如何在托管代码中获取EIP的当前值?

Alo*_*aus 7 .net c# clr

问题似乎是一个你不应该做的肮脏的黑客,但让我先解释一下.最终目标是在C++中使用方法局部静态.

void Func()
{
   static methodLocalObject = new ExpensiveThing();
   // use methodlocal Object
}
Run Code Online (Sandbox Code Playgroud)

这与指令指针有什么关系?我想根据我的调用者缓存数据.为了使这个快速,我回到堆栈中以获取我的调用者的地址,并将其用作字典的唯一键来存储数据.这将允许创建一个基于反射的跟踪器,它不会每次都使用Reflection来获取当前方法和类型的名称,但只有一次,并将反射信息存储在哈希表中.

到目前为止,答案仅以单声道为基础.我想尝试一个适用于.NET 3.5/4.0 32/64位的通用解决方案.我知道64位的调用约定是完全不同的,因此获得可靠的东西可能会遇到挑战.但另一方面,我在我的方法中完全控制堆栈的外观.在.NET 3.5和4.0之间,堆栈确实看起来非常不同,当然它在发布版本之间也有所不同.我仍然需要检查NGen是否确实创建了具有不同堆栈布局的代码.一种可能性是使用C++帮助器方法,该方法需要5个魔术整数参数(在x64上只有第5个将在堆栈上)并检查我在堆栈中可以找到它们的位置.另一种可能性是简单地使用整个堆栈,直到我在堆栈上找到我的魔术标记作为键并使用堆栈的这一部分作为唯一足够的密钥.但我不确定这种方法是否可行,或者是否有更好的选择.我知道我可以通过分析或调试apis以安全的方式走栈,但它们都不是很快.

对于跟踪库,通常的方法是使用反射来遍历堆栈以获取当前方法名称和类型.

class Tracer
{
    [MethodImpl(MethodImplOptions.NoInlining)]
    public Tracer()
    {
        StackFrame frame = new StackTrace().GetFrame(1); // get caller
        Console.WriteLine("Entered method {0}.{1}", frame.GetMethod().DeclaringType.FullName, frame.GetMethod().Name);
    }

}
Run Code Online (Sandbox Code Playgroud)

但这很慢.另一个解决方案是直接通过字符串传递数据,速度要快得多,但需要更多的输入.另一种解决方案是使用调用函数的指令指针(如果可以以非常快的方式确定)来绕过昂贵的反射调用.那么这是可能的:

class Tracer
{
    static Dictionary<Int64, string> _CachedMethods = new Dictionary<Int64, string>();

    [MethodImpl(MethodImplOptions.NoInlining)]
    public Tracer()
    {
        Int64 eip = GetEIpOfParentFrame();
        string name;
        lock (_CachedMethods)
        {
            if (!_CachedMethods.TryGetValue(eip, out name))
            {
                var callingMethod = new StackTrace().GetFrame(1).GetMethod();
                name =  callingMethod.DeclaringType + "." + callingMethod.Name;
                _CachedMethods[eip] = name;
            }
        }
        Console.WriteLine("Entered method {0}", name);

    }

    Int64 GetEIpOfParentFrame()
    {
        return 0; // todo this is the question how to get it
    }

}
Run Code Online (Sandbox Code Playgroud)

我知道解决方案需要不受管理.在C++中,有一个名为_ReturnAddress的编译器内部函数,但根据文档,它不能与托管代码一起使用.另一种提出相同问题的方法:是否有人知道.NET 3.5/4 x32/x64托管方法的调用约定和堆栈布局?

你的,Alois Kraus

seh*_*ehe 7

更新现在,对于最新版本的.NET,此答案已过时:请参阅此处如何在托管代码中获取EIP的当前值?

真正简短的回答是:CLR VM是一个堆栈机器,因此没有EIP.稍微长一点的答案是:如果您依赖于未记录的特定于实现的详细信息,则可以在非托管代码中从CPU EIP推断出可用ID.

概念证明

我只是在Linux 32位上使用mono 2.11进行了以下概念验证.我希望这些信息可能有所帮助.这实现了非托管函数:

extern static string CurrentMethodDisplay();
extern static uint CurrentMethodAddress();
Run Code Online (Sandbox Code Playgroud)

原生资源:tracehelper.c [1]:

#include <string.h>

void* CurrentMethodAddress()
{
    void* ip;
    asm ("movl 4(%%ebp),%0" : "=r"(ip) );
    return ip;
}

const char* const MethodDisplayFromAddress(void* ip);
const char* const CurrentMethodDisplay()
{
    return MethodDisplayFromAddress(CurrentMethodAddress());
}

#ifndef USE_UNDOCUMENTED_APIS
extern char * mono_pmip (void *ip);

const char* const MethodDisplayFromAddress(void* ip)
{
    const char* text = mono_pmip(ip);
    return strdup(text? text:"(unknown)");
}
#else

/* 
 * undocumented structures, not part of public API
 *
 * mono_pmip only returns a rather ugly string representation of the stack frame
 * this version of the code tries establish only the actual name of the method
 *
 * mono_pmip understands call trampolines as well, this function skips those
 */
struct _MonoDomain; // forward
struct _MonoMethod; // forward
typedef struct _MonoDomain  MonoDomain;
typedef struct _MonoMethod  MonoMethod;
struct _MonoJitInfo { MonoMethod* method; /* rest ommitted */ };

typedef struct _MonoJitInfo MonoJitInfo;

MonoDomain *mono_domain_get(void);
char* mono_method_full_name(MonoMethod *method, int signature);
MonoJitInfo *mono_jit_info_table_find(MonoDomain *domain, char *addr);

const char* const MethodDisplayFromAddress(void* ip)
{
    MonoJitInfo *ji = mono_jit_info_table_find (mono_domain_get(), ip);
    const char* text = ji? mono_method_full_name (ji->method, 1) : 0;
    return text? text:strdup("(unknown, trampoline?)");
}

#endif
Run Code Online (Sandbox Code Playgroud)

C#Source(client.cs)调用此本机库函数:

using System;
using System.Runtime.InteropServices;

namespace PoC
{
    class MainClass
    {
        [DllImportAttribute("libtracehelper.so")] extern static string CurrentMethodDisplay();
        [DllImportAttribute("libtracehelper.so")] extern static uint CurrentMethodAddress();

        static MainClass()
        {
            Console.WriteLine ("TRACE 0 {0:X8} {1}", CurrentMethodAddress(), CurrentMethodDisplay());
        }

        public static void Main (string[] args)
        {
            Console.WriteLine ("TRACE 1 {0:X8} {1}", CurrentMethodAddress(), CurrentMethodDisplay());
            {
                var instance = new MainClass();
                instance.OtherMethod();
            }
            Console.WriteLine ("TRACE 2 {0:X8} {1}", CurrentMethodAddress(), CurrentMethodDisplay());
            {
                var instance = new MainClass();
                instance.OtherMethod();
            }
            Console.WriteLine ("TRACE 3 {0:X8} {1}", CurrentMethodAddress(), CurrentMethodDisplay());
            Console.Read();
        }

        private void OtherMethod()
        {
            ThirdMethod();
            Console.WriteLine ("TRACE 4 {0:X8} {1}", CurrentMethodAddress(), CurrentMethodDisplay());
        }

        private void ThirdMethod()
        {
            Console.WriteLine ("TRACE 5 {0:X8} {1}", CurrentMethodAddress(), CurrentMethodDisplay());
        }
    }
}
Run Code Online (Sandbox Code Playgroud)

使用Makefile编译和链接:

CFLAGS+=-DUSE_UNDOCUMENTED_APIS
CFLAGS+=-fomit-frame-pointer
CFLAGS+=-save-temps
CFLAGS+=-g -O3

all: client.exe libtracehelper.so

client.exe: client.cs | libtracehelper.so
    gmcs -debug+ -optimize- client.cs 

tracehelper.s libtracehelper.so: tracehelper.c
    gcc -shared $(CFLAGS) -lmono -o $@ tracehelper.c 
#   gcc -g -O0 -shared -fomit-frame-pointer -save-temps -lmono -o $@ tracehelper.c 

test: client.exe
    LD_LIBRARY_PATH=".:..:/opt/mono/lib/" valgrind --tool=memcheck --leak-check=full --smc-check=all --suppressions=mono.supp mono --gc=sgen --debug ./client.exe

clean:
    rm -fv *.so *.exe a.out *.[iso] *.mdb
Run Code Online (Sandbox Code Playgroud)

运行此LD_LIBRARY_PATH=. ./client.exe结果导致:

TRACE 0 B57EF34B PoC.MainClass:.cctor ()
TRACE 1 B57EF1B3 PoC.MainClass:Main (string[])
TRACE 5 B57F973B PoC.MainClass:ThirdMethod ()
TRACE 4 B57F96E9 PoC.MainClass:OtherMethod ()
TRACE 2 B57EF225 PoC.MainClass:Main (string[])
TRACE 5 B57F973B PoC.MainClass:ThirdMethod ()
TRACE 4 B57F96E9 PoC.MainClass:OtherMethod ()
TRACE 3 B57EF292 PoC.MainClass:Main (string[])
Run Code Online (Sandbox Code Playgroud)

请注意,这是在Mono 2.11上.它也适用于2.6.7,有和没有优化.

[1] 我为此目的学习了GNU扩展asm ; 谢谢!

结论?

提供了概念证明; 此实现特定于Mono.一个类似的'技巧'可以在MS .Net上传递(使用SOS.dll的:: LoadLibrary,也许?)但是留给读者的练习:)

我本人还会继续我的另一个答案,但我想我已经屈服于挑战,就像我之前说的那样:YMMV,这里有龙,TIMTOWTDI,KISS等.

晚安


seh*_*ehe 2

C# 5.0 有一个新的、隐藏得很好的功能可以实现这一点。

来电者信息属性

注意显然,还有Microsoft BCL Portability Pack 1.1.3 Nuget 包,因此您可以在 .NET 4.0 中使用呼叫者信息属性。

这样做的作用是使您的可选参数神奇地具有与调用者相关的默认值。它有

它有一些非常漂亮的功能:

  • 调用者信息值在编译时作为文字发送到中间语言 (IL) 中。
  • 与异常的 StackTrace 属性的结果不同,结果不受混淆影响。

文档示例如下所示:

// using System.Runtime.CompilerServices 
// using System.Diagnostics; 

public void DoProcessing()
{
    TraceMessage("Something happened.");
}

public void TraceMessage(string message,
        [CallerMemberName] string memberName = "",
        [CallerFilePath] string sourceFilePath = "",
        [CallerLineNumber] int sourceLineNumber = 0)
{
    Trace.WriteLine("message: " + message);
    Trace.WriteLine("member name: " + memberName);
    Trace.WriteLine("source file path: " + sourceFilePath);
    Trace.WriteLine("source line number: " + sourceLineNumber);
}

// Sample Output: 
//  message: Something happened. 
//  member name: DoProcessing 
//  source file path: c:\Users\username\Documents\Visual Studio 2012\Projects\CallerInfoCS\CallerInfoCS\Form1.cs 
//  source line number: 31 
Run Code Online (Sandbox Code Playgroud)