Languages: English | 简体中文 | 繁體中文 | 日本語 | 한국어 | Français | Deutsch | Español | Italiano | Русский | العربية
Interposes openat by replacing its pointer in sys_call_table. Demonstrates neverc_krt_syscall_replace / neverc_krt_syscall_restore for classic syscall interception on ARM64 GKI kernels.
int neverc_krt_syscall_replace(int nr, neverc_krt_syscall_fn_t new_fn,
neverc_krt_syscall_fn_t *orig);
int neverc_krt_syscall_restore(int nr, neverc_krt_syscall_fn_t orig);cd examples/android-kernel-syscall-interpose
neverc make # debug: -g (default on the first build)
neverc make release # release: -O2 --strip
neverc make debug # switch back to debugSelect another kernel preset with, for example,
neverc make KERNEL=612 release. neverc make release selects
-O2 --strip. The Makefile records the selected KERNEL and PROFILE in
.nvk-build-flags, so later make push, make run, and bare make calls keep
using that artifact. Without the stamp, make defaults to debug. make debug
or an explicit PROFILE=... replaces the saved profile; make clean removes
the stamp, so the next build defaults to debug.
NeverC writes IDA-inspired, non-reserved release names in five classes:
functions fn_HEX, executable no-type labels code_HEX, objects obj_HEX,
other no-type labels sym_HEX, and absolute symbols abs_HEX. For ordinary
allocated definitions, HEX is a deterministic analysis EA derived from the
final SHF_ALLOC section layout (abs_HEX instead uses the absolute
st_value); it is not a hash, encryption, file offset, ELF virtual address, or
runtime kernel address. NeverC stores neither reserved sub_/loc_ forms nor
deliberately empty ordinary names.
For exact-name preservation, IDA's synthetic extern view, security boundaries,
and finalization-before-signing order, see the
release and strip policy.
neverc make runOr manually:
adb push nvk_syscall_interpose.ko /data/local/tests/
adb shell su -c 'insmod /data/local/tests/nvk_syscall_interpose.ko'
adb shell su -c 'dmesg | grep neverc_krt_syscall'On the device, cat /proc/kmsg streams the kernel ring buffer in real time — similar to DbgView on Windows. Use it when insmod fails with a vague error or you need the exact kernel rejection reason (vermagic, modversions, section size, and so on).
Terminal 1 (leave running):
adb shell
su
cat /proc/kmsgTerminal 2:
adb shell su -c 'insmod /data/local/tests/nvk_syscall_interpose.ko'New lines appear in terminal 1 as the kernel handles the load. Press Ctrl+C to stop.
Note: stock dmesg -w is missing on some Android builds; /proc/kmsg needs root but follows live kernel output reliably.
neverc make rmmod