tls.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535
  1. package ebpftracer
  2. import (
  3. "bufio"
  4. "bytes"
  5. "debug/buildinfo"
  6. "debug/elf"
  7. "errors"
  8. "fmt"
  9. "github.com/coroot/coroot-node-agent/ebpftracer/tracer"
  10. "github.com/coroot/coroot-node-agent/utils"
  11. "os"
  12. "regexp"
  13. "strconv"
  14. "strings"
  15. "github.com/cilium/ebpf/link"
  16. "github.com/coroot/coroot-node-agent/proc"
  17. "golang.org/x/arch/arm64/arm64asm"
  18. "golang.org/x/arch/x86/x86asm"
  19. "golang.org/x/mod/semver"
  20. "k8s.io/klog/v2"
  21. )
  22. const (
  23. minSupportedGoVersion = "v1.17.0"
  24. goTlsWriteSymbol = "crypto/tls.(*Conn).Write"
  25. goTlsReadSymbol = "crypto/tls.(*Conn).Read"
  26. goExecute = "runtime.execute"
  27. goNewproc1 = "runtime.newproc1"
  28. goRunqget = "runtime.runqget"
  29. goServeHTTP = "net/http.serverHandler.ServeHTTP"
  30. goTransport = "net/http.(*Transport).roundTrip"
  31. )
  32. var (
  33. opensslVersionRe = regexp.MustCompile(`OpenSSL\s(\d\.\d+\.\d+)`)
  34. )
  35. func (t *Tracer) AttachOpenSslUprobes(pid uint32) []link.Link {
  36. if t.disableL7Tracing {
  37. return nil
  38. }
  39. libPath, version := getSslLibPathAndVersion(pid)
  40. if libPath == "" || version == "" {
  41. return nil
  42. }
  43. log := func(msg string, err error) {
  44. if err != nil {
  45. for _, s := range []string{"no such file or directory", "no such process", "permission denied"} {
  46. if strings.HasSuffix(err.Error(), s) {
  47. return
  48. }
  49. }
  50. klog.ErrorfDepth(1, "pid=%d libssl_version=%s: %s: %s", pid, version, msg, err)
  51. return
  52. }
  53. klog.InfofDepth(1, "pid=%d libssl_version=%s: %s", pid, version, msg)
  54. }
  55. exe, err := link.OpenExecutable(libPath)
  56. if err != nil {
  57. log("failed to open executable", err)
  58. return nil
  59. }
  60. var links []link.Link
  61. writeEnter := "openssl_SSL_write_enter"
  62. readEnter := "openssl_SSL_read_enter"
  63. readExEnter := "openssl_SSL_read_ex_enter"
  64. readExit := "openssl_SSL_read_exit"
  65. switch {
  66. case semver.Compare(version, "v3.0.0") >= 0:
  67. writeEnter = "openssl_SSL_write_enter_v3_0"
  68. readEnter = "openssl_SSL_read_enter_v3_0"
  69. readExEnter = "openssl_SSL_read_ex_enter_v3_0"
  70. case semver.Compare(version, "v1.1.1") >= 0:
  71. writeEnter = "openssl_SSL_write_enter_v1_1_1"
  72. readEnter = "openssl_SSL_read_enter_v1_1_1"
  73. readExEnter = "openssl_SSL_read_ex_enter_v1_1_1"
  74. }
  75. type prog struct {
  76. symbol string
  77. uprobe string
  78. uretprobe string
  79. }
  80. progs := []prog{
  81. {symbol: "SSL_write", uprobe: writeEnter},
  82. {symbol: "SSL_write_ex", uprobe: writeEnter},
  83. {symbol: "SSL_read", uprobe: readEnter},
  84. {symbol: "SSL_read_ex", uprobe: readExEnter},
  85. {symbol: "SSL_read", uretprobe: readExit},
  86. {symbol: "SSL_read_ex", uretprobe: readExit},
  87. }
  88. for _, p := range progs {
  89. if p.uprobe != "" {
  90. l, err := exe.Uprobe(p.symbol, t.uprobes[p.uprobe], nil)
  91. if err != nil {
  92. //log("failed to attach uprobe", err)
  93. return nil
  94. }
  95. links = append(links, l)
  96. }
  97. if p.uretprobe != "" {
  98. l, err := exe.Uretprobe(p.symbol, t.uprobes[p.uretprobe], nil)
  99. if err != nil {
  100. //log("failed to attach uretprobe", err)
  101. return nil
  102. }
  103. links = append(links, l)
  104. }
  105. }
  106. //log("libssl uprobes attached", nil)
  107. return links
  108. }
  109. func (t *Tracer) AttachGoTlsUprobes(pid uint32, insID utils.ID) []link.Link {
  110. if t.disableL7Tracing {
  111. return nil
  112. }
  113. path := proc.Path(pid, "exe")
  114. var err error
  115. var name, version string
  116. log := func(msg string, err error) {
  117. if err != nil {
  118. for _, s := range []string{"not a Go executable", "no such file or directory", "no such process", "permission denied"} {
  119. if strings.HasSuffix(err.Error(), s) {
  120. return
  121. }
  122. }
  123. klog.ErrorfDepth(1, "pid=%d golang_app=%s golang_version=%s: %s: %s", pid, name, version, msg, err)
  124. return
  125. }
  126. klog.InfofDepth(1, "pid=%d golang_app=%s golang_version=%s: %s", pid, name, version, msg)
  127. }
  128. bi, err := buildinfo.ReadFile(path)
  129. if err != nil {
  130. log("failed to read build info", err)
  131. return nil
  132. }
  133. name, err = os.Readlink(path)
  134. if err != nil {
  135. log("failed to read name", err)
  136. return nil
  137. }
  138. version = strings.Replace(bi.GoVersion, "go", "v", 1)
  139. if semver.Compare(version, minSupportedGoVersion) < 0 {
  140. log(fmt.Sprintf("go_versions below %s are not supported", minSupportedGoVersion), nil)
  141. return nil
  142. }
  143. ef, err := elf.Open(path)
  144. if err != nil {
  145. log("failed to open as elf binary", err)
  146. return nil
  147. }
  148. defer ef.Close()
  149. symbols, err := ef.Symbols()
  150. if err != nil {
  151. if errors.Is(err, elf.ErrNoSymbols) {
  152. log("no symbol section", nil)
  153. return nil
  154. }
  155. log("failed to read symbols", err)
  156. return nil
  157. }
  158. textSection := ef.Section(".text")
  159. if textSection == nil {
  160. log("no text section", nil)
  161. return nil
  162. }
  163. textSectionData, err := textSection.Data()
  164. if err != nil {
  165. log("failed to read text section", err)
  166. return nil
  167. }
  168. textSectionLen := uint64(len(textSectionData) - 1)
  169. exe, err := link.OpenExecutable(path)
  170. if err != nil {
  171. log("failed to open executable", err)
  172. return nil
  173. }
  174. offset, ok := tracer.GetOffset(tracer.NewID("std", "runtime", "g", "goid"), path)
  175. //pOffset, ok2 := tracer.GetOffset(tracer.NewID("std", "runtime", "p", "goidcache"), path)
  176. //runnextOffset, ok3 := tracer.GetOffset(tracer.NewID("std", "runtime", "p", "runnext"), path)
  177. //if ok3 {
  178. //
  179. //}
  180. fmt.Println(offset, ok, version)
  181. //fmt.Println(runnextOffset, ok3, version)
  182. //os.Exit(1)
  183. if ok {
  184. realVersion := strings.Replace(bi.GoVersion, "go", "", 1)
  185. parts := strings.Split(realVersion, ".")
  186. var major, minor, revision int
  187. if len(parts) >= 3 {
  188. major, err = strconv.Atoi(parts[0])
  189. if err != nil {
  190. log("Error converting major version:", err)
  191. }
  192. minor, err = strconv.Atoi(parts[1])
  193. if err != nil {
  194. log("Error converting minor version:", err)
  195. }
  196. revision, err = strconv.Atoi(parts[2])
  197. if err != nil {
  198. log("Error converting revision version:", err)
  199. }
  200. goVersion := ((major & 0xFF) << 16) + ((minor & 0xFF) << 8) + min(revision, 255)
  201. info := tracer.EbpfProcInfo{}
  202. info.Version = uint32(goVersion)
  203. info.Offsets[tracer.OFFSET_IDX_GOID_RUNTIME_G] = uint16(offset)
  204. info.NetTCPConnItab = uint64(0)
  205. info.CryptoTLSConnItab = uint64(0)
  206. info.CredentialsSyscallConnItab = uint64(0)
  207. info.InstanceId = insID.HashtVal
  208. // 获取内存地址
  209. allocDetails, err := tracer.Allocate(int(pid))
  210. if err == nil && allocDetails != nil {
  211. info.StartAddr = allocDetails.StartAddr
  212. info.EndAddr = allocDetails.EndAddr
  213. }
  214. klog.Infoln("Major:", major)
  215. klog.Infoln("Minor:", minor)
  216. klog.Infoln("Revision:", revision)
  217. klog.Infoln("goVersion", goVersion)
  218. klog.Infoln("info.StartAddr", info.StartAddr)
  219. klog.Infoln("info.EndAddr", info.EndAddr)
  220. _, err = tracer.UpdateProcInfoToMap(t.collection, pid, info)
  221. if err != nil {
  222. klog.Error("failed to update program info", err)
  223. }
  224. }
  225. }
  226. var links []link.Link
  227. for _, s := range symbols {
  228. if elf.ST_TYPE(s.Info) != elf.STT_FUNC || s.Size == 0 {
  229. continue
  230. }
  231. switch s.Name {
  232. //case goTlsWriteSymbol, goTlsReadSymbol:
  233. case goExecute, goNewproc1, goRunqget, goServeHTTP, goTransport:
  234. default:
  235. continue
  236. }
  237. address := s.Value
  238. for _, p := range ef.Progs {
  239. if p.Type != elf.PT_LOAD || (p.Flags&elf.PF_X) == 0 {
  240. continue
  241. }
  242. if p.Vaddr <= s.Value && s.Value < (p.Vaddr+p.Memsz) {
  243. address = s.Value - p.Vaddr + p.Off
  244. break
  245. }
  246. }
  247. //fmt.Println("s.Name-----:", s.Name)
  248. switch s.Name {
  249. case goExecute:
  250. l, err := exe.Uprobe(s.Name, t.uprobes["runtime_execute"], &link.UprobeOptions{Address: address})
  251. if err != nil {
  252. log("failed to attach write_enter uprobe", err)
  253. klog.Infoln("runtime.execute no")
  254. return nil
  255. } else {
  256. klog.Infoln("runtime.execute ok")
  257. }
  258. links = append(links, l)
  259. case goNewproc1:
  260. l, err := exe.Uprobe(s.Name, t.uprobes["enter_runtime_newproc1"], &link.UprobeOptions{Address: address})
  261. if err != nil {
  262. log("failed to attach newproc1 uprobe", err)
  263. return nil
  264. }
  265. links = append(links, l)
  266. sStart := s.Value - textSection.Addr
  267. sEnd := sStart + s.Size
  268. if sEnd > textSectionLen {
  269. continue
  270. }
  271. sBytes := textSectionData[sStart:sEnd]
  272. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  273. if len(returnOffsets) == 0 {
  274. log("failed to attach enter_runtime_newproc1 uprobe", fmt.Errorf("no return offsets found"))
  275. return nil
  276. }
  277. for _, offset := range returnOffsets {
  278. l, err := exe.Uprobe(s.Name, t.uprobes["exit_runtime_newproc1"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  279. if err != nil {
  280. log("failed to attach exit_runtime_newproc1 uprobe", err)
  281. return nil
  282. }
  283. links = append(links, l)
  284. }
  285. case goRunqget:
  286. l, err := exe.Uprobe(s.Name, t.uprobes["enter_runtime_runqget"], &link.UprobeOptions{Address: address})
  287. if err != nil {
  288. log("failed to attach newproc1 uprobe", err)
  289. return nil
  290. }
  291. links = append(links, l)
  292. //sStart := s.Value - textSection.Addr
  293. //sEnd := sStart + s.Size
  294. //if sEnd > textSectionLen {
  295. // continue
  296. //}
  297. //sBytes := textSectionData[sStart:sEnd]
  298. //returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  299. //if len(returnOffsets) == 0 {
  300. // log("failed to attach enter_runtime_newproc1 uprobe", fmt.Errorf("no return offsets found"))
  301. // return nil
  302. //}
  303. //for _, offset := range returnOffsets {
  304. // l, err := exe.Uprobe(s.Name, t.uprobes["exit_runtime_newproc1"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  305. // if err != nil {
  306. // log("failed to attach exit_runtime_newproc1 uprobe", err)
  307. // return nil
  308. // }
  309. // links = append(links, l)
  310. //}
  311. case goServeHTTP:
  312. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_HandlerFunc_ServeHTTP"], &link.UprobeOptions{Address: address})
  313. if err != nil {
  314. log("failed to attach write_enter uprobe", err)
  315. fmt.Println("net/http.serverHandler.ServeHTTP no")
  316. fmt.Println(err)
  317. continue
  318. } else {
  319. fmt.Println("net/http.serverHandler.ServeHTTP ok")
  320. }
  321. links = append(links, l)
  322. sStart := s.Value - textSection.Addr
  323. sEnd := sStart + s.Size
  324. if sEnd > textSectionLen {
  325. continue
  326. }
  327. sBytes := textSectionData[sStart:sEnd]
  328. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  329. if len(returnOffsets) == 0 {
  330. log("failed to attach uprobe_HandlerFunc_ServeHTTP uprobe", fmt.Errorf("no return offsets found"))
  331. return nil
  332. }
  333. for _, offset := range returnOffsets {
  334. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_HandlerFunc_ServeHTTP_Returns"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  335. if err != nil {
  336. log("failed to attach exit_runtime_newproc1 uprobe", err)
  337. return nil
  338. }
  339. links = append(links, l)
  340. }
  341. case goTransport:
  342. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_Transport_roundTrip"], &link.UprobeOptions{Address: address})
  343. if err != nil {
  344. log("failed to attach write_enter uprobe", err)
  345. fmt.Println("net/http.uprobe_Transport_roundTrip no")
  346. fmt.Println(err)
  347. continue
  348. } else {
  349. fmt.Println("net/http.uprobe_Transport_roundTrip ok")
  350. }
  351. links = append(links, l)
  352. sStart := s.Value - textSection.Addr
  353. sEnd := sStart + s.Size
  354. if sEnd > textSectionLen {
  355. continue
  356. }
  357. sBytes := textSectionData[sStart:sEnd]
  358. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  359. if len(returnOffsets) == 0 {
  360. log("failed to attach uprobe_Transport_roundTrip uprobe", fmt.Errorf("no return offsets found"))
  361. return nil
  362. }
  363. for _, offset := range returnOffsets {
  364. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_Transport_roundTrip_Returns"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  365. if err != nil {
  366. log("failed to attach exit_runtime_newproc1 uprobe", err)
  367. return nil
  368. }
  369. links = append(links, l)
  370. }
  371. case goTlsWriteSymbol:
  372. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_write_enter"], &link.UprobeOptions{Address: address})
  373. if err != nil {
  374. log("failed to attach write_enter uprobe", err)
  375. return nil
  376. }
  377. links = append(links, l)
  378. case goTlsReadSymbol:
  379. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_enter"], &link.UprobeOptions{Address: address})
  380. if err != nil {
  381. log("failed to attach read_enter uprobe", err)
  382. return nil
  383. }
  384. links = append(links, l)
  385. sStart := s.Value - textSection.Addr
  386. sEnd := sStart + s.Size
  387. if sEnd > textSectionLen {
  388. continue
  389. }
  390. sBytes := textSectionData[sStart:sEnd]
  391. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  392. if len(returnOffsets) == 0 {
  393. log("failed to attach read_exit uprobe", fmt.Errorf("no return offsets found"))
  394. return nil
  395. }
  396. for _, offset := range returnOffsets {
  397. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_exit"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  398. if err != nil {
  399. log("failed to attach read_exit uprobe", err)
  400. return nil
  401. }
  402. links = append(links, l)
  403. }
  404. }
  405. }
  406. if len(links) == 0 {
  407. return nil
  408. }
  409. log("crypto/tls uprobes attached", nil)
  410. return links
  411. }
  412. func getSslLibPathAndVersion(pid uint32) (string, string) {
  413. f, err := os.Open(proc.Path(pid, "maps"))
  414. if err != nil {
  415. return "", ""
  416. }
  417. defer f.Close()
  418. scanner := bufio.NewScanner(f)
  419. scanner.Split(bufio.ScanLines)
  420. var libsslPath, libcryptoPath string
  421. for scanner.Scan() {
  422. parts := strings.Fields(scanner.Text())
  423. if len(parts) <= 5 {
  424. continue
  425. }
  426. libPath := parts[5]
  427. switch {
  428. case libsslPath == "" && strings.Contains(libPath, "libssl.so"):
  429. fullPath := proc.Path(pid, "root", libPath)
  430. if _, err = os.Stat(fullPath); err == nil {
  431. libsslPath = fullPath
  432. }
  433. case libcryptoPath == "" && strings.Contains(libPath, "libcrypto.so"):
  434. fullPath := proc.Path(pid, "root", libPath)
  435. if _, err = os.Stat(fullPath); err == nil {
  436. libcryptoPath = fullPath
  437. }
  438. default:
  439. continue
  440. }
  441. if libsslPath != "" && libcryptoPath != "" {
  442. break
  443. }
  444. }
  445. if libsslPath == "" || libcryptoPath == "" {
  446. return "", ""
  447. }
  448. ef, err := elf.Open(libcryptoPath)
  449. if err != nil {
  450. return "", ""
  451. }
  452. defer ef.Close()
  453. rodataSection := ef.Section(".rodata")
  454. if rodataSection == nil {
  455. return "", ""
  456. }
  457. rodataSectionData, err := rodataSection.Data()
  458. if err != nil {
  459. return "", ""
  460. }
  461. var version string
  462. for _, b := range bytes.Split(rodataSectionData, []byte("\x00")) {
  463. if len(b) == 0 {
  464. continue
  465. }
  466. s := string(b)
  467. if !strings.HasPrefix(s, "OpenSSL") {
  468. continue
  469. }
  470. if m := opensslVersionRe.FindStringSubmatch(s); len(m) > 1 {
  471. version = m[1]
  472. }
  473. }
  474. return libsslPath, "v" + version
  475. }
  476. func getReturnOffsets(machine elf.Machine, instructions []byte) []int {
  477. var res []int
  478. switch machine {
  479. case elf.EM_X86_64:
  480. for i := 0; i < len(instructions); {
  481. ins, err := x86asm.Decode(instructions[i:], 64)
  482. if err == nil && ins.Op == x86asm.RET {
  483. res = append(res, i)
  484. }
  485. i += ins.Len
  486. }
  487. case elf.EM_AARCH64:
  488. for i := 0; i < len(instructions); {
  489. ins, err := arm64asm.Decode(instructions[i:])
  490. if err == nil && ins.Op == arm64asm.RET {
  491. res = append(res, i)
  492. }
  493. i += 4
  494. }
  495. }
  496. return res
  497. }
  498. func min(a, b int) int {
  499. if a < b {
  500. return a
  501. }
  502. return b
  503. }