pa_offset = offset & ~(sysconf(_SC_PAGE_SIZE) - 1) 详解

发现很多文章都没有把pa_offset = offset & ~(sysconf(_SC_PAGE_SIZE) - 1) 详细计算过程写出来,自己专门计算了一遍,附在文末。本例为man mmap中的原样实例程序,加上了一些额外的无关代码及打印输出信息 让总字节数超过一页大小sysconf(_SC_PAGE_SIZE)以方便查看调试信息

#include <sys/mman.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>

#define handle_error(msg) \
    do { perror(msg); exit(EXIT_FAILURE); } while (0)

int main(int argc, char *argv[])
{
    char *addr;
    int fd;
    struct stat sb;
    off_t offset, pa_offset;
    size_t length;
    ssize_t s;

    if (argc < 3 || argc > 4) {
        fprintf(stderr, "%s file offset [length]\n", argv[0]);
        exit(EXIT_FAILURE);
    }

    fd = open(argv[1], O_RDONLY);
    if (fd == -1)
        handle_error("open");

    if (fstat(fd, &sb) == -1)           /* To obtain file size */
        handle_error("fstat");

    offset = atoi(argv[2]);
    pa_offset = offset & ~(sysconf(_SC_PAGE_SIZE) - 1);
        /* offset for mmap() must be page aligned */
     if (offset >= sb.st_size) {
        fprintf(stderr, "offset is past end of file\n");
        exit(EXIT_FAILURE);
    }

    if (argc == 4) {
        length = atoi(argv[3]);
        if (offset + length > sb.st_size)
            length = sb.st_size - offset;
                /* Can't display bytes past end of file */

    } else {    /* No length arg ==> display to end of file */
        length = sb.st_size - offset;
    }

    addr = mmap(NULL, length + offset - pa_offset, PROT_READ,
                MAP_PRIVATE, fd, pa_offset);
    if (addr == MAP_FAILED)
        handle_error("mmap");

    printf("length = %ld\n", length);
	printf("offset = %ld\n", offset);
	printf("pa_offset = %ld\n", pa_offset);
	printf("length + offset - pa_offset = %ld\n", length + offset - pa_offset);
    
    s = write(STDOUT_FILENO, addr + offset - pa_offset, length);
    if (s != length) {
        if (s == -1)
            handle_error("write");

        fprintf(stderr, "partial write");
        exit(EXIT_FAILURE);
    }

    munmap(addr, length + offset - pa_offset);
    close(fd);

    exit(EXIT_SUCCESS);
}

//**额外增加的代码开始
//**加上了一些额外的无关代码及打印输出信息 让总字节数超过一页大小sysconf(_SC_PAGE_SIZE)以方便查看调试信息**开始
/* 
#include "head.h"
struct msgbuff{
    long mtype;
    char mtext[512];
};

void send_msg(int qid, int type, char *m_msg, int size){
    struct msgbuff msg;
    msg.mtype = type;
    strcpy(msg.mtext, m_msg);
    if(msgsnd(qid, (void *)&msg, sizeof(msg.mtext), IPC_NOWAIT) == -1){
        perror("msgsnd");
        exit(1);
    } 
}

void get_msg(int qid, int type){
    while (1){
        struct msgbuff msg;
        bzero(&msg, sizeof(msg));//清空缓冲区,也可用memmet实现
        if (msgrcv(qid, (void *)&msg, sizeof(msg.mtext),type, MSG_NOERROR) == -1) {
            perror("msgrcv");
            exit(1);
        }
        printf("抢到了资源: <%d> <%s>\n", type, msg.mtext);

    }
}

int main(int argc, char **argv){
    int opt, mode = 2, msgtype = 1;
    int msgq_id;
    char mtext[512] = {0};
    //mode == 1-> send
    while((opt = getopt(argc, argv, "st:rm:")) != -1){
        switch(opt){
            case 's':
                mode = 1;
                break;
            case 'r':
                mode = 2;
                break;
            case 't':
                msgtype = atoi(optarg);
                break;
            case 'm':
                strcpy(mtext, optarg);
                break;
            default:
                fprintf(stderr, "Usage: %s -[s|r] -t type -m msg\n", argv[0]);
                exit(1);
        }
    }
    //int msgget(key_t key, int msgflg);
    if((msgq_id = msgget(2021, IPC_CREAT | 0666)) < 0){
        perror("msgget");
        exit(1);
    }
    if (mode == 1){
        send_msg(msgq_id, msgtype, mtext, sizeof(mtext));
    } else {
        get_msg(msgq_id, msgtype);
    }

    return 0;
}
// ./a.out -s -t 1 -m "I'm the 1th!"
// ./a.out -r -t 1.msgq.c
// #include "head.h"
struct msgbuff{
    long mtype;
    char mtext[512];
};

void send_msg(int qid, int type, char *m_msg, int size){
    struct msgbuff msg;
    msg.mtype = type;
    strcpy(msg.mtext, m_msg);
    if(msgsnd(qid, (void *)&msg, sizeof(msg.mtext), IPC_NOWAIT) == -1){
        perror("msgsnd");
        exit(1);
    }
}

void get_msg(int qid, int type){
    while (1){
        struct msgbuff msg;
        bzero(&msg, sizeof(msg));//清空缓冲区,也可用memmet实现
        if (msgrcv(qid, (void *)&msg, sizeof(msg.mtext),type, MSG_NOERROR) == -1) {
            perror("msgrcv");
            exit(1);
        }
        printf("抢到了资源: <%d> <%s>\n", type, msg.mtext);

    }
}

int main(int argc, char **argv){
    int opt, mode = 2, msgtype = 1;
    int msgq_id;
    char mtext[512] = {0};
    //mode == 1-> send
    while((opt = getopt(argc, argv, "st:rm:")) != -1){
        switch(opt){
            case 's':
                mode = 1;
                break;
            case 'r':
                mode = 2;
                break;
            case 't':
                msgtype = atoi(optarg);
                break;
            case 'm':
                strcpy(mtext, optarg);
                break;
            default:
                fprintf(stderr, "Usage: %s -[s|r] -t type -m msg\n", argv[0]);
                exit(1);
        }
    }
    //int msgget(key_t key, int msgflg);
    if((msgq_id = msgget(2021, IPC_CREAT | 0666)) < 0){
        perror("msgget");
        exit(1);
    }
    if (mode == 1){
        send_msg(msgq_id, msgtype, mtext, sizeof(mtext));
    } else {
        get_msg(msgq_id, msgtype);
    }

    return 0;
}
// ./a.out -s -t 1 -m "I'm the 1th!"
// ./a.out -r -t 1.msgq.c#include "head.h"
struct msgbuff{
    long mtype;
    char mtext[512];
};

void send_msg(int qid, int type, char *m_msg, int size){
    struct msgbuff msg;
    msg.mtype = type;
    strcpy(msg.mtext, m_msg);
    if(msgsnd(qid, (void *)&msg, sizeof(msg.mtext), IPC_NOWAIT) == -1){
        perror("msgsnd");
        exit(1);
    } 
}

void get_msg(int qid, int type){
    while (1){
        struct msgbuff msg;
        bzero(&msg, sizeof(msg));//清空缓冲区,也可用memmet实现
        if (msgrcv(qid, (void *)&msg, sizeof(msg.mtext),type, MSG_NOERROR) == -1) {
            perror("msgrcv");
            exit(1);
        }
        printf("抢到了资源: <%d> <%s>\n", type, msg.mtext);

    }
}

int main(int argc, char **argv){
    int opt, mode = 2, msgtype = 1;
    int msgq_id;
    char mtext[512] = {0};
    //mode == 1-> send
    while((opt = getopt(argc, argv, "st:rm:")) != -1){
        switch(opt){
            case 's':
                mode = 1;
                break;
            case 'r':
                mode = 2;
                break;
            case 't':
                msgtype = atoi(optarg);
                break;
            case 'm':
                strcpy(mtext, optarg);
                break;
            default:
                fprintf(stderr, "Usage: %s -[s|r] -t type -m msg\n", argv[0]);
                exit(1);
        }
    }
    //int msgget(key_t key, int msgflg);
    if((msgq_id = msgget(2021, IPC_CREAT | 0666)) < 0){
        perror("msgget");
        exit(1);
    }
    if (mode == 1){
        send_msg(msgq_id, msgtype, mtext, sizeof(mtext));
    } else {
        get_msg(msgq_id, msgtype);
    }

    return 0;
}
// ./a.out -s -t 1 -m "I'm the 1th!"
// ./a.out -r -t 1.msgq.c#include "head.h"
struct msgbuff{
    long mtype;
    char mtext[512];
};

void send_msg(int qid, int type, char *m_msg, int size){
    struct msgbuff msg;
    msg.mtype = type;
    strcpy(msg.mtext, m_msg);
    if(msgsnd(qid, (void *)&msg, sizeof(msg.mtext), IPC_NOWAIT) == -1){
        perror("msgsnd");
        exit(1);
    } 
}

void get_msg(int qid, int type){
    while (1){
        struct msgbuff msg;
        bzero(&msg, sizeof(msg));//清空缓冲区,也可用memmet实现
        if (msgrcv(qid, (void *)&msg, sizeof(msg.mtext),type, MSG_NOERROR) == -1) {
            perror("msgrcv");
            exit(1);
        }
        printf("抢到了资源: <%d> <%s>\n", type, msg.mtext);

    }
}

int main(int argc, char **argv){
    int opt, mode = 2, msgtype = 1;
    int msgq_id;
    char mtext[512] = {0};
    //mode == 1-> send
    while((opt = getopt(argc, argv, "st:rm:")) != -1){
        switch(opt){
            case 's':
                mode = 1;
                break;
            case 'r':
                mode = 2;
                break;
            case 't':
                msgtype = atoi(optarg);
                break;
            case 'm':
                strcpy(mtext, optarg);
                break;
            default:
                fprintf(stderr, "Usage: %s -[s|r] -t type -m msg\n", argv[0]);
                exit(1);
        }
    }
    //int msgget(key_t key, int msgflg);
    if((msgq_id = msgget(2021, IPC_CREAT | 0666)) < 0){
        perror("msgget");
        exit(1);
    }
    if (mode == 1){
        send_msg(msgq_id, msgtype, mtext, sizeof(mtext));
    } else {
        get_msg(msgq_id, msgtype);
    }

    return 0;
}
// ./a.out -s -t 1 -m "I'm the 1th!"
// ./a.out -r -t 1.msgq.c#include "head.h"
struct msgbuff{
    long mtype;
    char mtext[512];
};

void send_msg(int qid, int type, char *m_msg, int size){
    struct msgbuff msg;
    msg.mtype = type;
    strcpy(msg.mtext, m_msg);
    if(msgsnd(qid, (void *)&msg, sizeof(msg.mtext), IPC_NOWAIT) == -1){
        perror("msgsnd");
        exit(1);
    } 
}

void get_msg(int qid, int type){
    while (1){
        struct msgbuff msg;
        bzero(&msg, sizeof(msg));//清空缓冲区,也可用memmet实现
        if (msgrcv(qid, (void *)&msg, sizeof(msg.mtext),type, MSG_NOERROR) == -1) {
            perror("msgrcv");
            exit(1);
        }
        printf("抢到了资源: <%d> <%s>\n", type, msg.mtext);

    }
}

int main(int argc, char **argv){
    int opt, mode = 2, msgtype = 1;
    int msgq_id;
    char mtext[512] = {0};
    //mode == 1-> send
    while((opt = getopt(argc, argv, "st:rm:")) != -1){
        switch(opt){
            case 's':
                mode = 1;
                break;
            case 'r':
                mode = 2;
                break;
            case 't':
                msgtype = atoi(optarg);
                break;
            case 'm':
                strcpy(mtext, optarg);
                break;
            default:
                fprintf(stderr, "Usage: %s -[s|r] -t type -m msg\n", argv[0]);
                exit(1);
        }
    }
    //int msgget(key_t key, int msgflg);
    if((msgq_id = msgget(2021, IPC_CREAT | 0666)) < 0){
        perror("msgget");
        exit(1);
    }
    if (mode == 1){
        send_msg(msgq_id, msgtype, mtext, sizeof(mtext));
    } else {
        get_msg(msgq_id, msgtype);
    }

    return 0;
}
// ./a.out -s -t 1 -m "I'm the 1th!"
// ./a.out -r -t 1.msgq.c#include "head.h"
struct msgbuff{
    long mtype;
    char mtext[512];
};

void send_msg(int qid, int type, char *m_msg, int size){
    struct msgbuff msg;
    msg.mtype = type;
    strcpy(msg.mtext, m_msg);
    if(msgsnd(qid, (void *)&msg, sizeof(msg.mtext), IPC_NOWAIT) == -1){
        perror("msgsnd");
        exit(1);
    } 
}

void get_msg(int qid, int type){
    while (1){
        struct msgbuff msg;
        bzero(&msg, sizeof(msg));//清空缓冲区,也可用memmet实现
        if (msgrcv(qid, (void *)&msg, sizeof(msg.mtext),type, MSG_NOERROR) == -1) {
            perror("msgrcv");
            exit(1);
        }
        printf("抢到了资源: <%d> <%s>\n", type, msg.mtext);

    }
}

int main(int argc, char **argv){
    int opt, mode = 2, msgtype = 1;
    int msgq_id;
    char mtext[512] = {0};
    //mode == 1-> send
    while((opt = getopt(argc, argv, "st:rm:")) != -1){
        switch(opt){
            case 's':
                mode = 1;
                break;
            case 'r':
                mode = 2;
                break;
            case 't':
                msgtype = atoi(optarg);
                break;
            case 'm':
                strcpy(mtext, optarg);
                break;
            default:
                fprintf(stderr, "Usage: %s -[s|r] -t type -m msg\n", argv[0]);
                exit(1);
        }
    }
    //int msgget(key_t key, int msgflg);
    if((msgq_id = msgget(2021, IPC_CREAT | 0666)) < 0){
        perror("msgget");
        exit(1);
    }
    if (mode == 1){
        send_msg(msgq_id, msgtype, mtext, sizeof(mtext));
    } else {
        get_msg(msgq_id, msgtype);
    }

    return 0;
}
// ./a.out -s -t 1 -m "I'm the 1th!"
// ./a.out -r -t 1.msgq.c

*/
//**额外增加的结束
//加上了一些额外的无关代码及打印输出信息 让总字节数超过一页大小sysconf(_SC_PAGE_SIZE)以方便查看调试信息** 结束

编译命令:gcc mmap.c
程序执行格式: ./a.out file offset [length]
格式解析:./a.out +file 文件名 + offset偏移量 +length可选长度

./a.out mmap.c 10000

//执行结果,示例
length = 2266
offset = 10000
pa_offset = 8192

假设文件mmap.c文件大小为12266 ,
length =文件总大小(12266) - 偏移量offset(1000) = 2266

4096(sysconf(_SC_PAGE_SIZE)一页大小)

0001 0000 0000 0000 = 4096(sysconf(_SC_PAGE_SIZE)一页大小)
0000 1111 1111 1111 = (sysconf(_SC_PAGE_SIZE) - 1) =4095
~(0000 1111 1111 1111)
= 1111 0000 0000 0000 = ~ (sysconf(_SC_PAGE_SIZE) - 1) =61440

pa_offset = offset & ~(sysconf(_SC_PAGE_SIZE) - 1)
=10000 & 61440
=(0010 0111 0001 0000) & (1111 0000 0000 0000)
=(0010 0000 0000 0000)
=8192 //pa_offset即内存中的页偏移量

#if defined(__arm__) int process_vm_readv_syscall = 376; int process_vm_writev_syscall = 377; #elif defined(__aarch64__) int process_vm_readv_syscall = 270; int process_vm_writev_syscall = 271; #elif defined(__i386__) int process_vm_readv_syscall = 347; int process_vm_writev_syscall = 348; #else int process_vm_readv_syscall = 310; int process_vm_writev_syscall = 311; #endif ssize_t process_v(pid_t __pid, const struct iovec *__local_iov, unsigned long __local_iov_count, const struct iovec *__remote_iov, unsigned long __remote_iov_count, unsigned long __flags, bool iswrite) { return syscall((iswrite ? process_vm_writev_syscall : process_vm_readv_syscall), __pid, __local_iov, __local_iov_count, __remote_iov, __remote_iov_count, __flags); } bool WriteAddr(void *addr, void *buffer, size_t length) { unsigned long page_size = sysconf(_SC_PAGESIZE); unsigned long size = page_size * sizeof(uintptr_t); return mprotect((void *) ((uintptr_t) addr - ((uintptr_t) addr % page_size) - page_size), (size_t) size, PROT_EXEC | PROT_READ | PROT_WRITE) == 0 &amp;&amp; memcpy(addr, buffer, length) != 0; } // 进程读写内存 bool pvm(void *address, void *buffer, size_t size, bool iswrite) { struct iovec local[1]; struct iovec remote[1]; local[0].iov_base = buffer; local[0].iov_len = size; remote[0].iov_base = address; remote[0].iov_len = size; ssize_t bytes = process_v(pid, local, 1, remote, 1, 0, iswrite); return bytes == size; } // 读取内存 bool vm_readv(long address, void *buffer, size_t size) { return pvm(reinterpret_cast &lt; void *&gt;(address), buffer, size, false); } // 写入内存 bool vm_writev(long address, void *buffer, size_t size) { return pvm(reinterpret_cast &lt; void *&gt;(address), buffer, size, true); }读写不了怎么办
03-18
从您的描述来看,您尝试通过 `process_vm_readv` 和 `process_vm_writev` 系统调用来实现进程间内存读写功能。然而,在某些场景下可能会遇到无法正常工作的情况。 ### 可能的原因分析 1. **权限不足** 调用这两个系统调用需要目标进程有适当的访问权限。如果当前进程对目标进程没有足够的权限(例如目标进程的用户 ID 或者权限级别限制),操作会失败并返回错误码 `-EPERM`。 2. **地址无效** 如果提供的地址超出有效范围(如未映射到虚拟空间、非法指针等),操作系统将拒绝该请求,并返回 `-EFAULT` 错误。 3. **内核配置问题** 某些 Linux 发行版或特定版本的内核可能禁用了 `process_vm_readv/writev` 功能。在这种情况下,即使代码逻辑无误也可能导致函数不可用。 4. **SELinux/AppArmor 的影响** 安全模块(如 SELinux 或 AppArmor)可能会阻止此类跨进程的操作。如果您运行的是启用了强制安全策略的环境,则可能导致失败。 5. **调试模式下的限制** 当前进程中可能存在调试工具附加(如 GDB)。这种状态通常会对远程内存访问施加额外约束,从而引起异常情况发生。 --- ### 解决方案建议 #### 1. 验证是否具备必要权限 检查是否有足够高的权限去操控其他进程的数据段内容。可以临时提升至 root 用户测试效果;若成功说明普通账户缺乏相应权利设置。 ```bash sudo su - ``` 然后再次执行程序看看能否顺利运作起来。 #### 2. 修改目标区域属性 对于一些保护比较严格的页面来说,直接修改其值会被拦截下来。这时我们需要先调整那些存储单元所处位置的相关标志位: ```cpp if (!WriteAddr(address, buffer, size)) { perror(&quot;Failed to change memory protection&quot;); return false; } ``` 上述步骤就是更改指定块为可读写的例子。不过需要注意的是这样做会影响系统的稳定性以及安全性,请谨慎行事! #### 3. 查看具体的errno信息 为了更精确地定位出错原因,应该捕获 errno 并打印出来供参考: ```cpp #include &lt;cerrno&gt; ... perror(strerror(errno)); return bytes == ssize_t(size); // 返回布尔结果同时保留原语义表达形式 ``` #### 4. 切换至 ptrace 实现备选机制 如果确实由于各种因素而不得不放弃现有的 API ,那么还可以考虑采用 ptrace() 来完成类似的任务 。尽管效率较低且复杂度增加不少,但它兼容性较好并且几乎不受限于前面提到的所有障碍物。 示例片段如下所示: ```cpp long attach_and_rw(pid_t pid,long addr,void* data,size_t len,bool write){ if(0 != ptrace(PTRACE_ATTACH,pid,nullptr,nullptr)){ perror(&quot;Attach failed:&quot;); exit(-1); } waitpid(pid,&amp;status,WUNTRACED); struct iovec io_local={data,len}; struct user_regs_struct regs; ptrace(PTRACE_GETREGS,pid,&amp;regs,sizeof(regs)); if(write){ ioctl(fileno(stdout),&quot;TIOCSTI&quot;,(char*)&amp;io_local.iov_len); ptrace(PTRACE_POKETEXT,pid,(void*)addr,data,strlen((const char*)data)+1); }else{ readlink(&quot;/proc/self/exe&quot;,NULL,PAGE_SIZE); ptrace(PTRACE_PEEKDATA,pid,(void*)addr,&amp;value,sizeof(value)); } detach_process(pid); return SUCCESS; } ``` 以上仅作为思路引导之用,实际应用还需进一步完善细节处理部分。 --- ###
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值