Skip to content

Commit

Permalink
discord-krisp: Fix patch for newer discord versions
Browse files Browse the repository at this point in the history
  • Loading branch information
JustTNE committed Aug 10, 2024
1 parent d756ef8 commit e389756
Show file tree
Hide file tree
Showing 2 changed files with 105 additions and 9 deletions.
21 changes: 12 additions & 9 deletions pkgs/discord-krisp/default.nix
Original file line number Diff line number Diff line change
@@ -1,19 +1,22 @@
{ prev, ... }:
let
patch-krisp = prev.writeScript "patch-krisp" ''
discord_version="${prev.discord.version}"
file="$HOME/.config/discord/$discord_version/modules/discord_krisp/discord_krisp.node"
if [ -f "$file" ]; then
addr=$("${prev.rizin}/bin/rz-find" -x '4881ec00010000' "$file" | head -n1)
"${prev.rizin}/bin/rizin" -q -w -c "s $addr + 0x30 ; wao nop" "$file"
fi
'';
# krisp-patcher.py courtesy of https://github.com/sersorrel/sys
patch-krisp = prev.writers.writePython3 "krisp-patcher" {
libraries = with prev.python3Packages; [ capstone pyelftools ];
# Ignore syntax checker error codes that affect krisp-patcher.py
flakeIgnore = [
"E501"
"F403"
"F405"
];
} (builtins.readFile ./krisp-patcher.py);
binaryName = "Discord";
node_module="\\$HOME/.config/discord/${prev.discord.version}/modules/discord_krisp/discord_krisp.node";
in
prev.discord.overrideAttrs (previousAttrs: {
postInstall = previousAttrs.postInstall + ''
wrapProgramShell $out/opt/${binaryName}/${binaryName} \
--run "${patch-krisp}"
--run "${patch-krisp} ${node_module}"
'';
passthru = removeAttrs previousAttrs.passthru [ "updateScript" ];
meta = {
Expand Down
93 changes: 93 additions & 0 deletions pkgs/discord-krisp/krisp-patcher.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
# krisp-patcher.py courtesy of https://github.com/sersorrel/sys
import sys
import shutil

from elftools.elf.elffile import ELFFile
from capstone import *
from capstone.x86 import *

if len(sys.argv) < 2:
print(f"Usage: {sys.argv[0]} [path to discord_krisp.node]")
# "Unix programs generally use 2 for command line syntax errors and 1 for all other kind of errors."
exit()

executable = sys.argv[1]

elf: ELFFile

try:
elf = ELFFile(open(executable, "rb"))
except FileNotFoundError:
print("Krisp executable could not be located. Skipping.")
exit()

symtab = elf.get_section_by_name('.symtab')

krisp_initialize_address = symtab.get_symbol_by_name("_ZN7discord15KrispInitializeEv")[0].entry.st_value
isSignedByDiscord_address = symtab.get_symbol_by_name("_ZN7discord4util17IsSignedByDiscordERKNSt4__Cr12basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEE")[0].entry.st_value

text = elf.get_section_by_name('.text')
text_start = text['sh_addr']
text_start_file = text['sh_offset']
# This seems to always be zero (.text starts at the right offset in the file). Do it just in case?
address_to_file = text_start_file - text_start

# Done with the ELF now.
# elf.close()

krisp_initialize_offset = krisp_initialize_address - address_to_file
isSignedByDiscord_offset = krisp_initialize_address - address_to_file

f = open(executable, "rb")
f.seek(krisp_initialize_offset)
krisp_initialize = f.read(64)
f.close()

# States
found_issigned_by_discord_call = False
found_issigned_by_discord_test = False
found_issigned_by_discord_je = False
found_already_patched = False
je_location = None
je_size = 0

# We are looking for a call to IsSignedByDiscord, followed by a test, followed by a je.
# Then we replace the je with nops.

md = Cs(CS_ARCH_X86, CS_MODE_64)
md.detail = True
for i in md.disasm(krisp_initialize, krisp_initialize_address):
if i.id == X86_INS_CALL:
if i.operands[0].type == X86_OP_IMM:
if i.operands[0].imm == isSignedByDiscord_address:
found_issigned_by_discord_call = True

if i.id == X86_INS_TEST:
if found_issigned_by_discord_call:
found_issigned_by_discord_test = True

if i.id == X86_INS_JE:
if found_issigned_by_discord_test:
found_issigned_by_discord_je = True
je_location = i.address
je_size = len(i.bytes)
break

if i.id == X86_INS_NOP:
if found_issigned_by_discord_test:
found_already_patched = True
break

if je_location:
print(f"Found patch location: 0x{je_location:x}")

shutil.copyfile(executable, executable + ".orig")
f = open(executable, 'rb+')
f.seek(je_location - address_to_file)
f.write(b'\x90' * je_size) # je can be larger than 2 bytes given a large enough displacement :(
f.close()
else:
if found_already_patched:
print("Couldn't find patch location - already patched.")
else:
print("Couldn't find patch location - review manually. Sorry.")

0 comments on commit e389756

Please sign in to comment.