Dynamic analysis instrumentation debugging method and computer application program
By parsing the DWARF debugging information of binary files and using Kprobe or eBPF technology, dynamic instrumentation is achieved at any line of code, solving the flexibility and performance loss problems of function internal information collection in existing technologies and providing detailed function execution information.
Patent Information
- Application Number
- CN202511165636.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-08-20
AI Technical Summary
Existing debugging tools and methods are difficult to achieve flexible function internal information collection in production environments, especially stack variable information during function execution. Existing dynamic instrumentation methods also suffer from large performance loss or incomplete information collection.
By parsing the DWARF debugging information of the binary file, the runtime information of the analysis point to be instrumented is obtained, and dynamic instrumentation is performed in combination with Kprobe or eBPF technology to collect variable information on the function call stack and report it to the user-mode program.
It implements dynamic instrumentation at any line of code, can collect local and global variable information during function execution, and improves debugging flexibility and accuracy.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of fault debugging, and in particular to a dynamic analysis plugging debugging method and a computer application program. Background Art
[0002] Some currently available debugging tools or methods usually modify the source code to add print information. This method can very conveniently obtain almost any debugging information, but this method requires modifying the source code and recompiling, which is almost impossible to use in an actual production environment. There are also dynamic instrumentation technologies such as kprobe or eBPF technology to obtain debugging information, but these methods usually collect data at the function entry or exit. These tools are very flexible and can achieve zero-intrusion and dynamic collection of required data. However, these tools also have obvious limitations, that is, they can usually only collect information at the function entry or exit, and some information during the function execution process cannot be obtained, such as locating whether some key execution logic is executed, and collecting variable information in the stack during function execution.
[0003] Debugging by modifying source code has significant limitations and is almost unusable in production environments. While some dynamic binary instrumentation methods offer high flexibility and zero intrusion, current tools can only be used to collect function input parameter information and function return value information at function entry and exit points, and cannot effectively collect function internal call relationships and variable information on the stack.
[0004] "A binary multi-executable software instrumentation method based on dynamic instrumentation" (202210428966.X) provides a binary multi-executable software instrumentation method based on dynamic instrumentation. The code segment ending with the branch jump instruction is used as the translation block. It can very accurately track the call chain of each code block and clarify the precise process of function execution. However, it requires inserting probe code in each code block for information collection, which has a large performance loss and cannot collect information on the function call stack.
[0005] "An Improved Source Code Instrumentation Method for Dynamic Analysis" (202010539967.2) provides an improved source code instrumentation method for dynamic analysis. This method mainly targets the security aspects of the software and does not involve software information collection and call relationship acquisition.
[0006] "A binary instrumentation method for program dynamic analysis" (202110667217.8) discloses a binary instrumentation method for program dynamic analysis, which uses the debugging information of the binary file to solve the basic instruction block and obtain the program counter of the corresponding instruction block for instrumentation. It is basically consistent with "A binary multi-executable software instrumentation method based on dynamic instrumentation", and both do not collect function call stack information. Summary of the Invention
[0007] To address the deficiencies in the prior art, the present invention provides a dynamic analysis and instrumentation debugging method, comprising: Step S1: Obtain the information identifier of the point to be instrumented and analyzed; Step S2: parsing the DWARF debugging information of the binary file of the to-be-inserted analysis point based on the information identifier of the to-be-inserted analysis point to obtain runtime information therefrom, the runtime information including the to-be-inserted function, the instruction block to which it belongs, local symbols, and global symbols of the to-be-inserted analysis point; Step S3: Based on the to-be-inserted function and the instruction block to which it belongs, respectively obtain the program counter value of the to-be-inserted function and the program counter value of the first address of the instruction block to which it belongs, and calculate the difference between the program counter value of the to-be-inserted function and the program counter value of the first address of the instruction block to which it belongs; Step S4: Based on the local symbol and global symbol of the analysis point to be instrumented, a memory address mapping table is obtained, and the memory address mapping table is passed into the instrumentation execution function; Step S5: The instrumentation execution function is dynamically instrumented based on the difference between the program counter value of the function to be instrumented and the program counter value of the first address of the instruction block to which it belongs in step S3, and the memory address mapping table in step S4.
[0008] In step S4, a memory address mapping table is obtained by acquiring and saving the mapping relationship between the local symbols of the to-be-inserted analysis points and the memory addresses, and the mapping relationship between the global symbols of the to-be-inserted analysis points and the memory addresses in step S2.
[0009] Wherein, in step S5, the instrumentation execution function is dynamically instrumented by using Kprobe or eBPF technology.
[0010] Wherein, in step S1, the information identifier of the analysis point to be instrumented includes the source code file name, the instrumented source code line number and the name of the function to be instrumented.
[0011] Among them, in step S2, based on the source code file name of the analysis point to be inserted, the binary file compiled by the corresponding source code file is determined, the DWARF debugging information of the binary file is parsed, and runtime information is obtained therefrom. The runtime information includes the function to be inserted, the instruction block to which it belongs, the local symbols and the global symbols of the analysis point to be inserted.
[0012] Among them, before dynamic instrumentation, based on the name of the to-be-inserted function of the to-be-inserted analysis point obtained in step S1, the to-be-inserted function of the to-be-inserted analysis point is obtained, and the instrumentation execution function is hooked to the to-be-inserted function of the to-be-inserted analysis point, so that when the to-be-inserted function runs to the hook point, the instrumentation execution function will be called, thereby performing dynamic instrumentation in the instrumentation execution function.
[0013] Among them, in step S5, the insertion execution function is based on the difference between the program counter value of the to-be-inserted function and the program counter value of the first address of the instruction block to which it belongs in step S3, and the memory address mapping table in step S4. During the dynamic insertion process, the time when the to-be-inserted function of the to-be-inserted analysis point is called, and the local symbols and global symbols corresponding to the time when the to-be-inserted function is called are collected.
[0014] Among them, also include: Step S6: reporting the time when the to-be-inserted function of the to-be-inserted analysis point collected in step S5 is called, the local symbol and the global symbol corresponding to the to-be-inserted function when it is called, and the information identifier of the to-be-inserted analysis point in step S1 to the user-mode program; Step S7: The user-mode program understands the running status of the function to be instrumented based on the reported information and assists in problem analysis.
[0015] In step S6, the time when the to-be-inserted function of the to-be-inserted analysis point collected in step S5 is called, the local symbol and global symbol corresponding to the to-be-inserted function when the to-be-inserted function is called, and the information identifier of the to-be-inserted analysis point in step S1 are reported to the user-mode program through kernel memory mapping, BPF map or netlink.
[0016] The present invention further provides a computer application program for executing any one of the above-mentioned dynamic analysis and instrumentation debugging methods.
[0017] The present invention can dynamically insert a stub at any line of code and can collect information on all local variables and global variables stored in the stack of the current function when the line of code is executed, so as to better understand the relevant information of the current program running and greatly help debugging. DETAILED DESCRIPTION
[0018] In order to have a further understanding of the technical solution and beneficial effects of the present invention, the technical solution of the present invention and the beneficial effects produced are described in detail below.
[0019] The purpose of the present invention is to provide a dynamic analysis and instrumentation debugging method. By parsing the DWARF debugging information of a binary file, a specified line of a specified source code file is obtained for dynamic instrumentation. The DWARF debugging information can be used to parse and collect information about local variables stored in the stack used by the calling function. This allows dynamic instrumentation to be performed on any line of code, and information about all local and global variables stored in the stack of the current function when that line of code is executed can be collected. This allows for a better understanding of the relevant information of the current program execution, which is greatly helpful for debugging.
[0020] A specific implementation of the present invention is as follows: 1. Determine the information identifier of the analysis point to be instrumented. The information identifier includes the source code file name, instrumented source code line number, the function name and offset value to be instrumented, as well as the local symbols to be collected, the global symbols to be collected, and other information that needs to be collected.
[0021] The offset value is the line number offset of the to-be-instrumented analysis point within the to-be-instrumented function. For example, if Func_a is the to-be-instrumented function and xxx is the line number of the instrumented source code, then: xxx: Func_a(void) { / / xxx is the source code line number xxx+1: int a = 0, b = 1, c = 2; ... xxx+n: a = b + c; xxx+n+1: return a; } When specifying the analysis point to be instrumented, if you need to capture the input parameters when Func_a is running, the function name of the analysis point to be instrumented is Func_a, and the offset is 0. If you need to obtain the information of the corresponding local variables when running at line xxx+n, the function name of the analysis point to be instrumented is Func_a, and the offset is n.
[0022] The function to be instrumented and the offset value are the runtime information obtained when parsing the specific binary file in step 2. This information is used to obtain the specific runtime instrumentation address from the DWARF information. The difference is that the information for locating the analysis point to be instrumented in the source code file in step 1 is manually confirmed in the source file, such as the xxx+n position in Func_a above; while step 2 is to parse the actual location of the analysis point to be instrumented in step 1 from DWARF in the binary's runtime memory.
[0023] 2. Based on the source code file name of the analysis point to be instrumented, determine the binary file compiled from the corresponding source code file, and parse the DWARF debugging information of the binary file; obtain the information of the analysis point to be instrumented confirmed in step 1 when the binary file is actually running, which includes the runtime information corresponding to the analysis point to be instrumented, including the function to be instrumented, the instruction block to which it belongs, the file to which it belongs, and the local and global symbols.
[0024] Compare the local symbols and global symbols collected in this step with the local symbols and global symbols to be collected in step 1 respectively. The local symbols and global symbols in step 2 should be consistent with the local symbols and global symbols to be collected in step 1 respectively.
[0025] Compare the functions to be inserted collected in this step with those in step 1. The functions to be inserted collected in this step should be consistent with those in step 1. For example, if the xxx+n lines of the Func_a function are inserted in step 1, then in step 2, the function name parsed from the DWARF information using the xxx+n lines of the Func_a function must also be Func_a to ensure accurate parsing.
[0026] In the present invention, the belonging file is a file containing the function to be inserted, such as: there is a function Func_a in the aaa.c file, and Func_a may also exist in the bbb.c file. The present invention needs to insert a stub on the Func_a function in aaa.c. Then when we parse the DWARF information, we must parse the aaa.c file. If the bbb.c file is parsed, it means that the parsing is wrong.
[0027] 3. Obtain the program counter value of the function to be inserted from the function to be inserted at the analysis point to be inserted in step 2, obtain the program counter value of the first address of the instruction block to which the analysis point to be inserted belongs from the instruction block to which the analysis point to be inserted belongs, and calculate the difference between the program counter value of the function to be inserted and the program counter value of the first address of the instruction block to which the analysis point to be inserted belongs.
[0028] 4. Obtain the mapping relationship between the local symbol and memory address of the analysis point to be instrumented in step 2, as well as the mapping relationship between the global symbol and memory address of the analysis point to be instrumented in step 2, save the mapping relationship between the local symbol and memory address of the analysis point to be instrumented and the mapping relationship between the global symbol and memory address of the analysis point to be instrumented in a memory address mapping table, and pass it to the instrumentation execution function.
[0029] 5. The instrumentation execution function uses dynamic instrumentation technology such as Kprobe or eBPF technology. Dynamic instrumentation is performed based on the difference between the program counter value of the function to be instrumented in step 3 and the program counter value of the first address of the instruction block to which it belongs, as well as the memory address mapping table passed in step 4.
[0030] Specifically, before executing dynamic instrumentation, based on the name of the to-be-inserted function of the to-be-inserted analysis point obtained in step 1, the to-be-inserted function of the to-be-inserted analysis point is obtained, and the instrumentation execution function is hooked to the to-be-inserted function of the to-be-inserted analysis point; thus, when the to-be-inserted function runs to the hook point, the instrumentation execution function is called, and information of the to-be-inserted analysis point is collected in the instrumentation execution function. The collected information includes the time when the to-be-inserted function is called, and the local symbols and global symbols corresponding to the time when the to-be-inserted function is called.
[0031] Specifically, the instrumentation execution function parses the memory address mapping table passed in, obtains local symbols and global symbols from it, and collects information of the analysis points to be instrumented based on the local symbols and global symbols.
[0032] In the present invention, the so-called local symbols and global symbols refer to the local variable values and global variable values of the analysis points to be instrumented.
[0033] Symbol A represents the function to be instrumented, and symbol B represents the instrumented execution function. The calling relationship between the two is as follows: Function A: A(parameters) { variable1 = xxx; variable2 = parameter; Abd = variable1 + variable2; ..... } Here the original running process of function A is: Variable 1 = xxx; Step 1 Variable 2 = xxxx; Step 2 Abd = variable 1 + variable 2; Step 3 Next steps Perhaps due to the need to troubleshoot the problem, you need to know the value of the variable Abd. In this case, you can insert an information collection function B at the line of code after the third step: Abd = variable 1 + variable 2;. What function B needs to do is to parse the symbol information and memory address information of variable 1 and variable 2, so as to obtain the values of variable 1 and variable 2 by reading the memory value, and thus obtain the value of Abd through calculation.
[0034] 6. Report the information collected in step 5 and the information identifier obtained in step 1 to the user-mode program through kernel memory mapping, BPF map, netlink, etc.
[0035] 7. The user-mode program understands the running status of the analysis point to be instrumented and the relevant information collected inside the function to be instrumented based on the collected information reported in step 6, thereby understanding the running status of the function to be instrumented and assisting in problem analysis.
[0036] Therefore, the present invention obtains the associated information of instruction block and source code file line number by parsing the DWARF debugging information of binary file, matches the source code for the insertion code line, collects the corresponding program counter and carries out accurate dynamic insertion, and collects the calling situation of the designated line of the function to be inserted in the source code by observing the calling situation of the insertion analysis point. The mapping table of the local symbol and the memory address of the function to be inserted, the mapping table of the global symbol and the memory address are obtained by the DWARF debugging information of binary file, and the local variables and global variable information of the insertion analysis point are obtained. In this way, dynamic insertion can be carried out in any line of code, and the information of all local variables and global variables stored in the stack of the current function when the line of code is executed can be collected, so that the relevant information of the current program operation can be better understood, which is relatively helpful for debugging.
[0037] In this invention, the terms used are as follows: Kprobe is a dynamic probing mechanism in the Linux kernel. It allows users to insert probe points into kernel code at runtime. These probe points are essentially special sets of instructions. When the kernel executes a function with a probe point (including function entry points and return points), it triggers a predefined handler.
[0038] DWARF (Debugging With Attributed Record Formats) is a standard data format for debugging information. It is primarily used to store debugging-related information for a program, such as variable types, scopes, and locations, as well as function parameters, local variables, and other details.
[0039] eBPF (Extended Berkeley Packet Filter) is a kernel technology that originates from the Berkeley Packet Filter (BPF). eBPF allows users to securely run custom programs in kernel space. These programs can be loaded into the Linux kernel and executed when triggered by specific kernel events (such as system calls, network packet transmission and reception, process scheduling, etc.).
[0040] Although the present invention has been described using the above preferred embodiments, they are not intended to limit the scope of protection of the present invention. Any person skilled in the art may make various changes and modifications to the above embodiments without departing from the spirit and scope of the present invention. These changes and modifications are still within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be based on the definition of the claims.
Claims
1. The dynamic analysis and instrumentation debugging method is characterized by: include: Step S1: Obtain the information identifier of the point to be instrumented and analyzed; Step S2: parsing the DWARF debugging information of the binary file of the to-be-inserted analysis point based on the information identifier of the to-be-inserted analysis point to obtain runtime information therefrom, the runtime information including the to-be-inserted function, the instruction block to which it belongs, local symbols, and global symbols of the to-be-inserted analysis point; Step S3: Based on the to-be-inserted function and the instruction block to which it belongs, respectively obtain the program counter value of the to-be-inserted function and the program counter value of the first address of the instruction block to which it belongs, and calculate the difference between the program counter value of the to-be-inserted function and the program counter value of the first address of the instruction block to which it belongs; Step S4: Based on the local symbol and global symbol of the analysis point to be instrumented, a memory address mapping table is obtained, and the memory address mapping table is passed into the instrumentation execution function; Step S5: The instrumentation execution function is dynamically instrumented based on the difference between the program counter value of the function to be instrumented and the program counter value of the first address of the instruction block to which it belongs in step S3, and the memory address mapping table in step S4.
2. The dynamic analysis and instrumentation debugging method according to claim 1, wherein: In step S4, a memory address mapping table is obtained by acquiring and saving the mapping relationship between the local symbol and the memory address of the analysis point to be instrumented in step S2, and the mapping relationship between the global symbol and the memory address of the analysis point to be instrumented.
3. The dynamic analysis and instrumentation debugging method according to claim 1, wherein: In step S5, the instrumentation execution function is dynamically instrumented using Kprobe or eBPF technology.
4. The dynamic analysis and instrumentation debugging method according to claim 1, wherein: In step S1, the information identifier of the analysis point to be instrumented includes the source code file name, the instrumented source code line number and the name of the function to be instrumented.
5. The dynamic analysis and instrumentation debugging method according to claim 4, wherein: In step S2, based on the source code file name of the analysis point to be inserted, a binary file compiled by the corresponding source code file is determined, and the DWARF debugging information of the binary file is parsed to obtain runtime information. The runtime information includes the function to be inserted, the instruction block to which it belongs, the local symbols and the global symbols of the analysis point to be inserted.
6. The dynamic analysis and instrumentation debugging method according to claim 4, wherein: Before dynamic instrumentation is performed, based on the name of the to-be-inserted function of the to-be-inserted analysis point obtained in step S1, the to-be-inserted function of the to-be-inserted analysis point is obtained, and the instrumentation execution function is associated with the to-be-inserted function of the to-be-inserted analysis point, so that when the to-be-inserted function runs to the hook point, the instrumentation execution function is called, thereby performing dynamic instrumentation in the instrumentation execution function.
7. The dynamic analysis and instrumentation debugging method according to claim 4, wherein: In step S5, the instrumentation execution function collects the time when the to-be-inserted function of the to-be-inserted analysis point is called, and the local symbols and global symbols corresponding to the to-be-inserted function when it is called during the dynamic instrumentation process based on the difference between the program counter value of the to-be-inserted function and the first address program counter value of the instruction block to which it belongs in step S3, and the memory address mapping table in step S4.
8. The dynamic analysis and instrumentation debugging method according to claim 7, wherein: Also includes: Step S6: reporting the time when the to-be-inserted function of the to-be-inserted analysis point collected in step S5 is called, the local symbol and the global symbol corresponding to the to-be-inserted function when it is called, and the information identifier of the to-be-inserted analysis point in step S1 to the user-mode program; Step S7: The user-mode program understands the running status of the function to be instrumented based on the reported information and assists in problem analysis.
9. The dynamic analysis and instrumentation debugging method according to claim 8, characterized in that: In step S6, the time when the to-be-inserted function of the to-be-inserted analysis point collected in step S5 is called, the local symbol and global symbol corresponding to the call of the to-be-inserted function, and the information identifier of the to-be-inserted analysis point in step S1 are reported to the user-mode program through kernel memory mapping, BPF map or netlink.
10. A computer application, characterized in that: An instrumentation debugging method for performing dynamic analysis according to any one of claims 1 to 9.
Citation Information
Patent Citations
An Improved Source Code Instrumentation Method for Dynamic Analysis
CN111736846B
Binary multi-executive software instrumentation method based on dynamic instrumentation
CN114860586A
Dynamic analysis-oriented source code instrumentation improvement method
CN111736846A
Binary instrumentation method for program dynamic analysis
CN113535545A
Program control method and device, computer equipment and storage medium
CN113760290A