xref: /freebsd/lib/libproc/proc_bkpt.c (revision 27e54fb59e46cc309e9bdbd0697cafb11938c23c)
18eb20f36SRui Paulo /*
28eb20f36SRui Paulo  * Copyright (c) 2010 The FreeBSD Foundation
38eb20f36SRui Paulo  * All rights reserved.
48eb20f36SRui Paulo  *
58eb20f36SRui Paulo  * This software was developed by Rui Paulo under sponsorship from the
68eb20f36SRui Paulo  * FreeBSD Foundation.
78eb20f36SRui Paulo  *
88eb20f36SRui Paulo  * Redistribution and use in source and binary forms, with or without
98eb20f36SRui Paulo  * modification, are permitted provided that the following conditions
108eb20f36SRui Paulo  * are met:
118eb20f36SRui Paulo  * 1. Redistributions of source code must retain the above copyright
128eb20f36SRui Paulo  *    notice, this list of conditions and the following disclaimer.
138eb20f36SRui Paulo  * 2. Redistributions in binary form must reproduce the above copyright
148eb20f36SRui Paulo  *    notice, this list of conditions and the following disclaimer in the
158eb20f36SRui Paulo  *    documentation and/or other materials provided with the distribution.
168eb20f36SRui Paulo  *
178eb20f36SRui Paulo  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
188eb20f36SRui Paulo  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
198eb20f36SRui Paulo  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
208eb20f36SRui Paulo  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
218eb20f36SRui Paulo  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
228eb20f36SRui Paulo  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
238eb20f36SRui Paulo  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
248eb20f36SRui Paulo  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
258eb20f36SRui Paulo  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
268eb20f36SRui Paulo  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
278eb20f36SRui Paulo  * SUCH DAMAGE.
288eb20f36SRui Paulo  */
298eb20f36SRui Paulo 
308eb20f36SRui Paulo #include <sys/cdefs.h>
318eb20f36SRui Paulo __FBSDID("$FreeBSD$");
328eb20f36SRui Paulo 
338eb20f36SRui Paulo #include <sys/types.h>
348eb20f36SRui Paulo #include <sys/ptrace.h>
358eb20f36SRui Paulo #include <sys/wait.h>
368eb20f36SRui Paulo #include <machine/_inttypes.h>
378eb20f36SRui Paulo 
388eb20f36SRui Paulo #include <assert.h>
398eb20f36SRui Paulo #include <err.h>
408eb20f36SRui Paulo #include <errno.h>
41813b2694SMark Johnston #include <signal.h>
42813b2694SMark Johnston #include <stdio.h>
438eb20f36SRui Paulo #include "_libproc.h"
448eb20f36SRui Paulo 
45*27e54fb5SRuslan Bukin #if defined(__aarch64__)
46*27e54fb5SRuslan Bukin #define	AARCH64_BRK		0xd4200000
47*27e54fb5SRuslan Bukin #define	AARCH64_BRK_IMM16_SHIFT	5
48*27e54fb5SRuslan Bukin #define	AARCH64_BRK_IMM16_VAL	(0xd << AARCH64_BRK_IMM16_SHIFT)
49*27e54fb5SRuslan Bukin #define	BREAKPOINT_INSTR	(AARCH64_BRK | AARCH64_BRK_IMM16_VAL)
50*27e54fb5SRuslan Bukin #define	BREAKPOINT_INSTR_SZ	4
51*27e54fb5SRuslan Bukin #elif defined(__amd64__) || defined(__i386__)
528eb20f36SRui Paulo #define	BREAKPOINT_INSTR	0xcc	/* int 0x3 */
538eb20f36SRui Paulo #define	BREAKPOINT_INSTR_SZ	1
54*27e54fb5SRuslan Bukin #elif defined(__arm__)
55*27e54fb5SRuslan Bukin #define	BREAKPOINT_INSTR	0xe7ffffff	/* bkpt */
56*27e54fb5SRuslan Bukin #define	BREAKPOINT_INSTR_SZ	4
57f2242861SOleksandr Tymoshenko #elif defined(__mips__)
58f2242861SOleksandr Tymoshenko #define	BREAKPOINT_INSTR	0xd	/* break */
59f2242861SOleksandr Tymoshenko #define	BREAKPOINT_INSTR_SZ	4
60c7570492SJustin Hibbits #elif defined(__powerpc__)
61c7570492SJustin Hibbits #define	BREAKPOINT_INSTR	0x7fe00008	/* trap */
62c7570492SJustin Hibbits #define	BREAKPOINT_INSTR_SZ	4
638eb20f36SRui Paulo #else
648eb20f36SRui Paulo #error "Add support for your architecture"
658eb20f36SRui Paulo #endif
668eb20f36SRui Paulo 
67813b2694SMark Johnston static int
68813b2694SMark Johnston proc_stop(struct proc_handle *phdl)
69813b2694SMark Johnston {
70813b2694SMark Johnston 	int status;
71813b2694SMark Johnston 
72813b2694SMark Johnston 	if (kill(proc_getpid(phdl), SIGSTOP) == -1) {
73813b2694SMark Johnston 		DPRINTF("kill %d", proc_getpid(phdl));
74813b2694SMark Johnston 		return (-1);
75813b2694SMark Johnston 	} else if (waitpid(proc_getpid(phdl), &status, WSTOPPED) == -1) {
76813b2694SMark Johnston 		DPRINTF("waitpid %d", proc_getpid(phdl));
77813b2694SMark Johnston 		return (-1);
78813b2694SMark Johnston 	} else if (!WIFSTOPPED(status)) {
79813b2694SMark Johnston 		DPRINTFX("waitpid: unexpected status 0x%x", status);
80813b2694SMark Johnston 		return (-1);
81813b2694SMark Johnston 	}
82813b2694SMark Johnston 
83813b2694SMark Johnston 	return (0);
84813b2694SMark Johnston }
85813b2694SMark Johnston 
868eb20f36SRui Paulo int
878eb20f36SRui Paulo proc_bkptset(struct proc_handle *phdl, uintptr_t address,
888eb20f36SRui Paulo     unsigned long *saved)
898eb20f36SRui Paulo {
908eb20f36SRui Paulo 	struct ptrace_io_desc piod;
918eb20f36SRui Paulo 	unsigned long paddr, caddr;
9292f92525SMark Johnston 	int ret = 0, stopped;
938eb20f36SRui Paulo 
948eb20f36SRui Paulo 	*saved = 0;
958eb20f36SRui Paulo 	if (phdl->status == PS_DEAD || phdl->status == PS_UNDEAD ||
968eb20f36SRui Paulo 	    phdl->status == PS_IDLE) {
978eb20f36SRui Paulo 		errno = ENOENT;
988eb20f36SRui Paulo 		return (-1);
998eb20f36SRui Paulo 	}
1008eb20f36SRui Paulo 
101813b2694SMark Johnston 	DPRINTFX("adding breakpoint at 0x%lx", address);
102813b2694SMark Johnston 
10392f92525SMark Johnston 	stopped = 0;
10492f92525SMark Johnston 	if (phdl->status != PS_STOP) {
105813b2694SMark Johnston 		if (proc_stop(phdl) != 0)
106813b2694SMark Johnston 			return (-1);
10792f92525SMark Johnston 		stopped = 1;
10892f92525SMark Johnston 	}
109813b2694SMark Johnston 
1108eb20f36SRui Paulo 	/*
1118eb20f36SRui Paulo 	 * Read the original instruction.
1128eb20f36SRui Paulo 	 */
1138eb20f36SRui Paulo 	caddr = address;
1148eb20f36SRui Paulo 	paddr = 0;
1158eb20f36SRui Paulo 	piod.piod_op = PIOD_READ_I;
1168eb20f36SRui Paulo 	piod.piod_offs = (void *)caddr;
1178eb20f36SRui Paulo 	piod.piod_addr = &paddr;
1188eb20f36SRui Paulo 	piod.piod_len  = BREAKPOINT_INSTR_SZ;
1198eb20f36SRui Paulo 	if (ptrace(PT_IO, proc_getpid(phdl), (caddr_t)&piod, 0) < 0) {
12030e81f7eSMark Johnston 		DPRINTF("ERROR: couldn't read instruction at address 0x%"
12130e81f7eSMark Johnston 		    PRIuPTR, address);
122813b2694SMark Johnston 		ret = -1;
123813b2694SMark Johnston 		goto done;
1248eb20f36SRui Paulo 	}
1258eb20f36SRui Paulo 	*saved = paddr;
1268eb20f36SRui Paulo 	/*
1278eb20f36SRui Paulo 	 * Write a breakpoint instruction to that address.
1288eb20f36SRui Paulo 	 */
1298eb20f36SRui Paulo 	caddr = address;
1308eb20f36SRui Paulo 	paddr = BREAKPOINT_INSTR;
1318eb20f36SRui Paulo 	piod.piod_op = PIOD_WRITE_I;
1328eb20f36SRui Paulo 	piod.piod_offs = (void *)caddr;
1338eb20f36SRui Paulo 	piod.piod_addr = &paddr;
1348eb20f36SRui Paulo 	piod.piod_len  = BREAKPOINT_INSTR_SZ;
1358eb20f36SRui Paulo 	if (ptrace(PT_IO, proc_getpid(phdl), (caddr_t)&piod, 0) < 0) {
13630e81f7eSMark Johnston 		DPRINTF("ERROR: couldn't write instruction at address 0x%"
13730e81f7eSMark Johnston 		    PRIuPTR, address);
138813b2694SMark Johnston 		ret = -1;
139813b2694SMark Johnston 		goto done;
1408eb20f36SRui Paulo 	}
1418eb20f36SRui Paulo 
142813b2694SMark Johnston done:
14392f92525SMark Johnston 	if (stopped)
144813b2694SMark Johnston 		/* Restart the process if we had to stop it. */
14592f92525SMark Johnston 		proc_continue(phdl);
146813b2694SMark Johnston 
147813b2694SMark Johnston 	return (ret);
1488eb20f36SRui Paulo }
1498eb20f36SRui Paulo 
1508eb20f36SRui Paulo int
1518eb20f36SRui Paulo proc_bkptdel(struct proc_handle *phdl, uintptr_t address,
1528eb20f36SRui Paulo     unsigned long saved)
1538eb20f36SRui Paulo {
1548eb20f36SRui Paulo 	struct ptrace_io_desc piod;
1558eb20f36SRui Paulo 	unsigned long paddr, caddr;
15692f92525SMark Johnston 	int ret = 0, stopped;
1578eb20f36SRui Paulo 
1588eb20f36SRui Paulo 	if (phdl->status == PS_DEAD || phdl->status == PS_UNDEAD ||
1598eb20f36SRui Paulo 	    phdl->status == PS_IDLE) {
1608eb20f36SRui Paulo 		errno = ENOENT;
1618eb20f36SRui Paulo 		return (-1);
1628eb20f36SRui Paulo 	}
163813b2694SMark Johnston 
164813b2694SMark Johnston 	DPRINTFX("removing breakpoint at 0x%lx", address);
165813b2694SMark Johnston 
16692f92525SMark Johnston 	stopped = 0;
16792f92525SMark Johnston 	if (phdl->status != PS_STOP) {
168813b2694SMark Johnston 		if (proc_stop(phdl) != 0)
169813b2694SMark Johnston 			return (-1);
17092f92525SMark Johnston 		stopped = 1;
17192f92525SMark Johnston 	}
172813b2694SMark Johnston 
1738eb20f36SRui Paulo 	/*
1748eb20f36SRui Paulo 	 * Overwrite the breakpoint instruction that we setup previously.
1758eb20f36SRui Paulo 	 */
1768eb20f36SRui Paulo 	caddr = address;
1778eb20f36SRui Paulo 	paddr = saved;
1788eb20f36SRui Paulo 	piod.piod_op = PIOD_WRITE_I;
1798eb20f36SRui Paulo 	piod.piod_offs = (void *)caddr;
1808eb20f36SRui Paulo 	piod.piod_addr = &paddr;
1818eb20f36SRui Paulo 	piod.piod_len  = BREAKPOINT_INSTR_SZ;
1828eb20f36SRui Paulo 	if (ptrace(PT_IO, proc_getpid(phdl), (caddr_t)&piod, 0) < 0) {
18330e81f7eSMark Johnston 		DPRINTF("ERROR: couldn't write instruction at address 0x%"
18430e81f7eSMark Johnston 		    PRIuPTR, address);
185813b2694SMark Johnston 		ret = -1;
1868eb20f36SRui Paulo 	}
1878eb20f36SRui Paulo 
18892f92525SMark Johnston 	if (stopped)
189813b2694SMark Johnston 		/* Restart the process if we had to stop it. */
19092f92525SMark Johnston 		proc_continue(phdl);
191813b2694SMark Johnston 
192813b2694SMark Johnston 	return (ret);
1938eb20f36SRui Paulo }
1948eb20f36SRui Paulo 
1958eb20f36SRui Paulo /*
1968eb20f36SRui Paulo  * Decrement pc so that we delete the breakpoint at the correct
1978eb20f36SRui Paulo  * address, i.e. at the BREAKPOINT_INSTR address.
1988eb20f36SRui Paulo  */
1998eb20f36SRui Paulo void
2008eb20f36SRui Paulo proc_bkptregadj(unsigned long *pc)
2018eb20f36SRui Paulo {
2028eb20f36SRui Paulo 	*pc = *pc - BREAKPOINT_INSTR_SZ;
2038eb20f36SRui Paulo }
2048eb20f36SRui Paulo 
2058eb20f36SRui Paulo /*
2068eb20f36SRui Paulo  * Step over the breakpoint.
2078eb20f36SRui Paulo  */
2088eb20f36SRui Paulo int
2098eb20f36SRui Paulo proc_bkptexec(struct proc_handle *phdl, unsigned long saved)
2108eb20f36SRui Paulo {
2118eb20f36SRui Paulo 	unsigned long pc;
2128eb20f36SRui Paulo 	unsigned long samesaved;
2138eb20f36SRui Paulo 	int status;
2148eb20f36SRui Paulo 
2158eb20f36SRui Paulo 	if (proc_regget(phdl, REG_PC, &pc) < 0) {
21630e81f7eSMark Johnston 		DPRINTFX("ERROR: couldn't get PC register");
2178eb20f36SRui Paulo 		return (-1);
2188eb20f36SRui Paulo 	}
2198eb20f36SRui Paulo 	proc_bkptregadj(&pc);
2208eb20f36SRui Paulo 	if (proc_bkptdel(phdl, pc, saved) < 0) {
22130e81f7eSMark Johnston 		DPRINTFX("ERROR: couldn't delete breakpoint");
2228eb20f36SRui Paulo 		return (-1);
2238eb20f36SRui Paulo 	}
2248eb20f36SRui Paulo 	/*
2258eb20f36SRui Paulo 	 * Go back in time and step over the new instruction just
2268eb20f36SRui Paulo 	 * set up by proc_bkptdel().
2278eb20f36SRui Paulo 	 */
2288eb20f36SRui Paulo 	proc_regset(phdl, REG_PC, pc);
2298eb20f36SRui Paulo 	if (ptrace(PT_STEP, proc_getpid(phdl), (caddr_t)1, 0) < 0) {
23030e81f7eSMark Johnston 		DPRINTFX("ERROR: ptrace step failed");
2318eb20f36SRui Paulo 		return (-1);
2328eb20f36SRui Paulo 	}
2334c74b245SRui Paulo 	proc_wstatus(phdl);
2344c74b245SRui Paulo 	status = proc_getwstat(phdl);
2358eb20f36SRui Paulo 	if (!WIFSTOPPED(status)) {
23630e81f7eSMark Johnston 		DPRINTFX("ERROR: don't know why process stopped");
2378eb20f36SRui Paulo 		return (-1);
2388eb20f36SRui Paulo 	}
2398eb20f36SRui Paulo 	/*
2408eb20f36SRui Paulo 	 * Restore the breakpoint. The saved instruction should be
2418eb20f36SRui Paulo 	 * the same as the one that we were passed in.
2428eb20f36SRui Paulo 	 */
2438eb20f36SRui Paulo 	if (proc_bkptset(phdl, pc, &samesaved) < 0) {
24430e81f7eSMark Johnston 		DPRINTFX("ERROR: couldn't restore breakpoint");
2458eb20f36SRui Paulo 		return (-1);
2468eb20f36SRui Paulo 	}
2478eb20f36SRui Paulo 	assert(samesaved == saved);
2488eb20f36SRui Paulo 
2498eb20f36SRui Paulo 	return (0);
2508eb20f36SRui Paulo }
251