forked from gojue/ecapture
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathprobe_gossl.go
118 lines (98 loc) · 1.96 KB
/
probe_gossl.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
// Copyright © 2022 Hengqi Chen
package user
import (
"bytes"
"context"
"ecapture/assets"
"ecapture/pkg/event_processor"
"ecapture/pkg/proc"
"log"
"math"
"github.com/cilium/ebpf"
manager "github.com/ehids/ebpfmanager"
"golang.org/x/sys/unix"
)
func init() {
mod := &GoSSLProbe{}
Register(mod)
}
// GoSSLProbe represents a probe for Go SSL
type GoSSLProbe struct {
Module
mngr *manager.Manager
path string
isRegisterABI bool
}
func (p *GoSSLProbe) Init(ctx context.Context, l *log.Logger, cfg IConfig) error {
p.Module.Init(ctx, l)
p.Module.SetChild(p)
p.path = cfg.(*GoSSLConfig).Path
ver, err := proc.ExtraceGoVersion(p.path)
if err != nil {
return err
}
if ver.After(1, 15) {
p.isRegisterABI = true
}
return nil
}
func (p *GoSSLProbe) Name() string {
return MODULE_NAME_GOSSL
}
func (p *GoSSLProbe) Start() error {
var (
sec string
fn string
)
if p.isRegisterABI {
sec = "uprobe/abi_register"
fn = "probe_register"
} else {
sec = "uprobe/abi_stack"
fn = "probe_stack"
}
p.mngr = &manager.Manager{
Probes: []*manager.Probe{
{
Section: sec,
EbpfFuncName: fn,
AttachToFuncName: "crypto/tls.(*Conn).writeRecordLocked",
BinaryPath: p.path,
},
},
Maps: []*manager.Map{
{
Name: "events",
},
},
}
data, err := assets.Asset("user/bytecode/gossl_kern.o")
if err != nil {
return err
}
opts := manager.Options{
RLimit: &unix.Rlimit{
Cur: math.MaxUint64,
Max: math.MaxUint64,
},
}
if err := p.mngr.InitWithOptions(bytes.NewReader(data), opts); err != nil {
return err
}
return p.mngr.Start()
}
func (p *GoSSLProbe) Events() []*ebpf.Map {
var maps []*ebpf.Map
m, ok, err := p.mngr.GetMap("events")
if err != nil || !ok {
return maps
}
maps = append(maps, m)
return maps
}
func (p *GoSSLProbe) DecodeFun(m *ebpf.Map) (event_processor.IEventStruct, bool) {
return &goSSLEvent{}, true
}
func (p *GoSSLProbe) Close() error {
return nil
}