A Linux kernel source code processing method, device and equipment
By dynamically modifying the symbol parsing logic of the Linux kernel, the kernel symbol address is directly parsed from kallsyms, solving the problem of fixing kernel vulnerabilities in the absence of source code in embedded scenarios, and automating the automatic export of kernel symbols and repairing kernel vulnerabilities.
Patent Information
- Application Number
- CN202110557521.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-21
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-05-21
AI Technical Summary
In embedded scenarios, in the absence of direct access to specific Linux kernel sources, it is difficult to automatically repair security vulnerabilities in the Linux kernel, especially those involving the repair of unexported kernel symbols.
By dynamically modifying the logic responsible for symbol parsing in the Linux kernel, avoiding the parsing of kernel symbols from the symbol subset generated by the EXPORT_SYMBOL family macro, but directly parsing the kernel symbol address from kallsyms, thereby realizing the automatic export of kernel symbols.
It realizes automatic export of kernel symbols without any modification to the kernel module, providing an effective foundation for automated repair of kernel vulnerabilities, simplifying the repair process and improving efficiency.
Smart Images

Figure CN113254941B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of software development technology, and in particular to a Linux kernel source code processing method, device and equipment. Background Art
[0002] In the embedded industry, open source Linux is often used as the operating system for embedded devices. Linux often has security vulnerabilities and corresponding patches. However, compared with traditional commercial operating systems, the security vulnerability repair process of Linux is very different. Traditional commercial operating systems have parent companies that regularly release binary repair patches, which are easy to upgrade and integrate online. The Linux open source community advocates downloading the latest version of the code and recompiling it to replace the kernel, which is usually difficult to achieve in embedded scenarios. At the same time, the embedded industry chain is relatively long, involving the Linux kernel community, chip manufacturers, embedded device manufacturers, terminal equipment integrators, etc., and not all manufacturers in all links can access the specific Linux kernel source code that is ultimately written into the firmware of a certain embedded device. For example, companies at the end of the embedded industry chain can access embedded hardware and compiled, binary operating systems, but cannot access the original source code that generated the system. However, they need to correct the security vulnerabilities in them to ensure the security of their own products. At the same time, Linux security vulnerabilities can occur anywhere, which means that when writing security repair module code, you may need to reference unexported symbols in the Linux kernel at any time, and there are many unexported symbols. Therefore, how to repair security vulnerabilities in binary firmware without access to its specific Linux kernel source code is a difficult problem faced by the industry.
[0003] Currently, there are three ways to hot-fix Linux security vulnerabilities on the market: the first is to use the Linux Livepatch function, which is the most officially recognized method in addition to directly modifying the Linux kernel source code; the second is to manually write the Linux kernel and filter the vulnerability parameters in the kernel's surface functions to prevent malicious calls to kernel vulnerabilities; the third is to manually write the Linux kernel and use the same version and patched functions to replace the defective functions with security vulnerabilities in the kernel.
[0004] The first method requires the kernel to enable the Livepatch function in advance, but this is usually not done in embedded scenarios, so this method usually does not work.
[0005] The second method does not require the kernel to enable the Livepatch function, but requires technicians to be very clear about the principles of exploiting different vulnerabilities in order to write parameter filtering code in a targeted manner. At the same time, this method is not universal, as the principles of exploiting different vulnerabilities are different, making it difficult to generate repair code in batches and automatically.
[0006] The third method does not require the kernel to enable the Livepatch function, nor does it require technicians to be proficient in the principles of exploiting different vulnerabilities, but it does require technicians to modify the code when writing the function replacement code. As mentioned above, the vulnerable code may exist anywhere in Linux, so the replacement function usually contains a large number of unexported kernel symbols, and the process of manually modifying the kernel module is very cumbersome and difficult to batch and automate.
[0007] It can be seen that the above three methods are difficult to meet the needs of automatically repairing kernel vulnerabilities. Summary of the invention
[0008] The applicant discovered during the research that the loading process of the Linux kernel is essentially a dynamic linking process. For undefined symbols in the kernel, the kernel will search for the existence of the symbol in a special area. If the symbol exists, the symbol will be converted into an address. The function of the EXPORT_SYMBOL family macro (existing functional module) is to allow the modified symbol to enter this area. However, kallsyms (existing functional module) has opened up another area, in which all exported and unexported symbols are placed. Its original intention is not to use it for symbol resolution during linking, but to use it for kernel code debugging. Therefore, the logic responsible for resolving kernel symbols during linking in the Linux kernel can be dynamically modified to avoid resolving kernel symbols from the symbol subset generated by the EXPORT_SYMBOL family macro, so that the kernel symbol address can be directly resolved from kallsyms.
[0009] The present application provides a Linux kernel source code processing method, apparatus and device for automatically exporting kernel symbols in the kernel without performing any form of modification on the kernel module, thereby providing an effective basis for automatically repairing kernel vulnerabilities.
[0010] In order to achieve the above objectives, this application provides the following technical solutions:
[0011] A Linux kernel source code processing method, comprising:
[0012] Pre-obtain the parsing functions in the Linux kernel;
[0013] Adding a preset parsing logic to the parsing function to obtain a new parsing function; wherein the parsing logic includes logic provided by kallsyms for parsing kernel symbols;
[0014] Control the new parsing function to parse the kernel symbol table to obtain the kernel symbol address;
[0015] The kernel symbol address is exported externally.
[0016] Optionally, adding parsing logic to the parsing function to obtain a new parsing function includes:
[0017] Copying the parsing function and the preset parsing logic into a pre-built parsing replacement function;
[0018] The parsing replacement function is controlled to execute a preset jump instruction to obtain a new parsing function.
[0019] Optionally, the process of constructing the parsing replacement function includes:
[0020] Call the interface function provided by kallsyms to find the address of the parsing function;
[0021] Recording the function instruction stored at the address, and inserting a jump instruction corresponding to the processor architecture into the address;
[0022] Copying the function instruction to a preset springboard function;
[0023] The springboard function is controlled to execute the jump instruction to obtain a parsed replacement function.
[0024] Optionally, the exporting of the kernel symbol externally includes:
[0025] When it is detected that the Linux system is in a running state, the kernel symbols are exported externally.
[0026] A Linux kernel source code processing device, comprising:
[0027] The acquisition unit is used to pre-acquire the parsing function in the Linux kernel;
[0028] A correction unit, used for adding a preset parsing logic to the parsing function to obtain a new parsing function; wherein the parsing logic includes a logic provided by kallsyms for parsing kernel symbols;
[0029] A parsing unit, used for controlling the new parsing function to parse the kernel symbol table to obtain a kernel symbol address;
[0030] The export unit is used to export the kernel symbol address externally.
[0031] Optionally, the correction unit is specifically used for:
[0032] Copying the parsing function and the preset parsing logic into a pre-built parsing replacement function;
[0033] The parsing replacement function is controlled to execute a preset jump instruction to obtain a new parsing function.
[0034] Optionally, the process of the correction unit for constructing an analytical replacement function includes:
[0035] Call the interface function provided by kallsyms to find the address of the parsing function;
[0036] Recording the function instruction stored at the address, and inserting a jump instruction corresponding to the processor architecture into the address;
[0037] Copying the function instruction to a preset springboard function;
[0038] The springboard function is controlled to execute the jump instruction to obtain a parsed replacement function.
[0039] Optionally, the exporting unit is specifically used for:
[0040] When it is detected that the Linux system is in a running state, the kernel symbols are exported externally.
[0041] A computer-readable storage medium includes a stored program, wherein the program executes the Linux kernel source code processing method.
[0042] A Linux kernel source code processing device comprises: a processor, a memory and a bus; the processor and the memory are connected via the bus;
[0043] The memory is used to store programs, and the processor is used to run programs, wherein the Linux kernel source code processing method is executed when the program is running.
[0044] The technical solution provided by the present application obtains the parsing function in the Linux kernel in advance, adds the preset parsing logic to the parsing function, and obtains a new parsing function, wherein the parsing logic includes the logic for parsing kernel symbols provided by kallsyms. The new parsing function is controlled to parse the kernel symbol table, obtain the kernel symbol address, and export the kernel symbol address externally. Using the method shown in the present application, it is possible to automatically export the kernel symbols in the kernel without any form of modification to the kernel module, providing an effective basis for automatically repairing kernel vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0046] Figure 1 A schematic diagram of a Linux kernel source code processing method provided in an embodiment of the present application;
[0047] Figure 2a A schematic diagram of a kernel symbol export process provided in an embodiment of the present application;
[0048] Figure 2b A schematic diagram of another kernel symbol export process provided in an embodiment of the present application;
[0049] Figure 3 A schematic diagram of another Linux kernel source code processing method provided in an embodiment of the present application;
[0050] Figure 4 A schematic diagram of the architecture of a Linux kernel source code processing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0052] like Figure 1 FIG. 1 is a schematic diagram of a Linux kernel source code processing method provided in an embodiment of the present application, comprising the following steps:
[0053] S101: Obtain the parsing function in the Linux kernel in advance.
[0054] The parsing function is a function in the Linux kernel that is responsible for parsing kernel symbols when linking, and is common knowledge familiar to those skilled in the art. Specifically, the parsing function can be found from the Linux kernel by locating the name of the parsing function.
[0055] S102: Call the interface function provided by kallsyms to find the address of the parsing function.
[0056] Among them, kallsyms is a function disclosed by Linux to the outside world and is common knowledge familiar to those skilled in the art.
[0057] Specifically, the specific implementation logic of the interface function provided by kallsyms is called, including but not limited to: char*sym = "XXXXX"; void*addr = (void*)kallsyms_lookup_name(sym). The return value of Addr is the address of the resolution function (ie, the "XXXXX" symbol).
[0058] It should be noted that the above specific implementation process is only used for illustration.
[0059] S103: Record the function instruction stored in the address of the parsed function, and insert a jump instruction corresponding to the processor architecture into the address of the parsed function.
[0060] The so-called processor architecture refers to the processor architecture of the device to which the Linux system belongs, which is common knowledge familiar to those skilled in the art. In the embodiment of the present application, the jump instructions corresponding to different types of processor architectures are different. For example, for unconditional close jump instructions (an optional specific form of jump instructions), the jump instruction corresponding to the ARM architecture is "b xxx", and the jump instruction corresponding to the x86 architecture is "jmp xxx". For long-distance jump instructions (an optional specific form of jump instructions), the jump instruction corresponding to the ARM architecture is "ldrpc, [pc, #-4]", and the jump instruction corresponding to the x86 architecture is "ljump xx, xx".
[0061] S104: Copy the function instruction to the preset springboard function.
[0062] Among them, since S103 has executed the process of inserting the jump instruction corresponding to the processor architecture into the address of the parsed function, the function instruction stored in the address of the parsed function will be destroyed. In order to avoid losing the function instruction, the function instruction needs to be copied to the springboard function for backup.
[0063] It should be noted that in the embodiment of the present application, the springboard function is only used to implement function jump and does not have any business function itself.
[0064] S105: Control the springboard function to execute the jump instruction to obtain the parsed replacement function.
[0065] S106: Copy the parsing function and the parsing logic to the parsing replacement function.
[0066] The preset parsing logic includes the logic provided by kallsyms for parsing kernel symbols.
[0067] It should be noted that the parsing function and the preset parsing logic are both used for kernel symbol table parsing (ie, parsing kernel symbols). To avoid functional confusion, in the parsing replacement function, the parsing logic can be marked to prioritize kernel symbol table parsing.
[0068] S107: Control the parsing replacement function to execute a jump instruction to obtain a new parsing function.
[0069] Among them, the control resolution replacement function executes a jump instruction to obtain a new resolution function, and the new resolution function replaces the original resolution function to perform kernel symbol table resolution, which can make the kernel symbol resolution process have good atomicity and consistency, and ensure that the kernel symbol resolution process can be executed stably and reliably.
[0070] S108: Control the new parsing function to parse the kernel symbol table to obtain the kernel symbol address.
[0071] Among them, by controlling the new parsing function to parse the kernel symbol table and obtain the kernel symbol address, compared with the existing technology, it avoids parsing the kernel symbol from the symbol subset generated by the EXPORT_SYMBOL family macro (that is, directly controlling the original parsing function to parse the kernel symbol table and obtain the kernel symbol address), and realizes parsing the kernel symbol address from kallsyms. In this way, when loading the kernel module later, the non-EXPORT_SYMBOL-modified symbols can be directly used without any form of modification to the kernel module.
[0072] It should be noted that the original logic of Linux for parsing symbol addresses is only related to EXPORT_SYMBOL and the symbol area it creates, and has nothing to do with the kallsyms function and the symbol area involved in kallsyms. The role of EXPORT_SYMBOL is to implement dynamic linking of kernel modules, and kallsyms is used for kernel debugging. Therefore, in the existing Linux code, EXPORT_SYMBOL and kallsyms are not associated with each other, and in the embodiment of the present application, kallsyms is used as a dynamic link of the kernel module, and kallsyms is used to implement some functions of the original EXPORT_SYMBOL (because the former has more symbols, including both the symbols exported by the latter and the symbols not exported by the latter).
[0073] S109: When it is detected that the Linux system is in a running state, the kernel symbol address is exported externally.
[0074] Among them, when it is detected that the Linux system is in running state, the kernel symbol address is exported externally, which can realize targeted kernel symbol export. Specifically, the kernel symbols are only exported to the hot repair module, thereby ensuring that no other security risks are introduced when repairing kernel vulnerabilities.
[0075] It should be noted that the so-called hot repair module, i.e., a security module used to repair kernel vulnerabilities while the system is running, is common knowledge familiar to those skilled in the art. In the embodiment of the present application, it is difficult for the embedded system to obtain the hardware vendor source code for cold repair, so only hot repair can be performed.
[0076] Specifically, the execution diagram of the process described in this embodiment can be found in Figure 2a shown. Figure 2a The marked boxes shown in (i.e., the circular boxes marked with "1, 2, 3, 4, 5, 6, 7, 8, 9") correspond one-to-one with S101-S109 described in this embodiment ("1" corresponds to S101, "2" corresponds to S102, and so on, until they are completely one-to-one corresponding). In addition, the specific process of directly controlling the original parsing function to parse the kernel symbol table and obtain the kernel symbol address can be referred to. Figure 2b shown.
[0077] It should be noted that the above specific implementation process is only used for illustration, that is, to show the difference between the method described in this embodiment and the prior art solution.
[0078] In summary, by using the method shown in this embodiment, it is possible to automatically export kernel symbols in the kernel without performing any form of modification on the kernel module, thereby providing an effective basis for automatically repairing kernel vulnerabilities.
[0079] It should be noted that S106 mentioned in the above embodiment is an optional implementation of the Linux kernel source code processing method described in this application. In addition, S107 mentioned in the above embodiment is also an optional implementation of the Linux kernel source code processing method described in this application. To this end, the process mentioned in the above embodiment can be summarized as follows: Figure 3 The method shown.
[0080] like Figure 3 FIG. 1 is a schematic diagram of another Linux kernel source code processing method provided in an embodiment of the present application, comprising the following steps:
[0081] S301: Pre-acquire the parsing function in the Linux kernel.
[0082] S302: Adding preset parsing logic to the parsing function to obtain a new parsing function.
[0083] The parsing logic includes the logic provided by kallsyms for parsing kernel symbols.
[0084] S303: Control the new parsing function to parse the kernel symbol table to obtain the kernel symbol address.
[0085] S304: Export the kernel symbol address externally.
[0086] In summary, by using the method shown in this embodiment, it is possible to automatically export kernel symbols in the kernel without performing any form of modification on the kernel module, thereby providing an effective basis for automatically repairing kernel vulnerabilities.
[0087] Corresponding to the Linux kernel source code processing method provided in the above-mentioned embodiment of the present application, the embodiment of the present application also provides a Linux kernel source code processing device.
[0088] like Figure 4 FIG. 1 is a schematic diagram of the architecture of a Linux kernel source code processing device provided in an embodiment of the present application, including:
[0089] The acquisition unit 100 is used to pre-acquire the parsing function in the Linux kernel.
[0090] The correction unit 200 is used to add a preset parsing logic to the parsing function to obtain a new parsing function, wherein the parsing logic includes the logic provided by kallsyms for parsing kernel symbols.
[0091] The correction unit 200 is specifically used to: copy the parsing function and the preset parsing logic to the pre-built parsing replacement function; and control the parsing replacement function to execute the preset jump instruction to obtain a new parsing function.
[0092] The correction unit 200 is used to construct a process of parsing and replacing a function, including: calling an interface function provided by kallsyms to find the address of the parsing function; recording the function instructions stored at the address, and inserting a jump instruction corresponding to the processor architecture into the address; copying the function instructions to a preset springboard function; and controlling the springboard function to execute the jump instruction to obtain the parsing and replacing function.
[0093] The parsing unit 300 is used to control the new parsing function to parse the kernel symbol table to obtain the kernel symbol address.
[0094] The export unit 400 is used to export the kernel symbol address externally.
[0095] The export unit 400 is specifically used for exporting the kernel symbol address externally when it is detected that the Linux system is in a running state.
[0096] In summary, by using the method shown in this embodiment, it is possible to automatically export kernel symbols in the kernel without performing any form of modification on the kernel module, thereby providing an effective basis for automatically repairing kernel vulnerabilities.
[0097] The present application also provides a computer-readable storage medium, which includes a stored program, wherein the program executes the Linux kernel source code processing method provided by the present application.
[0098] The present application also provides a Linux kernel source code processing device, including: a processor, a memory and a bus. The processor and the memory are connected via a bus, the memory is used to store programs, and the processor is used to run programs, wherein when the program is running, the Linux kernel source code processing method provided by the present application is executed, including the following steps:
[0099] Pre-obtain the parsing functions in the Linux kernel;
[0100] Adding a preset parsing logic to the parsing function to obtain a new parsing function; wherein the parsing logic includes logic provided by kallsyms for parsing kernel symbols;
[0101] Control the new parsing function to parse the kernel symbol table to obtain the kernel symbol address;
[0102] The kernel symbol address is exported externally.
[0103] Optionally, adding parsing logic to the parsing function to obtain a new parsing function includes:
[0104] Copying the parsing function and the preset parsing logic into a pre-built parsing replacement function;
[0105] The parsing replacement function is controlled to execute a preset jump instruction to obtain a new parsing function.
[0106] Optionally, the process of constructing the parsing replacement function includes:
[0107] Call the interface function provided by kallsyms to find the address of the parsing function;
[0108] Recording the function instruction stored at the address, and inserting a jump instruction corresponding to the processor architecture into the address;
[0109] Copying the function instruction to a preset springboard function;
[0110] The springboard function is controlled to execute the jump instruction to obtain a parsed replacement function.
[0111] Optionally, the exporting of the kernel symbol externally includes:
[0112] When it is detected that the Linux system is in a running state, the kernel symbols are exported externally.
[0113] If the functions described in the method of the embodiment of the present application are implemented in the form of software functional units and sold or used as independent products, they can be stored in a storage medium readable by a computing device. Based on this understanding, the part of the embodiment of the present application that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions to enable a computing device (which can be a personal computer, server, mobile computing device or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program code.
[0114] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0115] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A Linux kernel source code processing method, characterized in that: include: Pre-acquire a parsing function in the Linux kernel; the parsing function in the Linux kernel is a function in the Linux kernel responsible for parsing kernel symbols during linking; Adding the parsing logic for parsing kernel symbols provided by kallsyms to the parsing function in the Linux kernel to obtain a new parsing function, so as to implement part of the functions of the original EXPORT_SYMBOL using kallsyms, thereby avoiding parsing kernel symbols from the symbol subset generated by the EXPORT_SYMBOL family macro; Control the new parsing function to parse the kernel symbol table to obtain the kernel symbol address; The kernel symbol address is exported externally.
2. The method according to claim 1, characterized in that: The method adds the parsing logic for parsing kernel symbols provided by kallsyms to the parsing function in the Linux kernel to obtain a new parsing function, including: Copying the parsing function and the parsing logic provided by kallsyms for parsing kernel symbols into a pre-built parsing replacement function; The parsing replacement function is controlled to execute a preset jump instruction to obtain a new parsing function.
3. The method according to claim 2, characterized in that The process of building a parsing replacement function includes: Call the interface function provided by kallsyms to find the address of the parsing function; Recording the function instruction stored at the address, and inserting a jump instruction corresponding to the processor architecture into the address; Copying the function instruction to a preset springboard function; The springboard function is controlled to execute the jump instruction to obtain a parsed replacement function.
4. The method according to claim 1, characterized in that: The exporting of the kernel symbol address externally includes: When it is detected that the Linux system is in a running state, the kernel symbol address is exported externally.
5. A Linux kernel source code processing device, characterized in that: include: An acquisition unit is used to pre-acquire a parsing function in the Linux kernel; the parsing function in the Linux kernel is a function in the Linux kernel responsible for parsing kernel symbols during linking; A correction unit is used to add a parsing logic for parsing kernel symbols provided by kallsyms to a parsing function in the Linux kernel, so as to obtain a new parsing function, so as to implement part of the functions of the original EXPORT_SYMBOL by using kallsyms, thereby avoiding parsing kernel symbols from a symbol subset generated by the EXPORT_SYMBOL family macro; A parsing unit, used for controlling the new parsing function to parse the kernel symbol table to obtain a kernel symbol address; The export unit is used to export the kernel symbol address externally.
6. The device according to claim 5, characterized in that The correction unit is specifically used for: Copying the parsing function and the parsing logic provided by kallsyms for parsing kernel symbols into a pre-built parsing replacement function; The parsing replacement function is controlled to execute a preset jump instruction to obtain a new parsing function.
7. The device according to claim 6, characterized in that The correction unit is used to construct a process of analyzing the replacement function, including: Call the interface function provided by kallsyms to find the address of the parsing function; Recording the function instruction stored at the address, and inserting a jump instruction corresponding to the processor architecture into the address; Copying the function instruction to a preset springboard function; The springboard function is controlled to execute the jump instruction to obtain a parsed replacement function.
8. The device according to claim 5, characterized in that The export unit is specifically used for: When it is detected that the Linux system is in a running state, the kernel symbol address is exported externally.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program executes the Linux kernel source code processing method according to any one of claims 1 to 4.
10. A Linux kernel source code processing device, characterized in that: include: processor, memory, and bus; The processor is connected to the memory via the bus; The memory is used to store programs, and the processor is used to run programs, wherein the program executes the Linux kernel source code processing method according to any one of claims 1 to 4 when running.
Citation Information
Patent Citations
Device and method for hooking new function in objective function and electronic device
CN103885750A
Hot patch generation method and device and server
CN112416360A
Method and system for parsing XML data
US20050234844A1