Conversation
Find the on-disk slice matching the loaded Mach-O CPU type and subtype before reading chained fixups. Account for fat32 and fat64 tables in either byte order, validate slice bounds, and keep runtime addresses relative to the loaded image. Add hook regressions for thin and universal libraries through all three open APIs, plus malformed-header and architecture-selection tests. Run the new regressions in the existing macOS CI job. Co-Authored-By: Codex <codex@openai.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
kubo/plthookis archived, so GitHub rejected creating this PR upstream. This draft keeps the tested patch reviewable in the fork for downstream MelonLoader integration; it has not been submitted or accepted upstream.Downstream integration: LavaGang/MelonLoader#1201.
When a loaded Mach-O image is part of a universal binary and uses
LC_DYLD_CHAINED_FIXUPS, plthook reads the fixup chain from the wrong file offset. A thin dylib that hooks successfully can fail withno such function: putsafter packaging the identical architecture into a universal dylib. This was encountered while loading a universal Unity player.This change locates the slice matching the loaded image's CPU type and subtype, then adds its file offset only when reading the chain from disk. Runtime addresses remain slice-relative. It handles fat32/fat64 architecture tables in either byte order and rejects truncated tables, missing architectures, and out-of-bounds slice/fixup reads. There are no public API changes or new pointer formats.
Validation on an Apple Silicon Mac:
plthook_open,plthook_open_by_handle, andplthook_open_by_address, on both x86_64 under Rosetta and native arm64.The regression is part of the existing Darwin
run_teststarget, so the current macOS CI steps execute it without workflow changes. It can also be run directly:The fixtures explicitly request chained fixups because older deployment/linker defaults otherwise hide this bug. No game assets are needed.