tls.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552
  1. package ebpftracer
  2. import (
  3. "bufio"
  4. "bytes"
  5. "debug/buildinfo"
  6. "debug/elf"
  7. "errors"
  8. "fmt"
  9. "github.com/cilium/ebpf/link"
  10. "github.com/coroot/coroot-node-agent/ebpftracer/tracer"
  11. "github.com/coroot/coroot-node-agent/proc"
  12. . "github.com/coroot/coroot-node-agent/utils/modelse"
  13. klog "github.com/sirupsen/logrus"
  14. "golang.org/x/arch/arm64/arm64asm"
  15. "golang.org/x/arch/x86/x86asm"
  16. "golang.org/x/mod/semver"
  17. "os"
  18. "regexp"
  19. "strconv"
  20. "strings"
  21. )
  22. const (
  23. minSupportedGoVersion = "v1.17.0"
  24. goTlsWriteSymbol = "crypto/tls.(*Conn).Write"
  25. goTlsReadSymbol = "crypto/tls.(*Conn).Read"
  26. goExecute = "runtime.execute"
  27. goNewproc1 = "runtime.newproc1"
  28. goRunqget = "runtime.runqget"
  29. goServeHTTP = "net/http.serverHandler.ServeHTTP"
  30. goTransport = "net/http.(*Transport).roundTrip"
  31. )
  32. var (
  33. opensslVersionRe = regexp.MustCompile(`OpenSSL\s(\d\.\d+\.\d+)`)
  34. )
  35. func (t *Tracer) AttachOpenSslUprobes(pid uint32) ([]link.Link, error) {
  36. if t.DisableL7Tracing() {
  37. return nil, nil
  38. }
  39. libPath, version := getSslLibPathAndVersion(pid)
  40. if libPath == "" || version == "" {
  41. return nil, nil
  42. }
  43. log := func(msg string, err error) {
  44. if err != nil {
  45. for _, s := range []string{"no such file or directory", "no such process", "permission denied"} {
  46. if strings.HasSuffix(err.Error(), s) {
  47. return
  48. }
  49. }
  50. klog.Errorf("pid=%d libssl_version=%s: %s: %s", pid, version, msg, err)
  51. return
  52. }
  53. klog.Infof("pid=%d libssl_version=%s: %s", pid, version, msg)
  54. }
  55. exe, err := link.OpenExecutable(libPath)
  56. if err != nil {
  57. log("failed to open executable", err)
  58. return nil, err
  59. }
  60. var links []link.Link
  61. writeEnter := "openssl_SSL_write_enter"
  62. readEnter := "openssl_SSL_read_enter"
  63. readExEnter := "openssl_SSL_read_ex_enter"
  64. readExit := "openssl_SSL_read_exit"
  65. switch {
  66. case semver.Compare(version, "v3.0.0") >= 0:
  67. writeEnter = "openssl_SSL_write_enter_v3_0"
  68. readEnter = "openssl_SSL_read_enter_v3_0"
  69. readExEnter = "openssl_SSL_read_ex_enter_v3_0"
  70. case semver.Compare(version, "v1.1.1") >= 0:
  71. writeEnter = "openssl_SSL_write_enter_v1_1_1"
  72. readEnter = "openssl_SSL_read_enter_v1_1_1"
  73. readExEnter = "openssl_SSL_read_ex_enter_v1_1_1"
  74. }
  75. type prog struct {
  76. symbol string
  77. uprobe string
  78. uretprobe string
  79. }
  80. progs := []prog{
  81. {symbol: "SSL_write", uprobe: writeEnter},
  82. {symbol: "SSL_read", uprobe: readEnter},
  83. {symbol: "SSL_read", uretprobe: readExit},
  84. }
  85. if semver.Compare(version, "v1.1.1") >= 0 {
  86. progs = append(progs, []prog{
  87. {symbol: "SSL_write_ex", uprobe: writeEnter},
  88. {symbol: "SSL_read_ex", uprobe: readExEnter},
  89. {symbol: "SSL_read_ex", uretprobe: readExit},
  90. }...)
  91. }
  92. for _, p := range progs {
  93. if p.uprobe != "" {
  94. l, err := exe.Uprobe(p.symbol, t.uprobes[p.uprobe], nil)
  95. if err != nil {
  96. //log("failed to attach uprobe", err)
  97. return nil, err
  98. }
  99. links = append(links, l)
  100. }
  101. if p.uretprobe != "" {
  102. l, err := exe.Uretprobe(p.symbol, t.uprobes[p.uretprobe], nil)
  103. if err != nil {
  104. //log("failed to attach uretprobe", err)
  105. return nil, err
  106. }
  107. links = append(links, l)
  108. }
  109. }
  110. //log("libssl uprobes attached", nil)
  111. return links, nil
  112. }
  113. func (t *Tracer) AttachGoTlsUprobes(pid uint32, appInfo *AppInfo, codeType uint16) ([]link.Link, error) {
  114. if t.DisableL7Tracing() {
  115. return nil, nil
  116. }
  117. path := proc.Path(pid, "exe")
  118. instanceID := appInfo.InstanceIdHash.HashtVal
  119. appID := appInfo.AppIdHash.HashtVal
  120. var err error
  121. var name, version string
  122. log := func(msg string, err error) {
  123. if err != nil {
  124. for _, s := range []string{"not a Go executable", "no such file or directory", "no such process", "permission denied"} {
  125. if strings.HasSuffix(err.Error(), s) {
  126. return
  127. }
  128. }
  129. klog.Errorf("pid=%d golang_app=%s golang_version=%s: %s: %s", pid, name, version, msg, err)
  130. return
  131. }
  132. klog.Infof("pid=%d golang_app=%s golang_version=%s: %s", pid, name, version, msg)
  133. }
  134. bi, err := buildinfo.ReadFile(path)
  135. if err != nil {
  136. log("failed to read build info", err)
  137. return nil, err
  138. }
  139. isGolangApp = true
  140. name, err = os.Readlink(path)
  141. if err != nil {
  142. log("failed to read name", err)
  143. return nil, err
  144. }
  145. version = strings.Replace(bi.GoVersion, "go", "v", 1)
  146. if semver.Compare(version, minSupportedGoVersion) < 0 {
  147. log(fmt.Sprintf("go_versions below %s are not supported", minSupportedGoVersion), nil)
  148. return nil, err
  149. }
  150. ef, err := elf.Open(path)
  151. if err != nil {
  152. log("failed to open as elf binary", err)
  153. return nil, err
  154. }
  155. defer ef.Close()
  156. symbols, err := ef.Symbols()
  157. if err != nil {
  158. if errors.Is(err, elf.ErrNoSymbols) {
  159. log("no symbol section", nil)
  160. return nil, err
  161. }
  162. log("failed to read symbols", err)
  163. return nil, err
  164. }
  165. textSection := ef.Section(".text")
  166. if textSection == nil {
  167. log("no text section", nil)
  168. return nil, err
  169. }
  170. textSectionData, err := textSection.Data()
  171. if err != nil {
  172. log("failed to read text section", err)
  173. return nil, err
  174. }
  175. textSectionLen := uint64(len(textSectionData) - 1)
  176. exe, err := link.OpenExecutable(path)
  177. if err != nil {
  178. log("failed to open executable", err)
  179. return nil, err
  180. }
  181. offset, ok := tracer.GetOffset(tracer.NewID("std", "runtime", "g", "goid"), path)
  182. fmt.Println(offset, ok, version)
  183. if ok {
  184. realVersion := strings.Replace(bi.GoVersion, "go", "", 1)
  185. parts := strings.Split(realVersion, ".")
  186. var major, minor, revision int
  187. if len(parts) >= 3 {
  188. major, err = strconv.Atoi(parts[0])
  189. if err != nil {
  190. log("Error converting major version:", err)
  191. return nil, err
  192. }
  193. minor, err = strconv.Atoi(parts[1])
  194. if err != nil {
  195. log("Error converting minor version:", err)
  196. return nil, err
  197. }
  198. revision, err = strconv.Atoi(parts[2])
  199. if err != nil {
  200. log("Error converting revision version:", err)
  201. return nil, err
  202. }
  203. goVersion := ((major & 0xFF) << 16) + ((minor & 0xFF) << 8) + min(revision, 255)
  204. info := EbpfProcInfo{}
  205. info.Version = uint32(goVersion)
  206. info.Offsets[OFFSET_IDX_GOID_RUNTIME_G] = uint16(offset)
  207. info.NetTCPConnItab = uint64(0)
  208. info.CryptoTLSConnItab = uint64(0)
  209. info.CredentialsSyscallConnItab = uint64(0)
  210. info.InstanceId = instanceID
  211. info.AppId = appID
  212. // go
  213. info.MethodPtrPos = uint64(0)
  214. info.UrlPtrPos = uint64(16)
  215. info.PathPtrPos = uint64(56)
  216. info.StatusCodePos = uint64(120)
  217. info.RequestHostPos = uint64(128)
  218. info.ProtoPos = uint64(24)
  219. info.CtxPtrPos = uint64(232)
  220. info.HeadersPtrPos = uint64(56)
  221. info.BucketsPtrPos = uint64(16)
  222. info.CodeType = codeType
  223. // 获取内存地址
  224. allocDetails, err := tracer.Allocate(int(pid))
  225. if err == nil && allocDetails != nil {
  226. info.StartAddr = allocDetails.StartAddr
  227. info.EndAddr = allocDetails.EndAddr
  228. }
  229. klog.Infoln("Major:", major)
  230. klog.Infoln("Minor:", minor)
  231. klog.Infoln("Revision:", revision)
  232. klog.Infoln("goVersion", goVersion)
  233. klog.Infoln("info.StartAddr", info.StartAddr)
  234. klog.Infoln("info.EndAddr", info.EndAddr)
  235. _, err = tracer.UpdateProcInfoToMap(t.collection, pid, info)
  236. if err != nil {
  237. klog.Error("failed to update program info", err)
  238. return nil, err
  239. }
  240. appInfo.EBPFProcInfo = &info
  241. }
  242. }
  243. var links []link.Link
  244. for _, s := range symbols {
  245. if elf.ST_TYPE(s.Info) != elf.STT_FUNC || s.Size == 0 {
  246. continue
  247. }
  248. switch s.Name {
  249. //case goTlsWriteSymbol, goTlsReadSymbol:
  250. case goExecute, goNewproc1, goRunqget, goServeHTTP, goTransport:
  251. default:
  252. continue
  253. }
  254. address := s.Value
  255. for _, p := range ef.Progs {
  256. if p.Type != elf.PT_LOAD || (p.Flags&elf.PF_X) == 0 {
  257. continue
  258. }
  259. if p.Vaddr <= s.Value && s.Value < (p.Vaddr+p.Memsz) {
  260. address = s.Value - p.Vaddr + p.Off
  261. break
  262. }
  263. }
  264. //fmt.Println("s.Name-----:", s.Name)
  265. switch s.Name {
  266. case goExecute:
  267. l, err := exe.Uprobe(s.Name, t.uprobes["runtime_execute"], &link.UprobeOptions{Address: address})
  268. if err != nil {
  269. log("failed to attach write_enter uprobe", err)
  270. klog.Infoln("runtime.execute no")
  271. return nil, err
  272. } else {
  273. klog.Infoln("runtime.execute ok")
  274. }
  275. links = append(links, l)
  276. case goNewproc1:
  277. l, err := exe.Uprobe(s.Name, t.uprobes["enter_runtime_newproc1"], &link.UprobeOptions{Address: address})
  278. if err != nil {
  279. log("failed to attach newproc1 uprobe", err)
  280. return nil, err
  281. }
  282. links = append(links, l)
  283. sStart := s.Value - textSection.Addr
  284. sEnd := sStart + s.Size
  285. if sEnd > textSectionLen {
  286. continue
  287. }
  288. sBytes := textSectionData[sStart:sEnd]
  289. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  290. if len(returnOffsets) == 0 {
  291. log("failed to attach enter_runtime_newproc1 uprobe", fmt.Errorf("no return offsets found"))
  292. return nil, err
  293. }
  294. for _, offset := range returnOffsets {
  295. l, err := exe.Uprobe(s.Name, t.uprobes["exit_runtime_newproc1"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  296. if err != nil {
  297. log("failed to attach exit_runtime_newproc1 uprobe", err)
  298. return nil, err
  299. }
  300. links = append(links, l)
  301. }
  302. case goRunqget:
  303. l, err := exe.Uprobe(s.Name, t.uprobes["enter_runtime_runqget"], &link.UprobeOptions{Address: address})
  304. if err != nil {
  305. log("failed to attach goRunqget uprobe", err)
  306. return nil, err
  307. }
  308. links = append(links, l)
  309. //sStart := s.Value - textSection.Addr
  310. //sEnd := sStart + s.Size
  311. //if sEnd > textSectionLen {
  312. // continue
  313. //}
  314. //sBytes := textSectionData[sStart:sEnd]
  315. //returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  316. //if len(returnOffsets) == 0 {
  317. // log("failed to attach enter_runtime_newproc1 uprobe", fmt.Errorf("no return offsets found"))
  318. // return nil
  319. //}
  320. //for _, offset := range returnOffsets {
  321. // l, err := exe.Uprobe(s.Name, t.uprobes["exit_runtime_newproc1"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  322. // if err != nil {
  323. // log("failed to attach exit_runtime_newproc1 uprobe", err)
  324. // return nil
  325. // }
  326. // links = append(links, l)
  327. //}
  328. case goServeHTTP:
  329. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_HandlerFunc_ServeHTTP"], &link.UprobeOptions{Address: address})
  330. if err != nil {
  331. klog.WithError(err).Errorln("failed to attach uprobe_HandlerFunc_ServeHTTP uprobe")
  332. continue
  333. }
  334. klog.Infoln("net/http.serverHandler.ServeHTTP ok")
  335. links = append(links, l)
  336. sStart := s.Value - textSection.Addr
  337. sEnd := sStart + s.Size
  338. if sEnd > textSectionLen {
  339. continue
  340. }
  341. sBytes := textSectionData[sStart:sEnd]
  342. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  343. if len(returnOffsets) == 0 {
  344. err = fmt.Errorf("failed to attach uprobe_HandlerFunc_ServeHTTP no return offsets found")
  345. klog.Errorln(err)
  346. return nil, err
  347. }
  348. for _, offset := range returnOffsets {
  349. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_HandlerFunc_ServeHTTP_Returns"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  350. if err != nil {
  351. klog.WithError(err).Errorln(fmt.Errorf("failed to attach exit_runtime_newproc1 uprobe"))
  352. return nil, err
  353. }
  354. links = append(links, l)
  355. }
  356. case goTransport:
  357. if t.DisableE2ETracing() {
  358. continue
  359. }
  360. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_Transport_roundTrip"], &link.UprobeOptions{Address: address})
  361. if err != nil {
  362. klog.WithError(err).Errorln(fmt.Errorf("failed to attach write_enter uprobe"))
  363. continue
  364. } else {
  365. }
  366. klog.Infoln("net/http.uprobe_Transport_roundTrip ok")
  367. links = append(links, l)
  368. sStart := s.Value - textSection.Addr
  369. sEnd := sStart + s.Size
  370. if sEnd > textSectionLen {
  371. continue
  372. }
  373. sBytes := textSectionData[sStart:sEnd]
  374. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  375. if len(returnOffsets) == 0 {
  376. err = fmt.Errorf("failed to attach uprobe_Transport_roundTrip uprobe no return offsets found")
  377. klog.Errorln(err)
  378. return nil, err
  379. }
  380. for _, offset := range returnOffsets {
  381. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_Transport_roundTrip_Returns"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  382. if err != nil {
  383. klog.WithError(err).Errorln("failed to attach exit_runtime_newproc1 uprobe")
  384. return nil, err
  385. }
  386. links = append(links, l)
  387. }
  388. case goTlsWriteSymbol:
  389. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_write_enter"], &link.UprobeOptions{Address: address})
  390. if err != nil {
  391. klog.WithError(err).Errorln("failed to attach write_enter uprobe")
  392. return nil, err
  393. }
  394. links = append(links, l)
  395. case goTlsReadSymbol:
  396. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_enter"], &link.UprobeOptions{Address: address})
  397. if err != nil {
  398. klog.WithError(err).Errorln("failed to attach read_enter uprobe")
  399. return nil, err
  400. }
  401. links = append(links, l)
  402. sStart := s.Value - textSection.Addr
  403. sEnd := sStart + s.Size
  404. if sEnd > textSectionLen {
  405. continue
  406. }
  407. sBytes := textSectionData[sStart:sEnd]
  408. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  409. if len(returnOffsets) == 0 {
  410. err = fmt.Errorf("failed to attach read_exit uprobe no return offsets found")
  411. klog.Errorln(err)
  412. return nil, err
  413. }
  414. for _, offset := range returnOffsets {
  415. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_exit"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  416. if err != nil {
  417. klog.WithError(err).Errorln("failed to attach read_exit uprobe")
  418. return nil, err
  419. }
  420. links = append(links, l)
  421. }
  422. }
  423. }
  424. if len(links) == 0 {
  425. return nil, err
  426. }
  427. klog.Infoln("crypto/tls uprobes attached")
  428. return links, nil
  429. }
  430. func getSslLibPathAndVersion(pid uint32) (string, string) {
  431. f, err := os.Open(proc.Path(pid, "maps"))
  432. if err != nil {
  433. return "", ""
  434. }
  435. defer f.Close()
  436. scanner := bufio.NewScanner(f)
  437. scanner.Split(bufio.ScanLines)
  438. var libsslPath, libcryptoPath string
  439. for scanner.Scan() {
  440. parts := strings.Fields(scanner.Text())
  441. if len(parts) <= 5 {
  442. continue
  443. }
  444. libPath := parts[5]
  445. switch {
  446. case libsslPath == "" && strings.Contains(libPath, "libssl.so"):
  447. fullPath := proc.Path(pid, "root", libPath)
  448. if _, err = os.Stat(fullPath); err == nil {
  449. libsslPath = fullPath
  450. }
  451. case libcryptoPath == "" && strings.Contains(libPath, "libcrypto.so"):
  452. fullPath := proc.Path(pid, "root", libPath)
  453. if _, err = os.Stat(fullPath); err == nil {
  454. libcryptoPath = fullPath
  455. }
  456. default:
  457. continue
  458. }
  459. if libsslPath != "" && libcryptoPath != "" {
  460. break
  461. }
  462. }
  463. if libsslPath == "" || libcryptoPath == "" {
  464. return "", ""
  465. }
  466. ef, err := elf.Open(libcryptoPath)
  467. if err != nil {
  468. return "", ""
  469. }
  470. defer ef.Close()
  471. rodataSection := ef.Section(".rodata")
  472. if rodataSection == nil {
  473. return "", ""
  474. }
  475. rodataSectionData, err := rodataSection.Data()
  476. if err != nil {
  477. return "", ""
  478. }
  479. var version string
  480. for _, b := range bytes.Split(rodataSectionData, []byte("\x00")) {
  481. if len(b) == 0 {
  482. continue
  483. }
  484. s := string(b)
  485. if !strings.HasPrefix(s, "OpenSSL") {
  486. continue
  487. }
  488. if m := opensslVersionRe.FindStringSubmatch(s); len(m) > 1 {
  489. version = m[1]
  490. }
  491. }
  492. return libsslPath, "v" + version
  493. }
  494. func getReturnOffsets(machine elf.Machine, instructions []byte) []int {
  495. var res []int
  496. switch machine {
  497. case elf.EM_X86_64:
  498. for i := 0; i < len(instructions); {
  499. ins, err := x86asm.Decode(instructions[i:], 64)
  500. if err == nil && ins.Op == x86asm.RET {
  501. res = append(res, i)
  502. }
  503. i += ins.Len
  504. }
  505. case elf.EM_AARCH64:
  506. for i := 0; i < len(instructions); {
  507. ins, err := arm64asm.Decode(instructions[i:])
  508. if err == nil && ins.Op == arm64asm.RET {
  509. res = append(res, i)
  510. }
  511. i += 4
  512. }
  513. }
  514. return res
  515. }
  516. func min(a, b int) int {
  517. if a < b {
  518. return a
  519. }
  520. return b
  521. }