inject_linux_amd64.go 39 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171
  1. package inject
  2. /*
  3. #cgo CFLAGS: -I include
  4. #cgo amd64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_amd64.a
  5. #cgo arm64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_arm64.a
  6. #include "hotpatch.h"
  7. #include <stdlib.h>
  8. */
  9. import "C"
  10. import (
  11. "bufio"
  12. "debug/elf"
  13. "fmt"
  14. "github.com/coroot/coroot-node-agent/utils"
  15. klog "github.com/sirupsen/logrus"
  16. "golang.org/x/arch/x86/x86asm"
  17. "os"
  18. "path/filepath"
  19. "strings"
  20. "syscall"
  21. "unsafe"
  22. )
  23. const (
  24. IO_FD_FDID_SYM_OFFSET = 129
  25. NET_SEND_SYM_OFFSET = 518
  26. // 备份指令长度
  27. ORIGIN_CODE_LEN = 12
  28. )
  29. type InstInfo struct {
  30. SymName string
  31. SymSize uint64
  32. SymAddr uint64
  33. PC uint64
  34. Inst x86asm.Inst
  35. OriginInst x86asm.Inst
  36. OriginCode []byte
  37. TargetAddr uint64
  38. OriginTargetAddr uint64
  39. }
  40. type InnerSymbolInfo struct {
  41. IO_fd_fdID InstInfo
  42. NET_Send InstInfo
  43. }
  44. func (j *JvmInjector) findReleaseAddressInfoFromMem() error {
  45. klog.Infof("findReleaseAddressInfoFromMem start.")
  46. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  47. releaseFuncSym := InnerSymbolInfo{}
  48. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  49. if err != nil {
  50. return err
  51. }
  52. pc := uint64(0)
  53. callCount := 0
  54. preContext := InstInfo{}
  55. for pc < uint64(len(code)) {
  56. inst, err := x86asm.Decode(code[pc:], 64)
  57. if err != nil {
  58. klog.Errorf("Decode error at offset 0x%x: %v\n", pc, err)
  59. pc++ // Skip this byte and try to decode again
  60. continue
  61. }
  62. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  63. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  64. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  65. currentData := InstInfo{
  66. PC: pc,
  67. SymAddr: funcAbsAddress + pc,
  68. Inst: inst,
  69. //IntelInst: x86asm.IntelSyntax(inst, 0, nil),
  70. }
  71. if pc == 10 && inst.Op == x86asm.JMP {
  72. // 已经被修改过的首指令
  73. j.PreCheck.EbpfCanInjection = true
  74. j.Uprobe.ELFPath = j.DebugLibNetInfo.LibPath
  75. if j.DebugLibNetInfo.FileDeleted {
  76. j.Uprobe.ELFPath = j.DebugLibNetInfo.MapFile
  77. }
  78. klog.Infof("[inject] Inst already modified. <%s>;elf:%s", x86asm.IntelSyntax(inst, 0, nil), j.Uprobe.ELFPath)
  79. return nil
  80. }
  81. if pc == 0 {
  82. j.ReleaseLibNetInfo.FuncSymbol.PC = currentData.PC
  83. j.ReleaseLibNetInfo.FuncSymbol.Inst = currentData.Inst
  84. j.ReleaseLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  85. }
  86. if inst.Op == x86asm.MOV {
  87. if dst, okDst := inst.Args[0].(x86asm.Mem); okDst {
  88. if dst.Base == x86asm.RBP {
  89. if src, okSrc := inst.Args[1].(x86asm.Reg); okSrc {
  90. if src == x86asm.R9L {
  91. // debug so
  92. klog.Infof("[inject] release.so is debug.so. <%s>", x86asm.IntelSyntax(inst, 0, nil))
  93. j.PreCheck.EbpfCanInjection = true
  94. j.Uprobe.ELFPath = j.ReleaseLibNetInfo.LibPath
  95. if j.ReleaseLibNetInfo.FileDeleted {
  96. j.Uprobe.ELFPath = j.ReleaseLibNetInfo.MapFile
  97. }
  98. return fmt.Errorf("MOV from register %v to memory %v\n", src, dst)
  99. //return nil
  100. }
  101. }
  102. }
  103. }
  104. //src, okSrc := inst.Args[1].(x86asm.Reg)
  105. //fmt.Println(inst.Args)
  106. //fmt.Printf("Instruction: %+v\n", inst)
  107. //
  108. //fmt.Println(okSrc)
  109. //if okDst && okSrc && dst == x86asm.RBP && src == x86asm.R9L {
  110. // fmt.Println("Instruction is 'mov %r9d, %rbp'")
  111. //}
  112. }
  113. if inst.Op == x86asm.CALL {
  114. //fmt.Printf("Pre instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  115. if callCount == 0 {
  116. releaseFuncSym.IO_fd_fdID = preContext
  117. releaseFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Release)"
  118. preInst := preContext.Inst
  119. klog.Infof("[findReleaseAddressInfoFromMem] preInst %v\n]", preInst)
  120. // 计算目标地址
  121. if preInst.Op == x86asm.MOV &&
  122. len(preInst.Args) == 4 &&
  123. preInst.Args[0] != nil &&
  124. preInst.Args[0] == x86asm.RDX &&
  125. preInst.Args[1] != nil {
  126. if mem, ok := preInst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  127. relOffset := mem.Disp // 直接从Mem结构体中读取偏移
  128. targetAddress := preContext.SymAddr + uint64(preInst.Len) + uint64(relOffset)
  129. klog.Infof("[findReleaseAddressInfoFromMem] target address 0x%x\n", targetAddress)
  130. releaseFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  131. } else {
  132. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  133. }
  134. } else {
  135. return fmt.Errorf("[findReleaseAddressInfoFromMem] The decoded instruction is not a MOV to RDX.")
  136. }
  137. }
  138. callCount++
  139. if callCount == 4 {
  140. releaseFuncSym.NET_Send = currentData
  141. klog.Infof("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  142. relOffset, ok := inst.Args[0].(x86asm.Rel)
  143. if !ok {
  144. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  145. }
  146. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  147. releaseFuncSym.NET_Send.TargetAddr = targetAddress
  148. klog.Infof("[findReleaseAddressInfoFromMem] target address 0x%x\n", releaseFuncSym.NET_Send)
  149. releaseFuncSym.NET_Send.SymName = "<NET_Send>(Release)"
  150. klog.Infof("[findReleaseAddressInfoFromMem] target address 0x%x\n", targetAddress)
  151. }
  152. }
  153. preContext = InstInfo{
  154. PC: pc,
  155. SymAddr: funcAbsAddress + pc,
  156. Inst: inst,
  157. }
  158. pc += uint64(inst.Len)
  159. }
  160. j.ReleaseLibNetInfo.InnerSymbol = releaseFuncSym
  161. j.ReleaseLibNetInfo.FuncSymbol.OriginCode = code[0:ORIGIN_CODE_LEN]
  162. return nil
  163. }
  164. func (j *JvmInjector) findDebugAddressInfoFromMem() (uint64, error) {
  165. klog.Infof("[findDebugAddressInfoFromMem] Looking for debug address info from Mem")
  166. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  167. debugFuncSym := InnerSymbolInfo{}
  168. //debugFuncSym.FuncSymbol.SymAddr = funcAbsAddress
  169. //offset := sym.Value
  170. size := j.DebugLibNetInfo.FuncSymbol.SymSize
  171. code, err := j.readMemory(funcAbsAddress, size)
  172. //fmt.Println(code, err)
  173. if err != nil {
  174. return 0, err
  175. }
  176. pc := uint64(0)
  177. preContext := InstInfo{}
  178. for pc < uint64(len(code)) {
  179. inst, err := x86asm.Decode(code[pc:], 64)
  180. if err != nil {
  181. klog.Errorf("Decode error at offset 0x%x: %v\n", pc, err)
  182. pc++ // Skip this byte and try to decode again
  183. continue
  184. }
  185. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  186. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  187. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  188. currentData := InstInfo{
  189. PC: pc,
  190. SymAddr: funcAbsAddress + pc,
  191. Inst: inst,
  192. }
  193. if pc == 0 {
  194. j.DebugLibNetInfo.FuncSymbol.PC = currentData.PC
  195. j.DebugLibNetInfo.FuncSymbol.Inst = currentData.Inst
  196. j.DebugLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  197. }
  198. if pc == IO_FD_FDID_SYM_OFFSET {
  199. klog.Infof("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  200. debugFuncSym.IO_fd_fdID = currentData
  201. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  202. // 计算目标地址
  203. if currentData.Inst.Op == x86asm.MOV &&
  204. len(currentData.Inst.Args) == 4 &&
  205. currentData.Inst.Args[0] != nil &&
  206. currentData.Inst.Args[0] == x86asm.RDX &&
  207. currentData.Inst.Args[1] != nil {
  208. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  209. // 直接从Mem结构体中读取偏移
  210. relOffset := mem.Disp
  211. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  212. klog.Infof("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  213. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  214. // 保存原始数据
  215. debugFuncSym.IO_fd_fdID.OriginTargetAddr = targetAddress
  216. debugFuncSym.IO_fd_fdID.OriginInst = currentData.Inst
  217. j.PreCheck.IoFdCheck = true
  218. } else {
  219. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  220. }
  221. } else {
  222. return 0, fmt.Errorf("[findDebugAddressInfoFromMem] The decoded instruction is not a MOV to RDX.")
  223. }
  224. }
  225. if pc == NET_SEND_SYM_OFFSET {
  226. debugFuncSym.NET_Send = currentData
  227. klog.Infof("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  228. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  229. if !ok {
  230. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  231. }
  232. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  233. debugFuncSym.NET_Send.TargetAddr = targetAddress
  234. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  235. klog.Infof("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  236. // 保存原始数据
  237. debugFuncSym.NET_Send.OriginTargetAddr = targetAddress
  238. debugFuncSym.NET_Send.OriginInst = currentData.Inst
  239. j.PreCheck.NetSendFuncCheck = true
  240. }
  241. preContext = InstInfo{
  242. PC: pc,
  243. SymAddr: funcAbsAddress + pc,
  244. Inst: inst,
  245. }
  246. pc += uint64(inst.Len)
  247. }
  248. j.DebugLibNetInfo.InnerSymbol = debugFuncSym
  249. return 0, nil
  250. }
  251. func (j *JvmInjector) checkDebugFuncSymAfterChange() (uint64, error) {
  252. klog.Infof("Checking debug function symbol after injection")
  253. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  254. debugFuncSym := InnerSymbolInfo{}
  255. code, err := j.readMemory(funcAbsAddress, j.DebugLibNetInfo.FuncSymbol.SymSize)
  256. if err != nil {
  257. return 0, err
  258. }
  259. pc := uint64(0)
  260. preContext := InstInfo{}
  261. for pc < uint64(len(code)) {
  262. inst, err := x86asm.Decode(code[pc:], 64)
  263. if err != nil {
  264. klog.Infof("Decode error at offset 0x%x: %v\n", pc, err)
  265. pc++ // Skip this byte and try to decode again
  266. continue
  267. }
  268. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  269. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  270. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  271. currentData := InstInfo{
  272. PC: pc,
  273. SymAddr: funcAbsAddress + pc,
  274. Inst: inst,
  275. }
  276. if pc == NET_SEND_SYM_OFFSET {
  277. klog.Infof("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  278. debugFuncSym.IO_fd_fdID = currentData
  279. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  280. // 计算目标地址
  281. if currentData.Inst.Op == x86asm.MOV &&
  282. len(currentData.Inst.Args) == 4 &&
  283. currentData.Inst.Args[0] != nil &&
  284. currentData.Inst.Args[0] == x86asm.RDX &&
  285. currentData.Inst.Args[1] != nil {
  286. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  287. // 直接从Mem结构体中读取偏移
  288. relOffset := mem.Disp
  289. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  290. klog.Infof("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  291. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  292. //j.PreCheck.IoFdCheck = true
  293. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr {
  294. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr = targetAddress
  295. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.Inst = currentData.Inst
  296. j.AfterCheck.IoFdCheck = true
  297. klog.Infoln("ok")
  298. }
  299. } else {
  300. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  301. }
  302. } else {
  303. return 0, fmt.Errorf("[checkDebugFuncSymAfterChange] The decoded instruction is not a MOV to RDX.")
  304. }
  305. }
  306. if pc == NET_SEND_SYM_OFFSET {
  307. debugFuncSym.NET_Send = currentData
  308. //fmt.Println(currentData.IntelInst)
  309. //klog.Infof("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  310. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  311. if !ok {
  312. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  313. }
  314. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  315. debugFuncSym.NET_Send.TargetAddr = targetAddress
  316. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  317. klog.Infof("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  318. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr {
  319. j.DebugLibNetInfo.InnerSymbol.NET_Send.TargetAddr = targetAddress
  320. j.DebugLibNetInfo.InnerSymbol.NET_Send.Inst = currentData.Inst
  321. j.AfterCheck.NetSendFuncCheck = true
  322. }
  323. }
  324. preContext = InstInfo{
  325. PC: pc,
  326. SymAddr: funcAbsAddress + pc,
  327. Inst: inst,
  328. }
  329. pc += uint64(inst.Len)
  330. }
  331. return 0, nil
  332. }
  333. func (j *JvmInjector) checkReleaseFuncSymAfterChange() error {
  334. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  335. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  336. if err != nil {
  337. return fmt.Errorf("readMemory error in checkReleaseFuncSymAfterChange <%v>", err)
  338. }
  339. // 原函数内容注释掉
  340. // inst, err := x86asm.Decode(code[0:], 64)
  341. // if err != nil {
  342. // return fmt.Errorf("Decode error in checkReleaseFuncSymAfterChange <%v>", err)
  343. // }
  344. // if inst.Op != x86asm.JMP {
  345. // return fmt.Errorf("The instruction does not JMP.")
  346. // }
  347. // relOffset, ok := inst.Args[0].(x86asm.Rel)
  348. // if !ok {
  349. // return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  350. // }
  351. // // 验证target与Debug入口是否一致
  352. // targetAddress := funcAbsAddress + uint64(inst.Len) + uint64(relOffset)
  353. // if targetAddress != j.DebugLibNetInfo.FuncSymbol.SymAddr {
  354. // return fmt.Errorf("Function entry jmp address does not match expectations.")
  355. // }
  356. // 新的验证逻辑:验证指令序列:movabs $imm64,%rax 和 jmp *%rax
  357. if len(code) < 13 { // movabs(10字节) + jmp(3字节) = 13字节
  358. return fmt.Errorf("Instruction sequence too short, expected at least 13 bytes, got %d", len(code))
  359. }
  360. // 验证第一个指令:movabs $imm64,%rax
  361. // movabs 指令格式:48 B8 + 8字节立即数 (RAX寄存器)
  362. // 48 B8 = movabs rax, imm64
  363. if code[0] != 0x48 || code[1] != 0xB8 {
  364. return fmt.Errorf("First instruction is not movabs rax, imm64. Got: 0x%02x 0x%02x", code[0], code[1])
  365. }
  366. // 提取立即数值 (小端序)
  367. imm64 := uint64(code[2]) | uint64(code[3])<<8 | uint64(code[4])<<16 | uint64(code[5])<<24 |
  368. uint64(code[6])<<32 | uint64(code[7])<<40 | uint64(code[8])<<48 | uint64(code[9])<<56
  369. // 验证立即数是否与 Debug 函数地址一致
  370. expectedAddr := j.DebugLibNetInfo.FuncSymbol.SymAddr
  371. if imm64 != expectedAddr {
  372. return fmt.Errorf("movabs immediate value mismatch. Expected: 0x%x (Debug function addr), Got: 0x%x", expectedAddr, imm64)
  373. }
  374. // 验证第二个指令:jmp *%rax
  375. // jmp *%rax 指令格式:FF E0
  376. if code[10] != 0xFF || code[11] != 0xE0 {
  377. return fmt.Errorf("Second instruction is not jmp *%%rax. Got: 0x%02x 0x%02x", code[10], code[11])
  378. }
  379. klog.Infof("[checkReleaseFuncSymAfterChange] Successfully verified instruction sequence: movabs $0x%x,%%rax; jmp *%%rax", imm64)
  380. return nil
  381. }
  382. // readMemory 用于读取指定地址的内存数据
  383. func (j *JvmInjector) readMemory(address uint64, size uint64) ([]byte, error) {
  384. memFile := fmt.Sprintf("/proc/%d/mem", j.Pid)
  385. file, err := os.Open(memFile)
  386. if err != nil {
  387. return nil, err
  388. }
  389. defer file.Close()
  390. data := make([]byte, size)
  391. _, err = file.ReadAt(data, int64(address))
  392. if err != nil {
  393. return nil, err
  394. }
  395. return data, nil
  396. }
  397. // findLibraryBases 用于在 /proc/[pid]/maps 文件中查找库的所有基地址
  398. func findLibraryBasesList(pid int, libraryName string, libPath string) ([]uint64, error) {
  399. mapsFile := fmt.Sprintf("/proc/%d/maps", pid)
  400. file, err := os.Open(mapsFile)
  401. if err != nil {
  402. return nil, err
  403. }
  404. defer file.Close()
  405. var bases []uint64
  406. scanner := bufio.NewScanner(file)
  407. for scanner.Scan() {
  408. line := scanner.Text()
  409. if strings.Contains(line, libraryName) && strings.Contains(line, libPath) {
  410. var start, end uint64
  411. fmt.Sscanf(line, "%x-%x", &start, &end)
  412. bases = append(bases, start)
  413. }
  414. }
  415. if len(bases) == 0 {
  416. return nil, fmt.Errorf("library %s not found", libraryName)
  417. }
  418. return bases, nil
  419. }
  420. func (j *JvmInjector) findLibBaseFromProcMaps(pid int, libName string) (uint64, string, string, bool, error) {
  421. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  422. file, err := os.Open(mapsFile)
  423. if err != nil {
  424. return 0, "", "", false, err
  425. }
  426. defer file.Close()
  427. var start, end uint64
  428. var deleted bool
  429. scanner := bufio.NewScanner(file)
  430. for scanner.Scan() {
  431. line := scanner.Text()
  432. if strings.Contains(line, "/"+libName) {
  433. fmt.Sscanf(line, "%x-%x", &start, &end)
  434. fields := strings.Fields(line)
  435. if len(fields) > 5 {
  436. path := fields[5]
  437. if len(fields) > 6 && fields[6] == "(deleted)" {
  438. deleted = true
  439. }
  440. if strings.HasSuffix(path, ".so") {
  441. klog.Infof("[inject] found library in map %s", path)
  442. return start, path, fmt.Sprintf("/proc/%d/map_files/%s", j.Pid, fields[0]), deleted, nil
  443. }
  444. }
  445. }
  446. }
  447. return 1, "", "", false, fmt.Errorf("library %s not found", libName)
  448. }
  449. func (j *JvmInjector) findLibBaseByPathFromProcMaps(libPath string) (uint64, string, error) {
  450. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  451. file, err := os.Open(mapsFile)
  452. if err != nil {
  453. return 0, "", err
  454. }
  455. defer file.Close()
  456. var start, end uint64
  457. scanner := bufio.NewScanner(file)
  458. for scanner.Scan() {
  459. line := scanner.Text()
  460. if strings.Contains(line, libPath) {
  461. fmt.Sscanf(line, "%x-%x", &start, &end)
  462. fields := strings.Fields(line)
  463. if len(fields) > 5 {
  464. path := fields[5]
  465. if strings.HasSuffix(path, ".so") {
  466. return start, path, nil
  467. }
  468. }
  469. }
  470. }
  471. return 1, "", fmt.Errorf("library %s not found in process.", libPath)
  472. }
  473. func (j *JvmInjector) getFunctionOffset(libPath, functionName string) (elf.Symbol, error) {
  474. elfFile, err := elf.Open(libPath)
  475. if err != nil {
  476. return elf.Symbol{}, fmt.Errorf("failed to open ELF file: %v", err)
  477. }
  478. defer elfFile.Close()
  479. symbols, err := elfFile.DynamicSymbols()
  480. if err != nil {
  481. return elf.Symbol{}, fmt.Errorf("failed to read dynamic symbols: %v", err)
  482. }
  483. for _, sym := range symbols {
  484. if sym.Name == functionName {
  485. //fmt.Println("size:", sym.Size)
  486. return sym, nil
  487. }
  488. }
  489. //textSection := elfFile.Section(".text")
  490. //if textSection == nil {
  491. // fmt.Println("textSection is null")
  492. // //return nil
  493. //}
  494. //textSectionData, err := textSection.Data()
  495. //if err != nil {
  496. // fmt.Println("textSectionData error is", err)
  497. // //return nil
  498. //}
  499. //textSectionLen := uint64(len(textSectionData) - 1)
  500. return elf.Symbol{}, fmt.Errorf("function %s not found", functionName)
  501. }
  502. //var PID string
  503. func (j *JvmInjector) InitProg() error {
  504. // 获取release库的基地址
  505. baseAddress, releaseSoFilePathInProc, mapFilesPath, deleted, err := FindLibBaseFromProcMaps(j.Pid, j.ReleaseLibNetInfo.LibName)
  506. //j.ReleaseLibNetInfo.LibPath = releaseSoFilePathInProc
  507. j.ReleaseLibNetInfo.FileDeleted = deleted
  508. j.ReleaseLibNetInfo.MapFile = mapFilesPath
  509. pJvmlibnetPhysicalPath := j.Rootfs + releaseSoFilePathInProc
  510. j.ReleaseLibNetInfo.LibPath = pJvmlibnetPhysicalPath
  511. if err != nil {
  512. return fmt.Errorf("Error finding base addresses: %v", err)
  513. }
  514. // jvm prog base
  515. //pJvmLibBaseDir := filepath.Dir(pJvmlibnetPhysicalPath)
  516. jvmLibBaseDir := filepath.Dir(releaseSoFilePathInProc)
  517. // proc maps load path
  518. debugSoFilePathInProc := filepath.Join(jvmLibBaseDir, j.DebugLibNetInfo.LibName)
  519. // Physical path
  520. debugSoFilePhysicalPath := filepath.Join(j.Rootfs, debugSoFilePathInProc)
  521. _, noFileErr := os.Stat(debugSoFilePhysicalPath)
  522. // find cwlibnet.so in proc maps
  523. var readDebugSoPathInMaps string
  524. _, readDebugSoPathInMaps, j.DebugLibNetInfo.MapFile, j.DebugLibNetInfo.FileDeleted, _ = FindLibBaseFromProcMaps(j.Pid, j.DebugLibNetInfo.LibName)
  525. j.DebugLibNetInfo.LibPath = debugSoFilePhysicalPath
  526. j.DebugLibNetInfo.ProcLoadPath = filepath.Join(jvmLibBaseDir, j.DebugLibNetInfo.LibName)
  527. // condition create
  528. pathFromProg := utils.GetDefaultLibsPath("jvm", j.DebugLibNetInfo.LibName)
  529. if noFileErr != nil && readDebugSoPathInMaps == "" && !j.DebugLibNetInfo.FileDeleted {
  530. err = CopyFileAndMatchPermissions(pathFromProg, debugSoFilePhysicalPath, pJvmlibnetPhysicalPath)
  531. klog.Infof("[src:%s],[target:%s],[perm:%s]", pathFromProg, debugSoFilePhysicalPath, pJvmlibnetPhysicalPath)
  532. if err != nil {
  533. return err
  534. }
  535. }
  536. functionName := j.ReleaseLibNetInfo.FuncSymbol.SymName
  537. //j.ReleaseLibNetInfo.LibPath = pJvmlibnetPhysicalPath
  538. klog.Infof("[inject] Base address of [%s]:[%x]", j.ReleaseLibNetInfo.LibName, baseAddress)
  539. // 获取函数的偏移量
  540. functionSym, err := GetFunctionOffset(pJvmlibnetPhysicalPath, functionName)
  541. // 计算函数的实际内存地址
  542. j.ReleaseLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  543. j.ReleaseLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  544. if err != nil {
  545. klog.WithError(err).Errorf("Error getting function offset")
  546. return err
  547. }
  548. klog.Infof("[inject] Actual memory address of %s at base 0x%x: 0x%x", functionName, baseAddress, j.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  549. if j.Uprobe.ELFPath == "" {
  550. if j.DebugLibNetInfo.FileDeleted {
  551. j.Uprobe.ELFPath = j.DebugLibNetInfo.MapFile
  552. } else {
  553. j.Uprobe.ELFPath = debugSoFilePhysicalPath
  554. }
  555. }
  556. err = j.findReleaseAddressInfoFromMem()
  557. if err != nil {
  558. return err
  559. } else {
  560. j.PreCheck.NeedInjectionCheck = true
  561. }
  562. return nil
  563. }
  564. func (j *JvmInjector) findDebugFuncContextFromLibPath() error {
  565. //libName := j.DebugLibNetInfo.LibPath
  566. // 获取release库的基地址
  567. baseAddress, libPath, err := FindLibBaseByPathFromProcMaps(j.Pid, j.DebugLibNetInfo.ProcLoadPath)
  568. klog.Infof("[inject] debug base address of [%s] : %x", libPath, baseAddress)
  569. functionName := j.DebugLibNetInfo.FuncSymbol.SymName
  570. //j.DebugLibNetInfo.LibPath = libPath
  571. if err != nil {
  572. klog.WithError(err).Errorf("[inject] error.")
  573. return err
  574. }
  575. // 获取函数的偏移量
  576. functionSym, err := GetFunctionOffset(j.DebugLibNetInfo.LibPath, functionName)
  577. // 计算函数的实际内存地址
  578. j.DebugLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  579. j.DebugLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  580. if err != nil {
  581. return fmt.Errorf("Error getting function offset: %v", err)
  582. }
  583. functionConvert0Sym, err := GetFunctionOffset(j.DebugLibNetInfo.LibPath, j.DebugLibNetInfo.FuncConvert0Symbol.SymName)
  584. // 计算函数的实际内存地址
  585. j.DebugLibNetInfo.FuncConvert0Symbol.SymAddr = baseAddress + functionConvert0Sym.Value
  586. j.DebugLibNetInfo.FuncConvert0Symbol.SymSize = functionConvert0Sym.Size
  587. if err != nil {
  588. return fmt.Errorf("Error getting function offset: %v", err)
  589. }
  590. functionGetTTLSym, err := GetFunctionOffset(j.DebugLibNetInfo.LibPath, j.DebugLibNetInfo.FuncGetTTLSymbol.SymName)
  591. // 计算函数的实际内存地址
  592. j.DebugLibNetInfo.FuncGetTTLSymbol.SymAddr = baseAddress + functionGetTTLSym.Value
  593. j.DebugLibNetInfo.FuncGetTTLSymbol.SymSize = functionGetTTLSym.Size
  594. if err != nil {
  595. return fmt.Errorf("Error getting function offset: %v", err)
  596. }
  597. _, err = j.findDebugAddressInfoFromMem()
  598. if err != nil {
  599. return fmt.Errorf("Error finding first CALL instuction: %v", err)
  600. }
  601. klog.Infof("First CALL instuction o1f %s at base 0x%x\n", functionName, baseAddress)
  602. return nil
  603. }
  604. func printCodeData(data LibNetInfo) {
  605. klog.Infof("========FuncEnter <0x%x> \n", data.FuncSymbol.SymAddr)
  606. klog.Infof("Name %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x> \nOrigin-Inst:<%s> | Inst:<%s> \n",
  607. data.InnerSymbol.IO_fd_fdID.SymName,
  608. data.InnerSymbol.IO_fd_fdID.SymAddr,
  609. data.InnerSymbol.IO_fd_fdID.OriginTargetAddr,
  610. data.InnerSymbol.IO_fd_fdID.TargetAddr,
  611. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.OriginInst, 0, nil),
  612. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.Inst, 0, nil))
  613. klog.Infof("\nName %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x>\nOrigin-Inst:<%s> | Inst:<%s> \n",
  614. data.InnerSymbol.NET_Send.SymName,
  615. data.InnerSymbol.NET_Send.SymAddr,
  616. data.InnerSymbol.NET_Send.OriginTargetAddr,
  617. data.InnerSymbol.NET_Send.TargetAddr,
  618. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.OriginInst, 0, nil),
  619. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.Inst, 0, nil))
  620. klog.Infoln("========")
  621. }
  622. func (j *JvmInjector) jvmInjectLib() int {
  623. dll := C.CString(j.DebugLibNetInfo.ProcLoadPath)
  624. rootfs := C.CString(j.Rootfs)
  625. defer C.free(unsafe.Pointer(dll))
  626. result := C.cw_inject_library(C.int(j.Pid), C.int(1), dll, rootfs)
  627. klog.Infof("Result: %d\n", result)
  628. return int(result)
  629. }
  630. func (j *JvmInjector) validateAllPreCheck() bool {
  631. return j.PreCheck.NeedInjectionCheck && j.PreCheck.LoadingCheck && j.PreCheck.IoFdCheck && j.PreCheck.NetSendFuncCheck
  632. }
  633. func (j *JvmInjector) validateAllModifyCheck() bool {
  634. return j.AfterCheck.IoFdCheck && j.AfterCheck.NetSendFuncCheck
  635. }
  636. /*修改部分*/
  637. func readData(pid int, addr uintptr) (uint64, error) {
  638. var data uint64
  639. if _, err := syscall.PtracePeekData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  640. return 0, fmt.Errorf("ptrace PEEKDATA: %v", err)
  641. }
  642. return data, nil
  643. }
  644. func writeData(pid int, addr uintptr, data uint64) error {
  645. if _, err := syscall.PtracePokeData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  646. return fmt.Errorf("ptrace POKEDATA: %v", err)
  647. }
  648. return nil
  649. }
  650. func readDataBytes(pid int, addr uintptr, size int) ([]byte, error) {
  651. data := make([]byte, size)
  652. if _, err := syscall.PtracePeekData(pid, addr, data); err != nil {
  653. return nil, fmt.Errorf("ptrace PEEKDATA: %v", err)
  654. }
  655. return data, nil
  656. }
  657. func writeDataBytes(pid int, addr uintptr, data []byte) error {
  658. if _, err := syscall.PtracePokeData(pid, addr, data); err != nil {
  659. return fmt.Errorf("ptrace POKEDATA: %v", err)
  660. }
  661. return nil
  662. }
  663. func modifyIoFdTargetAddr(pid int, insertAddr, distAddr, getTTLFunctionAddr uintptr) error {
  664. // newOffset := distAddr - (insertAddr + 7)
  665. // targetAddr := insertAddr + 3
  666. // // 获取目标地址处的数据
  667. // originalData, err := readData(pid, targetAddr)
  668. // if err != nil {
  669. // return err
  670. // }
  671. // // 更新数据中的目标偏移
  672. // updatedData := (originalData & 0xFFFFFFFF00000000) | uint64(newOffset&0xFFFFFFFF)
  673. // err = writeData(pid, targetAddr, updatedData)
  674. // if err != nil {
  675. // return err
  676. // }
  677. getTTLOffset := getTTLFunctionAddr - insertAddr - 5
  678. // 读取原始数据
  679. // alignedAddr := insertAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  680. originalData, err := readDataBytes(pid, insertAddr, 7)
  681. if err != nil {
  682. return err
  683. }
  684. // offset := insertAddr % uintptr(unsafe.Sizeof(uintptr(0)))
  685. offset := 0
  686. // 写入AMD64的绝对跳转指令: mov rax, addr; jmp rax
  687. var getTTLOffset32 uint32 = uint32(getTTLOffset)
  688. originalData[offset] = 0xE8 // call
  689. originalData[offset+1] = byte(getTTLOffset32)
  690. originalData[offset+2] = byte(getTTLOffset32 >> 8)
  691. originalData[offset+3] = byte(getTTLOffset32 >> 16)
  692. originalData[offset+4] = byte(getTTLOffset32 >> 24)
  693. originalData[offset+5] = 0x90 //nop
  694. originalData[offset+6] = 0x90 //nop
  695. err = writeDataBytes(pid, insertAddr, originalData)
  696. if err != nil {
  697. return err
  698. }
  699. //以上是先跳转到2GB内存的无用函数中
  700. //以下来写真正的跳转函数
  701. TTLOriginalData, err := readDataBytes(pid, getTTLFunctionAddr, 16)
  702. if err != nil {
  703. return err
  704. }
  705. TTLOriginalData[offset] = 0x50
  706. TTLOriginalData[offset+1] = 0x48
  707. TTLOriginalData[offset+2] = 0xb8
  708. TTLOriginalData[offset+3] = byte(distAddr)
  709. TTLOriginalData[offset+4] = byte(distAddr >> 8)
  710. TTLOriginalData[offset+5] = byte(distAddr >> 16)
  711. TTLOriginalData[offset+6] = byte(distAddr >> 24)
  712. TTLOriginalData[offset+7] = byte(distAddr >> 32)
  713. TTLOriginalData[offset+8] = byte(distAddr >> 40)
  714. TTLOriginalData[offset+9] = byte(distAddr >> 48)
  715. TTLOriginalData[offset+10] = byte(distAddr >> 56)
  716. TTLOriginalData[offset+11] = 0x48
  717. TTLOriginalData[offset+12] = 0x8b
  718. TTLOriginalData[offset+13] = 0x10
  719. TTLOriginalData[offset+14] = 0x58 //pop rax
  720. TTLOriginalData[offset+15] = 0xc3 //ret
  721. err = writeDataBytes(pid, getTTLFunctionAddr, TTLOriginalData)
  722. if err != nil {
  723. return err
  724. }
  725. return nil
  726. }
  727. func modifyNetSetTargetAddr(pid int, sendDebugAddr, sendReleaseAddr, convert0FunctionAddr uintptr) error {
  728. // sendOffset := sendReleaseAddr - sendDebugAddr - 5
  729. // // 读取原始数据
  730. // alignedAddr := sendDebugAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  731. // originalData, err := readData(pid, alignedAddr)
  732. // if err != nil {
  733. // return err
  734. // }
  735. // bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  736. // offsetLocation := (sendDebugAddr % uintptr(unsafe.Sizeof(uintptr(0)))) + 1
  737. // *(*uint32)(unsafe.Pointer(&bytes[offsetLocation])) = uint32(sendOffset)
  738. // err = writeData(pid, alignedAddr, originalData)
  739. // if err != nil {
  740. // return err
  741. // }
  742. convert0Offset := convert0FunctionAddr - sendDebugAddr - 5
  743. // 读取原始数据
  744. // alignedAddr := insertAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  745. originalData, err := readDataBytes(pid, sendDebugAddr, 5)
  746. if err != nil {
  747. return err
  748. }
  749. // offset := insertAddr % uintptr(unsafe.Sizeof(uintptr(0)))
  750. offset := 0
  751. // 写入AMD64的绝对跳转指令: mov rax, addr; jmp rax
  752. var convert0Offset32 uint32 = uint32(convert0Offset)
  753. originalData[offset] = 0xE8 // call
  754. originalData[offset+1] = byte(convert0Offset32)
  755. originalData[offset+2] = byte(convert0Offset32 >> 8)
  756. originalData[offset+3] = byte(convert0Offset32 >> 16)
  757. originalData[offset+4] = byte(convert0Offset32 >> 24)
  758. err = writeDataBytes(pid, sendDebugAddr, originalData)
  759. if err != nil {
  760. return err
  761. }
  762. convert0OriginalData, err := readDataBytes(pid, convert0FunctionAddr, 13)
  763. if err != nil {
  764. return err
  765. }
  766. convert0OriginalData[offset] = 0x48
  767. convert0OriginalData[offset+1] = 0xb8
  768. convert0OriginalData[offset+2] = byte(sendReleaseAddr)
  769. convert0OriginalData[offset+3] = byte(sendReleaseAddr >> 8)
  770. convert0OriginalData[offset+4] = byte(sendReleaseAddr >> 16)
  771. convert0OriginalData[offset+5] = byte(sendReleaseAddr >> 24)
  772. convert0OriginalData[offset+6] = byte(sendReleaseAddr >> 32)
  773. convert0OriginalData[offset+7] = byte(sendReleaseAddr >> 40)
  774. convert0OriginalData[offset+8] = byte(sendReleaseAddr >> 48)
  775. convert0OriginalData[offset+9] = byte(sendReleaseAddr >> 56)
  776. convert0OriginalData[offset+10] = 0xff
  777. convert0OriginalData[offset+11] = 0xd0
  778. convert0OriginalData[offset+12] = 0xc3
  779. err = writeDataBytes(pid, convert0FunctionAddr, convert0OriginalData)
  780. if err != nil {
  781. return err
  782. }
  783. return nil
  784. }
  785. // func modifyReleaseFuncEnter(pid int, originEnterAddr, debugEnterAddr uintptr) error {
  786. // offset := debugEnterAddr - (originEnterAddr + 5)
  787. // // 读取原始数据
  788. // alignedAddr := originEnterAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  789. // originalData, err := readData(pid, alignedAddr)
  790. // if err != nil {
  791. // return err
  792. // }
  793. // bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  794. // bytes[originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0)))] = 0xe9
  795. // *(*uint32)(unsafe.Pointer(&bytes[(originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0))))+1])) = uint32(offset)
  796. // err = writeData(pid, alignedAddr, originalData)
  797. // if err != nil {
  798. // return err
  799. // }
  800. // return nil
  801. // }
  802. func modifyReleaseFuncEnter(pid int, originEnterAddr, debugEnterAddr uintptr) error {
  803. // 读取原始数据 - 需要12字节来存储完整的跳转指令
  804. alignedAddr := originEnterAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  805. originalData, err := readDataBytes(pid, alignedAddr, 12)
  806. if err != nil {
  807. return err
  808. }
  809. offset := originEnterAddr % uintptr(unsafe.Sizeof(uintptr(0)))
  810. // 写入AMD64的绝对跳转指令: mov rax, addr; jmp rax
  811. originalData[offset] = 0x48 // REX.W prefix
  812. originalData[offset+1] = 0xb8 // mov rax, imm64
  813. // 按小端序写入64位地址
  814. originalData[offset+2] = byte(debugEnterAddr)
  815. originalData[offset+3] = byte(debugEnterAddr >> 8)
  816. originalData[offset+4] = byte(debugEnterAddr >> 16)
  817. originalData[offset+5] = byte(debugEnterAddr >> 24)
  818. originalData[offset+6] = byte(debugEnterAddr >> 32)
  819. originalData[offset+7] = byte(debugEnterAddr >> 40)
  820. originalData[offset+8] = byte(debugEnterAddr >> 48)
  821. originalData[offset+9] = byte(debugEnterAddr >> 56)
  822. originalData[offset+10] = 0xff // jmp rax
  823. originalData[offset+11] = 0xe0
  824. err = writeDataBytes(pid, alignedAddr, originalData)
  825. if err != nil {
  826. return err
  827. }
  828. return nil
  829. }
  830. func restoreOriginalInstructions(pid int, addr uintptr, instructions []byte) error {
  831. // alignedAddr := addr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  832. // originalData, err := readData(pid, alignedAddr)
  833. originalData, err := readDataBytes(pid, addr, len(instructions))
  834. if err != nil {
  835. return err
  836. }
  837. // bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  838. // for i := 0; i < len(instructions); i++ {
  839. // bytes[addr%uintptr(unsafe.Sizeof(uintptr(0)))+uintptr(i)] = instructions[i]
  840. // }
  841. // offset := addr % uintptr(unsafe.Sizeof(uintptr(0)))
  842. for i := 0; i < len(instructions); i++ {
  843. originalData[i] = instructions[i]
  844. }
  845. // err = writeData(pid, alignedAddr, originalData)
  846. err = writeDataBytes(pid, addr, originalData)
  847. if err != nil {
  848. return err
  849. }
  850. return nil
  851. }
  852. // func main() {
  853. // flag.StringVar(&PID, "p", "", "PID")
  854. // flag.Parse()
  855. // pidStr := PID // 替换为目标进程的 PID
  856. // pid, err := strconv.Atoi(pidStr)
  857. // if err != nil {
  858. // log.Fatalf("Invalid PID: %v", err)
  859. // }
  860. // functionName := "Java_java_net_SocketOutputStream_socketWrite0"
  861. // libraryName := "libnet.so"
  862. //
  863. // cwLibraryName := "cwlibnet.so"
  864. // cwLibraryPath := "/root/cwlibnet.so"
  865. //
  866. // jvmInjector := &JvmInjector{
  867. // pid: pid,
  868. // ReleaseLibNetInfo: LibNetInfo{
  869. // libName: libraryName,
  870. // FuncSymbol: instInfo{
  871. // SymName: functionName,
  872. // },
  873. // },
  874. // DebugLibNetInfo: LibNetInfo{
  875. // // TODO 根据版本设置
  876. // libName: cwLibraryName,
  877. // // TODO 根据版本设置
  878. // libPath: cwLibraryPath,
  879. // FuncSymbol: instInfo{
  880. // SymName: functionName,
  881. // },
  882. // },
  883. // }
  884. //
  885. // err = jvmInject(jvmInjector)
  886. // fmt.Println(err)
  887. // }
  888. func JvmInject(jvmInjector *JvmInjector) error {
  889. pid := jvmInjector.Pid
  890. var err error
  891. err = jvmInjector.InitProg()
  892. // Debug版本无需修改寄存器
  893. // 已经加载so并指令修改正确的
  894. if jvmInjector.PreCheck.EbpfCanInjection {
  895. klog.Infoln("[inject] eBPF can injection.")
  896. return nil
  897. }
  898. if err != nil {
  899. klog.WithError(err).Errorf("[inject] Error message during release phase.")
  900. return err
  901. }
  902. // 原指令校验通过
  903. if !jvmInjector.PreCheck.NeedInjectionCheck {
  904. return err
  905. }
  906. printCodeData(jvmInjector.ReleaseLibNetInfo)
  907. _type, _, err := FindLibBaseByPathFromProcMaps(pid, jvmInjector.DebugLibNetInfo.ProcLoadPath)
  908. if err != nil {
  909. // load so
  910. if _type == 1 {
  911. klog.Infoln("[inject] start load so.")
  912. resCode := jvmInjector.jvmInjectLib()
  913. if resCode == 0 {
  914. klog.Infof("[inject] load so successful. proc load path is [%s], file path in node is [%s]", jvmInjector.DebugLibNetInfo.ProcLoadPath, jvmInjector.DebugLibNetInfo.LibPath)
  915. jvmInjector.PreCheck.LoadingCheck = true
  916. } else {
  917. klog.Errorf("[inject] Failed load so. so path is [%s]", jvmInjector.DebugLibNetInfo.LibPath)
  918. return fmt.Errorf("[inject] Failed load so. code is %d so path is [%s]", resCode, jvmInjector.DebugLibNetInfo.LibPath)
  919. }
  920. }
  921. } else {
  922. klog.Infoln("[inject] so already loaded.")
  923. jvmInjector.PreCheck.LoadingCheck = true
  924. }
  925. if !jvmInjector.PreCheck.LoadingCheck {
  926. klog.Infof("Failed load so")
  927. return err
  928. }
  929. err = jvmInjector.findDebugFuncContextFromLibPath()
  930. if err != nil {
  931. klog.WithError(err).Errorf("[inject] Failed to find debug Func Context from libPath")
  932. return err
  933. }
  934. if !jvmInjector.validateAllPreCheck() {
  935. klog.Errorf("[inject] validateAllPreCheck failed: "+
  936. "NeedInjectionCheck=%v, LoadingCheck=%v, IoFdCheck=%v, NetSendFuncCheck=%v",
  937. jvmInjector.PreCheck.NeedInjectionCheck,
  938. jvmInjector.PreCheck.LoadingCheck,
  939. jvmInjector.PreCheck.IoFdCheck,
  940. jvmInjector.PreCheck.NetSendFuncCheck,
  941. )
  942. return err
  943. }
  944. // 修改
  945. debugFuncEnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncSymbol.SymAddr)
  946. debugFuncGetTTLEnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncGetTTLSymbol.SymAddr)
  947. debugFuncConvert0EnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncConvert0Symbol.SymAddr)
  948. debugIoFdAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.SymAddr)
  949. debugNetSendAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.NET_Send.SymAddr)
  950. originFuncEnterAddr := uintptr(jvmInjector.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  951. ioFdReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr)
  952. netSendReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr)
  953. klog.Infof("<0x%x> -> <0x%x>\n", originFuncEnterAddr, debugFuncEnterAddr)
  954. klog.Infof("<0x%x> -> <0x%x>\n", debugIoFdAddr, ioFdReleaseTargetAddr)
  955. klog.Infof("<0x%x> -> <0x%x>\n", debugNetSendAddr, netSendReleaseTargetAddr)
  956. klog.Infof("conver0 -> <0x%x>\n", debugFuncConvert0EnterAddr)
  957. klog.Infof("getttl -> <0x%x>\n", debugFuncGetTTLEnterAddr)
  958. // 附加到目标进程
  959. klog.Infof("attach")
  960. err = syscall.PtraceAttach(pid)
  961. if err != nil {
  962. klog.Errorf("ptrace ATTACH: %v", err)
  963. }
  964. // 等待目标进程停止
  965. klog.Infof("attach Wait")
  966. if _, err := syscall.Wait4(pid, nil, 0, nil); err != nil {
  967. klog.Errorf("wait4: %v", err)
  968. return err
  969. }
  970. //time.Now().UnixNano()
  971. // 修改目标的内存
  972. klog.Infof("modifyIoFdTargetAddr")
  973. err = modifyIoFdTargetAddr(pid, debugIoFdAddr, ioFdReleaseTargetAddr, debugFuncGetTTLEnterAddr)
  974. if err != nil {
  975. klog.Error(err)
  976. PtraceDetach(pid)
  977. return err
  978. }
  979. klog.Infof("modifyNetSetTargetAddr")
  980. err = modifyNetSetTargetAddr(pid, debugNetSendAddr, netSendReleaseTargetAddr, debugFuncConvert0EnterAddr)
  981. if err != nil {
  982. klog.Error(err)
  983. PtraceDetach(pid)
  984. return err
  985. }
  986. // 二次效验 读取并验证地址
  987. klog.Infof("checkDebugFuncSymAfterChange")
  988. _, err = jvmInjector.checkDebugFuncSymAfterChange()
  989. printCodeData(jvmInjector.ReleaseLibNetInfo)
  990. printCodeData(jvmInjector.DebugLibNetInfo)
  991. // 效验目标函数内地址是否与预期一致
  992. if !jvmInjector.validateAllModifyCheck() && err == nil {
  993. klog.WithError(err).Errorf("[inject] failed validateAllModifyCheck")
  994. PtraceDetach(pid)
  995. return err
  996. }
  997. // 更新函数入口
  998. klog.Infof("modifyReleaseFuncEnter")
  999. // 计算地址差
  1000. diff := originFuncEnterAddr - debugFuncEnterAddr
  1001. if diff < 0 {
  1002. diff = -diff
  1003. }
  1004. // 检查是否超过 2GB
  1005. if diff > (1 << 31) {
  1006. klog.Infof("[inject] originFuncEnterAddr(0x%x) and debugFuncEnterAddr(0x%x) distance > 2GB",
  1007. originFuncEnterAddr, debugFuncEnterAddr)
  1008. }
  1009. err = modifyReleaseFuncEnter(pid, originFuncEnterAddr, debugFuncEnterAddr)
  1010. if err != nil {
  1011. klog.WithError(err).Errorf("[inject] failed modifyReleaseFuncEnter")
  1012. PtraceDetach(pid)
  1013. return err
  1014. }
  1015. // 校验jmp地址修改正确 临时注释
  1016. klog.Infof("checkReleaseFuncSymAfterChange")
  1017. errReleaseFuncSymAfterChange := jvmInjector.checkReleaseFuncSymAfterChange()
  1018. if errReleaseFuncSymAfterChange != nil {
  1019. klog.WithError(errReleaseFuncSymAfterChange).Errorf("[inject] failed checkReleaseFuncSymAfterChange")
  1020. // 回滚
  1021. if len(jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode) == ORIGIN_CODE_LEN {
  1022. err = restoreOriginalInstructions(pid, originFuncEnterAddr, jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode)
  1023. if err != nil {
  1024. klog.WithError(err).Errorf("[inject] failed restoreOriginalInstructions")
  1025. PtraceDetach(pid)
  1026. return err
  1027. }
  1028. }
  1029. //PtraceDetach(pid)
  1030. //return errReleaseFuncSymAfterChange
  1031. }
  1032. return PtraceDetach(pid)
  1033. }
  1034. func PtraceDetach(pid int) error {
  1035. // 恢复执行
  1036. klog.Infof("Detach")
  1037. if err := syscall.PtraceDetach(pid); err != nil {
  1038. klog.Errorf("ptrace DETACH: %v", err)
  1039. return err
  1040. }
  1041. return nil
  1042. }