Files
time-mocker/crates
tiennm99 10f73fc32c refactor: harden IPC, hook install, and injection safety
Workspace-wide refactor that fixes correctness, safety, and concurrency
issues across the three crates while preserving the public CLI/UX surface.

core:
- Split SharedDelta into SharedDeltaReader / SharedDeltaWriter so the
  access-mode (FILE_MAP_READ vs ALL_ACCESS) is encoded in the type.
- Use AtomicI64::from_ptr on the page-aligned mapped view instead of a
  raw *mut AtomicI64 cast.
- Detect ERROR_ALREADY_EXISTS via CreateOutcome and surface it.
- Move MMF name to the Global\ namespace so cross-session injection is
  no longer silently scoped to the controller's session.
- Add tick-math round-trip tests (i64 + SYSTEMTIME boundary cases).

hook:
- install_hook! macro collapses the five hook installs to a table;
  per-hook failures are collected into InstallReport instead of
  aborting mid-chain and leaving a partial state armed.
- Unify fake_filetime helpers behind a single trampoline-parameterised fn.
- Fix GetLocalTime: previously returned UTC; now goes
  FILETIME(UTC) -> SYSTEMTIME -> SystemTimeToTzSpecificLocalTime so DST
  is resolved against the source date, matching real GetLocalTime.
- Replace thread::spawn from DllMain with raw CreateThread and
  DisableThreadLibraryCalls(hinst) to avoid loader-lock deadlocks;
  close the returned thread handle to plug a per-injection kernel leak.
- Propagate the real NtQuerySystemTime NTSTATUS instead of always
  returning STATUS_SUCCESS.
- Return STATUS_ACCESS_VIOLATION on null out-pointer.
- Pipe InstallReport + MMF-open failures to OutputDebugStringW for
  DbgView visibility in the target process.

ui:
- New win32_process_info module: pe_machine reads up to 64 KiB so PEs
  with large e_lfanew values parse cleanly; query_full_image_name and
  is_native_x64 (IsWow64Process2) gate inject against PID reuse and
  WoW64 / non-AMD64 targets.
- Drop for InjectionManager zeroes every injected process's delta so
  targets return to real time on UI exit.
- inject() reorders checks so the system-process guard runs against the
  filename derived from the live image path, not the stale watcher
  snapshot; failures are pushed to the ring-buffer log so auto-inject
  loops are no longer silent.
- Refuse to inject critical Windows processes (csrss, smss, lsass,
  services, svchost, MsMpEng, ...) explicitly.
- Switch the log from unbounded Vec to a VecDeque ring buffer (cap 1000).
- Rename eject -> disable to match what it actually does (zero delta,
  keep DLL loaded).
- Unicode-aware paths_equivalent via to_lowercase comparison so non-ASCII
  case differences don't yield false-positive PID-reuse errors.
- app.rs date/time picker: switch to DragValue so mid-typing keystrokes
  don't rewrite the date; clamp year 1970-2200; checked arithmetic on
  unix_micros -> FILETIME so far-future inputs don't silently overflow;
  surface DST-gap status to the user; "Now" auto-applies.
- Add 51 unit tests across mmf, PE parser, system-process guards, time
  math; expose helpers via pub(crate) for test access.
- Drop unused serde_json and thiserror deps.

Total: 56/56 tests passing, cargo clippy clean, cargo build --release
produces time_mocker_ui.exe and time_mocker_hook.dll.
2026-05-20 17:08:43 +07:00
..