简体   繁体   English

如何从Rust中的内存缓冲区执行原始指令?

[英]How to execute raw instructions from a memory buffer in Rust?

I'm attempting to make a buffer of memory executable, then execute it in Rust. 我试图使内存缓冲区可执行,然后在Rust中执行它。 I've gotten all the way until I need to cast the raw executable bytes as code/instructions. 我已经一路过关斩将,直到需要将原始的可执行字节转换为代码/指令为止。 You can see a working example in C below. 您可以在下面的C中看到一个有效的示例

Extra details: 额外详情:

  • Rust 1.34 锈1.34
  • Linux 的Linux
  • CC 8.2.1 CC 8.2.1
unsigned char code[] = {
0x55,                           //    push   %rbp
0x48, 0x89, 0xe5,               //    mov    %rsp,%rbp
0xb8, 0x37, 0x00, 0x00, 0x00,   //    mov    $0x37,%eax
0xc9,                           //    leaveq
0xc3                            //    retq
};


void reflect(const unsigned char *code) {
  void *buf;

  /* copy code to executable buffer */    
  buf = mmap(0, sizeof(code), PROT_READ|PROT_WRITE|PROT_EXEC,MAP_PRIVATE|MAP_ANON,-1,0);
  memcpy(buf, code, sizeof(code));

  ((void (*) (void))buf)();
}
extern crate mmap;

use mmap::{MapOption, MemoryMap};

unsafe fn reflect(instructions: &[u8]) {
    let map = MemoryMap::new(
        instructions.len(),
        &[
            MapOption::MapAddr(0 as *mut u8),
            MapOption::MapOffset(0),
            MapOption::MapFd(-1),
            MapOption::MapReadable,
            MapOption::MapWritable,
            MapOption::MapExecutable,
            MapOption::MapNonStandardFlags(libc::MAP_ANON),
            MapOption::MapNonStandardFlags(libc::MAP_PRIVATE),
        ],
    )
    .unwrap();

    std::ptr::copy(instructions.as_ptr(), map.data(), instructions.len());
    // How to cast into extern "C" fn() ?
}

Use mem::transmute to cast a raw pointer to a function pointer type. 使用mem::transmute将原始指针转换为函数指针类型。

use std::mem;

let func: unsafe extern "C" fn() = mem::transmute(map.data());
func();

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM