Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

使用popen执行命令行出错 #84

Open
weechatfly opened this issue Feb 6, 2020 · 1 comment
Open

使用popen执行命令行出错 #84

weechatfly opened this issue Feb 6, 2020 · 1 comment

Comments

@weechatfly
Copy link

android的so中使用popen执行命令行会出错,代码如下:
char buf_ps[1024];
FILE *ptr;
string result("");
if((ptr=popen(“cat /proc/self/cmdline”, "r"))!=NULL)
{
while(fgets(buf_ps, 1024, ptr)!=NULL)
{
result.append(buf_ps);
}
pclose(ptr);
}
出错如下:
[12:08:20 719] ERROR [cn.banny.unidbg.linux.ARMSyscallHandler] (ARMSyscallHandler:852) - execve filename=/system/bin/sh, args=[sh, -c, cat /proc/self/cmdline], env=[]
[12:08:20 720] INFO [cn.banny.unidbg.linux.ARMSyscallHandler] (ARMSyscallHandler:1361) - exit with code: 127
java.lang.Exception: exit_group status=127
at cn.banny.unidbg.linux.ARMSyscallHandler.exit_group(ARMSyscallHandler.java:1361)
at cn.banny.unidbg.linux.ARMSyscallHandler.hook(ARMSyscallHandler.java:321)
at unicorn.Unicorn.invokeInterruptCallbacks(Unicorn.java:123)
at unicorn.Unicorn.emu_start(Native Method)
at cn.banny.unidbg.AbstractEmulator.emulate(AbstractEmulator.java:302)
at cn.banny.unidbg.AbstractEmulator.eFunc(AbstractEmulator.java:400)
at cn.banny.unidbg.arm.AbstractARMEmulator.eFunc(AbstractARMEmulator.java:205)
at cn.banny.unidbg.linux.LinuxModule.emulateFunction(LinuxModule.java:203)
at cn.banny.unidbg.linux.android.dvm.DvmClass.callStaticJniMethod(DvmClass.java:209)
at cn.banny.unidbg.android.dx.DxSoUtilTest.testRomxSdk(DxSoUtilTest.java:142)
at cn.banny.unidbg.android.dx.DxSoUtilTest.main(DxSoUtilTest.java:93)
[12:08:20 724] DEBUG [cn.banny.unidbg.AbstractEmulator] (AbstractEmulator:329) - emulate unicorn@0x4020afe9[libnative-lib.so]0xafe9 finished sp=unicorn@0xbfffdea8, offset=95ms

@zhkl0228
Copy link
Owner

zhkl0228 commented Feb 6, 2020

`

private class MyAndroidARMEmulator extends AndroidARMEmulator {
@OverRide
protected UnixSyscallHandler createSyscallHandler(SvcMemory svcMemory) {
return new MyARMSyscallHandler(svcMemory);
}
}

private class MyARMSyscallHandler extends com.github.unidbg.linux.ARMSyscallHandler {
    public MyARMSyscallHandler(SvcMemory svcMemory) {
        super(svcMemory);
    }
    @Override
    protected boolean handleUnknownSyscall(Emulator emulator, int NR) {
        switch (NR) {
            case 114:
                wait4(emulator);
                return true;
            case 190:
                vfork(emulator);
                return true;
            case 359:
                pipe2(emulator);
                return true;
        }

        return super.handleUnknownSyscall(emulator, NR);
    }

    private void wait4(Emulator emulator) {
        EditableArm32RegisterContext context = emulator.getContext();
        int pid = context.getR0Int();
        Pointer wstatus = context.getR1Pointer();
        int options = context.getR2Int();
        Pointer rusage = context.getR3Pointer();
        System.out.println("wait4 pid=" + pid + ", wstatus=" + wstatus + ", options=0x" + Integer.toHexString(options) + ", rusage=" + rusage);
    }

    private void vfork(Emulator emulator) {
        EditableArm32RegisterContext context = emulator.getContext();
        int childPid = emulator.getPid() + ThreadLocalRandom.current().nextInt(256);
        int r0 = 0;
        if (parent) {
            r0 = childPid;
        }
        System.out.println("vfork pid=" + r0);
        context.setR0(r0);
    }

    private void pipe2(Emulator emulator) {
        EditableArm32RegisterContext context = emulator.getContext();
        Pointer pipefd = context.getPointerArg(0);
        int flags = context.getIntArg(1);
        int write = getMinFd();
        this.fdMap.put(write, new DumpFileIO(write));
        int read = getMinFd();
        String stdout = "com.ss.android.ugc.aweme\n"; // cat /proc/self/cmdline
        this.fdMap.put(read, new ByteArrayFileIO(0, "pipe2_read_side", stdout.getBytes()));
        pipefd.setInt(0, read);
        pipefd.setInt(4, write);
        System.out.println("pipe2 pipefd=" + pipefd + ", flags=0x" + flags + ", read=" + read + ", write=" + write + ", stdout=" + stdout);
        context.setR0(0);
    }
}`

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants