A Customized Invocation Method and Device for an Information Technology Application Innovation Operating System

By using Hook technology to expand in the Xinchuang operating system, the operating system call management in user-state and kernel-state is solved, and the problem of changing system call logic in the existing technology is solved, and the customization of system call logic and the guarantee of application business logic is realized.

CN119473307BActive Publication Date: 2025-06-24SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510052216.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-06-24
Estimated Expiration
2045-01-14

AI Technical Summary

Technical Problem

The calling interface function of the existing Xinchuang operating system is clear and fixed. When the system call logic needs to be changed, the kernel and Glibc components must be greatly modified, which makes it difficult and may affect the business logic of all applications.

Method used

Through Hook technology expansion, the operating system call management in user-state and kernel-state is realized, the system call interface is newly created and replaced, and the pre- and post-processing logic is added to ensure that the system call logic is customized without changing the kernel of the Xinchuang operating system.

Benefits of technology

It realizes the customization of system call logic by the Innovative Operating System, maintains the overall integrity of the system, ensures stability and compatibility, and ensures that the application's business logic is not affected.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119473307B_ABST
    Figure CN119473307B_ABST
Patent Text Reader

Abstract

The present invention discloses a customized call method and device for an information technology application (IT application) operating system, relating to the technical field of operating system management; including: Step 1: Using the gcc compilation tool to write a user-mode hook function, and customizing the user-mode system call by using the user-mode hook function; Step 2: Using the debugging tool kprobe of the IT application operating system kernel to customize the kernel-mode system call; The present invention realizes the operating system call management in the user mode and the kernel mode, realizes the customization of the call logic of the IT application operating system, maintains the overall integrity of the IT application operating system, ensures the stability and compatibility of the IT application operating system, and ensures the business logic of the application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention discloses a customized call method and device for an information technology innovation operating system, relating to the technical field of operating system management. Background Art

[0002] The emergence of the information technology innovation operating system aims to support and optimize specific information technology innovation applications. The information technology innovation operating system provides a series of call interfaces in the kernel state, and these interfaces are distinguished by call numbers for different functions. The Glibc component encapsulates the call interfaces of the information technology innovation operating system and provides interfaces that conform to the POSIX standard, enabling end-user programs to conveniently call these system functions.

[0003] However, the call interface functions of the information technology innovation operating system are clear and fixed. When it is necessary to change the system call logic, it is usually necessary to make substantial modifications to the kernel of the information technology innovation operating system and the Glibc component. However, the interfaces of the kernel of the information technology innovation operating system and the Glibc component are public interfaces. Making substantial modifications is not only difficult but also may have a wide impact on all applications running on the information technology innovation operating system, thereby affecting the business logic of these applications. Summary of the Invention

[0004] Aiming at the problems of the prior art, the present invention provides a customized call method and device for an information technology innovation operating system. Without changing the kernel of the information technology innovation operating system and the Glibc component, through Hook technology extension, it realizes the operating system call management in the user state and the kernel state, realizes the customization of the call logic of the information technology innovation operating system, maintains the overall integrity of the information technology innovation operating system, ensures the stability and compatibility of the information technology innovation operating system, and ensures the business logic of the application.

[0005] The specific solution proposed by the present invention is as follows:

[0006] The present invention provides a customized call method for an information technology innovation operating system, including:

[0007] Step 1: Use the gcc compilation tool to write a user-state hook function, and use the user-state hook function to customize the user-state system call:

[0008] Intercept the user-state system call of the system call interface through the user-state hook function in the Glibc component; assign the user-state function to be called to the system call function through the user-state hook function; enable the user-state function to be called when a user-state system call occurs subsequently; and add pre-processing logic before the system call interface for pre-processing of the business logic, and add post-processing logic after the system call interface for post-processing of the business logic;

[0009] Step 2: Customize the kernel-mode system call using the debugging tool kprobe of the domestic innovation operating system kernel:

[0010] Create a new system call: Use kprobe to obtain the kernel system call table pointer. According to the kernel system call table pointer, specify the function at the reserved index in the system call table for creating a new system call interface.

[0011] Replace the system call logic: Replace the system call logic by modifying the function at the reserved index in the specified system call table.

[0012] Add pre-processing for the system call: Specify a pre-processing function for the pre-processing of the kernel-mode system call.

[0013] Furthermore, when creating a new system call in Step 2 of the method for customizing the call of the domestic innovation operating system, it specifically includes: Using kprobe to obtain the kernel system call table pointer based on the function corresponding address returned by the kallsyms_lookup_name function. The kallsyms_lookup_name function is used to find the function symbol in the kernel symbol table and return the function corresponding address. According to the kernel system call table pointer, specify the function at the reserved index in the system call table for creating a new system call interface.

[0014] Furthermore, when replacing the system call logic in Step 2 of the method for customizing the call of the domestic innovation operating system, it specifically includes: Obtain the reserved index in the system call table, and obtain the index number according to the reserved index. Each index number corresponds to a system call interface.

[0015] Replace the system call logic corresponding to the system call interface by modifying the function at the reserved index in the specified system call table.

[0016] Furthermore, when adding pre-processing for the system call in Step 2 of the method for customizing the call of the domestic innovation operating system, it specifically includes: Use kprobe to find the name of the system call function that needs to add pre-processing in the kernel symbol table, and specify the system call function corresponding to the system call function name as the pre-processing function.

[0017] The present invention provides a device for customizing the call of a domestic innovation operating system, including a user-mode system call management module and a kernel-mode system call management module.

[0018] The user-mode system call management module uses the gcc compilation tool to write a user-mode hook function and customizes the user-mode system call using the user-mode hook function:

[0019] User-mode system calls that intercept system call interfaces through user-mode hook functions in the Glibc component; assign the user-mode function to be called to the system call function through the user-mode hook function; make the user-mode function to be called be called when a user-mode system call occurs subsequently; and add pre-processing logic before the system call interface for pre-processing of business logic, and add post-processing logic after the system call interface for post-processing of business logic;

[0020] The kernel-mode system call management module customizes kernel-mode system calls using the kprobe debugging tool of the Xinchuang operating system kernel:

[0021] Create a new system call: Use kprobe to obtain the kernel system call table pointer, and according to the kernel system call table pointer, specify the function at the reserved index in the system call table for creating a new system call interface;

[0022] Replace the system call logic: Replace the system call logic by modifying the function at the reserved index in the specified system call table;

[0023] Add pre-processing for system calls: Specify a pre-processing function for pre-processing kernel-mode system calls.

[0024] Furthermore, when the kernel-mode system call management module of the customized call device of the Xinchuang operating system creates a new system call, it specifically includes: Using kprobe to obtain the kernel system call table pointer according to the function corresponding address returned by the kallsyms_lookup_name function. The kallsyms_lookup_name function is used to find the function symbol in the kernel symbol table and return the function corresponding address. According to the kernel system call table pointer, specify the function at the reserved index in the system call table for creating a new system call interface.

[0025] Furthermore, when the kernel-mode system call management module of the customized call device of the Xinchuang operating system replaces the system call logic, it specifically includes: Obtain the reserved index in the system call table, and obtain the index number according to the reserved index. Each index number corresponds to a system call interface,

[0026] Replace the system call logic corresponding to the system call interface by modifying the function at the reserved index in the specified system call table.

[0027] Furthermore, when the kernel-mode system call management module of the customized call device of the Xinchuang operating system adds pre-processing for system calls, it specifically includes: Use kprobe to find the name of the system call function that needs to add pre-processing in the kernel symbol table, and specify the system call function corresponding to the system call function name as the pre-processing function.

[0028] The advantages of the present invention are as follows:

[0029] It realizes the system call management between the user space and the kernel space, supports the pre - processing of user - space system calls, supports the post - processing of user - space system calls, supports the creation of new kernel - space system call interfaces, supports the replacement of kernel - space system call logic, supports the pre - processing of kernel - space system calls. Without changing the kernel of the Xinchuang operating system, it realizes the customization of the system call logic of the Xinchuang operating system, maintains the overall integrity of the Xinchuang operating system, ensures the stability and compatibility of the Xinchuang operating system, and guarantees the business logic of the application. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 It is a schematic diagram of the method flow of the present invention.

[0031] Figure 2 It is a schematic diagram of the application framework of the device of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, so that those skilled in the art can better understand the present invention and be able to implement it, but the embodiments given are not intended to limit the present invention.

[0033] Embodiment 1: The present invention provides a customized call method for a Xinchuang operating system, including:

[0034] Step 1: Use the gcc compilation tool to write a user - space hook function, and customize the user - space system call using the user - space hook function:

[0035] Intercept the user - space system call of the system call interface through the user - space hook function in the Glibc component; assign the user - space function to be called to the system call function through the user - space hook function; make the user - space function to be called be called when a user - space system call occurs subsequently; and add pre - processing logic before the system call interface for pre - processing of business logic, and add post - processing logic after the system call interface for post - processing of business logic.

[0036] For example, write a user - space hook function: TRY_LOAD_HOOK_FUNC,

[0037] The input of the TRY_LOAD_HOOK_FUNC function is name: the name of the system call interface,

[0038] The TRY_LOAD_HOOK_FUNC function assigns the function named g_sys_##name to the system call function, and subsequent calls to the g_sys_##name function are equivalent to calling the system call of ##name.

[0039] Code example:

[0040] #define unlikely(x) __builtin_expect(!!(x), 0)

[0041] / / User-mode hook function, supporting interception of user-mode system calls

[0042] #define TRY_LOAD_HOOK_FUNC(name) if (unlikely(!g_sys_##name)) {g_sys_##name = (sys_##name##_t)dlsym(RTLD_NEXT,#name);}

[0043] / / User-mode system call management

[0044] void* SystemCallInterfaceName(size_t size)

[0045] {

[0046] TRY_LOAD_HOOK_FUNC(SystemCallInterfaceName);

[0047] / / Add pre-processing for system calls

[0048] void *p = g_sys_SystemCallInterfaceName(size);

[0049] / / Add post-processing for system calls

[0050] }

[0051] Step 2: Use the kprobe debugging tool of the Xinchuang operating system kernel to customize the kernel-mode system call:

[0052] Create a new system call: Use kprobe to obtain the kernel system call table pointer. According to the kernel system call table pointer, specify the function at the reserved index in the system call table to create a new system call interface.

[0053] When creating a new system call, it specifically includes: using kprobe to obtain the kernel system call table pointer based on the function corresponding address returned by the kallsyms_lookup_name function. The kallsyms_lookup_name function is used to find the function symbol in the kernel symbol table and return the function corresponding address. According to the kernel system call table pointer, specify the function at the reserved index in the system call table for creating a new system call interface. The system call table reserved index is some system call index numbers reserved by the domestic information technology innovation operating system, which do not implement specific business logic and are used to implement new system call logic. For example, the reserved index numbers are from 441 to 456.

[0054] For example, the code sample can be referred to as follows:

[0055] / / Implementation of the newly created system call function

[0056] asmlinkage long newly_created_system_call_function(const struct pt_regs *regs) {

[0057] / / Newly created system call business logic

[0058] return 0;

[0059] }

[0060] / / kprobe preprocessing function

[0061] preprocessing_function(struct kprobe *p, struct pt_regs *regs)

[0062] {

[0063] / / Obtain the address of the specified function

[0064] kln_addr = (--regs->ip);

[0065] return 0;

[0066] }

[0067] / / Kernel state system call management module initialization function

[0068] static int newly_created_system_call_initialization_function(void)

[0069] {

[0070] / / Obtain the address of the function "kallsyms_lookup_name" through the kprobe preprocessing function

[0071] kp->symbol_name = "kallsyms_lookup_name";

[0072] kp->pre_handler = preprocessing_function;

[0073] / / Register kprobe

[0074] ret = register_kprobe(kp);

[0075] / / Obtain the system call table through the function "kallsyms_lookup_name"

[0076] kln_pointer = (unsigned long (*)(const char *name)) kln_addr;

[0077] __sys_call_table = kln_pointer("sys_call_table");

[0078] / / Specify the reserved index 450 as the newly created system call function

[0079] __sys_call_table

[450] = (unsigned long) newly_created_system_call_function;

[0080] return 0;

[0081] }

[0082] / / User-mode system call program

[0083] int main()

[0084] {

[0085] syscall(newly_created_system_call_number, system_call_parameters);

[0086] return 0;

[0087] }

[0088] Replace system call logic: Replace the system call logic by modifying the function at the reserved index in the specified system call table.

[0089] When replacing the system call logic, it specifically includes: obtaining the reserved index in the system call table, obtaining the index number based on the reserved index, and each index number corresponds to a system call interface.

[0090] Replace the system call logic corresponding to the system call interface by modifying the function at the reserved index in the specified system call table.

[0091] Add pre - processing for system calls: Specify a pre - processing function for pre - processing system calls in kernel mode.

[0092] When adding pre - processing for system calls, specifically include: Use kprobe to find the name of the system call function that needs to add pre - processing in the kernel symbol table, and specify the system call function corresponding to the system call function name as the pre - processing function.

[0093] For example, the code sample can be referred to as follows:

[0094] / / Specify the kprobe kernel symbol as the name of the system call function that needs to add pre - processing

[0095] static struct kprobe kp = {

[0096] .symbol_name = the name of the system call function that needs to add pre - processing,

[0097] };

[0098] / / System call pre - processing function

[0099] static int pre - processing function(struct kprobe *p, struct pt_regs *regs)

[0100] {

[0101] / / Pre - processing logic

[0102] }

[0103] / / System call pre - processing kernel module

[0104] static int __init system call pre - processing function initialization(void)

[0105] {

[0106] / / Specify the pre - processing function

[0107] kp.pre_handler = pre - processing function;

[0108] ret = register_kprobe(&kp);

[0109] return 0;

[0110] }

[0111] Embodiment 2: Combination Figure 2 The present invention provides a customized call device for a domestic information technology operating system, including a user-mode system call management module and a kernel-mode system call management module.

[0112] The user-mode system call management module uses the gcc compilation tool to write a user-mode hook function and customizes the user-mode system call using the user-mode hook function:

[0113] In the Glibc component, the user-mode system call syscall of the system call interface posix is intercepted through the user-mode hook function; the user-mode function to be called is assigned as the system call function through the user-mode hook function; the user-mode function to be called is called when a user-mode system call occurs subsequently; and pre-processing logic is added before the system call interface for pre-processing of business logic, and post-processing logic is added after the system call interface for post-processing of business logic.

[0114] The kernel-mode system call management module uses the debugging tool kprobe of the operating system kernel to customize the kernel-mode system call:

[0115] New system call: Use kprobe to obtain the kernel system call table pointer, and according to the kernel system call table pointer, specify the function at the reserved index in the system call table for creating a new system call interface, that is, specify the reserved index 64 as the newly created system call function, and create a new system call syscall_64.tbl.

[0116] Replace system call logic: Replace the system call logic by modifying the function at the reserved index in the specified system call table.

[0117] Add pre-processing for system call: Specify a pre-processing function for pre-processing of kernel-mode system calls.

[0118] After the kernel-mode system call management module is successfully built, it can be loaded into the domestic information technology operating system kernel through the insmod command.

[0119] Regarding the information interaction and execution process between the above-mentioned device modules, etc., since they are based on the same concept as the method embodiment of the present invention, the specific content can be referred to the description in the method embodiment of the present invention and will not be elaborated here.

[0120] Similarly, the device of the present invention realizes the system call management between the user mode and the kernel mode, supports the pre-processing of user-mode system calls, supports the post-processing of user-mode system calls, supports the creation of new kernel-mode system call interfaces, supports the replacement of kernel-mode system call logic, and supports the pre-processing of kernel-mode system calls. Without changing the kernel of the domestic information technology innovation operating system, it realizes the customization of the system call logic of the domestic information technology innovation operating system, maintains the overall integrity of the domestic information technology innovation operating system, ensures the stability and compatibility of the domestic information technology innovation operating system, and ensures the business logic of the application.

[0121] It should be noted that not all steps and modules in the above-mentioned processes and device structures are necessary, and some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted according to needs. The system structure described in the above embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities respectively, or some components in multiple independent devices may be jointly implemented.

[0122] The above-described embodiments are only preferred embodiments given to fully illustrate the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or transformations made by those skilled in the art on the basis of the present invention are within the protection scope of the present invention. The protection scope of the present invention is subject to the claims.

Claims

1. A customized calling method for a trusted operating system, characterized by: include: Step 1: Use the gcc compiler tool to write a user-mode hook function, and use the user-mode hook function to customize the user-mode system call: In the Glibc component, the user-state system call of the system call interface is intercepted through the user-state hook function; the user-state function to be called is assigned as the system call function through the user-state hook function; the user-state function to be called is called when the user-state system call occurs subsequently; and the pre-processing logic is added before the system call interface for the pre-processing of the business logic, and the post-processing logic is added after the system call interface for the post-processing of the business logic; Step 2: Use the debugging tool kprobe of the Xinchuang operating system kernel to customize the kernel-mode system call: Create a new system call: Use kprobe to obtain the kernel system call table pointer. According to the kernel system call table pointer, specify the function with the reserved index in the system call table to create a new system call interface. Replace system call logic: Replace the system call logic by modifying the function of the reserved index in the specified system call table; Add system call pre-processing: specify the pre-processing function for pre-processing of kernel-mode system calls.

2. According to the customized calling method of the information creation operating system described in claim 1, it is characterized by When creating a new system call in step 2, it specifically includes: using kprobe to obtain the kernel system call table pointer according to the function corresponding address returned by the kallsyms_lookup_name function, the kallsyms_lookup_name function is used to find the function symbol in the kernel symbol table and return the function corresponding address, according to the kernel system call table pointer, specify the function of the reserved index in the system call table for creating a new system call interface.

3. According to the customized calling method of the information creation operating system described in claim 1, it is characterized by When replacing the system call logic in step 2, it specifically includes: obtaining a reserved index in the system call table, obtaining an index number according to the reserved index, each index number corresponds to a system call interface, Replace the system call logic corresponding to the system call interface by modifying the function of the reserved index in the specified system call table.

4. According to the customized calling method of the information creation operating system described in claim 1, it is characterized by When adding the system call pre-processing in step 2, specifically including: using kprobe to find the system call function name that needs to add the pre-processing in the kernel symbol table, and specifying the system call function corresponding to the system call function name as the pre-processing function.

5. A customized calling device for a trusted operating system, characterized in that Including user-mode system call management module and kernel-mode system call management module, The user-mode system call management module uses the gcc compiler tool to write user-mode hook functions and uses user-mode hook functions to customize user-mode system calls: In the Glibc component, the user-state system call of the system call interface is intercepted through the user-state hook function; the user-state function to be called is assigned as the system call function through the user-state hook function; the user-state function to be called is called when the user-state system call occurs subsequently; and the pre-processing logic is added before the system call interface for the pre-processing of the business logic, and the post-processing logic is added after the system call interface for the post-processing of the business logic; The kernel-mode system call management module uses the debugging tool kprobe of the Xinchuang operating system kernel to customize the kernel-mode system call: Create a new system call: Use kprobe to obtain the kernel system call table pointer. According to the kernel system call table pointer, specify the function with the reserved index in the system call table to create a new system call interface. Replace system call logic: Replace the system call logic by modifying the function of the reserved index in the specified system call table; Add system call pre-processing: specify the pre-processing function for pre-processing of kernel-mode system calls.

6. According to the customized calling device of the information creation operating system according to claim 5, it is characterized by When the kernel-mode system call management module creates a new system call, it specifically includes: using kprobe to obtain the kernel system call table pointer according to the function corresponding address returned by the kallsyms_lookup_name function, the kallsyms_lookup_name function is used to find the function symbol in the kernel symbol table and return the function corresponding address, according to the kernel system call table pointer, specify the function of the reserved index in the system call table for creating a new system call interface.

7. According to claim 5, a customized calling device for a trusted operating system is characterized by: When the kernel-mode system call management module replaces the system call logic, it specifically includes: obtaining a reserved index in the system call table, obtaining an index number according to the reserved index, each index number corresponds to a system call interface, Replace the system call logic corresponding to the system call interface by modifying the function of the reserved index in the specified system call table.

8. According to claim 5, a customized calling device for a trusted operating system is characterized by: When the kernel-mode system call management module adds a system call pre-processing, it specifically includes: using kprobe to find the system call function name that needs to add pre-processing in the kernel symbol table, and specifying the system call function corresponding to the system call function name as the pre-processing function.

Citation Information

Patent Citations

  • Message asynchronous forwarding system based on Linux operating system and method

    CN109587082A

  • Linux kernel system calling and parameter transferring method

    CN113868668A