You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Golang中与.NET Marshal.Copy方法等效的内存复制方式是什么?

How to Replicate [Marshal]::Copy in Go for Memory Patching

Hey there, great job getting VirtualProtect working to adjust memory permissions! Let's fix that missing memory copy part to match the PowerShell behavior you're aiming for.

First, let's clear up a misstep in your current code: when you're shifting the patch bytes into a uintptr and converting that to a pointer, you're creating a single integer from those bytes—not pointing to the actual byte data in your slice. That's not what we need. Instead, we want to directly access the underlying data of your patch slice and copy it to the target memory address.

The Right Way to Copy Memory in Go

Go's unsafe package gives us the tools to manipulate memory directly. You can choose between a clear manual byte-by-byte copy, or the more efficient runtime.memmove (similar to C's memmove under the hood).

Option 1: Manual Byte-by-Byte Copy

This approach is straightforward and makes every step explicit:

package main

import (
    "fmt"
    "unsafe"
)

// Assume your VirtualProtect implementation is here
func virtualProt(lpAddress unsafe.Pointer, dwSize uintptr, flNewProtect uint32, lpflOldProtect unsafe.Pointer) bool {
    // Your existing implementation logic
    return true
}

func main() {
    var patch = []byte{
        0x31, 0xC0, // xor rax, rax
        0xC3,       // ret
    }

    // Replace this with your actual target memory address
    var patchAddr uintptr = 0x1234567890ABCDEF
    var oldfperms uint32

    // Set target memory region to PAGE_EXECUTE_READWRITE (0x40)
    success := virtualProt(unsafe.Pointer(patchAddr), uintptr(len(patch)), 0x40, unsafe.Pointer(&oldfperms))
    if !success {
        fmt.Println("Failed to set memory permissions")
        return
    }

    // Copy each byte from patch to the target address
    targetPtr := unsafe.Pointer(patchAddr)
    for i, b := range patch {
        // Calculate the address of the i-th byte in the target region
        bytePtr := (*byte)(unsafe.Add(targetPtr, i))
        *bytePtr = b
    }

    // Restore original memory permissions
    success = virtualProt(unsafe.Pointer(patchAddr), uintptr(len(patch)), oldfperms, unsafe.Pointer(&oldfperms))
    if !success {
        fmt.Println("Failed to restore memory permissions")
    }
}

Option 2: Use runtime.memmove (Optimized for Bulk Copies)

For larger patches, runtime.memmove is more efficient since it's designed for bulk memory operations:

import "runtime"

// ... (keep your setup and permission code)

// Copy the entire patch slice to the target memory
runtime.memmove(
    unsafe.Pointer(patchAddr),   // Destination memory address
    unsafe.Pointer(&patch[0]),   // Start of the source patch data
    uintptr(len(patch)),         // Number of bytes to copy
)

// ... (restore original permissions)

Key Tips:

  • Ensure patchAddr is a valid, accessible memory address—unsafe operations skip Go's safety checks, so you need to confirm the address is correct.
  • Double-check permission flags: 0x40 is PAGE_EXECUTE_READWRITE; if you only need read-write access (no execute), use 0x04 (PAGE_READWRITE).
  • Always restore original memory permissions after patching to avoid unexpected behavior in the target process.

内容的提问来源于stack exchange,提问作者jplain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 18:38:13