MemSed: A New MEMory Search and EDit Tool for Linux, Inspired by Cheat Engine
github.com
github.com
It is still a work in progress, but works fairly well for day-to-day use at this point. Should run on most Linux distros and does not have any additional requirements, it's a single (nearly static) binary. Due to the nature of what it does (read/write process memory) it requires running as root, insert usual word of warning about that here.
Watch a short demo here: https://youtu.be/1IKFAe1RkZo
I'm new to HN so I apologize if I'm doing this wrong :)
I tried to do some quick research to see if there's any examples in the wild, but when I got to the point that I was searching for word salads like "launch elf as fork" I figured I was in over my head.
How it works currently is entirely based on the /proc FS, and even though processes launched by say user1 have /proc/123 and /proc/123/mem both owned by user1, and /proc/123/mem has rw permissions for owner, it returns a permission error when attempting to open the file. And rightfully so, wouldn't want any random program being able to spy and modify other programs' memory on the same permission level.
What you mention sounds like executing the code of the target program inside the same address space of the tool, which to me sounds like a nightmare (if it is even possible). I've had trouble with my own code (in other projects) getting OpenGL to work well between QtWebengine and GLFW, never managed to solve it, mixing contexts of different libraries in the same address space is already complex when you are writing the code yourself, let alone when you're mixing with arbitrary binaries made by others.
The only thing I could see working is the debugger approach, which I have no experience with (in implementation terms) and would start being out of scope of this project I think. I haven't looked at it much, but PINCE might be more akin to what you mentioned. https://github.com/korcankaraokcu/PINCE