You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何追踪.dynsym中open符号到内核openat系统调用的映射流程?

动态符号表中open符号与实际内核openat系统调用的映射追踪问题

问题现象

对包含fd = open("test_file.txt", O_RDWR | O_CREAT, 0644);代码编译出的二进制文件syscalltest进行分析时,出现以下差异:

  • 静态分析:执行readelf -s ./syscalltest查看.dynsym表,结果显示:
    open@GLIBC_2.2.5 (3)
    
    表明程序链接的是glibc的open函数。
  • 动态分析:执行strace ./syscalltest追踪系统调用,实际触发的内核系统调用是:
    openat(AT_FDCWD, "test_file.txt", O_RDWR|O_CREAT, 0644) = 3
    

已做尝试与困惑

我尝试追踪open符号到openat系统调用的映射流程,但找不到转换的定义位置。已克隆glibc源码并查看sysdeps/unix/sysv/linux/open.c,但该文件中的代码被#ifndef __OFF_T_MATCHES_OFF64_T预处理宏包裹,在64位系统中会被移除,仅用于32位兼容场景。此前得到的建议多为检查libc.so.6二进制文件或上述无关的open.c,均无法解决问题。

提问

在64位Linux系统中,动态链接的open符号实现为调用openat系统调用的具体步骤或对应的源码文件是什么?

附测试代码(syscalltest.c)

#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include <fcntl.h>
#include <sys/types.h>

void execute_syscalls() {
    int fd;
    char buffer[50];
    ssize_t bytes_read;
    const char *message = "Hello, System Call World!\n";

    // 1. open(编号2)系统调用(打开文件)
    fd = open("test_file.txt", O_RDWR | O_CREAT, 0644);
    if (fd == -1) {
        perror("open failed");
        return;
    }
    printf("open() called. FD: %d\n", fd);

    // 2. write(编号1)系统调用(写入文件)
    ssize_t bytes_written = write(fd, message, 26);
    printf("write() called. Bytes written: %ld\n", bytes_written);

    // 将文件指针移至开头
    lseek(fd, 0, SEEK_SET);

    // 3. read(编号0)系统调用(读取文件)
    bytes_read = read(fd, buffer, 26);
    if (bytes_read > 0) {
        buffer[bytes_read] = '\0';
        printf("read() called. Data: %s", buffer);
    }

    // 4. close(编号3)系统调用(关闭文件)
    close(fd);

    // 5. exit(编号60)系统调用(程序退出)
    // exit(0); // main函数结束时会自动调用
}

int main() {
    printf("Waiting for scanner to catch up...\n");
    sleep(6); // 等待时间长于扫描器的5秒周期
    execute_syscalls();
    return 0; 
}

内容的提问来源于stack exchange,提问作者신경철

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 01:20:10