diff --git a/tap/tlstapper/bpf/go_uprobes.c b/tap/tlstapper/bpf/go_uprobes.c index 568c412cb..4102cbc8f 100644 --- a/tap/tlstapper/bpf/go_uprobes.c +++ b/tap/tlstapper/bpf/go_uprobes.c @@ -56,6 +56,7 @@ Capstone Engine: https://www.capstone-engine.org/ #include "include/logger_messages.h" #include "include/pids.h" #include "include/common.h" +#include "include/go_abi_0.h" #include "include/go_abi_internal.h" #include "include/go_types.h" @@ -159,9 +160,25 @@ static __always_inline void go_crypto_tls_uprobe(struct pt_regs *ctx, struct bpf return; } #else - info.buffer_len = GO_ABI_INTERNAL_PT_REGS_R2(ctx); + if (abi == ABI0) { + err = bpf_probe_read(&info.buffer_len, sizeof(__u32), (void*)GO_ABI_0_PT_REGS_SP(ctx)+0x18); + if (err != 0) { + log_error(ctx, LOG_ERROR_READING_BYTES_COUNT, pid_tgid, err, ORIGIN_SSL_UPROBE_CODE); + return; + } + } else { + info.buffer_len = GO_ABI_INTERNAL_PT_REGS_R2(ctx); + } #endif - info.buffer = (void*)GO_ABI_INTERNAL_PT_REGS_R4(ctx); + if (abi == ABI0) { + err = bpf_probe_read(&info.buffer, sizeof(__u32), (void*)GO_ABI_0_PT_REGS_SP(ctx)+0x11); + if (err != 0) { + log_error(ctx, LOG_ERROR_READING_FROM_SSL_BUFFER, pid_tgid, err, ORIGIN_SSL_UPROBE_CODE); + return; + } + } else { + info.buffer = (void*)GO_ABI_INTERNAL_PT_REGS_R4(ctx); + } info.fd = go_crypto_tls_get_fd_from_tcp_conn(ctx); __u64 goroutine_id; @@ -228,7 +245,15 @@ static __always_inline void go_crypto_tls_ex_uprobe(struct pt_regs *ctx, struct } info.buffer_len = GO_ABI_INTERNAL_PT_REGS_R7(ctx); // n in return n, nil #else - info.buffer_len = GO_ABI_INTERNAL_PT_REGS_R1(ctx); // n in return n, nil + if (abi == ABI0) { + err = bpf_probe_read(&info.buffer_len, sizeof(__u32), (void*)GO_ABI_0_PT_REGS_SP(ctx)+0x28); + if (err != 0) { + log_error(ctx, LOG_ERROR_READING_BYTES_COUNT, pid_tgid, err, ORIGIN_SSL_UPROBE_CODE); + return; + } + } else { + info.buffer_len = GO_ABI_INTERNAL_PT_REGS_R1(ctx); // n in return n, nil + } #endif // This check achieves ignoring 0 length reads (the reads result with an error) if (info.buffer_len <= 0) { diff --git a/tap/tlstapper/bpf/include/go_abi_0.h b/tap/tlstapper/bpf/include/go_abi_0.h new file mode 100644 index 000000000..916dd316d --- /dev/null +++ b/tap/tlstapper/bpf/include/go_abi_0.h @@ -0,0 +1,52 @@ +/* +Note: This file is licenced differently from the rest of the project +SPDX-License-Identifier: GPL-2.0 +Copyright (C) UP9 Inc. +*/ + +#ifndef __GO_ABI_0__ +#define __GO_ABI_0__ + +/* +Go ABI0 (<=1.16) specification +https://go.dev/doc/asm + +Since ABI0 is a stack-based calling convention we only need the stack pointer and +if it's applicable the Goroutine pointer +*/ + +#include "target_arch.h" + +#if defined(bpf_target_x86) + +#ifdef __i386__ + +#define GO_ABI_0_PT_REGS_SP(x) ((x)->esp) + +#else + +#define GO_ABI_0_PT_REGS_SP(x) ((x)->sp) + +#endif + +#elif defined(bpf_target_arm) + +#define GO_ABI_0_PT_REGS_SP(x) ((x)->uregs[13]) +#define GO_ABI_0_PT_REGS_GP(x) ((x)->uregs[10]) + +#elif defined(bpf_target_arm64) + +/* arm64 provides struct user_pt_regs instead of struct pt_regs to userspace */ +struct pt_regs; +#define PT_REGS_ARM64 const volatile struct user_pt_regs +#define GO_ABI_0_PT_REGS_SP(x) (((PT_REGS_ARM64 *)(x))->sp) +#define GO_ABI_0_PT_REGS_GP(x) (((PT_REGS_ARM64 *)(x))->regs[18]) + +#elif defined(bpf_target_powerpc) + +#define GO_ABI_0_PT_REGS_SP(x) ((x)->sp) +#define GO_ABI_0_PT_REGS_GP(x) ((x)->gpr[30]) + +#endif + +#endif /* __GO_ABI_0__ */ diff --git a/tap/tlstapper/bpf/include/go_abi_internal.h b/tap/tlstapper/bpf/include/go_abi_internal.h index cb8351aec..b38572b76 100644 --- a/tap/tlstapper/bpf/include/go_abi_internal.h +++ b/tap/tlstapper/bpf/include/go_abi_internal.h @@ -8,54 +8,11 @@ Copyright (C) UP9 Inc. #define __GO_ABI_INTERNAL__ /* -Go internal ABI specification +Go internal ABI (1.17/current) specification https://go.googlesource.com/go/+/refs/heads/master/src/cmd/compile/abi-internal.md */ -/* Scan the ARCH passed in from ARCH env variable */ -#if defined(__TARGET_ARCH_x86) - #define bpf_target_x86 - #define bpf_target_defined -#elif defined(__TARGET_ARCH_s390) - #define bpf_target_s390 - #define bpf_target_defined -#elif defined(__TARGET_ARCH_arm) - #define bpf_target_arm - #define bpf_target_defined -#elif defined(__TARGET_ARCH_arm64) - #define bpf_target_arm64 - #define bpf_target_defined -#elif defined(__TARGET_ARCH_mips) - #define bpf_target_mips - #define bpf_target_defined -#elif defined(__TARGET_ARCH_powerpc) - #define bpf_target_powerpc - #define bpf_target_defined -#elif defined(__TARGET_ARCH_sparc) - #define bpf_target_sparc - #define bpf_target_defined -#else - #undef bpf_target_defined -#endif - -/* Fall back to what the compiler says */ -#ifndef bpf_target_defined -#if defined(__x86_64__) - #define bpf_target_x86 -#elif defined(__s390__) - #define bpf_target_s390 -#elif defined(__arm__) - #define bpf_target_arm -#elif defined(__aarch64__) - #define bpf_target_arm64 -#elif defined(__mips__) - #define bpf_target_mips -#elif defined(__powerpc__) - #define bpf_target_powerpc -#elif defined(__sparc__) - #define bpf_target_sparc -#endif -#endif +#include "target_arch.h" #if defined(bpf_target_x86) diff --git a/tap/tlstapper/bpf/include/target_arch.h b/tap/tlstapper/bpf/include/target_arch.h new file mode 100644 index 000000000..9c4a5cad4 --- /dev/null +++ b/tap/tlstapper/bpf/include/target_arch.h @@ -0,0 +1,55 @@ +/* +Note: This file is licenced differently from the rest of the project +SPDX-License-Identifier: GPL-2.0 +Copyright (C) UP9 Inc. +*/ + +#ifndef __TARGET_ARCH__ +#define __TARGET_ARCH__ + +/* Scan the ARCH passed in from ARCH env variable */ +#if defined(__TARGET_ARCH_x86) + #define bpf_target_x86 + #define bpf_target_defined +#elif defined(__TARGET_ARCH_s390) + #define bpf_target_s390 + #define bpf_target_defined +#elif defined(__TARGET_ARCH_arm) + #define bpf_target_arm + #define bpf_target_defined +#elif defined(__TARGET_ARCH_arm64) + #define bpf_target_arm64 + #define bpf_target_defined +#elif defined(__TARGET_ARCH_mips) + #define bpf_target_mips + #define bpf_target_defined +#elif defined(__TARGET_ARCH_powerpc) + #define bpf_target_powerpc + #define bpf_target_defined +#elif defined(__TARGET_ARCH_sparc) + #define bpf_target_sparc + #define bpf_target_defined +#else + #undef bpf_target_defined +#endif + +/* Fall back to what the compiler says */ +#ifndef bpf_target_defined +#if defined(__x86_64__) + #define bpf_target_x86 +#elif defined(__s390__) + #define bpf_target_s390 +#elif defined(__arm__) + #define bpf_target_arm +#elif defined(__aarch64__) + #define bpf_target_arm64 +#elif defined(__mips__) + #define bpf_target_mips +#elif defined(__powerpc__) + #define bpf_target_powerpc +#elif defined(__sparc__) + #define bpf_target_sparc +#endif +#endif + +#endif /* __TARGET_ARCH__ */