
时间:2022-02-20 21:17:22


I'm porting a C application into C#. The C app calls lots of functions from a 3rd-party DLL, so I wrote P/Invoke wrappers for these functions in C#. Some of these C functions allocate data which I have to use in the C# app, so I used IntPtr's, Marshal.PtrToStructure and Marshal.Copy to copy the native data (arrays and structures) into managed variables.

我正在将一个C应用程序移植到c#中。C应用程序从第三方DLL调用许多函数,所以我用c#为这些函数编写了P/Invoke包装器。其中一些C函数分配了我在c#应用中使用的数据,所以我使用了IntPtr, Marshal。PtrToStructure和元帅。复制以将本机数据(数组和结构)复制到托管变量中。

Unfortunately, the C# app proved to be much slower than the C version. A quick performance analysis showed that the above mentioned marshaling-based data copying is the bottleneck. I'm considering to speed up the C# code by rewriting it to use pointers instead. Since I don't have experience with unsafe code and pointers in C#, I need expert opinion regarding the following questions:


  1. What are the drawbacks of using unsafe code and pointers instead of IntPtr and Marshaling? For example, is it more unsafe (pun intended) in any way? People seem to prefer marshaling, but I don't know why.
  2. 使用不安全的代码和指针而不是IntPtr和封送的缺点是什么?例如,它是否更不安全(双关语)?人们似乎更喜欢编组,但我不知道为什么。
  3. Is using pointers for P/Invoking really faster than using marshaling? How much speedup can be expected approximately? I couldn't find any benchmark tests for this.
  4. 对P/调用使用指针真的比使用封送更快吗?预期的加速率大约是多少?我找不到任何基准测试。

Example code

To make the situation more clear, I hacked together a small example code (the real code is much more complex). I hope this example shows what I mean when I'm talking about "unsafe code and pointers" vs. "IntPtr and Marshal".


C library (DLL)



#ifndef _MY_LIB_H_
#define _MY_LIB_H_

struct MyData 
  int length;
  unsigned char* bytes;

__declspec(dllexport) void CreateMyData(struct MyData** myData, int length);
__declspec(dllexport) void DestroyMyData(struct MyData* myData);

#endif // _MY_LIB_H_



#include <stdlib.h>
#include "MyLib.h"

void CreateMyData(struct MyData** myData, int length)
  int i;

  *myData = (struct MyData*)malloc(sizeof(struct MyData));
  if (*myData != NULL)
    (*myData)->length = length;
    (*myData)->bytes = (unsigned char*)malloc(length * sizeof(char));
    if ((*myData)->bytes != NULL)
      for (i = 0; i < length; ++i)
        (*myData)->bytes[i] = (unsigned char)(i % 256);

void DestroyMyData(struct MyData* myData)
  if (myData != NULL)
    if (myData->bytes != NULL)

C application



#include <stdio.h>
#include "MyLib.h"

void main()
  struct MyData* myData = NULL;
  int length = 100 * 1024 * 1024;

  printf("=== C++ test ===\n");
  CreateMyData(&myData, length);
  if (myData != NULL)
    printf("Length: %d\n", myData->length);
    if (myData->bytes != NULL)
      printf("First: %d, last: %d\n", myData->bytes[0], myData->bytes[myData->length - 1]);
      printf("myData->bytes is NULL");
    printf("myData is NULL\n");

C# application, which uses IntPtr and Marshal



using System;
using System.Runtime.InteropServices;

public static class Program
  private struct MyData
    public int Length;
    public IntPtr Bytes;

  private static extern void CreateMyData(out IntPtr myData, int length);

  private static extern void DestroyMyData(IntPtr myData);

  public static void Main()
    Console.WriteLine("=== C# test, using IntPtr and Marshal ===");
    int length = 100 * 1024 * 1024;
    IntPtr myData1;
    CreateMyData(out myData1, length);
    if (myData1 != IntPtr.Zero)
      MyData myData2 = (MyData)Marshal.PtrToStructure(myData1, typeof(MyData));
      Console.WriteLine("Length: {0}", myData2.Length);
      if (myData2.Bytes != IntPtr.Zero)
        byte[] bytes = new byte[myData2.Length];
        Marshal.Copy(myData2.Bytes, bytes, 0, myData2.Length);
        Console.WriteLine("First: {0}, last: {1}", bytes[0], bytes[myData2.Length - 1]);
        Console.WriteLine("myData.Bytes is IntPtr.Zero");
      Console.WriteLine("myData is IntPtr.Zero");

C# application, which uses unsafe code and pointers



using System;
using System.Runtime.InteropServices;

public static class Program
  private unsafe struct MyData
    public int Length;
    public byte* Bytes;

  private unsafe static extern void CreateMyData(out MyData* myData, int length);

  private unsafe static extern void DestroyMyData(MyData* myData);

  public unsafe static void Main()
    Console.WriteLine("=== C# test, using unsafe code ===");
    int length = 100 * 1024 * 1024;
    MyData* myData;
    CreateMyData(out myData, length);
    if (myData != null)
      Console.WriteLine("Length: {0}", myData->Length);
      if (myData->Bytes != null)
        Console.WriteLine("First: {0}, last: {1}", myData->Bytes[0], myData->Bytes[myData->Length - 1]);
        Console.WriteLine("myData.Bytes is null");
      Console.WriteLine("myData is null");

6 个解决方案



It's a little old thread, but I recently made excessive performance tests with marshaling in C#. I need to unmarshal lots of data from a serial port over many days. It was important to me to have no memory leaks (because the smallest leak will get significant after a couple of million calls) and I also made a lot of statistical performance (time used) tests with very big structs (>10kb) just for the sake of it (an no, you should never have a 10kb struct :-) )

这是一个有点旧的线程,但是我最近在c#中进行了过多的性能测试。我需要在许多天内从一个串行端口中释放大量数据。我没有内存泄漏很重要(因为最小的泄漏后将得到显著的几百万调用),我也做了许多的统计性能(时间)使用测试非常大的结构(> 10 kb)只是为了它(不,你不应该有一个10 kb结构:-))

I tested the following three unmarshalling strategies (I also tested the marshalling). In nearly all cases the first one (MarshalMatters) outperformed the other two. Marshal.Copy was always slowest by far, the other two were mostly very close together in the race.


Using unsafe code can pose a significant security risk.




public class MarshalMatters
    public static T ReadUsingMarshalUnsafe<T>(byte[] data) where T : struct
            fixed (byte* p = &data[0])
                return (T)Marshal.PtrToStructure(new IntPtr(p), typeof(T));

    public unsafe static byte[] WriteUsingMarshalUnsafe<selectedT>(selectedT structure) where selectedT : struct
        byte[] byteArray = new byte[Marshal.SizeOf(structure)];
        fixed (byte* byteArrayPtr = byteArray)
            Marshal.StructureToPtr(structure, (IntPtr)byteArrayPtr, true);
        return byteArray;



public class Adam_Robinson

    private static T BytesToStruct<T>(byte[] rawData) where T : struct
        T result = default(T);
        GCHandle handle = GCHandle.Alloc(rawData, GCHandleType.Pinned);
            IntPtr rawDataPtr = handle.AddrOfPinnedObject();
            result = (T)Marshal.PtrToStructure(rawDataPtr, typeof(T));
        return result;

    /// <summary>
    /// no Copy. no unsafe. Gets a GCHandle to the memory via Alloc
    /// </summary>
    /// <typeparam name="selectedT"></typeparam>
    /// <param name="structure"></param>
    /// <returns></returns>
    public static byte[] StructToBytes<T>(T structure) where T : struct
        int size = Marshal.SizeOf(structure);
        byte[] rawData = new byte[size];
        GCHandle handle = GCHandle.Alloc(rawData, GCHandleType.Pinned);
            IntPtr rawDataPtr = handle.AddrOfPinnedObject();
            Marshal.StructureToPtr(structure, rawDataPtr, false);
        return rawData;



/// <summary>
/// http://*.com/questions/2623761/marshal-ptrtostructure-and-back-again-and-generic-solution-for-endianness-swap
/// </summary>
public class DanB
    /// <summary>
    /// uses Marshal.Copy! Not run in unsafe. Uses AllocHGlobal to get new memory and copies.
    /// </summary>
    public static byte[] GetBytes<T>(T structure) where T : struct
        var size = Marshal.SizeOf(structure); //or Marshal.SizeOf<selectedT>(); in .net 4.5.1
        byte[] rawData = new byte[size];
        IntPtr ptr = Marshal.AllocHGlobal(size);

        Marshal.StructureToPtr(structure, ptr, true);
        Marshal.Copy(ptr, rawData, 0, size);
        return rawData;

    public static T FromBytes<T>(byte[] bytes) where T : struct
        var structure = new T();
        int size = Marshal.SizeOf(structure);  //or Marshal.SizeOf<selectedT>(); in .net 4.5.1
        IntPtr ptr = Marshal.AllocHGlobal(size);

        Marshal.Copy(bytes, 0, ptr, size);

        structure = (T)Marshal.PtrToStructure(ptr, structure.GetType());

        return structure;



Considerations in Interoperability explains why and when Marshaling is required and at what cost. Quote:


  1. Marshaling occurs when a caller and a callee cannot operate on the same instance of data.
  2. 当调用者和被调用者不能对相同的数据实例进行操作时,就会发生封送。
  3. repeated marshaling can negatively affect the performance of your application.
  4. 重复封送会对应用程序的性能产生负面影响。

Therefore, answering your question if


... using pointers for P/Invoking really faster than using marshaling ...


first ask yourself a question if the managed code is able to operate on the unmanaged method return value instance. If the answer is yes then Marshaling and the associated performance cost is not required. The approximate time saving would be O(n) function where n of the size of the marshalled instance. In addition, not keeping both managed and unmanaged blocks of data in memory at the same time for the duration of the method (in "IntPtr and Marshal" example) eliminates additional overhead and the memory pressure.


What are the drawbacks of using unsafe code and pointers ...


The drawback is the risk associated with accessing the memory directly through pointers. There is nothing less safe to it than using pointers in C or C++. Use it if needed and makes sense. More details are here.


There is one "safety" concern with the presented examples: releasing of allocated unmanaged memory is not guaranteed after the managed code errors. The best practice is to


CreateMyData(out myData1, length);

if(myData1!=IntPtr.Zero) {
    try {
        // -> use myData1
        // <-
    finally {



Two answers,


  1. Unsafe code means it is not managed by the CLR. You need to take care of resources it uses.


  2. You cannot scale the performance because there are so many factors effecting it. But definitely using pointers will be much faster.




Just wanted to add my experience to this old thread: We used Marshaling in sound recording software - we received real time sound data from mixer into native buffers and marshaled it to byte[]. That was real performance killer. We were forced to move to unsafe structs as the only way to complete the task.


In case you don't have large native structs and don't mind that all data is filled twice - Marshaling is more elegant and much, much safer approach.




Because you stated that your code calls to 3rd-party DLL, I think the unsafe code is more suited in you scenario. You ran into a particular situation of wapping variable-length array in a struct; I know, I know this kind of usage occurs all the time, but it's not always the case after all. You might want to have a look of some questions about this, for example:


How do I marshal a struct that contains a variable-sized array to C#?

如何将包含可变大小数组的结构体编组到c# ?

If .. I say if .. you can modify the third party libraries a bit for this particular case, then you might consider the following usage:

如果. .我说如果. .对于这种特殊情况,您可以稍微修改一下第三方库,然后您可以考虑以下用法:

using System.Runtime.InteropServices;

public static class Program { /*
    private struct MyData {
        public int Length;
        public byte[] Bytes;
    } */

    // __declspec(dllexport) void WINAPI CreateMyDataAlt(BYTE bytes[], int length);
    private static extern void CreateMyDataAlt(byte[] myData, ref int length);

    private static extern void DestroyMyData(byte[] myData); */

    public static void Main() {
        Console.WriteLine("=== C# test, using IntPtr and Marshal ===");
        int length = 100*1024*1024;
        var myData1 = new byte[length];
        CreateMyDataAlt(myData1, ref length);

        if(0!=length) {
            // MyData myData2 = (MyData)Marshal.PtrToStructure(myData1, typeof(MyData));

            Console.WriteLine("Length: {0}", length);

            if(myData2.Bytes!=IntPtr.Zero) {
                byte[] bytes = new byte[myData2.Length];
                Marshal.Copy(myData2.Bytes, bytes, 0, myData2.Length); */
            Console.WriteLine("First: {0}, last: {1}", myData1[0], myData1[length-1]); /*
            else {
                Console.WriteLine("myData.Bytes is IntPtr.Zero");
            } */
        else {
            Console.WriteLine("myData is empty");

        // DestroyMyData(myData1);

As you can see much of your original marshalling code is commented out, and declared a CreateMyDataAlt(byte[], ref int) for a coresponding modified external unmanaged function CreateMyDataAlt(BYTE [], int). Some of the data copy and pointer check turns to be unnecessary, that says, the code can be even simpler and probably runs faster.

正如您所看到的,原始的编组代码被注释掉了,并为修改后的外部非托管函数CreateMyDataAlt(byte[], ref int)声明了一个CreateMyDataAlt(byte[], ref int)。有些数据复制和指针检查是不必要的,也就是说,代码可以更简单,可能运行得更快。

So, what's so different with the modification? The byte array is now marshalled directly without warpping in a struct and passed to the unmanaged side. You don't allocate the memory within the unmanaged code, rather, just filling data to it(implementation details omitted); and after the call, the data needed is provided to the managed side. If you want to present that the data is not filled and should not be used, you can simply set length to zero to tell the managed side. Because the byte array is allocated within the managed side, it'll be collected sometime, you don't have to take care of that.




For anyone still reading,


Something I don't think I saw in any of the answers, - unsafe code does present something of a security risk. It's not a huge risk, it would be something quite challenging to exploit. However, if like me you work in a PCI compliant organization, unsafe code is disallowed by policy for this reason.


Managed code is normally very secure because the CLR takes care of memory location and allocation, preventing you from accessing or writing any memory you're not supposed to.


When you use the unsafe keyword and compile with '/unsafe' and use pointers, you bypass these checks and create the potential for someone to use your application to gain some level of unauthorized access to the machine it is running on. Using something like a buffer-overrun attack, your code could be tricked into writing instructions into an area of memory that might then be accessed by the program counter (i.e. code injection), or just crash the machine.


Many years ago, SQL server actually fell prey to malicious code delivered in a TDS packet that was far longer than it was supposed to be. The method reading the packet didn't check the length and continued to write the contents past the reserved address space. The extra length and content were carefully crafted such that it wrote an entire program into memory - at the address of the next method. The attacker then had their own code being executed by the SQL server within a context that had the highest level of access. It didn't even need to break the encryption as the vulnerability was below this point in the transport layer stack.

许多年前,SQL server实际上是TDS包中恶意代码的牺牲品,这些恶意代码的传输时间比预期的要长得多。读取包的方法没有检查长度,而是继续将内容写入保留地址空间之后。额外的长度和内容是精心设计的,这样它就可以在下一个方法的地址将整个程序写到内存中。然后,攻击者在具有最高访问级别的上下文中由SQL服务器执行自己的代码。它甚至不需要打破加密,因为漏洞在传输层堆栈的这个点以下。



It's a little old thread, but I recently made excessive performance tests with marshaling in C#. I need to unmarshal lots of data from a serial port over many days. It was important to me to have no memory leaks (because the smallest leak will get significant after a couple of million calls) and I also made a lot of statistical performance (time used) tests with very big structs (>10kb) just for the sake of it (an no, you should never have a 10kb struct :-) )

这是一个有点旧的线程,但是我最近在c#中进行了过多的性能测试。我需要在许多天内从一个串行端口中释放大量数据。我没有内存泄漏很重要(因为最小的泄漏后将得到显著的几百万调用),我也做了许多的统计性能(时间)使用测试非常大的结构(> 10 kb)只是为了它(不,你不应该有一个10 kb结构:-))

I tested the following three unmarshalling strategies (I also tested the marshalling). In nearly all cases the first one (MarshalMatters) outperformed the other two. Marshal.Copy was always slowest by far, the other two were mostly very close together in the race.


Using unsafe code can pose a significant security risk.




public class MarshalMatters
    public static T ReadUsingMarshalUnsafe<T>(byte[] data) where T : struct
            fixed (byte* p = &data[0])
                return (T)Marshal.PtrToStructure(new IntPtr(p), typeof(T));

    public unsafe static byte[] WriteUsingMarshalUnsafe<selectedT>(selectedT structure) where selectedT : struct
        byte[] byteArray = new byte[Marshal.SizeOf(structure)];
        fixed (byte* byteArrayPtr = byteArray)
            Marshal.StructureToPtr(structure, (IntPtr)byteArrayPtr, true);
        return byteArray;



public class Adam_Robinson

    private static T BytesToStruct<T>(byte[] rawData) where T : struct
        T result = default(T);
        GCHandle handle = GCHandle.Alloc(rawData, GCHandleType.Pinned);
            IntPtr rawDataPtr = handle.AddrOfPinnedObject();
            result = (T)Marshal.PtrToStructure(rawDataPtr, typeof(T));
        return result;

    /// <summary>
    /// no Copy. no unsafe. Gets a GCHandle to the memory via Alloc
    /// </summary>
    /// <typeparam name="selectedT"></typeparam>
    /// <param name="structure"></param>
    /// <returns></returns>
    public static byte[] StructToBytes<T>(T structure) where T : struct
        int size = Marshal.SizeOf(structure);
        byte[] rawData = new byte[size];
        GCHandle handle = GCHandle.Alloc(rawData, GCHandleType.Pinned);
            IntPtr rawDataPtr = handle.AddrOfPinnedObject();
            Marshal.StructureToPtr(structure, rawDataPtr, false);
        return rawData;



/// <summary>
/// http://*.com/questions/2623761/marshal-ptrtostructure-and-back-again-and-generic-solution-for-endianness-swap
/// </summary>
public class DanB
    /// <summary>
    /// uses Marshal.Copy! Not run in unsafe. Uses AllocHGlobal to get new memory and copies.
    /// </summary>
    public static byte[] GetBytes<T>(T structure) where T : struct
        var size = Marshal.SizeOf(structure); //or Marshal.SizeOf<selectedT>(); in .net 4.5.1
        byte[] rawData = new byte[size];
        IntPtr ptr = Marshal.AllocHGlobal(size);

        Marshal.StructureToPtr(structure, ptr, true);
        Marshal.Copy(ptr, rawData, 0, size);
        return rawData;

    public static T FromBytes<T>(byte[] bytes) where T : struct
        var structure = new T();
        int size = Marshal.SizeOf(structure);  //or Marshal.SizeOf<selectedT>(); in .net 4.5.1
        IntPtr ptr = Marshal.AllocHGlobal(size);

        Marshal.Copy(bytes, 0, ptr, size);

        structure = (T)Marshal.PtrToStructure(ptr, structure.GetType());

        return structure;



Considerations in Interoperability explains why and when Marshaling is required and at what cost. Quote:


  1. Marshaling occurs when a caller and a callee cannot operate on the same instance of data.
  2. 当调用者和被调用者不能对相同的数据实例进行操作时,就会发生封送。
  3. repeated marshaling can negatively affect the performance of your application.
  4. 重复封送会对应用程序的性能产生负面影响。

Therefore, answering your question if


... using pointers for P/Invoking really faster than using marshaling ...


first ask yourself a question if the managed code is able to operate on the unmanaged method return value instance. If the answer is yes then Marshaling and the associated performance cost is not required. The approximate time saving would be O(n) function where n of the size of the marshalled instance. In addition, not keeping both managed and unmanaged blocks of data in memory at the same time for the duration of the method (in "IntPtr and Marshal" example) eliminates additional overhead and the memory pressure.


What are the drawbacks of using unsafe code and pointers ...


The drawback is the risk associated with accessing the memory directly through pointers. There is nothing less safe to it than using pointers in C or C++. Use it if needed and makes sense. More details are here.


There is one "safety" concern with the presented examples: releasing of allocated unmanaged memory is not guaranteed after the managed code errors. The best practice is to


CreateMyData(out myData1, length);

if(myData1!=IntPtr.Zero) {
    try {
        // -> use myData1
        // <-
    finally {



Two answers,


  1. Unsafe code means it is not managed by the CLR. You need to take care of resources it uses.


  2. You cannot scale the performance because there are so many factors effecting it. But definitely using pointers will be much faster.




Just wanted to add my experience to this old thread: We used Marshaling in sound recording software - we received real time sound data from mixer into native buffers and marshaled it to byte[]. That was real performance killer. We were forced to move to unsafe structs as the only way to complete the task.


In case you don't have large native structs and don't mind that all data is filled twice - Marshaling is more elegant and much, much safer approach.




Because you stated that your code calls to 3rd-party DLL, I think the unsafe code is more suited in you scenario. You ran into a particular situation of wapping variable-length array in a struct; I know, I know this kind of usage occurs all the time, but it's not always the case after all. You might want to have a look of some questions about this, for example:


How do I marshal a struct that contains a variable-sized array to C#?

如何将包含可变大小数组的结构体编组到c# ?

If .. I say if .. you can modify the third party libraries a bit for this particular case, then you might consider the following usage:

如果. .我说如果. .对于这种特殊情况,您可以稍微修改一下第三方库,然后您可以考虑以下用法:

using System.Runtime.InteropServices;

public static class Program { /*
    private struct MyData {
        public int Length;
        public byte[] Bytes;
    } */

    // __declspec(dllexport) void WINAPI CreateMyDataAlt(BYTE bytes[], int length);
    private static extern void CreateMyDataAlt(byte[] myData, ref int length);

    private static extern void DestroyMyData(byte[] myData); */

    public static void Main() {
        Console.WriteLine("=== C# test, using IntPtr and Marshal ===");
        int length = 100*1024*1024;
        var myData1 = new byte[length];
        CreateMyDataAlt(myData1, ref length);

        if(0!=length) {
            // MyData myData2 = (MyData)Marshal.PtrToStructure(myData1, typeof(MyData));

            Console.WriteLine("Length: {0}", length);

            if(myData2.Bytes!=IntPtr.Zero) {
                byte[] bytes = new byte[myData2.Length];
                Marshal.Copy(myData2.Bytes, bytes, 0, myData2.Length); */
            Console.WriteLine("First: {0}, last: {1}", myData1[0], myData1[length-1]); /*
            else {
                Console.WriteLine("myData.Bytes is IntPtr.Zero");
            } */
        else {
            Console.WriteLine("myData is empty");

        // DestroyMyData(myData1);

As you can see much of your original marshalling code is commented out, and declared a CreateMyDataAlt(byte[], ref int) for a coresponding modified external unmanaged function CreateMyDataAlt(BYTE [], int). Some of the data copy and pointer check turns to be unnecessary, that says, the code can be even simpler and probably runs faster.

正如您所看到的,原始的编组代码被注释掉了,并为修改后的外部非托管函数CreateMyDataAlt(byte[], ref int)声明了一个CreateMyDataAlt(byte[], ref int)。有些数据复制和指针检查是不必要的,也就是说,代码可以更简单,可能运行得更快。

So, what's so different with the modification? The byte array is now marshalled directly without warpping in a struct and passed to the unmanaged side. You don't allocate the memory within the unmanaged code, rather, just filling data to it(implementation details omitted); and after the call, the data needed is provided to the managed side. If you want to present that the data is not filled and should not be used, you can simply set length to zero to tell the managed side. Because the byte array is allocated within the managed side, it'll be collected sometime, you don't have to take care of that.




For anyone still reading,


Something I don't think I saw in any of the answers, - unsafe code does present something of a security risk. It's not a huge risk, it would be something quite challenging to exploit. However, if like me you work in a PCI compliant organization, unsafe code is disallowed by policy for this reason.


Managed code is normally very secure because the CLR takes care of memory location and allocation, preventing you from accessing or writing any memory you're not supposed to.


When you use the unsafe keyword and compile with '/unsafe' and use pointers, you bypass these checks and create the potential for someone to use your application to gain some level of unauthorized access to the machine it is running on. Using something like a buffer-overrun attack, your code could be tricked into writing instructions into an area of memory that might then be accessed by the program counter (i.e. code injection), or just crash the machine.


Many years ago, SQL server actually fell prey to malicious code delivered in a TDS packet that was far longer than it was supposed to be. The method reading the packet didn't check the length and continued to write the contents past the reserved address space. The extra length and content were carefully crafted such that it wrote an entire program into memory - at the address of the next method. The attacker then had their own code being executed by the SQL server within a context that had the highest level of access. It didn't even need to break the encryption as the vulnerability was below this point in the transport layer stack.

许多年前,SQL server实际上是TDS包中恶意代码的牺牲品,这些恶意代码的传输时间比预期的要长得多。读取包的方法没有检查长度,而是继续将内容写入保留地址空间之后。额外的长度和内容是精心设计的,这样它就可以在下一个方法的地址将整个程序写到内存中。然后,攻击者在具有最高访问级别的上下文中由SQL服务器执行自己的代码。它甚至不需要打破加密,因为漏洞在传输层堆栈的这个点以下。