tls.go 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381
  1. package ebpftracer
  2. import (
  3. "bufio"
  4. "bytes"
  5. "debug/buildinfo"
  6. "debug/elf"
  7. "errors"
  8. "fmt"
  9. "os"
  10. "regexp"
  11. "strings"
  12. "github.com/cilium/ebpf/link"
  13. "github.com/coroot/coroot-node-agent/proc"
  14. "golang.org/x/arch/arm64/arm64asm"
  15. "golang.org/x/arch/x86/x86asm"
  16. "golang.org/x/mod/semver"
  17. "k8s.io/klog/v2"
  18. )
  19. const (
  20. minSupportedGoVersion = "v1.17.0"
  21. goTlsWriteSymbol = "crypto/tls.(*Conn).Write"
  22. goTlsReadSymbol = "crypto/tls.(*Conn).Read"
  23. )
  24. var (
  25. opensslVersionRe = regexp.MustCompile(`OpenSSL\s(\d\.\d+\.\d+)`)
  26. )
  27. func (t *Tracer) AttachOpenSslUprobes(pid uint32) []link.Link {
  28. if t.disableL7Tracing {
  29. return nil
  30. }
  31. libPath, version := getSslLibPathAndVersion(pid)
  32. if libPath == "" || version == "" {
  33. return nil
  34. }
  35. log := func(msg string, err error) {
  36. if err != nil {
  37. for _, s := range []string{"no such file or directory", "no such process", "permission denied"} {
  38. if strings.HasSuffix(err.Error(), s) {
  39. return
  40. }
  41. }
  42. klog.ErrorfDepth(1, "pid=%d libssl_version=%s: %s: %s", pid, version, msg, err)
  43. return
  44. }
  45. klog.InfofDepth(1, "pid=%d libssl_version=%s: %s", pid, version, msg)
  46. }
  47. exe, err := link.OpenExecutable(libPath)
  48. if err != nil {
  49. log("failed to open executable", err)
  50. return nil
  51. }
  52. var links []link.Link
  53. writeEnter := "openssl_SSL_write_enter"
  54. readEnter := "openssl_SSL_read_enter"
  55. readExEnter := "openssl_SSL_read_ex_enter"
  56. readExit := "openssl_SSL_read_exit"
  57. switch {
  58. case semver.Compare(version, "v3.0.0") >= 0:
  59. writeEnter = "openssl_SSL_write_enter_v3_0"
  60. readEnter = "openssl_SSL_read_enter_v3_0"
  61. readExEnter = "openssl_SSL_read_ex_enter_v3_0"
  62. case semver.Compare(version, "v1.1.1") >= 0:
  63. writeEnter = "openssl_SSL_write_enter_v1_1_1"
  64. readEnter = "openssl_SSL_read_enter_v1_1_1"
  65. readExEnter = "openssl_SSL_read_ex_enter_v1_1_1"
  66. }
  67. type prog struct {
  68. symbol string
  69. uprobe string
  70. uretprobe string
  71. }
  72. progs := []prog{
  73. {symbol: "SSL_write", uprobe: writeEnter},
  74. {symbol: "SSL_write_ex", uprobe: writeEnter},
  75. {symbol: "SSL_read", uprobe: readEnter},
  76. {symbol: "SSL_read_ex", uprobe: readExEnter},
  77. {symbol: "SSL_read", uretprobe: readExit},
  78. {symbol: "SSL_read_ex", uretprobe: readExit},
  79. }
  80. for _, p := range progs {
  81. if p.uprobe != "" {
  82. l, err := exe.Uprobe(p.symbol, t.uprobes[p.uprobe], nil)
  83. if err != nil {
  84. log("failed to attach uprobe", err)
  85. return nil
  86. }
  87. links = append(links, l)
  88. }
  89. if p.uretprobe != "" {
  90. l, err := exe.Uretprobe(p.symbol, t.uprobes[p.uretprobe], nil)
  91. if err != nil {
  92. log("failed to attach uretprobe", err)
  93. return nil
  94. }
  95. links = append(links, l)
  96. }
  97. }
  98. log("libssl uprobes attached", nil)
  99. return links
  100. }
  101. func (t *Tracer) AttachGoTlsUprobes(pid uint32) []link.Link {
  102. if t.disableL7Tracing {
  103. return nil
  104. }
  105. path := proc.Path(pid, "exe")
  106. var err error
  107. var name, version string
  108. log := func(msg string, err error) {
  109. if err != nil {
  110. for _, s := range []string{"not a Go executable", "no such file or directory", "no such process", "permission denied"} {
  111. if strings.HasSuffix(err.Error(), s) {
  112. return
  113. }
  114. }
  115. klog.ErrorfDepth(1, "pid=%d golang_app=%s golang_version=%s: %s: %s", pid, name, version, msg, err)
  116. return
  117. }
  118. klog.InfofDepth(1, "pid=%d golang_app=%s golang_version=%s: %s", pid, name, version, msg)
  119. }
  120. bi, err := buildinfo.ReadFile(path)
  121. if err != nil {
  122. log("failed to read build info", err)
  123. return nil
  124. }
  125. name, err = os.Readlink(path)
  126. if err != nil {
  127. log("failed to read name", err)
  128. return nil
  129. }
  130. version = strings.Replace(bi.GoVersion, "go", "v", 1)
  131. if semver.Compare(version, minSupportedGoVersion) < 0 {
  132. log(fmt.Sprintf("go_versions below %s are not supported", minSupportedGoVersion), nil)
  133. return nil
  134. }
  135. ef, err := elf.Open(path)
  136. if err != nil {
  137. log("failed to open as elf binary", err)
  138. return nil
  139. }
  140. defer ef.Close()
  141. symbols, err := ef.Symbols()
  142. if err != nil {
  143. if errors.Is(err, elf.ErrNoSymbols) {
  144. log("no symbol section", nil)
  145. return nil
  146. }
  147. log("failed to read symbols", err)
  148. return nil
  149. }
  150. textSection := ef.Section(".text")
  151. if textSection == nil {
  152. log("no text section", nil)
  153. return nil
  154. }
  155. textSectionData, err := textSection.Data()
  156. if err != nil {
  157. log("failed to read text section", err)
  158. return nil
  159. }
  160. textSectionLen := uint64(len(textSectionData) - 1)
  161. exe, err := link.OpenExecutable(path)
  162. if err != nil {
  163. log("failed to open executable", err)
  164. return nil
  165. }
  166. var links []link.Link
  167. for _, s := range symbols {
  168. if elf.ST_TYPE(s.Info) != elf.STT_FUNC || s.Size == 0 {
  169. continue
  170. }
  171. switch s.Name {
  172. case goTlsWriteSymbol, goTlsReadSymbol, "runtime.execute", "runtime.newproc1":
  173. default:
  174. continue
  175. }
  176. address := s.Value
  177. for _, p := range ef.Progs {
  178. if p.Type != elf.PT_LOAD || (p.Flags&elf.PF_X) == 0 {
  179. continue
  180. }
  181. if p.Vaddr <= s.Value && s.Value < (p.Vaddr+p.Memsz) {
  182. address = s.Value - p.Vaddr + p.Off
  183. break
  184. }
  185. }
  186. fmt.Println("s.Name-----:", s.Name)
  187. switch s.Name {
  188. case "runtime.execute":
  189. l, err := exe.Uprobe(s.Name, t.uprobes["runtime_execute"], &link.UprobeOptions{Address: address})
  190. if err != nil {
  191. log("failed to attach write_enter uprobe", err)
  192. fmt.Println("runtime.execute no")
  193. fmt.Println(err)
  194. return nil
  195. } else {
  196. fmt.Println("runtime.execute ok")
  197. }
  198. links = append(links, l)
  199. case "runtime.newproc1":
  200. l, err := exe.Uprobe(s.Name, t.uprobes["enter_runtime_newproc1"], &link.UprobeOptions{Address: address})
  201. if err != nil {
  202. log("failed to attach write_enter uprobe", err)
  203. fmt.Println("runtime.newproc1 no")
  204. fmt.Println(err)
  205. return nil
  206. } else {
  207. fmt.Println("runtime.newproc1 ok")
  208. }
  209. links = append(links, l)
  210. sStart := s.Value - textSection.Addr
  211. sEnd := sStart + s.Size
  212. if sEnd > textSectionLen {
  213. continue
  214. }
  215. sBytes := textSectionData[sStart:sEnd]
  216. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  217. if len(returnOffsets) == 0 {
  218. log("failed to attach enter_runtime_newproc1 uprobe", fmt.Errorf("no return offsets found"))
  219. return nil
  220. }
  221. for _, offset := range returnOffsets {
  222. l, err := exe.Uprobe(s.Name, t.uprobes["exit_runtime_newproc1"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  223. if err != nil {
  224. log("failed to attach exit_runtime_newproc1 uprobe", err)
  225. return nil
  226. }
  227. links = append(links, l)
  228. }
  229. case goTlsWriteSymbol:
  230. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_write_enter"], &link.UprobeOptions{Address: address})
  231. if err != nil {
  232. log("failed to attach write_enter uprobe", err)
  233. return nil
  234. }
  235. links = append(links, l)
  236. case goTlsReadSymbol:
  237. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_enter"], &link.UprobeOptions{Address: address})
  238. if err != nil {
  239. log("failed to attach read_enter uprobe", err)
  240. return nil
  241. }
  242. links = append(links, l)
  243. sStart := s.Value - textSection.Addr
  244. sEnd := sStart + s.Size
  245. if sEnd > textSectionLen {
  246. continue
  247. }
  248. sBytes := textSectionData[sStart:sEnd]
  249. returnOffsets := getReturnOffsets(ef.Machine, sBytes)
  250. if len(returnOffsets) == 0 {
  251. log("failed to attach read_exit uprobe", fmt.Errorf("no return offsets found"))
  252. return nil
  253. }
  254. for _, offset := range returnOffsets {
  255. l, err := exe.Uprobe(s.Name, t.uprobes["go_crypto_tls_read_exit"], &link.UprobeOptions{Address: address, Offset: uint64(offset)})
  256. if err != nil {
  257. log("failed to attach read_exit uprobe", err)
  258. return nil
  259. }
  260. links = append(links, l)
  261. }
  262. }
  263. }
  264. if len(links) == 0 {
  265. return nil
  266. }
  267. log("crypto/tls uprobes attached", nil)
  268. return links
  269. }
  270. func getSslLibPathAndVersion(pid uint32) (string, string) {
  271. f, err := os.Open(proc.Path(pid, "maps"))
  272. if err != nil {
  273. return "", ""
  274. }
  275. defer f.Close()
  276. scanner := bufio.NewScanner(f)
  277. scanner.Split(bufio.ScanLines)
  278. var libsslPath, libcryptoPath string
  279. for scanner.Scan() {
  280. parts := strings.Fields(scanner.Text())
  281. if len(parts) <= 5 {
  282. continue
  283. }
  284. libPath := parts[5]
  285. switch {
  286. case libsslPath == "" && strings.Contains(libPath, "libssl.so"):
  287. fullPath := proc.Path(pid, "root", libPath)
  288. if _, err = os.Stat(fullPath); err == nil {
  289. libsslPath = fullPath
  290. }
  291. case libcryptoPath == "" && strings.Contains(libPath, "libcrypto.so"):
  292. fullPath := proc.Path(pid, "root", libPath)
  293. if _, err = os.Stat(fullPath); err == nil {
  294. libcryptoPath = fullPath
  295. }
  296. default:
  297. continue
  298. }
  299. if libsslPath != "" && libcryptoPath != "" {
  300. break
  301. }
  302. }
  303. if libsslPath == "" || libcryptoPath == "" {
  304. return "", ""
  305. }
  306. ef, err := elf.Open(libcryptoPath)
  307. if err != nil {
  308. return "", ""
  309. }
  310. defer ef.Close()
  311. rodataSection := ef.Section(".rodata")
  312. if rodataSection == nil {
  313. return "", ""
  314. }
  315. rodataSectionData, err := rodataSection.Data()
  316. if err != nil {
  317. return "", ""
  318. }
  319. var version string
  320. for _, b := range bytes.Split(rodataSectionData, []byte("\x00")) {
  321. if len(b) == 0 {
  322. continue
  323. }
  324. s := string(b)
  325. if !strings.HasPrefix(s, "OpenSSL") {
  326. continue
  327. }
  328. if m := opensslVersionRe.FindStringSubmatch(s); len(m) > 1 {
  329. version = m[1]
  330. }
  331. }
  332. return libsslPath, "v" + version
  333. }
  334. func getReturnOffsets(machine elf.Machine, instructions []byte) []int {
  335. var res []int
  336. switch machine {
  337. case elf.EM_X86_64:
  338. for i := 0; i < len(instructions); {
  339. ins, err := x86asm.Decode(instructions[i:], 64)
  340. if err == nil && ins.Op == x86asm.RET {
  341. res = append(res, i)
  342. }
  343. i += ins.Len
  344. }
  345. case elf.EM_AARCH64:
  346. for i := 0; i < len(instructions); {
  347. ins, err := arm64asm.Decode(instructions[i:])
  348. if err == nil && ins.Op == arm64asm.RET {
  349. res = append(res, i)
  350. }
  351. i += 4
  352. }
  353. }
  354. return res
  355. }