Binary translation method, binary translator, electronic device and readable storage medium

By mapping the first virtual page to the second virtual page during the binary translation process, and using the writeable permissions of the second virtual page to perform the write operation of the self-modified code, the invalid operation and redundant retranslation problems caused by the self-modified code are solved, and the performance of the translation system is improved.

CN119718339BActive Publication Date: 2025-06-06LOONGSON TECH CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510221931.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-06-06
Estimated Expiration
2045-02-26

AI Technical Summary

Technical Problem

During the binary translation process, invalid operations and redundant retranslation caused by self-modification of the code affect the performance of the translation system.

Method used

By mapping the first virtual page to the second virtual page in a shared mapping, the write operation of the self-modifying code is performed using the writable permissions of the second virtual page, and only the corresponding target basic block is invalidated, the self-modifying operation is completed with a smaller granularity.

Benefits of technology

Reduces unnecessary invalid operations and redundant retranslation, and improves the performance of the translation system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119718339B_ABST
    Figure CN119718339B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a binary translation method, a binary translator, an electronic device and a readable storage medium, the method comprising: in the case of determining that a self-modifying code is detected, mapping a first virtual page to a second virtual page in a shared mapping manner; the first virtual page is a virtual page where the write address of the self-modifying code is located; the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable; according to the write address of the self-modifying code, searching for the translated target basic block, and modifying the valid flag bit of the target basic block to invalid; based on the write address of the self-modifying code, writing the self-modifying code at the corresponding position in the second virtual page. The embodiment of the present invention completes the self-modifying operation with a smaller granularity and a lower cost, which can reduce redundant invalid operations, reduce redundant re-translation operations, and improve the performance of the translation system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a binary translation method, a binary translator, an electronic device and a readable storage medium. Background Art

[0002] Binary translation can convert the binary code of one ISA (Instruction Set Architecture) into the binary code of another instruction set architecture. Through binary translation technology, an application of one ISA (source architecture) can run on another ISA (target architecture).

[0003] Self-modifying code is a dynamic code generation technology in the computer field that allows the program to directly modify the original machine instructions in the memory or add new machine instructions through memory access instructions during runtime, and then execute them, thereby reducing the instruction path length and improving program execution performance.

[0004] When the translator detects self-modifying code, it needs to invalidate the previously translated host basic blocks in the code cache. This is because the client basic blocks have changed at this time, and the originally translated host basic blocks can no longer correctly correspond to the client basic blocks at this time, so they need to be re-translated to prevent incorrect execution.

[0005] However, since the operating system manages permissions on a page basis, when self-modifying code appears in a client basic block, it is necessary to invalidate the host basic blocks corresponding to all client basic blocks on the page where the client basic block is located. This generates a large number of redundant invalid operations, adds a large number of redundant re-translation operations, and affects the performance of the translation system. Summary of the invention

[0006] In view of the above problems, an embodiment of the present invention is proposed to provide a binary translation method that overcomes the above problems or at least partially solves the above problems, completes self-modification operations with smaller granularity and lower cost, can reduce redundant invalid operations, reduce redundant re-translation operations, and improve the performance of the translation system.

[0007] Correspondingly, the embodiment of the present invention also provides a binary translator, an electronic device, and a computer program product to ensure the implementation and application of the above method.

[0008] In a first aspect, an embodiment of the present invention discloses a binary translation method, which is applied to a binary translator. The method includes:

[0009] In the case where it is determined that the self-modifying code is detected, the first virtual page is mapped to the second virtual page in a shared mapping manner; the first virtual page is a virtual page where the write address of the self-modifying code is located; the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable;

[0010] According to the write address of the self-modifying code, searching for the translated target basic block, and modifying the valid flag bit of the target basic block to be invalid;

[0011] Based on the write address of the self-modifying code, the self-modifying code is written at a corresponding position in the second virtual page.

[0012] In a second aspect, an embodiment of the present invention discloses a binary translator, the binary translator comprising:

[0013] A memory mapping module, configured to map a first virtual page to a second virtual page in a shared mapping manner when it is determined that a self-modifying code is detected; the first virtual page is a virtual page where a write address of the self-modifying code is located; the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable;

[0014] A basic block invalidation module, used for searching the translated target basic block according to the write address of the self-modifying code, and modifying the valid flag bit of the target basic block to be invalid;

[0015] The self-modifying execution module is used to write the self-modifying code into a corresponding position in the second virtual page based on the write address of the self-modifying code.

[0016] In the third aspect, an embodiment of the present invention discloses an electronic device, comprising: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus; the memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute the steps of the binary translation method as described in any of the above.

[0017] In a fourth aspect, an embodiment of the present invention discloses a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the binary translation method as described in any of the above can be implemented.

[0018] In a fifth aspect, an embodiment of the present invention discloses a computer program product, including a computer program, which, when executed by a processor, performs the steps of any of the aforementioned binary translation methods.

[0019] The embodiments of the present invention include the following advantages:

[0020] In the binary translation process, the embodiment of the present invention optimizes the process of processing self-modifying codes. When the self-modifying code is detected, the first virtual page is mapped to the second virtual page in a shared mapping manner, so that the second virtual page is mapped to the physical memory corresponding to the first virtual page. In addition, the embodiment of the present invention maintains the permissions of the first virtual page unchanged (still not writable), and sets the permissions of the second virtual page to be writable, so that the write operation to the second virtual page has the same effect as the write operation to the first virtual page, and the write operation of the self-modifying code can be performed using the second virtual page. Furthermore, since the embodiment of the present invention does not need to restore the write permission of the first virtual page, an exception can still be triggered when the client program performs a write operation on the first virtual page (such as executing a self-modifying code), so that the binary translator can detect the self-modifying behavior. Therefore, there is no need to invalidate the host basic blocks corresponding to all client basic blocks in the entire first virtual page. Instead, a second virtual page with a shared mapping relationship is set for the first virtual page, and the basic block is modified based on the second virtual page. This achieves the granularity of the basic block, and only invalidates the target basic block corresponding to the write address of the self-modifying code. This achieves the self-modifying operation with a smaller granularity and a lower cost, which can reduce unnecessary invalid operations, reduce redundant re-translation operations, and improve the performance of the translation system. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a schematic diagram of the architecture of a dynamic binary translation of the present invention;

[0022] Figure 2 is a flowchart of a binary translation method embodiment of the present invention;

[0023] Figure 3 This is a schematic diagram of the binary translator modifying page permissions;

[0024] Figure 4 is a schematic diagram of performing a write operation using a second virtual page according to an embodiment of the present invention;

[0025] Figure 5 is a structural block diagram of a binary translator embodiment of the present invention;

[0026] Figure 6 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0027] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0028] The terms "first", "second", etc. in the specification and claims of the present invention are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable when appropriate, so that the embodiments of the present invention can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, the term "and / or" in the specification and claims is used to describe the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. In the embodiments of the present invention, the term "multiple" refers to two or more, and other quantifiers are similar.

[0029] Reference Figure 1 , shows a schematic diagram of the architecture of dynamic binary translation. Figure 1 As shown in the figure, dynamic binary translation adopts the "translate while running" method to translate the instructions of the client architecture into the instructions of the host architecture at runtime and run them on the host. After the translator reads the binary file of the target program, it translates and executes it according to the granularity of basic blocks (Translation Block, TB). A basic block usually ends with a control flow change instruction (such as an indirect jump instruction, a function call instruction, etc.). Before executing a basic block, it first searches in the code cache. If a translated basic block is found, it executes the basic block. If a translated basic block is not found in the code cache, it translates the basic block and puts the translated basic block into the code cache, and then executes the translated basic block. After executing a basic block, it searches for the next basic block in the code cache, and repeats this cycle until the program execution ends.

[0030] In the embodiment of the present invention, the untranslated basic block is called a client basic block. After translating the client basic block, a translated host code instruction stream (called a host basic block) is obtained, and the host basic block is stored in a code cache.

[0031] Before translating each client basic block, the binary translator sets the permissions of the page where the client basic block is located to non-writable, and records the original permissions of the page in the page descriptor of the page. The page descriptor (such as PageDesc) is a data structure used for memory management inside the binary translator, which is used to describe various attributes and information of a page. The binary translator removes the write permission of the page containing the client basic block in order to trigger an exception when the client program writes to this page (such as executing self-modifying code), so that the self-modifying behavior can be detected, and the binary translator can process the self-modifying code.

[0032] The page mentioned in the embodiment of the present invention refers to a virtual page. A virtual page is a concept in a virtual memory management system. Virtual memory is an abstraction provided by the operating system for each process, so that each process believes that it has a continuous, large address space, and this address space is divided into multiple virtual pages of equal size. The virtual pages of different processes can be mapped to the same or different physical memories, and this mapping relationship can be managed by the page table mechanism of the operating system.

[0033] The first virtual page refers to a virtual page in a host environment that simulates a client environment. For example, a first virtual page is recorded as PAGE1. PAGE1 may contain one or more client basic blocks, such as client basic blocks TB1, TB2, ...TBn. The smallest unit of self-modifying code is usually based on basic blocks. For example, self-modifying code needs to modify one or several basic blocks. If there is self-modifying code in the client program, TB2 will be modified during the program running. However, since the operating system controls read and write permissions in units of pages. Although the self-modifying code only needs to modify the client basic block TB2, it is necessary to invalidate the host basic blocks corresponding to all client basic blocks in the page (such as PAGE1) where the client basic block TB2 is located. When TB1, TB2, ...TBn are executed again, since TB1, TB2, ...TBn are all invalidated, TB1, TB2, ...TBn need to be re-translated, resulting in redundant translation operations, affecting translation performance.

[0034] Reference Figure 2 , shows a flowchart of a binary translation method embodiment of the present invention, the method is applied to a binary translator, and the method may include the following steps:

[0035] Step 101: When it is determined that a self-modifying code is detected, a first virtual page is mapped to a second virtual page in a shared mapping manner; the first virtual page is a virtual page where a write address of the self-modifying code is located; the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable;

[0036] Step 102: according to the write address of the self-modifying code, find the translated target basic block, and modify the valid flag bit of the target basic block to invalid;

[0037] Step 103: Write the self-modifying code into a corresponding position in the second virtual page based on the write address of the self-modifying code.

[0038] The binary translation method provided by the embodiment of the present invention can be applied to a binary translator to optimize the processing of self-modifying codes during dynamic binary translation, thereby completing the self-modifying operation with smaller granularity and lower cost.

[0039] In the case where it is determined that self-modifying code is detected, the embodiment of the present invention implements invalidation of host basic blocks at the granularity of basic blocks through page permission remapping combined with software write simulation technology.

[0040] Specifically, when it is determined that a self-modifying code is detected, the first virtual page is mapped to the second virtual page in a shared mapping manner. Shared mapping can realize data sharing, and modifications to the mapping area will be reflected in the mapped file or device. That is, the operation performed on the second virtual page is equivalent to the operation performed on the first virtual page.

[0041] The first virtual page is the virtual page where the write address of the self-modifying code is located, such as the first virtual page is PAGE1; the second virtual page is a newly applied virtual page, such as Parallel_PAGE1. It is obtained that the two virtual pages PAGE1 and Parallel_PAGE1 are mapped to the same physical memory (physical page), and are both mapped to the physical memory corresponding to PAGE1, but the permissions of the two virtual pages are different. The write permission of the first virtual page (such as PAGE1) is removed by the binary translator, so the permission of the first virtual page (such as PAGE1) is not writable. The permission of the second virtual page (such as Parallel_PAGE1) is writable. The embodiment of the present invention maps the first virtual page to the second virtual page with write permission in a shared mapping manner, thereby realizing the remapping of the permissions of the first virtual page, and the self-modifying code can be written by operating the second virtual page.

[0042] It should be noted that since the self-modifying code needs to modify the instructions in the first virtual page, it is necessary to perform a write operation on the first virtual page, and the first virtual page does not have write permission. Therefore, the embodiment of the present invention sets the second virtual page to have write permission, and for other permissions, such as read (R) permission and execute (X) permission, the second virtual page can be consistent with the first virtual page.

[0043] Before translating each client basic block, the binary translator sets the permission of the page where the client basic block is located to non-writable. Figure 3 , which shows a schematic diagram of a binary translator modifying page permissions. Figure 3 As shown, the operating system controls read and write permissions in units of pages. Assume that the original permission of page PAGE1 is RWX, which originally has write permission. Before translating the guest basic block in PAGE1, the binary translator removes the write permission of PAGE1, so that the permission of PAGE1 becomes RX, and the permission of PAGE1 becomes non-writable. Assume that PAGE1 contains the following guest basic blocks: GuestB1, GuestB2, and GuestB3. Assume that PAGE2 contains self-modifying code for modifying the guest basic block GuestB2 in PAGE1. After the translation of GuestB1, GuestB2, and GuestB3 is completed, the corresponding host basic blocks are obtained: HostB1, HostB2, and HostB3, which are saved in the code cache. It should be noted that the permission of PAGE1 has been set to non-writable when translating GuestB1. Therefore, when translating GuestB2, it is detected that the permission of PAGE1 is no longer writable, and there is no need to set it again.

[0044] PageDesc1 is the page descriptor of PAGE1, which is used to describe various attributes and information of PAGE1, including the original permission RWX of PAGE1 and the related information of the translated host basic block.

[0045] When the binary translator executes the self-modifying code in PAGE2, the write instruction of the self-modifying code is used to modify the guest basic block GuestB2 in PAGE1. Since the page (PAGE1) where the write address of the self-modifying code (the address to be operated by the write instruction, such as the address of GuestB2) is located does not have write permission at this time, a write address exception will be triggered, and the exception handling function registered in advance for handling the write address exception will be entered.

[0046] The exception handling function can determine whether the original permissions of the current page (the page that triggers the write address exception, i.e., PAGE1) are writable based on the original permissions recorded in the page descriptor PageDesc1 of the current page (the page that triggers the write address exception). If the original permissions are writable, it means that the write permissions of the page are removed by the translator during translation rather than by the client program. It can be determined that the write address exception is caused by the self-modifying code, and therefore it can be determined that the self-modifying code is detected.

[0047] In the case of self-modifying code being detected, if the unoptimized solution is adopted, it is necessary to invalidate the translated host basic blocks (such as HostB1, HostB2 and HostB3) corresponding to all guest basic blocks (such as GuestB1, GuestB2 and GuestB3) in the current page (such as PAGE1), and use the original permissions recorded in the page descriptor PageDesc1 corresponding to the page to reset the permissions of the page, that is, restore the write permissions of the page. The program execution flow returns to the write instruction that triggers the write address exception. At this time, the page (PAGE1) has restored the write permission and can be written normally. The client program can write the self-modifying code normally. At this time, GuestB2 in this example has been modified. Since the host basic block (HostB2) corresponding to the guest basic block (GuestB2) where the write address is located has been invalidated, when the guest basic block is executed, the write permission of the page will be removed again and the guest basic block (modified HostB2) will be retranslated. However, when GuestB1 or GuestB3 is executed again, HostB1 and HostB3 need to be translated again because both HostB1 and HostB3 are invalidated.

[0048] Although the smallest unit of self-modifying code is a basic block, if you want to modify GuestB2, the unoptimized solution needs to invalidate the translated host basic blocks corresponding to all client basic blocks in the page where GuestB2 is located. The reason is that if there are concurrent self-modifying behaviors of other basic blocks in the page where GuestB2 is located, for example, there is a self-modifying behavior to modify GuestB3 at the same time, in this case, since the write permission of PAGE1 is released with the self-modifying behavior of GuestB2, when modifying GuestB3, the write address exception will no longer be triggered, resulting in the situation that GuestB3 is modified but the translator cannot perceive it, which in turn causes HostB3 to be inconsistent with GuestB3 at this time, resulting in a translation error. Therefore, in order to avoid this error, it is necessary to invalidate the translated host basic blocks corresponding to all client basic blocks on PAGE1, and it is impossible to truly implement self-modifying behavior at the granularity of basic blocks.

[0049] In the optimized scheme of the embodiment of the present invention, when it is determined that the self-modifying code is detected, the first virtual page is mapped to the second virtual page with write permission in a shared mapping manner, and the permission of the first virtual page remains non-writable, but the self-modifying code is written by operating the second virtual page. The characteristic of shared mapping is that multiple virtual pages can be mapped to the same physical page, and the same data can be accessed through any of the virtual pages, and multiple virtual pages can have their own independent permissions, so the write permission of the first virtual page can be restored, but the self-modification behavior is completed in the exception handling function through the second virtual page of the shared mapping. For example, to modify GuestB2, since the page (PAGE1) where the address of GuestB2 is located has no write permission, a write address exception will be triggered and the exception handling function will be entered. In the exception handling function, PAGE1 is mapped to the second virtual page Parallel_PAGE1 with write permission in a shared mapping manner, and GuestB2 is modified through Parallel_PAGE1, and only HostB2 is invalidated. Even if there is a self-modification code for modifying GuestB3 at the same time, since PAGE1 still has no write permission, modifying GuestB3 will trigger a write address exception, enter the exception handling function, and perform the self-modification operation on GuestB3 in the exception handling function. Through the optimized solution of the embodiment of the present invention, for the concurrent self-modification behavior of multiple basic blocks in the same page, the translator can perceive the self-modification operation of each basic block and trigger the corresponding exception handling function for processing, which can ensure the correctness of the translation. Thus, the self-modification behavior with basic block as the granularity can be truly realized.

[0050] In an optional embodiment of the present invention, mapping the first virtual page to the second virtual page in a shared mapping manner may include:

[0051] Step S11, creating an anonymous file descriptor, binding the first virtual page to the anonymous file descriptor, and setting the memory mapping attribute of the first virtual page to shared mapping;

[0052] Step S12: Apply for a second virtual page, set the permission of the second virtual page to be writable, and bind the second virtual page to the anonymous file descriptor.

[0053] In the embodiment of the present invention, when it is determined that the self-modifying code is detected, an anonymous file descriptor (such as denoted as fd) is created. The anonymous file descriptor is a special file descriptor that is not associated with any file in the actual file system, but is directly associated with the memory.

[0054] An anonymous file descriptor is presented as a non-negative integer, which is returned to the program by the operating system when the system call that creates the anonymous file descriptor is called. Here, fd is an integer representing the anonymous file descriptor, and the program can subsequently use this integer as a parameter to call other system calls to operate on the resources associated with it.

[0055] For example, anonymous file descriptors combined with memory mapping-related system calls, such as the mmap system call in Linux, can be used to implement shared memory. Multiple processes can access the same memory area through the same anonymous file descriptor, thereby achieving data sharing.

[0056] The embodiment of the present invention modifies the memory mapping attribute of the first virtual page (such as PAGE1) from private mapping (MAP_PRIVATE) to shared mapping (MAP_SHARED), and establishes a binding relationship between the first virtual page and the anonymous file descriptor fd, while maintaining the permissions of the first virtual page unchanged (i.e., still not writable).

[0057] In addition, a new virtual page (second virtual page) can be applied for using the corresponding system call, such as Parallel_PAGE1. The second virtual page is a virtual page in the host environment. The second virtual page is also bound to the anonymous file descriptor fd, and the permission of the second virtual page is set to writable. Thus, the physical page mapped by the first virtual page is mapped to the second virtual page in a shared mapping manner, and the write operation to the second virtual page has the same effect as the write operation to the first virtual page.

[0058] In different operating systems, the form of the system call for applying for virtual pages may be different, such as the mmap system call in Linux. Taking the Linux system as an example, the form of the mmap system call is as follows:

[0059] void *mmap(void *addr, size_t length, int prot, int flags, int fd, off_t offset);

[0060] The fd parameter is passed in to the anonymous file descriptor created above, and the flags parameter is passed in to the shared mapping attribute (MAP_SHARED). Shared mapping is a mode of memory mapping that allows multiple virtual addresses to share the contents of the same physical memory area.

[0061] It should be noted that in order to avoid data loss or error in the first virtual page after a shared mapping is established between the first virtual page and the second virtual page, the data in the first virtual page can be copied to a temporary area before the first virtual page is bound to the anonymous file descriptor, and after the first virtual page is bound to the anonymous file descriptor, the data in the first virtual page can be copied from the temporary area to the first virtual page to ensure that the data in the first virtual page remains consistent before and after the shared mapping is established with the second virtual page.

[0062] Next, the target basic block is found and invalidated at a basic block granularity, and the self-modifying code is written in the second virtual page.

[0063] The embodiment of the present invention utilizes shared mapping to additionally create a second virtual page (Parallel_PAGE1) with write permission. When it is determined that self-modifying code is detected, the binary translator can utilize various internally maintained fields, combined with software write simulation technology, to utilize the second virtual page (Parallel_PAGE1) to implement the write operation of the self-modifying code.

[0064] Reference Figure 4 , shows a schematic diagram of performing a write operation using a second virtual page according to an embodiment of the present invention. Figure 4 As shown, since the first virtual page (PAGE1) and the second virtual page (Parallel_PAGE1) are mapped to the same physical page, the write operation performed on the newly applied mapped page (the second virtual page) has the same effect as the write operation performed on the original page (the first virtual page).

[0065] by Figure 3 For example, if the optimization method of steps 101 to 103 is adopted, only the target basic block HostB2 needs to be invalidated, and HostB1 and HostB3 remain valid. The next time when GuestB1, GuestB2 and GuestB3 are executed, since HostB2 has been invalidated, and HostB1 and HostB3 are still valid, only GuestB2 needs to be retranslated, and GuestB1 and GuestB3 do not need to be retranslated. In this way, redundant invalid operations can be reduced, redundant retranslation operations can be reduced, and the performance of the translation system can be improved.

[0066] In an optional embodiment of the present invention, the method may further include:

[0067] Before translating the client basic block in the first virtual page, the permission of the first virtual page is set to be non-writable, and the original permission of the first virtual page is recorded in the page descriptor corresponding to the first virtual page.

[0068] Before translating the client basic block, the binary translator sets the permission of the page (such as the first virtual page) containing the client basic block to be non-writable, and records the original permission of the page in the page descriptor of the page. The binary translator removes the write permission of the page in order to trigger an exception when the client program writes to the page (such as executing self-modifying code), so that the self-modifying behavior can be detected, and the binary translator can process the self-modifying code.

[0069] Further, the determining that the self-modifying code is detected may include:

[0070] Step S21, when receiving a write address exception signal triggered by executing a write instruction on the first virtual page, calling an exception handling function corresponding to the write address exception signal;

[0071] Step S22: In the exception handling function, the original permission of the first virtual page is obtained through the page descriptor corresponding to the first virtual page; if the original permission of the first virtual page is writable, it is determined that the self-modifying code is detected.

[0072] In an embodiment of the present invention, the exception handling function is a signal handling function registered in advance for the write address exception signal. When the self-modifying code attempts to modify a non-writable page (such as the first virtual page PAGE1), the hardware will detect the illegal operation and trigger a write address exception. After the operating system captures this exception, it will generate a corresponding signal (such as SIGSEGV) according to the exception type, which is called a write address exception signal. The operating system sends the generated write address exception signal to the process that caused the exception, that is, the binary translator. After receiving the write address exception signal, the binary translator suspends the current execution process, calls the previously registered exception handling function, and jumps to the exception handling function for execution.

[0073] In the exception handling function, the original permissions of the first virtual page can be obtained by querying the original permissions recorded in the page descriptor corresponding to the first virtual page; if the original permissions of the first virtual page are writable, it means that the write permissions of the first virtual page are removed by the binary translator during translation, rather than by the client program, and the write address exception is caused by self-modifying code, so it can be determined that the self-modifying code is detected.

[0074] In an optional embodiment of the present invention, searching for a translated target basic block according to a write address of the self-modifying code may include:

[0075] According to the write address that triggers the write address exception, a page base address corresponding to the write address is calculated; according to the page base address, a client basic block corresponding to the write address is searched; according to the client basic block corresponding to the write address, a translated target basic block is searched.

[0076] In an embodiment of the present invention, when a self-modifying code triggers a write address exception, the page base address (such as the base address of PAGE1) corresponding to the write address that triggers the write address exception can be calculated, and the guest basic block (such as GuestB2) corresponding to the write address in the page can be searched based on the page base address, thereby finding the translated target basic block (such as the host basic block HostB2) corresponding to the guest basic block, and then the valid flag bit of the target basic block (such as HostB2) can be modified to invalid.

[0077] When the self-modifying code triggers a write address exception, the write address is a location where the program attempts to modify its own code. The embodiment of the present invention does not limit the method for obtaining the write address.

[0078] In a specific implementation, the write instruction of the self-modifying code contains relevant information of the write operation, such as what value (source register) is to be written to where (destination register represents the address). Take the write instruction st.d as an example: st.d reg1,reg2,imm. In this write instruction, reg2 represents the base address (base) of the write address, and the immediate number imm represents the offset of the write address based on the base address (base). Therefore, "reg2+imm" is the write address of the write instruction, and reg1 represents the specific value to be written to the write address "reg2+imm". Therefore, the write address can be obtained according to the write instruction of the self-modifying code. Exemplarily, both reg1 and reg2 can represent different register identifiers, the register identified by reg1 contains the specific value to be written to the write address, and the register identified by reg2 contains the base address of the write address.

[0079] In addition, when the self-modifying code triggers a write address exception, the operating system kernel will detect that the program attempts to write to a non-writable address, and the kernel will save the process's signal context, which contains the write address of the instruction that triggered the exception. After detecting the exception, the operating system kernel will save the signal context information and pass it to the signal processing function (i.e., exception processing function) registered by the user program. The binary translator can obtain the write address that triggered the exception from the signal context information returned by the operating system kernel.

[0080] According to the write address that triggers the exception, the page base address corresponding to the write address (such as the base address of PAGE1) can be obtained.

[0081] Assuming the page size is PAGE_SIZE and the write address is write_addr, the page base address can be calculated as follows: First, subtract 1 from the page size PAGE_SIZE and invert it to get the page-aligned mask mask, that is, mask is: ~(PAGE_SIZE-1). Then, perform a bitwise AND operation on the write address write_addr and the mask mask to get the page base address. For example, if the page size PAGE_SIZE is 4k (4096) and the write address write_addr is 0x3004, first calculate the page-aligned mask mask as 0xfffff000, and then calculate the page base address as 0x3004&0xfffff000=0x3000.

[0082] According to the page base address, the client basic block (such as GuestB2) corresponding to the write address in the page can be found, thereby finding the translated target basic block (such as HostB2) corresponding to the client basic block, and modifying the valid flag bit of the target basic block to invalid.

[0083] In a specific implementation, a data structure (such as a hash table, a tree structure, or an array, etc.) can be maintained to store the information of the basic blocks in the page. This data structure can contain the information of the client basic blocks and the location information of the client basic blocks in the page. For example, a mapping table can be used to map the page base address to the basic block list in the page. Each basic block contains information such as its starting address and ending address. By traversing the basic block list in the page and checking the address range of each basic block, the client basic block containing the write address can be found. For example, it can be checked whether the write address is between the starting address and the ending address of the client basic block. If so, a pointer to the client basic block is returned, otherwise NULL is returned.

[0084] Furthermore, the binary translator can map the client basic block to the translated host basic block through a translation mapping table. This mapping table stores the correspondence between the client basic block and its corresponding translated host basic block. For example, a hash table can be used to store this mapping relationship. The address of the client basic block can be found according to the write address, and then the corresponding host basic block (target basic block) can be found in the hash table.

[0085] The target basic block (such as HostB2) has a valid flag, which is used to indicate whether the basic block is still valid. The valid flag can be stored in the metadata of the target basic block, or stored in a separate data structure, and is associated with the address of the target basic block. Exemplarily, setting the valid flag of the target basic block to false indicates that the basic block has expired.

[0086] Next, the self-modifying code is written into the second virtual page. Since the second virtual page and the first virtual page correspond to the same physical page, the same effect as that of writing to the first virtual page can be achieved by performing a write operation on the second virtual page.

[0087] In an optional embodiment of the present invention, writing the self-modifying code at a corresponding position in the second virtual page based on the write address of the self-modifying code may include:

[0088] Step S31, obtaining the write address of the self-modifying code and the base address of the first virtual page;

[0089] Step S32: Calculate the offset of the write address of the self-modifying code in the first virtual page based on the write address of the self-modifying code and the base address of the first virtual page;

[0090] Step S33, obtaining the base address of the second virtual page;

[0091] Step S34, calculating a target address corresponding to the write address of the self-modifying code in the second virtual page according to the base address of the second virtual page and the offset of the write address of the self-modifying code in the first virtual page;

[0092] Step S35 : writing the self-modifying code into the second virtual page based on the target address.

[0093] In the embodiment of the present invention, a preset field is added to the page descriptor corresponding to the first virtual page, and the preset field is used to record the base address of the second virtual page.

[0094] Further, the obtaining the base address of the second virtual page may include:

[0095] The value of a preset field in the page descriptor corresponding to the first virtual page is read; the preset field is used to record the base address of the second virtual page.

[0096] In the exception handling function, if it is determined that the write address exception is triggered by the self-modifying code, it is determined that the self-modifying code is detected. At this time, the physical page mapped by the first virtual page can be mapped to the second virtual page in a shared mapping manner, and the base address of the second virtual page can be recorded in the preset field (such as parallel_mapping) of the page descriptor corresponding to the first virtual page.

[0097] Since the preset field parallel_mapping records the base address of the second virtual page with write permission, the write address of the self-modifying code corresponding to the target address on the second virtual page can be calculated through the base address of the second virtual page and the offset of the write address, so that the self-modifying code can be written at the target address on the second virtual page, achieving the same effect as writing the self-modifying code at the write address on the first virtual page.

[0098] In an embodiment of the present invention, the first virtual page PAGE1 is the original virtual page of the client program. The binary translator removes the write permission of PAGE1 when translating the client basic block in PAGE1. When the client program executes the self-modifying code, it attempts to modify its own code. Since PAGE1 is not writable, a write address exception will be triggered. Therefore, the binary translator can intercept each self-modification behavior of the client program. The second virtual page Parallel_PAGE1 is a new virtual page applied by the binary translator to optimize the self-modifying code. The second virtual page corresponds to the same physical page as the first virtual page. Therefore, the data written through the second virtual page Parallel_PAGE1 can also be read from the first virtual page PAGE1.

[0099] In an example, assume that the write instruction of the client program's self-modification code is used to write the value of val to the address mem1=0x4008, that is, the write address is 0x4008. The base address of the first virtual page PAGE1 is 0x4000, and the offset of the write address in the first virtual page refers to the page offset of the write address relative to the base address of the first virtual page. Therefore, the offset of the write address 0x4008 in the first virtual page is 0x8. Assuming that the base address of the second virtual page Parallel_PAGE1 is 0x8000, after intercepting this self-modification behavior, according to the base address 0x8000 of the second virtual page Parallel_PAGE1 and the offset 0x8 of the write address 0x4008 in the first virtual page, the target address of the write address in the second virtual page can be calculated as: 0x8000+0x8=0x8008. Therefore, the value of val is written to the target address 0x8008 in the second virtual page, that is, the write instruction of this self-modification code is completed.

[0100] In an optional embodiment of the present invention, the method may further include:

[0101] Step S41, after determining that the self-modifying code is detected, reading the value of a preset field in the page descriptor corresponding to the first virtual page;

[0102] Step S42: If the value of the preset field is empty, the physical page mapped by the first virtual page is mapped to the second virtual page in a shared mapping manner, and the preset field is assigned the base address of the second virtual page.

[0103] In the embodiment of the present invention, a preset field parallel_mapping is added to the page descriptor of the first virtual page to record the base address of the second virtual page with write permission created by the translator when the self-modifying code writes to the first virtual page for the first time triggering a write address exception. The embodiment of the present invention does not limit the method of adding a preset field. For example, a variable can be added to the structure of the page descriptor to represent the preset field.

[0104] Furthermore, when receiving a write address exception signal, the embodiment of the present invention calls the pre-registered exception handling function corresponding to the write address exception signal. Within the exception handling function, if it is identified that the exception is triggered by the self-modifying code, it is further determined whether the write address triggers the exception for the first time. If it is the first time, the step of mapping the physical page mapped by the first virtual page to the second virtual page in a shared mapping manner is continued, and the base address of the second virtual page is recorded in the preset field of the page descriptor corresponding to the first virtual page.

[0105] The embodiment of the present invention can determine whether the write address triggers the write address exception for the first time by querying whether the value of the preset field in the page descriptor corresponding to the first virtual page is empty. If the value of the preset field is empty, it is determined that the write address triggers the write address exception for the first time; otherwise, it is determined that the write address does not trigger the write address exception for the first time.

[0106] If the value of the preset field in the page descriptor corresponding to the first virtual page is not empty, it means that the write address is not the first time to trigger the write address exception. The first virtual page has been shared mapped before, and the base address of the shared mapped second virtual page with write permission has been recorded in the preset field parallel_mapping. Therefore, there is no need to perform memory mapping again, and the base address of the second virtual page recorded in the preset field can be used directly to continue to execute subsequent steps.

[0107] In an optional embodiment of the present invention, the method may further include:

[0108] After writing the self-modifying code at the corresponding position in the second virtual page, the program counter is pointed to the next instruction.

[0109] The Program Counter (PC) is a register that stores the address of the instruction currently being executed. It indicates the location in memory of the next instruction to be executed.

[0110] In the embodiment of the present invention, the binary translator takes the program counter of the client platform as input, and first searches the code cache to see whether there is a translated host basic block corresponding to the current value of the program counter. If there is, it jumps to the translated host basic block and executes it directly; if not, it enters the translation state for translation. After the current client basic block is translated, the translated host basic block is stored in the code cache, and the execution state is entered to execute the translated host basic block.

[0111] exist Figure 3 In the example of invalidating basic blocks based on page granularity before optimization, the operations performed by the exception handling function include: invalidating the translated host basic blocks corresponding to all client basic blocks in the first virtual page, and restoring the write permission of the first virtual page. Therefore, the program counter (PC) after the exception handling function exits should point to the location that triggers the write address exception, that is, the location of the write instruction of the self-modifying code. At this time, the first virtual page has restored the write permission, and the client program can execute the operation of the write instruction of the self-modifying code.

[0112] After the embodiment of the present invention optimizes the processing of the self-modifying code, the operations performed by the exception handling function include: mapping the first virtual page to the second virtual page in a shared mapping manner, maintaining the permission of the first virtual page as non-writable, setting the permission of the second virtual page as writable, invalidating the host basic block corresponding to the client basic block at the write address that triggers the exception in the first virtual page with the basic block as the granularity, and writing the self-modifying code in the second virtual page. That is, the operation of executing the write instruction of the self-modifying code has been completed in the exception handling function, so the program counter after the exception handling function exits should point to the next instruction at the write address that originally triggered the exception to ensure the correct execution of the program.

[0113] In summary, the embodiment of the present invention optimizes the process of processing self-modifying code during binary translation. When self-modifying code is detected, the first virtual page is mapped to the second virtual page in a shared mapping manner, so that the second virtual page is mapped to the physical memory corresponding to the first virtual page. In addition, the embodiment of the present invention maintains the permissions of the first virtual page unchanged (still not writable), and sets the permissions of the second virtual page to be writable, so that the write operation to the second virtual page has the same effect as the write operation to the first virtual page, and the write operation of the self-modifying code can be performed using the second virtual page. Furthermore, since the embodiment of the present invention does not need to restore the write permission of the first virtual page, an exception can still be triggered when the client program performs a write operation on the first virtual page (such as executing a self-modifying code), so that the binary translator can detect the self-modifying behavior. Therefore, there is no need to invalidate the host basic blocks corresponding to all client basic blocks in the entire first virtual page. Instead, a second virtual page with a shared mapping relationship is set for the first virtual page, and the basic block is modified based on the second virtual page. This achieves the granularity of the basic block, and only invalidates the target basic block corresponding to the write address of the self-modifying code. This achieves the self-modifying operation with a smaller granularity and a lower cost, which can reduce unnecessary invalid operations, reduce redundant re-translation operations, and improve the performance of the translation system.

[0114] It should be noted that, for the sake of simplicity, the method embodiments are described as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0115] Reference Figure 5 , shows a structural block diagram of a binary translator embodiment of the present invention, the binary translator may include:

[0116] The memory mapping module 201 is used to map the first virtual page to the second virtual page in a shared mapping manner when it is determined that the self-modifying code is detected; the first virtual page is the virtual page where the write address of the self-modifying code is located; the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable;

[0117] A basic block invalidation module 202 is used to find a translated target basic block according to the write address of the self-modifying code, and modify the valid flag bit of the target basic block to invalid;

[0118] The self-modifying execution module 203 is configured to write the self-modifying code into a corresponding position in the second virtual page based on a write address of the self-modifying code.

[0119] Optionally, the self-modification execution module includes:

[0120] A first acquisition submodule, used for acquiring a write address of the self-modifying code and a base address of the first virtual page;

[0121] A first calculation submodule, configured to calculate an offset of the write address of the self-modifying code in the first virtual page based on the write address of the self-modifying code and a base address of the first virtual page;

[0122] A second acquisition submodule, used for acquiring a base address of the second virtual page;

[0123] A second calculation submodule, configured to calculate a target address corresponding to the write address of the self-modifying code in the second virtual page according to a base address of the second virtual page and an offset of the write address of the self-modifying code in the first virtual page;

[0124] A code writing submodule is used to write the self-modifying code in the second virtual page based on the target address.

[0125] Optionally, the second acquisition submodule is specifically used to:

[0126] The value of a preset field in the page descriptor corresponding to the first virtual page is read; the preset field is used to record the base address of the second virtual page.

[0127] Optionally, the binary translator further includes:

[0128] A field reading module, configured to read the value of a preset field in a page descriptor corresponding to the first virtual page after determining that the self-modifying code is detected;

[0129] The field judgment module is used to map the physical page mapped by the first virtual page to the second virtual page in a shared mapping manner if the value of the preset field is empty, and assign the preset field to the base address of the second virtual page.

[0130] Optionally, the binary translator further includes:

[0131] a permission removal module, used for setting the permission of the first virtual page to be non-writable before translating the client basic block in the first virtual page, and recording the original permission of the first virtual page in a page descriptor corresponding to the first virtual page;

[0132] Optionally, the memory mapping module includes:

[0133] a function calling submodule, configured to call an exception handling function corresponding to the write address exception signal upon receiving a write address exception signal triggered by executing a write instruction on the first virtual page;

[0134] The function execution submodule is used to obtain the original permission of the first virtual page through the page descriptor corresponding to the first virtual page in the exception handling function; if the original permission of the first virtual page is writable, determine that the self-modifying code is detected.

[0135] Optionally, the memory mapping module includes:

[0136] A first binding submodule, used for creating an anonymous file descriptor, binding the first virtual page to the anonymous file descriptor, and setting a memory mapping attribute of the first virtual page to a shared mapping;

[0137] The second binding submodule is used to apply for a second virtual page, set the permission of the second virtual page to be writable, and bind the second virtual page to the anonymous file descriptor.

[0138] Optionally, the binary translator further includes:

[0139] The counter adjustment module is used to point the program counter to the next instruction after writing the self-modifying code at the corresponding position in the second virtual page.

[0140] The embodiment of the present invention optimizes the binary translator. During the binary translation process, the process of processing self-modifying code is optimized. When the self-modifying code is detected, the first virtual page is mapped to the second virtual page in a shared mapping manner, so that the second virtual page is mapped to the physical memory corresponding to the first virtual page. In addition, the embodiment of the present invention maintains the permissions of the first virtual page unchanged (still not writable), and sets the permissions of the second virtual page to be writable, so that the write operation to the second virtual page has the same effect as the write operation to the first virtual page, and the write operation of the self-modifying code can be performed using the second virtual page. Furthermore, since the embodiment of the present invention does not need to restore the write permission of the first virtual page, an exception can still be triggered when the client program performs a write operation on the first virtual page (such as executing a self-modifying code), so that the binary translator can detect the self-modifying behavior. Therefore, there is no need to invalidate the host basic blocks corresponding to all client basic blocks in the entire first virtual page. Instead, a second virtual page with a shared mapping relationship is set for the first virtual page, and the basic block is modified based on the second virtual page. This achieves the granularity of the basic block, and only invalidates the target basic block corresponding to the write address of the self-modifying code. This achieves the self-modifying operation with a smaller granularity and a lower cost, which can reduce unnecessary invalid operations, reduce redundant re-translation operations, and improve the performance of the translation system.

[0141] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0142] Reference Figure 6 , is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Figure 6 As shown, the electronic device includes: a processor, a memory, a communication interface and a communication bus, and the processor, the memory and the communication interface communicate with each other through the communication bus; the memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute the steps of the binary translation method of the above-mentioned embodiment.

[0143] An embodiment of the present invention provides a non-transitory computer-readable storage medium. When instructions in the storage medium are executed by a program or a processor of a terminal, the terminal is enabled to perform the steps of the binary translation method of the aforementioned embodiment.

[0144] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0145] Those skilled in the art will appreciate that the embodiments of the embodiments of the present invention may be provided as methods, binary translators, or computer program products. Therefore, the embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0146] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0147] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing terminal device to operate in a predictable manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0148] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0149] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.

[0150] Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A binary translation method, characterized in that: Applied to a binary translator, the method comprises: In the case where it is determined that the self-modifying code is detected, the first virtual page is mapped to the second virtual page in a shared mapping manner; the first virtual page is a virtual page where the write address of the self-modifying code is located, and the memory mapping attribute of the first virtual page is set to shared mapping; the second virtual page is a newly applied virtual page in the host environment, and the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable; According to the write address of the self-modifying code, searching for the translated target basic block, and modifying the valid flag bit of the target basic block to be invalid; Based on the write address of the self-modifying code, writing the self-modifying code at a corresponding position in the second virtual page; Mapping the first virtual page to the second virtual page in a shared mapping manner includes: Creating an anonymous file descriptor, binding the first virtual page to the anonymous file descriptor, and setting a memory mapping attribute of the first virtual page to a shared mapping; Apply for a second virtual page, set the permission of the second virtual page to be writable, and bind the second virtual page to the anonymous file descriptor.

2. The method according to claim 1, characterized in that The step of writing the self-modifying code at a corresponding position in the second virtual page based on the write address of the self-modifying code comprises: Obtaining a write address of the self-modifying code and a base address of the first virtual page; Calculating an offset of the write address of the self-modifying code in the first virtual page based on the write address of the self-modifying code and the base address of the first virtual page; Obtaining a base address of the second virtual page; Calculate a target address corresponding to the write address of the self-modifying code in the second virtual page according to the base address of the second virtual page and the offset of the write address of the self-modifying code in the first virtual page; The self-modifying code is written in the second virtual page based on the target address.

3. The method according to claim 2, characterized in that The obtaining the base address of the second virtual page includes: The value of a preset field in the page descriptor corresponding to the first virtual page is read; the preset field is used to record the base address of the second virtual page.

4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: After determining that the self-modifying code is detected, reading a value of a preset field in a page descriptor corresponding to the first virtual page; If the value of the preset field is empty, the physical page mapped by the first virtual page is mapped to the second virtual page in a shared mapping manner, and the preset field is assigned a base address of the second virtual page.

5. The method according to claim 1, characterized in that The method further comprises: Before translating the client basic block in the first virtual page, setting the permission of the first virtual page to be non-writable, and recording the original permission of the first virtual page in a page descriptor corresponding to the first virtual page; The determining that the self-modifying code is detected includes: When receiving a write address exception signal triggered by executing a write instruction on the first virtual page, calling an exception handling function corresponding to the write address exception signal; In the exception handling function, the original permission of the first virtual page is obtained through the page descriptor corresponding to the first virtual page; If the original permission of the first virtual page is writable, it is determined that self-modifying code is detected.

6. The method according to claim 1, characterized in that The method further comprises: After writing the self-modifying code at the corresponding position in the second virtual page, the program counter is pointed to the next instruction.

7. A binary translator, characterized in that The binary translator comprises: A memory mapping module, configured to map a first virtual page to a second virtual page in a shared mapping manner when it is determined that a self-modifying code is detected; the first virtual page is a virtual page where a write address of the self-modifying code is located, and a memory mapping attribute of the first virtual page is set to shared mapping; the second virtual page is a newly applied virtual page in a host environment, and the second virtual page corresponds to the same physical page as the first virtual page; the permission of the first virtual page is not writable, and the permission of the second virtual page is writable; A basic block invalidation module, used for searching the translated target basic block according to the write address of the self-modifying code, and modifying the valid flag bit of the target basic block to be invalid; A self-modifying execution module, configured to write the self-modifying code into a corresponding position in the second virtual page based on a write address of the self-modifying code; The memory mapping module comprises: A first binding submodule, used for creating an anonymous file descriptor, binding the first virtual page to the anonymous file descriptor, and setting a memory mapping attribute of the first virtual page to a shared mapping; The second binding submodule is used to apply for a second virtual page, set the permission of the second virtual page to be writable, and bind the second virtual page to the anonymous file descriptor.

8. The binary translator according to claim 7, characterized in that: The self-modification execution module comprises: A first acquisition submodule, used for acquiring a write address of the self-modifying code and a base address of the first virtual page; A first calculation submodule, configured to calculate an offset of the write address of the self-modifying code in the first virtual page based on the write address of the self-modifying code and a base address of the first virtual page; A second acquisition submodule, used for acquiring a base address of the second virtual page; A second calculation submodule, configured to calculate a target address corresponding to the write address of the self-modifying code in the second virtual page according to a base address of the second virtual page and an offset of the write address of the self-modifying code in the first virtual page; A code writing submodule is used to write the self-modifying code in the second virtual page based on the target address.

9. The binary translator according to claim 8, characterized in that: The second acquisition submodule is specifically used for: The value of a preset field in the page descriptor corresponding to the first virtual page is read; the preset field is used to record the base address of the second virtual page.

10. The binary translator according to any one of claims 7 to 9, characterized in that: The binary translator also includes: A field reading module, configured to read the value of a preset field in a page descriptor corresponding to the first virtual page after determining that the self-modifying code is detected; The field judgment module is used to map the physical page mapped by the first virtual page to the second virtual page in a shared mapping manner if the value of the preset field is empty, and assign the preset field to the base address of the second virtual page.

11. The binary translator according to claim 7, characterized in that: The binary translator also includes: a permission removal module, used for setting the permission of the first virtual page to be non-writable before translating the client basic block in the first virtual page, and recording the original permission of the first virtual page in a page descriptor corresponding to the first virtual page; The memory mapping module comprises: a function calling submodule, configured to call an exception handling function corresponding to the write address exception signal upon receiving a write address exception signal triggered by executing a write instruction on the first virtual page; The function execution submodule is used to obtain the original permission of the first virtual page through the page descriptor corresponding to the first virtual page in the exception handling function; if the original permission of the first virtual page is writable, determine that the self-modifying code is detected.

12. The binary translator according to claim 7, characterized in that: The binary translator also includes: The counter adjustment module is used to point the program counter to the next instruction after writing the self-modifying code at the corresponding position in the second virtual page.

13. An electronic device, characterized in that: include: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to execute the steps of the binary translation method according to any one of claims 1 to 6.

14. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the binary translation method according to any one of claims 1 to 6 are implemented.

15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the binary translation method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • A binary translation-based self-modification code detection method and device

    CN109710267A