158f0484fSRodney W. Grimes /*- 258f0484fSRodney W. Grimes * Copyright (c) 1989, 1992, 1993 358f0484fSRodney W. Grimes * The Regents of the University of California. All rights reserved. 458f0484fSRodney W. Grimes * 558f0484fSRodney W. Grimes * This code is derived from software developed by the Computer Systems 658f0484fSRodney W. Grimes * Engineering group at Lawrence Berkeley Laboratory under DARPA contract 758f0484fSRodney W. Grimes * BG 91-66 and contributed to Berkeley. 858f0484fSRodney W. Grimes * 958f0484fSRodney W. Grimes * Redistribution and use in source and binary forms, with or without 1058f0484fSRodney W. Grimes * modification, are permitted provided that the following conditions 1158f0484fSRodney W. Grimes * are met: 1258f0484fSRodney W. Grimes * 1. Redistributions of source code must retain the above copyright 1358f0484fSRodney W. Grimes * notice, this list of conditions and the following disclaimer. 1458f0484fSRodney W. Grimes * 2. Redistributions in binary form must reproduce the above copyright 1558f0484fSRodney W. Grimes * notice, this list of conditions and the following disclaimer in the 1658f0484fSRodney W. Grimes * documentation and/or other materials provided with the distribution. 1758f0484fSRodney W. Grimes * 3. All advertising materials mentioning features or use of this software 1858f0484fSRodney W. Grimes * must display the following acknowledgement: 1958f0484fSRodney W. Grimes * This product includes software developed by the University of 2058f0484fSRodney W. Grimes * California, Berkeley and its contributors. 2158f0484fSRodney W. Grimes * 4. Neither the name of the University nor the names of its contributors 2258f0484fSRodney W. Grimes * may be used to endorse or promote products derived from this software 2358f0484fSRodney W. Grimes * without specific prior written permission. 2458f0484fSRodney W. Grimes * 2558f0484fSRodney W. Grimes * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 2658f0484fSRodney W. Grimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 2758f0484fSRodney W. Grimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 2858f0484fSRodney W. Grimes * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 2958f0484fSRodney W. Grimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 3058f0484fSRodney W. Grimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 3158f0484fSRodney W. Grimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 3258f0484fSRodney W. Grimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 3358f0484fSRodney W. Grimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 3458f0484fSRodney W. Grimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 3558f0484fSRodney W. Grimes * SUCH DAMAGE. 3658f0484fSRodney W. Grimes */ 3758f0484fSRodney W. Grimes 3858f0484fSRodney W. Grimes #if defined(LIBC_SCCS) && !defined(lint) 3958f0484fSRodney W. Grimes static char sccsid[] = "@(#)kvm_proc.c 8.3 (Berkeley) 9/23/93"; 4058f0484fSRodney W. Grimes #endif /* LIBC_SCCS and not lint */ 4158f0484fSRodney W. Grimes 4258f0484fSRodney W. Grimes /* 4358f0484fSRodney W. Grimes * Proc traversal interface for kvm. ps and w are (probably) the exclusive 4458f0484fSRodney W. Grimes * users of this code, so we've factored it out into a separate module. 4558f0484fSRodney W. Grimes * Thus, we keep this grunge out of the other kvm applications (i.e., 4658f0484fSRodney W. Grimes * most other applications are interested only in open/close/read/nlist). 4758f0484fSRodney W. Grimes */ 4858f0484fSRodney W. Grimes 4958f0484fSRodney W. Grimes #include <sys/param.h> 5058f0484fSRodney W. Grimes #include <sys/user.h> 5158f0484fSRodney W. Grimes #include <sys/proc.h> 5258f0484fSRodney W. Grimes #include <sys/exec.h> 5358f0484fSRodney W. Grimes #include <sys/stat.h> 5458f0484fSRodney W. Grimes #include <sys/ioctl.h> 5558f0484fSRodney W. Grimes #include <sys/tty.h> 56338c7541SDavid Greenman #include <sys/file.h> 5751295a4dSJordan K. Hubbard #include <stdio.h> 5851295a4dSJordan K. Hubbard #include <stdlib.h> 5958f0484fSRodney W. Grimes #include <unistd.h> 6058f0484fSRodney W. Grimes #include <nlist.h> 6158f0484fSRodney W. Grimes #include <kvm.h> 6258f0484fSRodney W. Grimes 6358f0484fSRodney W. Grimes #include <vm/vm.h> 6458f0484fSRodney W. Grimes #include <vm/vm_param.h> 6558f0484fSRodney W. Grimes #include <vm/swap_pager.h> 6658f0484fSRodney W. Grimes 6758f0484fSRodney W. Grimes #include <sys/sysctl.h> 6858f0484fSRodney W. Grimes 6958f0484fSRodney W. Grimes #include <limits.h> 7077721f53SPeter Wemm #include <memory.h> 7158f0484fSRodney W. Grimes #include <db.h> 7258f0484fSRodney W. Grimes #include <paths.h> 7358f0484fSRodney W. Grimes 7458f0484fSRodney W. Grimes #include "kvm_private.h" 7558f0484fSRodney W. Grimes 7651295a4dSJordan K. Hubbard #if used 7758f0484fSRodney W. Grimes static char * 7858f0484fSRodney W. Grimes kvm_readswap(kd, p, va, cnt) 7958f0484fSRodney W. Grimes kvm_t *kd; 8058f0484fSRodney W. Grimes const struct proc *p; 8158f0484fSRodney W. Grimes u_long va; 8258f0484fSRodney W. Grimes u_long *cnt; 8358f0484fSRodney W. Grimes { 8421d54b07SRodney W. Grimes #ifdef __FreeBSD__ 8521d54b07SRodney W. Grimes /* XXX Stubbed out, our vm system is differnet */ 8621d54b07SRodney W. Grimes _kvm_err(kd, kd->program, "kvm_readswap not implemented"); 8721d54b07SRodney W. Grimes return(0); 8821d54b07SRodney W. Grimes #endif /* __FreeBSD__ */ 8958f0484fSRodney W. Grimes } 9051295a4dSJordan K. Hubbard #endif 9158f0484fSRodney W. Grimes 9258f0484fSRodney W. Grimes #define KREAD(kd, addr, obj) \ 9358f0484fSRodney W. Grimes (kvm_read(kd, addr, (char *)(obj), sizeof(*obj)) != sizeof(*obj)) 9458f0484fSRodney W. Grimes 9558f0484fSRodney W. Grimes /* 9658f0484fSRodney W. Grimes * Read proc's from memory file into buffer bp, which has space to hold 9758f0484fSRodney W. Grimes * at most maxcnt procs. 9858f0484fSRodney W. Grimes */ 9958f0484fSRodney W. Grimes static int 10058f0484fSRodney W. Grimes kvm_proclist(kd, what, arg, p, bp, maxcnt) 10158f0484fSRodney W. Grimes kvm_t *kd; 10258f0484fSRodney W. Grimes int what, arg; 10358f0484fSRodney W. Grimes struct proc *p; 10458f0484fSRodney W. Grimes struct kinfo_proc *bp; 10558f0484fSRodney W. Grimes int maxcnt; 10658f0484fSRodney W. Grimes { 10758f0484fSRodney W. Grimes register int cnt = 0; 10858f0484fSRodney W. Grimes struct eproc eproc; 10958f0484fSRodney W. Grimes struct pgrp pgrp; 11058f0484fSRodney W. Grimes struct session sess; 11158f0484fSRodney W. Grimes struct tty tty; 11258f0484fSRodney W. Grimes struct proc proc; 113a58930d8STor Egge struct proc pproc; 11458f0484fSRodney W. Grimes 11537e4fbc4SJeffrey Hsu for (; cnt < maxcnt && p != NULL; p = proc.p_list.le_next) { 11658f0484fSRodney W. Grimes if (KREAD(kd, (u_long)p, &proc)) { 11758f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "can't read proc at %x", p); 11858f0484fSRodney W. Grimes return (-1); 11958f0484fSRodney W. Grimes } 12058f0484fSRodney W. Grimes if (KREAD(kd, (u_long)proc.p_cred, &eproc.e_pcred) == 0) 12151295a4dSJordan K. Hubbard (void)(KREAD(kd, (u_long)eproc.e_pcred.pc_ucred, 12251295a4dSJordan K. Hubbard &eproc.e_ucred)); 12358f0484fSRodney W. Grimes 12458f0484fSRodney W. Grimes switch(what) { 12558f0484fSRodney W. Grimes 12658f0484fSRodney W. Grimes case KERN_PROC_PID: 12758f0484fSRodney W. Grimes if (proc.p_pid != (pid_t)arg) 12858f0484fSRodney W. Grimes continue; 12958f0484fSRodney W. Grimes break; 13058f0484fSRodney W. Grimes 13158f0484fSRodney W. Grimes case KERN_PROC_UID: 13258f0484fSRodney W. Grimes if (eproc.e_ucred.cr_uid != (uid_t)arg) 13358f0484fSRodney W. Grimes continue; 13458f0484fSRodney W. Grimes break; 13558f0484fSRodney W. Grimes 13658f0484fSRodney W. Grimes case KERN_PROC_RUID: 13758f0484fSRodney W. Grimes if (eproc.e_pcred.p_ruid != (uid_t)arg) 13858f0484fSRodney W. Grimes continue; 13958f0484fSRodney W. Grimes break; 14058f0484fSRodney W. Grimes } 14158f0484fSRodney W. Grimes /* 14258f0484fSRodney W. Grimes * We're going to add another proc to the set. If this 14358f0484fSRodney W. Grimes * will overflow the buffer, assume the reason is because 14458f0484fSRodney W. Grimes * nprocs (or the proc list) is corrupt and declare an error. 14558f0484fSRodney W. Grimes */ 14658f0484fSRodney W. Grimes if (cnt >= maxcnt) { 14758f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "nprocs corrupt"); 14858f0484fSRodney W. Grimes return (-1); 14958f0484fSRodney W. Grimes } 15058f0484fSRodney W. Grimes /* 15158f0484fSRodney W. Grimes * gather eproc 15258f0484fSRodney W. Grimes */ 15358f0484fSRodney W. Grimes eproc.e_paddr = p; 15458f0484fSRodney W. Grimes if (KREAD(kd, (u_long)proc.p_pgrp, &pgrp)) { 15558f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "can't read pgrp at %x", 15658f0484fSRodney W. Grimes proc.p_pgrp); 15758f0484fSRodney W. Grimes return (-1); 15858f0484fSRodney W. Grimes } 159a58930d8STor Egge if (proc.p_oppid) 160a58930d8STor Egge eproc.e_ppid = proc.p_oppid; 161a58930d8STor Egge else if (proc.p_pptr) { 162a58930d8STor Egge if (KREAD(kd, (u_long)proc.p_pptr, &pproc)) { 163a58930d8STor Egge _kvm_err(kd, kd->program, "can't read pproc at %x", 164a58930d8STor Egge proc.p_pptr); 165a58930d8STor Egge return (-1); 166a58930d8STor Egge } 167a58930d8STor Egge eproc.e_ppid = pproc.p_pid; 168a58930d8STor Egge } else 169a58930d8STor Egge eproc.e_ppid = 0; 17058f0484fSRodney W. Grimes eproc.e_sess = pgrp.pg_session; 17158f0484fSRodney W. Grimes eproc.e_pgid = pgrp.pg_id; 17258f0484fSRodney W. Grimes eproc.e_jobc = pgrp.pg_jobc; 17358f0484fSRodney W. Grimes if (KREAD(kd, (u_long)pgrp.pg_session, &sess)) { 17458f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "can't read session at %x", 17558f0484fSRodney W. Grimes pgrp.pg_session); 17658f0484fSRodney W. Grimes return (-1); 17758f0484fSRodney W. Grimes } 178b8321444SPeter Wemm (void)memcpy(eproc.e_login, sess.s_login, 179b8321444SPeter Wemm sizeof(eproc.e_login)); 18058f0484fSRodney W. Grimes if ((proc.p_flag & P_CONTROLT) && sess.s_ttyp != NULL) { 18158f0484fSRodney W. Grimes if (KREAD(kd, (u_long)sess.s_ttyp, &tty)) { 18258f0484fSRodney W. Grimes _kvm_err(kd, kd->program, 18358f0484fSRodney W. Grimes "can't read tty at %x", sess.s_ttyp); 18458f0484fSRodney W. Grimes return (-1); 18558f0484fSRodney W. Grimes } 18658f0484fSRodney W. Grimes eproc.e_tdev = tty.t_dev; 18758f0484fSRodney W. Grimes eproc.e_tsess = tty.t_session; 18858f0484fSRodney W. Grimes if (tty.t_pgrp != NULL) { 18958f0484fSRodney W. Grimes if (KREAD(kd, (u_long)tty.t_pgrp, &pgrp)) { 19058f0484fSRodney W. Grimes _kvm_err(kd, kd->program, 19158f0484fSRodney W. Grimes "can't read tpgrp at &x", 19258f0484fSRodney W. Grimes tty.t_pgrp); 19358f0484fSRodney W. Grimes return (-1); 19458f0484fSRodney W. Grimes } 19558f0484fSRodney W. Grimes eproc.e_tpgid = pgrp.pg_id; 19658f0484fSRodney W. Grimes } else 19758f0484fSRodney W. Grimes eproc.e_tpgid = -1; 19858f0484fSRodney W. Grimes } else 19958f0484fSRodney W. Grimes eproc.e_tdev = NODEV; 20058f0484fSRodney W. Grimes eproc.e_flag = sess.s_ttyvp ? EPROC_CTTY : 0; 20158f0484fSRodney W. Grimes if (sess.s_leader == p) 20258f0484fSRodney W. Grimes eproc.e_flag |= EPROC_SLEADER; 20358f0484fSRodney W. Grimes if (proc.p_wmesg) 20458f0484fSRodney W. Grimes (void)kvm_read(kd, (u_long)proc.p_wmesg, 20558f0484fSRodney W. Grimes eproc.e_wmesg, WMESGLEN); 20658f0484fSRodney W. Grimes 20758f0484fSRodney W. Grimes #ifdef sparc 20858f0484fSRodney W. Grimes (void)kvm_read(kd, (u_long)&proc.p_vmspace->vm_rssize, 20958f0484fSRodney W. Grimes (char *)&eproc.e_vm.vm_rssize, 21058f0484fSRodney W. Grimes sizeof(eproc.e_vm.vm_rssize)); 21158f0484fSRodney W. Grimes (void)kvm_read(kd, (u_long)&proc.p_vmspace->vm_tsize, 21258f0484fSRodney W. Grimes (char *)&eproc.e_vm.vm_tsize, 21358f0484fSRodney W. Grimes 3 * sizeof(eproc.e_vm.vm_rssize)); /* XXX */ 21458f0484fSRodney W. Grimes #else 21558f0484fSRodney W. Grimes (void)kvm_read(kd, (u_long)proc.p_vmspace, 21658f0484fSRodney W. Grimes (char *)&eproc.e_vm, sizeof(eproc.e_vm)); 21758f0484fSRodney W. Grimes #endif 21858f0484fSRodney W. Grimes eproc.e_xsize = eproc.e_xrssize = 0; 21958f0484fSRodney W. Grimes eproc.e_xccount = eproc.e_xswrss = 0; 22058f0484fSRodney W. Grimes 22158f0484fSRodney W. Grimes switch (what) { 22258f0484fSRodney W. Grimes 22358f0484fSRodney W. Grimes case KERN_PROC_PGRP: 22458f0484fSRodney W. Grimes if (eproc.e_pgid != (pid_t)arg) 22558f0484fSRodney W. Grimes continue; 22658f0484fSRodney W. Grimes break; 22758f0484fSRodney W. Grimes 22858f0484fSRodney W. Grimes case KERN_PROC_TTY: 22958f0484fSRodney W. Grimes if ((proc.p_flag & P_CONTROLT) == 0 || 23058f0484fSRodney W. Grimes eproc.e_tdev != (dev_t)arg) 23158f0484fSRodney W. Grimes continue; 23258f0484fSRodney W. Grimes break; 23358f0484fSRodney W. Grimes } 23458f0484fSRodney W. Grimes bcopy(&proc, &bp->kp_proc, sizeof(proc)); 23558f0484fSRodney W. Grimes bcopy(&eproc, &bp->kp_eproc, sizeof(eproc)); 23658f0484fSRodney W. Grimes ++bp; 23758f0484fSRodney W. Grimes ++cnt; 23858f0484fSRodney W. Grimes } 23958f0484fSRodney W. Grimes return (cnt); 24058f0484fSRodney W. Grimes } 24158f0484fSRodney W. Grimes 24258f0484fSRodney W. Grimes /* 24358f0484fSRodney W. Grimes * Build proc info array by reading in proc list from a crash dump. 24458f0484fSRodney W. Grimes * Return number of procs read. maxcnt is the max we will read. 24558f0484fSRodney W. Grimes */ 24658f0484fSRodney W. Grimes static int 24758f0484fSRodney W. Grimes kvm_deadprocs(kd, what, arg, a_allproc, a_zombproc, maxcnt) 24858f0484fSRodney W. Grimes kvm_t *kd; 24958f0484fSRodney W. Grimes int what, arg; 25058f0484fSRodney W. Grimes u_long a_allproc; 25158f0484fSRodney W. Grimes u_long a_zombproc; 25258f0484fSRodney W. Grimes int maxcnt; 25358f0484fSRodney W. Grimes { 25458f0484fSRodney W. Grimes register struct kinfo_proc *bp = kd->procbase; 25558f0484fSRodney W. Grimes register int acnt, zcnt; 25658f0484fSRodney W. Grimes struct proc *p; 25758f0484fSRodney W. Grimes 25858f0484fSRodney W. Grimes if (KREAD(kd, a_allproc, &p)) { 25958f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "cannot read allproc"); 26058f0484fSRodney W. Grimes return (-1); 26158f0484fSRodney W. Grimes } 26258f0484fSRodney W. Grimes acnt = kvm_proclist(kd, what, arg, p, bp, maxcnt); 26358f0484fSRodney W. Grimes if (acnt < 0) 26458f0484fSRodney W. Grimes return (acnt); 26558f0484fSRodney W. Grimes 26658f0484fSRodney W. Grimes if (KREAD(kd, a_zombproc, &p)) { 26758f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "cannot read zombproc"); 26858f0484fSRodney W. Grimes return (-1); 26958f0484fSRodney W. Grimes } 27058f0484fSRodney W. Grimes zcnt = kvm_proclist(kd, what, arg, p, bp + acnt, maxcnt - acnt); 27158f0484fSRodney W. Grimes if (zcnt < 0) 27258f0484fSRodney W. Grimes zcnt = 0; 27358f0484fSRodney W. Grimes 27458f0484fSRodney W. Grimes return (acnt + zcnt); 27558f0484fSRodney W. Grimes } 27658f0484fSRodney W. Grimes 27758f0484fSRodney W. Grimes struct kinfo_proc * 27858f0484fSRodney W. Grimes kvm_getprocs(kd, op, arg, cnt) 27958f0484fSRodney W. Grimes kvm_t *kd; 28058f0484fSRodney W. Grimes int op, arg; 28158f0484fSRodney W. Grimes int *cnt; 28258f0484fSRodney W. Grimes { 28358f0484fSRodney W. Grimes int mib[4], size, st, nprocs; 28458f0484fSRodney W. Grimes 28558f0484fSRodney W. Grimes if (kd->procbase != 0) { 28658f0484fSRodney W. Grimes free((void *)kd->procbase); 28758f0484fSRodney W. Grimes /* 28858f0484fSRodney W. Grimes * Clear this pointer in case this call fails. Otherwise, 28958f0484fSRodney W. Grimes * kvm_close() will free it again. 29058f0484fSRodney W. Grimes */ 29158f0484fSRodney W. Grimes kd->procbase = 0; 29258f0484fSRodney W. Grimes } 29358f0484fSRodney W. Grimes if (ISALIVE(kd)) { 29458f0484fSRodney W. Grimes size = 0; 29558f0484fSRodney W. Grimes mib[0] = CTL_KERN; 29658f0484fSRodney W. Grimes mib[1] = KERN_PROC; 29758f0484fSRodney W. Grimes mib[2] = op; 29858f0484fSRodney W. Grimes mib[3] = arg; 29944ffb5f5SPoul-Henning Kamp st = sysctl(mib, op == KERN_PROC_ALL ? 3 : 4, NULL, &size, NULL, 0); 30058f0484fSRodney W. Grimes if (st == -1) { 30158f0484fSRodney W. Grimes _kvm_syserr(kd, kd->program, "kvm_getprocs"); 30258f0484fSRodney W. Grimes return (0); 30358f0484fSRodney W. Grimes } 30458f0484fSRodney W. Grimes kd->procbase = (struct kinfo_proc *)_kvm_malloc(kd, size); 30558f0484fSRodney W. Grimes if (kd->procbase == 0) 30658f0484fSRodney W. Grimes return (0); 30744ffb5f5SPoul-Henning Kamp st = sysctl(mib, op == KERN_PROC_ALL ? 3 : 4, kd->procbase, &size, NULL, 0); 30858f0484fSRodney W. Grimes if (st == -1) { 30958f0484fSRodney W. Grimes _kvm_syserr(kd, kd->program, "kvm_getprocs"); 31058f0484fSRodney W. Grimes return (0); 31158f0484fSRodney W. Grimes } 31258f0484fSRodney W. Grimes if (size % sizeof(struct kinfo_proc) != 0) { 31358f0484fSRodney W. Grimes _kvm_err(kd, kd->program, 31458f0484fSRodney W. Grimes "proc size mismatch (%d total, %d chunks)", 31558f0484fSRodney W. Grimes size, sizeof(struct kinfo_proc)); 31658f0484fSRodney W. Grimes return (0); 31758f0484fSRodney W. Grimes } 31858f0484fSRodney W. Grimes nprocs = size / sizeof(struct kinfo_proc); 31958f0484fSRodney W. Grimes } else { 32058f0484fSRodney W. Grimes struct nlist nl[4], *p; 32158f0484fSRodney W. Grimes 32258f0484fSRodney W. Grimes nl[0].n_name = "_nprocs"; 32358f0484fSRodney W. Grimes nl[1].n_name = "_allproc"; 32458f0484fSRodney W. Grimes nl[2].n_name = "_zombproc"; 32558f0484fSRodney W. Grimes nl[3].n_name = 0; 32658f0484fSRodney W. Grimes 32758f0484fSRodney W. Grimes if (kvm_nlist(kd, nl) != 0) { 32858f0484fSRodney W. Grimes for (p = nl; p->n_type != 0; ++p) 32958f0484fSRodney W. Grimes ; 33058f0484fSRodney W. Grimes _kvm_err(kd, kd->program, 33158f0484fSRodney W. Grimes "%s: no such symbol", p->n_name); 33258f0484fSRodney W. Grimes return (0); 33358f0484fSRodney W. Grimes } 33458f0484fSRodney W. Grimes if (KREAD(kd, nl[0].n_value, &nprocs)) { 33558f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "can't read nprocs"); 33658f0484fSRodney W. Grimes return (0); 33758f0484fSRodney W. Grimes } 33858f0484fSRodney W. Grimes size = nprocs * sizeof(struct kinfo_proc); 33958f0484fSRodney W. Grimes kd->procbase = (struct kinfo_proc *)_kvm_malloc(kd, size); 34058f0484fSRodney W. Grimes if (kd->procbase == 0) 34158f0484fSRodney W. Grimes return (0); 34258f0484fSRodney W. Grimes 34358f0484fSRodney W. Grimes nprocs = kvm_deadprocs(kd, op, arg, nl[1].n_value, 34458f0484fSRodney W. Grimes nl[2].n_value, nprocs); 34558f0484fSRodney W. Grimes #ifdef notdef 34658f0484fSRodney W. Grimes size = nprocs * sizeof(struct kinfo_proc); 34758f0484fSRodney W. Grimes (void)realloc(kd->procbase, size); 34858f0484fSRodney W. Grimes #endif 34958f0484fSRodney W. Grimes } 35058f0484fSRodney W. Grimes *cnt = nprocs; 35158f0484fSRodney W. Grimes return (kd->procbase); 35258f0484fSRodney W. Grimes } 35358f0484fSRodney W. Grimes 35458f0484fSRodney W. Grimes void 35558f0484fSRodney W. Grimes _kvm_freeprocs(kd) 35658f0484fSRodney W. Grimes kvm_t *kd; 35758f0484fSRodney W. Grimes { 35858f0484fSRodney W. Grimes if (kd->procbase) { 35958f0484fSRodney W. Grimes free(kd->procbase); 36058f0484fSRodney W. Grimes kd->procbase = 0; 36158f0484fSRodney W. Grimes } 36258f0484fSRodney W. Grimes } 36358f0484fSRodney W. Grimes 36458f0484fSRodney W. Grimes void * 36558f0484fSRodney W. Grimes _kvm_realloc(kd, p, n) 36658f0484fSRodney W. Grimes kvm_t *kd; 36758f0484fSRodney W. Grimes void *p; 36858f0484fSRodney W. Grimes size_t n; 36958f0484fSRodney W. Grimes { 37058f0484fSRodney W. Grimes void *np = (void *)realloc(p, n); 37158f0484fSRodney W. Grimes 37258f0484fSRodney W. Grimes if (np == 0) 37358f0484fSRodney W. Grimes _kvm_err(kd, kd->program, "out of memory"); 37458f0484fSRodney W. Grimes return (np); 37558f0484fSRodney W. Grimes } 37658f0484fSRodney W. Grimes 37758f0484fSRodney W. Grimes #ifndef MAX 37858f0484fSRodney W. Grimes #define MAX(a, b) ((a) > (b) ? (a) : (b)) 37958f0484fSRodney W. Grimes #endif 38058f0484fSRodney W. Grimes 38158f0484fSRodney W. Grimes /* 38258f0484fSRodney W. Grimes * Read in an argument vector from the user address space of process p. 38377721f53SPeter Wemm * addr if the user-space base address of narg null-terminated contiguous 38458f0484fSRodney W. Grimes * strings. This is used to read in both the command arguments and 38558f0484fSRodney W. Grimes * environment strings. Read at most maxcnt characters of strings. 38658f0484fSRodney W. Grimes */ 38758f0484fSRodney W. Grimes static char ** 38858f0484fSRodney W. Grimes kvm_argv(kd, p, addr, narg, maxcnt) 38958f0484fSRodney W. Grimes kvm_t *kd; 39077721f53SPeter Wemm const struct proc *p; 39158f0484fSRodney W. Grimes register u_long addr; 39258f0484fSRodney W. Grimes register int narg; 39358f0484fSRodney W. Grimes register int maxcnt; 39458f0484fSRodney W. Grimes { 39577721f53SPeter Wemm register char *np, *cp, *ep, *ap; 39677721f53SPeter Wemm register u_long oaddr = -1; 39758f0484fSRodney W. Grimes register int len, cc; 39858f0484fSRodney W. Grimes register char **argv; 39958f0484fSRodney W. Grimes 40058f0484fSRodney W. Grimes /* 40158f0484fSRodney W. Grimes * Check that there aren't an unreasonable number of agruments, 40258f0484fSRodney W. Grimes * and that the address is in user space. 40358f0484fSRodney W. Grimes */ 4046b492ae4SPeter Wemm if (narg > 512 || addr < VM_MIN_ADDRESS || addr >= VM_MAXUSER_ADDRESS) 40558f0484fSRodney W. Grimes return (0); 40658f0484fSRodney W. Grimes 4076b492ae4SPeter Wemm /* 4086b492ae4SPeter Wemm * kd->argv : work space for fetching the strings from the target 4096b492ae4SPeter Wemm * process's space, and is converted for returning to caller 4106b492ae4SPeter Wemm */ 41158f0484fSRodney W. Grimes if (kd->argv == 0) { 41258f0484fSRodney W. Grimes /* 41358f0484fSRodney W. Grimes * Try to avoid reallocs. 41458f0484fSRodney W. Grimes */ 41558f0484fSRodney W. Grimes kd->argc = MAX(narg + 1, 32); 41658f0484fSRodney W. Grimes kd->argv = (char **)_kvm_malloc(kd, kd->argc * 41758f0484fSRodney W. Grimes sizeof(*kd->argv)); 41858f0484fSRodney W. Grimes if (kd->argv == 0) 41958f0484fSRodney W. Grimes return (0); 42058f0484fSRodney W. Grimes } else if (narg + 1 > kd->argc) { 42158f0484fSRodney W. Grimes kd->argc = MAX(2 * kd->argc, narg + 1); 42258f0484fSRodney W. Grimes kd->argv = (char **)_kvm_realloc(kd, kd->argv, kd->argc * 42358f0484fSRodney W. Grimes sizeof(*kd->argv)); 42458f0484fSRodney W. Grimes if (kd->argv == 0) 42558f0484fSRodney W. Grimes return (0); 42658f0484fSRodney W. Grimes } 4276b492ae4SPeter Wemm /* 4286b492ae4SPeter Wemm * kd->argspc : returned to user, this is where the kd->argv 4296b492ae4SPeter Wemm * arrays are left pointing to the collected strings. 4306b492ae4SPeter Wemm */ 43158f0484fSRodney W. Grimes if (kd->argspc == 0) { 4322572133eSPoul-Henning Kamp kd->argspc = (char *)_kvm_malloc(kd, PAGE_SIZE); 43358f0484fSRodney W. Grimes if (kd->argspc == 0) 43458f0484fSRodney W. Grimes return (0); 4352572133eSPoul-Henning Kamp kd->arglen = PAGE_SIZE; 43658f0484fSRodney W. Grimes } 4376b492ae4SPeter Wemm /* 4386b492ae4SPeter Wemm * kd->argbuf : used to pull in pages from the target process. 4396b492ae4SPeter Wemm * the strings are copied out of here. 4406b492ae4SPeter Wemm */ 44177721f53SPeter Wemm if (kd->argbuf == 0) { 4422572133eSPoul-Henning Kamp kd->argbuf = (char *)_kvm_malloc(kd, PAGE_SIZE); 44377721f53SPeter Wemm if (kd->argbuf == 0) 44477721f53SPeter Wemm return (0); 44577721f53SPeter Wemm } 4466b492ae4SPeter Wemm 4476b492ae4SPeter Wemm /* Pull in the target process'es argv vector */ 44877721f53SPeter Wemm cc = sizeof(char *) * narg; 44977721f53SPeter Wemm if (kvm_uread(kd, p, addr, (char *)kd->argv, cc) != cc) 45077721f53SPeter Wemm return (0); 4516b492ae4SPeter Wemm /* 4526b492ae4SPeter Wemm * ap : saved start address of string we're working on in kd->argspc 4536b492ae4SPeter Wemm * np : pointer to next place to write in kd->argspc 4546b492ae4SPeter Wemm * len: length of data in kd->argspc 4556b492ae4SPeter Wemm * argv: pointer to the argv vector that we are hunting around the 4566b492ae4SPeter Wemm * target process space for, and converting to addresses in 4576b492ae4SPeter Wemm * our address space (kd->argspc). 4586b492ae4SPeter Wemm */ 45977721f53SPeter Wemm ap = np = kd->argspc; 46058f0484fSRodney W. Grimes argv = kd->argv; 46158f0484fSRodney W. Grimes len = 0; 46258f0484fSRodney W. Grimes /* 46358f0484fSRodney W. Grimes * Loop over pages, filling in the argument vector. 4646b492ae4SPeter Wemm * Note that the argv strings could be pointing *anywhere* in 4656b492ae4SPeter Wemm * the user address space and are no longer contiguous. 4666b492ae4SPeter Wemm * Note that *argv is modified when we are going to fetch a string 4676b492ae4SPeter Wemm * that crosses a page boundary. We copy the next part of the string 4686b492ae4SPeter Wemm * into to "np" and eventually convert the pointer. 46958f0484fSRodney W. Grimes */ 47077721f53SPeter Wemm while (argv < kd->argv + narg && *argv != 0) { 4716b492ae4SPeter Wemm 4726b492ae4SPeter Wemm /* get the address that the current argv string is on */ 4732572133eSPoul-Henning Kamp addr = (u_long)*argv & ~(PAGE_SIZE - 1); 4746b492ae4SPeter Wemm 4756b492ae4SPeter Wemm /* is it the same page as the last one? */ 47677721f53SPeter Wemm if (addr != oaddr) { 4772572133eSPoul-Henning Kamp if (kvm_uread(kd, p, addr, kd->argbuf, PAGE_SIZE) != 4782572133eSPoul-Henning Kamp PAGE_SIZE) 47977721f53SPeter Wemm return (0); 48077721f53SPeter Wemm oaddr = addr; 48177721f53SPeter Wemm } 4826b492ae4SPeter Wemm 4836b492ae4SPeter Wemm /* offset within the page... kd->argbuf */ 4842572133eSPoul-Henning Kamp addr = (u_long)*argv & (PAGE_SIZE - 1); 4856b492ae4SPeter Wemm 4866b492ae4SPeter Wemm /* cp = start of string, cc = count of chars in this chunk */ 48777721f53SPeter Wemm cp = kd->argbuf + addr; 4882572133eSPoul-Henning Kamp cc = PAGE_SIZE - addr; 4896b492ae4SPeter Wemm 4906b492ae4SPeter Wemm /* dont get more than asked for by user process */ 49158f0484fSRodney W. Grimes if (maxcnt > 0 && cc > maxcnt - len) 4926b492ae4SPeter Wemm cc = maxcnt - len; 4936b492ae4SPeter Wemm 4946b492ae4SPeter Wemm /* pointer to end of string if we found it in this page */ 49577721f53SPeter Wemm ep = memchr(cp, '\0', cc); 49677721f53SPeter Wemm if (ep != 0) 49777721f53SPeter Wemm cc = ep - cp + 1; 4986b492ae4SPeter Wemm /* 4996b492ae4SPeter Wemm * at this point, cc is the count of the chars that we are 5006b492ae4SPeter Wemm * going to retrieve this time. we may or may not have found 5016b492ae4SPeter Wemm * the end of it. (ep points to the null if the end is known) 5026b492ae4SPeter Wemm */ 5036b492ae4SPeter Wemm 5046b492ae4SPeter Wemm /* will we exceed the malloc/realloced buffer? */ 50558f0484fSRodney W. Grimes if (len + cc > kd->arglen) { 50658f0484fSRodney W. Grimes register int off; 50758f0484fSRodney W. Grimes register char **pp; 50858f0484fSRodney W. Grimes register char *op = kd->argspc; 50958f0484fSRodney W. Grimes 51058f0484fSRodney W. Grimes kd->arglen *= 2; 51158f0484fSRodney W. Grimes kd->argspc = (char *)_kvm_realloc(kd, kd->argspc, 51258f0484fSRodney W. Grimes kd->arglen); 51358f0484fSRodney W. Grimes if (kd->argspc == 0) 51458f0484fSRodney W. Grimes return (0); 51558f0484fSRodney W. Grimes /* 51658f0484fSRodney W. Grimes * Adjust argv pointers in case realloc moved 51758f0484fSRodney W. Grimes * the string space. 51858f0484fSRodney W. Grimes */ 51958f0484fSRodney W. Grimes off = kd->argspc - op; 52077721f53SPeter Wemm for (pp = kd->argv; pp < argv; pp++) 52158f0484fSRodney W. Grimes *pp += off; 52277721f53SPeter Wemm ap += off; 52377721f53SPeter Wemm np += off; 52458f0484fSRodney W. Grimes } 5256b492ae4SPeter Wemm /* np = where to put the next part of the string in kd->argspc*/ 5266b492ae4SPeter Wemm /* np is kinda redundant.. could use "kd->argspc + len" */ 52777721f53SPeter Wemm memcpy(np, cp, cc); 5286b492ae4SPeter Wemm np += cc; /* inc counters */ 52958f0484fSRodney W. Grimes len += cc; 5306b492ae4SPeter Wemm 5316b492ae4SPeter Wemm /* 5326b492ae4SPeter Wemm * if end of string found, set the *argv pointer to the 5336b492ae4SPeter Wemm * saved beginning of string, and advance. argv points to 5346b492ae4SPeter Wemm * somewhere in kd->argv.. This is initially relative 5356b492ae4SPeter Wemm * to the target process, but when we close it off, we set 5366b492ae4SPeter Wemm * it to point in our address space. 5376b492ae4SPeter Wemm */ 53877721f53SPeter Wemm if (ep != 0) { 53977721f53SPeter Wemm *argv++ = ap; 54077721f53SPeter Wemm ap = np; 5416b492ae4SPeter Wemm } else { 5426b492ae4SPeter Wemm /* update the address relative to the target process */ 54377721f53SPeter Wemm *argv += cc; 5446b492ae4SPeter Wemm } 5456b492ae4SPeter Wemm 54658f0484fSRodney W. Grimes if (maxcnt > 0 && len >= maxcnt) { 54758f0484fSRodney W. Grimes /* 54858f0484fSRodney W. Grimes * We're stopping prematurely. Terminate the 54977721f53SPeter Wemm * current string. 55058f0484fSRodney W. Grimes */ 55177721f53SPeter Wemm if (ep == 0) { 55277721f53SPeter Wemm *np = '\0'; 55377721f53SPeter Wemm *argv++ = ap; 55477721f53SPeter Wemm } 55577721f53SPeter Wemm break; 55677721f53SPeter Wemm } 55777721f53SPeter Wemm } 55877721f53SPeter Wemm /* Make sure argv is terminated. */ 55977721f53SPeter Wemm *argv = 0; 56058f0484fSRodney W. Grimes return (kd->argv); 56158f0484fSRodney W. Grimes } 56258f0484fSRodney W. Grimes 56358f0484fSRodney W. Grimes static void 56458f0484fSRodney W. Grimes ps_str_a(p, addr, n) 56558f0484fSRodney W. Grimes struct ps_strings *p; 56658f0484fSRodney W. Grimes u_long *addr; 56758f0484fSRodney W. Grimes int *n; 56858f0484fSRodney W. Grimes { 56958f0484fSRodney W. Grimes *addr = (u_long)p->ps_argvstr; 57058f0484fSRodney W. Grimes *n = p->ps_nargvstr; 57158f0484fSRodney W. Grimes } 57258f0484fSRodney W. Grimes 57358f0484fSRodney W. Grimes static void 57458f0484fSRodney W. Grimes ps_str_e(p, addr, n) 57558f0484fSRodney W. Grimes struct ps_strings *p; 57658f0484fSRodney W. Grimes u_long *addr; 57758f0484fSRodney W. Grimes int *n; 57858f0484fSRodney W. Grimes { 57958f0484fSRodney W. Grimes *addr = (u_long)p->ps_envstr; 58058f0484fSRodney W. Grimes *n = p->ps_nenvstr; 58158f0484fSRodney W. Grimes } 58258f0484fSRodney W. Grimes 58358f0484fSRodney W. Grimes /* 58458f0484fSRodney W. Grimes * Determine if the proc indicated by p is still active. 58558f0484fSRodney W. Grimes * This test is not 100% foolproof in theory, but chances of 58658f0484fSRodney W. Grimes * being wrong are very low. 58758f0484fSRodney W. Grimes */ 58858f0484fSRodney W. Grimes static int 58958f0484fSRodney W. Grimes proc_verify(kd, kernp, p) 59058f0484fSRodney W. Grimes kvm_t *kd; 59158f0484fSRodney W. Grimes u_long kernp; 59258f0484fSRodney W. Grimes const struct proc *p; 59358f0484fSRodney W. Grimes { 59458f0484fSRodney W. Grimes struct proc kernproc; 59558f0484fSRodney W. Grimes 59658f0484fSRodney W. Grimes /* 59758f0484fSRodney W. Grimes * Just read in the whole proc. It's not that big relative 59858f0484fSRodney W. Grimes * to the cost of the read system call. 59958f0484fSRodney W. Grimes */ 60058f0484fSRodney W. Grimes if (kvm_read(kd, kernp, (char *)&kernproc, sizeof(kernproc)) != 60158f0484fSRodney W. Grimes sizeof(kernproc)) 60258f0484fSRodney W. Grimes return (0); 60358f0484fSRodney W. Grimes return (p->p_pid == kernproc.p_pid && 60458f0484fSRodney W. Grimes (kernproc.p_stat != SZOMB || p->p_stat == SZOMB)); 60558f0484fSRodney W. Grimes } 60658f0484fSRodney W. Grimes 60758f0484fSRodney W. Grimes static char ** 60858f0484fSRodney W. Grimes kvm_doargv(kd, kp, nchr, info) 60958f0484fSRodney W. Grimes kvm_t *kd; 61058f0484fSRodney W. Grimes const struct kinfo_proc *kp; 61158f0484fSRodney W. Grimes int nchr; 61277721f53SPeter Wemm void (*info)(struct ps_strings *, u_long *, int *); 61358f0484fSRodney W. Grimes { 61458f0484fSRodney W. Grimes register const struct proc *p = &kp->kp_proc; 61558f0484fSRodney W. Grimes register char **ap; 61658f0484fSRodney W. Grimes u_long addr; 61758f0484fSRodney W. Grimes int cnt; 6187350dd84SPeter Wemm struct ps_strings arginfo, *ps_strings; 6197350dd84SPeter Wemm int mib[2]; 6207350dd84SPeter Wemm size_t len; 6217350dd84SPeter Wemm 6227350dd84SPeter Wemm ps_strings = NULL; 6237350dd84SPeter Wemm mib[0] = CTL_KERN; 6247350dd84SPeter Wemm mib[1] = KERN_PS_STRINGS; 6257350dd84SPeter Wemm len = sizeof(ps_strings); 6267350dd84SPeter Wemm if (sysctl(mib, 2, &ps_strings, &len, NULL, 0) < 0 || 6277350dd84SPeter Wemm ps_strings == NULL) 6287350dd84SPeter Wemm ps_strings = PS_STRINGS; 62958f0484fSRodney W. Grimes 63058f0484fSRodney W. Grimes /* 63158f0484fSRodney W. Grimes * Pointers are stored at the top of the user stack. 63258f0484fSRodney W. Grimes */ 63358f0484fSRodney W. Grimes if (p->p_stat == SZOMB || 6347350dd84SPeter Wemm kvm_uread(kd, p, ps_strings, (char *)&arginfo, 63577721f53SPeter Wemm sizeof(arginfo)) != sizeof(arginfo)) 63658f0484fSRodney W. Grimes return (0); 63758f0484fSRodney W. Grimes 63858f0484fSRodney W. Grimes (*info)(&arginfo, &addr, &cnt); 63977721f53SPeter Wemm if (cnt == 0) 64077721f53SPeter Wemm return (0); 64158f0484fSRodney W. Grimes ap = kvm_argv(kd, p, addr, cnt, nchr); 64258f0484fSRodney W. Grimes /* 64358f0484fSRodney W. Grimes * For live kernels, make sure this process didn't go away. 64458f0484fSRodney W. Grimes */ 64558f0484fSRodney W. Grimes if (ap != 0 && ISALIVE(kd) && 64658f0484fSRodney W. Grimes !proc_verify(kd, (u_long)kp->kp_eproc.e_paddr, p)) 64758f0484fSRodney W. Grimes ap = 0; 64858f0484fSRodney W. Grimes return (ap); 64958f0484fSRodney W. Grimes } 65058f0484fSRodney W. Grimes 65158f0484fSRodney W. Grimes /* 65258f0484fSRodney W. Grimes * Get the command args. This code is now machine independent. 65358f0484fSRodney W. Grimes */ 65458f0484fSRodney W. Grimes char ** 65558f0484fSRodney W. Grimes kvm_getargv(kd, kp, nchr) 65658f0484fSRodney W. Grimes kvm_t *kd; 65758f0484fSRodney W. Grimes const struct kinfo_proc *kp; 65858f0484fSRodney W. Grimes int nchr; 65958f0484fSRodney W. Grimes { 66058f0484fSRodney W. Grimes return (kvm_doargv(kd, kp, nchr, ps_str_a)); 66158f0484fSRodney W. Grimes } 66258f0484fSRodney W. Grimes 66358f0484fSRodney W. Grimes char ** 66458f0484fSRodney W. Grimes kvm_getenvv(kd, kp, nchr) 66558f0484fSRodney W. Grimes kvm_t *kd; 66658f0484fSRodney W. Grimes const struct kinfo_proc *kp; 66758f0484fSRodney W. Grimes int nchr; 66858f0484fSRodney W. Grimes { 66958f0484fSRodney W. Grimes return (kvm_doargv(kd, kp, nchr, ps_str_e)); 67058f0484fSRodney W. Grimes } 67158f0484fSRodney W. Grimes 67258f0484fSRodney W. Grimes /* 67358f0484fSRodney W. Grimes * Read from user space. The user context is given by p. 67458f0484fSRodney W. Grimes */ 67558f0484fSRodney W. Grimes ssize_t 67658f0484fSRodney W. Grimes kvm_uread(kd, p, uva, buf, len) 67758f0484fSRodney W. Grimes kvm_t *kd; 67851295a4dSJordan K. Hubbard register const struct proc *p; 67958f0484fSRodney W. Grimes register u_long uva; 68058f0484fSRodney W. Grimes register char *buf; 68158f0484fSRodney W. Grimes register size_t len; 68258f0484fSRodney W. Grimes { 68358f0484fSRodney W. Grimes register char *cp; 684338c7541SDavid Greenman char procfile[MAXPATHLEN]; 685338c7541SDavid Greenman ssize_t amount; 686338c7541SDavid Greenman int fd; 68758f0484fSRodney W. Grimes 6887350dd84SPeter Wemm if (!ISALIVE(kd)) { 6897350dd84SPeter Wemm _kvm_err(kd, kd->program, "cannot read user space from dead kernel"); 6907350dd84SPeter Wemm return(0); 6917350dd84SPeter Wemm } 6927350dd84SPeter Wemm 69358f0484fSRodney W. Grimes cp = buf; 69458f0484fSRodney W. Grimes 695338c7541SDavid Greenman sprintf(procfile, "/proc/%d/mem", p->p_pid); 696338c7541SDavid Greenman fd = open(procfile, O_RDONLY, 0); 69758f0484fSRodney W. Grimes 698338c7541SDavid Greenman if (fd < 0) { 699338c7541SDavid Greenman _kvm_err(kd, kd->program, "cannot open %s", procfile); 700338c7541SDavid Greenman close(fd); 70158f0484fSRodney W. Grimes return (0); 70258f0484fSRodney W. Grimes } 703338c7541SDavid Greenman 704338c7541SDavid Greenman 705338c7541SDavid Greenman while (len > 0) { 706ec4f2251SJoerg Wunsch if (lseek(fd, (off_t)uva, 0) == -1 && errno != 0) { 707338c7541SDavid Greenman _kvm_err(kd, kd->program, "invalid address (%x) in %s", uva, procfile); 70858f0484fSRodney W. Grimes break; 70958f0484fSRodney W. Grimes } 710567127faSDavid Greenman amount = read(fd, cp, len); 711338c7541SDavid Greenman if (amount < 0) { 712338c7541SDavid Greenman _kvm_err(kd, kd->program, "error reading %s", procfile); 713338c7541SDavid Greenman break; 714338c7541SDavid Greenman } 715338c7541SDavid Greenman cp += amount; 716338c7541SDavid Greenman uva += amount; 717338c7541SDavid Greenman len -= amount; 718338c7541SDavid Greenman } 719338c7541SDavid Greenman 720338c7541SDavid Greenman close(fd); 72158f0484fSRodney W. Grimes return (ssize_t)(cp - buf); 72258f0484fSRodney W. Grimes } 723