Skip to content
This repository

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
tree: af1c78c4be
Fetching contributors…

Cannot retrieve contributors at this time

file 202 lines (152 sloc) 5.824 kb
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202
#include "jumppatching.h"
#include <iostream>
#include <map>
#include <string>
#include <fstream>

using namespace std;

//const unsigned int jumppatching::thunk_bx_offset = 0x0001ec9b; /* Hardcoded for libc */
//const unsigned int jumppatching::thunk_cx_offset = 0x0001fc6c; /* Hardcoded for libc */

map<string, list<jumppatching*>* > *patch_database; // <symbol name, list of patches>

std::map<std::string, int> current_addresses;

typedef struct patch_entry_struct {
    text_symbol source;
    text_symbol dest;
    int offset;
    int d_offset;
} patch_entry;

text_symbol lookup_symbol_by_name(char* name)
{
    list<text_symbol>::iterator it;
    for(it = entry_list.begin(); it != entry_list.end(); it++)
    {
        if(strcmp(it->symbolName, name) == 0)
        {
            return *it;
        }
    }
}

list<patch_entry> patch_entry_list;

/**
* Reads the file line by line & fills out a list of jump patches
* Format:
* <source function> <dest function> <offset> <dest offset>
* @param path
* @return
*/
void read_patch_file(char* path)
{
    fstream file;
    file.open(path, fstream::in);
    
    while(!file.eof())
    {
        char buffer[250];
        memset(buffer, 0, 250);
        file.getline(buffer, 250);
    
        if(strlen(buffer) == 0)
            break;
        
        char* toks = strtok(buffer, " ");
        
        text_symbol source = lookup_symbol_by_name(toks);
        
        toks = strtok(NULL, " ");
        
        text_symbol dest = lookup_symbol_by_name(toks);
        
        toks = strtok(NULL, " ");
        
        int offset = strtoul (toks,NULL,0);
        
        toks = strtok(NULL, " ");
        
        int d_offset = strtoul (toks,NULL,0);
        
        patch_entry temp = { source, dest, offset, d_offset };
        
        patch_entry_list.push_back(temp);
    }
    
    file.close();
}


/* Calculates and updates the jump distance for teh given offset and destination address */
bool lowlevel_patch(unsigned char *buffer, int offset, int dest)
{
    if(offset > 0x1000000)
    {
// cout << "Flipping offset of patch!" << endl;
        offset = TEXT_TO_FILE(offset);
    }
    
    if(dest > 0x1000000)
    {
// cout << "Flipping dest of patch!" << endl;
        dest = TEXT_TO_FILE(offset);
    }
// cout << hex << "Patching: 0x" << (offset) << " to 0x" << (dest) << endl;
// cout << hex << "\t" << FILE_TO_TEXT(offset) << " to 0x" << FILE_TO_TEXT(dest) << endl;
        
int distance_to_jump = dest-offset-4; // 4 bytes for the instruction

*((int*)(buffer+offset)) = distance_to_jump;

// cout << hex << "Patched jump: 0x" << distance_to_jump << endl;

return true;
}

#define STR_EXPAND(tok) #tok

#define STR(tok) STR_EXPAND(tok)

#define START() patches = new list<jumppatching*>;

#define GEN_PATCH(func,dest,off,d_off,count)\
patch func ## _patch_ ## count;\
strcpy(func ## _patch_ ## count.function_name,STR(func));\
strcpy(func ## _patch_ ## count.dest_function_name, STR(dest));\
func ## _patch_ ## count.offset = off;\
func ## _patch_ ## count.dest_offset = d_off ;

#define GEN_JUMP(func,count) \
jumppatching* jump_ ## func ## _ ## count = new jumppatching(); \
jump_ ## func ## _ ## count ->function_call_patches.push_front( func ## _patch_ ## count);

#define GEN_INSERT(func,count) \
patches->push_back( jump_ ## func ## _ ## count ); \
patch_db->insert(pair<string, list<jumppatching*>* > ( STR(func) , patches));

#define MASTER(func,dest,off,d_off,count) \
START() \
ADDITION(func,dest,off,d_off,count)

#define ADDITION(func,dest,off,d_off,count) \
GEN_PATCH( func , dest , off, d_off , count) \
GEN_JUMP( func, count) \
GEN_INSERT ( func , count)

/*
* Iterates through every symbol and prepares the list of patches
* needed for each symbol
*/
map<string, list<jumppatching*>* >* prepare_patch_database()
{
    
    list<jumppatching*> *patches;
    map<string, list<jumppatching*>* >* patch_db = new map<string, list<jumppatching*>* >;

    list<patch_entry>::iterator it;
    
    for(it = patch_entry_list.begin(); it != patch_entry_list.end(); it++)
    {
        if(patch_db->find(it->source.symbolName) != patch_db->end())
        {
            patches = (patch_db->find(it->source.symbolName))->second;
        }
        else
        {
            patches = new list<jumppatching*>;
        }
        
        
        patch temp_patch;
        strcpy(temp_patch.function_name, it->source.symbolName);
        strcpy(temp_patch.dest_function_name, it->dest.symbolName);
        temp_patch.offset = it->offset;
        temp_patch.dest_offset = it->d_offset;
        
        jumppatching* jump = new jumppatching();
        jump->function_call_patches.push_front(temp_patch);
        
        patches->push_back(jump);
        patch_db->insert(pair<string, list<jumppatching*>* > ( it->source.symbolName, patches));
    }
    
    /*
patch jump_function1_patch;
strcpy(jump_function1_patch.function_name, "jump_function1");
strcpy(jump_function1_patch.dest_function_name, "function1");
jump_function1_patch.offset = 4;
jump_function1_patch.dest_offset = 0;
*/

/*
jumppatching* jf1_patch = new jumppatching();
jf1_patch->function_call_patches.push_front(jump_function1_patch);

jumppatching* jf2_patch = new jumppatching();
jf2_patch->function_call_patches.push_front(jump_function2_patch);
*/
     /*
patches->push_back(jf1_patch);
patches->push_back(jf2_patch);
patch_db->insert(pair<string, list<jumppatching*>* >("jump_function1", patches));
patch_db->insert(pair<string, list<jumppatching*>* >("jump_function2", patches));
*/


    patch_database = patch_db;
    return patch_db;
}
Something went wrong with that request. Please try again.