAD_WITH_ALTERED_SEARCH_PATH) results in ERROR_INVALID_PARAMETER.

According to LoadLibraryEx documentation, this results in an undefined behavior when a library name is given as a relative path.
With that in mind, it would be best practise to secure system32 dll loading by using OPTION_OPEN_FLAGS set to LOAD_LIBRARY_SEARCH_SYSTEM32 for those interfaces against system32 dlls.

Map<String, Object> DEFAULT_W32SYSTEM32APIOptions = new HashMap<String, Object>(W32APIOptions.DEFAULT_OPTIONS) {{ //LOAD_LIBRARY_SEARCH_SYSTEM32 put(com.sun.jna.Library.OPTION_OPEN_FLAGS, 0x00000800); }};
Once we switched to LOAD_LIBRARY_SEARCH_SYSTEM32 all system32 dlls in use were properly found/loaded.

主要语言
Java
星标
8.9k
派生
1.7k
PR 合并指标
30 天内没有已合并 PR

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

java-native-access/jna 的其他 Issue

查看 java-native-access/jna 的全部 Issue

相似的 Issue

更多 Java Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。