panda-re 0.49.0

The official library for interfacing with PANDA (Platform for Architecture-Neutral Dynamic Analysis)
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
//! Bindings for various built-in PANDA plugins

use crate::{sys::panda_require, ARCH_NAME};
use libloading::Symbol;
use once_cell::sync::OnceCell;
use std::ffi::CString;
use std::path::{Path, PathBuf};

pub mod cosi;
pub mod glib;
pub mod guest_plugin_manager;
pub mod hooks;
pub mod hooks2;
pub mod osi;
pub mod proc_start_linux;

#[cfg(not(feature = "ppc"))]
pub mod syscalls2;

/// A macro for importing an external PANDA plugin to use
///
/// **Note:** it is recommended that, if the plugin you want to use already has
/// panda-rs bindings, they should be used instead. Those are located in the
/// [`plugins`](crate::plugins) module, and typically include a note about where
/// the high-level bindings for the given plugin are located.
///
/// ## Example Usage
///
/// ### Declaring bindings for free function in an external plugin:
///
/// ```
/// plugin_import!{
///     static OSI: Osi = extern "osi" {
///         fn get_process_handles(cpu: *mut CPUState) -> GBoxedSlice<OsiProcHandle>;
///         fn get_current_thread(cpu: *mut CPUState) -> GBox<OsiThread>;
///         fn get_modules(cpu: *mut CPUState) -> GBoxedSlice<OsiModule>;
///         fn get_mappings(cpu: *mut CPUState, p: *mut OsiProc) -> GBoxedSlice<OsiModule>;
///         fn get_processes(cpu: *mut CPUState) -> GBoxedSlice<OsiProc>;
///         fn get_current_process(cpu: *mut CPUState) -> GBox<OsiProc>;
///     };
/// }
/// ```
///
/// This will create a lazy initialized static variable named `OSI` in the current
/// scope. This static will include all of the functions listed as methods, when
/// any function is run the plugin (the name of which is specified by `extern "osi"`)
/// will be loaded on the fly before executing the method.
///
/// To load a plugin without running any function, `plugin_import` also automatically
/// creates an `ensure_init` method which initializes the plugin without any other
/// side effects.
///
/// ### Plugin Callbacks
///
/// Plugin-to-Plugin callbacks in PANDA are typically quite verbose to make bindings for
/// by hand, so the `plugin_import` macro provides a shorthand for defining a function
/// prototype for the callback and it will generate all the code needed to add and remove
/// callbacks for it.
///
/// ```
/// plugin_import! {
///     static PROC_START_LINUX: ProcStartLinux = extern "proc_start_linux" {
///         callbacks {
///             fn on_rec_auxv(cpu: &mut CPUState, tb: &mut TranslationBlock, auxv: &AuxvValues);
///         }
///     };
/// }
/// ```
///
/// the above creates another lazy static which has the following methods for working with
/// the `on_rec_auxv` callback:
///
/// * `add_callback_on_rec_auxv` - add a callback by function pointer
/// * `remove_callback_on_rec_auxv` - remove a callback by function pointer
///
/// One requirement of these function pointers is that they must use the C ABI. So the
/// argument for both methods would be of the type:
///
/// ```
/// extern "C" fn (&mut CPUState, &mut TranslationBlock, &AuxvValues)
/// ```
///
/// This macro will also generate a trait allowing any plugin-to-plugin callbacks to be
/// used via the [`PppCallback`] API. So the above would generate
/// a trait called `ProcStartLinuxCallbacks` which would have a method called `on_rec_auxv`,
/// which is automatically implemented for [`PppCallback`].
///
/// [`PppCallback`]: crate::PppCallback
#[macro_export]
macro_rules! plugin_import {
    {
        $(
            #[ $type_meta:meta ]
        )*
        static $static:ident : $ty:ident = extern $name:literal {
        $(
            $(
                #[$meta:meta]
             )*
            fn $fn_name:ident
                $(
                    <
                        $(
                            $lifetimes:lifetime
                        ),*
                        $(,)?
                    >
                )?
            (
                $(
                    $arg_name:ident : $arg_ty:ty
                 ),*
                $(,)?
            ) $(-> $fn_ret:ty)?;
         )*
        $(
            callbacks {
                $(
                    fn $cb_fn_name:ident(
                        $(
                            $cb_arg_name:ident : $cb_arg_ty:ty
                         ),*
                        $(,)?
                    ) $(-> $cb_fn_ret:ty)?;
                )*
            }
        )?
        };
    } => {
        $(
            #[ $type_meta ]
        )*
        pub struct $ty {
            plugin: $crate::plugins::Plugin
        }

        impl $ty {
            /// Create a new handle to this plugin
            pub fn new() -> Self {
                Self {
                    plugin: $crate::plugins::Plugin::new($name)
                }
            }

            /// Load the plugin and initialize it if it hasn't been loaded already.
            pub fn ensure_init(&self) {}

            $(
                $(
                    #[$meta]
                 )*
                pub fn $fn_name $(< $($lifetimes),* >)? (&self $(, $arg_name : $arg_ty )*) $(-> $fn_ret)? {
                    unsafe {
                        self.plugin.get::<unsafe extern "C" fn($($arg_ty),*) $(-> $fn_ret)?>(
                            stringify!($fn_name)
                        )(
                            $(
                                $arg_name
                            ),*
                        )
                    }
                }
             )*

            $($(
                $crate::paste::paste!{
                    pub fn [<add_callback_ $cb_fn_name>](
                        &self,
                        callback: extern "C" fn(
                            $($cb_arg_name: $cb_arg_ty),*
                        )
                    )
                    {
                        let add_cb = self.plugin.get::<
                            extern "C" fn(
                                extern "C" fn(
                                    $($cb_arg_ty),*
                                ) $(-> $cb_fn_ret)?
                            )
                        >(
                            concat!("ppp_add_cb_", stringify!($cb_fn_name))
                        );

                        add_cb(callback);
                    }

                    pub fn [<remove_callback_ $cb_fn_name>](
                        &self,
                        callback: extern "C" fn(
                            $($cb_arg_name: $cb_arg_ty),*
                        )
                    )
                    {
                        let remove_cb = self.plugin.get::<
                            extern "C" fn(
                                extern "C" fn(
                                    $($cb_arg_ty),*
                                ) $(-> $cb_fn_ret)?
                            )
                        >(
                            concat!("ppp_remove_cb_", stringify!($cb_fn_name))
                        );

                        remove_cb(callback);
                    }

                    #[doc(hidden)]
                    pub fn [<add_callback_ $cb_fn_name _with_context>](
                        &self,
                        callback: unsafe extern "C" fn(
                            *mut std::ffi::c_void, $($cb_arg_name: $cb_arg_ty),*
                        ),
                        context: *mut std::ffi::c_void,
                    )
                    {
                        let add_cb = self.plugin.get::<
                            extern "C" fn(
                                unsafe extern "C" fn(
                                    *mut std::ffi::c_void, $($cb_arg_ty),*
                                ) $(-> $cb_fn_ret)?,
                                *mut std::ffi::c_void,
                            )
                        >(
                            concat!("ppp_add_cb_", stringify!($cb_fn_name), "_with_context")
                        );

                        add_cb(callback, context);
                    }

                    #[doc(hidden)]
                    pub fn [<remove_callback_ $cb_fn_name _with_context>](
                        &self,
                        callback: unsafe extern "C" fn(
                            *mut std::ffi::c_void, $($cb_arg_name: $cb_arg_ty),*
                        ),
                        context: *mut std::ffi::c_void,
                    )
                    {
                        let remove_cb = self.plugin.get::<
                            extern "C" fn(
                                unsafe extern "C" fn(
                                    *mut std::ffi::c_void, $($cb_arg_ty),*
                                ) $(-> $cb_fn_ret)?,
                                *mut std::ffi::c_void,
                            )
                        >(
                            concat!("ppp_remove_cb_", stringify!($cb_fn_name), "_with_context")
                        );

                        remove_cb(callback, context);
                    }
                }
            )*)?
        }

        $crate::lazy_static::lazy_static!{
            $(
                #[ $type_meta ]
            )*
            pub static ref $static: $ty = $ty::new();
        }

        $(
            $crate::paste::paste!{
                /// A trait for expressing the plugin-to-plugin callbacks provided by
                /// the given plugin. See `panda::PppCallback` for more information,
                /// as this is intended to be used as an extension trait for it.
                pub trait [<$ty Callbacks>] {
                    $(
                        /// Installs the given closure over the callback slot provided
                        /// by the `panda::PppCallback` this is called on, setting it to
                        /// be run whenever the `
                        #[doc = stringify!($cb_fn_name)]
                        ///` callback is hit.
                        ///
                        /// ## Arguments
                        ///
                        $(
                            #[doc = "* `"]
                            #[doc = stringify!($cb_arg_name)]
                            #[doc = "` - `"]
                            #[doc = stringify!($cb_arg_ty)]
                            #[doc = "`"]
                            #[doc = ""]
                        )*
                        /// ## Example
                        ///
                        /// ```
                        /// use panda::PppCallback;
                        /// use panda::prelude::*;
                        #[doc = concat!(
                            "use /*...*/::",
                            stringify!($ty),
                            "Callbacks;"
                        )]
                        ///
                        #[doc = concat!(
                            "PppCallbacks::new()\n    .",
                            stringify!($cb_fn_name),
                            "(|",
                            $(
                                stringify!($cb_arg_name),
                                ": ",
                                stringify!($cb_arg_ty),
                                ", ",
                            )*
                            "|{\n        // callback code\n    });"
                        )]
                        /// ```
                        fn $cb_fn_name<CallbackFn>(self, callback: CallbackFn)
                            where CallbackFn: FnMut($($cb_arg_ty),*) $(-> $cb_fn_ret)? + 'static;
                    )*
                }

                impl [<$ty Callbacks>] for $crate::PppCallback {
                    $(
                        fn $cb_fn_name<CallbackFn>(self, callback: CallbackFn)
                            where CallbackFn: FnMut($($cb_arg_ty),*) $(-> $cb_fn_ret)? + 'static
                        {
                            use std::ffi::c_void;
                            let closure_ref: *mut c_void = unsafe {
                                let x: Box<Box<
                                    dyn FnMut($($cb_arg_ty),*) $(-> $cb_fn_ret)?
                                >> = Box::new(
                                    Box::new(callback) as Box<_>
                                );
                                core::mem::transmute(x)
                            };

                            unsafe extern "C" fn trampoline(
                                context: *mut c_void, $($cb_arg_name : $cb_arg_ty),*
                            ) $(-> $cb_fn_ret)?
                            {
                                let closure: &mut &mut (
                                    dyn FnMut($($cb_arg_ty),*) $(-> $cb_fn_ret)?
                                ) = core::mem::transmute(
                                    context
                                );

                                closure($($cb_arg_name),*)
                            }

                            unsafe fn drop_fn(this: *mut c_void) {
                                let _: Box<Box<
                                    dyn FnMut($($cb_arg_ty),*) $(-> $cb_fn_ret)?
                                >> = core::mem::transmute(this);
                            }

                            unsafe fn enable(this: *mut c_void) {
                                $static.[<add_callback_ $cb_fn_name _with_context>](
                                    trampoline,
                                    this
                                );
                            }

                            unsafe fn disable(this: *mut c_void) {
                                $static.[<remove_callback_ $cb_fn_name _with_context>](
                                    trampoline,
                                    this
                                );
                            }

                            let callback = $crate::InternalPppClosureCallback {
                                closure_ref,
                                drop_fn,
                                enable,
                                disable,
                                is_enabled: false,
                            };
                            $crate::Panda::run_after_init(move || {
                                unsafe {
                                    $crate::__internal_install_ppp_closure_callback(
                                        self,
                                        callback
                                    );
                                }
                            });
                        }
                    )*
                }
            }
        )?
    }
}

/// A wrapper for a dynamic library loaded as a PANDA plugin. Is used internally by
/// the [`plugin_import`] macro to manage loading/unloading PANDA plugins lazily.
pub struct Plugin {
    lib: libloading::Library,
}

const PANDA_GLOBAL_INSTALLS: &[&str] = &["/usr/local/lib/panda", "/usr/lib/panda"];

fn get_panda_path() -> Option<&'static Path> {
    static PANDA_PATH: OnceCell<Option<PathBuf>> = OnceCell::new();

    PANDA_PATH
        .get_or_init(|| {
            if let Ok(path) = std::env::var("PANDA_PATH") {
                Some(PathBuf::from(path))
            } else {
                for possible_path in PANDA_GLOBAL_INSTALLS {
                    let path = PathBuf::from(possible_path);

                    if path.exists() {
                        return Some(path);
                    }
                }

                None
            }
        })
        .as_deref()
}

fn get_panda_plugin_dir() -> Option<&'static Path> {
    static PANDA_PLUGIN_DIR: OnceCell<Option<PathBuf>> = OnceCell::new();

    PANDA_PLUGIN_DIR
        .get_or_init(|| {
            let panda_path = get_panda_path()?;

            if let Ok(path) = std::env::var("PANDA_PLUGIN_DIR") {
                Some(panda_path.join(path))
            } else {
                let path = panda_path.join(&format!("{}/panda/plugins", ARCH_NAME));
                if path.exists() {
                    return Some(path);
                }

                let path = panda_path.join(&format!("{}-softmmu/panda/plugins", ARCH_NAME));
                if path.exists() {
                    return Some(path);
                }

                let path = panda_path.join(ARCH_NAME);
                if path.exists() {
                    return Some(path);
                }

                None
            }
        })
        .as_deref()
}

impl Plugin {
    pub fn new(name: &str) -> Self {
        let panda_path =
            get_panda_path().expect("PANDA_PATH not set and PANDA is not installed globally");

        unsafe {
            std::env::set_var("PANDA_DIR", &panda_path);

            let c_name = CString::new(name).unwrap();
            panda_require(c_name.as_ptr());
        }

        let path = get_panda_plugin_dir()
            .expect("Could not find panda plugin dir, consider setting PANDA_PLUGIN_DIR")
            .join(&format!("panda_{}.so", name));

        if !path.exists() {
            panic!("Could not find plugin {} at {}", name, path.display());
        }

        Self {
            lib: libloading::Library::new(path).expect("Failed to load plugin"),
        }
    }

    pub fn get<T>(&self, sym: &str) -> Symbol<T> {
        let symbol: Vec<_> = sym.bytes().chain(std::iter::once(0)).collect();
        unsafe { self.lib.get(&symbol).expect("Could not find symbol") }
    }
}