如何追踪.dynsym中open符号到内核openat系统调用的映射流程?
动态符号表中open符号与实际内核openat系统调用的映射追踪问题
问题现象
对包含fd = open("test_file.txt", O_RDWR | O_CREAT, 0644);代码编译出的二进制文件syscalltest进行分析时,出现以下差异:
- 静态分析:执行
readelf -s ./syscalltest查看.dynsym表,结果显示:
表明程序链接的是glibc的open@GLIBC_2.2.5 (3)open函数。 - 动态分析:执行
strace ./syscalltest追踪系统调用,实际触发的内核系统调用是:openat(AT_FDCWD, "test_file.txt", O_RDWR|O_CREAT, 0644) = 3
已做尝试与困惑
我尝试追踪open符号到openat系统调用的映射流程,但找不到转换的定义位置。已克隆glibc源码并查看sysdeps/unix/sysv/linux/open.c,但该文件中的代码被#ifndef __OFF_T_MATCHES_OFF64_T预处理宏包裹,在64位系统中会被移除,仅用于32位兼容场景。此前得到的建议多为检查libc.so.6二进制文件或上述无关的open.c,均无法解决问题。
提问
在64位Linux系统中,动态链接的open符号实现为调用openat系统调用的具体步骤或对应的源码文件是什么?
附测试代码(syscalltest.c)
#include <stdio.h> #include <stdlib.h> #include <unistd.h> #include <fcntl.h> #include <sys/types.h> void execute_syscalls() { int fd; char buffer[50]; ssize_t bytes_read; const char *message = "Hello, System Call World!\n"; // 1. open(编号2)系统调用(打开文件) fd = open("test_file.txt", O_RDWR | O_CREAT, 0644); if (fd == -1) { perror("open failed"); return; } printf("open() called. FD: %d\n", fd); // 2. write(编号1)系统调用(写入文件) ssize_t bytes_written = write(fd, message, 26); printf("write() called. Bytes written: %ld\n", bytes_written); // 将文件指针移至开头 lseek(fd, 0, SEEK_SET); // 3. read(编号0)系统调用(读取文件) bytes_read = read(fd, buffer, 26); if (bytes_read > 0) { buffer[bytes_read] = '\0'; printf("read() called. Data: %s", buffer); } // 4. close(编号3)系统调用(关闭文件) close(fd); // 5. exit(编号60)系统调用(程序退出) // exit(0); // main函数结束时会自动调用 } int main() { printf("Waiting for scanner to catch up...\n"); sleep(6); // 等待时间长于扫描器的5秒周期 execute_syscalls(); return 0; }
内容的提问来源于stack exchange,提问作者신경철
相关产品推荐
相关产品推荐

