inject_linux_amd64.go 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897
  1. package inject
  2. /*
  3. #cgo CFLAGS: -I include
  4. #cgo amd64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_amd64.a
  5. #cgo arm64 LDFLAGS: ${SRCDIR}/lib/libhotpatch_arm64.a
  6. #include "hotpatch.h"
  7. #include <stdlib.h>
  8. */
  9. import "C"
  10. import (
  11. "bufio"
  12. "debug/elf"
  13. "fmt"
  14. klog "github.com/sirupsen/logrus"
  15. "golang.org/x/arch/x86/x86asm"
  16. "os"
  17. "strings"
  18. "syscall"
  19. "time"
  20. "unsafe"
  21. )
  22. const (
  23. IO_FD_FDID_SYM_OFFSET = 129
  24. NET_SEND_SYM_OFFSET = 518
  25. )
  26. type InstInfo struct {
  27. SymName string
  28. SymSize uint64
  29. SymAddr uint64
  30. PC uint64
  31. Inst x86asm.Inst
  32. OriginInst x86asm.Inst
  33. OriginCode []byte
  34. TargetAddr uint64
  35. OriginTargetAddr uint64
  36. }
  37. type InnerSymbolInfo struct {
  38. IO_fd_fdID InstInfo
  39. NET_Send InstInfo
  40. }
  41. type LibNetInfo struct {
  42. LibName string
  43. LibPath string
  44. FuncSymbol InstInfo
  45. InnerSymbol InnerSymbolInfo
  46. }
  47. type UprobeData struct {
  48. Offset int
  49. Func string
  50. ELFPath string
  51. }
  52. type JvmInjector struct {
  53. Pid int
  54. ReleaseLibNetInfo LibNetInfo
  55. DebugLibNetInfo LibNetInfo
  56. RecodeInfo LibNetInfo
  57. // 原方法首个指令不为jmp | ReleaseLibNetInfo 读取无异常
  58. PreCheck struct {
  59. NeedInjectionCheck bool // 原指令校验 true表示可以继续执行注入
  60. LoadingCheck bool // true 表示加载成功
  61. IoFdCheck bool // fd地址校验
  62. NetSendFuncCheck bool // netsend校验
  63. EbpfCanInjection bool // 满足则注入ebpf
  64. }
  65. AfterCheck struct {
  66. IoFdCheck bool
  67. NetSendFuncCheck bool
  68. }
  69. Uprobe UprobeData
  70. }
  71. func (j *JvmInjector) findReleaseAddressInfoFromMem() error {
  72. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  73. releaseFuncSym := InnerSymbolInfo{}
  74. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  75. if err != nil {
  76. return err
  77. }
  78. pc := uint64(0)
  79. callCount := 0
  80. preContext := InstInfo{}
  81. for pc < uint64(len(code)) {
  82. inst, err := x86asm.Decode(code[pc:], 64)
  83. if err != nil {
  84. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  85. pc++ // Skip this byte and try to decode again
  86. continue
  87. }
  88. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  89. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  90. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  91. currentData := InstInfo{
  92. PC: pc,
  93. SymAddr: funcAbsAddress + pc,
  94. Inst: inst,
  95. //IntelInst: x86asm.IntelSyntax(inst, 0, nil),
  96. }
  97. if pc == 0 && inst.Op == x86asm.JMP {
  98. // 已经被修改过的首指令
  99. j.PreCheck.EbpfCanInjection = true
  100. j.Uprobe.ELFPath = j.DebugLibNetInfo.LibPath
  101. klog.Infof("[inject] Inst already modified. <%s>", x86asm.IntelSyntax(inst, 0, nil))
  102. return nil
  103. }
  104. if pc == 0 {
  105. j.ReleaseLibNetInfo.FuncSymbol.PC = currentData.PC
  106. j.ReleaseLibNetInfo.FuncSymbol.Inst = currentData.Inst
  107. j.ReleaseLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  108. }
  109. if inst.Op == x86asm.MOV {
  110. if dst, okDst := inst.Args[0].(x86asm.Mem); okDst {
  111. if dst.Base == x86asm.RBP {
  112. if src, okSrc := inst.Args[1].(x86asm.Reg); okSrc {
  113. if src == x86asm.R9L {
  114. // debug so
  115. klog.Infof("[inject] release.so is debug.so. <%s>", x86asm.IntelSyntax(inst, 0, nil))
  116. j.PreCheck.EbpfCanInjection = true
  117. j.Uprobe.ELFPath = j.ReleaseLibNetInfo.LibPath
  118. return fmt.Errorf("MOV from register %v to memory %v\n", src, dst)
  119. //return nil
  120. }
  121. }
  122. }
  123. }
  124. //src, okSrc := inst.Args[1].(x86asm.Reg)
  125. //fmt.Println(inst.Args)
  126. //fmt.Printf("Instruction: %+v\n", inst)
  127. //
  128. //fmt.Println(okSrc)
  129. //if okDst && okSrc && dst == x86asm.RBP && src == x86asm.R9L {
  130. // fmt.Println("Instruction is 'mov %r9d, %rbp'")
  131. //}
  132. }
  133. if inst.Op == x86asm.CALL {
  134. //fmt.Printf("Pre instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  135. if callCount == 0 {
  136. releaseFuncSym.IO_fd_fdID = preContext
  137. releaseFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Release)"
  138. preInst := preContext.Inst
  139. fmt.Println(preInst.Op)
  140. fmt.Println((preInst.Args))
  141. // 计算目标地址
  142. if preInst.Op == x86asm.MOV &&
  143. len(preInst.Args) == 4 &&
  144. preInst.Args[0] != nil &&
  145. preInst.Args[0] == x86asm.RDX &&
  146. preInst.Args[1] != nil {
  147. if mem, ok := preInst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  148. relOffset := mem.Disp // 直接从Mem结构体中读取偏移
  149. targetAddress := preContext.SymAddr + uint64(preInst.Len) + uint64(relOffset)
  150. fmt.Printf("Target address: 0x%x\n", targetAddress)
  151. releaseFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  152. } else {
  153. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  154. }
  155. } else {
  156. return fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  157. }
  158. //os.Exit(1)
  159. }
  160. callCount++
  161. if callCount == 4 {
  162. releaseFuncSym.NET_Send = currentData
  163. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  164. relOffset, ok := inst.Args[0].(x86asm.Rel)
  165. if !ok {
  166. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  167. }
  168. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  169. releaseFuncSym.NET_Send.TargetAddr = targetAddress
  170. fmt.Println(releaseFuncSym.NET_Send)
  171. releaseFuncSym.NET_Send.SymName = "<NET_Send>(Release)"
  172. fmt.Printf("Target address: 0x%x\n", targetAddress)
  173. }
  174. }
  175. preContext = InstInfo{
  176. PC: pc,
  177. SymAddr: funcAbsAddress + pc,
  178. Inst: inst,
  179. }
  180. pc += uint64(inst.Len)
  181. }
  182. j.ReleaseLibNetInfo.InnerSymbol = releaseFuncSym
  183. j.ReleaseLibNetInfo.FuncSymbol.OriginCode = code[0:5]
  184. return nil
  185. }
  186. func (j *JvmInjector) findDebugAddressInfoFromMem() (uint64, error) {
  187. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  188. debugFuncSym := InnerSymbolInfo{}
  189. //debugFuncSym.FuncSymbol.SymAddr = funcAbsAddress
  190. //offset := sym.Value
  191. size := j.DebugLibNetInfo.FuncSymbol.SymSize
  192. code, err := j.readMemory(funcAbsAddress, size)
  193. //fmt.Println(code, err)
  194. if err != nil {
  195. return 0, err
  196. }
  197. pc := uint64(0)
  198. preContext := InstInfo{}
  199. for pc < uint64(len(code)) {
  200. inst, err := x86asm.Decode(code[pc:], 64)
  201. if err != nil {
  202. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  203. pc++ // Skip this byte and try to decode again
  204. continue
  205. }
  206. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  207. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  208. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  209. currentData := InstInfo{
  210. PC: pc,
  211. SymAddr: funcAbsAddress + pc,
  212. Inst: inst,
  213. }
  214. if pc == 0 {
  215. j.DebugLibNetInfo.FuncSymbol.PC = currentData.PC
  216. j.DebugLibNetInfo.FuncSymbol.Inst = currentData.Inst
  217. j.DebugLibNetInfo.FuncSymbol.OriginInst = currentData.Inst
  218. }
  219. if pc == IO_FD_FDID_SYM_OFFSET {
  220. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  221. debugFuncSym.IO_fd_fdID = currentData
  222. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  223. // 计算目标地址
  224. if currentData.Inst.Op == x86asm.MOV &&
  225. len(currentData.Inst.Args) == 4 &&
  226. currentData.Inst.Args[0] != nil &&
  227. currentData.Inst.Args[0] == x86asm.RDX &&
  228. currentData.Inst.Args[1] != nil {
  229. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  230. // 直接从Mem结构体中读取偏移
  231. relOffset := mem.Disp
  232. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  233. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  234. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  235. // 保存原始数据
  236. debugFuncSym.IO_fd_fdID.OriginTargetAddr = targetAddress
  237. debugFuncSym.IO_fd_fdID.OriginInst = currentData.Inst
  238. j.PreCheck.IoFdCheck = true
  239. } else {
  240. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  241. }
  242. } else {
  243. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  244. }
  245. }
  246. if pc == NET_SEND_SYM_OFFSET {
  247. debugFuncSym.NET_Send = currentData
  248. fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  249. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  250. if !ok {
  251. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  252. }
  253. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  254. debugFuncSym.NET_Send.TargetAddr = targetAddress
  255. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  256. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  257. // 保存原始数据
  258. debugFuncSym.NET_Send.OriginTargetAddr = targetAddress
  259. debugFuncSym.NET_Send.OriginInst = currentData.Inst
  260. j.PreCheck.NetSendFuncCheck = true
  261. }
  262. preContext = InstInfo{
  263. PC: pc,
  264. SymAddr: funcAbsAddress + pc,
  265. Inst: inst,
  266. }
  267. pc += uint64(inst.Len)
  268. }
  269. j.DebugLibNetInfo.InnerSymbol = debugFuncSym
  270. return 0, nil
  271. }
  272. func (j *JvmInjector) checkDebugFuncSymAfterChange() (uint64, error) {
  273. funcAbsAddress := j.DebugLibNetInfo.FuncSymbol.SymAddr
  274. debugFuncSym := InnerSymbolInfo{}
  275. code, err := j.readMemory(funcAbsAddress, j.DebugLibNetInfo.FuncSymbol.SymSize)
  276. if err != nil {
  277. return 0, err
  278. }
  279. pc := uint64(0)
  280. preContext := InstInfo{}
  281. for pc < uint64(len(code)) {
  282. inst, err := x86asm.Decode(code[pc:], 64)
  283. if err != nil {
  284. fmt.Printf("Decode error at offset 0x%x: %v\n", pc, err)
  285. pc++ // Skip this byte and try to decode again
  286. continue
  287. }
  288. //fmt.Printf("Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, Inst)
  289. //fmt.Printf("Decoded x86 instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.IntelSyntax(inst, 0, nil))
  290. //fmt.Printf("Decoded GNU instuction at 0x%x: %v\n", funcAbsAddress+pc, x86asm.GNUSyntax(Inst, 0, nil))
  291. currentData := InstInfo{
  292. PC: pc,
  293. SymAddr: funcAbsAddress + pc,
  294. Inst: inst,
  295. }
  296. if pc == NET_SEND_SYM_OFFSET {
  297. fmt.Printf("Instuction at 0x%x: %v\n", preContext.PC, preContext.Inst)
  298. debugFuncSym.IO_fd_fdID = currentData
  299. debugFuncSym.IO_fd_fdID.SymName = "<IO_fd_fdID>(Debug)"
  300. // 计算目标地址
  301. if currentData.Inst.Op == x86asm.MOV &&
  302. len(currentData.Inst.Args) == 4 &&
  303. currentData.Inst.Args[0] != nil &&
  304. currentData.Inst.Args[0] == x86asm.RDX &&
  305. currentData.Inst.Args[1] != nil {
  306. if mem, ok := currentData.Inst.Args[1].(x86asm.Mem); ok && mem.Base == x86asm.RIP {
  307. // 直接从Mem结构体中读取偏移
  308. relOffset := mem.Disp
  309. targetAddress := currentData.SymAddr + uint64(currentData.Inst.Len) + uint64(relOffset)
  310. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.IO_fd_fdID.SymName, targetAddress)
  311. debugFuncSym.IO_fd_fdID.TargetAddr = targetAddress
  312. //j.PreCheck.IoFdCheck = true
  313. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr {
  314. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr = targetAddress
  315. j.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.Inst = currentData.Inst
  316. j.AfterCheck.IoFdCheck = true
  317. fmt.Println("ok")
  318. }
  319. } else {
  320. return 0, fmt.Errorf("The instruction does not use RIP-relative addressing.")
  321. }
  322. } else {
  323. return 0, fmt.Errorf("The decoded instruction is not a MOV to RDX.")
  324. }
  325. }
  326. if pc == NET_SEND_SYM_OFFSET {
  327. debugFuncSym.NET_Send = currentData
  328. //fmt.Println(currentData.IntelInst)
  329. //fmt.Printf("4 call Decoded instuction at 0x%x: %v\n", funcAbsAddress+pc, inst)
  330. relOffset, ok := (inst.Args[0].(x86asm.Rel))
  331. if !ok {
  332. return 0, fmt.Errorf("The decoded instruction is not a Rel.")
  333. }
  334. targetAddress := currentData.SymAddr + uint64(inst.Len) + uint64(relOffset)
  335. debugFuncSym.NET_Send.TargetAddr = targetAddress
  336. debugFuncSym.NET_Send.SymName = "<NET_Send>(Debug)"
  337. fmt.Printf("Find %s Target address: 0x%x\n", debugFuncSym.NET_Send.SymName, targetAddress)
  338. if targetAddress == j.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr {
  339. j.DebugLibNetInfo.InnerSymbol.NET_Send.TargetAddr = targetAddress
  340. j.DebugLibNetInfo.InnerSymbol.NET_Send.Inst = currentData.Inst
  341. j.AfterCheck.NetSendFuncCheck = true
  342. }
  343. }
  344. preContext = InstInfo{
  345. PC: pc,
  346. SymAddr: funcAbsAddress + pc,
  347. Inst: inst,
  348. }
  349. pc += uint64(inst.Len)
  350. }
  351. return 0, nil
  352. }
  353. func (j *JvmInjector) checkReleaseFuncSymAfterChange() error {
  354. funcAbsAddress := j.ReleaseLibNetInfo.FuncSymbol.SymAddr
  355. code, err := j.readMemory(funcAbsAddress, j.ReleaseLibNetInfo.FuncSymbol.SymSize)
  356. if err != nil {
  357. return fmt.Errorf("readMemory error in checkReleaseFuncSymAfterChange <%v>", err)
  358. }
  359. inst, err := x86asm.Decode(code[0:], 64)
  360. if err != nil {
  361. return fmt.Errorf("Decode error in checkReleaseFuncSymAfterChange <%v>", err)
  362. }
  363. if inst.Op != x86asm.JMP {
  364. return fmt.Errorf("The instruction does not JMP.")
  365. }
  366. relOffset, ok := inst.Args[0].(x86asm.Rel)
  367. if !ok {
  368. return fmt.Errorf("The instruction does not use RIP-relative addressing.")
  369. }
  370. // 验证target与Debug入口是否一致
  371. targetAddress := funcAbsAddress + uint64(inst.Len) + uint64(relOffset)
  372. if targetAddress != j.DebugLibNetInfo.FuncSymbol.SymAddr {
  373. return fmt.Errorf("Function entry jmp address does not match expectations.")
  374. }
  375. return nil
  376. }
  377. // readMemory 用于读取指定地址的内存数据
  378. func (j *JvmInjector) readMemory(address uint64, size uint64) ([]byte, error) {
  379. memFile := fmt.Sprintf("/proc/%d/mem", j.Pid)
  380. file, err := os.Open(memFile)
  381. if err != nil {
  382. return nil, err
  383. }
  384. defer file.Close()
  385. data := make([]byte, size)
  386. _, err = file.ReadAt(data, int64(address))
  387. if err != nil {
  388. return nil, err
  389. }
  390. return data, nil
  391. }
  392. // findLibraryBases 用于在 /proc/[pid]/maps 文件中查找库的所有基地址
  393. func findLibraryBasesList(pid int, libraryName string, libPath string) ([]uint64, error) {
  394. mapsFile := fmt.Sprintf("/proc/%d/maps", pid)
  395. file, err := os.Open(mapsFile)
  396. if err != nil {
  397. return nil, err
  398. }
  399. defer file.Close()
  400. var bases []uint64
  401. scanner := bufio.NewScanner(file)
  402. for scanner.Scan() {
  403. line := scanner.Text()
  404. if strings.Contains(line, libraryName) && strings.Contains(line, libPath) {
  405. var start, end uint64
  406. fmt.Sscanf(line, "%x-%x", &start, &end)
  407. bases = append(bases, start)
  408. }
  409. }
  410. if len(bases) == 0 {
  411. return nil, fmt.Errorf("library %s not found", libraryName)
  412. }
  413. return bases, nil
  414. }
  415. func (j *JvmInjector) findLibBaseFromProcMaps(libName string) (uint64, string, error) {
  416. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  417. file, err := os.Open(mapsFile)
  418. if err != nil {
  419. return 0, "", err
  420. }
  421. defer file.Close()
  422. var start, end uint64
  423. scanner := bufio.NewScanner(file)
  424. for scanner.Scan() {
  425. line := scanner.Text()
  426. if strings.Contains(line, "/"+libName) {
  427. fmt.Sscanf(line, "%x-%x", &start, &end)
  428. fields := strings.Fields(line)
  429. if len(fields) > 5 {
  430. path := fields[5]
  431. if strings.HasSuffix(path, ".so") {
  432. klog.Infof("[inject] found library %s", path)
  433. return start, path, nil
  434. }
  435. }
  436. }
  437. }
  438. return 1, "", fmt.Errorf("library %s not found", libName)
  439. }
  440. func (j *JvmInjector) findLibBaseByPathFromProcMaps(libPath string) (uint64, string, error) {
  441. mapsFile := fmt.Sprintf("/proc/%d/maps", j.Pid)
  442. file, err := os.Open(mapsFile)
  443. if err != nil {
  444. return 0, "", err
  445. }
  446. defer file.Close()
  447. var start, end uint64
  448. scanner := bufio.NewScanner(file)
  449. for scanner.Scan() {
  450. line := scanner.Text()
  451. if strings.Contains(line, libPath) {
  452. fmt.Sscanf(line, "%x-%x", &start, &end)
  453. fields := strings.Fields(line)
  454. if len(fields) > 5 {
  455. path := fields[5]
  456. if strings.HasSuffix(path, ".so") {
  457. fmt.Printf("Found library %s\n", path)
  458. return start, path, nil
  459. }
  460. }
  461. }
  462. }
  463. return 1, "", fmt.Errorf("library %s not found", libPath)
  464. }
  465. func (j *JvmInjector) getFunctionOffset(libPath, functionName string) (elf.Symbol, error) {
  466. elfFile, err := elf.Open(libPath)
  467. if err != nil {
  468. return elf.Symbol{}, fmt.Errorf("failed to open ELF file: %v", err)
  469. }
  470. defer elfFile.Close()
  471. symbols, err := elfFile.DynamicSymbols()
  472. if err != nil {
  473. return elf.Symbol{}, fmt.Errorf("failed to read dynamic symbols: %v", err)
  474. }
  475. for _, sym := range symbols {
  476. if sym.Name == functionName {
  477. fmt.Println("size:", sym.Size)
  478. return sym, nil
  479. }
  480. }
  481. //textSection := elfFile.Section(".text")
  482. //if textSection == nil {
  483. // fmt.Println("textSection is null")
  484. // //return nil
  485. //}
  486. //textSectionData, err := textSection.Data()
  487. //if err != nil {
  488. // fmt.Println("textSectionData error is", err)
  489. // //return nil
  490. //}
  491. //textSectionLen := uint64(len(textSectionData) - 1)
  492. return elf.Symbol{}, fmt.Errorf("function %s not found", functionName)
  493. }
  494. //var PID string
  495. func (j *JvmInjector) findReleaseFuncContextFromLibPath() error {
  496. // 获取release库的基地址
  497. baseAddress, libPath, err := j.findLibBaseFromProcMaps(j.ReleaseLibNetInfo.LibName)
  498. functionName := j.ReleaseLibNetInfo.FuncSymbol.SymName
  499. j.ReleaseLibNetInfo.LibPath = libPath
  500. libName := j.ReleaseLibNetInfo.LibName
  501. if err != nil {
  502. return fmt.Errorf("Error finding base addresses: %v", err)
  503. }
  504. klog.Infof("[inject] Base address of %s: %x", libName, baseAddress)
  505. // 获取函数的偏移量
  506. functionSym, err := j.getFunctionOffset(libPath, functionName)
  507. // 计算函数的实际内存地址
  508. j.ReleaseLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  509. j.ReleaseLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  510. if err != nil {
  511. klog.WithError(err).Errorf("Error getting function offset")
  512. return err
  513. }
  514. klog.Infof("[inject] Actual memory address of %s at base 0x%x: 0x%x", functionName, baseAddress, j.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  515. err = j.findReleaseAddressInfoFromMem()
  516. if err != nil {
  517. return err
  518. } else {
  519. j.PreCheck.NeedInjectionCheck = true
  520. }
  521. return nil
  522. }
  523. func (j *JvmInjector) findDebugFuncContextFromLibPath() error {
  524. //libName := j.DebugLibNetInfo.LibPath
  525. // 获取release库的基地址
  526. baseAddress, libPath, err := j.findLibBaseByPathFromProcMaps(j.DebugLibNetInfo.LibPath)
  527. fmt.Println("debug libPath", libPath)
  528. functionName := j.DebugLibNetInfo.FuncSymbol.SymName
  529. j.DebugLibNetInfo.LibPath = libPath
  530. if err != nil {
  531. return err
  532. }
  533. // 获取函数的偏移量
  534. functionSym, err := j.getFunctionOffset(libPath, functionName)
  535. // 计算函数的实际内存地址
  536. j.DebugLibNetInfo.FuncSymbol.SymAddr = baseAddress + functionSym.Value
  537. j.DebugLibNetInfo.FuncSymbol.SymSize = functionSym.Size
  538. if err != nil {
  539. return fmt.Errorf("Error getting function offset: %v", err)
  540. }
  541. _, err = j.findDebugAddressInfoFromMem()
  542. if err != nil {
  543. return fmt.Errorf("Error finding first CALL instuction: %v", err)
  544. }
  545. fmt.Printf("First CALL instuction o1f %s at base 0x%x\n", functionName, baseAddress)
  546. return nil
  547. }
  548. func printCodeData(data LibNetInfo) {
  549. fmt.Printf("========FuncEnter <0x%x> \n", data.FuncSymbol.SymAddr)
  550. fmt.Printf("Name %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x> \nOrigin-Inst:<%s> | Inst:<%s> \n",
  551. data.InnerSymbol.IO_fd_fdID.SymName,
  552. data.InnerSymbol.IO_fd_fdID.SymAddr,
  553. data.InnerSymbol.IO_fd_fdID.OriginTargetAddr,
  554. data.InnerSymbol.IO_fd_fdID.TargetAddr,
  555. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.OriginInst, 0, nil),
  556. x86asm.IntelSyntax(data.InnerSymbol.IO_fd_fdID.Inst, 0, nil))
  557. fmt.Printf("\nName %s | CurrentAddr:<0x%x>\nOrigin-TargetAddr:<0x%x> | TargetAddr:<0x%x>\nOrigin-Inst:<%s> | Inst:<%s> \n",
  558. data.InnerSymbol.NET_Send.SymName,
  559. data.InnerSymbol.NET_Send.SymAddr,
  560. data.InnerSymbol.NET_Send.OriginTargetAddr,
  561. data.InnerSymbol.NET_Send.TargetAddr,
  562. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.OriginInst, 0, nil),
  563. x86asm.IntelSyntax(data.InnerSymbol.NET_Send.Inst, 0, nil))
  564. fmt.Println("========")
  565. }
  566. func (j *JvmInjector) jvmInjectLib() int {
  567. dll := C.CString(j.DebugLibNetInfo.LibPath) // 替换为实际的DLL路径
  568. defer C.free(unsafe.Pointer(dll)) // 确保在使用完字符串后释放内存
  569. result := C.cw_inject_library(C.int(j.Pid), C.int(1), dll)
  570. fmt.Printf("Result: %d\n", result)
  571. return int(result)
  572. }
  573. func (j *JvmInjector) validateAllPreCheck() bool {
  574. return j.PreCheck.NeedInjectionCheck && j.PreCheck.LoadingCheck && j.PreCheck.IoFdCheck && j.PreCheck.NetSendFuncCheck
  575. }
  576. func (j *JvmInjector) validateAllModifyCheck() bool {
  577. return j.AfterCheck.IoFdCheck && j.AfterCheck.NetSendFuncCheck
  578. }
  579. /*修改部分*/
  580. func readData(pid int, addr uintptr) (uint64, error) {
  581. var data uint64
  582. if _, err := syscall.PtracePeekData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  583. return 0, fmt.Errorf("ptrace PEEKDATA: %v", err)
  584. }
  585. return data, nil
  586. }
  587. func writeData(pid int, addr uintptr, data uint64) error {
  588. if _, err := syscall.PtracePokeData(pid, addr, (*[8]byte)(unsafe.Pointer(&data))[:]); err != nil {
  589. return fmt.Errorf("ptrace POKEDATA: %v", err)
  590. }
  591. return nil
  592. }
  593. func modifyIoFdTargetAddr(pid int, insertAddr, distAddr uintptr) error {
  594. newOffset := distAddr - (insertAddr + 7)
  595. targetAddr := insertAddr + 3
  596. // 获取目标地址处的数据
  597. originalData, err := readData(pid, targetAddr)
  598. if err != nil {
  599. return err
  600. }
  601. // 更新数据中的目标偏移
  602. updatedData := (originalData & 0xFFFFFFFF00000000) | uint64(newOffset&0xFFFFFFFF)
  603. err = writeData(pid, targetAddr, updatedData)
  604. if err != nil {
  605. return err
  606. }
  607. return nil
  608. }
  609. func modifyNetSetTargetAddr(pid int, sendDebugAddr, sendReleaseAddr uintptr) error {
  610. sendOffset := sendReleaseAddr - sendDebugAddr - 5
  611. // 读取原始数据
  612. alignedAddr := sendDebugAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  613. originalData, err := readData(pid, alignedAddr)
  614. if err != nil {
  615. return err
  616. }
  617. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  618. offsetLocation := (sendDebugAddr % uintptr(unsafe.Sizeof(uintptr(0)))) + 1
  619. *(*uint32)(unsafe.Pointer(&bytes[offsetLocation])) = uint32(sendOffset)
  620. err = writeData(pid, alignedAddr, originalData)
  621. if err != nil {
  622. return err
  623. }
  624. return nil
  625. }
  626. func modifyReleaseFuncEnter(pid int, originEnterAddr, debugEnterAddr uintptr) error {
  627. offset := debugEnterAddr - (originEnterAddr + 5)
  628. // 读取原始数据
  629. alignedAddr := originEnterAddr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  630. originalData, err := readData(pid, alignedAddr)
  631. if err != nil {
  632. return err
  633. }
  634. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  635. bytes[originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0)))] = 0xe9
  636. *(*uint32)(unsafe.Pointer(&bytes[(originEnterAddr%uintptr(unsafe.Sizeof(uintptr(0))))+1])) = uint32(offset)
  637. err = writeData(pid, alignedAddr, originalData)
  638. if err != nil {
  639. return err
  640. }
  641. return nil
  642. }
  643. func restoreOriginalInstructions(pid int, addr uintptr, instructions []byte) error {
  644. alignedAddr := addr & ^(uintptr(unsafe.Sizeof(uintptr(0))) - 1)
  645. originalData, err := readData(pid, alignedAddr)
  646. if err != nil {
  647. return err
  648. }
  649. bytes := (*[8]byte)(unsafe.Pointer(&originalData))
  650. for i := 0; i < len(instructions); i++ {
  651. bytes[addr%uintptr(unsafe.Sizeof(uintptr(0)))+uintptr(i)] = instructions[i]
  652. }
  653. err = writeData(pid, alignedAddr, originalData)
  654. if err != nil {
  655. return err
  656. }
  657. return nil
  658. }
  659. //func main() {
  660. // flag.StringVar(&PID, "p", "", "PID")
  661. // flag.Parse()
  662. // pidStr := PID // 替换为目标进程的 PID
  663. // pid, err := strconv.Atoi(pidStr)
  664. // if err != nil {
  665. // log.Fatalf("Invalid PID: %v", err)
  666. // }
  667. // functionName := "Java_java_net_SocketOutputStream_socketWrite0"
  668. // libraryName := "libnet.so"
  669. //
  670. // cwLibraryName := "cwlibnet.so"
  671. // cwLibraryPath := "/root/cwlibnet.so"
  672. //
  673. // jvmInjector := &JvmInjector{
  674. // pid: pid,
  675. // ReleaseLibNetInfo: LibNetInfo{
  676. // libName: libraryName,
  677. // FuncSymbol: instInfo{
  678. // SymName: functionName,
  679. // },
  680. // },
  681. // DebugLibNetInfo: LibNetInfo{
  682. // // TODO 根据版本设置
  683. // libName: cwLibraryName,
  684. // // TODO 根据版本设置
  685. // libPath: cwLibraryPath,
  686. // FuncSymbol: instInfo{
  687. // SymName: functionName,
  688. // },
  689. // },
  690. // }
  691. //
  692. // err = jvmInject(jvmInjector)
  693. // fmt.Println(err)
  694. //}
  695. func JvmInject(jvmInjector *JvmInjector) error {
  696. pid := jvmInjector.Pid
  697. var err error
  698. err = jvmInjector.findReleaseFuncContextFromLibPath()
  699. // Debug版本无需修改寄存器
  700. // 已经加载so并指令修改正确的
  701. if jvmInjector.PreCheck.EbpfCanInjection {
  702. klog.Infoln("[inject] eBPF can injection.")
  703. return nil
  704. }
  705. if err != nil {
  706. klog.WithError(err).Errorf("[inject] Error message during release phase.")
  707. return err
  708. }
  709. // 原指令校验通过
  710. if !jvmInjector.PreCheck.NeedInjectionCheck {
  711. return err
  712. }
  713. printCodeData(jvmInjector.ReleaseLibNetInfo)
  714. _type, _, err := jvmInjector.findLibBaseByPathFromProcMaps(jvmInjector.DebugLibNetInfo.LibPath)
  715. if err != nil {
  716. // load so
  717. if _type == 1 {
  718. fmt.Println(err, "Load it.")
  719. if jvmInjector.jvmInjectLib() == 0 {
  720. jvmInjector.PreCheck.LoadingCheck = true
  721. } else {
  722. return err
  723. }
  724. }
  725. } else {
  726. jvmInjector.PreCheck.LoadingCheck = true
  727. }
  728. if !jvmInjector.PreCheck.LoadingCheck {
  729. fmt.Println("Failed load so")
  730. return err
  731. }
  732. err = jvmInjector.findDebugFuncContextFromLibPath()
  733. fmt.Println("find debug Context", err)
  734. if err != nil {
  735. return err
  736. }
  737. if !jvmInjector.validateAllPreCheck() {
  738. fmt.Println("failed validateAllPreCheck ", jvmInjector.PreCheck)
  739. return err
  740. }
  741. // 修改
  742. debugFuncEnterAddr := uintptr(jvmInjector.DebugLibNetInfo.FuncSymbol.SymAddr)
  743. debugIoFdAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.IO_fd_fdID.SymAddr)
  744. debugNetSendAddr := uintptr(jvmInjector.DebugLibNetInfo.InnerSymbol.NET_Send.SymAddr)
  745. originFuncEnterAddr := uintptr(jvmInjector.ReleaseLibNetInfo.FuncSymbol.SymAddr)
  746. ioFdReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.IO_fd_fdID.TargetAddr)
  747. netSendReleaseTargetAddr := uintptr(jvmInjector.ReleaseLibNetInfo.InnerSymbol.NET_Send.TargetAddr)
  748. fmt.Printf("<0x%x> -> <0x%x>\n", originFuncEnterAddr, debugFuncEnterAddr)
  749. fmt.Printf("<0x%x> -> <0x%x>\n", debugIoFdAddr, ioFdReleaseTargetAddr)
  750. fmt.Printf("<0x%x> -> <0x%x>\n", debugNetSendAddr, netSendReleaseTargetAddr)
  751. // 附加到目标进程
  752. err = syscall.PtraceAttach(pid)
  753. if err != nil {
  754. fmt.Printf("ptrace ATTACH: %v", err)
  755. }
  756. // 等待目标进程停止
  757. if _, err := syscall.Wait4(pid, nil, 0, nil); err != nil {
  758. fmt.Printf("wait4: %v", err)
  759. return err
  760. }
  761. time.Now().UnixNano()
  762. // 修改目标的内存
  763. err = modifyIoFdTargetAddr(pid, debugIoFdAddr, ioFdReleaseTargetAddr)
  764. if err != nil {
  765. fmt.Println(err)
  766. return err
  767. }
  768. err = modifyNetSetTargetAddr(pid, debugNetSendAddr, netSendReleaseTargetAddr)
  769. fmt.Println(err)
  770. if err != nil {
  771. fmt.Println(err)
  772. return err
  773. }
  774. // 二次效验 读取并验证地址
  775. _, err = jvmInjector.checkDebugFuncSymAfterChange()
  776. printCodeData(jvmInjector.ReleaseLibNetInfo)
  777. printCodeData(jvmInjector.DebugLibNetInfo)
  778. // 效验目标函数内地址是否与预期一致
  779. if !jvmInjector.validateAllModifyCheck() && err == nil {
  780. return err
  781. }
  782. // 更新函数入口
  783. err = modifyReleaseFuncEnter(pid, originFuncEnterAddr, debugFuncEnterAddr)
  784. if err != nil {
  785. fmt.Println(err)
  786. return err
  787. }
  788. // 校验jmp地址修改正确
  789. err = jvmInjector.checkReleaseFuncSymAfterChange()
  790. if err != nil {
  791. fmt.Println(err)
  792. if len(jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode) == 5 {
  793. err = restoreOriginalInstructions(pid, originFuncEnterAddr, jvmInjector.ReleaseLibNetInfo.FuncSymbol.OriginCode)
  794. if err != nil {
  795. fmt.Println(err)
  796. return err
  797. }
  798. }
  799. }
  800. // 恢复执行
  801. if err = syscall.PtraceDetach(pid); err != nil {
  802. fmt.Printf("ptrace DETACH: %v", err)
  803. return err
  804. }
  805. return nil
  806. }