Update syshook ret definition (#109)
This commit is contained in:
parent
689bc5ffff
commit
97bef506ee
@ -10,18 +10,34 @@
|
|||||||
#include "libafl/exit.h"
|
#include "libafl/exit.h"
|
||||||
#include "libafl/hook.h"
|
#include "libafl/hook.h"
|
||||||
|
|
||||||
struct syshook_ret {
|
enum libafl_syshook_ret_tag {
|
||||||
target_ulong retval;
|
LIBAFL_SYSHOOK_RUN,
|
||||||
bool skip_syscall;
|
LIBAFL_SYSHOOK_SKIP,
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// Representation of a pre-syscall hook result.
|
||||||
|
// It is associated with the LibAFL enum `SyscallHookResult`.
|
||||||
|
// Any change made here should be also propagated to the Rust enum.
|
||||||
|
struct libafl_syshook_ret {
|
||||||
|
enum libafl_syshook_ret_tag tag;
|
||||||
|
union {
|
||||||
|
target_ulong syshook_skip_retval;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
typedef struct libafl_syshook_ret (*libafl_pre_syscall_cb)(
|
||||||
|
uint64_t data, int sys_num, target_ulong arg0, target_ulong arg1,
|
||||||
|
target_ulong arg2, target_ulong arg3, target_ulong arg4, target_ulong arg5,
|
||||||
|
target_ulong arg6, target_ulong arg7);
|
||||||
|
|
||||||
|
typedef target_ulong (*libafl_post_syscall_cb)(
|
||||||
|
uint64_t data, target_ulong ret, int sys_num, target_ulong arg0,
|
||||||
|
target_ulong arg1, target_ulong arg2, target_ulong arg3, target_ulong arg4,
|
||||||
|
target_ulong arg5, target_ulong arg6, target_ulong arg7);
|
||||||
|
|
||||||
struct libafl_pre_syscall_hook {
|
struct libafl_pre_syscall_hook {
|
||||||
// functions
|
// functions
|
||||||
struct syshook_ret (*callback)(uint64_t data, int sys_num,
|
libafl_pre_syscall_cb callback;
|
||||||
target_ulong arg0, target_ulong arg1,
|
|
||||||
target_ulong arg2, target_ulong arg3,
|
|
||||||
target_ulong arg4, target_ulong arg5,
|
|
||||||
target_ulong arg6, target_ulong arg7);
|
|
||||||
|
|
||||||
// data
|
// data
|
||||||
uint64_t data;
|
uint64_t data;
|
||||||
@ -33,11 +49,7 @@ struct libafl_pre_syscall_hook {
|
|||||||
|
|
||||||
struct libafl_post_syscall_hook {
|
struct libafl_post_syscall_hook {
|
||||||
// functions
|
// functions
|
||||||
target_ulong (*callback)(uint64_t data, target_ulong ret, int sys_num,
|
libafl_post_syscall_cb callback;
|
||||||
target_ulong arg0, target_ulong arg1,
|
|
||||||
target_ulong arg2, target_ulong arg3,
|
|
||||||
target_ulong arg4, target_ulong arg5,
|
|
||||||
target_ulong arg6, target_ulong arg7);
|
|
||||||
|
|
||||||
// data
|
// data
|
||||||
uint64_t data;
|
uint64_t data;
|
||||||
@ -47,19 +59,9 @@ struct libafl_post_syscall_hook {
|
|||||||
struct libafl_post_syscall_hook* next;
|
struct libafl_post_syscall_hook* next;
|
||||||
};
|
};
|
||||||
|
|
||||||
size_t libafl_add_pre_syscall_hook(
|
size_t libafl_add_pre_syscall_hook(libafl_pre_syscall_cb callback,
|
||||||
struct syshook_ret (*callback)(uint64_t data, int sys_num,
|
|
||||||
target_ulong arg0, target_ulong arg1,
|
|
||||||
target_ulong arg2, target_ulong arg3,
|
|
||||||
target_ulong arg4, target_ulong arg5,
|
|
||||||
target_ulong arg6, target_ulong arg7),
|
|
||||||
uint64_t data);
|
uint64_t data);
|
||||||
size_t libafl_add_post_syscall_hook(
|
size_t libafl_add_post_syscall_hook(libafl_post_syscall_cb callback,
|
||||||
target_ulong (*callback)(uint64_t data, target_ulong ret, int sys_num,
|
|
||||||
target_ulong arg0, target_ulong arg1,
|
|
||||||
target_ulong arg2, target_ulong arg3,
|
|
||||||
target_ulong arg4, target_ulong arg5,
|
|
||||||
target_ulong arg6, target_ulong arg7),
|
|
||||||
uint64_t data);
|
uint64_t data);
|
||||||
|
|
||||||
int libafl_qemu_remove_pre_syscall_hook(size_t num);
|
int libafl_qemu_remove_pre_syscall_hook(size_t num);
|
||||||
|
@ -9,12 +9,7 @@ size_t libafl_post_syscall_hooks_num = 0;
|
|||||||
GEN_REMOVE_HOOK1(pre_syscall)
|
GEN_REMOVE_HOOK1(pre_syscall)
|
||||||
GEN_REMOVE_HOOK1(post_syscall)
|
GEN_REMOVE_HOOK1(post_syscall)
|
||||||
|
|
||||||
size_t libafl_add_pre_syscall_hook(
|
size_t libafl_add_pre_syscall_hook(libafl_pre_syscall_cb callback,
|
||||||
struct syshook_ret (*callback)(uint64_t data, int sys_num,
|
|
||||||
target_ulong arg0, target_ulong arg1,
|
|
||||||
target_ulong arg2, target_ulong arg3,
|
|
||||||
target_ulong arg4, target_ulong arg5,
|
|
||||||
target_ulong arg6, target_ulong arg7),
|
|
||||||
uint64_t data)
|
uint64_t data)
|
||||||
{
|
{
|
||||||
struct libafl_pre_syscall_hook* hook =
|
struct libafl_pre_syscall_hook* hook =
|
||||||
@ -57,14 +52,16 @@ bool libafl_hook_syscall_pre_run(CPUArchState* env, int num, abi_long arg1,
|
|||||||
struct libafl_pre_syscall_hook* h = libafl_pre_syscall_hooks;
|
struct libafl_pre_syscall_hook* h = libafl_pre_syscall_hooks;
|
||||||
while (h) {
|
while (h) {
|
||||||
// no null check
|
// no null check
|
||||||
struct syshook_ret hook_ret = h->callback(
|
struct libafl_syshook_ret hook_ret = h->callback(
|
||||||
h->data, num, (target_ulong)arg1, (target_ulong)arg2,
|
h->data, num, (target_ulong)arg1, (target_ulong)arg2,
|
||||||
(target_ulong)arg3, (target_ulong)arg4, (target_ulong)arg5,
|
(target_ulong)arg3, (target_ulong)arg4, (target_ulong)arg5,
|
||||||
(target_ulong)arg6, (target_ulong)arg7, (target_ulong)arg8);
|
(target_ulong)arg6, (target_ulong)arg7, (target_ulong)arg8);
|
||||||
if (hook_ret.skip_syscall) {
|
|
||||||
|
if (hook_ret.tag == LIBAFL_SYSHOOK_SKIP) {
|
||||||
skip_syscall = true;
|
skip_syscall = true;
|
||||||
*ret = (abi_ulong)hook_ret.retval;
|
*ret = (abi_ulong)hook_ret.syshook_skip_retval;
|
||||||
}
|
}
|
||||||
|
|
||||||
h = h->next;
|
h = h->next;
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -77,6 +74,7 @@ void libafl_hook_syscall_post_run(int num, abi_long arg1, abi_long arg2,
|
|||||||
abi_long* ret)
|
abi_long* ret)
|
||||||
{
|
{
|
||||||
struct libafl_post_syscall_hook* p = libafl_post_syscall_hooks;
|
struct libafl_post_syscall_hook* p = libafl_post_syscall_hooks;
|
||||||
|
|
||||||
while (p) {
|
while (p) {
|
||||||
// no null check
|
// no null check
|
||||||
*ret = (abi_ulong)p->callback(p->data, (target_ulong)*ret, num,
|
*ret = (abi_ulong)p->callback(p->data, (target_ulong)*ret, num,
|
||||||
|
@ -58,13 +58,12 @@ uint64_t libafl_set_brk(uint64_t new_brk)
|
|||||||
return old_brk;
|
return old_brk;
|
||||||
}
|
}
|
||||||
|
|
||||||
void libafl_set_return_on_crash(bool return_on_crash) {
|
void libafl_set_return_on_crash(bool return_on_crash)
|
||||||
|
{
|
||||||
libafl_return_on_crash = return_on_crash;
|
libafl_return_on_crash = return_on_crash;
|
||||||
}
|
}
|
||||||
|
|
||||||
bool libafl_get_return_on_crash(void) {
|
bool libafl_get_return_on_crash(void) { return libafl_return_on_crash; }
|
||||||
return libafl_return_on_crash;
|
|
||||||
}
|
|
||||||
|
|
||||||
#ifdef AS_LIB
|
#ifdef AS_LIB
|
||||||
void libafl_qemu_init(int argc, char** argv)
|
void libafl_qemu_init(int argc, char** argv)
|
||||||
|
Loading…
x
Reference in New Issue
Block a user