inject_linux_amd64.go 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871
  1. package inject
  2. /*
  3. #cgo CFLAGS: -I include
  4. #cgo amd64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_amd64.a
  5. #cgo arm64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_arm64.a
  6. #include "hotpatch.h"
  7. #include <stdlib.h>
  8. */
  9. import "C"
  10. import (
  11. "bufio"
  12. "debug/elf"
  13. "fmt"
  14. klog "github.com/sirupsen/logrus"
  15. "golang.org/x/arch/x86/x86asm"
  16. "log"
  17. "os"
  18. "strings"
  19. "syscall"
  20. "time"
  21. "unsafe"
  22. )
  23. const (
  24. IO_FD_FDID_SYM_OFFSET = 129
  25. NET_SEND_SYM_OFFSET = 518
  26. )
  27. type InstInfo struct {
  28. SymName string
  29. SymSize uint64
  30. SymAddr uint64
  31. PC uint64
  32. Inst x86asm.Inst
  33. OriginInst x86asm.Inst
  34. OriginCode []byte
  35. TargetAddr uint64
  36. OriginTargetAddr uint64
  37. }
  38. type InnerSymbolInfo struct {
  39. IO_fd_fdID InstInfo
  40. NET_Send InstInfo
  41. }
  42. type LibNetInfo struct {
  43. LibName string
  44. LibPath string
  45. FuncSymbol InstInfo
  46. InnerSymbol InnerSymbolInfo
  47. }
  48. type UprobeData struct {
  49. Offset int
  50. Func string
  51. ELFPath string
  52. }
  53. type JvmInjector struct {
  54. Pid int
  55. ReleaseLibNetInfo LibNetInfo
  56. DebugLibNetInfo LibNetInfo
  57. RecodeInfo LibNetInfo
  58. // 原方法首个指令不为jmp | ReleaseLibNetInfo 读取无异常
  59. PreCheck struct {
  60. NeedInjectionCheck bool // 原指令校验 true表示可以继续执行注入
  61. LoadingCheck bool // true 表示加载成功
  62. IoFdCheck bool // fd地址校验
  63. NetSendFuncCheck bool // netsend校验
  64. EbpfCanInjection bool // 满足则注入ebpf
  65. }
  66. AfterCheck struct {
  67. IoFdCheck bool
  68. NetSendFuncCheck bool
  69. }
  70. Uprobe UprobeData
  71. }
  72. func (j *JvmInjector) findReleaseAddressInfoFromMem() error {
  73. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  74. releaseFuncSym := InnerSymbolInfo{}
  75. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  76. if err != nil {
  77. return err
  78. }
  79. pc := uint64(0)
  80. callCount := 0
  81. preContext := InstInfo{}
  82. for pc < uint64(len(code)) {
  83. inst, err := x86asm.Decode(code[pc:], 64)
  84. if err != nil {
  85. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  86. pc++ // Skip this byte and try to decode again
  87. continue
  88. }
  89. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  90. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  91. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  92. currentData := InstInfo{
  93. PC: pc,
  94. SymAddr: funcAbsAddress + pc,
  95. Inst: inst,
  96. //IntelInst: x86asm.IntelSyntax(inst, 0, nil),
  97. }
  98. if pc == 0 && inst.Op == x86asm.JMP {
  99. // 已经被修改过的首指令
  100. j.PreCheck.EbpfCanInjection = true
  101. klog.Infof("[inject] Inst already modified. <%s>", x86asm.IntelSyntax(inst, 0, nil))
  102. return nil
  103. }
  104. if pc == 0 {
  105. j.ReleaseLibNetInfo.FuncSymbol.PC = currentData.PC
  106. j.ReleaseLibNetInfo.FuncSymbol.Inst = currentData.Inst
  107. j.ReleaseLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  108. }
  109. if inst.Op == x86asm.MOV {
  110. if dst, okDst := inst.Args[0].(x86asm.Mem); okDst {
  111. if dst.Base == x86asm.RBP {
  112. if src, okSrc := inst.Args[1].(x86asm.Reg); okSrc {
  113. if src == x86asm.R9L {
  114. // debug so
  115. j.PreCheck.EbpfCanInjection = true
  116. return fmt.Errorf("MOV from register %v to memory %v\n", src, dst)
  117. }
  118. }
  119. }
  120. }
  121. //src, okSrc := inst.Args[1].(x86asm.Reg)
  122. //fmt.Println(inst.Args)
  123. //fmt.Printf("Instruction: %+v\n", inst)
  124. //
  125. //fmt.Println(okSrc)
  126. //if okDst && okSrc && dst == x86asm.RBP && src == x86asm.R9L {
  127. // fmt.Println("Instruction is 'mov %r9d, %rbp'")
  128. //}
  129. }
  130. if inst.Op == x86asm.CALL {
  131. //fmt.Printf("Pre instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  132. if callCount == 0 {
  133. releaseFuncSym.IO_fd_fdID = preContext
  134. releaseFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Release)"
  135. preInst := preContext.Inst
  136. fmt.Println(preInst.Op)
  137. fmt.Println((preInst.Args))
  138. // 计算目标地址
  139. if preInst.Op == x86asm.MOV &&
  140. len(preInst.Args) == 4 &&
  141. preInst.Args[0] != nil &&
  142. preInst.Args[0] == x86asm.RDX &&
  143. preInst.Args[1] != nil {
  144. if mem, ok := preInst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  145. relOffset := mem.Disp // 直接从Mem结构体中读取偏移
  146. targetAddress := preContext.SymAddr + uint64(preInst.Len) + uint64(relOffset)
  147. fmt.Printf("Target address: 0x%x\n", targetAddress)
  148. releaseFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  149. } else {
  150. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  151. }
  152. } else {
  153. return fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  154. }
  155. //os.Exit(1)
  156. }
  157. callCount++
  158. if callCount == 4 {
  159. releaseFuncSym.NET_Send = currentData
  160. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  161. relOffset, ok := inst.Args[0].(x86asm.Rel)
  162. if !ok {
  163. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  164. }
  165. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  166. releaseFuncSym.NET_Send.TargetAddr = targetAddress
  167. fmt.Println(releaseFuncSym.NET_Send)
  168. releaseFuncSym.NET_Send.SymName = "<NET_Send>(Release)"
  169. fmt.Printf("Target address: 0x%x\n", targetAddress)
  170. }
  171. }
  172. preContext = InstInfo{
  173. PC: pc,
  174. SymAddr: funcAbsAddress + pc,
  175. Inst: inst,
  176. }
  177. pc += uint64(inst.Len)
  178. }
  179. j.ReleaseLibNetInfo.InnerSymbol = releaseFuncSym
  180. j.ReleaseLibNetInfo.FuncSymbol.OriginCode = code[0:5]
  181. return nil
  182. }
  183. func (j *JvmInjector) findDebugAddressInfoFromMem() (uint64, error) {
  184. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  185. debugFuncSym := InnerSymbolInfo{}
  186. //debugFuncSym.FuncSymbol.SymAddr = funcAbsAddress
  187. //offset := sym.Value
  188. size := j.DebugLibNetInfo.FuncSymbol.SymSize
  189. code, err := j.readMemory(funcAbsAddress, size)
  190. //fmt.Println(code, err)
  191. if err != nil {
  192. return 0, err
  193. }
  194. pc := uint64(0)
  195. preContext := InstInfo{}
  196. for pc < uint64(len(code)) {
  197. inst, err := x86asm.Decode(code[pc:], 64)
  198. if err != nil {
  199. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  200. pc++ // Skip this byte and try to decode again
  201. continue
  202. }
  203. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  204. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  205. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  206. currentData := InstInfo{
  207. PC: pc,
  208. SymAddr: funcAbsAddress + pc,
  209. Inst: inst,
  210. }
  211. if pc == 0 {
  212. j.DebugLibNetInfo.FuncSymbol.PC = currentData.PC
  213. j.DebugLibNetInfo.FuncSymbol.Inst = currentData.Inst
  214. j.DebugLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  215. }
  216. if pc == IO_FD_FDID_SYM_OFFSET {
  217. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  218. debugFuncSym.IO_fd_fdID = currentData
  219. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  220. // 计算目标地址
  221. if currentData.Inst.Op == x86asm.MOV &&
  222. len(currentData.Inst.Args) == 4 &&
  223. currentData.Inst.Args[0] != nil &&
  224. currentData.Inst.Args[0] == x86asm.RDX &&
  225. currentData.Inst.Args[1] != nil {
  226. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  227. // 直接从Mem结构体中读取偏移
  228. relOffset := mem.Disp
  229. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  230. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  231. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  232. // 保存原始数据
  233. debugFuncSym.IO_fd_fdID.OriginTargetAddr = targetAddress
  234. debugFuncSym.IO_fd_fdID.OriginInst = currentData.Inst
  235. j.PreCheck.IoFdCheck = true
  236. } else {
  237. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  238. }
  239. } else {
  240. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  241. }
  242. }
  243. if pc == NET_SEND_SYM_OFFSET {
  244. debugFuncSym.NET_Send = currentData
  245. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  246. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  247. if !ok {
  248. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  249. }
  250. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  251. debugFuncSym.NET_Send.TargetAddr = targetAddress
  252. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  253. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  254. // 保存原始数据
  255. debugFuncSym.NET_Send.OriginTargetAddr = targetAddress
  256. debugFuncSym.NET_Send.OriginInst = currentData.Inst
  257. j.PreCheck.NetSendFuncCheck = true
  258. }
  259. preContext = InstInfo{
  260. PC: pc,
  261. SymAddr: funcAbsAddress + pc,
  262. Inst: inst,
  263. }
  264. pc += uint64(inst.Len)
  265. }
  266. j.DebugLibNetInfo.InnerSymbol = debugFuncSym
  267. return 0, nil
  268. }
  269. func (j *JvmInjector) checkDebugFuncSymAfterChange() (uint64, error) {
  270. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  271. debugFuncSym := InnerSymbolInfo{}
  272. code, err := j.readMemory(funcAbsAddress, j.DebugLibNetInfo.FuncSymbol.SymSize)
  273. if err != nil {
  274. return 0, err
  275. }
  276. pc := uint64(0)
  277. preContext := InstInfo{}
  278. for pc < uint64(len(code)) {
  279. inst, err := x86asm.Decode(code[pc:], 64)
  280. if err != nil {
  281. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  282. pc++ // Skip this byte and try to decode again
  283. continue
  284. }
  285. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  286. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  287. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  288. currentData := InstInfo{
  289. PC: pc,
  290. SymAddr: funcAbsAddress + pc,
  291. Inst: inst,
  292. }
  293. if pc == NET_SEND_SYM_OFFSET {
  294. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  295. debugFuncSym.IO_fd_fdID = currentData
  296. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  297. // 计算目标地址
  298. if currentData.Inst.Op == x86asm.MOV &&
  299. len(currentData.Inst.Args) == 4 &&
  300. currentData.Inst.Args[0] != nil &&
  301. currentData.Inst.Args[0] == x86asm.RDX &&
  302. currentData.Inst.Args[1] != nil {
  303. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  304. // 直接从Mem结构体中读取偏移
  305. relOffset := mem.Disp
  306. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  307. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  308. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  309. //j.PreCheck.IoFdCheck = true
  310. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr {
  311. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr = targetAddress
  312. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.Inst = currentData.Inst
  313. j.AfterCheck.IoFdCheck = true
  314. fmt.Println("ok")
  315. }
  316. } else {
  317. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  318. }
  319. } else {
  320. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  321. }
  322. }
  323. if pc == NET_SEND_SYM_OFFSET {
  324. debugFuncSym.NET_Send = currentData
  325. //fmt.Println(currentData.IntelInst)
  326. //fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  327. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  328. if !ok {
  329. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  330. }
  331. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  332. debugFuncSym.NET_Send.TargetAddr = targetAddress
  333. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  334. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  335. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr {
  336. j.DebugLibNetInfo.InnerSymbol.NET_Send.TargetAddr = targetAddress
  337. j.DebugLibNetInfo.InnerSymbol.NET_Send.Inst = currentData.Inst
  338. j.AfterCheck.NetSendFuncCheck = true
  339. }
  340. }
  341. preContext = InstInfo{
  342. PC: pc,
  343. SymAddr: funcAbsAddress + pc,
  344. Inst: inst,
  345. }
  346. pc += uint64(inst.Len)
  347. }
  348. return 0, nil
  349. }
  350. func (j *JvmInjector) checkReleaseFuncSymAfterChange() error {
  351. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  352. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  353. if err != nil {
  354. return fmt.Errorf("readMemory error in checkReleaseFuncSymAfterChange <%v>", err)
  355. }
  356. inst, err := x86asm.Decode(code[0:], 64)
  357. if err != nil {
  358. return fmt.Errorf("Decode error in checkReleaseFuncSymAfterChange <%v>", err)
  359. }
  360. if inst.Op != x86asm.JMP {
  361. return fmt.Errorf("The instruction does not JMP.")
  362. }
  363. relOffset, ok := inst.Args[0].(x86asm.Rel)
  364. if !ok {
  365. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  366. }
  367. // 验证target与Debug入口是否一致
  368. targetAddress := funcAbsAddress + uint64(inst.Len) + uint64(relOffset)
  369. if targetAddress != j.DebugLibNetInfo.FuncSymbol.SymAddr {
  370. return fmt.Errorf("Function entry jmp address does not match expectations.")
  371. }
  372. return nil
  373. }
  374. // readMemory 用于读取指定地址的内存数据
  375. func (j *JvmInjector) readMemory(address uint64, size uint64) ([]byte, error) {
  376. memFile := fmt.Sprintf("/proc/%d/mem", j.Pid)
  377. file, err := os.Open(memFile)
  378. if err != nil {
  379. return nil, err
  380. }
  381. defer file.Close()
  382. data := make([]byte, size)
  383. _, err = file.ReadAt(data, int64(address))
  384. if err != nil {
  385. return nil, err
  386. }
  387. return data, nil
  388. }
  389. // findLibraryBases 用于在 /proc/[pid]/maps 文件中查找库的所有基地址
  390. func findLibraryBasesList(pid int, libraryName string, libPath string) ([]uint64, error) {
  391. mapsFile := fmt.Sprintf("/proc/%d/maps", pid)
  392. file, err := os.Open(mapsFile)
  393. if err != nil {
  394. return nil, err
  395. }
  396. defer file.Close()
  397. var bases []uint64
  398. scanner := bufio.NewScanner(file)
  399. for scanner.Scan() {
  400. line := scanner.Text()
  401. if strings.Contains(line, libraryName) && strings.Contains(line, libPath) {
  402. var start, end uint64
  403. fmt.Sscanf(line, "%x-%x", &start, &end)
  404. bases = append(bases, start)
  405. }
  406. }
  407. if len(bases) == 0 {
  408. return nil, fmt.Errorf("library %s not found", libraryName)
  409. }
  410. return bases, nil
  411. }
  412. func (j *JvmInjector) findLibBaseFromProcMaps(libName string) (uint64, string, error) {
  413. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  414. file, err := os.Open(mapsFile)
  415. if err != nil {
  416. return 0, "", err
  417. }
  418. defer file.Close()
  419. var start, end uint64
  420. scanner := bufio.NewScanner(file)
  421. for scanner.Scan() {
  422. line := scanner.Text()
  423. if strings.Contains(line, "/"+libName) {
  424. fmt.Sscanf(line, "%x-%x", &start, &end)
  425. fields := strings.Fields(line)
  426. if len(fields) > 5 {
  427. path := fields[5]
  428. if strings.HasSuffix(path, ".so") {
  429. klog.Infof("[inject] found library %s", path)
  430. return start, path, nil
  431. }
  432. }
  433. }
  434. }
  435. return 1, "", fmt.Errorf("library %s not found", libName)
  436. }
  437. func (j *JvmInjector) getFunctionOffset(libPath, functionName string) (elf.Symbol, error) {
  438. elfFile, err := elf.Open(libPath)
  439. if err != nil {
  440. return elf.Symbol{}, fmt.Errorf("failed to open ELF file: %v", err)
  441. }
  442. defer elfFile.Close()
  443. symbols, err := elfFile.DynamicSymbols()
  444. if err != nil {
  445. return elf.Symbol{}, fmt.Errorf("failed to read dynamic symbols: %v", err)
  446. }
  447. for _, sym := range symbols {
  448. if sym.Name == functionName {
  449. fmt.Println("size:", sym.Size)
  450. return sym, nil
  451. }
  452. }
  453. //textSection := elfFile.Section(".text")
  454. //if textSection == nil {
  455. // fmt.Println("textSection is null")
  456. // //return nil
  457. //}
  458. //textSectionData, err := textSection.Data()
  459. //if err != nil {
  460. // fmt.Println("textSectionData error is", err)
  461. // //return nil
  462. //}
  463. //textSectionLen := uint64(len(textSectionData) - 1)
  464. return elf.Symbol{}, fmt.Errorf("function %s not found", functionName)
  465. }
  466. //var PID string
  467. func (j *JvmInjector) findReleaseFuncContextFromLibPath() error {
  468. // 获取release库的基地址
  469. baseAddress, libPath, err := j.findLibBaseFromProcMaps(j.ReleaseLibNetInfo.LibName)
  470. functionName := j.ReleaseLibNetInfo.FuncSymbol.SymName
  471. j.ReleaseLibNetInfo.LibPath = libPath
  472. libName := j.ReleaseLibNetInfo.LibName
  473. if err != nil {
  474. log.Fatalf("Error finding base addresses: %v", err)
  475. return err
  476. }
  477. klog.Infof("[inject] Base address of %s: %x", libName, baseAddress)
  478. // 获取函数的偏移量
  479. functionSym, err := j.getFunctionOffset(libPath, functionName)
  480. // 计算函数的实际内存地址
  481. j.ReleaseLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  482. j.ReleaseLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  483. if err != nil {
  484. klog.WithError(err).Errorf("Error getting function offset")
  485. return err
  486. }
  487. klog.Infof("[inject] Actual memory address of %s at base 0x%x: 0x%x", functionName, baseAddress, j.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  488. err = j.findReleaseAddressInfoFromMem()
  489. if err != nil {
  490. return err
  491. } else {
  492. j.PreCheck.NeedInjectionCheck = true
  493. }
  494. return nil
  495. }
  496. func (j *JvmInjector) findDebugFuncContextFromLibPath() error {
  497. libName := j.DebugLibNetInfo.LibName
  498. // 获取release库的基地址
  499. baseAddress, libPath, err := j.findLibBaseFromProcMaps(libName)
  500. fmt.Println(libPath)
  501. functionName := j.DebugLibNetInfo.FuncSymbol.SymName
  502. j.DebugLibNetInfo.LibPath = libPath
  503. if err != nil {
  504. log.Fatalf("Error finding base addresses: %v", err)
  505. return err
  506. }
  507. // 获取函数的偏移量
  508. functionSym, err := j.getFunctionOffset(libPath, functionName)
  509. // 计算函数的实际内存地址
  510. j.DebugLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  511. j.DebugLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  512. if err != nil {
  513. log.Fatalf("Error getting function offset: %v", err)
  514. return err
  515. }
  516. fmt.Printf("Actual memory address of %s at base 0x%x: 0x%x\n", functionName, baseAddress, j.DebugLibNetInfo.FuncSymbol.SymAddr)
  517. _, err = j.findDebugAddressInfoFromMem()
  518. if err != nil {
  519. log.Printf("Error finding first CALL instuction: %v", err)
  520. return err
  521. }
  522. fmt.Printf("First CALL instuction o1f %s at base 0x%x\n", functionName, baseAddress)
  523. return nil
  524. }
  525. func printCodeData(data LibNetInfo) {
  526. fmt.Printf("========FuncEnter <0x%x> \n", data.FuncSymbol.SymAddr)
  527. fmt.Printf("Name %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x> \nOrigin-Inst:<%s> | Inst:<%s> \n",
  528. data.InnerSymbol.IO_fd_fdID.SymName,
  529. data.InnerSymbol.IO_fd_fdID.SymAddr,
  530. data.InnerSymbol.IO_fd_fdID.OriginTargetAddr,
  531. data.InnerSymbol.IO_fd_fdID.TargetAddr,
  532. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.OriginInst, 0, nil),
  533. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.Inst, 0, nil))
  534. fmt.Printf("\nName %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x>\nOrigin-Inst:<%s> | Inst:<%s> \n",
  535. data.InnerSymbol.NET_Send.SymName,
  536. data.InnerSymbol.NET_Send.SymAddr,
  537. data.InnerSymbol.NET_Send.OriginTargetAddr,
  538. data.InnerSymbol.NET_Send.TargetAddr,
  539. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.OriginInst, 0, nil),
  540. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.Inst, 0, nil))
  541. fmt.Println("========")
  542. }
  543. func (j *JvmInjector) jvmInjectLib() int {
  544. dll := C.CString(j.DebugLibNetInfo.LibPath) // 替换为实际的DLL路径
  545. defer C.free(unsafe.Pointer(dll)) // 确保在使用完字符串后释放内存
  546. result := C.cw_inject_library(C.int(j.Pid), C.int(1), dll)
  547. fmt.Printf("Result: %d\n", result)
  548. return int(result)
  549. }
  550. func (j *JvmInjector) validateAllPreCheck() bool {
  551. return j.PreCheck.NeedInjectionCheck && j.PreCheck.LoadingCheck && j.PreCheck.IoFdCheck && j.PreCheck.NetSendFuncCheck
  552. }
  553. func (j *JvmInjector) validateAllModifyCheck() bool {
  554. return j.AfterCheck.IoFdCheck && j.AfterCheck.NetSendFuncCheck
  555. }
  556. /*修改部分*/
  557. func readData(pid int, addr uintptr) (uint64, error) {
  558. var data uint64
  559. if _, err := syscall.PtracePeekData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  560. return 0, fmt.Errorf("ptrace PEEKDATA: %v", err)
  561. }
  562. return data, nil
  563. }
  564. func writeData(pid int, addr uintptr, data uint64) error {
  565. if _, err := syscall.PtracePokeData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  566. return fmt.Errorf("ptrace POKEDATA: %v", err)
  567. }
  568. return nil
  569. }
  570. func modifyIoFdTargetAddr(pid int, insertAddr, distAddr uintptr) error {
  571. newOffset := distAddr - (insertAddr + 7)
  572. targetAddr := insertAddr + 3
  573. // 获取目标地址处的数据
  574. originalData, err := readData(pid, targetAddr)
  575. if err != nil {
  576. return err
  577. }
  578. // 更新数据中的目标偏移
  579. updatedData := (originalData & 0xFFFFFFFF00000000) | uint64(newOffset&0xFFFFFFFF)
  580. err = writeData(pid, targetAddr, updatedData)
  581. if err != nil {
  582. return err
  583. }
  584. return nil
  585. }
  586. func modifyNetSetTargetAddr(pid int, sendDebugAddr, sendReleaseAddr uintptr) error {
  587. sendOffset := sendReleaseAddr - sendDebugAddr - 5
  588. // 读取原始数据
  589. alignedAddr := sendDebugAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  590. originalData, err := readData(pid, alignedAddr)
  591. if err != nil {
  592. return err
  593. }
  594. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  595. offsetLocation := (sendDebugAddr % uintptr(unsafe.Sizeof(uintptr(0)))) + 1
  596. *(*uint32)(unsafe.Pointer(&bytes[offsetLocation])) = uint32(sendOffset)
  597. err = writeData(pid, alignedAddr, originalData)
  598. if err != nil {
  599. return err
  600. }
  601. return nil
  602. }
  603. func modifyReleaseFuncEnter(pid int, originEnterAddr, debugEnterAddr uintptr) error {
  604. offset := debugEnterAddr - (originEnterAddr + 5)
  605. // 读取原始数据
  606. alignedAddr := originEnterAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  607. originalData, err := readData(pid, alignedAddr)
  608. if err != nil {
  609. return err
  610. }
  611. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  612. bytes[originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0)))] = 0xe9
  613. *(*uint32)(unsafe.Pointer(&bytes[(originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0))))+1])) = uint32(offset)
  614. err = writeData(pid, alignedAddr, originalData)
  615. if err != nil {
  616. return err
  617. }
  618. return nil
  619. }
  620. func restoreOriginalInstructions(pid int, addr uintptr, instructions []byte) error {
  621. alignedAddr := addr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  622. originalData, err := readData(pid, alignedAddr)
  623. if err != nil {
  624. return err
  625. }
  626. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  627. for i := 0; i < len(instructions); i++ {
  628. bytes[addr%uintptr(unsafe.Sizeof(uintptr(0)))+uintptr(i)] = instructions[i]
  629. }
  630. err = writeData(pid, alignedAddr, originalData)
  631. if err != nil {
  632. return err
  633. }
  634. return nil
  635. }
  636. //func main() {
  637. // flag.StringVar(&PID, "p", "", "PID")
  638. // flag.Parse()
  639. // pidStr := PID // 替换为目标进程的 PID
  640. // pid, err := strconv.Atoi(pidStr)
  641. // if err != nil {
  642. // log.Fatalf("Invalid PID: %v", err)
  643. // }
  644. // functionName := "Java_java_net_SocketOutputStream_socketWrite0"
  645. // libraryName := "libnet.so"
  646. //
  647. // cwLibraryName := "cwlibnet.so"
  648. // cwLibraryPath := "/root/cwlibnet.so"
  649. //
  650. // jvmInjector := &JvmInjector{
  651. // pid: pid,
  652. // ReleaseLibNetInfo: LibNetInfo{
  653. // libName: libraryName,
  654. // FuncSymbol: instInfo{
  655. // SymName: functionName,
  656. // },
  657. // },
  658. // DebugLibNetInfo: LibNetInfo{
  659. // // TODO 根据版本设置
  660. // libName: cwLibraryName,
  661. // // TODO 根据版本设置
  662. // libPath: cwLibraryPath,
  663. // FuncSymbol: instInfo{
  664. // SymName: functionName,
  665. // },
  666. // },
  667. // }
  668. //
  669. // err = jvmInject(jvmInjector)
  670. // fmt.Println(err)
  671. //}
  672. func JvmInject(jvmInjector *JvmInjector) error {
  673. pid := jvmInjector.Pid
  674. var err error
  675. err = jvmInjector.findReleaseFuncContextFromLibPath()
  676. // Debug版本无需修改寄存器
  677. // 已经加载so并指令修改正确的
  678. if jvmInjector.PreCheck.EbpfCanInjection {
  679. klog.Infoln("[inject] eBPF can injection.")
  680. return nil
  681. }
  682. if err != nil {
  683. klog.WithError(err).Errorf("[inject] Error message during release phase.")
  684. return err
  685. }
  686. // 原指令校验通过
  687. if !jvmInjector.PreCheck.NeedInjectionCheck {
  688. return err
  689. }
  690. printCodeData(jvmInjector.ReleaseLibNetInfo)
  691. _type, _, err := jvmInjector.findLibBaseFromProcMaps(jvmInjector.DebugLibNetInfo.LibName)
  692. if err != nil {
  693. // load so
  694. if _type == 1 {
  695. fmt.Println(err, "Load it.")
  696. if jvmInjector.jvmInjectLib() == 0 {
  697. jvmInjector.PreCheck.LoadingCheck = true
  698. } else {
  699. return err
  700. }
  701. }
  702. } else {
  703. jvmInjector.PreCheck.LoadingCheck = true
  704. }
  705. if !jvmInjector.PreCheck.LoadingCheck {
  706. fmt.Println("Failed load so")
  707. return err
  708. }
  709. err = jvmInjector.findDebugFuncContextFromLibPath()
  710. if err != nil {
  711. log.Fatalf("Failed to find debug Context: %v", err)
  712. }
  713. if !jvmInjector.validateAllPreCheck() {
  714. fmt.Println("failed validateAllPreCheck ")
  715. return err
  716. }
  717. // 修改
  718. debugFuncEnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncSymbol.SymAddr)
  719. debugIoFdAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.SymAddr)
  720. debugNetSendAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.NET_Send.SymAddr)
  721. originFuncEnterAddr := uintptr(jvmInjector.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  722. ioFdReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr)
  723. netSendReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr)
  724. fmt.Printf("<0x%x> -> <0x%x>\n", originFuncEnterAddr, debugFuncEnterAddr)
  725. fmt.Printf("<0x%x> -> <0x%x>\n", debugIoFdAddr, ioFdReleaseTargetAddr)
  726. fmt.Printf("<0x%x> -> <0x%x>\n", debugNetSendAddr, netSendReleaseTargetAddr)
  727. // 附加到目标进程
  728. err = syscall.PtraceAttach(pid)
  729. if err != nil {
  730. fmt.Printf("ptrace ATTACH: %v", err)
  731. }
  732. // 等待目标进程停止
  733. if _, err := syscall.Wait4(pid, nil, 0, nil); err != nil {
  734. fmt.Printf("wait4: %v", err)
  735. return err
  736. }
  737. time.Now().UnixNano()
  738. // 修改目标的内存
  739. err = modifyIoFdTargetAddr(pid, debugIoFdAddr, ioFdReleaseTargetAddr)
  740. if err != nil {
  741. fmt.Println(err)
  742. return err
  743. }
  744. err = modifyNetSetTargetAddr(pid, debugNetSendAddr, netSendReleaseTargetAddr)
  745. fmt.Println(err)
  746. if err != nil {
  747. fmt.Println(err)
  748. return err
  749. }
  750. // 二次效验 读取并验证地址
  751. _, err = jvmInjector.checkDebugFuncSymAfterChange()
  752. printCodeData(jvmInjector.ReleaseLibNetInfo)
  753. printCodeData(jvmInjector.DebugLibNetInfo)
  754. // 效验目标函数内地址是否与预期一致
  755. if !jvmInjector.validateAllModifyCheck() && err == nil {
  756. return err
  757. }
  758. // 更新函数入口
  759. err = modifyReleaseFuncEnter(pid, originFuncEnterAddr, debugFuncEnterAddr)
  760. if err != nil {
  761. fmt.Println(err)
  762. return err
  763. }
  764. // 校验jmp地址修改正确
  765. err = jvmInjector.checkReleaseFuncSymAfterChange()
  766. if err != nil {
  767. fmt.Println(err)
  768. if len(jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode) == 5 {
  769. err = restoreOriginalInstructions(pid, originFuncEnterAddr, jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode)
  770. if err != nil {
  771. fmt.Println(err)
  772. return err
  773. }
  774. }
  775. }
  776. // 恢复执行
  777. if err = syscall.PtraceDetach(pid); err != nil {
  778. fmt.Printf("ptrace DETACH: %v", err)
  779. return err
  780. }
  781. return nil
  782. }