tls.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489
  1. package ebpftracer
  2. import (
  3. "bufio"
  4. "bytes"
  5. "debug/buildinfo"
  6. "debug/elf"
  7. "errors"
  8. "fmt"
  9. "github.com/coroot/coroot-node-agent/ebpftracer/tracer"
  10. "os"
  11. "regexp"
  12. "strconv"
  13. "strings"
  14. "github.com/cilium/ebpf/link"
  15. "github.com/coroot/coroot-node-agent/proc"
  16. "golang.org/x/arch/arm64/arm64asm"
  17. "golang.org/x/arch/x86/x86asm"
  18. "golang.org/x/mod/semver"
  19. "k8s.io/klog/v2"
  20. )
  21. const (
  22. minSupportedGoVersion = "v1.17.0"
  23. goTlsWriteSymbol = "crypto/tls.(*Conn).Write"
  24. goTlsReadSymbol = "crypto/tls.(*Conn).Read"
  25. goExecute = "runtime.execute"
  26. goNewproc1 = "runtime.newproc1"
  27. goServeHTTP = "net/http.serverHandler.ServeHTTP"
  28. goTransport = "net/http.(*Transport).roundTrip"
  29. )
  30. var (
  31. opensslVersionRe = regexp.MustCompile(`OpenSSL\s(\d\.\d+\.\d+)`)
  32. )
  33. func (t *Tracer) AttachOpenSslUprobes(pid uint32) []link.Link {
  34. if t.disableL7Tracing {
  35. return nil
  36. }
  37. libPath, version := getSslLibPathAndVersion(pid)
  38. if libPath == "" || version == "" {
  39. return nil
  40. }
  41. log := func(msg string, err error) {
  42. if err != nil {
  43. for _, s := range []string{"no such file or directory", "no such process", "permission denied"} {
  44. if strings.HasSuffix(err.Error(), s) {
  45. return
  46. }
  47. }
  48. klog.ErrorfDepth(1, "pid=%d libssl_version=%s: %s: %s", pid, version, msg, err)
  49. return
  50. }
  51. klog.InfofDepth(1, "pid=%d libssl_version=%s: %s", pid, version, msg)
  52. }
  53. exe, err := link.OpenExecutable(libPath)
  54. if err != nil {
  55. log("failed to open executable", err)
  56. return nil
  57. }
  58. var links []link.Link
  59. writeEnter := "openssl_SSL_write_enter"
  60. readEnter := "openssl_SSL_read_enter"
  61. readExEnter := "openssl_SSL_read_ex_enter"
  62. readExit := "openssl_SSL_read_exit"
  63. switch {
  64. case semver.Compare(version, "v3.0.0") >= 0:
  65. writeEnter = "openssl_SSL_write_enter_v3_0"
  66. readEnter = "openssl_SSL_read_enter_v3_0"
  67. readExEnter = "openssl_SSL_read_ex_enter_v3_0"
  68. case semver.Compare(version, "v1.1.1") >= 0:
  69. writeEnter = "openssl_SSL_write_enter_v1_1_1"
  70. readEnter = "openssl_SSL_read_enter_v1_1_1"
  71. readExEnter = "openssl_SSL_read_ex_enter_v1_1_1"
  72. }
  73. type prog struct {
  74. symbol string
  75. uprobe string
  76. uretprobe string
  77. }
  78. progs := []prog{
  79. {symbol: "SSL_write", uprobe: writeEnter},
  80. {symbol: "SSL_write_ex", uprobe: writeEnter},
  81. {symbol: "SSL_read", uprobe: readEnter},
  82. {symbol: "SSL_read_ex", uprobe: readExEnter},
  83. {symbol: "SSL_read", uretprobe: readExit},
  84. {symbol: "SSL_read_ex", uretprobe: readExit},
  85. }
  86. for _, p := range progs {
  87. if p.uprobe != "" {
  88. l, err := exe.Uprobe(p.symbol, t.uprobes[p.uprobe], nil)
  89. if err != nil {
  90. log("failed to attach uprobe", err)
  91. return nil
  92. }
  93. links = append(links, l)
  94. }
  95. if p.uretprobe != "" {
  96. l, err := exe.Uretprobe(p.symbol, t.uprobes[p.uretprobe], nil)
  97. if err != nil {
  98. log("failed to attach uretprobe", err)
  99. return nil
  100. }
  101. links = append(links, l)
  102. }
  103. }
  104. log("libssl uprobes attached", nil)
  105. return links
  106. }
  107. func (t *Tracer) AttachGoTlsUprobes(pid uint32) []link.Link {
  108. if t.disableL7Tracing {
  109. return nil
  110. }
  111. path := proc.Path(pid, "exe")
  112. var err error
  113. var name, version string
  114. log := func(msg string, err error) {
  115. if err != nil {
  116. for _, s := range []string{"not a Go executable", "no such file or directory", "no such process", "permission denied"} {
  117. if strings.HasSuffix(err.Error(), s) {
  118. return
  119. }
  120. }
  121. klog.ErrorfDepth(1, "pid=%d golang_app=%s golang_version=%s: %s: %s", pid, name, version, msg, err)
  122. return
  123. }
  124. klog.InfofDepth(1, "pid=%d golang_app=%s golang_version=%s: %s", pid, name, version, msg)
  125. }
  126. bi, err := buildinfo.ReadFile(path)
  127. if err != nil {
  128. log("failed to read build info", err)
  129. return nil
  130. }
  131. name, err = os.Readlink(path)
  132. if err != nil {
  133. log("failed to read name", err)
  134. return nil
  135. }
  136. version = strings.Replace(bi.GoVersion, "go", "v", 1)
  137. if semver.Compare(version, minSupportedGoVersion) < 0 {
  138. log(fmt.Sprintf("go_versions below %s are not supported", minSupportedGoVersion), nil)
  139. return nil
  140. }
  141. ef, err := elf.Open(path)
  142. if err != nil {
  143. log("failed to open as elf binary", err)
  144. return nil
  145. }
  146. defer ef.Close()
  147. symbols, err := ef.Symbols()
  148. if err != nil {
  149. if errors.Is(err, elf.ErrNoSymbols) {
  150. log("no symbol section", nil)
  151. return nil
  152. }
  153. log("failed to read symbols", err)
  154. return nil
  155. }
  156. textSection := ef.Section(".text")
  157. if textSection == nil {
  158. log("no text section", nil)
  159. return nil
  160. }
  161. textSectionData, err := textSection.Data()
  162. if err != nil {
  163. log("failed to read text section", err)
  164. return nil
  165. }
  166. textSectionLen := uint64(len(textSectionData) - 1)
  167. exe, err := link.OpenExecutable(path)
  168. if err != nil {
  169. log("failed to open executable", err)
  170. return nil
  171. }
  172. offset, ok := tracer.GetOffset(tracer.NewID("std", "runtime", "g", "goid"), path)
  173. fmt.Println(offset, ok, version)
  174. if ok {
  175. realVersion := strings.Replace(bi.GoVersion, "go", "", 1)
  176. parts := strings.Split(realVersion, ".")
  177. var major, minor, revision int
  178. if len(parts) >= 3 {
  179. major, err = strconv.Atoi(parts[0])
  180. if err != nil {
  181. log("Error converting major version:", err)
  182. }
  183. minor, err = strconv.Atoi(parts[1])
  184. if err != nil {
  185. log("Error converting minor version:", err)
  186. }
  187. revision, err = strconv.Atoi(parts[2])
  188. if err != nil {
  189. log("Error converting revision version:", err)
  190. }
  191. goVersion := ((major & 0xFF) << 16) + ((minor & 0xFF) << 8) + min(revision, 255)
  192. klog.Infoln("Major:", major)
  193. klog.Infoln("Minor:", minor)
  194. klog.Infoln("Revision:", revision)
  195. klog.Infoln("goVersion", goVersion)
  196. info := tracer.EbpfProcInfo{}
  197. info.Version = uint32(goVersion)
  198. info.Offsets[tracer.OFFSET_IDX_GOID_RUNTIME_G] = uint16(offset)
  199. info.NetTCPConnItab = uint64(0)
  200. info.CryptoTLSConnItab = uint64(0)
  201. info.CredentialsSyscallConnItab = uint64(0)
  202. _, err = tracer.UpdateProcInfoToMap(t.collection, pid, info)
  203. if err != nil {
  204. klog.Error("failed to update program info", err)
  205. }
  206. }
  207. }
  208. var links []link.Link
  209. for _, s := range symbols {
  210. if elf.ST_TYPE(s.Info) != elf.STT_FUNC || s.Size == 0 {
  211. continue
  212. }
  213. switch s.Name {
  214. //case goTlsWriteSymbol, goTlsReadSymbol:
  215. case goExecute, goNewproc1, goServeHTTP, goTransport:
  216. default:
  217. continue
  218. }
  219. address := s.Value
  220. for _, p := range ef.Progs {
  221. if p.Type != elf.PT_LOAD || (p.Flags&elf.PF_X) == 0 {
  222. continue
  223. }
  224. if p.Vaddr <= s.Value && s.Value < (p.Vaddr+p.Memsz) {
  225. address = s.Value - p.Vaddr + p.Off
  226. break
  227. }
  228. }
  229. fmt.Println("s.Name-----:", s.Name)
  230. switch s.Name {
  231. case goExecute:
  232. l, err := exe.Uprobe(s.Name, t.uprobes["runtime_execute"], &link.UprobeOptions{Address: address})
  233. if err != nil {
  234. log("failed to attach write_enter uprobe", err)
  235. klog.Infoln("runtime.execute no")
  236. return nil
  237. } else {
  238. klog.Infoln("runtime.execute ok")
  239. }
  240. links = append(links, l)
  241. case goNewproc1:
  242. l, err := exe.Uprobe(s.Name, t.uprobes["enter_runtime_newproc1"], &link.UprobeOptions{Address: address})
  243. if err != nil {
  244. log("failed to attach newproc1 uprobe", err)
  245. return nil
  246. }
  247. links = append(links, l)
  248. sStart := s.Value - textSection.Addr
  249. sEnd := sStart + s.Size
  250. if sEnd > textSectionLen {
  251. continue
  252. }
  253. sBytes := textSectionData[sStart:sEnd]
  254. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  255. if len(returnOffsets) == 0 {
  256. log("failed to attach enter_runtime_newproc1 uprobe", fmt.Errorf("no return offsets found"))
  257. return nil
  258. }
  259. for _, offset := range returnOffsets {
  260. l, err := exe.Uprobe(s.Name, t.uprobes["exit_runtime_newproc1"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  261. if err != nil {
  262. log("failed to attach exit_runtime_newproc1 uprobe", err)
  263. return nil
  264. }
  265. links = append(links, l)
  266. }
  267. case goServeHTTP:
  268. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_HandlerFunc_ServeHTTP"], &link.UprobeOptions{Address: address})
  269. if err != nil {
  270. log("failed to attach write_enter uprobe", err)
  271. fmt.Println("net/http.serverHandler.ServeHTTP no")
  272. fmt.Println(err)
  273. continue
  274. } else {
  275. fmt.Println("net/http.serverHandler.ServeHTTP ok")
  276. }
  277. links = append(links, l)
  278. sStart := s.Value - textSection.Addr
  279. sEnd := sStart + s.Size
  280. if sEnd > textSectionLen {
  281. continue
  282. }
  283. sBytes := textSectionData[sStart:sEnd]
  284. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  285. if len(returnOffsets) == 0 {
  286. log("failed to attach uprobe_HandlerFunc_ServeHTTP uprobe", fmt.Errorf("no return offsets found"))
  287. return nil
  288. }
  289. for _, offset := range returnOffsets {
  290. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_HandlerFunc_ServeHTTP_Returns"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  291. if err != nil {
  292. log("failed to attach exit_runtime_newproc1 uprobe", err)
  293. return nil
  294. }
  295. links = append(links, l)
  296. }
  297. case goTransport:
  298. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_Transport_roundTrip"], &link.UprobeOptions{Address: address})
  299. if err != nil {
  300. log("failed to attach write_enter uprobe", err)
  301. fmt.Println("net/http.uprobe_Transport_roundTrip no")
  302. fmt.Println(err)
  303. continue
  304. } else {
  305. fmt.Println("net/http.uprobe_Transport_roundTrip ok")
  306. }
  307. links = append(links, l)
  308. sStart := s.Value - textSection.Addr
  309. sEnd := sStart + s.Size
  310. if sEnd > textSectionLen {
  311. continue
  312. }
  313. sBytes := textSectionData[sStart:sEnd]
  314. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  315. if len(returnOffsets) == 0 {
  316. log("failed to attach uprobe_Transport_roundTrip uprobe", fmt.Errorf("no return offsets found"))
  317. return nil
  318. }
  319. for _, offset := range returnOffsets {
  320. l, err := exe.Uprobe(s.Name, t.uprobes["uprobe_Transport_roundTrip_Returns"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  321. if err != nil {
  322. log("failed to attach exit_runtime_newproc1 uprobe", err)
  323. return nil
  324. }
  325. links = append(links, l)
  326. }
  327. case goTlsWriteSymbol:
  328. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_write_enter"], &link.UprobeOptions{Address: address})
  329. if err != nil {
  330. log("failed to attach write_enter uprobe", err)
  331. return nil
  332. }
  333. links = append(links, l)
  334. case goTlsReadSymbol:
  335. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_enter"], &link.UprobeOptions{Address: address})
  336. if err != nil {
  337. log("failed to attach read_enter uprobe", err)
  338. return nil
  339. }
  340. links = append(links, l)
  341. sStart := s.Value - textSection.Addr
  342. sEnd := sStart + s.Size
  343. if sEnd > textSectionLen {
  344. continue
  345. }
  346. sBytes := textSectionData[sStart:sEnd]
  347. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  348. if len(returnOffsets) == 0 {
  349. log("failed to attach read_exit uprobe", fmt.Errorf("no return offsets found"))
  350. return nil
  351. }
  352. for _, offset := range returnOffsets {
  353. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_exit"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  354. if err != nil {
  355. log("failed to attach read_exit uprobe", err)
  356. return nil
  357. }
  358. links = append(links, l)
  359. }
  360. }
  361. }
  362. if len(links) == 0 {
  363. return nil
  364. }
  365. log("crypto/tls uprobes attached", nil)
  366. return links
  367. }
  368. func getSslLibPathAndVersion(pid uint32) (string, string) {
  369. f, err := os.Open(proc.Path(pid, "maps"))
  370. if err != nil {
  371. return "", ""
  372. }
  373. defer f.Close()
  374. scanner := bufio.NewScanner(f)
  375. scanner.Split(bufio.ScanLines)
  376. var libsslPath, libcryptoPath string
  377. for scanner.Scan() {
  378. parts := strings.Fields(scanner.Text())
  379. if len(parts) <= 5 {
  380. continue
  381. }
  382. libPath := parts[5]
  383. switch {
  384. case libsslPath == "" && strings.Contains(libPath, "libssl.so"):
  385. fullPath := proc.Path(pid, "root", libPath)
  386. if _, err = os.Stat(fullPath); err == nil {
  387. libsslPath = fullPath
  388. }
  389. case libcryptoPath == "" && strings.Contains(libPath, "libcrypto.so"):
  390. fullPath := proc.Path(pid, "root", libPath)
  391. if _, err = os.Stat(fullPath); err == nil {
  392. libcryptoPath = fullPath
  393. }
  394. default:
  395. continue
  396. }
  397. if libsslPath != "" && libcryptoPath != "" {
  398. break
  399. }
  400. }
  401. if libsslPath == "" || libcryptoPath == "" {
  402. return "", ""
  403. }
  404. ef, err := elf.Open(libcryptoPath)
  405. if err != nil {
  406. return "", ""
  407. }
  408. defer ef.Close()
  409. rodataSection := ef.Section(".rodata")
  410. if rodataSection == nil {
  411. return "", ""
  412. }
  413. rodataSectionData, err := rodataSection.Data()
  414. if err != nil {
  415. return "", ""
  416. }
  417. var version string
  418. for _, b := range bytes.Split(rodataSectionData, []byte("\x00")) {
  419. if len(b) == 0 {
  420. continue
  421. }
  422. s := string(b)
  423. if !strings.HasPrefix(s, "OpenSSL") {
  424. continue
  425. }
  426. if m := opensslVersionRe.FindStringSubmatch(s); len(m) > 1 {
  427. version = m[1]
  428. }
  429. }
  430. return libsslPath, "v" + version
  431. }
  432. func getReturnOffsets(machine elf.Machine, instructions []byte) []int {
  433. var res []int
  434. switch machine {
  435. case elf.EM_X86_64:
  436. for i := 0; i < len(instructions); {
  437. ins, err := x86asm.Decode(instructions[i:], 64)
  438. if err == nil && ins.Op == x86asm.RET {
  439. res = append(res, i)
  440. }
  441. i += ins.Len
  442. }
  443. case elf.EM_AARCH64:
  444. for i := 0; i < len(instructions); {
  445. ins, err := arm64asm.Decode(instructions[i:])
  446. if err == nil && ins.Op == arm64asm.RET {
  447. res = append(res, i)
  448. }
  449. i += 4
  450. }
  451. }
  452. return res
  453. }
  454. func min(a, b int) int {
  455. if a < b {
  456. return a
  457. }
  458. return b
  459. }