18 |
19 |
--------------------------------------------------------------------------------
/app/src/main/AndroidManifest.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
9 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # SimpleIORedirect
2 | Android I/O redirection implementation, using seccomp user notify mechanism
3 |
4 | * At least kernel version **5.10** required
5 | * This example has been tested on `aarch64`, `x86_64` and `riscv64` architectures
6 | * This example currently only supports debug build, in release build you should implement memory read and write yourself
7 |
8 | 使用 seccomp user notify 机制的 Android I/O 重定向实现
9 |
10 | * 至少需要 **5.10** 版本内核
11 | * 本示例已在 `aarch64`, `x86_64` 与 `riscv64` 架构上测试通过
12 | * 本示例目前仅支持 debug 构建, 在 release 构建时你应该自行实现内存读写
13 |
14 | [Download example](https://github.com/eirv/SimpleIORedirect/raw/main/app-debug.apk)
15 |
16 | 提示: ~~稍加修改可以对最新某数字加固实现过签~~
17 |
18 | 看来已经开始有人用于过签360加固了🤔
19 | 
20 | 
21 | 
22 |
--------------------------------------------------------------------------------
/app/proguard-rules.pro:
--------------------------------------------------------------------------------
1 | # Add project specific ProGuard rules here.
2 | # You can control the set of applied configuration files using the
3 | # proguardFiles setting in build.gradle.
4 | #
5 | # For more details, see
6 | # http://developer.android.com/guide/developing/tools/proguard.html
7 |
8 | # If your project uses WebView with JS, uncomment the following
9 | # and specify the fully qualified class name to the JavaScript interface
10 | # class:
11 | #-keepclassmembers class fqcn.of.javascript.interface.for.webview {
12 | # public *;
13 | #}
14 |
15 | # Uncomment this to preserve the line number information for
16 | # debugging stack traces.
17 | #-keepattributes SourceFile,LineNumberTable
18 |
19 | # If you keep the line number information, uncomment this to
20 | # hide the original source file name.
21 | #-renamesourcefileattribute SourceFile
--------------------------------------------------------------------------------
/.idea/deploymentTargetDropDown.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
--------------------------------------------------------------------------------
/settings.gradle:
--------------------------------------------------------------------------------
1 | pluginManagement {
2 | repositories {
3 | maven { url 'https://maven.aliyun.com/repository/public/' }
4 | maven { url 'https://maven.aliyun.com/repository/google/' }
5 | maven { url 'https://maven.aliyun.com/repository/gradle-plugin/' }
6 | google {
7 | content {
8 | includeGroupByRegex("com\\.android.*")
9 | includeGroupByRegex("com\\.google.*")
10 | includeGroupByRegex("androidx.*")
11 | }
12 | }
13 | mavenCentral()
14 | gradlePluginPortal()
15 | }
16 | }
17 | dependencyResolutionManagement {
18 | repositoriesMode.set(RepositoriesMode.FAIL_ON_PROJECT_REPOS)
19 | repositories {
20 | maven { url 'https://maven.aliyun.com/repository/public/' }
21 | maven { url 'https://maven.aliyun.com/repository/google/' }
22 | google()
23 | mavenCentral()
24 | }
25 | }
26 |
27 | rootProject.name = "SimpleIORedirect"
28 | include ':app'
29 |
--------------------------------------------------------------------------------
/app/build.gradle:
--------------------------------------------------------------------------------
1 | plugins {
2 | alias(libs.plugins.androidApplication)
3 | }
4 |
5 | android {
6 | namespace 'io.github.eirv.simpleioredirect'
7 | compileSdk 35
8 | ndkVersion '29.0.13113456'
9 |
10 | defaultConfig {
11 | applicationId "io.github.eirv.simpleioredirect"
12 | minSdk 31
13 | targetSdk 35
14 | versionCode 1
15 | versionName "1.0"
16 |
17 | externalNativeBuild {
18 | cmake {
19 | cppFlags '-std=c++23'
20 | arguments += '-DANDROID_STL=none'
21 | }
22 | }
23 | ndk {
24 | abiFilters 'arm64-v8a', 'armeabi-v7a', 'x86', 'x86_64', 'riscv64'
25 | }
26 | }
27 |
28 | buildTypes {
29 | release {
30 | minifyEnabled false
31 | proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro'
32 | }
33 | }
34 | externalNativeBuild {
35 | cmake {
36 | path 'src/main/cpp/CMakeLists.txt'
37 | version '3.22.1'
38 | }
39 | }
40 | compileOptions {
41 | sourceCompatibility JavaVersion.VERSION_11
42 | targetCompatibility JavaVersion.VERSION_11
43 | }
44 | packagingOptions {
45 | jniLibs.useLegacyPackaging true
46 | }
47 | }
48 |
49 | dependencies {
50 | }
--------------------------------------------------------------------------------
/gradle.properties:
--------------------------------------------------------------------------------
1 | # Project-wide Gradle settings.
2 | # IDE (e.g. Android Studio) users:
3 | # Gradle settings configured through the IDE *will override*
4 | # any settings specified in this file.
5 | # For more details on how to configure your build environment visit
6 | # http://www.gradle.org/docs/current/userguide/build_environment.html
7 | # Specifies the JVM arguments used for the daemon process.
8 | # The setting is particularly useful for tweaking memory settings.
9 | org.gradle.jvmargs=-Xmx2048m -Dfile.encoding=UTF-8
10 | # When configured, Gradle will run in incubating parallel mode.
11 | # This option should only be used with decoupled projects. For more details, visit
12 | # https://developer.android.com/r/tools/gradle-multi-project-decoupled-projects
13 | # org.gradle.parallel=true
14 | # AndroidX package structure to make it clearer which packages are bundled with the
15 | # Android operating system, and which are packaged with your app's APK
16 | # https://developer.android.com/topic/libraries/support-library/androidx-rn
17 | android.useAndroidX=true
18 | # Kotlin code style for this project: "official" or "obsolete":
19 | kotlin.code.style=official
20 | # Enables namespacing of each library's R class so that its R class includes only the
21 | # resources declared in the library itself and none from the library's dependencies,
22 | # thereby reducing the size of the R class for that library
23 | android.nonTransitiveRClass=true
--------------------------------------------------------------------------------
/gradle/libs.versions.toml:
--------------------------------------------------------------------------------
1 | [versions]
2 | agp = "8.9.0"
3 | kotlin = "1.9.0"
4 | coreKtx = "1.12.0"
5 | junit = "4.13.2"
6 | junitVersion = "1.1.5"
7 | espressoCore = "3.5.1"
8 | lifecycleRuntimeKtx = "2.7.0"
9 | activityCompose = "1.8.2"
10 | composeBom = "2023.08.00"
11 |
12 | [libraries]
13 | androidx-core-ktx = { group = "androidx.core", name = "core-ktx", version.ref = "coreKtx" }
14 | junit = { group = "junit", name = "junit", version.ref = "junit" }
15 | androidx-junit = { group = "androidx.test.ext", name = "junit", version.ref = "junitVersion" }
16 | androidx-espresso-core = { group = "androidx.test.espresso", name = "espresso-core", version.ref = "espressoCore" }
17 | androidx-lifecycle-runtime-ktx = { group = "androidx.lifecycle", name = "lifecycle-runtime-ktx", version.ref = "lifecycleRuntimeKtx" }
18 | androidx-activity-compose = { group = "androidx.activity", name = "activity-compose", version.ref = "activityCompose" }
19 | androidx-compose-bom = { group = "androidx.compose", name = "compose-bom", version.ref = "composeBom" }
20 | androidx-ui = { group = "androidx.compose.ui", name = "ui" }
21 | androidx-ui-graphics = { group = "androidx.compose.ui", name = "ui-graphics" }
22 | androidx-ui-tooling = { group = "androidx.compose.ui", name = "ui-tooling" }
23 | androidx-ui-tooling-preview = { group = "androidx.compose.ui", name = "ui-tooling-preview" }
24 | androidx-ui-test-manifest = { group = "androidx.compose.ui", name = "ui-test-manifest" }
25 | androidx-ui-test-junit4 = { group = "androidx.compose.ui", name = "ui-test-junit4" }
26 | androidx-material3 = { group = "androidx.compose.material3", name = "material3" }
27 |
28 | [plugins]
29 | androidApplication = { id = "com.android.application", version.ref = "agp" }
30 | jetbrainsKotlinAndroid = { id = "org.jetbrains.kotlin.android", version.ref = "kotlin" }
31 |
32 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable/ic_launcher_foreground.xml:
--------------------------------------------------------------------------------
1 |
7 |
8 |
9 |
15 |
18 |
21 |
22 |
23 |
24 |
30 |
--------------------------------------------------------------------------------
/app/src/main/java/io/github/eirv/simpleioredirect/MainActivity.java:
--------------------------------------------------------------------------------
1 | package io.github.eirv.simpleioredirect;
2 |
3 | import android.app.Activity;
4 | import android.app.AlertDialog;
5 | import android.os.Build;
6 | import android.os.Bundle;
7 | import android.util.Log;
8 | import android.widget.TextView;
9 |
10 | import java.io.File;
11 | import java.io.IOException;
12 | import java.nio.file.Files;
13 | import java.nio.file.Paths;
14 |
15 | public class MainActivity extends Activity {
16 | private static final String TARGET_PATH = "/just/for/fun";
17 |
18 | static {
19 | System.loadLibrary("io-redirect");
20 | }
21 |
22 | @Override
23 | protected void onCreate(Bundle savedInstanceState) {
24 | super.onCreate(savedInstanceState);
25 |
26 | var redirection = new File(getDataDir(), "redirection.txt");
27 | try {
28 | Files.write(redirection.toPath(), "This is redirection.txt".getBytes());
29 | } catch (IOException ignored) {
30 | }
31 |
32 | var actionBar = getActionBar();
33 | if (actionBar != null) {
34 | actionBar.setSubtitle(TARGET_PATH);
35 | }
36 |
37 | if (!redirect(TARGET_PATH, redirection.getPath())) {
38 | new AlertDialog.Builder(this)
39 | .setTitle("Error")
40 | .setMessage("This example cannot be run on your device and requires at least kernel version 5.10")
41 | .setPositiveButton(android.R.string.ok, null)
42 | .create()
43 | .show();
44 | }
45 |
46 | var textView = new TextView(this);
47 | textView.setText(readFile(TARGET_PATH));
48 | if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.VANILLA_ICE_CREAM) {
49 | textView.setFitsSystemWindows(true);
50 | }
51 | setContentView(textView);
52 | }
53 |
54 | private static String readFile(String path) {
55 | try {
56 | return new String(Files.readAllBytes(Paths.get(path)));
57 | } catch (IOException e) {
58 | return Log.getStackTraceString(e);
59 | }
60 | }
61 |
62 | public static native boolean redirect(String target, String redirection);
63 | }
64 |
--------------------------------------------------------------------------------
/gradlew.bat:
--------------------------------------------------------------------------------
1 | @rem
2 | @rem Copyright 2015 the original author or authors.
3 | @rem
4 | @rem Licensed under the Apache License, Version 2.0 (the "License");
5 | @rem you may not use this file except in compliance with the License.
6 | @rem You may obtain a copy of the License at
7 | @rem
8 | @rem https://www.apache.org/licenses/LICENSE-2.0
9 | @rem
10 | @rem Unless required by applicable law or agreed to in writing, software
11 | @rem distributed under the License is distributed on an "AS IS" BASIS,
12 | @rem WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 | @rem See the License for the specific language governing permissions and
14 | @rem limitations under the License.
15 | @rem
16 |
17 | @if "%DEBUG%" == "" @echo off
18 | @rem ##########################################################################
19 | @rem
20 | @rem Gradle startup script for Windows
21 | @rem
22 | @rem ##########################################################################
23 |
24 | @rem Set local scope for the variables with windows NT shell
25 | if "%OS%"=="Windows_NT" setlocal
26 |
27 | set DIRNAME=%~dp0
28 | if "%DIRNAME%" == "" set DIRNAME=.
29 | set APP_BASE_NAME=%~n0
30 | set APP_HOME=%DIRNAME%
31 |
32 | @rem Resolve any "." and ".." in APP_HOME to make it shorter.
33 | for %%i in ("%APP_HOME%") do set APP_HOME=%%~fi
34 |
35 | @rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
36 | set DEFAULT_JVM_OPTS="-Xmx64m" "-Xms64m"
37 |
38 | @rem Find java.exe
39 | if defined JAVA_HOME goto findJavaFromJavaHome
40 |
41 | set JAVA_EXE=java.exe
42 | %JAVA_EXE% -version >NUL 2>&1
43 | if "%ERRORLEVEL%" == "0" goto execute
44 |
45 | echo.
46 | echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
47 | echo.
48 | echo Please set the JAVA_HOME variable in your environment to match the
49 | echo location of your Java installation.
50 |
51 | goto fail
52 |
53 | :findJavaFromJavaHome
54 | set JAVA_HOME=%JAVA_HOME:"=%
55 | set JAVA_EXE=%JAVA_HOME%/bin/java.exe
56 |
57 | if exist "%JAVA_EXE%" goto execute
58 |
59 | echo.
60 | echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
61 | echo.
62 | echo Please set the JAVA_HOME variable in your environment to match the
63 | echo location of your Java installation.
64 |
65 | goto fail
66 |
67 | :execute
68 | @rem Setup the command line
69 |
70 | set CLASSPATH=%APP_HOME%\gradle\wrapper\gradle-wrapper.jar
71 |
72 |
73 | @rem Execute Gradle
74 | "%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -classpath "%CLASSPATH%" org.gradle.wrapper.GradleWrapperMain %*
75 |
76 | :end
77 | @rem End local scope for the variables with windows NT shell
78 | if "%ERRORLEVEL%"=="0" goto mainEnd
79 |
80 | :fail
81 | rem Set variable GRADLE_EXIT_CONSOLE if you need the _script_ return code instead of
82 | rem the _cmd.exe /c_ return code!
83 | if not "" == "%GRADLE_EXIT_CONSOLE%" exit 1
84 | exit /b 1
85 |
86 | :mainEnd
87 | if "%OS%"=="Windows_NT" endlocal
88 |
89 | :omega
90 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable/ic_launcher_background.xml:
--------------------------------------------------------------------------------
1 |
2 |
7 |
10 |
15 |
20 |
25 |
30 |
35 |
40 |
45 |
50 |
55 |
60 |
65 |
70 |
75 |
80 |
85 |
90 |
95 |
100 |
105 |
110 |
115 |
120 |
125 |
130 |
135 |
140 |
145 |
150 |
155 |
160 |
165 |
170 |
171 |
--------------------------------------------------------------------------------
/gradlew:
--------------------------------------------------------------------------------
1 | #!/usr/bin/env sh
2 |
3 | #
4 | # Copyright 2015 the original author or authors.
5 | #
6 | # Licensed under the Apache License, Version 2.0 (the "License");
7 | # you may not use this file except in compliance with the License.
8 | # You may obtain a copy of the License at
9 | #
10 | # https://www.apache.org/licenses/LICENSE-2.0
11 | #
12 | # Unless required by applicable law or agreed to in writing, software
13 | # distributed under the License is distributed on an "AS IS" BASIS,
14 | # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15 | # See the License for the specific language governing permissions and
16 | # limitations under the License.
17 | #
18 |
19 | ##############################################################################
20 | ##
21 | ## Gradle start up script for UN*X
22 | ##
23 | ##############################################################################
24 |
25 | # Attempt to set APP_HOME
26 | # Resolve links: $0 may be a link
27 | PRG="$0"
28 | # Need this for relative symlinks.
29 | while [ -h "$PRG" ] ; do
30 | ls=`ls -ld "$PRG"`
31 | link=`expr "$ls" : '.*-> \(.*\)$'`
32 | if expr "$link" : '/.*' > /dev/null; then
33 | PRG="$link"
34 | else
35 | PRG=`dirname "$PRG"`"/$link"
36 | fi
37 | done
38 | SAVED="`pwd`"
39 | cd "`dirname \"$PRG\"`/" >/dev/null
40 | APP_HOME="`pwd -P`"
41 | cd "$SAVED" >/dev/null
42 |
43 | APP_NAME="Gradle"
44 | APP_BASE_NAME=`basename "$0"`
45 |
46 | # Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
47 | DEFAULT_JVM_OPTS='"-Xmx64m" "-Xms64m"'
48 |
49 | # Use the maximum available, or set MAX_FD != -1 to use that value.
50 | MAX_FD="maximum"
51 |
52 | warn () {
53 | echo "$*"
54 | }
55 |
56 | die () {
57 | echo
58 | echo "$*"
59 | echo
60 | exit 1
61 | }
62 |
63 | # OS specific support (must be 'true' or 'false').
64 | cygwin=false
65 | msys=false
66 | darwin=false
67 | nonstop=false
68 | case "`uname`" in
69 | CYGWIN* )
70 | cygwin=true
71 | ;;
72 | Darwin* )
73 | darwin=true
74 | ;;
75 | MINGW* )
76 | msys=true
77 | ;;
78 | NONSTOP* )
79 | nonstop=true
80 | ;;
81 | esac
82 |
83 | CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
84 |
85 |
86 | # Determine the Java command to use to start the JVM.
87 | if [ -n "$JAVA_HOME" ] ; then
88 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
89 | # IBM's JDK on AIX uses strange locations for the executables
90 | JAVACMD="$JAVA_HOME/jre/sh/java"
91 | else
92 | JAVACMD="$JAVA_HOME/bin/java"
93 | fi
94 | if [ ! -x "$JAVACMD" ] ; then
95 | die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
96 |
97 | Please set the JAVA_HOME variable in your environment to match the
98 | location of your Java installation."
99 | fi
100 | else
101 | JAVACMD="java"
102 | which java >/dev/null 2>&1 || die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
103 |
104 | Please set the JAVA_HOME variable in your environment to match the
105 | location of your Java installation."
106 | fi
107 |
108 | # Increase the maximum file descriptors if we can.
109 | if [ "$cygwin" = "false" -a "$darwin" = "false" -a "$nonstop" = "false" ] ; then
110 | MAX_FD_LIMIT=`ulimit -H -n`
111 | if [ $? -eq 0 ] ; then
112 | if [ "$MAX_FD" = "maximum" -o "$MAX_FD" = "max" ] ; then
113 | MAX_FD="$MAX_FD_LIMIT"
114 | fi
115 | ulimit -n $MAX_FD
116 | if [ $? -ne 0 ] ; then
117 | warn "Could not set maximum file descriptor limit: $MAX_FD"
118 | fi
119 | else
120 | warn "Could not query maximum file descriptor limit: $MAX_FD_LIMIT"
121 | fi
122 | fi
123 |
124 | # For Darwin, add options to specify how the application appears in the dock
125 | if $darwin; then
126 | GRADLE_OPTS="$GRADLE_OPTS \"-Xdock:name=$APP_NAME\" \"-Xdock:icon=$APP_HOME/media/gradle.icns\""
127 | fi
128 |
129 | # For Cygwin or MSYS, switch paths to Windows format before running java
130 | if [ "$cygwin" = "true" -o "$msys" = "true" ] ; then
131 | APP_HOME=`cygpath --path --mixed "$APP_HOME"`
132 | CLASSPATH=`cygpath --path --mixed "$CLASSPATH"`
133 |
134 | JAVACMD=`cygpath --unix "$JAVACMD"`
135 |
136 | # We build the pattern for arguments to be converted via cygpath
137 | ROOTDIRSRAW=`find -L / -maxdepth 1 -mindepth 1 -type d 2>/dev/null`
138 | SEP=""
139 | for dir in $ROOTDIRSRAW ; do
140 | ROOTDIRS="$ROOTDIRS$SEP$dir"
141 | SEP="|"
142 | done
143 | OURCYGPATTERN="(^($ROOTDIRS))"
144 | # Add a user-defined pattern to the cygpath arguments
145 | if [ "$GRADLE_CYGPATTERN" != "" ] ; then
146 | OURCYGPATTERN="$OURCYGPATTERN|($GRADLE_CYGPATTERN)"
147 | fi
148 | # Now convert the arguments - kludge to limit ourselves to /bin/sh
149 | i=0
150 | for arg in "$@" ; do
151 | CHECK=`echo "$arg"|egrep -c "$OURCYGPATTERN" -`
152 | CHECK2=`echo "$arg"|egrep -c "^-"` ### Determine if an option
153 |
154 | if [ $CHECK -ne 0 ] && [ $CHECK2 -eq 0 ] ; then ### Added a condition
155 | eval `echo args$i`=`cygpath --path --ignore --mixed "$arg"`
156 | else
157 | eval `echo args$i`="\"$arg\""
158 | fi
159 | i=`expr $i + 1`
160 | done
161 | case $i in
162 | 0) set -- ;;
163 | 1) set -- "$args0" ;;
164 | 2) set -- "$args0" "$args1" ;;
165 | 3) set -- "$args0" "$args1" "$args2" ;;
166 | 4) set -- "$args0" "$args1" "$args2" "$args3" ;;
167 | 5) set -- "$args0" "$args1" "$args2" "$args3" "$args4" ;;
168 | 6) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" ;;
169 | 7) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" ;;
170 | 8) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" ;;
171 | 9) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" "$args8" ;;
172 | esac
173 | fi
174 |
175 | # Escape application args
176 | save () {
177 | for i do printf %s\\n "$i" | sed "s/'/'\\\\''/g;1s/^/'/;\$s/\$/' \\\\/" ; done
178 | echo " "
179 | }
180 | APP_ARGS=`save "$@"`
181 |
182 | # Collect all arguments for the java command, following the shell quoting and substitution rules
183 | eval set -- $DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS "\"-Dorg.gradle.appname=$APP_BASE_NAME\"" -classpath "\"$CLASSPATH\"" org.gradle.wrapper.GradleWrapperMain "$APP_ARGS"
184 |
185 | exec "$JAVACMD" "$@"
186 |
--------------------------------------------------------------------------------
/app/src/main/cpp/main.cpp:
--------------------------------------------------------------------------------
1 | #include
2 | #include
3 | #include
4 | #include
5 | #include
6 | #include
7 | #include
8 | #include
9 | #include
10 | #include
11 | #include
12 | #include
13 | #include
14 | #include
15 | #include
16 | #include
17 | #include
18 | #include
19 | #include
20 | #include
21 | #include
22 |
23 | #include "logging.h"
24 |
25 | static inline int seccomp(int op, int fd, void *arg) {
26 | return syscall(__NR_seccomp, op, fd, arg);
27 | }
28 |
29 | static int sendfd(int sockfd, int fd) {
30 | int data;
31 | struct iovec iov{};
32 | struct msghdr msgh{};
33 | struct cmsghdr *cmsgp;
34 |
35 | /* Allocate a char array of suitable size to hold the ancillary data.
36 | However, since this buffer is in reality a 'struct cmsghdr', use a
37 | union to ensure that it is suitably aligned. */
38 | union {
39 | char buf[CMSG_SPACE(sizeof(int))];
40 | /* Space large enough to hold an 'int' */
41 | struct cmsghdr align;
42 | } controlMsg{};
43 |
44 | /* The 'msg_name' field can be used to specify the address of the
45 | destination socket when sending a datagram. However, we do not
46 | need to use this field because 'sockfd' is a connected socket. */
47 |
48 | msgh.msg_name = nullptr;
49 | msgh.msg_namelen = 0;
50 |
51 | /* On Linux, we must transmit at least one byte of real data in
52 | order to send ancillary data. We transmit an arbitrary integer
53 | whose value is ignored by recvfd(). */
54 |
55 | msgh.msg_iov = &iov;
56 | msgh.msg_iovlen = 1;
57 | iov.iov_base = &data;
58 | iov.iov_len = sizeof(int);
59 | data = 12345;
60 |
61 | /* Set 'msghdr' fields that describe ancillary data */
62 |
63 | msgh.msg_control = controlMsg.buf;
64 | msgh.msg_controllen = sizeof(controlMsg.buf);
65 |
66 | /* Set up ancillary data describing file descriptor to send */
67 |
68 | cmsgp = reinterpret_cast(msgh.msg_control);
69 | cmsgp->cmsg_level = SOL_SOCKET;
70 | cmsgp->cmsg_type = SCM_RIGHTS;
71 | cmsgp->cmsg_len = CMSG_LEN(sizeof(int));
72 | memcpy(CMSG_DATA(cmsgp), &fd, sizeof(int));
73 |
74 | /* Send real plus ancillary data */
75 |
76 | if (sendmsg(sockfd, &msgh, 0) == -1) return -1;
77 |
78 | return 0;
79 | }
80 |
81 | static int recvfd(int sockfd) {
82 | int data, fd;
83 | ssize_t nr;
84 | struct iovec iov{};
85 | struct msghdr msgh{};
86 |
87 | /* Allocate a char buffer for the ancillary data. See the comments
88 | in sendfd() */
89 | union {
90 | char buf[CMSG_SPACE(sizeof(int))];
91 | struct cmsghdr align;
92 | } controlMsg{};
93 | struct cmsghdr *cmsgp;
94 |
95 | /* The 'msg_name' field can be used to obtain the address of the
96 | sending socket. However, we do not need this information. */
97 |
98 | msgh.msg_name = nullptr;
99 | msgh.msg_namelen = 0;
100 |
101 | /* Specify buffer for receiving real data */
102 |
103 | msgh.msg_iov = &iov;
104 | msgh.msg_iovlen = 1;
105 | iov.iov_base = &data; /* Real data is an 'int' */
106 | iov.iov_len = sizeof(int);
107 |
108 | /* Set 'msghdr' fields that describe ancillary data */
109 |
110 | msgh.msg_control = controlMsg.buf;
111 | msgh.msg_controllen = sizeof(controlMsg.buf);
112 |
113 | /* Receive real plus ancillary data; real data is ignored */
114 |
115 | nr = recvmsg(sockfd, &msgh, 0);
116 | if (nr == -1) return -1;
117 |
118 | cmsgp = CMSG_FIRSTHDR(&msgh);
119 |
120 | /* Check the validity of the 'cmsghdr' */
121 |
122 | if (cmsgp == nullptr || cmsgp->cmsg_len != CMSG_LEN(sizeof(int)) ||
123 | cmsgp->cmsg_level != SOL_SOCKET || cmsgp->cmsg_type != SCM_RIGHTS) {
124 | errno = EINVAL;
125 | return -1;
126 | }
127 |
128 | /* Return the received file descriptor to our caller */
129 |
130 | memcpy(&fd, CMSG_DATA(cmsgp), sizeof(int));
131 | return fd;
132 | }
133 |
134 | class ProcessMemory {
135 | public:
136 | explicit ProcessMemory(pid_t pid) : pid_(pid) {
137 | }
138 |
139 | int Read(uintptr_t addr, void *buf, size_t size) const {
140 | iovec local{buf, size};
141 | iovec remote{reinterpret_cast(addr), size};
142 | return process_vm_readv(pid_, &local, 1, &remote, 1, 0);
143 | }
144 |
145 | int Write(uintptr_t addr, void *buf, size_t size) const {
146 | iovec local{buf, size};
147 | iovec remote{reinterpret_cast(addr), size};
148 | return process_vm_writev(pid_, &local, 1, &remote, 1, 0);
149 | }
150 |
151 | private:
152 | pid_t pid_;
153 | };
154 |
155 | void EnterSupervisor(int nfd, const char *target, const char *redirection) {
156 | seccomp_notif *req;
157 | seccomp_notif_resp *resp;
158 | seccomp_notif_sizes sizes{};
159 |
160 | if (seccomp(SECCOMP_GET_NOTIF_SIZES, 0, &sizes) == 0) {
161 | req = reinterpret_cast(malloc(sizes.seccomp_notif));
162 | resp = reinterpret_cast(malloc(sizes.seccomp_notif_resp));
163 | } else {
164 | LOGE("seccomp(SECCOMP_GET_NOTIF_SIZES): %m");
165 | return;
166 | }
167 |
168 | char path[PATH_MAX];
169 |
170 | for (;;) {
171 | memset(req, 0, sizes.seccomp_notif);
172 | if (ioctl(nfd, SECCOMP_IOCTL_NOTIF_RECV, req) < 0) {
173 | if (errno == EINTR) continue;
174 | LOGE("ioctl(SECCOMP_IOCTL_NOTIF_RECV): %m");
175 | goto exit;
176 | }
177 |
178 | memset(resp, 0, sizes.seccomp_notif_resp);
179 | resp->id = req->id;
180 |
181 | ProcessMemory mem(req->pid);
182 | int nread = mem.Read(req->data.args[1], path, sizeof(path) - 1);
183 |
184 | if (nread > 0) {
185 | path[nread] = '\0';
186 | LOGV("open: %s", path);
187 |
188 | if (strcmp(path, target) == 0) {
189 | int srcfd = openat(AT_FDCWD, redirection, req->data.args[2],
190 | req->data.args[3]);
191 | if (srcfd > 0) {
192 | seccomp_notif_addfd addfd = {.id = req->id,
193 | .flags = 0 /* SECCOMP_ADDFD_FLAG_SEND */,
194 | .srcfd = static_cast(srcfd)};
195 | resp->val = ioctl(nfd, SECCOMP_IOCTL_NOTIF_ADDFD, &addfd);
196 | close(srcfd);
197 | } else {
198 | resp->error = -errno;
199 | }
200 | } else {
201 | resp->flags = SECCOMP_USER_NOTIF_FLAG_CONTINUE;
202 | }
203 | } else {
204 | resp->flags = SECCOMP_USER_NOTIF_FLAG_CONTINUE;
205 | }
206 |
207 | if (ioctl(nfd, SECCOMP_IOCTL_NOTIF_SEND, resp) < 0) {
208 | LOGE("ioctl(SECCOMP_IOCTL_NOTIF_SEND): %m");
209 | }
210 | }
211 |
212 | exit:
213 | free(req);
214 | free(resp);
215 | LOGD("supervisor exit");
216 | _exit(0);
217 | }
218 |
219 | bool InitIORedirect(const char *target, const char *redirection) {
220 | utsname un{};
221 | uname(&un);
222 |
223 | char *str;
224 | int kernel_major = strtol(un.release, &str, 10);
225 | int kernel_minor = strtol(str + 1, nullptr, 10);
226 |
227 | if (KERNEL_VERSION(kernel_major, kernel_minor, 0) < KERNEL_VERSION(5, 9, 0)) {
228 | LOGE("Kernel(%s) not supported", un.release);
229 | return false;
230 | }
231 |
232 | prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0);
233 |
234 | sock_filter filter[] = {
235 | BPF_STMT(BPF_LD | BPF_W | BPF_ABS, offsetof(seccomp_data, nr)),
236 | BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, __NR_openat, 1, 0),
237 | BPF_STMT(BPF_RET | BPF_K, SECCOMP_RET_ALLOW),
238 | BPF_STMT(BPF_RET | BPF_K, SECCOMP_RET_USER_NOTIF),
239 | };
240 |
241 | sock_fprog prog{sizeof(filter) / sizeof(sock_filter), filter};
242 |
243 | int socked_fds[2];
244 | socketpair(AF_UNIX, SOCK_STREAM, 0, socked_fds);
245 |
246 | int supervisor_pid = fork();
247 | if (supervisor_pid < 0) {
248 | LOGE("Failed to fork supervisor");
249 | return false;
250 | } else if (supervisor_pid == 0) {
251 | int notify_fd = recvfd(socked_fds[1]);
252 | close(socked_fds[0]);
253 | close(socked_fds[1]);
254 | EnterSupervisor(notify_fd, strdup(target), strdup(redirection));
255 | }
256 |
257 | int notify_fd = seccomp(SECCOMP_SET_MODE_FILTER,
258 | SECCOMP_FILTER_FLAG_NEW_LISTENER, &prog);
259 | if (notify_fd < 0) {
260 | LOGE("seccomp: %m");
261 | return false;
262 | }
263 |
264 | sendfd(socked_fds[0], notify_fd);
265 | close(socked_fds[0]);
266 | close(socked_fds[1]);
267 | close(notify_fd);
268 |
269 | return true;
270 | }
271 |
272 | extern "C"
273 | JNIEXPORT jboolean JNICALL
274 | Java_io_github_eirv_simpleioredirect_MainActivity_redirect(JNIEnv *env, jclass,
275 | jstring target, jstring redirection) {
276 | auto t = env->GetStringUTFChars(target, nullptr);
277 | auto r = env->GetStringUTFChars(redirection, nullptr);
278 |
279 | LOGD("Redirect %s -> %s", t, r);
280 | bool result = InitIORedirect(t, r);
281 |
282 | env->ReleaseStringUTFChars(target, t);
283 | env->ReleaseStringUTFChars(redirection, r);
284 |
285 | return result;
286 | }
--------------------------------------------------------------------------------
/LICENSE:
--------------------------------------------------------------------------------
1 | Apache License
2 | Version 2.0, January 2004
3 | http://www.apache.org/licenses/
4 |
5 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
6 |
7 | 1. Definitions.
8 |
9 | "License" shall mean the terms and conditions for use, reproduction,
10 | and distribution as defined by Sections 1 through 9 of this document.
11 |
12 | "Licensor" shall mean the copyright owner or entity authorized by
13 | the copyright owner that is granting the License.
14 |
15 | "Legal Entity" shall mean the union of the acting entity and all
16 | other entities that control, are controlled by, or are under common
17 | control with that entity. For the purposes of this definition,
18 | "control" means (i) the power, direct or indirect, to cause the
19 | direction or management of such entity, whether by contract or
20 | otherwise, or (ii) ownership of fifty percent (50%) or more of the
21 | outstanding shares, or (iii) beneficial ownership of such entity.
22 |
23 | "You" (or "Your") shall mean an individual or Legal Entity
24 | exercising permissions granted by this License.
25 |
26 | "Source" form shall mean the preferred form for making modifications,
27 | including but not limited to software source code, documentation
28 | source, and configuration files.
29 |
30 | "Object" form shall mean any form resulting from mechanical
31 | transformation or translation of a Source form, including but
32 | not limited to compiled object code, generated documentation,
33 | and conversions to other media types.
34 |
35 | "Work" shall mean the work of authorship, whether in Source or
36 | Object form, made available under the License, as indicated by a
37 | copyright notice that is included in or attached to the work
38 | (an example is provided in the Appendix below).
39 |
40 | "Derivative Works" shall mean any work, whether in Source or Object
41 | form, that is based on (or derived from) the Work and for which the
42 | editorial revisions, annotations, elaborations, or other modifications
43 | represent, as a whole, an original work of authorship. For the purposes
44 | of this License, Derivative Works shall not include works that remain
45 | separable from, or merely link (or bind by name) to the interfaces of,
46 | the Work and Derivative Works thereof.
47 |
48 | "Contribution" shall mean any work of authorship, including
49 | the original version of the Work and any modifications or additions
50 | to that Work or Derivative Works thereof, that is intentionally
51 | submitted to Licensor for inclusion in the Work by the copyright owner
52 | or by an individual or Legal Entity authorized to submit on behalf of
53 | the copyright owner. For the purposes of this definition, "submitted"
54 | means any form of electronic, verbal, or written communication sent
55 | to the Licensor or its representatives, including but not limited to
56 | communication on electronic mailing lists, source code control systems,
57 | and issue tracking systems that are managed by, or on behalf of, the
58 | Licensor for the purpose of discussing and improving the Work, but
59 | excluding communication that is conspicuously marked or otherwise
60 | designated in writing by the copyright owner as "Not a Contribution."
61 |
62 | "Contributor" shall mean Licensor and any individual or Legal Entity
63 | on behalf of whom a Contribution has been received by Licensor and
64 | subsequently incorporated within the Work.
65 |
66 | 2. Grant of Copyright License. Subject to the terms and conditions of
67 | this License, each Contributor hereby grants to You a perpetual,
68 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
69 | copyright license to reproduce, prepare Derivative Works of,
70 | publicly display, publicly perform, sublicense, and distribute the
71 | Work and such Derivative Works in Source or Object form.
72 |
73 | 3. Grant of Patent License. Subject to the terms and conditions of
74 | this License, each Contributor hereby grants to You a perpetual,
75 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable
76 | (except as stated in this section) patent license to make, have made,
77 | use, offer to sell, sell, import, and otherwise transfer the Work,
78 | where such license applies only to those patent claims licensable
79 | by such Contributor that are necessarily infringed by their
80 | Contribution(s) alone or by combination of their Contribution(s)
81 | with the Work to which such Contribution(s) was submitted. If You
82 | institute patent litigation against any entity (including a
83 | cross-claim or counterclaim in a lawsuit) alleging that the Work
84 | or a Contribution incorporated within the Work constitutes direct
85 | or contributory patent infringement, then any patent licenses
86 | granted to You under this License for that Work shall terminate
87 | as of the date such litigation is filed.
88 |
89 | 4. Redistribution. You may reproduce and distribute copies of the
90 | Work or Derivative Works thereof in any medium, with or without
91 | modifications, and in Source or Object form, provided that You
92 | meet the following conditions:
93 |
94 | (a) You must give any other recipients of the Work or
95 | Derivative Works a copy of this License; and
96 |
97 | (b) You must cause any modified files to carry prominent notices
98 | stating that You changed the files; and
99 |
100 | (c) You must retain, in the Source form of any Derivative Works
101 | that You distribute, all copyright, patent, trademark, and
102 | attribution notices from the Source form of the Work,
103 | excluding those notices that do not pertain to any part of
104 | the Derivative Works; and
105 |
106 | (d) If the Work includes a "NOTICE" text file as part of its
107 | distribution, then any Derivative Works that You distribute must
108 | include a readable copy of the attribution notices contained
109 | within such NOTICE file, excluding those notices that do not
110 | pertain to any part of the Derivative Works, in at least one
111 | of the following places: within a NOTICE text file distributed
112 | as part of the Derivative Works; within the Source form or
113 | documentation, if provided along with the Derivative Works; or,
114 | within a display generated by the Derivative Works, if and
115 | wherever such third-party notices normally appear. The contents
116 | of the NOTICE file are for informational purposes only and
117 | do not modify the License. You may add Your own attribution
118 | notices within Derivative Works that You distribute, alongside
119 | or as an addendum to the NOTICE text from the Work, provided
120 | that such additional attribution notices cannot be construed
121 | as modifying the License.
122 |
123 | You may add Your own copyright statement to Your modifications and
124 | may provide additional or different license terms and conditions
125 | for use, reproduction, or distribution of Your modifications, or
126 | for any such Derivative Works as a whole, provided Your use,
127 | reproduction, and distribution of the Work otherwise complies with
128 | the conditions stated in this License.
129 |
130 | 5. Submission of Contributions. Unless You explicitly state otherwise,
131 | any Contribution intentionally submitted for inclusion in the Work
132 | by You to the Licensor shall be under the terms and conditions of
133 | this License, without any additional terms or conditions.
134 | Notwithstanding the above, nothing herein shall supersede or modify
135 | the terms of any separate license agreement you may have executed
136 | with Licensor regarding such Contributions.
137 |
138 | 6. Trademarks. This License does not grant permission to use the trade
139 | names, trademarks, service marks, or product names of the Licensor,
140 | except as required for reasonable and customary use in describing the
141 | origin of the Work and reproducing the content of the NOTICE file.
142 |
143 | 7. Disclaimer of Warranty. Unless required by applicable law or
144 | agreed to in writing, Licensor provides the Work (and each
145 | Contributor provides its Contributions) on an "AS IS" BASIS,
146 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
147 | implied, including, without limitation, any warranties or conditions
148 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
149 | PARTICULAR PURPOSE. You are solely responsible for determining the
150 | appropriateness of using or redistributing the Work and assume any
151 | risks associated with Your exercise of permissions under this License.
152 |
153 | 8. Limitation of Liability. In no event and under no legal theory,
154 | whether in tort (including negligence), contract, or otherwise,
155 | unless required by applicable law (such as deliberate and grossly
156 | negligent acts) or agreed to in writing, shall any Contributor be
157 | liable to You for damages, including any direct, indirect, special,
158 | incidental, or consequential damages of any character arising as a
159 | result of this License or out of the use or inability to use the
160 | Work (including but not limited to damages for loss of goodwill,
161 | work stoppage, computer failure or malfunction, or any and all
162 | other commercial damages or losses), even if such Contributor
163 | has been advised of the possibility of such damages.
164 |
165 | 9. Accepting Warranty or Additional Liability. While redistributing
166 | the Work or Derivative Works thereof, You may choose to offer,
167 | and charge a fee for, acceptance of support, warranty, indemnity,
168 | or other liability obligations and/or rights consistent with this
169 | License. However, in accepting such obligations, You may act only
170 | on Your own behalf and on Your sole responsibility, not on behalf
171 | of any other Contributor, and only if You agree to indemnify,
172 | defend, and hold each Contributor harmless for any liability
173 | incurred by, or claims asserted against, such Contributor by reason
174 | of your accepting any such warranty or additional liability.
175 |
176 | END OF TERMS AND CONDITIONS
177 |
178 | APPENDIX: How to apply the Apache License to your work.
179 |
180 | To apply the Apache License to your work, attach the following
181 | boilerplate notice, with the fields enclosed by brackets "[]"
182 | replaced with your own identifying information. (Don't include
183 | the brackets!) The text should be enclosed in the appropriate
184 | comment syntax for the file format. We also recommend that a
185 | file or class name and description of purpose be included on the
186 | same "printed page" as the copyright notice for easier
187 | identification within third-party archives.
188 |
189 | Copyright [yyyy] [name of copyright owner]
190 |
191 | Licensed under the Apache License, Version 2.0 (the "License");
192 | you may not use this file except in compliance with the License.
193 | You may obtain a copy of the License at
194 |
195 | http://www.apache.org/licenses/LICENSE-2.0
196 |
197 | Unless required by applicable law or agreed to in writing, software
198 | distributed under the License is distributed on an "AS IS" BASIS,
199 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
200 | See the License for the specific language governing permissions and
201 | limitations under the License.
202 |
--------------------------------------------------------------------------------