1 /*
2 * CDDL HEADER START
3 *
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
7 *
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
12 *
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
18 *
19 * CDDL HEADER END
20 */
21
22 /*
23 * Copyright 2010 Sun Microsystems, Inc. All rights reserved.
24 * Use is subject to license terms.
25 */
26 /*
27 * Copyright 2018 Joyent, Inc.
28 * Copyright (c) 2014 by Delphix. All rights reserved.
29 * Copyright 2025 Oxide Computer Company
30 */
31
32 /*
33 * User Process Target
34 *
35 * The user process target is invoked when the -u or -p command-line options
36 * are used, or when an ELF executable file or ELF core file is specified on
37 * the command-line. This target is also selected by default when no target
38 * options are present. In this case, it defaults the executable name to
39 * "a.out". If no process or core file is currently attached, the target
40 * functions as a kind of virtual /dev/zero (in accordance with adb(1)
41 * semantics); reads from the virtual address space return zeroes and writes
42 * fail silently. The proc target itself is designed as a wrapper around the
43 * services provided by libproc.so: t->t_pshandle is set to the struct
44 * ps_prochandle pointer returned as a handle by libproc. The target also
45 * opens the executable file itself using the MDB GElf services, for
46 * interpreting the .symtab and .dynsym if no libproc handle has been
47 * initialized, and for handling i/o to and from the object file. Currently,
48 * the only ISA-dependent portions of the proc target are the $r and ::fpregs
49 * dcmds, the callbacks for t_next() and t_step_out(), and the list of named
50 * registers; these are linked in from the proc_isadep.c file for each ISA and
51 * called from the common code in this file.
52 *
53 * The user process target implements complete user process control using the
54 * facilities provided by libproc.so. The MDB execution control model and
55 * an overview of software event management is described in mdb_target.c. The
56 * proc target implements breakpoints by replacing the instruction of interest
57 * with a trap instruction, and then restoring the original instruction to step
58 * over the breakpoint. The idea of replacing program text with instructions
59 * that transfer control to the debugger dates back as far as 1951 [1]. When
60 * the target stops, we replace each breakpoint with the original instruction
61 * as part of the disarm operation. This means that no special processing is
62 * required for t_vread() because the instrumented instructions will never be
63 * seen by the debugger once the target stops. Some debuggers have improved
64 * start/stop performance by leaving breakpoint traps in place and then
65 * handling a read from a breakpoint address as a special case. Although this
66 * improves efficiency for a source-level debugger, it runs somewhat contrary
67 * to the philosophy of the low-level debugger. Since we remove the
68 * instructions, users can apply other external debugging tools to the process
69 * once it has stopped (e.g. the proc(1) tools) and not be misled by MDB
70 * instrumentation. The tracing of faults, signals, system calls, and
71 * watchpoints and general process inspection is implemented directly using
72 * the mechanisms provided by /proc, as described originally in [2] and [3].
73 *
74 * References
75 *
76 * [1] S. Gill, "The Diagnosis Of Mistakes In Programmes on the EDSAC",
77 * Proceedings of the Royal Society Series A Mathematical and Physical
78 * Sciences, Cambridge University Press, 206(1087), May 1951, pp. 538-554.
79 *
80 * [2] T.J. Killian, "Processes as Files", Proceedings of the USENIX Association
81 * Summer Conference, Salt Lake City, June 1984, pp. 203-207.
82 *
83 * [3] Roger Faulkner and Ron Gomes, "The Process File System and Process
84 * Model in UNIX System V", Proceedings of the USENIX Association
85 * Winter Conference, Dallas, January 1991, pp. 243-252.
86 */
87
88 #include <mdb/mdb_proc.h>
89 #include <mdb/mdb_disasm.h>
90 #include <mdb/mdb_signal.h>
91 #include <mdb/mdb_string.h>
92 #include <mdb/mdb_module.h>
93 #include <mdb/mdb_debug.h>
94 #include <mdb/mdb_conf.h>
95 #include <mdb/mdb_err.h>
96 #include <mdb/mdb_types.h>
97 #include <mdb/mdb.h>
98
99 #include <sys/utsname.h>
100 #include <sys/wait.h>
101 #include <sys/stat.h>
102 #include <termio.h>
103 #include <signal.h>
104 #include <stdio_ext.h>
105 #include <stdlib.h>
106 #include <string.h>
107 #include <ctype.h>
108
109 #define PC_FAKE -1UL /* illegal pc value unequal 0 */
110 #define PANIC_BUFSIZE 1024
111
112 static const char PT_EXEC_PATH[] = "a.out"; /* Default executable */
113 static const char PT_CORE_PATH[] = "core"; /* Default core file */
114
115 static const pt_ptl_ops_t proc_lwp_ops;
116 static const pt_ptl_ops_t proc_tdb_ops;
117 static const mdb_se_ops_t proc_brkpt_ops;
118 static const mdb_se_ops_t proc_wapt_ops;
119
120 static int pt_setrun(mdb_tgt_t *, mdb_tgt_status_t *, int);
121 static void pt_activate_common(mdb_tgt_t *);
122 static mdb_tgt_vespec_f pt_ignore_sig;
123 static mdb_tgt_se_f pt_fork;
124 static mdb_tgt_se_f pt_exec;
125
126 static int pt_lookup_by_name_thr(mdb_tgt_t *, const char *,
127 const char *, GElf_Sym *, mdb_syminfo_t *, mdb_tgt_tid_t);
128 static int tlsbase(mdb_tgt_t *, mdb_tgt_tid_t, Lmid_t, const char *,
129 psaddr_t *);
130
131 /*
132 * When debugging postmortem, we don't resolve names as we may very well not
133 * be on a system on which those names resolve.
134 */
135 #define PT_LIBPROC_RESOLVE(P) \
136 (!(mdb.m_flags & MDB_FL_LMRAW) && Pstate(P) != PS_DEAD)
137
138 /*
139 * The Perror_printf() function interposes on the default, empty libproc
140 * definition. It will be called to report additional information on complex
141 * errors, such as a corrupt core file. We just pass the args to vwarn.
142 */
143 /*ARGSUSED*/
144 void
Perror_printf(struct ps_prochandle * P,const char * format,...)145 Perror_printf(struct ps_prochandle *P, const char *format, ...)
146 {
147 va_list alist;
148
149 va_start(alist, format);
150 vwarn(format, alist);
151 va_end(alist);
152 }
153
154 /*
155 * Open the specified i/o backend as the a.out executable file, and attempt to
156 * load its standard and dynamic symbol tables. Note that if mdb_gelf_create
157 * succeeds, io is assigned to p_fio and is automatically held by gelf_create.
158 */
159 static mdb_gelf_file_t *
pt_open_aout(mdb_tgt_t * t,mdb_io_t * io)160 pt_open_aout(mdb_tgt_t *t, mdb_io_t *io)
161 {
162 pt_data_t *pt = t->t_data;
163 GElf_Sym s1, s2;
164
165 if ((pt->p_file = mdb_gelf_create(io, ET_NONE, GF_FILE)) == NULL)
166 return (NULL);
167
168 pt->p_symtab = mdb_gelf_symtab_create_file(pt->p_file,
169 SHT_SYMTAB, MDB_TGT_SYMTAB);
170 pt->p_dynsym = mdb_gelf_symtab_create_file(pt->p_file,
171 SHT_DYNSYM, MDB_TGT_DYNSYM);
172
173 /*
174 * If we've got an _start symbol with a zero size, prime the private
175 * symbol table with a copy of _start with its size set to the distance
176 * between _mcount and _start. We do this because DevPro has shipped
177 * the Intel crt1.o without proper .size directives for years, which
178 * precludes proper identification of _start in stack traces.
179 */
180 if (mdb_gelf_symtab_lookup_by_name(pt->p_dynsym, "_start", &s1,
181 NULL) == 0 && s1.st_size == 0 &&
182 GELF_ST_TYPE(s1.st_info) == STT_FUNC) {
183 if (mdb_gelf_symtab_lookup_by_name(pt->p_dynsym, "_mcount",
184 &s2, NULL) == 0 && GELF_ST_TYPE(s2.st_info) == STT_FUNC) {
185 s1.st_size = s2.st_value - s1.st_value;
186 mdb_gelf_symtab_insert(mdb.m_prsym, "_start", &s1);
187 }
188 }
189
190 pt->p_fio = io;
191 return (pt->p_file);
192 }
193
194 /*
195 * Destroy the symbol tables and GElf file object associated with p_fio. Note
196 * that we do not need to explicitly free p_fio: its reference count is
197 * automatically decremented by mdb_gelf_destroy, which will free it if needed.
198 */
199 static void
pt_close_aout(mdb_tgt_t * t)200 pt_close_aout(mdb_tgt_t *t)
201 {
202 pt_data_t *pt = t->t_data;
203
204 if (pt->p_symtab != NULL) {
205 mdb_gelf_symtab_destroy(pt->p_symtab);
206 pt->p_symtab = NULL;
207 }
208
209 if (pt->p_dynsym != NULL) {
210 mdb_gelf_symtab_destroy(pt->p_dynsym);
211 pt->p_dynsym = NULL;
212 }
213
214 if (pt->p_file != NULL) {
215 mdb_gelf_destroy(pt->p_file);
216 pt->p_file = NULL;
217 }
218
219 mdb_gelf_symtab_delete(mdb.m_prsym, "_start", NULL);
220 pt->p_fio = NULL;
221 }
222
223 typedef struct tdb_mapping {
224 const char *tm_thr_lib;
225 const char *tm_db_dir;
226 const char *tm_db_name;
227 } tdb_mapping_t;
228
229 static const tdb_mapping_t tdb_map[] = {
230 { "/lwp/amd64/libthread.so", "/usr/lib/lwp/", "libthread_db.so" },
231 { "/lwp/sparcv9/libthread.so", "/usr/lib/lwp/", "libthread_db.so" },
232 { "/lwp/libthread.so", "/usr/lib/lwp/", "libthread_db.so" },
233 { "/libthread.so", "/lib/", "libthread_db.so" },
234 { "/libc_hwcap", "/lib/", "libc_db.so" },
235 { "/libc.so", "/lib/", "libc_db.so" }
236 };
237
238 /*
239 * Pobject_iter callback that we use to search for the presence of libthread in
240 * order to load the corresponding libthread_db support. We derive the
241 * libthread_db path dynamically based on the libthread path. If libthread is
242 * found, this function returns 1 (and thus Pobject_iter aborts and returns 1)
243 * regardless of whether it was successful in loading the libthread_db support.
244 * If we iterate over all objects and no libthread is found, 0 is returned.
245 * Since libthread_db support was then merged into libc_db, we load either
246 * libc_db or libthread_db, depending on which library we see first.
247 */
248 /*ARGSUSED*/
249 static int
thr_check(mdb_tgt_t * t,const prmap_t * pmp,const char * name)250 thr_check(mdb_tgt_t *t, const prmap_t *pmp, const char *name)
251 {
252 pt_data_t *pt = t->t_data;
253 const mdb_tdb_ops_t *ops;
254 char *p;
255
256 char path[MAXPATHLEN];
257
258 int libn;
259
260 if (name == NULL)
261 return (0); /* no rtld_db object name; keep going */
262
263 for (libn = 0; libn < sizeof (tdb_map) / sizeof (tdb_map[0]); libn++) {
264 if ((p = strstr(name, tdb_map[libn].tm_thr_lib)) != NULL)
265 break;
266 }
267
268 if (p == NULL)
269 return (0); /* no match; keep going */
270
271 path[0] = '\0';
272 (void) strlcat(path, mdb.m_root, sizeof (path));
273 (void) strlcat(path, tdb_map[libn].tm_db_dir, sizeof (path));
274 #if !defined(_ILP32)
275 (void) strlcat(path, "64/", sizeof (path));
276 #endif /* !_ILP32 */
277 (void) strlcat(path, tdb_map[libn].tm_db_name, sizeof (path));
278
279 /* Append the trailing library version number. */
280 (void) strlcat(path, strrchr(name, '.'), sizeof (path));
281
282 if ((ops = mdb_tdb_load(path)) == NULL) {
283 if (libn != 0 || errno != ENOENT)
284 warn("failed to load %s", path);
285 goto err;
286 }
287
288 if (ops == pt->p_tdb_ops)
289 return (1); /* no changes needed */
290
291 PTL_DTOR(t);
292 pt->p_tdb_ops = ops;
293 pt->p_ptl_ops = &proc_tdb_ops;
294 pt->p_ptl_hdl = NULL;
295
296 if (PTL_CTOR(t) == -1) {
297 warn("failed to initialize %s", path);
298 goto err;
299 }
300
301 mdb_dprintf(MDB_DBG_TGT, "loaded %s for debugging %s\n", path, name);
302 (void) mdb_tgt_status(t, &t->t_status);
303 return (1);
304 err:
305 PTL_DTOR(t);
306 pt->p_tdb_ops = NULL;
307 pt->p_ptl_ops = &proc_lwp_ops;
308 pt->p_ptl_hdl = NULL;
309
310 if (libn != 0 || errno != ENOENT) {
311 warn("warning: debugger will only be able to "
312 "examine raw LWPs\n");
313 }
314
315 (void) mdb_tgt_status(t, &t->t_status);
316 return (1);
317 }
318
319 /*
320 * Whenever the link map is consistent following an add or delete event, we ask
321 * libproc to update its mappings, check to see if we need to load libthread_db,
322 * and then update breakpoints which have been mapped or unmapped.
323 */
324 /*ARGSUSED*/
325 static void
pt_rtld_event(mdb_tgt_t * t,int vid,void * private)326 pt_rtld_event(mdb_tgt_t *t, int vid, void *private)
327 {
328 struct ps_prochandle *P = t->t_pshandle;
329 pt_data_t *pt = t->t_data;
330 rd_event_msg_t rdm;
331 int docontinue = 1;
332
333 if (rd_event_getmsg(pt->p_rtld, &rdm) == RD_OK) {
334
335 mdb_dprintf(MDB_DBG_TGT, "rtld event type 0x%x state 0x%x\n",
336 rdm.type, rdm.u.state);
337
338 if (rdm.type == RD_DLACTIVITY && rdm.u.state == RD_CONSISTENT) {
339 mdb_sespec_t *sep, *nsep = mdb_list_next(&t->t_active);
340 pt_brkpt_t *ptb;
341
342 Pupdate_maps(P);
343
344 if (Pobject_iter(P, (proc_map_f *)thr_check, t) == 0 &&
345 pt->p_ptl_ops != &proc_lwp_ops) {
346 mdb_dprintf(MDB_DBG_TGT, "unloading thread_db "
347 "support after dlclose\n");
348 PTL_DTOR(t);
349 pt->p_tdb_ops = NULL;
350 pt->p_ptl_ops = &proc_lwp_ops;
351 pt->p_ptl_hdl = NULL;
352 (void) mdb_tgt_status(t, &t->t_status);
353 }
354
355 for (sep = nsep; sep != NULL; sep = nsep) {
356 nsep = mdb_list_next(sep);
357 ptb = sep->se_data;
358
359 if (sep->se_ops == &proc_brkpt_ops &&
360 Paddr_to_map(P, ptb->ptb_addr) == NULL)
361 mdb_tgt_sespec_idle_one(t, sep,
362 EMDB_NOMAP);
363 }
364
365 if (!mdb_tgt_sespec_activate_all(t) &&
366 (mdb.m_flags & MDB_FL_BPTNOSYMSTOP) &&
367 pt->p_rtld_finished) {
368 /*
369 * We weren't able to activate the breakpoints.
370 * If so requested, we'll return without
371 * calling continue, thus throwing the user into
372 * the debugger.
373 */
374 docontinue = 0;
375 }
376
377 if (pt->p_rdstate == PT_RD_ADD)
378 pt->p_rdstate = PT_RD_CONSIST;
379 }
380
381 if (rdm.type == RD_PREINIT)
382 (void) mdb_tgt_sespec_activate_all(t);
383
384 if (rdm.type == RD_POSTINIT) {
385 pt->p_rtld_finished = TRUE;
386 if (!mdb_tgt_sespec_activate_all(t) &&
387 (mdb.m_flags & MDB_FL_BPTNOSYMSTOP)) {
388 /*
389 * Now that rtld has been initialized, we
390 * should be able to initialize all deferred
391 * breakpoints. If we can't, don't let the
392 * target continue.
393 */
394 docontinue = 0;
395 }
396 }
397
398 if (rdm.type == RD_DLACTIVITY && rdm.u.state == RD_ADD &&
399 pt->p_rtld_finished)
400 pt->p_rdstate = MAX(pt->p_rdstate, PT_RD_ADD);
401 }
402
403 if (docontinue)
404 (void) mdb_tgt_continue(t, NULL);
405 }
406
407 static void
pt_post_attach(mdb_tgt_t * t)408 pt_post_attach(mdb_tgt_t *t)
409 {
410 struct ps_prochandle *P = t->t_pshandle;
411 const lwpstatus_t *psp = &Pstatus(P)->pr_lwp;
412 pt_data_t *pt = t->t_data;
413 int hflag = MDB_TGT_SPEC_HIDDEN;
414
415 mdb_dprintf(MDB_DBG_TGT, "attach pr_flags=0x%x pr_why=%d pr_what=%d\n",
416 psp->pr_flags, psp->pr_why, psp->pr_what);
417
418 /*
419 * When we grab a process, the initial setting of p_rtld_finished
420 * should be false if the process was just created by exec; otherwise
421 * we permit unscoped references to resolve because we do not know how
422 * far the process has proceeded through linker initialization.
423 */
424 if ((psp->pr_flags & PR_ISTOP) && psp->pr_why == PR_SYSEXIT &&
425 psp->pr_errno == 0 && psp->pr_what == SYS_execve) {
426 if (mdb.m_target == NULL) {
427 warn("target performed exec of %s\n",
428 IOP_NAME(pt->p_fio));
429 }
430 pt->p_rtld_finished = FALSE;
431 } else
432 pt->p_rtld_finished = TRUE;
433
434 /*
435 * When we grab a process, if it is stopped by job control and part of
436 * the same session (i.e. same controlling tty), set MDB_FL_JOBCTL so
437 * we will know to bring it to the foreground when we continue it.
438 */
439 if (mdb.m_term != NULL && (psp->pr_flags & PR_STOPPED) &&
440 psp->pr_why == PR_JOBCONTROL && getsid(0) == Pstatus(P)->pr_sid)
441 mdb.m_flags |= MDB_FL_JOBCTL;
442
443 /*
444 * When we grab control of a live process, set F_RDWR so that the
445 * target layer permits writes to the target's address space.
446 */
447 t->t_flags |= MDB_TGT_F_RDWR;
448
449 (void) Pfault(P, FLTBPT, TRUE); /* always trace breakpoints */
450 (void) Pfault(P, FLTWATCH, TRUE); /* always trace watchpoints */
451 (void) Pfault(P, FLTTRACE, TRUE); /* always trace single-step */
452
453 (void) Punsetflags(P, PR_ASYNC); /* require synchronous mode */
454 (void) Psetflags(P, PR_BPTADJ); /* always adjust eip on x86 */
455 (void) Psetflags(P, PR_FORK); /* inherit tracing on fork */
456
457 /*
458 * Install event specifiers to track fork and exec activities:
459 */
460 (void) mdb_tgt_add_sysexit(t, SYS_vfork, hflag, pt_fork, NULL);
461 (void) mdb_tgt_add_sysexit(t, SYS_forksys, hflag, pt_fork, NULL);
462 (void) mdb_tgt_add_sysexit(t, SYS_execve, hflag, pt_exec, NULL);
463
464 /*
465 * Attempt to instantiate the librtld_db agent and set breakpoints
466 * to track rtld activity. We will legitimately fail to instantiate
467 * the rtld_db agent if the target is statically linked.
468 */
469 if (pt->p_rtld == NULL && (pt->p_rtld = Prd_agent(P)) != NULL) {
470 rd_notify_t rdn;
471 rd_err_e err;
472
473 if ((err = rd_event_enable(pt->p_rtld, TRUE)) != RD_OK) {
474 warn("failed to enable rtld_db event tracing: %s\n",
475 rd_errstr(err));
476 goto out;
477 }
478
479 if ((err = rd_event_addr(pt->p_rtld, RD_PREINIT,
480 &rdn)) == RD_OK && rdn.type == RD_NOTIFY_BPT) {
481 (void) mdb_tgt_add_vbrkpt(t, rdn.u.bptaddr,
482 hflag, pt_rtld_event, NULL);
483 } else {
484 warn("failed to install rtld_db preinit tracing: %s\n",
485 rd_errstr(err));
486 }
487
488 if ((err = rd_event_addr(pt->p_rtld, RD_POSTINIT,
489 &rdn)) == RD_OK && rdn.type == RD_NOTIFY_BPT) {
490 (void) mdb_tgt_add_vbrkpt(t, rdn.u.bptaddr,
491 hflag, pt_rtld_event, NULL);
492 } else {
493 warn("failed to install rtld_db postinit tracing: %s\n",
494 rd_errstr(err));
495 }
496
497 if ((err = rd_event_addr(pt->p_rtld, RD_DLACTIVITY,
498 &rdn)) == RD_OK && rdn.type == RD_NOTIFY_BPT) {
499 (void) mdb_tgt_add_vbrkpt(t, rdn.u.bptaddr,
500 hflag, pt_rtld_event, NULL);
501 } else {
502 warn("failed to install rtld_db activity tracing: %s\n",
503 rd_errstr(err));
504 }
505 }
506 out:
507 Pupdate_maps(P);
508 Psync(P);
509
510 /*
511 * If librtld_db failed to initialize due to an error or because we are
512 * debugging a statically linked executable, allow unscoped references.
513 */
514 if (pt->p_rtld == NULL)
515 pt->p_rtld_finished = TRUE;
516
517 (void) mdb_tgt_sespec_activate_all(t);
518 }
519
520 /*ARGSUSED*/
521 static int
pt_vespec_delete(mdb_tgt_t * t,void * private,int id,void * data)522 pt_vespec_delete(mdb_tgt_t *t, void *private, int id, void *data)
523 {
524 if (id < 0) {
525 ASSERT(data == NULL); /* we don't use any ve_data */
526 (void) mdb_tgt_vespec_delete(t, id);
527 }
528 return (0);
529 }
530
531 static void
pt_pre_detach(mdb_tgt_t * t,int clear_matched)532 pt_pre_detach(mdb_tgt_t *t, int clear_matched)
533 {
534 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
535 pt_data_t *pt = t->t_data;
536 long cmd = 0;
537
538 /*
539 * If we are about to release the process and it is stopped on a traced
540 * SIGINT, breakpoint fault, single-step fault, or watchpoint, make
541 * sure to clear this event prior to releasing the process so that it
542 * does not subsequently reissue the fault and die from SIGTRAP.
543 */
544 if (psp->pr_flags & PR_ISTOP) {
545 if (psp->pr_why == PR_FAULTED && (psp->pr_what == FLTBPT ||
546 psp->pr_what == FLTTRACE || psp->pr_what == FLTWATCH))
547 cmd = PCCFAULT;
548 else if (psp->pr_why == PR_SIGNALLED && psp->pr_what == SIGINT)
549 cmd = PCCSIG;
550
551 if (cmd != 0)
552 (void) write(Pctlfd(t->t_pshandle), &cmd, sizeof (cmd));
553 }
554
555 if (Pstate(t->t_pshandle) == PS_UNDEAD)
556 (void) waitpid(Pstatus(t->t_pshandle)->pr_pid, NULL, WNOHANG);
557
558 (void) mdb_tgt_vespec_iter(t, pt_vespec_delete, NULL);
559 mdb_tgt_sespec_idle_all(t, EMDB_NOPROC, clear_matched);
560
561 if (pt->p_fio != pt->p_aout_fio) {
562 pt_close_aout(t);
563 (void) pt_open_aout(t, pt->p_aout_fio);
564 }
565
566 PTL_DTOR(t);
567 pt->p_tdb_ops = NULL;
568 pt->p_ptl_ops = &proc_lwp_ops;
569 pt->p_ptl_hdl = NULL;
570
571 pt->p_rtld = NULL;
572 pt->p_signal = 0;
573 pt->p_rtld_finished = FALSE;
574 pt->p_rdstate = PT_RD_NONE;
575 }
576
577 static void
pt_release_parents(mdb_tgt_t * t)578 pt_release_parents(mdb_tgt_t *t)
579 {
580 struct ps_prochandle *P = t->t_pshandle;
581 pt_data_t *pt = t->t_data;
582
583 mdb_sespec_t *sep;
584 pt_vforkp_t *vfp;
585
586 while ((vfp = mdb_list_next(&pt->p_vforkp)) != NULL) {
587 mdb_dprintf(MDB_DBG_TGT, "releasing vfork parent %d\n",
588 (int)Pstatus(vfp->p_pshandle)->pr_pid);
589
590 /*
591 * To release vfork parents, we must also wipe out any armed
592 * events in the parent by switching t_pshandle and calling
593 * se_disarm(). Do not change states or lose the matched list.
594 */
595 t->t_pshandle = vfp->p_pshandle;
596
597 for (sep = mdb_list_next(&t->t_active); sep != NULL;
598 sep = mdb_list_next(sep)) {
599 if (sep->se_state == MDB_TGT_SPEC_ARMED)
600 (void) sep->se_ops->se_disarm(t, sep);
601 }
602
603 t->t_pshandle = P;
604
605 Prelease(vfp->p_pshandle, PRELEASE_CLEAR);
606 mdb_list_delete(&pt->p_vforkp, vfp);
607 mdb_free(vfp, sizeof (pt_vforkp_t));
608 }
609 }
610
611 /*ARGSUSED*/
612 static void
pt_fork(mdb_tgt_t * t,int vid,void * private)613 pt_fork(mdb_tgt_t *t, int vid, void *private)
614 {
615 struct ps_prochandle *P = t->t_pshandle;
616 const lwpstatus_t *psp = &Pstatus(P)->pr_lwp;
617 pt_data_t *pt = t->t_data;
618 mdb_sespec_t *sep;
619
620 int follow_parent = mdb.m_forkmode != MDB_FM_CHILD;
621 int is_vfork = (psp->pr_what == SYS_vfork ||
622 (psp->pr_what == SYS_forksys && psp->pr_sysarg[0] == 2));
623
624 struct ps_prochandle *C;
625 const lwpstatus_t *csp;
626 char sysname[32];
627 int gcode;
628 char c;
629
630 mdb_dprintf(MDB_DBG_TGT, "parent %s: errno=%d rv1=%ld rv2=%ld\n",
631 proc_sysname(psp->pr_what, sysname, sizeof (sysname)),
632 psp->pr_errno, psp->pr_rval1, psp->pr_rval2);
633
634 if (psp->pr_errno != 0) {
635 (void) mdb_tgt_continue(t, NULL);
636 return; /* fork failed */
637 }
638
639 /*
640 * If forkmode is ASK and stdout is a terminal, then ask the user to
641 * explicitly set the fork behavior for this particular fork.
642 */
643 if (mdb.m_forkmode == MDB_FM_ASK && mdb.m_term != NULL) {
644 mdb_iob_printf(mdb.m_err, "%s: %s detected: follow (p)arent "
645 "or (c)hild? ", mdb.m_pname, sysname);
646 mdb_iob_flush(mdb.m_err);
647
648 while (IOP_READ(mdb.m_term, &c, sizeof (c)) == sizeof (c)) {
649 if (c == 'P' || c == 'p') {
650 mdb_iob_printf(mdb.m_err, "%c\n", c);
651 follow_parent = TRUE;
652 break;
653 } else if (c == 'C' || c == 'c') {
654 mdb_iob_printf(mdb.m_err, "%c\n", c);
655 follow_parent = FALSE;
656 break;
657 }
658 }
659 }
660
661 /*
662 * The parent is now stopped on exit from its fork call. We must now
663 * grab the child on its return from fork in order to manipulate it.
664 */
665 if ((C = Pgrab(psp->pr_rval1, PGRAB_RETAIN, &gcode)) == NULL) {
666 warn("failed to grab forked child process %ld: %s\n",
667 psp->pr_rval1, Pgrab_error(gcode));
668 return; /* just stop if we failed to grab the child */
669 }
670
671 /*
672 * We may have grabbed the child and stopped it prematurely before it
673 * stopped on exit from fork. If so, wait up to 1 sec for it to settle.
674 */
675 if (Pstatus(C)->pr_lwp.pr_why != PR_SYSEXIT)
676 (void) Pwait(C, MILLISEC);
677
678 csp = &Pstatus(C)->pr_lwp;
679
680 if (csp->pr_why != PR_SYSEXIT ||
681 (csp->pr_what != SYS_vfork && csp->pr_what != SYS_forksys)) {
682 warn("forked child process %ld did not stop on exit from "
683 "fork as expected\n", psp->pr_rval1);
684 }
685
686 warn("target forked child process %ld (debugger following %s)\n",
687 psp->pr_rval1, follow_parent ? "parent" : "child");
688
689 (void) Punsetflags(C, PR_ASYNC); /* require synchronous mode */
690 (void) Psetflags(C, PR_BPTADJ); /* always adjust eip on x86 */
691 (void) Prd_agent(C); /* initialize librtld_db */
692
693 /*
694 * At the time pt_fork() is called, the target event engine has already
695 * disarmed the specifiers on the active list, clearing out events in
696 * the parent process. However, this means that events that change
697 * the address space (e.g. breakpoints) have not been effectively
698 * disarmed in the child since its address space reflects the state of
699 * the process at the time of fork when events were armed. We must
700 * therefore handle this as a special case and re-invoke the disarm
701 * callback of each active specifier to clean out the child process.
702 */
703 if (!is_vfork) {
704 for (t->t_pshandle = C, sep = mdb_list_next(&t->t_active);
705 sep != NULL; sep = mdb_list_next(sep)) {
706 if (sep->se_state == MDB_TGT_SPEC_ACTIVE)
707 (void) sep->se_ops->se_disarm(t, sep);
708 }
709
710 t->t_pshandle = P; /* restore pshandle to parent */
711 }
712
713 /*
714 * If we're following the parent process, we need to temporarily change
715 * t_pshandle to refer to the child handle C so that we can clear out
716 * all the events in the child prior to releasing it below. If we are
717 * tracing a vfork, we also need to explicitly wait for the child to
718 * exec, exit, or die before we can reset and continue the parent. We
719 * avoid having to deal with the vfork child forking again by clearing
720 * PR_FORK and setting PR_RLC; if it does fork it will effectively be
721 * released from our control and we will continue following the parent.
722 */
723 if (follow_parent) {
724 if (is_vfork) {
725 mdb_tgt_status_t status;
726
727 ASSERT(psp->pr_flags & PR_VFORKP);
728 mdb_tgt_sespec_idle_all(t, EBUSY, FALSE);
729 t->t_pshandle = C;
730
731 (void) Psysexit(C, SYS_execve, TRUE);
732
733 (void) Punsetflags(C, PR_FORK | PR_KLC);
734 (void) Psetflags(C, PR_RLC);
735
736 do {
737 if (pt_setrun(t, &status, 0) == -1 ||
738 status.st_state == MDB_TGT_UNDEAD ||
739 status.st_state == MDB_TGT_LOST)
740 break; /* failure or process died */
741
742 } while (csp->pr_why != PR_SYSEXIT ||
743 csp->pr_errno != 0 || csp->pr_what != SYS_execve);
744 } else
745 t->t_pshandle = C;
746 }
747
748 /*
749 * If we are following the child, destroy any active libthread_db
750 * handle before we release the parent process.
751 */
752 if (!follow_parent) {
753 PTL_DTOR(t);
754 pt->p_tdb_ops = NULL;
755 pt->p_ptl_ops = &proc_lwp_ops;
756 pt->p_ptl_hdl = NULL;
757 }
758
759 /*
760 * Idle all events to make sure the address space and tracing flags are
761 * restored, and then release the process we are not tracing. If we
762 * are following the child of a vfork, we push the parent's pshandle
763 * on to a list of vfork parents to be released when we exec or exit.
764 */
765 if (is_vfork && !follow_parent) {
766 pt_vforkp_t *vfp = mdb_alloc(sizeof (pt_vforkp_t), UM_SLEEP);
767
768 ASSERT(psp->pr_flags & PR_VFORKP);
769 vfp->p_pshandle = P;
770 mdb_list_append(&pt->p_vforkp, vfp);
771 mdb_tgt_sespec_idle_all(t, EBUSY, FALSE);
772
773 } else {
774 mdb_tgt_sespec_idle_all(t, EBUSY, FALSE);
775 Prelease(t->t_pshandle, PRELEASE_CLEAR);
776 if (!follow_parent)
777 pt_release_parents(t);
778 }
779
780 /*
781 * Now that all the hard stuff is done, switch t_pshandle back to the
782 * process we are following and reset our events to the ACTIVE state.
783 * If we are following the child, reset the libthread_db handle as well
784 * as the rtld agent.
785 */
786 if (follow_parent)
787 t->t_pshandle = P;
788 else {
789 t->t_pshandle = C;
790 pt->p_rtld = Prd_agent(C);
791 (void) Pobject_iter(t->t_pshandle, (proc_map_f *)thr_check, t);
792 }
793
794 (void) mdb_tgt_sespec_activate_all(t);
795 (void) mdb_tgt_continue(t, NULL);
796 }
797
798 /*ARGSUSED*/
799 static void
pt_exec(mdb_tgt_t * t,int vid,void * private)800 pt_exec(mdb_tgt_t *t, int vid, void *private)
801 {
802 struct ps_prochandle *P = t->t_pshandle;
803 const pstatus_t *psp = Pstatus(P);
804 pt_data_t *pt = t->t_data;
805 int follow_exec = mdb.m_execmode == MDB_EM_FOLLOW;
806 pid_t pid = psp->pr_pid;
807
808 char execname[MAXPATHLEN];
809 mdb_sespec_t *sep, *nsep;
810 mdb_io_t *io;
811 char c;
812
813 mdb_dprintf(MDB_DBG_TGT, "exit from %s: errno=%d\n", proc_sysname(
814 psp->pr_lwp.pr_what, execname, sizeof (execname)),
815 psp->pr_lwp.pr_errno);
816
817 if (psp->pr_lwp.pr_errno != 0) {
818 (void) mdb_tgt_continue(t, NULL);
819 return; /* exec failed */
820 }
821
822 /*
823 * If execmode is ASK and stdout is a terminal, then ask the user to
824 * explicitly set the exec behavior for this particular exec. If
825 * Pstate() still shows PS_LOST, we are being called from pt_setrun()
826 * directly and therefore we must resume the terminal since it is still
827 * in the suspended state as far as tgt_continue() is concerned.
828 */
829 if (mdb.m_execmode == MDB_EM_ASK && mdb.m_term != NULL) {
830 if (Pstate(P) == PS_LOST)
831 IOP_RESUME(mdb.m_term);
832
833 mdb_iob_printf(mdb.m_err, "%s: %s detected: (f)ollow new "
834 "program or (s)top? ", mdb.m_pname, execname);
835 mdb_iob_flush(mdb.m_err);
836
837 while (IOP_READ(mdb.m_term, &c, sizeof (c)) == sizeof (c)) {
838 if (c == 'F' || c == 'f') {
839 mdb_iob_printf(mdb.m_err, "%c\n", c);
840 follow_exec = TRUE;
841 break;
842 } else if (c == 'S' || c == 's') {
843 mdb_iob_printf(mdb.m_err, "%c\n", c);
844 follow_exec = FALSE;
845 break;
846 }
847 }
848
849 if (Pstate(P) == PS_LOST)
850 IOP_SUSPEND(mdb.m_term);
851 }
852
853 pt_release_parents(t); /* release any waiting vfork parents */
854 pt_pre_detach(t, FALSE); /* remove our breakpoints and idle events */
855 Preset_maps(P); /* libproc must delete mappings and symtabs */
856 pt_close_aout(t); /* free pt symbol tables and GElf file data */
857
858 /*
859 * If we lost control of the process across the exec and are not able
860 * to reopen it, we have no choice but to clear the matched event list
861 * and wait for the user to quit or otherwise release the process.
862 */
863 if (Pstate(P) == PS_LOST && Preopen(P) == -1) {
864 int error = errno;
865
866 warn("lost control of PID %d due to exec of %s executable\n",
867 (int)pid, error == EOVERFLOW ? "64-bit" : "set-id");
868
869 for (sep = t->t_matched; sep != T_SE_END; sep = nsep) {
870 nsep = sep->se_matched;
871 sep->se_matched = NULL;
872 mdb_tgt_sespec_rele(t, sep);
873 }
874
875 if (error != EOVERFLOW)
876 return; /* just stop if we exec'd a set-id executable */
877 }
878
879 if (Pstate(P) != PS_LOST) {
880 if (Pexecname(P, execname, sizeof (execname)) == NULL) {
881 (void) mdb_iob_snprintf(execname, sizeof (execname),
882 "/proc/%d/object/a.out", (int)pid);
883 }
884
885 if (follow_exec == FALSE || psp->pr_dmodel == PR_MODEL_NATIVE)
886 warn("target performed exec of %s\n", execname);
887
888 io = mdb_fdio_create_path(NULL, execname, pt->p_oflags, 0);
889 if (io == NULL) {
890 warn("failed to open %s", execname);
891 warn("a.out symbol tables will not be available\n");
892 } else if (pt_open_aout(t, io) == NULL) {
893 (void) mdb_dis_select(pt_disasm(NULL));
894 mdb_io_destroy(io);
895 } else
896 (void) mdb_dis_select(pt_disasm(&pt->p_file->gf_ehdr));
897 }
898
899 /*
900 * We reset our libthread_db state here, but deliberately do NOT call
901 * PTL_DTOR because we do not want to call libthread_db's td_ta_delete.
902 * This interface is hopelessly broken in that it writes to the process
903 * address space (which we do not want it to do after an exec) and it
904 * doesn't bother deallocating any of its storage anyway.
905 */
906 pt->p_tdb_ops = NULL;
907 pt->p_ptl_ops = &proc_lwp_ops;
908 pt->p_ptl_hdl = NULL;
909
910 if (follow_exec && psp->pr_dmodel != PR_MODEL_NATIVE) {
911 const char *argv[3];
912 char *state, *env;
913 char pidarg[16];
914 size_t envlen;
915
916 if (realpath(getexecname(), execname) == NULL) {
917 warn("cannot follow PID %d -- failed to resolve "
918 "debugger pathname for re-exec", (int)pid);
919 return;
920 }
921
922 warn("restarting debugger to follow PID %d ...\n", (int)pid);
923 mdb_dprintf(MDB_DBG_TGT, "re-exec'ing %s\n", execname);
924
925 (void) mdb_snprintf(pidarg, sizeof (pidarg), "-p%d", (int)pid);
926
927 state = mdb_get_config();
928 envlen = strlen(MDB_CONFIG_ENV_VAR) + 1 + strlen(state) + 1;
929 env = mdb_alloc(envlen, UM_SLEEP);
930 (void) snprintf(env, envlen,
931 "%s=%s", MDB_CONFIG_ENV_VAR, state);
932
933 (void) putenv(env);
934
935 argv[0] = mdb.m_pname;
936 argv[1] = pidarg;
937 argv[2] = NULL;
938
939 if (mdb.m_term != NULL)
940 IOP_SUSPEND(mdb.m_term);
941
942 Prelease(P, PRELEASE_CLEAR | PRELEASE_HANG);
943 (void) execv(execname, (char *const *)argv);
944 warn("failed to re-exec debugger");
945
946 if (mdb.m_term != NULL)
947 IOP_RESUME(mdb.m_term);
948
949 t->t_pshandle = pt->p_idlehandle;
950 return;
951 }
952
953 pt_post_attach(t); /* install tracing flags and activate events */
954 pt_activate_common(t); /* initialize librtld_db and libthread_db */
955
956 if (psp->pr_dmodel != PR_MODEL_NATIVE && mdb.m_term != NULL) {
957 warn("loadable dcmds will not operate on non-native %d-bit "
958 "data model\n", psp->pr_dmodel == PR_MODEL_ILP32 ? 32 : 64);
959 warn("use ::release -a and then run mdb -p %d to restart "
960 "debugger\n", (int)pid);
961 }
962
963 if (follow_exec)
964 (void) mdb_tgt_continue(t, NULL);
965 }
966
967 static int
pt_setflags(mdb_tgt_t * t,int flags)968 pt_setflags(mdb_tgt_t *t, int flags)
969 {
970 pt_data_t *pt = t->t_data;
971
972 if ((flags ^ t->t_flags) & MDB_TGT_F_RDWR) {
973 int mode = (flags & MDB_TGT_F_RDWR) ? O_RDWR : O_RDONLY;
974 mdb_io_t *io;
975
976 if (pt->p_fio == NULL)
977 return (set_errno(EMDB_NOEXEC));
978
979 io = mdb_fdio_create_path(NULL, IOP_NAME(pt->p_fio), mode, 0);
980
981 if (io == NULL)
982 return (-1); /* errno is set for us */
983
984 t->t_flags = (t->t_flags & ~MDB_TGT_F_RDWR) |
985 (flags & MDB_TGT_F_RDWR);
986
987 pt->p_fio = mdb_io_hold(io);
988 mdb_io_rele(pt->p_file->gf_io);
989 pt->p_file->gf_io = pt->p_fio;
990 }
991
992 if (flags & MDB_TGT_F_FORCE) {
993 t->t_flags |= MDB_TGT_F_FORCE;
994 pt->p_gflags |= PGRAB_FORCE;
995 }
996
997 return (0);
998 }
999
1000 /*ARGSUSED*/
1001 static int
pt_frame(void * arglim,uintptr_t pc,uint_t argc,const long * argv,const mdb_tgt_gregset_t * gregs)1002 pt_frame(void *arglim, uintptr_t pc, uint_t argc, const long *argv,
1003 const mdb_tgt_gregset_t *gregs)
1004 {
1005 argc = MIN(argc, (uint_t)(uintptr_t)arglim);
1006 mdb_printf("%a(", pc);
1007
1008 if (argc != 0) {
1009 mdb_printf("%lr", *argv++);
1010 for (argc--; argc != 0; argc--)
1011 mdb_printf(", %lr", *argv++);
1012 }
1013
1014 mdb_printf(")\n");
1015 return (0);
1016 }
1017
1018 static int
pt_framev(void * arglim,uintptr_t pc,uint_t argc,const long * argv,const mdb_tgt_gregset_t * gregs)1019 pt_framev(void *arglim, uintptr_t pc, uint_t argc, const long *argv,
1020 const mdb_tgt_gregset_t *gregs)
1021 {
1022 argc = MIN(argc, (uint_t)(uintptr_t)arglim);
1023 #if defined(__i386) || defined(__amd64)
1024 mdb_printf("%0?lr %a(", gregs->gregs[R_FP], pc);
1025 #else
1026 mdb_printf("%0?lr %a(", gregs->gregs[R_SP], pc);
1027 #endif
1028 if (argc != 0) {
1029 mdb_printf("%lr", *argv++);
1030 for (argc--; argc != 0; argc--)
1031 mdb_printf(", %lr", *argv++);
1032 }
1033
1034 mdb_printf(")\n");
1035 return (0);
1036 }
1037
1038 static int
pt_framer(void * arglim,uintptr_t pc,uint_t argc,const long * argv,const mdb_tgt_gregset_t * gregs)1039 pt_framer(void *arglim, uintptr_t pc, uint_t argc, const long *argv,
1040 const mdb_tgt_gregset_t *gregs)
1041 {
1042 if (pt_frameregs(arglim, pc, argc, argv, gregs, pc == PC_FAKE) == -1) {
1043 /*
1044 * Use verbose format if register format is not supported.
1045 */
1046 return (pt_framev(arglim, pc, argc, argv, gregs));
1047 }
1048
1049 return (0);
1050 }
1051
1052 /*ARGSUSED*/
1053 static int
pt_stack_common(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv,mdb_tgt_stack_f * func,prgreg_t saved_pc)1054 pt_stack_common(uintptr_t addr, uint_t flags, int argc,
1055 const mdb_arg_t *argv, mdb_tgt_stack_f *func, prgreg_t saved_pc)
1056 {
1057 void *arg = (void *)(uintptr_t)mdb.m_nargs;
1058 mdb_tgt_t *t = mdb.m_target;
1059 mdb_tgt_gregset_t gregs;
1060
1061 if (argc != 0) {
1062 if (argv->a_type == MDB_TYPE_CHAR || argc > 1)
1063 return (DCMD_USAGE);
1064
1065 arg = (void *)(uintptr_t)mdb_argtoull(argv);
1066 }
1067
1068 if (t->t_pshandle == NULL || Pstate(t->t_pshandle) == PS_IDLE) {
1069 mdb_warn("no process active\n");
1070 return (DCMD_ERR);
1071 }
1072
1073 /*
1074 * In the universe of sparcv7, sparcv9, ia32, and amd64 this code can be
1075 * common: <sys/procfs_isa.h> conveniently #defines R_FP to be the
1076 * appropriate register we need to set in order to perform a stack
1077 * traceback from a given frame address.
1078 */
1079 if (flags & DCMD_ADDRSPEC) {
1080 bzero(&gregs, sizeof (gregs));
1081 gregs.gregs[R_FP] = addr;
1082 #ifdef __sparc
1083 gregs.gregs[R_I7] = saved_pc;
1084 #endif /* __sparc */
1085 } else if (PTL_GETREGS(t, PTL_TID(t), gregs.gregs) != 0) {
1086 mdb_warn("failed to get current register set");
1087 return (DCMD_ERR);
1088 }
1089
1090 (void) mdb_tgt_stack_iter(t, &gregs, func, arg);
1091 return (DCMD_OK);
1092 }
1093
1094 static int
pt_stack(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1095 pt_stack(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1096 {
1097 return (pt_stack_common(addr, flags, argc, argv, pt_frame, 0));
1098 }
1099
1100 static int
pt_stackv(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1101 pt_stackv(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1102 {
1103 return (pt_stack_common(addr, flags, argc, argv, pt_framev, 0));
1104 }
1105
1106 static int
pt_stackr(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1107 pt_stackr(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1108 {
1109 /*
1110 * Force printing of first register window, by setting the
1111 * saved pc (%i7) to PC_FAKE.
1112 */
1113 return (pt_stack_common(addr, flags, argc, argv, pt_framer, PC_FAKE));
1114 }
1115
1116 /*ARGSUSED*/
1117 static int
pt_ignored(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1118 pt_ignored(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1119 {
1120 struct ps_prochandle *P = mdb.m_target->t_pshandle;
1121 char buf[PRSIGBUFSZ];
1122
1123 if ((flags & DCMD_ADDRSPEC) || argc != 0)
1124 return (DCMD_USAGE);
1125
1126 if (P == NULL) {
1127 mdb_warn("no process is currently active\n");
1128 return (DCMD_ERR);
1129 }
1130
1131 mdb_printf("%s\n", proc_sigset2str(&Pstatus(P)->pr_sigtrace, " ",
1132 FALSE, buf, sizeof (buf)));
1133
1134 return (DCMD_OK);
1135 }
1136
1137 /*ARGSUSED*/
1138 static int
pt_lwpid(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1139 pt_lwpid(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1140 {
1141 struct ps_prochandle *P = mdb.m_target->t_pshandle;
1142
1143 if ((flags & DCMD_ADDRSPEC) || argc != 0)
1144 return (DCMD_USAGE);
1145
1146 if (P == NULL) {
1147 mdb_warn("no process is currently active\n");
1148 return (DCMD_ERR);
1149 }
1150
1151 mdb_printf("%d\n", Pstatus(P)->pr_lwp.pr_lwpid);
1152 return (DCMD_OK);
1153 }
1154
1155 static int
pt_print_lwpid(int * n,const lwpstatus_t * psp)1156 pt_print_lwpid(int *n, const lwpstatus_t *psp)
1157 {
1158 struct ps_prochandle *P = mdb.m_target->t_pshandle;
1159 int nlwp = Pstatus(P)->pr_nlwp;
1160
1161 if (*n == nlwp - 2)
1162 mdb_printf("%d and ", (int)psp->pr_lwpid);
1163 else if (*n == nlwp - 1)
1164 mdb_printf("%d are", (int)psp->pr_lwpid);
1165 else
1166 mdb_printf("%d, ", (int)psp->pr_lwpid);
1167
1168 (*n)++;
1169 return (0);
1170 }
1171
1172 /*ARGSUSED*/
1173 static int
pt_lwpids(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1174 pt_lwpids(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1175 {
1176 struct ps_prochandle *P = mdb.m_target->t_pshandle;
1177 int n = 0;
1178
1179 if (P == NULL) {
1180 mdb_warn("no process is currently active\n");
1181 return (DCMD_ERR);
1182 }
1183
1184 switch (Pstatus(P)->pr_nlwp) {
1185 case 0:
1186 mdb_printf("no lwps are");
1187 break;
1188 case 1:
1189 mdb_printf("lwpid %d is the only lwp",
1190 Pstatus(P)->pr_lwp.pr_lwpid);
1191 break;
1192 default:
1193 mdb_printf("lwpids ");
1194 (void) Plwp_iter(P, (proc_lwp_f *)pt_print_lwpid, &n);
1195 }
1196
1197 switch (Pstate(P)) {
1198 case PS_DEAD:
1199 mdb_printf(" in core of process %d.\n", Pstatus(P)->pr_pid);
1200 break;
1201 case PS_IDLE:
1202 mdb_printf(" in idle target.\n");
1203 break;
1204 default:
1205 mdb_printf(" in process %d.\n", (int)Pstatus(P)->pr_pid);
1206 break;
1207 }
1208
1209 return (DCMD_OK);
1210 }
1211
1212 /*ARGSUSED*/
1213 static int
pt_ignore(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1214 pt_ignore(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1215 {
1216 pt_data_t *pt = mdb.m_target->t_data;
1217
1218 if (!(flags & DCMD_ADDRSPEC) || argc != 0)
1219 return (DCMD_USAGE);
1220
1221 if (addr < 1 || addr > pt->p_maxsig) {
1222 mdb_warn("invalid signal number -- 0t%lu\n", addr);
1223 return (DCMD_ERR);
1224 }
1225
1226 (void) mdb_tgt_vespec_iter(mdb.m_target, pt_ignore_sig, (void *)addr);
1227 return (DCMD_OK);
1228 }
1229
1230 /*ARGSUSED*/
1231 static int
pt_attach(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1232 pt_attach(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1233 {
1234 mdb_tgt_t *t = mdb.m_target;
1235 pt_data_t *pt = t->t_data;
1236 int state, perr;
1237
1238 if (!(flags & DCMD_ADDRSPEC) && argc == 0)
1239 return (DCMD_USAGE);
1240
1241 if (((flags & DCMD_ADDRSPEC) && argc != 0) || argc > 1 ||
1242 (argc != 0 && argv->a_type != MDB_TYPE_STRING))
1243 return (DCMD_USAGE);
1244
1245 if (t->t_pshandle != NULL && Pstate(t->t_pshandle) != PS_IDLE) {
1246 mdb_warn("debugger is already attached to a %s\n",
1247 (Pstate(t->t_pshandle) == PS_DEAD) ? "core" : "process");
1248 return (DCMD_ERR);
1249 }
1250
1251 if (pt->p_fio == NULL) {
1252 mdb_warn("attach requires executable to be specified on "
1253 "command-line (or use -p)\n");
1254 return (DCMD_ERR);
1255 }
1256
1257 if (flags & DCMD_ADDRSPEC)
1258 t->t_pshandle = Pgrab((pid_t)addr, pt->p_gflags, &perr);
1259 else
1260 t->t_pshandle = proc_arg_grab(argv->a_un.a_str,
1261 PR_ARG_ANY, pt->p_gflags, &perr);
1262
1263 if (t->t_pshandle == NULL) {
1264 t->t_pshandle = pt->p_idlehandle;
1265 mdb_warn("cannot attach: %s\n", Pgrab_error(perr));
1266 return (DCMD_ERR);
1267 }
1268
1269 state = Pstate(t->t_pshandle);
1270 if (state != PS_DEAD && state != PS_IDLE) {
1271 (void) Punsetflags(t->t_pshandle, PR_KLC);
1272 (void) Psetflags(t->t_pshandle, PR_RLC);
1273 pt_post_attach(t);
1274 pt_activate_common(t);
1275 }
1276
1277 (void) mdb_tgt_status(t, &t->t_status);
1278 mdb_module_load_all(0);
1279 return (DCMD_OK);
1280 }
1281
1282 static int
pt_regstatus(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1283 pt_regstatus(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1284 {
1285 mdb_tgt_t *t = mdb.m_target;
1286
1287 if (t->t_pshandle != NULL) {
1288 const pstatus_t *psp = Pstatus(t->t_pshandle);
1289 int cursig = psp->pr_lwp.pr_cursig;
1290 char signame[SIG2STR_MAX];
1291 int state = Pstate(t->t_pshandle);
1292
1293 if (state != PS_DEAD && state != PS_IDLE)
1294 mdb_printf("process id = %d\n", psp->pr_pid);
1295 else
1296 mdb_printf("no process\n");
1297
1298 if (cursig != 0 && sig2str(cursig, signame) == 0)
1299 mdb_printf("SIG%s: %s\n", signame, strsignal(cursig));
1300 }
1301
1302 return (pt_regs(addr, flags, argc, argv));
1303 }
1304
1305 static int
pt_thread_name(mdb_tgt_t * t,mdb_tgt_tid_t tid,char * buf,size_t bufsize)1306 pt_thread_name(mdb_tgt_t *t, mdb_tgt_tid_t tid, char *buf, size_t bufsize)
1307 {
1308 char name[THREAD_NAME_MAX];
1309
1310 buf[0] = '\0';
1311
1312 if (t->t_pshandle == NULL ||
1313 Plwp_getname(t->t_pshandle, tid, name, sizeof (name)) != 0 ||
1314 name[0] == '\0') {
1315 if (mdb_snprintf(buf, bufsize, "%lu", tid) > bufsize) {
1316 return (set_errno(EMDB_NAME2BIG));
1317 }
1318
1319 return (0);
1320 }
1321
1322 if (mdb_snprintf(buf, bufsize, "%lu [%s]", tid, name) > bufsize) {
1323 return (set_errno(EMDB_NAME2BIG));
1324 }
1325
1326 return (0);
1327 }
1328
1329 static int
pt_findstack(uintptr_t tid,uint_t flags,int argc,const mdb_arg_t * argv)1330 pt_findstack(uintptr_t tid, uint_t flags, int argc, const mdb_arg_t *argv)
1331 {
1332 mdb_tgt_t *t = mdb.m_target;
1333 mdb_tgt_gregset_t gregs;
1334 int showargs = 0;
1335 int count;
1336 uintptr_t pc, sp;
1337 char name[128];
1338
1339 if (!(flags & DCMD_ADDRSPEC))
1340 return (DCMD_USAGE);
1341
1342 count = mdb_getopts(argc, argv, 'v', MDB_OPT_SETBITS, TRUE, &showargs,
1343 NULL);
1344 argc -= count;
1345 argv += count;
1346
1347 if (argc > 1 || (argc == 1 && argv->a_type != MDB_TYPE_STRING))
1348 return (DCMD_USAGE);
1349
1350 if (PTL_GETREGS(t, tid, gregs.gregs) != 0) {
1351 mdb_warn("failed to get register set for thread %p", tid);
1352 return (DCMD_ERR);
1353 }
1354
1355 pc = gregs.gregs[R_PC];
1356 #if defined(__i386) || defined(__amd64)
1357 sp = gregs.gregs[R_FP];
1358 #else
1359 sp = gregs.gregs[R_SP];
1360 #endif
1361
1362 (void) pt_thread_name(t, tid, name, sizeof (name));
1363
1364 mdb_printf("stack pointer for thread %s: %p\n", name, sp);
1365 if (pc != 0)
1366 mdb_printf("[ %0?lr %a() ]\n", sp, pc);
1367
1368 (void) mdb_inc_indent(2);
1369 mdb_set_dot(sp);
1370
1371 if (argc == 1)
1372 (void) mdb_eval(argv->a_un.a_str);
1373 else if (showargs)
1374 (void) mdb_eval("<.$C");
1375 else
1376 (void) mdb_eval("<.$C0");
1377
1378 (void) mdb_dec_indent(2);
1379 return (DCMD_OK);
1380 }
1381
1382 /*ARGSUSED*/
1383 static int
pt_gcore(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1384 pt_gcore(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1385 {
1386 mdb_tgt_t *t = mdb.m_target;
1387 char *prefix = "core";
1388 char *content_str = NULL;
1389 core_content_t content = CC_CONTENT_DEFAULT;
1390 size_t size;
1391 char *fname;
1392 pid_t pid;
1393
1394 if (flags & DCMD_ADDRSPEC)
1395 return (DCMD_USAGE);
1396
1397 if (mdb_getopts(argc, argv,
1398 'o', MDB_OPT_STR, &prefix,
1399 'c', MDB_OPT_STR, &content_str, NULL) != argc)
1400 return (DCMD_USAGE);
1401
1402 if (content_str != NULL &&
1403 (proc_str2content(content_str, &content) != 0 ||
1404 content == CC_CONTENT_INVALID)) {
1405 mdb_warn("invalid content string '%s'\n", content_str);
1406 return (DCMD_ERR);
1407 }
1408
1409 if (t->t_pshandle == NULL) {
1410 mdb_warn("no process active\n");
1411 return (DCMD_ERR);
1412 }
1413
1414 pid = Pstatus(t->t_pshandle)->pr_pid;
1415 size = 1 + mdb_snprintf(NULL, 0, "%s.%d", prefix, (int)pid);
1416 fname = mdb_alloc(size, UM_SLEEP | UM_GC);
1417 (void) mdb_snprintf(fname, size, "%s.%d", prefix, (int)pid);
1418
1419 if (Pgcore(t->t_pshandle, fname, content) != 0) {
1420 /*
1421 * Short writes during dumping are specifically described by
1422 * EBADE, just as ZFS uses this otherwise-unused code for
1423 * checksum errors. Translate to and mdb errno.
1424 */
1425 if (errno == EBADE)
1426 (void) set_errno(EMDB_SHORTWRITE);
1427 mdb_warn("couldn't dump core");
1428 return (DCMD_ERR);
1429 }
1430
1431 mdb_warn("%s dumped\n", fname);
1432
1433 return (DCMD_OK);
1434 }
1435
1436 /*ARGSUSED*/
1437 static int
pt_kill(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1438 pt_kill(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1439 {
1440 mdb_tgt_t *t = mdb.m_target;
1441 pt_data_t *pt = t->t_data;
1442 int state;
1443
1444 if ((flags & DCMD_ADDRSPEC) || argc != 0)
1445 return (DCMD_USAGE);
1446
1447 if (t->t_pshandle != NULL &&
1448 (state = Pstate(t->t_pshandle)) != PS_DEAD && state != PS_IDLE) {
1449 mdb_warn("victim process PID %d forcibly terminated\n",
1450 (int)Pstatus(t->t_pshandle)->pr_pid);
1451 pt_pre_detach(t, TRUE);
1452 pt_release_parents(t);
1453 Prelease(t->t_pshandle, PRELEASE_KILL);
1454 t->t_pshandle = pt->p_idlehandle;
1455 (void) mdb_tgt_status(t, &t->t_status);
1456 mdb.m_flags &= ~(MDB_FL_VCREATE | MDB_FL_JOBCTL);
1457 } else
1458 mdb_warn("no victim process is currently under control\n");
1459
1460 return (DCMD_OK);
1461 }
1462
1463 /*ARGSUSED*/
1464 static int
pt_detach(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1465 pt_detach(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1466 {
1467 mdb_tgt_t *t = mdb.m_target;
1468 pt_data_t *pt = t->t_data;
1469 int rflags = pt->p_rflags;
1470
1471 if (argc != 0 && argv->a_type == MDB_TYPE_STRING &&
1472 strcmp(argv->a_un.a_str, "-a") == 0) {
1473 rflags = PRELEASE_HANG | PRELEASE_CLEAR;
1474 argv++;
1475 argc--;
1476 }
1477
1478 if ((flags & DCMD_ADDRSPEC) || argc != 0)
1479 return (DCMD_USAGE);
1480
1481 if (t->t_pshandle == NULL || Pstate(t->t_pshandle) == PS_IDLE) {
1482 mdb_warn("debugger is not currently attached to a process "
1483 "or core file\n");
1484 return (DCMD_ERR);
1485 }
1486
1487 pt_pre_detach(t, TRUE);
1488 pt_release_parents(t);
1489 Prelease(t->t_pshandle, rflags);
1490 t->t_pshandle = pt->p_idlehandle;
1491 (void) mdb_tgt_status(t, &t->t_status);
1492 mdb.m_flags &= ~(MDB_FL_VCREATE | MDB_FL_JOBCTL);
1493
1494 return (DCMD_OK);
1495 }
1496
1497 static uintmax_t
reg_disc_get(const mdb_var_t * v)1498 reg_disc_get(const mdb_var_t *v)
1499 {
1500 mdb_tgt_t *t = MDB_NV_COOKIE(v);
1501 mdb_tgt_tid_t tid = PTL_TID(t);
1502 mdb_tgt_reg_t r = 0;
1503
1504 if (tid != (mdb_tgt_tid_t)-1L)
1505 (void) mdb_tgt_getareg(t, tid, mdb_nv_get_name(v), &r);
1506
1507 return (r);
1508 }
1509
1510 static void
reg_disc_set(mdb_var_t * v,uintmax_t r)1511 reg_disc_set(mdb_var_t *v, uintmax_t r)
1512 {
1513 mdb_tgt_t *t = MDB_NV_COOKIE(v);
1514 mdb_tgt_tid_t tid = PTL_TID(t);
1515
1516 if (tid != (mdb_tgt_tid_t)-1L && mdb_tgt_putareg(t, tid,
1517 mdb_nv_get_name(v), r) == -1)
1518 mdb_warn("failed to modify %%%s register", mdb_nv_get_name(v));
1519 }
1520
1521 static void
pt_print_reason(const lwpstatus_t * psp)1522 pt_print_reason(const lwpstatus_t *psp)
1523 {
1524 char name[SIG2STR_MAX + 4]; /* enough for SIG+name+\0, syscall or flt */
1525 const char *desc;
1526
1527 switch (psp->pr_why) {
1528 case PR_REQUESTED:
1529 mdb_printf("stopped by debugger");
1530 break;
1531 case PR_SIGNALLED:
1532 mdb_printf("stopped on %s (%s)", proc_signame(psp->pr_what,
1533 name, sizeof (name)), strsignal(psp->pr_what));
1534 break;
1535 case PR_SYSENTRY:
1536 mdb_printf("stopped on entry to %s system call",
1537 proc_sysname(psp->pr_what, name, sizeof (name)));
1538 break;
1539 case PR_SYSEXIT:
1540 mdb_printf("stopped on exit from %s system call",
1541 proc_sysname(psp->pr_what, name, sizeof (name)));
1542 break;
1543 case PR_JOBCONTROL:
1544 mdb_printf("stopped by job control");
1545 break;
1546 case PR_FAULTED:
1547 if (psp->pr_what == FLTBPT) {
1548 mdb_printf("stopped on a breakpoint");
1549 } else if (psp->pr_what == FLTWATCH) {
1550 switch (psp->pr_info.si_code) {
1551 case TRAP_RWATCH:
1552 desc = "read";
1553 break;
1554 case TRAP_WWATCH:
1555 desc = "write";
1556 break;
1557 case TRAP_XWATCH:
1558 desc = "execute";
1559 break;
1560 default:
1561 desc = "unknown";
1562 }
1563 mdb_printf("stopped %s a watchpoint (%s access to %p)",
1564 psp->pr_info.si_trapafter ? "after" : "on",
1565 desc, psp->pr_info.si_addr);
1566 } else if (psp->pr_what == FLTTRACE) {
1567 mdb_printf("stopped after a single-step");
1568 } else {
1569 mdb_printf("stopped on a %s fault",
1570 proc_fltname(psp->pr_what, name, sizeof (name)));
1571 }
1572 break;
1573 case PR_SUSPENDED:
1574 case PR_CHECKPOINT:
1575 mdb_printf("suspended by the kernel");
1576 break;
1577 default:
1578 mdb_printf("stopped for unknown reason (%d/%d)",
1579 psp->pr_why, psp->pr_what);
1580 }
1581 }
1582
1583 static void
pt_status_dcmd_upanic(prupanic_t * pru)1584 pt_status_dcmd_upanic(prupanic_t *pru)
1585 {
1586 size_t i;
1587
1588 mdb_printf("process panicked\n");
1589 if ((pru->pru_flags & PRUPANIC_FLAG_MSG_ERROR) != 0) {
1590 mdb_printf("warning: process upanic message was bad\n");
1591 return;
1592 }
1593
1594 if ((pru->pru_flags & PRUPANIC_FLAG_MSG_VALID) == 0)
1595 return;
1596
1597 if ((pru->pru_flags & PRUPANIC_FLAG_MSG_TRUNC) != 0) {
1598 mdb_printf("warning: process upanic message truncated\n");
1599 }
1600
1601 mdb_printf("upanic message: ");
1602
1603 for (i = 0; i < PRUPANIC_BUFLEN; i++) {
1604 if (pru->pru_data[i] == '\0')
1605 break;
1606 if (isascii(pru->pru_data[i]) && isprint(pru->pru_data[i])) {
1607 mdb_printf("%c", pru->pru_data[i]);
1608 } else {
1609 mdb_printf("\\x%02x", pru->pru_data[i]);
1610 }
1611 }
1612 mdb_printf("\n");
1613 }
1614
1615 /*ARGSUSED*/
1616 static int
pt_status_dcmd(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1617 pt_status_dcmd(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1618 {
1619 mdb_tgt_t *t = mdb.m_target;
1620 struct ps_prochandle *P = t->t_pshandle;
1621 pt_data_t *pt = t->t_data;
1622
1623 if (P != NULL) {
1624 const psinfo_t *pip = Ppsinfo(P);
1625 const pstatus_t *psp = Pstatus(P);
1626 int cursig = 0, bits = 0, coredump = 0;
1627 int state;
1628 GElf_Sym sym;
1629 uintptr_t panicstr;
1630 char *panicbuf = mdb_alloc(PANIC_BUFSIZE, UM_SLEEP);
1631 const siginfo_t *sip = &(psp->pr_lwp.pr_info);
1632 prupanic_t *pru = NULL;
1633
1634 char execname[MAXPATHLEN], buf[BUFSIZ];
1635 char signame[SIG2STR_MAX + 4]; /* enough for SIG+name+\0 */
1636
1637 mdb_tgt_spec_desc_t desc;
1638 mdb_sespec_t *sep;
1639
1640 struct utsname uts;
1641 prcred_t cred;
1642 psinfo_t pi;
1643
1644 (void) strcpy(uts.nodename, "unknown machine");
1645 (void) Puname(P, &uts);
1646
1647 if (pip != NULL) {
1648 bcopy(pip, &pi, sizeof (psinfo_t));
1649 proc_unctrl_psinfo(&pi);
1650 } else
1651 bzero(&pi, sizeof (psinfo_t));
1652
1653 bits = pi.pr_dmodel == PR_MODEL_ILP32 ? 32 : 64;
1654
1655 state = Pstate(P);
1656 if (psp != NULL && state != PS_UNDEAD && state != PS_IDLE)
1657 cursig = psp->pr_lwp.pr_cursig;
1658
1659 if (state == PS_DEAD && pip != NULL) {
1660 mdb_printf("debugging core file of %s (%d-bit) "
1661 "from %s\n", pi.pr_fname, bits, uts.nodename);
1662
1663 } else if (state == PS_DEAD) {
1664 mdb_printf("debugging core file\n");
1665
1666 } else if (state == PS_IDLE) {
1667 const GElf_Ehdr *ehp = &pt->p_file->gf_ehdr;
1668
1669 mdb_printf("debugging %s file (%d-bit)\n",
1670 ehp->e_type == ET_EXEC ? "executable" : "object",
1671 ehp->e_ident[EI_CLASS] == ELFCLASS32 ? 32 : 64);
1672
1673 } else if (state == PS_UNDEAD && pi.pr_pid == 0) {
1674 mdb_printf("debugging defunct process\n");
1675
1676 } else {
1677 mdb_printf("debugging PID %d (%d-bit)\n",
1678 pi.pr_pid, bits);
1679 }
1680
1681 if (Pexecname(P, execname, sizeof (execname)) != NULL)
1682 mdb_printf("file: %s\n", execname);
1683
1684 if (pip != NULL && state == PS_DEAD)
1685 mdb_printf("initial argv: %s\n", pi.pr_psargs);
1686
1687 if (state != PS_UNDEAD && state != PS_IDLE) {
1688 mdb_printf("threading model: ");
1689 if (pt->p_ptl_ops == &proc_lwp_ops)
1690 mdb_printf("raw lwps\n");
1691 else
1692 mdb_printf("native threads\n");
1693 }
1694
1695 mdb_printf("status: ");
1696 switch (state) {
1697 case PS_RUN:
1698 ASSERT(!(psp->pr_flags & PR_STOPPED));
1699 mdb_printf("process is running");
1700 if (psp->pr_flags & PR_DSTOP)
1701 mdb_printf(", debugger stop directive pending");
1702 mdb_printf("\n");
1703 break;
1704
1705 case PS_STOP:
1706 ASSERT(psp->pr_flags & PR_STOPPED);
1707 pt_print_reason(&psp->pr_lwp);
1708
1709 if (psp->pr_flags & PR_DSTOP)
1710 mdb_printf(", debugger stop directive pending");
1711 if (psp->pr_flags & PR_ASLEEP)
1712 mdb_printf(", sleeping in %s system call",
1713 proc_sysname(psp->pr_lwp.pr_syscall,
1714 signame, sizeof (signame)));
1715
1716 mdb_printf("\n");
1717
1718 for (sep = t->t_matched; sep != T_SE_END;
1719 sep = sep->se_matched) {
1720 mdb_printf("event: %s\n", sep->se_ops->se_info(
1721 t, sep, mdb_list_next(&sep->se_velist),
1722 &desc, buf, sizeof (buf)));
1723 }
1724 break;
1725
1726 case PS_LOST:
1727 mdb_printf("debugger lost control of process\n");
1728 break;
1729
1730 case PS_UNDEAD:
1731 coredump = WIFSIGNALED(pi.pr_wstat) &&
1732 WCOREDUMP(pi.pr_wstat);
1733 /*FALLTHRU*/
1734
1735 case PS_DEAD:
1736 if (cursig == 0 && WIFSIGNALED(pi.pr_wstat))
1737 cursig = WTERMSIG(pi.pr_wstat);
1738
1739 (void) Pupanic(P, &pru);
1740
1741 /*
1742 * Test for upanic first. We can only use pr_wstat == 0
1743 * as a test for gcore if an NT_PRCRED note is present;
1744 * these features were added at the same time in Solaris
1745 * 8.
1746 */
1747 if (pru != NULL) {
1748 pt_status_dcmd_upanic(pru);
1749 Pupanic_free(pru);
1750 } else if (pi.pr_wstat == 0 && Pstate(P) == PS_DEAD &&
1751 Pcred(P, &cred, 1) == 0) {
1752 mdb_printf("process core file generated "
1753 "with gcore(1)\n");
1754 } else if (cursig != 0) {
1755 mdb_printf("process terminated by %s (%s)",
1756 proc_signame(cursig, signame,
1757 sizeof (signame)), strsignal(cursig));
1758
1759 if (sip->si_signo != 0 && SI_FROMUSER(sip) &&
1760 sip->si_pid != 0) {
1761 mdb_printf(", pid=%d uid=%u",
1762 (int)sip->si_pid, sip->si_uid);
1763 if (sip->si_code != 0) {
1764 mdb_printf(" code=%d",
1765 sip->si_code);
1766 }
1767 } else {
1768 switch (sip->si_signo) {
1769 case SIGILL:
1770 case SIGTRAP:
1771 case SIGFPE:
1772 case SIGSEGV:
1773 case SIGBUS:
1774 case SIGEMT:
1775 mdb_printf(", addr=%p",
1776 sip->si_addr);
1777 default:
1778 break;
1779 }
1780 }
1781
1782 if (coredump)
1783 mdb_printf(" - core file dumped");
1784 mdb_printf("\n");
1785 } else {
1786 mdb_printf("process terminated with exit "
1787 "status %d\n", WEXITSTATUS(pi.pr_wstat));
1788 }
1789
1790 if (Plookup_by_name(t->t_pshandle, "libc.so",
1791 "panicstr", &sym) == 0 &&
1792 Pread(t->t_pshandle, &panicstr, sizeof (panicstr),
1793 sym.st_value) == sizeof (panicstr) &&
1794 Pread_string(t->t_pshandle, panicbuf,
1795 PANIC_BUFSIZE, panicstr) > 0) {
1796 mdb_printf("libc panic message: %s",
1797 panicbuf);
1798 }
1799
1800 break;
1801
1802 case PS_IDLE:
1803 mdb_printf("idle\n");
1804 break;
1805
1806 default:
1807 mdb_printf("unknown libproc Pstate: %d\n", Pstate(P));
1808 }
1809 mdb_free(panicbuf, PANIC_BUFSIZE);
1810
1811 } else if (pt->p_file != NULL) {
1812 const GElf_Ehdr *ehp = &pt->p_file->gf_ehdr;
1813
1814 mdb_printf("debugging %s file (%d-bit)\n",
1815 ehp->e_type == ET_EXEC ? "executable" : "object",
1816 ehp->e_ident[EI_CLASS] == ELFCLASS32 ? 32 : 64);
1817 mdb_printf("executable file: %s\n", IOP_NAME(pt->p_fio));
1818 mdb_printf("status: idle\n");
1819 }
1820
1821 return (DCMD_OK);
1822 }
1823
1824 static int
pt_tls(uintptr_t tid,uint_t flags,int argc,const mdb_arg_t * argv)1825 pt_tls(uintptr_t tid, uint_t flags, int argc, const mdb_arg_t *argv)
1826 {
1827 const char *name;
1828 const char *object;
1829 GElf_Sym sym;
1830 mdb_syminfo_t si;
1831 mdb_tgt_t *t = mdb.m_target;
1832
1833 if (!(flags & DCMD_ADDRSPEC) || argc > 1)
1834 return (DCMD_USAGE);
1835
1836 if (argc == 0) {
1837 psaddr_t b;
1838
1839 if (tlsbase(t, tid, PR_LMID_EVERY, MDB_TGT_OBJ_EXEC, &b) != 0) {
1840 mdb_warn("failed to lookup tlsbase for %r", tid);
1841 return (DCMD_ERR);
1842 }
1843
1844 mdb_printf("%lr\n", b);
1845 mdb_set_dot(b);
1846
1847 return (DCMD_OK);
1848 }
1849
1850 name = argv[0].a_un.a_str;
1851 object = MDB_TGT_OBJ_EVERY;
1852
1853 if (pt_lookup_by_name_thr(t, object, name, &sym, &si, tid) != 0) {
1854 mdb_warn("failed to lookup %s", name);
1855 return (DCMD_ABORT); /* avoid repeated failure */
1856 }
1857
1858 if (GELF_ST_TYPE(sym.st_info) != STT_TLS && DCMD_HDRSPEC(flags))
1859 mdb_warn("%s does not refer to thread local storage\n", name);
1860
1861 mdb_printf("%llr\n", sym.st_value);
1862 mdb_set_dot(sym.st_value);
1863
1864 return (DCMD_OK);
1865 }
1866
1867 /*ARGSUSED*/
1868 static int
pt_tmodel(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1869 pt_tmodel(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1870 {
1871 mdb_tgt_t *t = mdb.m_target;
1872 pt_data_t *pt = t->t_data;
1873 const pt_ptl_ops_t *ptl_ops;
1874
1875 if (argc != 1 || argv->a_type != MDB_TYPE_STRING)
1876 return (DCMD_USAGE);
1877
1878 if (strcmp(argv->a_un.a_str, "thread") == 0)
1879 ptl_ops = &proc_tdb_ops;
1880 else if (strcmp(argv->a_un.a_str, "lwp") == 0)
1881 ptl_ops = &proc_lwp_ops;
1882 else
1883 return (DCMD_USAGE);
1884
1885 if (t->t_pshandle != NULL && pt->p_ptl_ops != ptl_ops) {
1886 PTL_DTOR(t);
1887 pt->p_tdb_ops = NULL;
1888 pt->p_ptl_ops = &proc_lwp_ops;
1889 pt->p_ptl_hdl = NULL;
1890
1891 if (ptl_ops == &proc_tdb_ops) {
1892 (void) Pobject_iter(t->t_pshandle, (proc_map_f *)
1893 thr_check, t);
1894 }
1895 }
1896
1897 (void) mdb_tgt_status(t, &t->t_status);
1898 return (DCMD_OK);
1899 }
1900
1901 static const char *
env_match(const char * cmp,const char * nameval)1902 env_match(const char *cmp, const char *nameval)
1903 {
1904 const char *loc;
1905 size_t cmplen = strlen(cmp);
1906
1907 loc = strchr(nameval, '=');
1908 if (loc != NULL && (loc - nameval) == cmplen &&
1909 strncmp(nameval, cmp, cmplen) == 0) {
1910 return (loc + 1);
1911 }
1912
1913 return (NULL);
1914 }
1915
1916 /*ARGSUSED*/
1917 static int
print_env(void * data,struct ps_prochandle * P,uintptr_t addr,const char * nameval)1918 print_env(void *data, struct ps_prochandle *P, uintptr_t addr,
1919 const char *nameval)
1920 {
1921 const char *value;
1922
1923 if (nameval == NULL) {
1924 mdb_printf("<0x%p>\n", addr);
1925 } else {
1926 if (data == NULL)
1927 mdb_printf("%s\n", nameval);
1928 else if ((value = env_match(data, nameval)) != NULL)
1929 mdb_printf("%s\n", value);
1930 }
1931
1932 return (0);
1933 }
1934
1935 /*ARGSUSED*/
1936 static int
pt_getenv(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)1937 pt_getenv(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
1938 {
1939 mdb_tgt_t *t = mdb.m_target;
1940 pt_data_t *pt = t->t_data;
1941 int i;
1942 uint_t opt_t = 0;
1943 mdb_var_t *v;
1944
1945 i = mdb_getopts(argc, argv,
1946 't', MDB_OPT_SETBITS, TRUE, &opt_t, NULL);
1947
1948 argc -= i;
1949 argv += i;
1950
1951 if ((flags & DCMD_ADDRSPEC) || argc > 1)
1952 return (DCMD_USAGE);
1953
1954 if (argc == 1 && argv->a_type != MDB_TYPE_STRING)
1955 return (DCMD_USAGE);
1956
1957 if (opt_t && t->t_pshandle == NULL) {
1958 mdb_warn("no process active\n");
1959 return (DCMD_ERR);
1960 }
1961
1962 if (opt_t && (Pstate(t->t_pshandle) == PS_IDLE ||
1963 Pstate(t->t_pshandle) == PS_UNDEAD)) {
1964 mdb_warn("-t option requires target to be running\n");
1965 return (DCMD_ERR);
1966 }
1967
1968 if (opt_t != 0) {
1969 if (Penv_iter(t->t_pshandle, print_env,
1970 argc == 0 ? NULL : (void *)argv->a_un.a_str) != 0)
1971 return (DCMD_ERR);
1972 } else if (argc == 1) {
1973 if ((v = mdb_nv_lookup(&pt->p_env, argv->a_un.a_str)) == NULL)
1974 return (DCMD_ERR);
1975
1976 ASSERT(strchr(mdb_nv_get_cookie(v), '=') != NULL);
1977 mdb_printf("%s\n", strchr(mdb_nv_get_cookie(v), '=') + 1);
1978 } else {
1979
1980 mdb_nv_rewind(&pt->p_env);
1981 while ((v = mdb_nv_advance(&pt->p_env)) != NULL)
1982 mdb_printf("%s\n", mdb_nv_get_cookie(v));
1983 }
1984
1985 return (DCMD_OK);
1986 }
1987
1988 /*
1989 * Function to set a variable in the internal environment, which is used when
1990 * creating new processes. Note that it is possible that 'nameval' can refer to
1991 * read-only memory, if mdb calls putenv() on an existing value before calling
1992 * this function. While we should avoid this situation, this function is
1993 * designed to be robust in the face of such changes.
1994 */
1995 static void
pt_env_set(pt_data_t * pt,const char * nameval)1996 pt_env_set(pt_data_t *pt, const char *nameval)
1997 {
1998 mdb_var_t *v;
1999 char *equals, *val;
2000 const char *name;
2001 size_t len;
2002
2003 if ((equals = strchr(nameval, '=')) != NULL) {
2004 val = strdup(nameval);
2005 equals = val + (equals - nameval);
2006 } else {
2007 /*
2008 * nameval doesn't contain an equals character. Convert this to
2009 * be 'nameval='.
2010 */
2011 len = strlen(nameval);
2012 val = mdb_alloc(len + 2, UM_SLEEP);
2013 (void) mdb_snprintf(val, len + 2, "%s=", nameval);
2014 equals = val + len;
2015 }
2016
2017 /* temporary truncate the string for lookup/insert */
2018 *equals = '\0';
2019 v = mdb_nv_lookup(&pt->p_env, val);
2020
2021 if (v != NULL) {
2022 char *old = mdb_nv_get_cookie(v);
2023 mdb_free(old, strlen(old) + 1);
2024 name = mdb_nv_get_name(v);
2025 } else {
2026 /*
2027 * The environment is created using MDB_NV_EXTNAME, so we must
2028 * provide external storage for the variable names.
2029 */
2030 name = strdup(val);
2031 }
2032
2033 *equals = '=';
2034
2035 (void) mdb_nv_insert(&pt->p_env, name, NULL, (uintptr_t)val,
2036 MDB_NV_EXTNAME);
2037
2038 *equals = '=';
2039 }
2040
2041 /*
2042 * Clears the internal environment.
2043 */
2044 static void
pt_env_clear(pt_data_t * pt)2045 pt_env_clear(pt_data_t *pt)
2046 {
2047 mdb_var_t *v;
2048 char *val, *name;
2049
2050 mdb_nv_rewind(&pt->p_env);
2051 while ((v = mdb_nv_advance(&pt->p_env)) != NULL) {
2052
2053 name = (char *)mdb_nv_get_name(v);
2054 val = mdb_nv_get_cookie(v);
2055
2056 mdb_nv_remove(&pt->p_env, v);
2057
2058 mdb_free(name, strlen(name) + 1);
2059 mdb_free(val, strlen(val) + 1);
2060 }
2061 }
2062
2063 /*ARGSUSED*/
2064 static int
pt_setenv(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)2065 pt_setenv(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
2066 {
2067 mdb_tgt_t *t = mdb.m_target;
2068 pt_data_t *pt = t->t_data;
2069 char *nameval;
2070 size_t len;
2071 int alloc;
2072
2073 if ((flags & DCMD_ADDRSPEC) || argc == 0 || argc > 2)
2074 return (DCMD_USAGE);
2075
2076 if ((argc > 0 && argv[0].a_type != MDB_TYPE_STRING) ||
2077 (argc > 1 && argv[1].a_type != MDB_TYPE_STRING))
2078 return (DCMD_USAGE);
2079
2080 if (t->t_pshandle == NULL) {
2081 mdb_warn("no process active\n");
2082 return (DCMD_ERR);
2083 }
2084
2085 /*
2086 * If the process is in some sort of running state, warn the user that
2087 * changes won't immediately take effect.
2088 */
2089 if (Pstate(t->t_pshandle) == PS_RUN ||
2090 Pstate(t->t_pshandle) == PS_STOP) {
2091 mdb_warn("warning: changes will not take effect until process"
2092 " is restarted\n");
2093 }
2094
2095 /*
2096 * We allow two forms of operation. The first is the usual "name=value"
2097 * parameter. We also allow the user to specify two arguments, where
2098 * the first is the name of the variable, and the second is the value.
2099 */
2100 alloc = 0;
2101 if (argc == 1) {
2102 nameval = (char *)argv->a_un.a_str;
2103 } else {
2104 len = strlen(argv[0].a_un.a_str) +
2105 strlen(argv[1].a_un.a_str) + 2;
2106 nameval = mdb_alloc(len, UM_SLEEP);
2107 (void) mdb_snprintf(nameval, len, "%s=%s", argv[0].a_un.a_str,
2108 argv[1].a_un.a_str);
2109 alloc = 1;
2110 }
2111
2112 pt_env_set(pt, nameval);
2113
2114 if (alloc)
2115 mdb_free(nameval, strlen(nameval) + 1);
2116
2117 return (DCMD_OK);
2118 }
2119
2120 /*ARGSUSED*/
2121 static int
pt_unsetenv(uintptr_t addr,uint_t flags,int argc,const mdb_arg_t * argv)2122 pt_unsetenv(uintptr_t addr, uint_t flags, int argc, const mdb_arg_t *argv)
2123 {
2124 mdb_tgt_t *t = mdb.m_target;
2125 pt_data_t *pt = t->t_data;
2126 mdb_var_t *v;
2127 char *value, *name;
2128
2129 if ((flags & DCMD_ADDRSPEC) || argc > 1)
2130 return (DCMD_USAGE);
2131
2132 if (argc == 1 && argv->a_type != MDB_TYPE_STRING)
2133 return (DCMD_USAGE);
2134
2135 if (t->t_pshandle == NULL) {
2136 mdb_warn("no process active\n");
2137 return (DCMD_ERR);
2138 }
2139
2140 /*
2141 * If the process is in some sort of running state, warn the user that
2142 * changes won't immediately take effect.
2143 */
2144 if (Pstate(t->t_pshandle) == PS_RUN ||
2145 Pstate(t->t_pshandle) == PS_STOP) {
2146 mdb_warn("warning: changes will not take effect until process"
2147 " is restarted\n");
2148 }
2149
2150 if (argc == 0) {
2151 pt_env_clear(pt);
2152 } else {
2153 if ((v = mdb_nv_lookup(&pt->p_env, argv->a_un.a_str)) != NULL) {
2154 name = (char *)mdb_nv_get_name(v);
2155 value = mdb_nv_get_cookie(v);
2156
2157 mdb_nv_remove(&pt->p_env, v);
2158
2159 mdb_free(name, strlen(name) + 1);
2160 mdb_free(value, strlen(value) + 1);
2161 }
2162 }
2163
2164 return (DCMD_OK);
2165 }
2166
2167 void
getenv_help(void)2168 getenv_help(void)
2169 {
2170 mdb_printf("-t show current process environment"
2171 " instead of initial environment.\n");
2172 }
2173
2174 static const mdb_dcmd_t pt_dcmds[] = {
2175 { "$c", "?[cnt]", "print stack backtrace", pt_stack },
2176 { "$C", "?[cnt]", "print stack backtrace", pt_stackv },
2177 { "$i", NULL, "print signals that are ignored", pt_ignored },
2178 { "$l", NULL, "print the representative thread's lwp id", pt_lwpid },
2179 { "$L", NULL, "print list of the active lwp ids", pt_lwpids },
2180 { "$r", "?[-u]", "print general-purpose registers", pt_regs },
2181 { "$x", "?", "print floating point registers", pt_fpregs },
2182 { "$X", "?", "print floating point registers", pt_fpregs },
2183 { "$y", "?", "print floating point registers", pt_fpregs },
2184 { "$Y", "?", "print floating point registers", pt_fpregs },
2185 { "$?", "?", "print status and registers", pt_regstatus },
2186 { ":A", "?[core|pid]", "attach to process or core file", pt_attach },
2187 { ":i", ":", "ignore signal (delete all matching events)", pt_ignore },
2188 { ":k", NULL, "forcibly kill and release target", pt_kill },
2189 { ":R", "[-a]", "release the previously attached process", pt_detach },
2190 { "attach", "?[core|pid]",
2191 "attach to process or core file", pt_attach },
2192 { "findstack", ":[-v]", "find user thread stack", pt_findstack },
2193 { "gcore", "[-o prefix] [-c content]",
2194 "produce a core file for the attached process", pt_gcore },
2195 { "getenv", "[-t] [name]", "display an environment variable",
2196 pt_getenv, getenv_help },
2197 { "kill", NULL, "forcibly kill and release target", pt_kill },
2198 { "release", "[-a]",
2199 "release the previously attached process", pt_detach },
2200 { "regs", "?[-u]", "print general-purpose registers", pt_regs },
2201 { "fpregs", "?[-dqs]", "print floating point registers", pt_fpregs },
2202 { "setenv", "name=value", "set an environment variable", pt_setenv },
2203 { "stack", "?[cnt]", "print stack backtrace", pt_stack },
2204 { "stackregs", "?", "print stack backtrace and registers", pt_stackr },
2205 { "status", NULL, "print summary of current target", pt_status_dcmd },
2206 { "tls", ":symbol",
2207 "lookup TLS data in the context of a given thread", pt_tls },
2208 { "tmodel", "{thread|lwp}", NULL, pt_tmodel },
2209 { "unsetenv", "[name]", "clear an environment variable", pt_unsetenv },
2210 { NULL }
2211 };
2212
2213 static void
pt_thr_walk_fini(mdb_walk_state_t * wsp)2214 pt_thr_walk_fini(mdb_walk_state_t *wsp)
2215 {
2216 mdb_addrvec_destroy(wsp->walk_data);
2217 mdb_free(wsp->walk_data, sizeof (mdb_addrvec_t));
2218 }
2219
2220 static int
pt_thr_walk_init(mdb_walk_state_t * wsp)2221 pt_thr_walk_init(mdb_walk_state_t *wsp)
2222 {
2223 wsp->walk_data = mdb_zalloc(sizeof (mdb_addrvec_t), UM_SLEEP);
2224 mdb_addrvec_create(wsp->walk_data);
2225
2226 if (PTL_ITER(mdb.m_target, wsp->walk_data) == -1) {
2227 mdb_warn("failed to iterate over threads");
2228 pt_thr_walk_fini(wsp);
2229 return (WALK_ERR);
2230 }
2231
2232 return (WALK_NEXT);
2233 }
2234
2235 static int
pt_thr_walk_step(mdb_walk_state_t * wsp)2236 pt_thr_walk_step(mdb_walk_state_t *wsp)
2237 {
2238 if (mdb_addrvec_length(wsp->walk_data) != 0) {
2239 return (wsp->walk_callback(mdb_addrvec_shift(wsp->walk_data),
2240 NULL, wsp->walk_cbdata));
2241 }
2242 return (WALK_DONE);
2243 }
2244
2245 static const mdb_walker_t pt_walkers[] = {
2246 { "thread", "walk list of valid thread identifiers",
2247 pt_thr_walk_init, pt_thr_walk_step, pt_thr_walk_fini },
2248 { NULL }
2249 };
2250
2251 static int
pt_agent_check(boolean_t * agent,const lwpstatus_t * psp)2252 pt_agent_check(boolean_t *agent, const lwpstatus_t *psp)
2253 {
2254 if (psp->pr_flags & PR_AGENT)
2255 *agent = B_TRUE;
2256
2257 return (0);
2258 }
2259
2260 static void
pt_activate_common(mdb_tgt_t * t)2261 pt_activate_common(mdb_tgt_t *t)
2262 {
2263 pt_data_t *pt = t->t_data;
2264 boolean_t hasagent = B_FALSE;
2265 GElf_Sym sym;
2266
2267 /*
2268 * If we have a libproc handle and AT_BASE is set, the process or core
2269 * is dynamically linked. We call Prd_agent() to force libproc to
2270 * try to initialize librtld_db, and issue a warning if that fails.
2271 */
2272 if (t->t_pshandle != NULL && Pgetauxval(t->t_pshandle,
2273 AT_BASE) != -1L && Prd_agent(t->t_pshandle) == NULL) {
2274 mdb_warn("warning: librtld_db failed to initialize; shared "
2275 "library information will not be available\n");
2276 }
2277
2278 if (t->t_pshandle != NULL) {
2279 (void) Plwp_iter(t->t_pshandle,
2280 (proc_lwp_f *)pt_agent_check, &hasagent);
2281 }
2282
2283 if (hasagent) {
2284 mdb_warn("agent lwp detected; forcing "
2285 "lwp thread model (use ::tmodel to change)\n");
2286 } else if (t->t_pshandle != NULL && Pstate(t->t_pshandle) != PS_IDLE) {
2287 /*
2288 * If we have a libproc handle and we do not have an agent LWP,
2289 * look for the correct thread debugging library. (If we have
2290 * an agent LWP, we leave the model as the raw LWP model to
2291 * allow the agent LWP to be visible to the debugger.)
2292 */
2293 (void) Pobject_iter(t->t_pshandle, (proc_map_f *)thr_check, t);
2294 }
2295
2296 /*
2297 * If there's a global object named '_mdb_abort_info', assuming we're
2298 * debugging mdb itself and load the developer support module.
2299 */
2300 if (mdb_gelf_symtab_lookup_by_name(pt->p_symtab, "_mdb_abort_info",
2301 &sym, NULL) == 0 && GELF_ST_TYPE(sym.st_info) == STT_OBJECT) {
2302 if (mdb_module_load("mdb_ds", MDB_MOD_SILENT) < 0)
2303 mdb_warn("warning: failed to load developer support\n");
2304 }
2305
2306 mdb_tgt_elf_export(pt->p_file);
2307 }
2308
2309 static void
pt_activate(mdb_tgt_t * t)2310 pt_activate(mdb_tgt_t *t)
2311 {
2312 static const mdb_nv_disc_t reg_disc = {
2313 .disc_set = reg_disc_set,
2314 .disc_get = reg_disc_get
2315 };
2316
2317 pt_data_t *pt = t->t_data;
2318 struct utsname u1, u2;
2319 mdb_var_t *v;
2320 core_content_t content;
2321
2322 if (t->t_pshandle) {
2323 mdb_prop_postmortem = (Pstate(t->t_pshandle) == PS_DEAD);
2324 mdb_prop_kernel = FALSE;
2325 } else
2326 mdb_prop_kernel = mdb_prop_postmortem = FALSE;
2327
2328 mdb_prop_datamodel = MDB_TGT_MODEL_NATIVE;
2329
2330 /*
2331 * If we're examining a core file that doesn't contain program text,
2332 * and uname(2) doesn't match the NT_UTSNAME note recorded in the
2333 * core file, issue a warning.
2334 */
2335 if (mdb_prop_postmortem == TRUE &&
2336 ((content = Pcontent(t->t_pshandle)) == CC_CONTENT_INVALID ||
2337 !(content & CC_CONTENT_TEXT)) &&
2338 uname(&u1) >= 0 && Puname(t->t_pshandle, &u2) == 0 &&
2339 (strcmp(u1.release, u2.release) != 0 ||
2340 strcmp(u1.version, u2.version) != 0)) {
2341 mdb_warn("warning: core file is from %s %s %s; shared text "
2342 "mappings may not match installed libraries\n",
2343 u2.sysname, u2.release, u2.version);
2344 }
2345
2346 /*
2347 * Perform the common initialization tasks -- these are shared with
2348 * the pt_exec() and pt_run() subroutines.
2349 */
2350 pt_activate_common(t);
2351
2352 (void) mdb_tgt_register_dcmds(t, &pt_dcmds[0], MDB_MOD_FORCE);
2353 (void) mdb_tgt_register_walkers(t, &pt_walkers[0], MDB_MOD_FORCE);
2354
2355 /*
2356 * Iterate through our register description list and export
2357 * each register as a named variable.
2358 */
2359 mdb_nv_rewind(&pt->p_regs);
2360 while ((v = mdb_nv_advance(&pt->p_regs)) != NULL) {
2361 ushort_t rd_flags = MDB_TGT_R_FLAGS(mdb_nv_get_value(v));
2362
2363 if (!(rd_flags & MDB_TGT_R_EXPORT))
2364 continue; /* Don't export register as a variable */
2365
2366 (void) mdb_nv_insert(&mdb.m_nv, mdb_nv_get_name(v), ®_disc,
2367 (uintptr_t)t, MDB_NV_PERSIST);
2368 }
2369 }
2370
2371 static void
pt_deactivate(mdb_tgt_t * t)2372 pt_deactivate(mdb_tgt_t *t)
2373 {
2374 pt_data_t *pt = t->t_data;
2375 const mdb_dcmd_t *dcp;
2376 const mdb_walker_t *wp;
2377 mdb_var_t *v, *w;
2378
2379 mdb_nv_rewind(&pt->p_regs);
2380 while ((v = mdb_nv_advance(&pt->p_regs)) != NULL) {
2381 ushort_t rd_flags = MDB_TGT_R_FLAGS(mdb_nv_get_value(v));
2382
2383 if (!(rd_flags & MDB_TGT_R_EXPORT))
2384 continue; /* Didn't export register as a variable */
2385
2386 if (w = mdb_nv_lookup(&mdb.m_nv, mdb_nv_get_name(v))) {
2387 w->v_flags &= ~MDB_NV_PERSIST;
2388 mdb_nv_remove(&mdb.m_nv, w);
2389 }
2390 }
2391
2392 for (wp = &pt_walkers[0]; wp->walk_name != NULL; wp++) {
2393 if (mdb_module_remove_walker(t->t_module, wp->walk_name) == -1)
2394 warn("failed to remove walk %s", wp->walk_name);
2395 }
2396
2397 for (dcp = &pt_dcmds[0]; dcp->dc_name != NULL; dcp++) {
2398 if (mdb_module_remove_dcmd(t->t_module, dcp->dc_name) == -1)
2399 warn("failed to remove dcmd %s", dcp->dc_name);
2400 }
2401
2402 mdb_prop_postmortem = FALSE;
2403 mdb_prop_kernel = FALSE;
2404 mdb_prop_datamodel = MDB_TGT_MODEL_UNKNOWN;
2405 }
2406
2407 static void
pt_periodic(mdb_tgt_t * t)2408 pt_periodic(mdb_tgt_t *t)
2409 {
2410 pt_data_t *pt = t->t_data;
2411
2412 if (pt->p_rdstate == PT_RD_CONSIST) {
2413 if (t->t_pshandle != NULL && Pstate(t->t_pshandle) < PS_LOST &&
2414 !(mdb.m_flags & MDB_FL_NOMODS)) {
2415 mdb_printf("%s: You've got symbols!\n", mdb.m_pname);
2416 mdb_module_load_all(0);
2417 }
2418 pt->p_rdstate = PT_RD_NONE;
2419 }
2420 }
2421
2422 static void
pt_destroy(mdb_tgt_t * t)2423 pt_destroy(mdb_tgt_t *t)
2424 {
2425 pt_data_t *pt = t->t_data;
2426
2427 if (pt->p_idlehandle != NULL && pt->p_idlehandle != t->t_pshandle)
2428 Prelease(pt->p_idlehandle, 0);
2429
2430 if (t->t_pshandle != NULL) {
2431 PTL_DTOR(t);
2432 pt_release_parents(t);
2433 pt_pre_detach(t, TRUE);
2434 Prelease(t->t_pshandle, pt->p_rflags);
2435 }
2436
2437 mdb.m_flags &= ~(MDB_FL_VCREATE | MDB_FL_JOBCTL);
2438 pt_close_aout(t);
2439
2440 if (pt->p_aout_fio != NULL)
2441 mdb_io_rele(pt->p_aout_fio);
2442
2443 pt_env_clear(pt);
2444 mdb_nv_destroy(&pt->p_env);
2445
2446 mdb_nv_destroy(&pt->p_regs);
2447 mdb_free(pt, sizeof (pt_data_t));
2448 }
2449
2450 /*ARGSUSED*/
2451 static const char *
pt_name(mdb_tgt_t * t)2452 pt_name(mdb_tgt_t *t)
2453 {
2454 return ("proc");
2455 }
2456
2457 static const char *
pt_platform(mdb_tgt_t * t)2458 pt_platform(mdb_tgt_t *t)
2459 {
2460 pt_data_t *pt = t->t_data;
2461
2462 if (t->t_pshandle != NULL &&
2463 Pplatform(t->t_pshandle, pt->p_platform, MAXNAMELEN) != NULL)
2464 return (pt->p_platform);
2465
2466 return (mdb_conf_platform());
2467 }
2468
2469 static int
pt_uname(mdb_tgt_t * t,struct utsname * utsp)2470 pt_uname(mdb_tgt_t *t, struct utsname *utsp)
2471 {
2472 if (t->t_pshandle != NULL)
2473 return (Puname(t->t_pshandle, utsp));
2474
2475 return (uname(utsp) >= 0 ? 0 : -1);
2476 }
2477
2478 static int
pt_dmodel(mdb_tgt_t * t)2479 pt_dmodel(mdb_tgt_t *t)
2480 {
2481 if (t->t_pshandle == NULL)
2482 return (MDB_TGT_MODEL_NATIVE);
2483
2484 switch (Pstatus(t->t_pshandle)->pr_dmodel) {
2485 case PR_MODEL_ILP32:
2486 return (MDB_TGT_MODEL_ILP32);
2487 case PR_MODEL_LP64:
2488 return (MDB_TGT_MODEL_LP64);
2489 }
2490
2491 return (MDB_TGT_MODEL_UNKNOWN);
2492 }
2493
2494 static ssize_t
pt_vread(mdb_tgt_t * t,void * buf,size_t nbytes,uintptr_t addr)2495 pt_vread(mdb_tgt_t *t, void *buf, size_t nbytes, uintptr_t addr)
2496 {
2497 ssize_t n;
2498
2499 /*
2500 * If no handle is open yet, reads from virtual addresses are
2501 * allowed to succeed but return zero-filled memory.
2502 */
2503 if (t->t_pshandle == NULL) {
2504 bzero(buf, nbytes);
2505 return (nbytes);
2506 }
2507
2508 if ((n = Pread(t->t_pshandle, buf, nbytes, addr)) <= 0)
2509 return (set_errno(EMDB_NOMAP));
2510
2511 return (n);
2512 }
2513
2514 static ssize_t
pt_vwrite(mdb_tgt_t * t,const void * buf,size_t nbytes,uintptr_t addr)2515 pt_vwrite(mdb_tgt_t *t, const void *buf, size_t nbytes, uintptr_t addr)
2516 {
2517 ssize_t n;
2518
2519 /*
2520 * If no handle is open yet, writes to virtual addresses are
2521 * allowed to succeed but do not actually modify anything.
2522 */
2523 if (t->t_pshandle == NULL)
2524 return (nbytes);
2525
2526 n = Pwrite(t->t_pshandle, buf, nbytes, addr);
2527
2528 if (n == -1 && errno == EIO)
2529 return (set_errno(EMDB_NOMAP));
2530
2531 return (n);
2532 }
2533
2534 static ssize_t
pt_fread(mdb_tgt_t * t,void * buf,size_t nbytes,uintptr_t addr)2535 pt_fread(mdb_tgt_t *t, void *buf, size_t nbytes, uintptr_t addr)
2536 {
2537 pt_data_t *pt = t->t_data;
2538
2539 if (pt->p_file != NULL) {
2540 return (mdb_gelf_rw(pt->p_file, buf, nbytes, addr,
2541 IOPF_READ(pt->p_fio), GIO_READ));
2542 }
2543
2544 bzero(buf, nbytes);
2545 return (nbytes);
2546 }
2547
2548 static ssize_t
pt_fwrite(mdb_tgt_t * t,const void * buf,size_t nbytes,uintptr_t addr)2549 pt_fwrite(mdb_tgt_t *t, const void *buf, size_t nbytes, uintptr_t addr)
2550 {
2551 pt_data_t *pt = t->t_data;
2552
2553 if (pt->p_file != NULL) {
2554 return (mdb_gelf_rw(pt->p_file, (void *)buf, nbytes, addr,
2555 IOPF_WRITE(pt->p_fio), GIO_WRITE));
2556 }
2557
2558 return (nbytes);
2559 }
2560
2561 static const char *
pt_resolve_lmid(const char * object,Lmid_t * lmidp)2562 pt_resolve_lmid(const char *object, Lmid_t *lmidp)
2563 {
2564 Lmid_t lmid = PR_LMID_EVERY;
2565 const char *p;
2566
2567 if (object == MDB_TGT_OBJ_EVERY || object == MDB_TGT_OBJ_EXEC)
2568 lmid = LM_ID_BASE; /* restrict scope to a.out's link map */
2569 else if (object != MDB_TGT_OBJ_RTLD && strncmp(object, "LM", 2) == 0 &&
2570 (p = strchr(object, '`')) != NULL) {
2571 object += 2; /* skip past initial "LM" prefix */
2572 lmid = strntoul(object, (size_t)(p - object), mdb.m_radix);
2573 object = p + 1; /* skip past link map specifier */
2574 }
2575
2576 *lmidp = lmid;
2577 return (object);
2578 }
2579
2580 static int
tlsbase(mdb_tgt_t * t,mdb_tgt_tid_t tid,Lmid_t lmid,const char * object,psaddr_t * basep)2581 tlsbase(mdb_tgt_t *t, mdb_tgt_tid_t tid, Lmid_t lmid, const char *object,
2582 psaddr_t *basep)
2583 {
2584 pt_data_t *pt = t->t_data;
2585 const rd_loadobj_t *loadobjp;
2586 td_thrhandle_t th;
2587 td_err_e err;
2588
2589 if (object == MDB_TGT_OBJ_EVERY)
2590 return (set_errno(EINVAL));
2591
2592 if (t->t_pshandle == NULL || Pstate(t->t_pshandle) == PS_IDLE)
2593 return (set_errno(EMDB_NOPROC));
2594
2595 if (pt->p_tdb_ops == NULL)
2596 return (set_errno(EMDB_TDB));
2597
2598 err = pt->p_tdb_ops->td_ta_map_id2thr(pt->p_ptl_hdl, tid, &th);
2599 if (err != TD_OK)
2600 return (set_errno(tdb_to_errno(err)));
2601
2602 /*
2603 * If this fails, rtld_db has failed to initialize properly.
2604 */
2605 if ((loadobjp = Plmid_to_loadobj(t->t_pshandle, lmid, object)) == NULL)
2606 return (set_errno(EMDB_NORTLD));
2607
2608 /*
2609 * This will fail if the TLS block has not been allocated for the
2610 * object that contains the TLS symbol in question.
2611 */
2612 err = pt->p_tdb_ops->td_thr_tlsbase(&th, loadobjp->rl_tlsmodid, basep);
2613 if (err != TD_OK)
2614 return (set_errno(tdb_to_errno(err)));
2615
2616 return (0);
2617 }
2618
2619 typedef struct {
2620 mdb_tgt_t *pl_tgt;
2621 const char *pl_name;
2622 Lmid_t pl_lmid;
2623 GElf_Sym *pl_symp;
2624 mdb_syminfo_t *pl_sip;
2625 mdb_tgt_tid_t pl_tid;
2626 mdb_bool_t pl_found;
2627 } pt_lookup_t;
2628
2629 /*ARGSUSED*/
2630 static int
pt_lookup_cb(void * data,const prmap_t * pmp,const char * object)2631 pt_lookup_cb(void *data, const prmap_t *pmp, const char *object)
2632 {
2633 pt_lookup_t *plp = data;
2634 struct ps_prochandle *P = plp->pl_tgt->t_pshandle;
2635 prsyminfo_t si;
2636 GElf_Sym sym;
2637
2638 if (Pxlookup_by_name(P, plp->pl_lmid, object, plp->pl_name, &sym,
2639 &si) != 0)
2640 return (0);
2641
2642 /*
2643 * If we encounter a match with SHN_UNDEF, keep looking for a
2644 * better match. Return the first match with SHN_UNDEF set if no
2645 * better match is found.
2646 */
2647 if (sym.st_shndx == SHN_UNDEF) {
2648 if (!plp->pl_found) {
2649 plp->pl_found = TRUE;
2650 *plp->pl_symp = sym;
2651 plp->pl_sip->sym_table = si.prs_table;
2652 plp->pl_sip->sym_id = si.prs_id;
2653 }
2654
2655 return (0);
2656 }
2657
2658 /*
2659 * Note that if the symbol's st_shndx is SHN_UNDEF we don't have the
2660 * TLS offset anyway, so adding in the tlsbase would be worthless.
2661 */
2662 if (GELF_ST_TYPE(sym.st_info) == STT_TLS &&
2663 plp->pl_tid != (mdb_tgt_tid_t)-1) {
2664 psaddr_t base;
2665
2666 if (tlsbase(plp->pl_tgt, plp->pl_tid, plp->pl_lmid, object,
2667 &base) != 0)
2668 return (-1); /* errno is set for us */
2669
2670 sym.st_value += base;
2671 }
2672
2673 plp->pl_found = TRUE;
2674 *plp->pl_symp = sym;
2675 plp->pl_sip->sym_table = si.prs_table;
2676 plp->pl_sip->sym_id = si.prs_id;
2677
2678 return (1);
2679 }
2680
2681 /*
2682 * Lookup the symbol with a thread context so that we can adjust TLS symbols
2683 * to get the values as they would appear in the context of the given thread.
2684 */
2685 static int
pt_lookup_by_name_thr(mdb_tgt_t * t,const char * object,const char * name,GElf_Sym * symp,mdb_syminfo_t * sip,mdb_tgt_tid_t tid)2686 pt_lookup_by_name_thr(mdb_tgt_t *t, const char *object,
2687 const char *name, GElf_Sym *symp, mdb_syminfo_t *sip, mdb_tgt_tid_t tid)
2688 {
2689 struct ps_prochandle *P = t->t_pshandle;
2690 pt_data_t *pt = t->t_data;
2691 Lmid_t lmid;
2692 uint_t i;
2693 const rd_loadobj_t *aout_lop;
2694
2695 object = pt_resolve_lmid(object, &lmid);
2696
2697 if (P != NULL) {
2698 pt_lookup_t pl;
2699
2700 pl.pl_tgt = t;
2701 pl.pl_name = name;
2702 pl.pl_lmid = lmid;
2703 pl.pl_symp = symp;
2704 pl.pl_sip = sip;
2705 pl.pl_tid = tid;
2706 pl.pl_found = FALSE;
2707
2708 if (object == MDB_TGT_OBJ_EVERY) {
2709 if (Pobject_iter_resolved(P, pt_lookup_cb, &pl) == -1)
2710 return (-1); /* errno is set for us */
2711 if ((!pl.pl_found) &&
2712 (Pobject_iter(P, pt_lookup_cb, &pl) == -1))
2713 return (-1); /* errno is set for us */
2714 } else {
2715 const prmap_t *pmp;
2716
2717 /*
2718 * This can fail either due to an invalid lmid or
2719 * an invalid object. To determine which is
2720 * faulty, we test the lmid against known valid
2721 * lmids and then see if using a wild-card lmid
2722 * improves ths situation.
2723 */
2724 if ((pmp = Plmid_to_map(P, lmid, object)) == NULL) {
2725 if (lmid != PR_LMID_EVERY &&
2726 lmid != LM_ID_BASE &&
2727 lmid != LM_ID_LDSO &&
2728 Plmid_to_map(P, PR_LMID_EVERY, object)
2729 != NULL)
2730 return (set_errno(EMDB_NOLMID));
2731 else
2732 return (set_errno(EMDB_NOOBJ));
2733 }
2734
2735 if (pt_lookup_cb(&pl, pmp, object) == -1)
2736 return (-1); /* errno is set for us */
2737 }
2738
2739 if (pl.pl_found)
2740 return (0);
2741 }
2742
2743 /*
2744 * If libproc doesn't have the symbols for rtld, we're cooked --
2745 * mdb doesn't have those symbols either.
2746 */
2747 if (object == MDB_TGT_OBJ_RTLD)
2748 return (set_errno(EMDB_NOSYM));
2749
2750 if (object != MDB_TGT_OBJ_EXEC && object != MDB_TGT_OBJ_EVERY) {
2751 int status = mdb_gelf_symtab_lookup_by_file(pt->p_symtab,
2752 object, name, symp, &sip->sym_id);
2753
2754 if (status != 0) {
2755 if (P != NULL &&
2756 Plmid_to_map(P, PR_LMID_EVERY, object) != NULL)
2757 return (set_errno(EMDB_NOSYM));
2758 else
2759 return (-1); /* errno set from lookup_by_file */
2760 }
2761
2762 goto found;
2763 }
2764
2765 if (mdb_gelf_symtab_lookup_by_name(pt->p_symtab, name, symp, &i) == 0) {
2766 sip->sym_table = MDB_TGT_SYMTAB;
2767 sip->sym_id = i;
2768 goto local_found;
2769 }
2770
2771 if (mdb_gelf_symtab_lookup_by_name(pt->p_dynsym, name, symp, &i) == 0) {
2772 sip->sym_table = MDB_TGT_DYNSYM;
2773 sip->sym_id = i;
2774 goto local_found;
2775 }
2776
2777 return (set_errno(EMDB_NOSYM));
2778
2779 local_found:
2780 if (pt->p_file != NULL &&
2781 pt->p_file->gf_ehdr.e_type == ET_DYN &&
2782 P != NULL &&
2783 (aout_lop = Pname_to_loadobj(P, PR_OBJ_EXEC)) != NULL)
2784 symp->st_value += aout_lop->rl_base;
2785
2786 found:
2787 /*
2788 * If the symbol has type TLS, libproc should have found the symbol
2789 * if it exists and has been allocated.
2790 */
2791 if (GELF_ST_TYPE(symp->st_info) == STT_TLS)
2792 return (set_errno(EMDB_TLS));
2793
2794 return (0);
2795 }
2796
2797 static int
pt_lookup_by_name(mdb_tgt_t * t,const char * object,const char * name,GElf_Sym * symp,mdb_syminfo_t * sip)2798 pt_lookup_by_name(mdb_tgt_t *t, const char *object,
2799 const char *name, GElf_Sym *symp, mdb_syminfo_t *sip)
2800 {
2801 return (pt_lookup_by_name_thr(t, object, name, symp, sip, PTL_TID(t)));
2802 }
2803
2804 static int
pt_lookup_by_addr(mdb_tgt_t * t,uintptr_t addr,uint_t flags,char * buf,size_t nbytes,GElf_Sym * symp,mdb_syminfo_t * sip)2805 pt_lookup_by_addr(mdb_tgt_t *t, uintptr_t addr, uint_t flags,
2806 char *buf, size_t nbytes, GElf_Sym *symp, mdb_syminfo_t *sip)
2807 {
2808 struct ps_prochandle *P = t->t_pshandle;
2809 pt_data_t *pt = t->t_data;
2810 rd_plt_info_t rpi = { 0 };
2811
2812 const char *pltsym;
2813 int rv, match, i;
2814
2815 mdb_gelf_symtab_t *gsts[3]; /* mdb.m_prsym, .symtab, .dynsym */
2816 int gstc = 0; /* number of valid gsts[] entries */
2817
2818 mdb_gelf_symtab_t *gst = NULL; /* set if 'sym' is from a gst */
2819 const prmap_t *pmp = NULL; /* set if 'sym' is from libproc */
2820 GElf_Sym sym; /* best symbol found so far if !exact */
2821 prsyminfo_t si;
2822
2823 /*
2824 * Fill in our array of symbol table pointers with the private symbol
2825 * table, static symbol table, and dynamic symbol table if applicable.
2826 * These are done in order of precedence so that if we match and
2827 * MDB_TGT_SYM_EXACT is set, we need not look any further.
2828 */
2829 if (mdb.m_prsym != NULL)
2830 gsts[gstc++] = mdb.m_prsym;
2831 if (P == NULL && pt->p_symtab != NULL)
2832 gsts[gstc++] = pt->p_symtab;
2833 if (P == NULL && pt->p_dynsym != NULL)
2834 gsts[gstc++] = pt->p_dynsym;
2835
2836 /*
2837 * Loop through our array attempting to match the address. If we match
2838 * and we're in exact mode, we're done. Otherwise save the symbol in
2839 * the local sym variable if it is closer than our previous match.
2840 * We explicitly watch for zero-valued symbols since DevPro insists
2841 * on storing __fsr_init_value's value as the symbol value instead
2842 * of storing it in a constant integer.
2843 */
2844 for (i = 0; i < gstc; i++) {
2845 if (mdb_gelf_symtab_lookup_by_addr(gsts[i], addr, flags, buf,
2846 nbytes, symp, &sip->sym_id) != 0 || symp->st_value == 0)
2847 continue;
2848
2849 if (flags & MDB_TGT_SYM_EXACT) {
2850 gst = gsts[i];
2851 goto found;
2852 }
2853
2854 if (gst == NULL || mdb_gelf_sym_closer(symp, &sym, addr)) {
2855 gst = gsts[i];
2856 sym = *symp;
2857 }
2858 }
2859
2860 /*
2861 * If we have no libproc handle active, we're done: fail if gst is
2862 * NULL; otherwise copy out our best symbol and skip to the end.
2863 * We also skip to found if gst is the private symbol table: we
2864 * want this to always take precedence over PLT re-vectoring.
2865 */
2866 if (P == NULL || (gst != NULL && gst == mdb.m_prsym)) {
2867 if (gst == NULL)
2868 return (set_errno(EMDB_NOSYMADDR));
2869 *symp = sym;
2870 goto found;
2871 }
2872
2873 /*
2874 * Check to see if the address is in a PLT: if it is, use librtld_db to
2875 * attempt to resolve the PLT entry. If the entry is bound, reset addr
2876 * to the bound address, add a special prefix to the caller's buf,
2877 * forget our previous guess, and then continue using the new addr.
2878 * If the entry is not bound, copy the corresponding symbol name into
2879 * buf and return a fake symbol for the given address.
2880 */
2881 if ((pltsym = Ppltdest(P, addr)) != NULL) {
2882 const rd_loadobj_t *rlp;
2883 rd_agent_t *rap;
2884
2885 if ((rap = Prd_agent(P)) != NULL &&
2886 (rlp = Paddr_to_loadobj(P, addr)) != NULL &&
2887 rd_plt_resolution(rap, addr, Pstatus(P)->pr_lwp.pr_lwpid,
2888 rlp->rl_plt_base, &rpi) == RD_OK &&
2889 (rpi.pi_flags & RD_FLG_PI_PLTBOUND)) {
2890 size_t n;
2891 n = mdb_iob_snprintf(buf, nbytes, "PLT=");
2892 addr = rpi.pi_baddr;
2893 if (n > nbytes) {
2894 buf += nbytes;
2895 nbytes = 0;
2896 } else {
2897 buf += n;
2898 nbytes -= n;
2899 }
2900 gst = NULL;
2901 } else {
2902 (void) mdb_iob_snprintf(buf, nbytes, "PLT:%s", pltsym);
2903 bzero(symp, sizeof (GElf_Sym));
2904 symp->st_value = addr;
2905 symp->st_info = GELF_ST_INFO(STB_GLOBAL, STT_FUNC);
2906 return (0);
2907 }
2908 }
2909
2910 /*
2911 * Ask libproc to convert the address to the closest symbol for us.
2912 * Once we get the closest symbol, we perform the EXACT match or
2913 * smart-mode or absolute distance check ourself:
2914 */
2915 if (PT_LIBPROC_RESOLVE(P)) {
2916 rv = Pxlookup_by_addr_resolved(P, addr, buf, nbytes,
2917 symp, &si);
2918 } else {
2919 rv = Pxlookup_by_addr(P, addr, buf, nbytes,
2920 symp, &si);
2921 }
2922 if ((rv == 0) && (symp->st_value != 0) &&
2923 (gst == NULL || mdb_gelf_sym_closer(symp, &sym, addr))) {
2924
2925 if (flags & MDB_TGT_SYM_EXACT)
2926 match = (addr == symp->st_value);
2927 else if (mdb.m_symdist == 0)
2928 match = (addr >= symp->st_value &&
2929 addr < symp->st_value + symp->st_size);
2930 else
2931 match = (addr >= symp->st_value &&
2932 addr < symp->st_value + mdb.m_symdist);
2933
2934 if (match) {
2935 pmp = Paddr_to_map(P, addr);
2936 gst = NULL;
2937 sip->sym_table = si.prs_table;
2938 sip->sym_id = si.prs_id;
2939 goto found;
2940 }
2941 }
2942
2943 /*
2944 * If we get here, Plookup_by_addr has failed us. If we have no
2945 * previous best symbol (gst == NULL), we've failed completely.
2946 * Otherwise we copy out that symbol and continue on to 'found'.
2947 */
2948 if (gst == NULL)
2949 return (set_errno(EMDB_NOSYMADDR));
2950 *symp = sym;
2951 found:
2952 /*
2953 * Once we've found something, copy the final name into the caller's
2954 * buffer and prefix it with the mapping name if appropriate.
2955 */
2956 if (pmp != NULL && pmp != Pname_to_map(P, PR_OBJ_EXEC)) {
2957 const char *prefix = pmp->pr_mapname;
2958 Lmid_t lmid;
2959
2960 if (PT_LIBPROC_RESOLVE(P)) {
2961 if (Pobjname_resolved(P, addr, pt->p_objname,
2962 MDB_TGT_MAPSZ))
2963 prefix = pt->p_objname;
2964 } else {
2965 if (Pobjname(P, addr, pt->p_objname, MDB_TGT_MAPSZ))
2966 prefix = pt->p_objname;
2967 }
2968
2969 if (buf != NULL && nbytes > 1) {
2970 (void) strncpy(pt->p_symname, buf, MDB_TGT_SYM_NAMLEN);
2971 pt->p_symname[MDB_TGT_SYM_NAMLEN - 1] = '\0';
2972 } else {
2973 pt->p_symname[0] = '\0';
2974 }
2975
2976 if (prefix == pt->p_objname && Plmid(P, addr, &lmid) == 0 && (
2977 (lmid != LM_ID_BASE && lmid != LM_ID_LDSO) ||
2978 (mdb.m_flags & MDB_FL_SHOWLMID))) {
2979 (void) mdb_iob_snprintf(buf, nbytes, "LM%lr`%s`%s",
2980 lmid, strbasename(prefix), pt->p_symname);
2981 } else {
2982 (void) mdb_iob_snprintf(buf, nbytes, "%s`%s",
2983 strbasename(prefix), pt->p_symname);
2984 }
2985
2986 } else if (gst != NULL && buf != NULL && nbytes > 0) {
2987 (void) strncpy(buf, mdb_gelf_sym_name(gst, symp), nbytes);
2988 buf[nbytes - 1] = '\0';
2989 }
2990
2991 return (0);
2992 }
2993
2994
2995 static int
pt_symbol_iter_cb(void * arg,const GElf_Sym * sym,const char * name,const prsyminfo_t * sip)2996 pt_symbol_iter_cb(void *arg, const GElf_Sym *sym, const char *name,
2997 const prsyminfo_t *sip)
2998 {
2999 pt_symarg_t *psp = arg;
3000
3001 psp->psym_info.sym_id = sip->prs_id;
3002
3003 return (psp->psym_func(psp->psym_private, sym, name, &psp->psym_info,
3004 psp->psym_obj));
3005 }
3006
3007 static int
pt_objsym_iter(void * arg,const prmap_t * pmp,const char * object)3008 pt_objsym_iter(void *arg, const prmap_t *pmp, const char *object)
3009 {
3010 Lmid_t lmid = PR_LMID_EVERY;
3011 pt_symarg_t *psp = arg;
3012
3013 psp->psym_obj = object;
3014
3015 (void) Plmid(psp->psym_targ->t_pshandle, pmp->pr_vaddr, &lmid);
3016 (void) Pxsymbol_iter(psp->psym_targ->t_pshandle, lmid, object,
3017 psp->psym_which, psp->psym_type, pt_symbol_iter_cb, arg);
3018
3019 return (0);
3020 }
3021
3022 static int
pt_symbol_filt(void * arg,const GElf_Sym * sym,const char * name,uint_t id)3023 pt_symbol_filt(void *arg, const GElf_Sym *sym, const char *name, uint_t id)
3024 {
3025 pt_symarg_t *psp = arg;
3026
3027 if (mdb_tgt_sym_match(sym, psp->psym_type)) {
3028 psp->psym_info.sym_id = id;
3029 return (psp->psym_func(psp->psym_private, sym, name,
3030 &psp->psym_info, psp->psym_obj));
3031 }
3032
3033 return (0);
3034 }
3035
3036 static int
pt_symbol_iter(mdb_tgt_t * t,const char * object,uint_t which,uint_t type,mdb_tgt_sym_f * func,void * private)3037 pt_symbol_iter(mdb_tgt_t *t, const char *object, uint_t which,
3038 uint_t type, mdb_tgt_sym_f *func, void *private)
3039 {
3040 pt_data_t *pt = t->t_data;
3041 mdb_gelf_symtab_t *gst;
3042 pt_symarg_t ps;
3043 Lmid_t lmid;
3044
3045 object = pt_resolve_lmid(object, &lmid);
3046
3047 ps.psym_targ = t;
3048 ps.psym_which = which;
3049 ps.psym_type = type;
3050 ps.psym_func = func;
3051 ps.psym_private = private;
3052 ps.psym_obj = object;
3053
3054 if (t->t_pshandle != NULL) {
3055 if (object != MDB_TGT_OBJ_EVERY) {
3056 if (Plmid_to_map(t->t_pshandle, lmid, object) == NULL)
3057 return (set_errno(EMDB_NOOBJ));
3058 (void) Pxsymbol_iter(t->t_pshandle, lmid, object,
3059 which, type, pt_symbol_iter_cb, &ps);
3060 return (0);
3061 } else if (Prd_agent(t->t_pshandle) != NULL) {
3062 if (PT_LIBPROC_RESOLVE(t->t_pshandle)) {
3063 (void) Pobject_iter_resolved(t->t_pshandle,
3064 pt_objsym_iter, &ps);
3065 } else {
3066 (void) Pobject_iter(t->t_pshandle,
3067 pt_objsym_iter, &ps);
3068 }
3069 return (0);
3070 }
3071 }
3072
3073 if (lmid != LM_ID_BASE && lmid != PR_LMID_EVERY)
3074 return (set_errno(EMDB_NOLMID));
3075
3076 if (object != MDB_TGT_OBJ_EXEC && object != MDB_TGT_OBJ_EVERY &&
3077 pt->p_fio != NULL &&
3078 strcmp(object, IOP_NAME(pt->p_fio)) != 0)
3079 return (set_errno(EMDB_NOOBJ));
3080
3081 if (which == MDB_TGT_SYMTAB)
3082 gst = pt->p_symtab;
3083 else
3084 gst = pt->p_dynsym;
3085
3086 if (gst != NULL) {
3087 ps.psym_info.sym_table = gst->gst_tabid;
3088 mdb_gelf_symtab_iter(gst, pt_symbol_filt, &ps);
3089 }
3090
3091 return (0);
3092 }
3093
3094 static const mdb_map_t *
pt_prmap_to_mdbmap(mdb_tgt_t * t,const prmap_t * prp,mdb_map_t * mp)3095 pt_prmap_to_mdbmap(mdb_tgt_t *t, const prmap_t *prp, mdb_map_t *mp)
3096 {
3097 struct ps_prochandle *P = t->t_pshandle;
3098 char *rv, name[MAXPATHLEN];
3099 Lmid_t lmid;
3100
3101 if (PT_LIBPROC_RESOLVE(P)) {
3102 rv = Pobjname_resolved(P, prp->pr_vaddr, name, sizeof (name));
3103 } else {
3104 rv = Pobjname(P, prp->pr_vaddr, name, sizeof (name));
3105 }
3106
3107 if (rv != NULL) {
3108 if (Plmid(P, prp->pr_vaddr, &lmid) == 0 && (
3109 (lmid != LM_ID_BASE && lmid != LM_ID_LDSO) ||
3110 (mdb.m_flags & MDB_FL_SHOWLMID))) {
3111 (void) mdb_iob_snprintf(mp->map_name, MDB_TGT_MAPSZ,
3112 "LM%lr`%s", lmid, name);
3113 } else {
3114 (void) strncpy(mp->map_name, name, MDB_TGT_MAPSZ - 1);
3115 mp->map_name[MDB_TGT_MAPSZ - 1] = '\0';
3116 }
3117 } else {
3118 (void) strncpy(mp->map_name, prp->pr_mapname,
3119 MDB_TGT_MAPSZ - 1);
3120 mp->map_name[MDB_TGT_MAPSZ - 1] = '\0';
3121 }
3122
3123 mp->map_base = prp->pr_vaddr;
3124 mp->map_size = prp->pr_size;
3125 mp->map_flags = 0;
3126
3127 if (prp->pr_mflags & MA_READ)
3128 mp->map_flags |= MDB_TGT_MAP_R;
3129 if (prp->pr_mflags & MA_WRITE)
3130 mp->map_flags |= MDB_TGT_MAP_W;
3131 if (prp->pr_mflags & MA_EXEC)
3132 mp->map_flags |= MDB_TGT_MAP_X;
3133
3134 if (prp->pr_mflags & MA_SHM)
3135 mp->map_flags |= MDB_TGT_MAP_SHMEM;
3136 if (prp->pr_mflags & MA_BREAK)
3137 mp->map_flags |= MDB_TGT_MAP_HEAP;
3138 if (prp->pr_mflags & MA_STACK)
3139 mp->map_flags |= MDB_TGT_MAP_STACK;
3140 if (prp->pr_mflags & MA_ANON)
3141 mp->map_flags |= MDB_TGT_MAP_ANON;
3142
3143 return (mp);
3144 }
3145
3146 /*ARGSUSED*/
3147 static int
pt_map_apply(void * arg,const prmap_t * prp,const char * name)3148 pt_map_apply(void *arg, const prmap_t *prp, const char *name)
3149 {
3150 pt_maparg_t *pmp = arg;
3151 mdb_map_t map;
3152
3153 return (pmp->pmap_func(pmp->pmap_private,
3154 pt_prmap_to_mdbmap(pmp->pmap_targ, prp, &map), map.map_name));
3155 }
3156
3157 static int
pt_mapping_iter(mdb_tgt_t * t,mdb_tgt_map_f * func,void * private)3158 pt_mapping_iter(mdb_tgt_t *t, mdb_tgt_map_f *func, void *private)
3159 {
3160 if (t->t_pshandle != NULL) {
3161 pt_maparg_t pm;
3162
3163 pm.pmap_targ = t;
3164 pm.pmap_func = func;
3165 pm.pmap_private = private;
3166
3167 if (PT_LIBPROC_RESOLVE(t->t_pshandle)) {
3168 (void) Pmapping_iter_resolved(t->t_pshandle,
3169 pt_map_apply, &pm);
3170 } else {
3171 (void) Pmapping_iter(t->t_pshandle,
3172 pt_map_apply, &pm);
3173 }
3174 return (0);
3175 }
3176
3177 return (set_errno(EMDB_NOPROC));
3178 }
3179
3180 static int
pt_object_iter(mdb_tgt_t * t,mdb_tgt_map_f * func,void * private)3181 pt_object_iter(mdb_tgt_t *t, mdb_tgt_map_f *func, void *private)
3182 {
3183 pt_data_t *pt = t->t_data;
3184
3185 /*
3186 * If we have a libproc handle, we can just call Pobject_iter to
3187 * iterate over its list of load object information.
3188 */
3189 if (t->t_pshandle != NULL) {
3190 pt_maparg_t pm;
3191
3192 pm.pmap_targ = t;
3193 pm.pmap_func = func;
3194 pm.pmap_private = private;
3195
3196 if (PT_LIBPROC_RESOLVE(t->t_pshandle)) {
3197 (void) Pobject_iter_resolved(t->t_pshandle,
3198 pt_map_apply, &pm);
3199 } else {
3200 (void) Pobject_iter(t->t_pshandle,
3201 pt_map_apply, &pm);
3202 }
3203 return (0);
3204 }
3205
3206 /*
3207 * If we're examining an executable or other ELF file but we have no
3208 * libproc handle, fake up some information based on DT_NEEDED entries.
3209 */
3210 if (pt->p_dynsym != NULL && pt->p_file->gf_dyns != NULL &&
3211 pt->p_fio != NULL) {
3212 mdb_gelf_sect_t *gsp = pt->p_dynsym->gst_ssect;
3213 GElf_Dyn *dynp = pt->p_file->gf_dyns;
3214 mdb_map_t *mp = &pt->p_map;
3215 const char *s = IOP_NAME(pt->p_fio);
3216 size_t i;
3217
3218 (void) strncpy(mp->map_name, s, MDB_TGT_MAPSZ);
3219 mp->map_name[MDB_TGT_MAPSZ - 1] = '\0';
3220 mp->map_flags = MDB_TGT_MAP_R | MDB_TGT_MAP_X;
3221 mp->map_base = 0;
3222 mp->map_size = 0;
3223
3224 if (func(private, mp, s) != 0)
3225 return (0);
3226
3227 for (i = 0; i < pt->p_file->gf_ndyns; i++, dynp++) {
3228 if (dynp->d_tag == DT_NEEDED) {
3229 s = (char *)gsp->gs_data + dynp->d_un.d_val;
3230 (void) strncpy(mp->map_name, s, MDB_TGT_MAPSZ);
3231 mp->map_name[MDB_TGT_MAPSZ - 1] = '\0';
3232 if (func(private, mp, s) != 0)
3233 return (0);
3234 }
3235 }
3236
3237 return (0);
3238 }
3239
3240 return (set_errno(EMDB_NOPROC));
3241 }
3242
3243 static const mdb_map_t *
pt_addr_to_map(mdb_tgt_t * t,uintptr_t addr)3244 pt_addr_to_map(mdb_tgt_t *t, uintptr_t addr)
3245 {
3246 pt_data_t *pt = t->t_data;
3247 const prmap_t *pmp;
3248
3249 if (t->t_pshandle == NULL) {
3250 (void) set_errno(EMDB_NOPROC);
3251 return (NULL);
3252 }
3253
3254 if ((pmp = Paddr_to_map(t->t_pshandle, addr)) == NULL) {
3255 (void) set_errno(EMDB_NOMAP);
3256 return (NULL);
3257 }
3258
3259 return (pt_prmap_to_mdbmap(t, pmp, &pt->p_map));
3260 }
3261
3262 static const mdb_map_t *
pt_name_to_map(mdb_tgt_t * t,const char * object)3263 pt_name_to_map(mdb_tgt_t *t, const char *object)
3264 {
3265 pt_data_t *pt = t->t_data;
3266 const prmap_t *pmp;
3267 Lmid_t lmid;
3268
3269 if (t->t_pshandle == NULL) {
3270 (void) set_errno(EMDB_NOPROC);
3271 return (NULL);
3272 }
3273
3274 object = pt_resolve_lmid(object, &lmid);
3275
3276 if ((pmp = Plmid_to_map(t->t_pshandle, lmid, object)) == NULL) {
3277 (void) set_errno(EMDB_NOOBJ);
3278 return (NULL);
3279 }
3280
3281 return (pt_prmap_to_mdbmap(t, pmp, &pt->p_map));
3282 }
3283
3284 static ctf_file_t *
pt_addr_to_ctf(mdb_tgt_t * t,uintptr_t addr)3285 pt_addr_to_ctf(mdb_tgt_t *t, uintptr_t addr)
3286 {
3287 ctf_file_t *ret;
3288
3289 if (t->t_pshandle == NULL) {
3290 (void) set_errno(EMDB_NOPROC);
3291 return (NULL);
3292 }
3293
3294 if ((ret = Paddr_to_ctf(t->t_pshandle, addr)) == NULL) {
3295 (void) set_errno(EMDB_NOOBJ);
3296 return (NULL);
3297 }
3298
3299 return (ret);
3300 }
3301
3302 static ctf_file_t *
pt_name_to_ctf(mdb_tgt_t * t,const char * name)3303 pt_name_to_ctf(mdb_tgt_t *t, const char *name)
3304 {
3305 ctf_file_t *ret;
3306
3307 if (t->t_pshandle == NULL) {
3308 (void) set_errno(EMDB_NOPROC);
3309 return (NULL);
3310 }
3311
3312 if ((ret = Pname_to_ctf(t->t_pshandle, name)) == NULL) {
3313 (void) set_errno(EMDB_NOOBJ);
3314 return (NULL);
3315 }
3316
3317 return (ret);
3318 }
3319
3320 static int
pt_status(mdb_tgt_t * t,mdb_tgt_status_t * tsp)3321 pt_status(mdb_tgt_t *t, mdb_tgt_status_t *tsp)
3322 {
3323 const pstatus_t *psp;
3324 prgregset_t gregs;
3325 int state;
3326
3327 bzero(tsp, sizeof (mdb_tgt_status_t));
3328
3329 if (t->t_pshandle == NULL) {
3330 tsp->st_state = MDB_TGT_IDLE;
3331 return (0);
3332 }
3333
3334 switch (state = Pstate(t->t_pshandle)) {
3335 case PS_RUN:
3336 tsp->st_state = MDB_TGT_RUNNING;
3337 break;
3338
3339 case PS_STOP:
3340 tsp->st_state = MDB_TGT_STOPPED;
3341 psp = Pstatus(t->t_pshandle);
3342
3343 tsp->st_tid = PTL_TID(t);
3344 if (PTL_GETREGS(t, tsp->st_tid, gregs) == 0)
3345 tsp->st_pc = gregs[R_PC];
3346
3347 if (psp->pr_flags & PR_ISTOP)
3348 tsp->st_flags |= MDB_TGT_ISTOP;
3349 if (psp->pr_flags & PR_DSTOP)
3350 tsp->st_flags |= MDB_TGT_DSTOP;
3351
3352 break;
3353
3354 case PS_LOST:
3355 tsp->st_state = MDB_TGT_LOST;
3356 break;
3357 case PS_UNDEAD:
3358 tsp->st_state = MDB_TGT_UNDEAD;
3359 break;
3360 case PS_DEAD:
3361 tsp->st_state = MDB_TGT_DEAD;
3362 break;
3363 case PS_IDLE:
3364 tsp->st_state = MDB_TGT_IDLE;
3365 break;
3366 default:
3367 fail("unknown libproc state (%d)\n", state);
3368 }
3369
3370 if (t->t_flags & MDB_TGT_F_BUSY)
3371 tsp->st_flags |= MDB_TGT_BUSY;
3372
3373 return (0);
3374 }
3375
3376 static void
pt_dupfd(const char * file,int oflags,mode_t mode,int dfd)3377 pt_dupfd(const char *file, int oflags, mode_t mode, int dfd)
3378 {
3379 int fd;
3380
3381 if ((fd = open(file, oflags, mode)) >= 0) {
3382 (void) fcntl(fd, F_DUP2FD, dfd);
3383 (void) close(fd);
3384 } else
3385 warn("failed to open %s as descriptor %d", file, dfd);
3386 }
3387
3388 /*
3389 * The Pcreate_callback() function interposes on the default, empty libproc
3390 * definition. It will be called following a fork of a new child process by
3391 * Pcreate() below, but before the exec of the new process image. We use this
3392 * callback to optionally redirect stdin and stdout and reset the dispositions
3393 * of SIGPIPE and SIGQUIT from SIG_IGN back to SIG_DFL.
3394 */
3395 /*ARGSUSED*/
3396 void
Pcreate_callback(struct ps_prochandle * P)3397 Pcreate_callback(struct ps_prochandle *P)
3398 {
3399 pt_data_t *pt = mdb.m_target->t_data;
3400
3401 if (pt->p_stdin != NULL)
3402 pt_dupfd(pt->p_stdin, O_RDWR, 0, STDIN_FILENO);
3403 if (pt->p_stdout != NULL)
3404 pt_dupfd(pt->p_stdout, O_CREAT | O_WRONLY, 0666, STDOUT_FILENO);
3405
3406 (void) mdb_signal_sethandler(SIGPIPE, MDB_SIG_DFL, NULL);
3407 (void) mdb_signal_sethandler(SIGQUIT, MDB_SIG_DFL, NULL);
3408 }
3409
3410 static int
pt_run(mdb_tgt_t * t,int argc,const mdb_arg_t * argv)3411 pt_run(mdb_tgt_t *t, int argc, const mdb_arg_t *argv)
3412 {
3413 pt_data_t *pt = t->t_data;
3414 struct ps_prochandle *P;
3415 char execname[MAXPATHLEN];
3416 const char **pargv;
3417 int pargc = 0;
3418 int i, perr;
3419 char **penv;
3420 mdb_var_t *v;
3421
3422 if (pt->p_aout_fio == NULL) {
3423 warn("run requires executable to be specified on "
3424 "command-line\n");
3425 return (set_errno(EMDB_TGT));
3426 }
3427
3428 pargv = mdb_alloc(sizeof (char *) * (argc + 2), UM_SLEEP);
3429 pargv[pargc++] = strbasename(IOP_NAME(pt->p_aout_fio));
3430
3431 for (i = 0; i < argc; i++) {
3432 if (argv[i].a_type != MDB_TYPE_STRING) {
3433 mdb_free(pargv, sizeof (char *) * (argc + 2));
3434 return (set_errno(EINVAL));
3435 }
3436 if (argv[i].a_un.a_str[0] == '<')
3437 pt->p_stdin = argv[i].a_un.a_str + 1;
3438 else if (argv[i].a_un.a_str[0] == '>')
3439 pt->p_stdout = argv[i].a_un.a_str + 1;
3440 else
3441 pargv[pargc++] = argv[i].a_un.a_str;
3442 }
3443 pargv[pargc] = NULL;
3444
3445 /*
3446 * Since Pcreate() uses execvp() and "." may not be present in $PATH,
3447 * we must manually prepend "./" when the executable is a simple name.
3448 */
3449 if (strchr(IOP_NAME(pt->p_aout_fio), '/') == NULL) {
3450 (void) snprintf(execname, sizeof (execname), "./%s",
3451 IOP_NAME(pt->p_aout_fio));
3452 } else {
3453 (void) snprintf(execname, sizeof (execname), "%s",
3454 IOP_NAME(pt->p_aout_fio));
3455 }
3456
3457 penv = mdb_alloc((mdb_nv_size(&pt->p_env)+ 1) * sizeof (char *),
3458 UM_SLEEP);
3459 for (mdb_nv_rewind(&pt->p_env), i = 0;
3460 (v = mdb_nv_advance(&pt->p_env)) != NULL; i++)
3461 penv[i] = mdb_nv_get_cookie(v);
3462 penv[i] = NULL;
3463
3464 P = Pxcreate(execname, (char **)pargv, penv, &perr, NULL, 0);
3465 mdb_free(pargv, sizeof (char *) * (argc + 2));
3466 pt->p_stdin = pt->p_stdout = NULL;
3467
3468 mdb_free(penv, i * sizeof (char *));
3469
3470 if (P == NULL) {
3471 warn("failed to create process: %s\n", Pcreate_error(perr));
3472 return (set_errno(EMDB_TGT));
3473 }
3474
3475 if (t->t_pshandle != NULL) {
3476 pt_pre_detach(t, TRUE);
3477 if (t->t_pshandle != pt->p_idlehandle)
3478 Prelease(t->t_pshandle, pt->p_rflags);
3479 }
3480
3481 (void) Punsetflags(P, PR_RLC); /* make sure run-on-last-close is off */
3482 (void) Psetflags(P, PR_KLC); /* kill on last close by debugger */
3483 pt->p_rflags = PRELEASE_KILL; /* kill on debugger Prelease */
3484 t->t_pshandle = P;
3485
3486 pt_post_attach(t);
3487 pt_activate_common(t);
3488 (void) mdb_tgt_status(t, &t->t_status);
3489 mdb.m_flags |= MDB_FL_VCREATE;
3490
3491 return (0);
3492 }
3493
3494 /*
3495 * Forward a signal to the victim process in order to force it to stop or die.
3496 * Refer to the comments above pt_setrun(), below, for more info.
3497 */
3498 /*ARGSUSED*/
3499 static void
pt_sigfwd(int sig,siginfo_t * sip,ucontext_t * ucp,mdb_tgt_t * t)3500 pt_sigfwd(int sig, siginfo_t *sip, ucontext_t *ucp, mdb_tgt_t *t)
3501 {
3502 struct ps_prochandle *P = t->t_pshandle;
3503 const lwpstatus_t *psp = &Pstatus(P)->pr_lwp;
3504 pid_t pid = Pstatus(P)->pr_pid;
3505 long ctl[2];
3506
3507 if (getpgid(pid) != mdb.m_pgid) {
3508 mdb_dprintf(MDB_DBG_TGT, "fwd SIG#%d to %d\n", sig, (int)pid);
3509 (void) kill(pid, sig);
3510 }
3511
3512 if (Pwait(P, 1) == 0 && (psp->pr_flags & PR_STOPPED) &&
3513 psp->pr_why == PR_JOBCONTROL && Pdstop(P) == 0) {
3514 /*
3515 * If we're job control stopped and our DSTOP is pending, the
3516 * victim will never see our signal, so undo the kill() and
3517 * then send SIGCONT the victim to kick it out of the job
3518 * control stop and force our DSTOP to take effect.
3519 */
3520 if ((psp->pr_flags & PR_DSTOP) &&
3521 prismember(&Pstatus(P)->pr_sigpend, sig)) {
3522 ctl[0] = PCUNKILL;
3523 ctl[1] = sig;
3524 (void) write(Pctlfd(P), ctl, sizeof (ctl));
3525 }
3526
3527 mdb_dprintf(MDB_DBG_TGT, "fwd SIGCONT to %d\n", (int)pid);
3528 (void) kill(pid, SIGCONT);
3529 }
3530 }
3531
3532 /*
3533 * Common code for step and continue: if no victim process has been created,
3534 * call pt_run() to create one. Then set the victim running, clearing any
3535 * pending fault. One special case is that if the victim was previously
3536 * stopped on reception of SIGINT, we know that SIGINT was traced and the user
3537 * requested the victim to stop, so clear this signal before continuing.
3538 * For all other traced signals, the signal will be delivered on continue.
3539 *
3540 * Once the victim process is running, we wait for it to stop on an event of
3541 * interest. Although libproc provides the basic primitive to wait for the
3542 * victim, we must be careful in our handling of signals. We want to allow the
3543 * user to issue a SIGINT or SIGQUIT using the designated terminal control
3544 * character (typically ^C and ^\), and have these signals stop the target and
3545 * return control to the debugger if the signals are traced. There are three
3546 * cases to be considered in our implementation:
3547 *
3548 * (1) If the debugger and victim are in the same process group, both receive
3549 * the signal from the terminal driver. The debugger returns from Pwait() with
3550 * errno = EINTR, so we want to loop back and continue waiting until the victim
3551 * stops on receipt of its SIGINT or SIGQUIT.
3552 *
3553 * (2) If the debugger and victim are in different process groups, and the
3554 * victim is a member of the foreground process group, it will receive the
3555 * signal from the terminal driver and the debugger will not. As such, we
3556 * will remain blocked in Pwait() until the victim stops on its signal.
3557 *
3558 * (3) If the debugger and victim are in different process groups, and the
3559 * debugger is a member of the foreground process group, it will receive the
3560 * signal from the terminal driver, and the victim will not. The debugger
3561 * returns from Pwait() with errno = EINTR, so we need to forward the signal
3562 * to the victim process directly and then Pwait() again for it to stop.
3563 *
3564 * We can observe that all three cases are handled by simply calling Pwait()
3565 * repeatedly if it fails with EINTR, and forwarding SIGINT and SIGQUIT to
3566 * the victim if it is in a different process group, using pt_sigfwd() above.
3567 *
3568 * An additional complication is that the process may not be able to field
3569 * the signal if it is currently stopped by job control. In this case, we
3570 * also DSTOP the process, and then send it a SIGCONT to wake it up from
3571 * job control and force it to re-enter stop() under the control of /proc.
3572 *
3573 * Finally, we would like to allow the user to suspend the process using the
3574 * terminal suspend character (typically ^Z) if both are in the same session.
3575 * We again employ pt_sigfwd() to forward SIGTSTP to the victim, wait for it to
3576 * stop from job control, and then capture it using /proc. Once the process
3577 * has stopped, normal SIGTSTP processing is restored and the user can issue
3578 * another ^Z in order to suspend the debugger and return to the parent shell.
3579 */
3580 static int
pt_setrun(mdb_tgt_t * t,mdb_tgt_status_t * tsp,int flags)3581 pt_setrun(mdb_tgt_t *t, mdb_tgt_status_t *tsp, int flags)
3582 {
3583 struct ps_prochandle *P = t->t_pshandle;
3584 pt_data_t *pt = t->t_data;
3585 pid_t old_pgid = -1;
3586
3587 mdb_signal_f *intf, *quitf, *tstpf;
3588 const lwpstatus_t *psp;
3589 void *intd, *quitd, *tstpd;
3590
3591 int sig = pt->p_signal;
3592 int error = 0;
3593 int pgid = -1;
3594
3595 pt->p_signal = 0; /* clear pending signal */
3596
3597 if (P == NULL && pt_run(t, 0, NULL) == -1)
3598 return (-1); /* errno is set for us */
3599
3600 P = t->t_pshandle;
3601 psp = &Pstatus(P)->pr_lwp;
3602
3603 if (sig == 0 && psp->pr_why == PR_SIGNALLED && psp->pr_what == SIGINT)
3604 flags |= PRCSIG; /* clear pending SIGINT */
3605 else
3606 flags |= PRCFAULT; /* clear any pending fault (e.g. BPT) */
3607
3608 intf = mdb_signal_gethandler(SIGINT, &intd);
3609 quitf = mdb_signal_gethandler(SIGQUIT, &quitd);
3610 tstpf = mdb_signal_gethandler(SIGTSTP, &tstpd);
3611
3612 (void) mdb_signal_sethandler(SIGINT, (mdb_signal_f *)pt_sigfwd, t);
3613 (void) mdb_signal_sethandler(SIGQUIT, (mdb_signal_f *)pt_sigfwd, t);
3614 (void) mdb_signal_sethandler(SIGTSTP, (mdb_signal_f *)pt_sigfwd, t);
3615
3616 if (sig != 0 && Pstate(P) == PS_RUN &&
3617 kill(Pstatus(P)->pr_pid, sig) == -1) {
3618 error = errno;
3619 goto out;
3620 }
3621
3622 /*
3623 * If we attached to a job stopped background process in the same
3624 * session, make its pgid the foreground process group before running
3625 * it. Ignore SIGTTOU while doing this to avoid being suspended.
3626 */
3627 if (mdb.m_flags & MDB_FL_JOBCTL) {
3628 (void) mdb_signal_sethandler(SIGTTOU, MDB_SIG_IGN, NULL);
3629 (void) IOP_CTL(mdb.m_term, TIOCGPGRP, &old_pgid);
3630 (void) IOP_CTL(mdb.m_term, TIOCSPGRP,
3631 (void *)&Pstatus(P)->pr_pgid);
3632 (void) mdb_signal_sethandler(SIGTTOU, MDB_SIG_DFL, NULL);
3633 }
3634
3635 if (Pstate(P) != PS_RUN && Psetrun(P, sig, flags) == -1) {
3636 error = errno;
3637 goto out;
3638 }
3639
3640 /*
3641 * If the process is stopped on job control, resume its process group
3642 * by sending it a SIGCONT if we are in the same session. Otherwise
3643 * we have no choice but to wait for someone else to foreground it.
3644 */
3645 if (psp->pr_why == PR_JOBCONTROL) {
3646 if (mdb.m_flags & MDB_FL_JOBCTL)
3647 (void) kill(-Pstatus(P)->pr_pgid, SIGCONT);
3648 else if (mdb.m_term != NULL)
3649 warn("process is still suspended by job control ...\n");
3650 }
3651
3652 /*
3653 * Wait for the process to stop. As described above, we loop around if
3654 * we are interrupted (EINTR). If we lose control, attempt to re-open
3655 * the process, or call pt_exec() if that fails to handle a re-exec.
3656 * If the process dies (ENOENT) or Pwait() fails, break out of the loop.
3657 */
3658 while (Pwait(P, 0) == -1) {
3659 if (errno != EINTR) {
3660 if (Pstate(P) == PS_LOST) {
3661 if (Preopen(P) == 0)
3662 continue; /* Pwait() again */
3663 else
3664 pt_exec(t, 0, NULL);
3665 } else if (errno != ENOENT)
3666 warn("failed to wait for event");
3667 break;
3668 }
3669 }
3670
3671 /*
3672 * If we changed the foreground process group, restore the old pgid
3673 * while ignoring SIGTTOU so we are not accidentally suspended.
3674 */
3675 if (old_pgid != -1) {
3676 (void) mdb_signal_sethandler(SIGTTOU, MDB_SIG_IGN, NULL);
3677 (void) IOP_CTL(mdb.m_term, TIOCSPGRP, &pgid);
3678 (void) mdb_signal_sethandler(SIGTTOU, MDB_SIG_DFL, NULL);
3679 }
3680
3681 /*
3682 * If we're now stopped on exit from a successful exec, release any
3683 * vfork parents and clean out their address space before returning
3684 * to tgt_continue() and perturbing the list of armed event specs.
3685 * If we're stopped for any other reason, just update the mappings.
3686 */
3687 switch (Pstate(P)) {
3688 case PS_STOP:
3689 if (psp->pr_why == PR_SYSEXIT && psp->pr_errno == 0 &&
3690 psp->pr_what == SYS_execve)
3691 pt_release_parents(t);
3692 else
3693 Pupdate_maps(P);
3694 break;
3695
3696 case PS_UNDEAD:
3697 case PS_LOST:
3698 pt_release_parents(t);
3699 break;
3700 }
3701
3702 out:
3703 (void) mdb_signal_sethandler(SIGINT, intf, intd);
3704 (void) mdb_signal_sethandler(SIGQUIT, quitf, quitd);
3705 (void) mdb_signal_sethandler(SIGTSTP, tstpf, tstpd);
3706 (void) pt_status(t, tsp);
3707
3708 return (error ? set_errno(error) : 0);
3709 }
3710
3711 static int
pt_step(mdb_tgt_t * t,mdb_tgt_status_t * tsp)3712 pt_step(mdb_tgt_t *t, mdb_tgt_status_t *tsp)
3713 {
3714 return (pt_setrun(t, tsp, PRSTEP));
3715 }
3716
3717 static int
pt_continue(mdb_tgt_t * t,mdb_tgt_status_t * tsp)3718 pt_continue(mdb_tgt_t *t, mdb_tgt_status_t *tsp)
3719 {
3720 return (pt_setrun(t, tsp, 0));
3721 }
3722
3723 static int
pt_signal(mdb_tgt_t * t,int sig)3724 pt_signal(mdb_tgt_t *t, int sig)
3725 {
3726 pt_data_t *pt = t->t_data;
3727
3728 if (sig > 0 && sig <= pt->p_maxsig) {
3729 pt->p_signal = sig; /* pending until next pt_setrun */
3730 return (0);
3731 }
3732
3733 return (set_errno(EMDB_BADSIGNUM));
3734 }
3735
3736 static int
pt_sysenter_ctor(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)3737 pt_sysenter_ctor(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
3738 {
3739 struct ps_prochandle *P = t->t_pshandle;
3740
3741 if (P != NULL && Pstate(P) < PS_LOST) {
3742 sep->se_data = args; /* data is raw system call number */
3743 return (Psysentry(P, (intptr_t)args, TRUE) < 0 ? -1 : 0);
3744 }
3745
3746 return (set_errno(EMDB_NOPROC));
3747 }
3748
3749 static void
pt_sysenter_dtor(mdb_tgt_t * t,mdb_sespec_t * sep)3750 pt_sysenter_dtor(mdb_tgt_t *t, mdb_sespec_t *sep)
3751 {
3752 (void) Psysentry(t->t_pshandle, (intptr_t)sep->se_data, FALSE);
3753 }
3754
3755 /*ARGSUSED*/
3756 static char *
pt_sysenter_info(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_vespec_t * vep,mdb_tgt_spec_desc_t * sp,char * buf,size_t nbytes)3757 pt_sysenter_info(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_vespec_t *vep,
3758 mdb_tgt_spec_desc_t *sp, char *buf, size_t nbytes)
3759 {
3760 char name[32];
3761 int sysnum;
3762
3763 if (vep != NULL)
3764 sysnum = (intptr_t)vep->ve_args;
3765 else
3766 sysnum = (intptr_t)sep->se_data;
3767
3768 (void) proc_sysname(sysnum, name, sizeof (name));
3769 (void) mdb_iob_snprintf(buf, nbytes, "stop on entry to %s", name);
3770
3771 return (buf);
3772 }
3773
3774 /*ARGSUSED*/
3775 static int
pt_sysenter_match(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)3776 pt_sysenter_match(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
3777 {
3778 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
3779 int sysnum = (intptr_t)sep->se_data;
3780
3781 return (psp->pr_why == PR_SYSENTRY && psp->pr_what == sysnum);
3782 }
3783
3784 static const mdb_se_ops_t proc_sysenter_ops = {
3785 .se_ctor = pt_sysenter_ctor,
3786 .se_dtor = pt_sysenter_dtor,
3787 .se_info = pt_sysenter_info,
3788 .se_secmp = no_se_secmp,
3789 .se_vecmp = no_se_vecmp,
3790 .se_arm = no_se_arm,
3791 .se_disarm = no_se_disarm,
3792 .se_cont = no_se_cont,
3793 .se_match = pt_sysenter_match,
3794 };
3795
3796 static int
pt_sysexit_ctor(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)3797 pt_sysexit_ctor(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
3798 {
3799 struct ps_prochandle *P = t->t_pshandle;
3800
3801 if (P != NULL && Pstate(P) < PS_LOST) {
3802 sep->se_data = args; /* data is raw system call number */
3803 return (Psysexit(P, (intptr_t)args, TRUE) < 0 ? -1 : 0);
3804 }
3805
3806 return (set_errno(EMDB_NOPROC));
3807 }
3808
3809 static void
pt_sysexit_dtor(mdb_tgt_t * t,mdb_sespec_t * sep)3810 pt_sysexit_dtor(mdb_tgt_t *t, mdb_sespec_t *sep)
3811 {
3812 (void) Psysexit(t->t_pshandle, (intptr_t)sep->se_data, FALSE);
3813 }
3814
3815 /*ARGSUSED*/
3816 static char *
pt_sysexit_info(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_vespec_t * vep,mdb_tgt_spec_desc_t * sp,char * buf,size_t nbytes)3817 pt_sysexit_info(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_vespec_t *vep,
3818 mdb_tgt_spec_desc_t *sp, char *buf, size_t nbytes)
3819 {
3820 char name[32];
3821 int sysnum;
3822
3823 if (vep != NULL)
3824 sysnum = (intptr_t)vep->ve_args;
3825 else
3826 sysnum = (intptr_t)sep->se_data;
3827
3828 (void) proc_sysname(sysnum, name, sizeof (name));
3829 (void) mdb_iob_snprintf(buf, nbytes, "stop on exit from %s", name);
3830
3831 return (buf);
3832 }
3833
3834 /*ARGSUSED*/
3835 static int
pt_sysexit_match(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)3836 pt_sysexit_match(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
3837 {
3838 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
3839 int sysnum = (intptr_t)sep->se_data;
3840
3841 return (psp->pr_why == PR_SYSEXIT && psp->pr_what == sysnum);
3842 }
3843
3844 static const mdb_se_ops_t proc_sysexit_ops = {
3845 .se_ctor = pt_sysexit_ctor,
3846 .se_dtor = pt_sysexit_dtor,
3847 .se_info = pt_sysexit_info,
3848 .se_secmp = no_se_secmp,
3849 .se_vecmp = no_se_vecmp,
3850 .se_arm = no_se_arm,
3851 .se_disarm = no_se_disarm,
3852 .se_cont = no_se_cont,
3853 .se_match = pt_sysexit_match,
3854 };
3855
3856 static int
pt_signal_ctor(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)3857 pt_signal_ctor(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
3858 {
3859 struct ps_prochandle *P = t->t_pshandle;
3860
3861 if (P != NULL && Pstate(P) < PS_LOST) {
3862 sep->se_data = args; /* data is raw signal number */
3863 return (Psignal(P, (intptr_t)args, TRUE) < 0 ? -1 : 0);
3864 }
3865
3866 return (set_errno(EMDB_NOPROC));
3867 }
3868
3869 static void
pt_signal_dtor(mdb_tgt_t * t,mdb_sespec_t * sep)3870 pt_signal_dtor(mdb_tgt_t *t, mdb_sespec_t *sep)
3871 {
3872 (void) Psignal(t->t_pshandle, (intptr_t)sep->se_data, FALSE);
3873 }
3874
3875 /*ARGSUSED*/
3876 static char *
pt_signal_info(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_vespec_t * vep,mdb_tgt_spec_desc_t * sp,char * buf,size_t nbytes)3877 pt_signal_info(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_vespec_t *vep,
3878 mdb_tgt_spec_desc_t *sp, char *buf, size_t nbytes)
3879 {
3880 char name[SIG2STR_MAX];
3881 int signum;
3882
3883 if (vep != NULL)
3884 signum = (intptr_t)vep->ve_args;
3885 else
3886 signum = (intptr_t)sep->se_data;
3887
3888 (void) proc_signame(signum, name, sizeof (name));
3889 (void) mdb_iob_snprintf(buf, nbytes, "stop on %s", name);
3890
3891 return (buf);
3892 }
3893
3894 /*ARGSUSED*/
3895 static int
pt_signal_match(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)3896 pt_signal_match(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
3897 {
3898 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
3899 int signum = (intptr_t)sep->se_data;
3900
3901 return (psp->pr_why == PR_SIGNALLED && psp->pr_what == signum);
3902 }
3903
3904 static const mdb_se_ops_t proc_signal_ops = {
3905 .se_ctor = pt_signal_ctor,
3906 .se_dtor = pt_signal_dtor,
3907 .se_info = pt_signal_info,
3908 .se_secmp = no_se_secmp,
3909 .se_vecmp = no_se_vecmp,
3910 .se_arm = no_se_arm,
3911 .se_disarm = no_se_disarm,
3912 .se_cont = no_se_cont,
3913 .se_match = pt_signal_match,
3914 };
3915
3916 static int
pt_fault_ctor(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)3917 pt_fault_ctor(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
3918 {
3919 struct ps_prochandle *P = t->t_pshandle;
3920
3921 if (P != NULL && Pstate(P) < PS_LOST) {
3922 sep->se_data = args; /* data is raw fault number */
3923 return (Pfault(P, (intptr_t)args, TRUE) < 0 ? -1 : 0);
3924 }
3925
3926 return (set_errno(EMDB_NOPROC));
3927 }
3928
3929 static void
pt_fault_dtor(mdb_tgt_t * t,mdb_sespec_t * sep)3930 pt_fault_dtor(mdb_tgt_t *t, mdb_sespec_t *sep)
3931 {
3932 int fault = (intptr_t)sep->se_data;
3933
3934 if (fault != FLTBPT && fault != FLTTRACE && fault != FLTWATCH)
3935 (void) Pfault(t->t_pshandle, fault, FALSE);
3936 }
3937
3938 /*ARGSUSED*/
3939 static char *
pt_fault_info(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_vespec_t * vep,mdb_tgt_spec_desc_t * sp,char * buf,size_t nbytes)3940 pt_fault_info(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_vespec_t *vep,
3941 mdb_tgt_spec_desc_t *sp, char *buf, size_t nbytes)
3942 {
3943 char name[32];
3944 int fltnum;
3945
3946 if (vep != NULL)
3947 fltnum = (intptr_t)vep->ve_args;
3948 else
3949 fltnum = (intptr_t)sep->se_data;
3950
3951 (void) proc_fltname(fltnum, name, sizeof (name));
3952 (void) mdb_iob_snprintf(buf, nbytes, "stop on %s", name);
3953
3954 return (buf);
3955 }
3956
3957 /*ARGSUSED*/
3958 static int
pt_fault_match(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)3959 pt_fault_match(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
3960 {
3961 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
3962 int fltnum = (intptr_t)sep->se_data;
3963
3964 return (psp->pr_why == PR_FAULTED && psp->pr_what == fltnum);
3965 }
3966
3967 static const mdb_se_ops_t proc_fault_ops = {
3968 .se_ctor = pt_fault_ctor,
3969 .se_dtor = pt_fault_dtor,
3970 .se_info = pt_fault_info,
3971 .se_secmp = no_se_secmp,
3972 .se_vecmp = no_se_vecmp,
3973 .se_arm = no_se_arm,
3974 .se_disarm = no_se_disarm,
3975 .se_cont = no_se_cont,
3976 .se_match = pt_fault_match,
3977 };
3978
3979 /*
3980 * Callback for pt_ignore() dcmd above: for each VID, determine if it
3981 * corresponds to a vespec that traces the specified signal, and delete it.
3982 */
3983 /*ARGSUSED*/
3984 static int
pt_ignore_sig(mdb_tgt_t * t,void * sig,int vid,void * data)3985 pt_ignore_sig(mdb_tgt_t *t, void *sig, int vid, void *data)
3986 {
3987 mdb_vespec_t *vep = mdb_tgt_vespec_lookup(t, vid);
3988
3989 if (vep->ve_se->se_ops == &proc_signal_ops && vep->ve_args == sig)
3990 (void) mdb_tgt_vespec_delete(t, vid);
3991
3992 return (0);
3993 }
3994
3995 static int
pt_brkpt_ctor(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)3996 pt_brkpt_ctor(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
3997 {
3998 pt_data_t *pt = t->t_data;
3999 pt_bparg_t *pta = args;
4000 pt_brkpt_t *ptb;
4001 GElf_Sym s;
4002
4003 if (t->t_pshandle == NULL || Pstate(t->t_pshandle) >= PS_LOST)
4004 return (set_errno(EMDB_NOPROC));
4005
4006 if (pta->pta_symbol != NULL) {
4007 if (!pt->p_rtld_finished &&
4008 strchr(pta->pta_symbol, '`') == NULL)
4009 return (set_errno(EMDB_NOSYM));
4010 if (mdb_tgt_lookup_by_scope(t, pta->pta_symbol, &s,
4011 NULL) == -1) {
4012 if (errno != EMDB_NOOBJ && !(errno == EMDB_NOSYM &&
4013 (!(mdb.m_flags & MDB_FL_BPTNOSYMSTOP) ||
4014 !pt->p_rtld_finished))) {
4015 warn("breakpoint %s activation failed",
4016 pta->pta_symbol);
4017 }
4018 return (-1); /* errno is set for us */
4019 }
4020
4021 pta->pta_addr = (uintptr_t)s.st_value;
4022 }
4023
4024 #ifdef __sparc
4025 if (pta->pta_addr & 3)
4026 return (set_errno(EMDB_BPALIGN));
4027 #endif
4028
4029 if (Paddr_to_map(t->t_pshandle, pta->pta_addr) == NULL)
4030 return (set_errno(EMDB_NOMAP));
4031
4032 ptb = mdb_alloc(sizeof (pt_brkpt_t), UM_SLEEP);
4033 ptb->ptb_addr = pta->pta_addr;
4034 ptb->ptb_instr = 0;
4035 sep->se_data = ptb;
4036
4037 return (0);
4038 }
4039
4040 /*ARGSUSED*/
4041 static void
pt_brkpt_dtor(mdb_tgt_t * t,mdb_sespec_t * sep)4042 pt_brkpt_dtor(mdb_tgt_t *t, mdb_sespec_t *sep)
4043 {
4044 mdb_free(sep->se_data, sizeof (pt_brkpt_t));
4045 }
4046
4047 /*ARGSUSED*/
4048 static char *
pt_brkpt_info(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_vespec_t * vep,mdb_tgt_spec_desc_t * sp,char * buf,size_t nbytes)4049 pt_brkpt_info(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_vespec_t *vep,
4050 mdb_tgt_spec_desc_t *sp, char *buf, size_t nbytes)
4051 {
4052 uintptr_t addr = 0;
4053
4054 if (vep != NULL) {
4055 pt_bparg_t *pta = vep->ve_args;
4056
4057 if (pta->pta_symbol != NULL) {
4058 (void) mdb_iob_snprintf(buf, nbytes, "stop at %s",
4059 pta->pta_symbol);
4060 } else {
4061 (void) mdb_iob_snprintf(buf, nbytes, "stop at %a",
4062 pta->pta_addr);
4063 addr = pta->pta_addr;
4064 }
4065
4066 } else {
4067 addr = ((pt_brkpt_t *)sep->se_data)->ptb_addr;
4068 (void) mdb_iob_snprintf(buf, nbytes, "stop at %a", addr);
4069 }
4070
4071 sp->spec_base = addr;
4072 sp->spec_size = sizeof (instr_t);
4073
4074 return (buf);
4075 }
4076
4077 static int
pt_brkpt_secmp(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)4078 pt_brkpt_secmp(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
4079 {
4080 pt_brkpt_t *ptb = sep->se_data;
4081 pt_bparg_t *pta = args;
4082 GElf_Sym sym;
4083
4084 if (pta->pta_symbol != NULL) {
4085 return (mdb_tgt_lookup_by_scope(t, pta->pta_symbol,
4086 &sym, NULL) == 0 && sym.st_value == ptb->ptb_addr);
4087 }
4088
4089 return (pta->pta_addr == ptb->ptb_addr);
4090 }
4091
4092 /*ARGSUSED*/
4093 static int
pt_brkpt_vecmp(mdb_tgt_t * t,mdb_vespec_t * vep,void * args)4094 pt_brkpt_vecmp(mdb_tgt_t *t, mdb_vespec_t *vep, void *args)
4095 {
4096 pt_bparg_t *pta1 = vep->ve_args;
4097 pt_bparg_t *pta2 = args;
4098
4099 if (pta1->pta_symbol != NULL && pta2->pta_symbol != NULL)
4100 return (strcmp(pta1->pta_symbol, pta2->pta_symbol) == 0);
4101
4102 if (pta1->pta_symbol == NULL && pta2->pta_symbol == NULL)
4103 return (pta1->pta_addr == pta2->pta_addr);
4104
4105 return (0); /* fail if one is symbolic, other is an explicit address */
4106 }
4107
4108 static int
pt_brkpt_arm(mdb_tgt_t * t,mdb_sespec_t * sep)4109 pt_brkpt_arm(mdb_tgt_t *t, mdb_sespec_t *sep)
4110 {
4111 pt_brkpt_t *ptb = sep->se_data;
4112 return (Psetbkpt(t->t_pshandle, ptb->ptb_addr, &ptb->ptb_instr));
4113 }
4114
4115 /*
4116 * In order to disarm a breakpoint, we replace the trap instruction at ptb_addr
4117 * with the saved instruction. However, if we have stopped after a successful
4118 * exec(2), we do not want to restore ptb_instr because the address space has
4119 * now been replaced with the text of a different executable, and so restoring
4120 * the saved instruction would be incorrect. The exec itself has effectively
4121 * removed all breakpoint trap instructions for us, so we can just return.
4122 */
4123 static int
pt_brkpt_disarm(mdb_tgt_t * t,mdb_sespec_t * sep)4124 pt_brkpt_disarm(mdb_tgt_t *t, mdb_sespec_t *sep)
4125 {
4126 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
4127 pt_brkpt_t *ptb = sep->se_data;
4128
4129 if (psp->pr_why == PR_SYSEXIT && psp->pr_errno == 0 &&
4130 psp->pr_what == SYS_execve)
4131 return (0); /* do not restore saved instruction */
4132
4133 return (Pdelbkpt(t->t_pshandle, ptb->ptb_addr, ptb->ptb_instr));
4134 }
4135
4136 /*
4137 * Determine whether the specified sespec is an armed watchpoint that overlaps
4138 * with the given breakpoint and has the given flags set. We use this to find
4139 * conflicts with breakpoints, below.
4140 */
4141 static int
pt_wp_overlap(mdb_sespec_t * sep,pt_brkpt_t * ptb,int flags)4142 pt_wp_overlap(mdb_sespec_t *sep, pt_brkpt_t *ptb, int flags)
4143 {
4144 const prwatch_t *wp = sep->se_data;
4145
4146 return (sep->se_state == MDB_TGT_SPEC_ARMED &&
4147 sep->se_ops == &proc_wapt_ops && (wp->pr_wflags & flags) &&
4148 ptb->ptb_addr - wp->pr_vaddr < wp->pr_size);
4149 }
4150
4151 /*
4152 * We step over breakpoints using Pxecbkpt() in libproc. If a conflicting
4153 * watchpoint is present, we must temporarily remove it before stepping over
4154 * the breakpoint so we do not immediately re-trigger the watchpoint. We know
4155 * the watchpoint has already triggered on our trap instruction as part of
4156 * fetching it. Before we return, we must re-install any disabled watchpoints.
4157 */
4158 static int
pt_brkpt_cont(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)4159 pt_brkpt_cont(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
4160 {
4161 pt_brkpt_t *ptb = sep->se_data;
4162 int status = -1;
4163 int error;
4164 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
4165
4166 /*
4167 * If the PC no longer matches our original address, then the user has
4168 * changed it while we have been stopped. In this case, it no longer
4169 * makes any sense to continue over this breakpoint. We return as if we
4170 * continued normally.
4171 */
4172 if ((uintptr_t)psp->pr_info.si_addr != psp->pr_reg[R_PC])
4173 return (pt_status(t, tsp));
4174
4175 for (sep = mdb_list_next(&t->t_active); sep; sep = mdb_list_next(sep)) {
4176 if (pt_wp_overlap(sep, ptb, WA_EXEC))
4177 (void) Pdelwapt(t->t_pshandle, sep->se_data);
4178 }
4179
4180 if (Pxecbkpt(t->t_pshandle, ptb->ptb_instr) == 0 &&
4181 Pdelbkpt(t->t_pshandle, ptb->ptb_addr, ptb->ptb_instr) == 0)
4182 status = pt_status(t, tsp);
4183
4184 error = errno; /* save errno from Pxecbkpt, Pdelbkpt, or pt_status */
4185
4186 for (sep = mdb_list_next(&t->t_active); sep; sep = mdb_list_next(sep)) {
4187 if (pt_wp_overlap(sep, ptb, WA_EXEC) &&
4188 Psetwapt(t->t_pshandle, sep->se_data) == -1) {
4189 sep->se_state = MDB_TGT_SPEC_ERROR;
4190 sep->se_errno = errno;
4191 }
4192 }
4193
4194 (void) set_errno(error);
4195 return (status);
4196 }
4197
4198 /*ARGSUSED*/
4199 static int
pt_brkpt_match(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)4200 pt_brkpt_match(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
4201 {
4202 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
4203 pt_brkpt_t *ptb = sep->se_data;
4204
4205 return (psp->pr_why == PR_FAULTED && psp->pr_what == FLTBPT &&
4206 psp->pr_reg[R_PC] == ptb->ptb_addr);
4207 }
4208
4209 static const mdb_se_ops_t proc_brkpt_ops = {
4210 .se_ctor = pt_brkpt_ctor,
4211 .se_dtor = pt_brkpt_dtor,
4212 .se_info = pt_brkpt_info,
4213 .se_secmp = pt_brkpt_secmp,
4214 .se_vecmp = pt_brkpt_vecmp,
4215 .se_arm = pt_brkpt_arm,
4216 .se_disarm = pt_brkpt_disarm,
4217 .se_cont = pt_brkpt_cont,
4218 .se_match = pt_brkpt_match,
4219 };
4220
4221 static int
pt_wapt_ctor(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)4222 pt_wapt_ctor(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
4223 {
4224 if (t->t_pshandle == NULL || Pstate(t->t_pshandle) >= PS_LOST)
4225 return (set_errno(EMDB_NOPROC));
4226
4227 sep->se_data = mdb_alloc(sizeof (prwatch_t), UM_SLEEP);
4228 bcopy(args, sep->se_data, sizeof (prwatch_t));
4229 return (0);
4230 }
4231
4232 /*ARGSUSED*/
4233 static void
pt_wapt_dtor(mdb_tgt_t * t,mdb_sespec_t * sep)4234 pt_wapt_dtor(mdb_tgt_t *t, mdb_sespec_t *sep)
4235 {
4236 mdb_free(sep->se_data, sizeof (prwatch_t));
4237 }
4238
4239 /*ARGSUSED*/
4240 static char *
pt_wapt_info(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_vespec_t * vep,mdb_tgt_spec_desc_t * sp,char * buf,size_t nbytes)4241 pt_wapt_info(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_vespec_t *vep,
4242 mdb_tgt_spec_desc_t *sp, char *buf, size_t nbytes)
4243 {
4244 prwatch_t *wp = vep != NULL ? vep->ve_args : sep->se_data;
4245 char desc[24];
4246
4247 ASSERT(wp->pr_wflags != 0);
4248 desc[0] = '\0';
4249
4250 switch (wp->pr_wflags) {
4251 case WA_READ:
4252 (void) strcat(desc, "/read");
4253 break;
4254 case WA_WRITE:
4255 (void) strcat(desc, "/write");
4256 break;
4257 case WA_EXEC:
4258 (void) strcat(desc, "/exec");
4259 break;
4260 default:
4261 if (wp->pr_wflags & WA_READ)
4262 (void) strcat(desc, "/r");
4263 if (wp->pr_wflags & WA_WRITE)
4264 (void) strcat(desc, "/w");
4265 if (wp->pr_wflags & WA_EXEC)
4266 (void) strcat(desc, "/x");
4267 }
4268
4269 (void) mdb_iob_snprintf(buf, nbytes, "stop on %s of [%la, %la)",
4270 desc + 1, wp->pr_vaddr, wp->pr_vaddr + wp->pr_size);
4271
4272 sp->spec_base = wp->pr_vaddr;
4273 sp->spec_size = wp->pr_size;
4274
4275 return (buf);
4276 }
4277
4278 /*ARGSUSED*/
4279 static int
pt_wapt_secmp(mdb_tgt_t * t,mdb_sespec_t * sep,void * args)4280 pt_wapt_secmp(mdb_tgt_t *t, mdb_sespec_t *sep, void *args)
4281 {
4282 prwatch_t *wp1 = sep->se_data;
4283 prwatch_t *wp2 = args;
4284
4285 return (wp1->pr_vaddr == wp2->pr_vaddr &&
4286 wp1->pr_size == wp2->pr_size && wp1->pr_wflags == wp2->pr_wflags);
4287 }
4288
4289 /*ARGSUSED*/
4290 static int
pt_wapt_vecmp(mdb_tgt_t * t,mdb_vespec_t * vep,void * args)4291 pt_wapt_vecmp(mdb_tgt_t *t, mdb_vespec_t *vep, void *args)
4292 {
4293 prwatch_t *wp1 = vep->ve_args;
4294 prwatch_t *wp2 = args;
4295
4296 return (wp1->pr_vaddr == wp2->pr_vaddr &&
4297 wp1->pr_size == wp2->pr_size && wp1->pr_wflags == wp2->pr_wflags);
4298 }
4299
4300 static int
pt_wapt_arm(mdb_tgt_t * t,mdb_sespec_t * sep)4301 pt_wapt_arm(mdb_tgt_t *t, mdb_sespec_t *sep)
4302 {
4303 return (Psetwapt(t->t_pshandle, sep->se_data));
4304 }
4305
4306 static int
pt_wapt_disarm(mdb_tgt_t * t,mdb_sespec_t * sep)4307 pt_wapt_disarm(mdb_tgt_t *t, mdb_sespec_t *sep)
4308 {
4309 return (Pdelwapt(t->t_pshandle, sep->se_data));
4310 }
4311
4312 /*
4313 * Determine whether the specified sespec is an armed breakpoint at the
4314 * given %pc. We use this to find conflicts with watchpoints below.
4315 */
4316 static int
pt_bp_overlap(mdb_sespec_t * sep,uintptr_t pc)4317 pt_bp_overlap(mdb_sespec_t *sep, uintptr_t pc)
4318 {
4319 pt_brkpt_t *ptb = sep->se_data;
4320
4321 return (sep->se_state == MDB_TGT_SPEC_ARMED &&
4322 sep->se_ops == &proc_brkpt_ops && ptb->ptb_addr == pc);
4323 }
4324
4325 /*
4326 * We step over watchpoints using Pxecwapt() in libproc. If a conflicting
4327 * breakpoint is present, we must temporarily disarm it before stepping
4328 * over the watchpoint so we do not immediately re-trigger the breakpoint.
4329 * This is similar to the case handled in pt_brkpt_cont(), above.
4330 */
4331 static int
pt_wapt_cont(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)4332 pt_wapt_cont(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
4333 {
4334 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
4335 mdb_sespec_t *bep = NULL;
4336 int status = -1;
4337 int error;
4338
4339 /*
4340 * If the PC no longer matches our original address, then the user has
4341 * changed it while we have been stopped. In this case, it no longer
4342 * makes any sense to continue over this instruction. We return as if
4343 * we continued normally.
4344 */
4345 if ((uintptr_t)psp->pr_info.si_pc != psp->pr_reg[R_PC])
4346 return (pt_status(t, tsp));
4347
4348 if (psp->pr_info.si_code != TRAP_XWATCH) {
4349 for (bep = mdb_list_next(&t->t_active); bep != NULL;
4350 bep = mdb_list_next(bep)) {
4351 if (pt_bp_overlap(bep, psp->pr_reg[R_PC])) {
4352 (void) bep->se_ops->se_disarm(t, bep);
4353 bep->se_state = MDB_TGT_SPEC_ACTIVE;
4354 break;
4355 }
4356 }
4357 }
4358
4359 if (Pxecwapt(t->t_pshandle, sep->se_data) == 0)
4360 status = pt_status(t, tsp);
4361
4362 error = errno; /* save errno from Pxecwapt or pt_status */
4363
4364 if (bep != NULL)
4365 mdb_tgt_sespec_arm_one(t, bep);
4366
4367 (void) set_errno(error);
4368 return (status);
4369 }
4370
4371 /*ARGSUSED*/
4372 static int
pt_wapt_match(mdb_tgt_t * t,mdb_sespec_t * sep,mdb_tgt_status_t * tsp)4373 pt_wapt_match(mdb_tgt_t *t, mdb_sespec_t *sep, mdb_tgt_status_t *tsp)
4374 {
4375 const lwpstatus_t *psp = &Pstatus(t->t_pshandle)->pr_lwp;
4376 prwatch_t *wp = sep->se_data;
4377
4378 return (psp->pr_why == PR_FAULTED && psp->pr_what == FLTWATCH &&
4379 (uintptr_t)psp->pr_info.si_addr - wp->pr_vaddr < wp->pr_size);
4380 }
4381
4382 static const mdb_se_ops_t proc_wapt_ops = {
4383 .se_ctor = pt_wapt_ctor,
4384 .se_dtor = pt_wapt_dtor,
4385 .se_info = pt_wapt_info,
4386 .se_secmp = pt_wapt_secmp,
4387 .se_vecmp = pt_wapt_vecmp,
4388 .se_arm = pt_wapt_arm,
4389 .se_disarm = pt_wapt_disarm,
4390 .se_cont = pt_wapt_cont,
4391 .se_match = pt_wapt_match,
4392 };
4393
4394 static void
pt_bparg_dtor(mdb_vespec_t * vep)4395 pt_bparg_dtor(mdb_vespec_t *vep)
4396 {
4397 pt_bparg_t *pta = vep->ve_args;
4398
4399 if (pta->pta_symbol != NULL)
4400 strfree(pta->pta_symbol);
4401
4402 mdb_free(pta, sizeof (pt_bparg_t));
4403 }
4404
4405 static int
pt_add_vbrkpt(mdb_tgt_t * t,uintptr_t addr,int spec_flags,mdb_tgt_se_f * func,void * data)4406 pt_add_vbrkpt(mdb_tgt_t *t, uintptr_t addr,
4407 int spec_flags, mdb_tgt_se_f *func, void *data)
4408 {
4409 pt_bparg_t *pta = mdb_alloc(sizeof (pt_bparg_t), UM_SLEEP);
4410
4411 pta->pta_symbol = NULL;
4412 pta->pta_addr = addr;
4413
4414 return (mdb_tgt_vespec_insert(t, &proc_brkpt_ops, spec_flags,
4415 func, data, pta, pt_bparg_dtor));
4416 }
4417
4418 static int
pt_add_sbrkpt(mdb_tgt_t * t,const char * sym,int spec_flags,mdb_tgt_se_f * func,void * data)4419 pt_add_sbrkpt(mdb_tgt_t *t, const char *sym,
4420 int spec_flags, mdb_tgt_se_f *func, void *data)
4421 {
4422 pt_bparg_t *pta;
4423
4424 if (sym[0] == '`') {
4425 (void) set_errno(EMDB_NOOBJ);
4426 return (0);
4427 }
4428
4429 if (sym[strlen(sym) - 1] == '`') {
4430 (void) set_errno(EMDB_NOSYM);
4431 return (0);
4432 }
4433
4434 pta = mdb_alloc(sizeof (pt_bparg_t), UM_SLEEP);
4435 pta->pta_symbol = strdup(sym);
4436 pta->pta_addr = 0;
4437
4438 return (mdb_tgt_vespec_insert(t, &proc_brkpt_ops, spec_flags,
4439 func, data, pta, pt_bparg_dtor));
4440 }
4441
4442 static int
pt_wparg_overlap(const prwatch_t * wp1,const prwatch_t * wp2)4443 pt_wparg_overlap(const prwatch_t *wp1, const prwatch_t *wp2)
4444 {
4445 if (wp2->pr_vaddr + wp2->pr_size <= wp1->pr_vaddr)
4446 return (0); /* no range overlap */
4447
4448 if (wp1->pr_vaddr + wp1->pr_size <= wp2->pr_vaddr)
4449 return (0); /* no range overlap */
4450
4451 return (wp1->pr_vaddr != wp2->pr_vaddr ||
4452 wp1->pr_size != wp2->pr_size || wp1->pr_wflags != wp2->pr_wflags);
4453 }
4454
4455 static void
pt_wparg_dtor(mdb_vespec_t * vep)4456 pt_wparg_dtor(mdb_vespec_t *vep)
4457 {
4458 mdb_free(vep->ve_args, sizeof (prwatch_t));
4459 }
4460
4461 static int
pt_add_vwapt(mdb_tgt_t * t,uintptr_t addr,size_t len,uint_t wflags,int spec_flags,mdb_tgt_se_f * func,void * data)4462 pt_add_vwapt(mdb_tgt_t *t, uintptr_t addr, size_t len, uint_t wflags,
4463 int spec_flags, mdb_tgt_se_f *func, void *data)
4464 {
4465 prwatch_t *wp = mdb_alloc(sizeof (prwatch_t), UM_SLEEP);
4466 mdb_sespec_t *sep;
4467
4468 wp->pr_vaddr = addr;
4469 wp->pr_size = len;
4470 wp->pr_wflags = 0;
4471
4472 if (wflags & MDB_TGT_WA_R)
4473 wp->pr_wflags |= WA_READ;
4474 if (wflags & MDB_TGT_WA_W)
4475 wp->pr_wflags |= WA_WRITE;
4476 if (wflags & MDB_TGT_WA_X)
4477 wp->pr_wflags |= WA_EXEC;
4478
4479 for (sep = mdb_list_next(&t->t_active); sep; sep = mdb_list_next(sep)) {
4480 if (sep->se_ops == &proc_wapt_ops &&
4481 mdb_list_next(&sep->se_velist) != NULL &&
4482 pt_wparg_overlap(wp, sep->se_data))
4483 goto dup;
4484 }
4485
4486 for (sep = mdb_list_next(&t->t_idle); sep; sep = mdb_list_next(sep)) {
4487 if (sep->se_ops == &proc_wapt_ops && pt_wparg_overlap(wp,
4488 ((mdb_vespec_t *)mdb_list_next(&sep->se_velist))->ve_args))
4489 goto dup;
4490 }
4491
4492 return (mdb_tgt_vespec_insert(t, &proc_wapt_ops, spec_flags,
4493 func, data, wp, pt_wparg_dtor));
4494
4495 dup:
4496 mdb_free(wp, sizeof (prwatch_t));
4497 (void) set_errno(EMDB_WPDUP);
4498 return (0);
4499 }
4500
4501 static int
pt_add_sysenter(mdb_tgt_t * t,int sysnum,int spec_flags,mdb_tgt_se_f * func,void * data)4502 pt_add_sysenter(mdb_tgt_t *t, int sysnum,
4503 int spec_flags, mdb_tgt_se_f *func, void *data)
4504 {
4505 if (sysnum <= 0 || sysnum > PRMAXSYS) {
4506 (void) set_errno(EMDB_BADSYSNUM);
4507 return (0);
4508 }
4509
4510 return (mdb_tgt_vespec_insert(t, &proc_sysenter_ops, spec_flags,
4511 func, data, (void *)(uintptr_t)sysnum, no_ve_dtor));
4512 }
4513
4514 static int
pt_add_sysexit(mdb_tgt_t * t,int sysnum,int spec_flags,mdb_tgt_se_f * func,void * data)4515 pt_add_sysexit(mdb_tgt_t *t, int sysnum,
4516 int spec_flags, mdb_tgt_se_f *func, void *data)
4517 {
4518 if (sysnum <= 0 || sysnum > PRMAXSYS) {
4519 (void) set_errno(EMDB_BADSYSNUM);
4520 return (0);
4521 }
4522
4523 return (mdb_tgt_vespec_insert(t, &proc_sysexit_ops, spec_flags,
4524 func, data, (void *)(uintptr_t)sysnum, no_ve_dtor));
4525 }
4526
4527 static int
pt_add_signal(mdb_tgt_t * t,int signum,int spec_flags,mdb_tgt_se_f * func,void * data)4528 pt_add_signal(mdb_tgt_t *t, int signum,
4529 int spec_flags, mdb_tgt_se_f *func, void *data)
4530 {
4531 pt_data_t *pt = t->t_data;
4532
4533 if (signum <= 0 || signum > pt->p_maxsig) {
4534 (void) set_errno(EMDB_BADSIGNUM);
4535 return (0);
4536 }
4537
4538 return (mdb_tgt_vespec_insert(t, &proc_signal_ops, spec_flags,
4539 func, data, (void *)(uintptr_t)signum, no_ve_dtor));
4540 }
4541
4542 static int
pt_add_fault(mdb_tgt_t * t,int fltnum,int spec_flags,mdb_tgt_se_f * func,void * data)4543 pt_add_fault(mdb_tgt_t *t, int fltnum,
4544 int spec_flags, mdb_tgt_se_f *func, void *data)
4545 {
4546 if (fltnum <= 0 || fltnum > PRMAXFAULT) {
4547 (void) set_errno(EMDB_BADFLTNUM);
4548 return (0);
4549 }
4550
4551 return (mdb_tgt_vespec_insert(t, &proc_fault_ops, spec_flags,
4552 func, data, (void *)(uintptr_t)fltnum, no_ve_dtor));
4553 }
4554
4555 static int
pt_getareg(mdb_tgt_t * t,mdb_tgt_tid_t tid,const char * rname,mdb_tgt_reg_t * rp)4556 pt_getareg(mdb_tgt_t *t, mdb_tgt_tid_t tid,
4557 const char *rname, mdb_tgt_reg_t *rp)
4558 {
4559 pt_data_t *pt = t->t_data;
4560 prgregset_t grs;
4561 mdb_var_t *v;
4562
4563 if (t->t_pshandle == NULL)
4564 return (set_errno(EMDB_NOPROC));
4565
4566 if ((v = mdb_nv_lookup(&pt->p_regs, rname)) != NULL) {
4567 uintmax_t rd_nval = mdb_nv_get_value(v);
4568 ushort_t rd_num = MDB_TGT_R_NUM(rd_nval);
4569 ushort_t rd_flags = MDB_TGT_R_FLAGS(rd_nval);
4570
4571 if (!MDB_TGT_R_IS_FP(rd_flags)) {
4572 mdb_tgt_reg_t r = 0;
4573
4574 #if defined(__sparc) && defined(_ILP32)
4575 /*
4576 * If we are debugging on 32-bit SPARC, the globals and
4577 * outs can have 32 upper bits hiding in the xregs.
4578 */
4579 /* gcc doesn't like >= R_G0 because R_G0 == 0 */
4580 int is_g = (rd_num == R_G0 ||
4581 rd_num >= R_G1 && rd_num <= R_G7);
4582 int is_o = (rd_num >= R_O0 && rd_num <= R_O7);
4583 prxregset_t xrs;
4584
4585 if (is_g && PTL_GETXREGS(t, tid, &xrs) == 0 &&
4586 xrs.pr_type == XR_TYPE_V8P) {
4587 r |= (uint64_t)xrs.pr_un.pr_v8p.pr_xg[
4588 rd_num - R_G0 + XR_G0] << 32;
4589 }
4590
4591 if (is_o && PTL_GETXREGS(t, tid, &xrs) == 0 &&
4592 xrs.pr_type == XR_TYPE_V8P) {
4593 r |= (uint64_t)xrs.pr_un.pr_v8p.pr_xo[
4594 rd_num - R_O0 + XR_O0] << 32;
4595 }
4596 #endif /* __sparc && _ILP32 */
4597
4598 /*
4599 * Avoid sign-extension by casting: recall that procfs
4600 * defines prgreg_t as a long or int and our native
4601 * register handling uses uint64_t's.
4602 */
4603 if (PTL_GETREGS(t, tid, grs) == 0) {
4604 *rp = r | (ulong_t)grs[rd_num];
4605 if (rd_flags & MDB_TGT_R_32)
4606 *rp &= 0xffffffffULL;
4607 else if (rd_flags & MDB_TGT_R_16)
4608 *rp &= 0xffffULL;
4609 else if (rd_flags & MDB_TGT_R_8H)
4610 *rp = (*rp & 0xff00ULL) >> 8;
4611 else if (rd_flags & MDB_TGT_R_8L)
4612 *rp &= 0xffULL;
4613 return (0);
4614 }
4615 return (-1);
4616 } else
4617 return (pt_getfpreg(t, tid, rd_num, rd_flags, rp));
4618 }
4619
4620 return (set_errno(EMDB_BADREG));
4621 }
4622
4623 static int
pt_putareg(mdb_tgt_t * t,mdb_tgt_tid_t tid,const char * rname,mdb_tgt_reg_t r)4624 pt_putareg(mdb_tgt_t *t, mdb_tgt_tid_t tid, const char *rname, mdb_tgt_reg_t r)
4625 {
4626 pt_data_t *pt = t->t_data;
4627 prgregset_t grs;
4628 mdb_var_t *v;
4629
4630 if (t->t_pshandle == NULL)
4631 return (set_errno(EMDB_NOPROC));
4632
4633 if ((v = mdb_nv_lookup(&pt->p_regs, rname)) != NULL) {
4634 uintmax_t rd_nval = mdb_nv_get_value(v);
4635 ushort_t rd_num = MDB_TGT_R_NUM(rd_nval);
4636 ushort_t rd_flags = MDB_TGT_R_FLAGS(rd_nval);
4637
4638 if (!MDB_TGT_R_IS_FP(rd_flags)) {
4639
4640 if (rd_flags & MDB_TGT_R_32)
4641 r &= 0xffffffffULL;
4642 else if (rd_flags & MDB_TGT_R_16)
4643 r &= 0xffffULL;
4644 else if (rd_flags & MDB_TGT_R_8H)
4645 r = (r & 0xffULL) << 8;
4646 else if (rd_flags & MDB_TGT_R_8L)
4647 r &= 0xffULL;
4648
4649 if (PTL_GETREGS(t, tid, grs) == 0) {
4650 grs[rd_num] = (prgreg_t)r;
4651 return (PTL_SETREGS(t, tid, grs));
4652 }
4653 return (-1);
4654 } else
4655 return (pt_putfpreg(t, tid, rd_num, rd_flags, r));
4656 }
4657
4658 return (set_errno(EMDB_BADREG));
4659 }
4660
4661 static int
pt_stack_call(pt_stkarg_t * psp,const prgregset_t grs,uint_t argc,long * argv)4662 pt_stack_call(pt_stkarg_t *psp, const prgregset_t grs, uint_t argc, long *argv)
4663 {
4664 psp->pstk_gotpc |= (grs[R_PC] != 0);
4665
4666 if (!psp->pstk_gotpc)
4667 return (0); /* skip initial zeroed frames */
4668
4669 return (psp->pstk_func(psp->pstk_private, grs[R_PC],
4670 argc, argv, (const struct mdb_tgt_gregset *)grs));
4671 }
4672
4673 static int
pt_stack_iter(mdb_tgt_t * t,const mdb_tgt_gregset_t * gsp,mdb_tgt_stack_f * func,void * arg)4674 pt_stack_iter(mdb_tgt_t *t, const mdb_tgt_gregset_t *gsp,
4675 mdb_tgt_stack_f *func, void *arg)
4676 {
4677 if (t->t_pshandle != NULL) {
4678 pt_stkarg_t pstk;
4679
4680 pstk.pstk_func = func;
4681 pstk.pstk_private = arg;
4682 pstk.pstk_gotpc = FALSE;
4683
4684 (void) Pstack_iter(t->t_pshandle, gsp->gregs,
4685 (proc_stack_f *)pt_stack_call, &pstk);
4686
4687 return (0);
4688 }
4689
4690 return (set_errno(EMDB_NOPROC));
4691 }
4692
4693 static int
pt_auxv(mdb_tgt_t * t,const auxv_t ** auxvp)4694 pt_auxv(mdb_tgt_t *t, const auxv_t **auxvp)
4695 {
4696 if (t->t_pshandle != NULL) {
4697 *auxvp = Pgetauxvec(t->t_pshandle);
4698 return (0);
4699 }
4700
4701 return (set_errno(EMDB_NOPROC));
4702 }
4703
4704
4705 static const mdb_tgt_ops_t proc_ops = {
4706 .t_setflags = pt_setflags,
4707 .t_setcontext = (int (*)())(uintptr_t)mdb_tgt_notsup,
4708 .t_activate = pt_activate,
4709 .t_deactivate = pt_deactivate,
4710 .t_periodic = pt_periodic,
4711 .t_destroy = pt_destroy,
4712 .t_name = pt_name,
4713 .t_isa = (const char *(*)())mdb_conf_isa,
4714 .t_platform = pt_platform,
4715 .t_uname = pt_uname,
4716 .t_dmodel = pt_dmodel,
4717 .t_aread = (ssize_t (*)())mdb_tgt_notsup,
4718 .t_awrite = (ssize_t (*)())mdb_tgt_notsup,
4719 .t_vread = pt_vread,
4720 .t_vwrite = pt_vwrite,
4721 .t_pread = (ssize_t (*)())mdb_tgt_notsup,
4722 .t_pwrite = (ssize_t (*)())mdb_tgt_notsup,
4723 .t_fread = pt_fread,
4724 .t_fwrite = pt_fwrite,
4725 .t_ioread = (ssize_t (*)())mdb_tgt_notsup,
4726 .t_iowrite = (ssize_t (*)())mdb_tgt_notsup,
4727 .t_vtop = (int (*)())(uintptr_t)mdb_tgt_notsup,
4728 .t_lookup_by_name = pt_lookup_by_name,
4729 .t_lookup_by_addr = pt_lookup_by_addr,
4730 .t_symbol_iter = pt_symbol_iter,
4731 .t_mapping_iter = pt_mapping_iter,
4732 .t_object_iter = pt_object_iter,
4733 .t_addr_to_map = pt_addr_to_map,
4734 .t_name_to_map = pt_name_to_map,
4735 .t_addr_to_ctf = pt_addr_to_ctf,
4736 .t_name_to_ctf = pt_name_to_ctf,
4737 .t_status = pt_status,
4738 .t_run = pt_run,
4739 .t_step = pt_step,
4740 .t_step_out = pt_step_out,
4741 .t_next = pt_next,
4742 .t_cont = pt_continue,
4743 .t_signal = pt_signal,
4744 .t_add_vbrkpt = pt_add_vbrkpt,
4745 .t_add_sbrkpt = pt_add_sbrkpt,
4746 .t_add_pwapt = (int (*)())(uintptr_t)mdb_tgt_null,
4747 .t_add_vwapt = pt_add_vwapt,
4748 .t_add_iowapt = (int (*)())(uintptr_t)mdb_tgt_null,
4749 .t_add_sysenter = pt_add_sysenter,
4750 .t_add_sysexit = pt_add_sysexit,
4751 .t_add_signal = pt_add_signal,
4752 .t_add_fault = pt_add_fault,
4753 .t_getareg = pt_getareg,
4754 .t_putareg = pt_putareg,
4755 .t_stack_iter = pt_stack_iter,
4756 .t_auxv = pt_auxv,
4757 .t_thread_name = pt_thread_name,
4758 };
4759
4760 /*
4761 * Utility function for converting libproc errno values to mdb error values
4762 * for the ptl calls below. Currently, we only need to convert ENOENT to
4763 * EMDB_NOTHREAD to produce a more useful error message for the user.
4764 */
4765 static int
ptl_err(int error)4766 ptl_err(int error)
4767 {
4768 if (error != 0 && errno == ENOENT)
4769 return (set_errno(EMDB_NOTHREAD));
4770
4771 return (error);
4772 }
4773
4774 /*ARGSUSED*/
4775 static mdb_tgt_tid_t
pt_lwp_tid(mdb_tgt_t * t,void * tap)4776 pt_lwp_tid(mdb_tgt_t *t, void *tap)
4777 {
4778 if (t->t_pshandle != NULL)
4779 return (Pstatus(t->t_pshandle)->pr_lwp.pr_lwpid);
4780
4781 return (set_errno(EMDB_NOPROC));
4782 }
4783
4784 static int
pt_lwp_add(mdb_addrvec_t * ap,const lwpstatus_t * psp)4785 pt_lwp_add(mdb_addrvec_t *ap, const lwpstatus_t *psp)
4786 {
4787 mdb_addrvec_unshift(ap, psp->pr_lwpid);
4788 return (0);
4789 }
4790
4791 /*ARGSUSED*/
4792 static int
pt_lwp_iter(mdb_tgt_t * t,void * tap,mdb_addrvec_t * ap)4793 pt_lwp_iter(mdb_tgt_t *t, void *tap, mdb_addrvec_t *ap)
4794 {
4795 if (t->t_pshandle != NULL)
4796 return (Plwp_iter(t->t_pshandle, (proc_lwp_f *)pt_lwp_add, ap));
4797
4798 return (set_errno(EMDB_NOPROC));
4799 }
4800
4801 /*ARGSUSED*/
4802 static int
pt_lwp_getregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prgregset_t gregs)4803 pt_lwp_getregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid, prgregset_t gregs)
4804 {
4805 if (t->t_pshandle != NULL) {
4806 return (ptl_err(Plwp_getregs(t->t_pshandle,
4807 (lwpid_t)tid, gregs)));
4808 }
4809 return (set_errno(EMDB_NOPROC));
4810 }
4811
4812 /*ARGSUSED*/
4813 static int
pt_lwp_setregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prgregset_t gregs)4814 pt_lwp_setregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid, prgregset_t gregs)
4815 {
4816 if (t->t_pshandle != NULL) {
4817 return (ptl_err(Plwp_setregs(t->t_pshandle,
4818 (lwpid_t)tid, gregs)));
4819 }
4820 return (set_errno(EMDB_NOPROC));
4821 }
4822
4823
4824 /*ARGSUSED*/
4825 static int
pt_lwp_getxregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prxregset_t ** xregs,size_t * sizep)4826 pt_lwp_getxregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid, prxregset_t **xregs,
4827 size_t *sizep)
4828 {
4829 if (t->t_pshandle != NULL) {
4830 return (ptl_err(Plwp_getxregs(t->t_pshandle,
4831 (lwpid_t)tid, xregs, sizep)));
4832 }
4833 return (set_errno(EMDB_NOPROC));
4834 }
4835
4836 static void
pt_lwp_freexregs(mdb_tgt_t * t,void * tap,prxregset_t * xregs,size_t size)4837 pt_lwp_freexregs(mdb_tgt_t *t, void *tap, prxregset_t *xregs, size_t size)
4838 {
4839 if (t->t_pshandle != NULL) {
4840 Plwp_freexregs(t->t_pshandle, xregs, size);
4841 }
4842 }
4843
4844 static int
pt_lwp_setxregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,const prxregset_t * xregs,size_t len)4845 pt_lwp_setxregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid,
4846 const prxregset_t *xregs, size_t len)
4847 {
4848 if (t->t_pshandle != NULL) {
4849 return (ptl_err(Plwp_setxregs(t->t_pshandle,
4850 (lwpid_t)tid, xregs, len)));
4851 }
4852 return (set_errno(EMDB_NOPROC));
4853 }
4854
4855 /*ARGSUSED*/
4856 static int
pt_lwp_getfpregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prfpregset_t * fpregs)4857 pt_lwp_getfpregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid,
4858 prfpregset_t *fpregs)
4859 {
4860 if (t->t_pshandle != NULL) {
4861 return (ptl_err(Plwp_getfpregs(t->t_pshandle,
4862 (lwpid_t)tid, fpregs)));
4863 }
4864 return (set_errno(EMDB_NOPROC));
4865 }
4866
4867 /*ARGSUSED*/
4868 static int
pt_lwp_setfpregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,const prfpregset_t * fpregs)4869 pt_lwp_setfpregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid,
4870 const prfpregset_t *fpregs)
4871 {
4872 if (t->t_pshandle != NULL) {
4873 return (ptl_err(Plwp_setfpregs(t->t_pshandle,
4874 (lwpid_t)tid, fpregs)));
4875 }
4876 return (set_errno(EMDB_NOPROC));
4877 }
4878
4879 static const pt_ptl_ops_t proc_lwp_ops = {
4880 .ptl_ctor = (int (*)())(uintptr_t)mdb_tgt_nop,
4881 .ptl_dtor = (void (*)())(uintptr_t)mdb_tgt_nop,
4882 .ptl_tid = pt_lwp_tid,
4883 .ptl_iter = pt_lwp_iter,
4884 .ptl_getregs = pt_lwp_getregs,
4885 .ptl_setregs = pt_lwp_setregs,
4886 .ptl_getxregs = pt_lwp_getxregs,
4887 .ptl_freexregs = pt_lwp_freexregs,
4888 .ptl_setxregs = pt_lwp_setxregs,
4889 .ptl_getfpregs = pt_lwp_getfpregs,
4890 .ptl_setfpregs = pt_lwp_setfpregs
4891 };
4892
4893 static int
pt_tdb_ctor(mdb_tgt_t * t)4894 pt_tdb_ctor(mdb_tgt_t *t)
4895 {
4896 pt_data_t *pt = t->t_data;
4897 td_thragent_t *tap;
4898 td_err_e err;
4899
4900 if ((err = pt->p_tdb_ops->td_ta_new(t->t_pshandle, &tap)) != TD_OK)
4901 return (set_errno(tdb_to_errno(err)));
4902
4903 pt->p_ptl_hdl = tap;
4904 return (0);
4905 }
4906
4907 static void
pt_tdb_dtor(mdb_tgt_t * t,void * tap)4908 pt_tdb_dtor(mdb_tgt_t *t, void *tap)
4909 {
4910 pt_data_t *pt = t->t_data;
4911
4912 ASSERT(tap == pt->p_ptl_hdl);
4913 (void) pt->p_tdb_ops->td_ta_delete(tap);
4914 pt->p_ptl_hdl = NULL;
4915 }
4916
4917 static mdb_tgt_tid_t
pt_tdb_tid(mdb_tgt_t * t,void * tap)4918 pt_tdb_tid(mdb_tgt_t *t, void *tap)
4919 {
4920 pt_data_t *pt = t->t_data;
4921
4922 td_thrhandle_t th;
4923 td_thrinfo_t ti;
4924 td_err_e err;
4925
4926 if (t->t_pshandle == NULL)
4927 return (set_errno(EMDB_NOPROC));
4928
4929 if ((err = pt->p_tdb_ops->td_ta_map_lwp2thr(tap,
4930 Pstatus(t->t_pshandle)->pr_lwp.pr_lwpid, &th)) != TD_OK)
4931 return (set_errno(tdb_to_errno(err)));
4932
4933 if ((err = pt->p_tdb_ops->td_thr_get_info(&th, &ti)) != TD_OK)
4934 return (set_errno(tdb_to_errno(err)));
4935
4936 return (ti.ti_tid);
4937 }
4938
4939 static int
pt_tdb_add(const td_thrhandle_t * thp,pt_addarg_t * pap)4940 pt_tdb_add(const td_thrhandle_t *thp, pt_addarg_t *pap)
4941 {
4942 td_thrinfo_t ti;
4943
4944 if (pap->pa_pt->p_tdb_ops->td_thr_get_info(thp, &ti) == TD_OK &&
4945 ti.ti_state != TD_THR_ZOMBIE)
4946 mdb_addrvec_unshift(pap->pa_ap, ti.ti_tid);
4947
4948 return (0);
4949 }
4950
4951 static int
pt_tdb_iter(mdb_tgt_t * t,void * tap,mdb_addrvec_t * ap)4952 pt_tdb_iter(mdb_tgt_t *t, void *tap, mdb_addrvec_t *ap)
4953 {
4954 pt_data_t *pt = t->t_data;
4955 pt_addarg_t arg;
4956 int err;
4957
4958 if (t->t_pshandle == NULL)
4959 return (set_errno(EMDB_NOPROC));
4960
4961 arg.pa_pt = pt;
4962 arg.pa_ap = ap;
4963
4964 if ((err = pt->p_tdb_ops->td_ta_thr_iter(tap, (td_thr_iter_f *)
4965 pt_tdb_add, &arg, TD_THR_ANY_STATE, TD_THR_LOWEST_PRIORITY,
4966 TD_SIGNO_MASK, TD_THR_ANY_USER_FLAGS)) != TD_OK)
4967 return (set_errno(tdb_to_errno(err)));
4968
4969 return (0);
4970 }
4971
4972 static int
pt_tdb_getregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prgregset_t gregs)4973 pt_tdb_getregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid, prgregset_t gregs)
4974 {
4975 pt_data_t *pt = t->t_data;
4976
4977 td_thrhandle_t th;
4978 td_err_e err;
4979
4980 if (t->t_pshandle == NULL)
4981 return (set_errno(EMDB_NOPROC));
4982
4983 if ((err = pt->p_tdb_ops->td_ta_map_id2thr(tap, tid, &th)) != TD_OK)
4984 return (set_errno(tdb_to_errno(err)));
4985
4986 err = pt->p_tdb_ops->td_thr_getgregs(&th, gregs);
4987 if (err != TD_OK && err != TD_PARTIALREG)
4988 return (set_errno(tdb_to_errno(err)));
4989
4990 return (0);
4991 }
4992
4993 static int
pt_tdb_setregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prgregset_t gregs)4994 pt_tdb_setregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid, prgregset_t gregs)
4995 {
4996 pt_data_t *pt = t->t_data;
4997
4998 td_thrhandle_t th;
4999 td_err_e err;
5000
5001 if (t->t_pshandle == NULL)
5002 return (set_errno(EMDB_NOPROC));
5003
5004 if ((err = pt->p_tdb_ops->td_ta_map_id2thr(tap, tid, &th)) != TD_OK)
5005 return (set_errno(tdb_to_errno(err)));
5006
5007 err = pt->p_tdb_ops->td_thr_setgregs(&th, gregs);
5008 if (err != TD_OK && err != TD_PARTIALREG)
5009 return (set_errno(tdb_to_errno(err)));
5010
5011 return (0);
5012 }
5013
5014 static int
pt_tdb_getxregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prxregset_t ** xregs,size_t * sizep)5015 pt_tdb_getxregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid, prxregset_t **xregs,
5016 size_t *sizep)
5017 {
5018 pt_data_t *pt = t->t_data;
5019
5020 td_thrhandle_t th;
5021 td_err_e err;
5022 int xregsize;
5023 prxregset_t *pxr;
5024
5025 if (t->t_pshandle == NULL)
5026 return (set_errno(EMDB_NOPROC));
5027
5028 if ((err = pt->p_tdb_ops->td_ta_map_id2thr(tap, tid, &th)) != TD_OK)
5029 return (set_errno(tdb_to_errno(err)));
5030
5031 if ((err = pt->p_tdb_ops->td_thr_getxregsize(&th, &xregsize)) != TD_OK)
5032 return (set_errno(tdb_to_errno(err)));
5033
5034 if (xregsize == 0) {
5035 return (set_errno(ENODATA));
5036 }
5037
5038 pxr = mdb_alloc(xregsize, UM_SLEEP);
5039
5040 err = pt->p_tdb_ops->td_thr_getxregs(&th, pxr);
5041 if (err != TD_OK && err != TD_PARTIALREG) {
5042 mdb_free(pxr, xregsize);
5043 return (set_errno(tdb_to_errno(err)));
5044 }
5045
5046 *xregs = pxr;
5047 *sizep = xregsize;
5048 return (0);
5049 }
5050
5051 static void
pt_tdb_freexregs(mdb_tgt_t * t __unused,void * tap __unused,prxregset_t * pxr,size_t size)5052 pt_tdb_freexregs(mdb_tgt_t *t __unused, void *tap __unused, prxregset_t *pxr,
5053 size_t size)
5054 {
5055 mdb_free(pxr, size);
5056 }
5057
5058 static int
pt_tdb_setxregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,const prxregset_t * xregs,size_t len __unused)5059 pt_tdb_setxregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid,
5060 const prxregset_t *xregs, size_t len __unused)
5061 {
5062 pt_data_t *pt = t->t_data;
5063
5064 td_thrhandle_t th;
5065 td_err_e err;
5066
5067 if (t->t_pshandle == NULL)
5068 return (set_errno(EMDB_NOPROC));
5069
5070 if ((err = pt->p_tdb_ops->td_ta_map_id2thr(tap, tid, &th)) != TD_OK)
5071 return (set_errno(tdb_to_errno(err)));
5072
5073 err = pt->p_tdb_ops->td_thr_setxregs(&th, xregs);
5074 if (err != TD_OK && err != TD_PARTIALREG)
5075 return (set_errno(tdb_to_errno(err)));
5076
5077 return (0);
5078 }
5079
5080 static int
pt_tdb_getfpregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,prfpregset_t * fpregs)5081 pt_tdb_getfpregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid,
5082 prfpregset_t *fpregs)
5083 {
5084 pt_data_t *pt = t->t_data;
5085
5086 td_thrhandle_t th;
5087 td_err_e err;
5088
5089 if (t->t_pshandle == NULL)
5090 return (set_errno(EMDB_NOPROC));
5091
5092 if ((err = pt->p_tdb_ops->td_ta_map_id2thr(tap, tid, &th)) != TD_OK)
5093 return (set_errno(tdb_to_errno(err)));
5094
5095 err = pt->p_tdb_ops->td_thr_getfpregs(&th, fpregs);
5096 if (err != TD_OK && err != TD_PARTIALREG)
5097 return (set_errno(tdb_to_errno(err)));
5098
5099 return (0);
5100 }
5101
5102 static int
pt_tdb_setfpregs(mdb_tgt_t * t,void * tap,mdb_tgt_tid_t tid,const prfpregset_t * fpregs)5103 pt_tdb_setfpregs(mdb_tgt_t *t, void *tap, mdb_tgt_tid_t tid,
5104 const prfpregset_t *fpregs)
5105 {
5106 pt_data_t *pt = t->t_data;
5107
5108 td_thrhandle_t th;
5109 td_err_e err;
5110
5111 if (t->t_pshandle == NULL)
5112 return (set_errno(EMDB_NOPROC));
5113
5114 if ((err = pt->p_tdb_ops->td_ta_map_id2thr(tap, tid, &th)) != TD_OK)
5115 return (set_errno(tdb_to_errno(err)));
5116
5117 err = pt->p_tdb_ops->td_thr_setfpregs(&th, fpregs);
5118 if (err != TD_OK && err != TD_PARTIALREG)
5119 return (set_errno(tdb_to_errno(err)));
5120
5121 return (0);
5122 }
5123
5124 static const pt_ptl_ops_t proc_tdb_ops = {
5125 .ptl_ctor = pt_tdb_ctor,
5126 .ptl_dtor = pt_tdb_dtor,
5127 .ptl_tid = pt_tdb_tid,
5128 .ptl_iter = pt_tdb_iter,
5129 .ptl_getregs = pt_tdb_getregs,
5130 .ptl_setregs = pt_tdb_setregs,
5131 .ptl_getxregs = pt_tdb_getxregs,
5132 .ptl_freexregs = pt_tdb_freexregs,
5133 .ptl_setxregs = pt_tdb_setxregs,
5134 .ptl_getfpregs = pt_tdb_getfpregs,
5135 .ptl_setfpregs = pt_tdb_setfpregs
5136 };
5137
5138 static ssize_t
pt_xd_auxv(mdb_tgt_t * t,void * buf,size_t nbytes)5139 pt_xd_auxv(mdb_tgt_t *t, void *buf, size_t nbytes)
5140 {
5141 struct ps_prochandle *P = t->t_pshandle;
5142 const auxv_t *auxp, *auxv = NULL;
5143 int auxn = 0;
5144
5145 if (P != NULL && (auxv = Pgetauxvec(P)) != NULL &&
5146 auxv->a_type != AT_NULL) {
5147 for (auxp = auxv, auxn = 1; auxp->a_type != 0; auxp++)
5148 auxn++;
5149 }
5150
5151 if (buf == NULL && nbytes == 0)
5152 return (sizeof (auxv_t) * auxn);
5153
5154 if (auxn == 0)
5155 return (set_errno(ENODATA));
5156
5157 nbytes = MIN(nbytes, sizeof (auxv_t) * auxn);
5158 bcopy(auxv, buf, nbytes);
5159 return (nbytes);
5160 }
5161
5162 static ssize_t
pt_xd_cred(mdb_tgt_t * t,void * buf,size_t nbytes)5163 pt_xd_cred(mdb_tgt_t *t, void *buf, size_t nbytes)
5164 {
5165 prcred_t cr, *crp;
5166 size_t cbytes = 0;
5167
5168 if (t->t_pshandle != NULL && Pcred(t->t_pshandle, &cr, 1) == 0) {
5169 cbytes = (cr.pr_ngroups <= 1) ? sizeof (prcred_t) :
5170 (sizeof (prcred_t) + (cr.pr_ngroups - 1) * sizeof (gid_t));
5171 }
5172
5173 if (buf == NULL && nbytes == 0)
5174 return (cbytes);
5175
5176 if (cbytes == 0)
5177 return (set_errno(ENODATA));
5178
5179 crp = mdb_alloc(cbytes, UM_SLEEP);
5180
5181 if (Pcred(t->t_pshandle, crp, cr.pr_ngroups) == -1)
5182 return (set_errno(ENODATA));
5183
5184 nbytes = MIN(nbytes, cbytes);
5185 bcopy(crp, buf, nbytes);
5186 mdb_free(crp, cbytes);
5187 return (nbytes);
5188 }
5189
5190 static ssize_t
pt_xd_ehdr(mdb_tgt_t * t,void * buf,size_t nbytes)5191 pt_xd_ehdr(mdb_tgt_t *t, void *buf, size_t nbytes)
5192 {
5193 pt_data_t *pt = t->t_data;
5194
5195 if (buf == NULL && nbytes == 0)
5196 return (sizeof (GElf_Ehdr));
5197
5198 if (pt->p_file == NULL)
5199 return (set_errno(ENODATA));
5200
5201 nbytes = MIN(nbytes, sizeof (GElf_Ehdr));
5202 bcopy(&pt->p_file->gf_ehdr, buf, nbytes);
5203 return (nbytes);
5204 }
5205
5206 static int
pt_copy_lwp(lwpstatus_t ** lspp,const lwpstatus_t * lsp)5207 pt_copy_lwp(lwpstatus_t **lspp, const lwpstatus_t *lsp)
5208 {
5209 bcopy(lsp, *lspp, sizeof (lwpstatus_t));
5210 (*lspp)++;
5211 return (0);
5212 }
5213
5214 static ssize_t
pt_xd_lwpstatus(mdb_tgt_t * t,void * buf,size_t nbytes)5215 pt_xd_lwpstatus(mdb_tgt_t *t, void *buf, size_t nbytes)
5216 {
5217 lwpstatus_t *lsp, *lbuf;
5218 const pstatus_t *psp;
5219 int nlwp = 0;
5220
5221 if (t->t_pshandle != NULL && (psp = Pstatus(t->t_pshandle)) != NULL)
5222 nlwp = psp->pr_nlwp;
5223
5224 if (buf == NULL && nbytes == 0)
5225 return (sizeof (lwpstatus_t) * nlwp);
5226
5227 if (nlwp == 0)
5228 return (set_errno(ENODATA));
5229
5230 lsp = lbuf = mdb_alloc(sizeof (lwpstatus_t) * nlwp, UM_SLEEP);
5231 nbytes = MIN(nbytes, sizeof (lwpstatus_t) * nlwp);
5232
5233 (void) Plwp_iter(t->t_pshandle, (proc_lwp_f *)pt_copy_lwp, &lsp);
5234 bcopy(lbuf, buf, nbytes);
5235
5236 mdb_free(lbuf, sizeof (lwpstatus_t) * nlwp);
5237 return (nbytes);
5238 }
5239
5240 static ssize_t
pt_xd_pshandle(mdb_tgt_t * t,void * buf,size_t nbytes)5241 pt_xd_pshandle(mdb_tgt_t *t, void *buf, size_t nbytes)
5242 {
5243 if (buf == NULL && nbytes == 0)
5244 return (sizeof (struct ps_prochandle *));
5245
5246 if (t->t_pshandle == NULL || nbytes != sizeof (struct ps_prochandle *))
5247 return (set_errno(ENODATA));
5248
5249 bcopy(&t->t_pshandle, buf, nbytes);
5250 return (nbytes);
5251 }
5252
5253 static ssize_t
pt_xd_psinfo(mdb_tgt_t * t,void * buf,size_t nbytes)5254 pt_xd_psinfo(mdb_tgt_t *t, void *buf, size_t nbytes)
5255 {
5256 const psinfo_t *psp;
5257
5258 if (buf == NULL && nbytes == 0)
5259 return (sizeof (psinfo_t));
5260
5261 if (t->t_pshandle == NULL || (psp = Ppsinfo(t->t_pshandle)) == NULL)
5262 return (set_errno(ENODATA));
5263
5264 nbytes = MIN(nbytes, sizeof (psinfo_t));
5265 bcopy(psp, buf, nbytes);
5266 return (nbytes);
5267 }
5268
5269 static ssize_t
pt_xd_pstatus(mdb_tgt_t * t,void * buf,size_t nbytes)5270 pt_xd_pstatus(mdb_tgt_t *t, void *buf, size_t nbytes)
5271 {
5272 const pstatus_t *psp;
5273
5274 if (buf == NULL && nbytes == 0)
5275 return (sizeof (pstatus_t));
5276
5277 if (t->t_pshandle == NULL || (psp = Pstatus(t->t_pshandle)) == NULL)
5278 return (set_errno(ENODATA));
5279
5280 nbytes = MIN(nbytes, sizeof (pstatus_t));
5281 bcopy(psp, buf, nbytes);
5282 return (nbytes);
5283 }
5284
5285 static ssize_t
pt_xd_utsname(mdb_tgt_t * t,void * buf,size_t nbytes)5286 pt_xd_utsname(mdb_tgt_t *t, void *buf, size_t nbytes)
5287 {
5288 struct utsname uts;
5289
5290 if (buf == NULL && nbytes == 0)
5291 return (sizeof (struct utsname));
5292
5293 if (t->t_pshandle == NULL || Puname(t->t_pshandle, &uts) != 0)
5294 return (set_errno(ENODATA));
5295
5296 nbytes = MIN(nbytes, sizeof (struct utsname));
5297 bcopy(&uts, buf, nbytes);
5298 return (nbytes);
5299 }
5300
5301 int
mdb_proc_tgt_create(mdb_tgt_t * t,int argc,const char * argv[])5302 mdb_proc_tgt_create(mdb_tgt_t *t, int argc, const char *argv[])
5303 {
5304 pt_data_t *pt = mdb_zalloc(sizeof (pt_data_t), UM_SLEEP);
5305
5306 const char *aout_path = argc > 0 ? argv[0] : PT_EXEC_PATH;
5307 const char *core_path = argc > 1 ? argv[1] : NULL;
5308
5309 const mdb_tgt_regdesc_t *rdp;
5310 char execname[MAXPATHLEN];
5311 struct stat64 st;
5312 int perr;
5313 int state = 0;
5314 struct rlimit rlim;
5315 int i;
5316
5317 if (argc > 2) {
5318 mdb_free(pt, sizeof (pt_data_t));
5319 return (set_errno(EINVAL));
5320 }
5321
5322 if (t->t_flags & MDB_TGT_F_RDWR)
5323 pt->p_oflags = O_RDWR;
5324 else
5325 pt->p_oflags = O_RDONLY;
5326
5327 if (t->t_flags & MDB_TGT_F_FORCE)
5328 pt->p_gflags |= PGRAB_FORCE;
5329 if (t->t_flags & MDB_TGT_F_NOSTOP)
5330 pt->p_gflags |= PGRAB_NOSTOP;
5331
5332 pt->p_ptl_ops = &proc_lwp_ops;
5333 pt->p_maxsig = sysconf(_SC_SIGRT_MAX);
5334
5335 (void) mdb_nv_create(&pt->p_regs, UM_SLEEP);
5336 (void) mdb_nv_create(&pt->p_env, UM_SLEEP);
5337
5338 t->t_ops = &proc_ops;
5339 t->t_data = pt;
5340
5341 /*
5342 * If no core file name was specified, but the file ./core is present,
5343 * infer that we want to debug it. I find this behavior confusing,
5344 * so we only do this when precise adb(1) compatibility is required.
5345 */
5346 if (core_path == NULL && (mdb.m_flags & MDB_FL_ADB) &&
5347 access(PT_CORE_PATH, F_OK) == 0)
5348 core_path = PT_CORE_PATH;
5349
5350 /*
5351 * For compatibility with adb(1), the special name "-" may be used
5352 * to suppress the loading of the executable or core file.
5353 */
5354 if (aout_path != NULL && strcmp(aout_path, "-") == 0)
5355 aout_path = NULL;
5356 if (core_path != NULL && strcmp(core_path, "-") == 0)
5357 core_path = NULL;
5358
5359 /*
5360 * If a core file or pid was specified, attempt to grab it now using
5361 * proc_arg_grab(); otherwise we'll create a fresh process later.
5362 */
5363 if (core_path != NULL && (t->t_pshandle = proc_arg_xgrab(core_path,
5364 aout_path == PT_EXEC_PATH ? NULL : aout_path, PR_ARG_ANY,
5365 pt->p_gflags, &perr, NULL)) == NULL) {
5366 mdb_warn("cannot debug %s: %s\n", core_path, Pgrab_error(perr));
5367 goto err;
5368 }
5369
5370 if (aout_path != NULL &&
5371 (pt->p_idlehandle = Pgrab_file(aout_path, &perr)) != NULL &&
5372 t->t_pshandle == NULL)
5373 t->t_pshandle = pt->p_idlehandle;
5374
5375 if (t->t_pshandle != NULL)
5376 state = Pstate(t->t_pshandle);
5377
5378 /*
5379 * Make sure we'll have enough file descriptors to handle a target
5380 * has many many mappings.
5381 */
5382 if (getrlimit(RLIMIT_NOFILE, &rlim) == 0) {
5383 rlim.rlim_cur = rlim.rlim_max;
5384 (void) setrlimit(RLIMIT_NOFILE, &rlim);
5385 (void) enable_extended_FILE_stdio(-1, -1);
5386 }
5387
5388 /*
5389 * If we don't have an executable path or the executable path is the
5390 * /proc/<pid>/object/a.out path, but we now have a libproc handle (and
5391 * it didn't come from a core file), attempt to derive the executable
5392 * path using Pexecname(). We need to do this in the /proc case in
5393 * order to open the executable for writing because /proc/object/<file>
5394 * permission are masked with 0555. If Pexecname() fails us, fall back
5395 * to /proc/<pid>/object/a.out.
5396 */
5397 if (t->t_pshandle != NULL && core_path == NULL &&
5398 (aout_path == NULL || (stat64(aout_path, &st) == 0 &&
5399 strcmp(st.st_fstype, "proc") == 0))) {
5400 GElf_Sym s;
5401 aout_path = Pexecname(t->t_pshandle, execname, MAXPATHLEN);
5402 if (aout_path == NULL && state != PS_DEAD && state != PS_IDLE) {
5403 (void) mdb_iob_snprintf(execname, sizeof (execname),
5404 "/proc/%d/object/a.out",
5405 (int)Pstatus(t->t_pshandle)->pr_pid);
5406 aout_path = execname;
5407 }
5408 if (aout_path == NULL &&
5409 Plookup_by_name(t->t_pshandle, "a.out", "_start", &s) != 0)
5410 mdb_warn("warning: failed to infer pathname to "
5411 "executable; symbol table will not be available\n");
5412
5413 mdb_dprintf(MDB_DBG_TGT, "a.out is %s\n", aout_path);
5414 }
5415
5416 /*
5417 * Attempt to open the executable file. We only want this operation
5418 * to actually cause the constructor to abort if the executable file
5419 * name was given explicitly. If we defaulted to PT_EXEC_PATH or
5420 * derived the executable using Pexecname, then we want to continue
5421 * along with p_fio and p_file set to NULL.
5422 */
5423 if (aout_path != NULL && (pt->p_aout_fio = mdb_fdio_create_path(NULL,
5424 aout_path, pt->p_oflags, 0)) == NULL && argc > 0) {
5425 mdb_warn("failed to open %s", aout_path);
5426 goto err;
5427 }
5428
5429 /*
5430 * Now create an ELF file from the input file, if we have one. Again,
5431 * only abort the constructor if the name was given explicitly.
5432 */
5433 if (pt->p_aout_fio != NULL && pt_open_aout(t,
5434 mdb_io_hold(pt->p_aout_fio)) == NULL && argc > 0)
5435 goto err;
5436
5437 /*
5438 * If we've successfully opened an ELF file, select the appropriate
5439 * disassembler based on the ELF header.
5440 */
5441 if (pt->p_file != NULL)
5442 (void) mdb_dis_select(pt_disasm(&pt->p_file->gf_ehdr));
5443 else
5444 (void) mdb_dis_select(pt_disasm(NULL));
5445
5446 /*
5447 * Add each register described in the target ISA register description
5448 * list to our hash table of register descriptions and then add any
5449 * appropriate ISA-specific floating-point register descriptions.
5450 */
5451 for (rdp = pt_regdesc; rdp->rd_name != NULL; rdp++) {
5452 (void) mdb_nv_insert(&pt->p_regs, rdp->rd_name, NULL,
5453 MDB_TGT_R_NVAL(rdp->rd_num, rdp->rd_flags), MDB_NV_RDONLY);
5454 }
5455 pt_addfpregs(t);
5456
5457 /*
5458 * Certain important /proc structures may be of interest to mdb
5459 * modules and their dcmds. Export these using the xdata interface:
5460 */
5461 (void) mdb_tgt_xdata_insert(t, "auxv",
5462 "procfs auxv_t array", pt_xd_auxv);
5463 (void) mdb_tgt_xdata_insert(t, "cred",
5464 "procfs prcred_t structure", pt_xd_cred);
5465 (void) mdb_tgt_xdata_insert(t, "ehdr",
5466 "executable file GElf_Ehdr structure", pt_xd_ehdr);
5467 (void) mdb_tgt_xdata_insert(t, "lwpstatus",
5468 "procfs lwpstatus_t array", pt_xd_lwpstatus);
5469 (void) mdb_tgt_xdata_insert(t, "pshandle",
5470 "libproc proc service API handle", pt_xd_pshandle);
5471 (void) mdb_tgt_xdata_insert(t, "psinfo",
5472 "procfs psinfo_t structure", pt_xd_psinfo);
5473 (void) mdb_tgt_xdata_insert(t, "pstatus",
5474 "procfs pstatus_t structure", pt_xd_pstatus);
5475 (void) mdb_tgt_xdata_insert(t, "utsname",
5476 "utsname structure", pt_xd_utsname);
5477
5478 /*
5479 * Force a status update now so that we fill in t_status with the
5480 * latest information based on any successful grab.
5481 */
5482 (void) mdb_tgt_status(t, &t->t_status);
5483
5484 /*
5485 * If we're not examining a core file, trace SIGINT and all signals
5486 * that cause the process to dump core as part of our initialization.
5487 */
5488 if ((t->t_pshandle != NULL && state != PS_DEAD && state != PS_IDLE) ||
5489 (pt->p_file != NULL && pt->p_file->gf_ehdr.e_type == ET_EXEC)) {
5490
5491 int tflag = MDB_TGT_SPEC_STICKY; /* default sigs are sticky */
5492
5493 (void) mdb_tgt_add_signal(t, SIGINT, tflag, no_se_f, NULL);
5494 (void) mdb_tgt_add_signal(t, SIGQUIT, tflag, no_se_f, NULL);
5495 (void) mdb_tgt_add_signal(t, SIGILL, tflag, no_se_f, NULL);
5496 (void) mdb_tgt_add_signal(t, SIGTRAP, tflag, no_se_f, NULL);
5497 (void) mdb_tgt_add_signal(t, SIGABRT, tflag, no_se_f, NULL);
5498 (void) mdb_tgt_add_signal(t, SIGEMT, tflag, no_se_f, NULL);
5499 (void) mdb_tgt_add_signal(t, SIGFPE, tflag, no_se_f, NULL);
5500 (void) mdb_tgt_add_signal(t, SIGBUS, tflag, no_se_f, NULL);
5501 (void) mdb_tgt_add_signal(t, SIGSEGV, tflag, no_se_f, NULL);
5502 (void) mdb_tgt_add_signal(t, SIGSYS, tflag, no_se_f, NULL);
5503 (void) mdb_tgt_add_signal(t, SIGXCPU, tflag, no_se_f, NULL);
5504 (void) mdb_tgt_add_signal(t, SIGXFSZ, tflag, no_se_f, NULL);
5505 }
5506
5507 /*
5508 * If we've grabbed a live process, establish our initial breakpoints
5509 * and librtld_db agent so we can track rtld activity. If FL_VCREATE
5510 * is set, this process was created by a previous instantiation of
5511 * the debugger, so reset pr_flags to kill it; otherwise we attached
5512 * to an already running process. Pgrab() has already set the PR_RLC
5513 * flag appropriately based on whether the process was stopped when we
5514 * attached.
5515 */
5516 if (t->t_pshandle != NULL && state != PS_DEAD && state != PS_IDLE) {
5517 if (mdb.m_flags & MDB_FL_VCREATE) {
5518 (void) Punsetflags(t->t_pshandle, PR_RLC);
5519 (void) Psetflags(t->t_pshandle, PR_KLC);
5520 pt->p_rflags = PRELEASE_KILL;
5521 } else {
5522 (void) Punsetflags(t->t_pshandle, PR_KLC);
5523 }
5524 pt_post_attach(t);
5525 }
5526
5527 /*
5528 * Initialize a local copy of the environment, which can be modified
5529 * before running the program.
5530 */
5531 for (i = 0; mdb.m_env[i] != NULL; i++)
5532 pt_env_set(pt, mdb.m_env[i]);
5533
5534 /*
5535 * If adb(1) compatibility mode is on, then print the appropriate
5536 * greeting message if we have grabbed a core file.
5537 */
5538 if ((mdb.m_flags & MDB_FL_ADB) && t->t_pshandle != NULL &&
5539 state == PS_DEAD) {
5540 const pstatus_t *psp = Pstatus(t->t_pshandle);
5541 int cursig = psp->pr_lwp.pr_cursig;
5542 char signame[SIG2STR_MAX];
5543
5544 mdb_printf("core file = %s -- program ``%s'' on platform %s\n",
5545 core_path, aout_path ? aout_path : "?", pt_platform(t));
5546
5547 if (cursig != 0 && sig2str(cursig, signame) == 0)
5548 mdb_printf("SIG%s: %s\n", signame, strsignal(cursig));
5549 }
5550
5551 return (0);
5552
5553 err:
5554 pt_destroy(t);
5555 return (-1);
5556 }
5557