From 51deb0996fdaf4f41f0b260dccf05d5b244269f9 Mon Sep 17 00:00:00 2001 From: DavidVentura Date: Fri, 19 Jan 2024 17:23:52 +0100 Subject: [PATCH] clean up a bit and impl pack_ClntPkt --- func_replacements.js | 389 +++++++++++++++++++++---------------------- 1 file changed, 193 insertions(+), 196 deletions(-) diff --git a/func_replacements.js b/func_replacements.js index 40eb0d7..aa3784b 100644 --- a/func_replacements.js +++ b/func_replacements.js @@ -1,114 +1,4 @@ -const pack_P2pHdr = (in_buf, out_buf) => { - // shitty memcpy - out_buf.writeByteArray(in_buf.readByteArray(4)); - return 4; -}; - -const create_Close = (buf) => { - buf.writeByteArray([0xf1, 0xf0, 0x00, 0x00]); - return 4; -}; - -const create_LanSearchExt = (buf) => { - buf.writeByteArray([0xf1, 0x32, 0x00, 0x00]); - return 4; -}; - -const create_LanSearch = (buf) => { - buf.writeByteArray([0xf1, 0x30, 0x00, 0x00]); - return 4; -}; - -const create_P2pAliveAck = (buf) => { - buf.writeByteArray([0xf1, 0xe1, 0x00, 0x00]); - return 4; -}; -const create_P2pAlive = (buf) => { - buf.writeByteArray([0xf1, 0xe0, 0x00, 0x00]); - return 4; -}; - -const create_Hello = (buf) => { - buf.writeByteArray([0xf1, 0x0, 0x0, 0x0]); - return 4; -}; - -const create_P2pRdy = (outbuf, inbuf) => { - // TODO: this is literlly the same as create_LstReq, just different command - /* - * in - 0 1 2 3 4 5 6 7 8 9 A B C D E - F 0123456789ABCDEF 00000000 42 41 54 43 00 00 00 00 00 09 4c fb 45 58 4c - 56 BATC......L.EXLV 00000010 53 00 00 00 S... - - out - 0 1 2 3 4 5 6 7 8 9 A B C D E - F 0123456789ABCDEF 00000000 f1 42 00 14 00 00 00 00 42 41 54 43 00 00 00 - 00 .B......BATC.... 00000010 00 09 4c fb 45 58 4c 56 53 00 00 00 - ..L.EXLVS... retval 0x18 - */ - const P2PRDY_SIZE = 0x14; - outbuf.writeU16(0x42f1); - outbuf.add(2).writeU16(P2PRDY_SIZE << 8); - outbuf.add(8).writeU64(inbuf.readU64()); - outbuf.add(16).writeU64(inbuf.add(8).readU64()); - outbuf.add(2 * 0xc).writeU32(inbuf.add(16).readU32()); - return P2PRDY_SIZE + 4; -}; - -const create_P2pReq = (outbuf, inbuf, m_s_addr, addr_fam) => { - const P2PREQ_SIZE = 0x24; - - /* - P2P req addr_fam 2 m_s_addr - 0 1 2 3 4 5 6 7 8 9 A B C D E F - 0123456789ABCDEF 00000000 02 00 00 00 c0 a8 01 64 00 00 00 00 00 00 00 00 - .......d........ - - at byte 4 is c0 a8 01 64 which is 192 168 1 100 - - in - 0 1 2 3 4 5 6 7 8 9 A B C D E F - 0123456789ABCDEF 00000000 42 41 54 43 00 00 00 00 00 09 4c fb 45 58 4c 56 - BATC......L.EXLV - - mine - 0 1 2 3 4 5 6 7 8 9 A B C D E F - 0123456789ABCDEF 00000000 f1 20 00 24 00 00 00 00 42 41 54 43 00 00 00 00 - . .$....BATC.... 00000010 00 09 4c fb 45 58 4c 56 53 00 00 00 00 00 00 00 - ..L.EXLVS....... 00000020 00 00 00 00 00 00 00 00 ........ - - original - 0 1 2 3 4 5 6 7 8 9 A B C D E F - 0123456789ABCDEF 00000000 f1 20 00 24 00 00 00 00 42 41 54 43 00 00 00 00 - . .$....BATC.... 00000010 00 09 4c fb 45 58 4c 56 53 00 00 00 00 02 00 00 - ..L.EXLVS....... 00000020 64 01 a8 c0 00 00 00 00 d....... - - */ - - // let new_outbuf = Memory.alloc(0x2c); - outbuf.writeU16(0x20f1); - outbuf.add(2).writeU16(P2PREQ_SIZE << 8); - outbuf.add(8).writeU64(inbuf.readU64()); - outbuf.add(16).writeU64(inbuf.add(8).readU64()); - outbuf.add(2 * 0xc).writeU32(inbuf.add(16).readU32()); - - outbuf.add(2 * 0xe).writeByteArray(swap_endianness_u16(m_s_addr)); - outbuf.add(2 * 0xf).writeByteArray(swap_endianness_u16(m_s_addr.add(2))); - - outbuf.add(2 * 0x12).writeU64(0); - outbuf.add(2 * 0x10).writeByteArray(swap_endianness_u32(m_s_addr.add(4))); // ip address - - // og_func(outbuf, inbuf, m_s_addr, addr_fam); - // console.log("in"); - // console.log(inbuf.readByteArray(0x10)); - // console.log("mine"); - // console.log(new_outbuf.readByteArray(0x28)); - // console.log("original"); - // console.log(outbuf.readByteArray(0x28)); - - return P2PREQ_SIZE + 4; -}; +const u16_swap = (x) => ((x & 0xff00) >> 8) | ((x & 0x00ff) << 8); const swap_endianness_u16 = (ptr) => { const bytes = ptr.readU16(); @@ -125,6 +15,121 @@ const swap_endianness_u32 = (ptr) => { ]; return swapped; }; + +const compare_buf = (a, b, len) => { + console.log(`comparin len ${len}`); + const ba = new Uint8Array(a.readByteArray(len)); + const bb = new Uint8Array(b.readByteArray(len)); + + let deltas = new Uint8Array(len); + let bad = false; + for (let i = 0; i < len; i++) { + if (ba[i] == bb[i]) { + deltas[i] = 0; + } else { + deltas[i] = 0xff; + bad = true; + } + } + if (bad) { + console.log("deltas"); + console.log(deltas.buffer); + console.log("buf a"); + console.log(ba.buffer); + console.log("buf b"); + console.log(bb.buffer); + console.log("####"); + } +}; + +const Commands = { + Close: 0xf1f0, + LanSearchExt: 0xf132, + LanSearch: 0xf130, + P2PAlive: 0xf1e0, + P2PAliveAck: 0xf1e1, + Hello: 0xf100, + P2pRdy: 0xf142, + P2pReq: 0xf120, + LstReq: 0xf167, + DrwAck: 0xf1d1, + Drw: 0xf1d0, +}; + +const CommandsByValue = Object.keys(Commands).reduce((acc, cur) => { + acc[Commands[cur]] = cur; + return acc; +}, {}); + +const pack_P2pHdr = (in_buf, out_buf) => { + // shitty memcpy + out_buf.writeByteArray(in_buf.readByteArray(4)); + return 4; +}; + +const writeCommand2 = (command, buf) => { + buf.writeByteArray([(command & 0xff00) >> 8, command & 0xff]); +}; +const writeCommand4 = (command, buf) => { + buf.writeByteArray([(command & 0xff00) >> 8, command & 0xff, 0x00, 0x00]); +}; +const create_Close = (buf) => { + writeCommand4(Commands.Close, buf); + return 4; +}; + +const create_LanSearchExt = (buf) => { + writeCommand4(Commands.LanSearchExt, buf); + return 4; +}; + +const create_LanSearch = (buf) => { + writeCommand4(Commands.LanSearch, buf); + return 4; +}; + +const create_P2pAliveAck = (buf) => { + writeCommand4(Commands.P2PAliveAck, buf); + return 4; +}; +const create_P2pAlive = (buf) => { + writeCommand4(Commands.P2PAlive, buf); + return 4; +}; + +const create_Hello = (buf) => { + writeCommand4(Commands.Hello, buf); + return 4; +}; + +const create_P2pRdy = (outbuf, inbuf) => { + // TODO: this is literlly the same as create_LstReq, just different command + const P2PRDY_SIZE = 0x14; + writeCommand2(Commands.P2pRdy, outbuf); + outbuf.add(2).writeU16(P2PRDY_SIZE << 8); + outbuf.add(8).writeU64(inbuf.readU64()); + outbuf.add(16).writeU64(inbuf.add(8).readU64()); + outbuf.add(2 * 0xc).writeU32(inbuf.add(16).readU32()); + return P2PRDY_SIZE + 4; +}; + +const create_P2pReq = (outbuf, inbuf, m_s_addr, addr_fam) => { + const P2PREQ_SIZE = 0x24; + writeCommand2(Commands.P2pReq, outbuf); + outbuf.add(2).writeU16(P2PREQ_SIZE << 8); + outbuf.add(8).writeU64(inbuf.readU64()); + outbuf.add(16).writeU64(inbuf.add(8).readU64()); + outbuf.add(2 * 0xc).writeU32(inbuf.add(16).readU32()); + + outbuf.add(2 * 0xe).writeByteArray(swap_endianness_u16(m_s_addr)); + outbuf.add(2 * 0xf).writeByteArray(swap_endianness_u16(m_s_addr.add(2))); + + outbuf.add(2 * 0x12).writeU64(0); + outbuf.add(2 * 0x10).writeByteArray(swap_endianness_u32(m_s_addr.add(4))); // ip address + + return P2PREQ_SIZE + 4; +}; + const create_LstReq = (outbuf, inbuf) => { /* original in @@ -140,58 +145,35 @@ const create_LstReq = (outbuf, inbuf) => { */ const LISTREQ_SIZE = 0x14; - outbuf.writeU16(0x67f1); + writeCommand2(Commands.LstReq, outbuf); outbuf.add(2).writeU16(LISTREQ_SIZE << 8); // 4 * sizeof(short) outbuf.add(8).writeU64(inbuf.readU64()); // 8 * sizeof(short) outbuf.add(16).writeU64(inbuf.add(8).readU64()); - // 8 * sizeof(short) + // 0xc * sizeof(short) outbuf.add(2 * 0xc).writeU32(inbuf.add(0x10).readU32()); - /* - let new_outbuf = Memory.alloc(0x1c); - og_func(new_outbuf, inbuf); - console.log("mine"); - console.log(outbuf.readByteArray(0x1c)); - console.log("original"); - console.log(new_outbuf.readByteArray(0x1c)); - */ - return LISTREQ_SIZE + 4; // this is actually wrong (and unused) in the code -- it is 0x1c }; const dbg_create_DrwAck = (og_func) => { - const create_DrwAck = (outbuf, idk_param2, idk_param3, half_len, inbuf) => { - console.log(`2: ${idk_param2} 3: ${idk_param3}, halflen: ${half_len}`); - console.log("inbuf"); + const create_DrwAck = (outbuf, idk_param2, channel, half_len, inbuf) => { + // console.log(`2: ${idk_param2} 3: ${channel}, halflen: ${half_len}`); + // param2 is 0xd1 if "unlocked" and 0xd2 if "locked"? const copyLen = half_len * 2; - //console.log(inbuf.readByteArray(copyLen)); - - //console.log("outbuf BEFORE"); - //console.log(outbuf.readByteArray(copyLen + 12)); - - //const retval = og_func(outbuf, idk_param2, idk_param3, half_len, inbuf); - //console.log("outbuf"); - //console.log(outbuf.readByteArray(copyLen + 12)); - - //const new_outbuf = Memory.alloc(copyLen + 12); - outbuf.writeU16(0xd1f1); + writeCommand2(Commands.DrwAck, outbuf); outbuf.add(2).writeU16(u16_swap(copyLen + 4)); outbuf.add(8).writeU8(idk_param2); - outbuf.add(9).writeU8(idk_param3); + outbuf.add(9).writeU8(channel); outbuf.add(10).writeU16(u16_swap(half_len)); outbuf.add(12).writeByteArray(inbuf.readByteArray(copyLen)); - - //console.log("my outbuf"); - //console.log(new_outbuf.readByteArray(copyLen + 12)); return half_len * 2 + 8; // this is wrong in the code as well - should be +12 }; return create_DrwAck; }; -const u16_swap = (x) => ((x & 0xff00) >> 8) | ((x & 0x00ff) << 8); const dbg_create_Drw = (og_func) => { const create_Drw = ( outbuf, @@ -203,27 +185,28 @@ const dbg_create_Drw = (og_func) => { ) => { /// idk_param4 goes up by 0x100 per call - //console.log( - // `2: ${idk_param2.toString(16)} 3: ${idk_param3.toString(16)} 4: ${idk_param4.toString(16)} copylen: ${copy_len}`, + // console.log( + // `2: ${idk_param2.toString(16)} 3: ${idk_param3.toString(16)} 4: + // ${idk_param4.toString(16)} copylen: ${copy_len}`, //); /* * 2: ffffffd1 3: 0 4: 3100 copylen: 44 - In buffer - 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF - 00000000 11 0a 31 10 24 00 00 00 75 39 4c 74 01 01 01 01 ..1.$...u9Lt.... - 00000010 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ................ - 00000020 01 01 01 01 01 01 01 01 01 01 01 00 ............ - OG retval 52 - OG out buffer - 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF - 00000000 f1 d0 00 30 00 00 00 00 d1 00 00 31 11 0a 31 10 ...0.......1..1. - 00000010 24 00 00 00 75 39 4c 74 01 01 01 01 01 01 01 01 $...u9Lt........ - 00000020 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 ................ - 00000030 01 01 01 01 - */ + In buffer + 0 1 2 3 4 5 6 7 8 9 A B C D E F + 0123456789ABCDEF 00000000 11 0a 31 10 24 00 00 00 75 39 4c 74 01 01 01 01 + ..1.$...u9Lt.... 00000010 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 + ................ 00000020 01 01 01 01 01 01 01 01 01 01 01 00 ............ + OG retval 52 + OG out buffer + 0 1 2 3 4 5 6 7 8 9 A B C D E F + 0123456789ABCDEF 00000000 f1 d0 00 30 00 00 00 00 d1 00 00 31 11 0a 31 10 + ...0.......1..1. 00000010 24 00 00 00 75 39 4c 74 01 01 01 01 01 01 01 01 + $...u9Lt........ 00000020 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 01 + ................ 00000030 01 01 01 01 + */ const copy_len_swapped = u16_swap(copy_len + 4); - outbuf.writeU16(0xd0f1); + writeCommand2(Commands.Drw, outbuf); outbuf.add(2).writeU16(copy_len_swapped); outbuf.add(8).writeU8(0xd1); outbuf.add(10).writeU16(idk_param4); @@ -233,17 +216,58 @@ const dbg_create_Drw = (og_func) => { }; return create_Drw; }; -const debugInOut = (inbuf, outbuf, og_func, insize, outsize) => { - console.log("In buffer"); - console.log(inbuf.readByteArray(insize)); +const dbg_pack_ClntPkt = (og_func) => { + const pack_ClntPkt = (addr_fam, inbuf, outbuf) => { + const cmd = u16_swap(inbuf.readU16()); + console.log( + `pack_ClntPkt: cmd 0x${cmd.toString(16)} = ${ + CommandsByValue[cmd] + }; fam ${addr_fam}; inbuf =>`, + ); + //console.log(inbuf.readByteArray(16)); - let og_outbuf = Memory.alloc(outsize); - console.log("OG retval", og_func(inbuf, og_outbuf)); - console.log("OG out buffer"); - console.log(og_outbuf.readByteArray(outsize)); + //const ret = og_func(addr_fam, inbuf, outbuf); - console.log("My out buffer"); - console.log(outbuf.readByteArray(outsize)); + // const new_outbuf = Memory.alloc(ret); + const hdrLen = pack_P2pHdr(inbuf, outbuf); + const packFn = { + [Commands.LanSearch]: () => hdrLen, + [Commands.LanSearchExt]: () => hdrLen, + [Commands.Close]: () => hdrLen, + [Commands.Hello]: () => hdrLen, + [Commands.P2pReq]: () => + hdrLen + pack_P2pReq4(inbuf.add(8), outbuf.add(hdrLen)), + [Commands.LstReq]: () => + hdrLen + pack_P2pId(inbuf.add(8), outbuf.add(hdrLen)), + [Commands.DrwAck]: () => { + const pkt_size = u16_swap(inbuf.add(2).readU16()); + return hdrLen + pack_DrwAck(inbuf.add(8), pkt_size, outbuf.add(hdrLen)); + }, + [Commands.Drw]: () => { + const pkt_size = u16_swap(inbuf.add(2).readU16()); + return hdrLen + pack_Drw(inbuf.add(8), pkt_size, outbuf.add(hdrLen)); + }, + }; + /* + // No PackClnt? + P2PAlive: 0xf1e0, + P2PAliveAck: 0xf1e1, + + P2pRdy: 0xf142, // idk?? + */ + + const fn = packFn[cmd]; + if (fn == undefined) { + console.error(`IDK how to handle ${cmd}`); + } else { + const my_ret = fn(); + //compare_buf(outbuf, new_outbuf, ret); + //console.log(new_outbuf.readByteArray(ret)); + return my_ret; + } + return -1; + }; + return pack_ClntPkt; }; const pack_Drw = (inbuf, m_pkt_size, outbuf) => { @@ -259,7 +283,7 @@ const pack_Drw = (inbuf, m_pkt_size, outbuf) => { return m_pkt_size; }; -// FIXME literally identical +// FIXME literally identical to pack_Drw const pack_DrwAck = (inbuf, m_pkt_size, outbuf) => { // a shitty memcpy? const DRW_ACK_HDR_SIZE = 0x4; @@ -275,7 +299,6 @@ const pack_DrwAck = (inbuf, m_pkt_size, outbuf) => { }; const pack_P2pId = (inbuf, outbuf) => { - // TODO not verified correct but works ? outbuf.writeU64(inbuf.readU64()); outbuf.add(8).writeU32(inbuf.add(8).readU32()); outbuf.add(0xc).writeU64(inbuf.add(0xc).readU32()); @@ -285,26 +308,10 @@ const pack_P2pId = (inbuf, outbuf) => { const pack_P2pReq4 = (inbuf, outbuf) => { // a shitty memcpy? - /* - In buffer - 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF - 00000000 42 41 54 43 00 00 00 00 00 09 4c fb 45 58 4c 56 BATC......L.EXLV - 00000010 53 00 00 00 00 02 00 00 64 01 a8 c0 00 00 00 00 S.......d....... - OG retval 36 - OG out buffer - 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF - 00000000 42 41 54 43 00 00 00 00 00 09 4c fb 45 58 4c 56 BATC......L.EXLV - 00000010 53 00 00 00 00 02 00 00 64 01 a8 c0 00 00 00 00 S.......d....... - My out buffer - 0 1 2 3 4 5 6 7 8 9 A B C D E F 0123456789ABCDEF - 00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ - 00000010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ - - */ Memory.copy(outbuf, inbuf, 0x24); - //debugInOut(inbuf, outbuf, og_func, 0x20, 0x20); // probably 0x18 return 0x24; }; + export const replace_func = (stub, ret, args) => { const name_in_elf = stub.name.replace("dbg_", ""); // UGH FIXME const symbol_addr = DebugSymbol.fromName(name_in_elf).address; @@ -342,17 +349,6 @@ export const replace_func = (stub, ret, args) => { * pack_ClntPkt * UdpPktSend */ - -/* pack_ClntPkt = - * pack_P2pHdr - * pack_ - * RSLgnEx, RlyReq4, RlyPortAck, RlyPortExAck, RlyReqEx, Drw, HelloToAck, - * DrwAck, DevLgn4, LanSearchExtAck, P2pReq4, RSLGn - */ -/* - hard - [NOT REPLACED] pack_ClntPkt - */ export const replaceFunctions = () => { const replacements = [ [create_P2pAlive, "uint8", ["pointer"]], @@ -379,6 +375,7 @@ export const replaceFunctions = () => { [pack_DrwAck, "uint8", ["pointer", "uint16", "pointer"]], [pack_P2pId, "uint32", ["pointer", "pointer"]], [pack_P2pReq4, "uint64", ["pointer", "pointer"]], + [dbg_pack_ClntPkt, "uint32", ["uint32", "pointer", "pointer"]], ]; replacements.forEach((x) => replace_func(...x));