Mono.Cecil替换方法中的参数

时间:2016-03-22 10:13:21

标签: c# mono cil mono.cecil

任务:

查找所有通话功能

public static void WriteString(int index0, string s, int index1)
{
    Console.WriteLine(s);
}
在SomeCnsl.exe中

并在函数ChangeString

中包装参数's'
public static string ChangeText(string text)
{
    return text + "new";
}

示例:

original: WriteString(0,"hello",1);
wrap:     WriteString(0,ChangeText("hello"),1);

要解决此任务,我使用Mono.Cecil。 我的解决方案看起来像这样:

private static AssemblyDefinition MainAssembly;
static void Main(string[] args)
{
    MainAssembly = AssemblyDefinition.ReadAssembly("SomeCnsl.exe");

    var changeTextMethod = typeof(SomeCnsl.Program).GetMethod("ChangeText");
    var changeTextMethodRef = MainAssembly.MainModule.Import(changeTextMethod);

    var mainMethod = MainAssembly.Modules.SelectMany(mod => ModuleDefinitionRocks.GetAllTypes(mod))
        .SelectMany(t => t.Methods)
        .Where(method => null != method.Body);

    foreach (var body in mainMethod.Select(m => m.Body))
    {
        var processor = body.GetILProcessor();
        var instructions = body.Instructions.Where(instr => instr.OpCode == OpCodes.Call && instr.ToString().Contains("WriteString")).ToList();
        foreach (var instr in instructions)
        {
            var stringEndArg = GetStringArgument(instr);
            var writeInstruction = processor.Create(OpCodes.Call, changeTextMethodRef);
            processor.InsertAfter(stringEndArg, writeInstruction);
        }
    }
    SavePatchedAssembly();
}

要查找字符串参数,我创建递归方法GetStringArgument:

public static Instruction GetStringArgument(Instruction callDrawString)
{       
    if (callDrawString.Previous.OpCode == OpCodes.Ldstr || callDrawString.Previous.OpCode == OpCodes.Ldarg_1 ||
        (callDrawString.Previous.OpCode == OpCodes.Call && callDrawString.Previous.ToString().Contains("System.String::")) ||
        (callDrawString.Previous.OpCode == OpCodes.Callvirt && callDrawString.Previous.ToString().Contains("System.String::")) ||
        (callDrawString.Previous.OpCode == OpCodes.Callvirt && callDrawString.Previous.ToString().Contains("Generic.List`1<System.String>::get_Item")) ||
        (callDrawString.Previous.OpCode == OpCodes.Callvirt && callDrawString.Previous.ToString().Contains("Generic.Dictionary`2<") && callDrawString.Previous.ToString().Contains("System.String>::get_Item")) ||
        ((callDrawString.Previous.Operand as ParameterReference) != null && (callDrawString.Previous.Operand as ParameterReference).ParameterType.FullName == typeof(string).FullName) ||
        ((callDrawString.Previous.Operand as FieldReference) != null && (callDrawString.Previous.Operand as FieldReference).FieldType.FullName == typeof(string).FullName) ||
        ((callDrawString.Previous.Operand as PropertyReference) != null && (callDrawString.Previous.Operand as PropertyReference).PropertyType.FullName == typeof(string).FullName))
    {
        return callDrawString.Previous;
    }
    else
    {
        return GetStringArgument(callDrawString.Previous);
    }
}

这是有效的。直到在WriteString的参数中放入一些字符串,如:

static Dictionary<string, int> listParam = new Dictionary<string, int> { { "first", 1 }, { "second", 2 }, { "third", 3 } };
static int index = 2;
static string indexString = "second";

static void Main(string[] args)
{
    while(true)
    {
        Thread.Sleep(1000);
        WriteString(index, indexString, listParam[indexString]);
    }        
}

ILCode WriteString call:
    IL_0022: ldsfld       int32 SomeCnsl.Program::index
    IL_0027: ldsfld       string SomeCnsl.Program::indexString
    IL_002c: ldsfld       class [mscorlib]System.Collections.Generic.Dictionary`2<string, int32> SomeCnsl.Program::listParam
    IL_0031: ldsfld       string SomeCnsl.Program::indexString
    IL_0036: callvirt     instance !1/*int32*/ class [mscorlib]System.Collections.Generic.Dictionary`2<string, int32>::get_Item(!0/*string*/)
    IL_003b: call         void SomeCnsl.Program::WriteString(string, int32, int32)
    IL_0040: nop          

所以,我的问题是:

我可以更精确地定义函数WriteText中第二个参数的所有IL命令吗?如果我能,那怎么样?

1 个答案:

答案 0 :(得分:0)

这不是你的问题的答案,但它可以帮助你以另一种方式做到这一点。 您可以使用Roslyn根据需要重写代码。

您可以通过继承CSharpSyntaxRewriting执行此操作,然后覆盖相关方法。之后,您将收到一个带有修改过的代码的新语法树,然后您可以编译它并将其保存到磁盘。 例如,看看here