Skip to content

Latest commit

 

History

History
87 lines (63 loc) · 3.15 KB

File metadata and controls

87 lines (63 loc) · 3.15 KB

Languages: English | 简体中文 | 繁體中文 | 日本語 | 한국어 | Français | Deutsch | Español | Italiano | Русский | العربية

← NeverC Examples

Android Kernel Syscall Interpose

Interposes openat by replacing its pointer in sys_call_table. Demonstrates neverc_krt_syscall_replace / neverc_krt_syscall_restore for classic syscall interception on ARM64 GKI kernels.

API

int neverc_krt_syscall_replace(int nr, neverc_krt_syscall_fn_t new_fn,
                               neverc_krt_syscall_fn_t *orig);
int neverc_krt_syscall_restore(int nr, neverc_krt_syscall_fn_t orig);

Build

cd examples/android-kernel-syscall-interpose
neverc make          # debug: -g (default on the first build)
neverc make release  # release: -O2 --strip
neverc make debug    # switch back to debug

Select another kernel preset with, for example, neverc make KERNEL=612 release. neverc make release selects -O2 --strip. The Makefile records the selected KERNEL and PROFILE in .nvk-build-flags, so later make push, make run, and bare make calls keep using that artifact. Without the stamp, make defaults to debug. make debug or an explicit PROFILE=... replaces the saved profile; make clean removes the stamp, so the next build defaults to debug.

NeverC writes IDA-inspired, non-reserved release names in five classes: functions fn_HEX, executable no-type labels code_HEX, objects obj_HEX, other no-type labels sym_HEX, and absolute symbols abs_HEX. For ordinary allocated definitions, HEX is a deterministic analysis EA derived from the final SHF_ALLOC section layout (abs_HEX instead uses the absolute st_value); it is not a hash, encryption, file offset, ELF virtual address, or runtime kernel address. NeverC stores neither reserved sub_/loc_ forms nor deliberately empty ordinary names.

For exact-name preservation, IDA's synthetic extern view, security boundaries, and finalization-before-signing order, see the release and strip policy.

Deploy & Run

neverc make run

Or manually:

adb push nvk_syscall_interpose.ko /data/local/tests/
adb shell su -c 'insmod /data/local/tests/nvk_syscall_interpose.ko'
adb shell su -c 'dmesg | grep neverc_krt_syscall'

Kernel log (live)

On the device, cat /proc/kmsg streams the kernel ring buffer in real time — similar to DbgView on Windows. Use it when insmod fails with a vague error or you need the exact kernel rejection reason (vermagic, modversions, section size, and so on).

Terminal 1 (leave running):

adb shell
su
cat /proc/kmsg

Terminal 2:

adb shell su -c 'insmod /data/local/tests/nvk_syscall_interpose.ko'

New lines appear in terminal 1 as the kernel handles the load. Press Ctrl+C to stop.

Note: stock dmesg -w is missing on some Android builds; /proc/kmsg needs root but follows live kernel output reliably.

Unload

neverc make rmmod