18eb20f36SRui Paulo /* 28eb20f36SRui Paulo * Copyright (c) 2010 The FreeBSD Foundation 38eb20f36SRui Paulo * All rights reserved. 48eb20f36SRui Paulo * 58eb20f36SRui Paulo * This software was developed by Rui Paulo under sponsorship from the 68eb20f36SRui Paulo * FreeBSD Foundation. 78eb20f36SRui Paulo * 88eb20f36SRui Paulo * Redistribution and use in source and binary forms, with or without 98eb20f36SRui Paulo * modification, are permitted provided that the following conditions 108eb20f36SRui Paulo * are met: 118eb20f36SRui Paulo * 1. Redistributions of source code must retain the above copyright 128eb20f36SRui Paulo * notice, this list of conditions and the following disclaimer. 138eb20f36SRui Paulo * 2. Redistributions in binary form must reproduce the above copyright 148eb20f36SRui Paulo * notice, this list of conditions and the following disclaimer in the 158eb20f36SRui Paulo * documentation and/or other materials provided with the distribution. 168eb20f36SRui Paulo * 178eb20f36SRui Paulo * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 188eb20f36SRui Paulo * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 198eb20f36SRui Paulo * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 208eb20f36SRui Paulo * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 218eb20f36SRui Paulo * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 228eb20f36SRui Paulo * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 238eb20f36SRui Paulo * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 248eb20f36SRui Paulo * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 258eb20f36SRui Paulo * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 268eb20f36SRui Paulo * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 278eb20f36SRui Paulo * SUCH DAMAGE. 288eb20f36SRui Paulo */ 298eb20f36SRui Paulo 308eb20f36SRui Paulo #include <sys/cdefs.h> 318eb20f36SRui Paulo __FBSDID("$FreeBSD$"); 328eb20f36SRui Paulo 338eb20f36SRui Paulo #include <sys/types.h> 348eb20f36SRui Paulo #include <sys/ptrace.h> 358eb20f36SRui Paulo #include <sys/wait.h> 368eb20f36SRui Paulo #include <machine/_inttypes.h> 378eb20f36SRui Paulo 388eb20f36SRui Paulo #include <assert.h> 398eb20f36SRui Paulo #include <err.h> 408eb20f36SRui Paulo #include <errno.h> 41813b2694SMark Johnston #include <signal.h> 42813b2694SMark Johnston #include <stdio.h> 438eb20f36SRui Paulo #include "_libproc.h" 448eb20f36SRui Paulo 45*27e54fb5SRuslan Bukin #if defined(__aarch64__) 46*27e54fb5SRuslan Bukin #define AARCH64_BRK 0xd4200000 47*27e54fb5SRuslan Bukin #define AARCH64_BRK_IMM16_SHIFT 5 48*27e54fb5SRuslan Bukin #define AARCH64_BRK_IMM16_VAL (0xd << AARCH64_BRK_IMM16_SHIFT) 49*27e54fb5SRuslan Bukin #define BREAKPOINT_INSTR (AARCH64_BRK | AARCH64_BRK_IMM16_VAL) 50*27e54fb5SRuslan Bukin #define BREAKPOINT_INSTR_SZ 4 51*27e54fb5SRuslan Bukin #elif defined(__amd64__) || defined(__i386__) 528eb20f36SRui Paulo #define BREAKPOINT_INSTR 0xcc /* int 0x3 */ 538eb20f36SRui Paulo #define BREAKPOINT_INSTR_SZ 1 54*27e54fb5SRuslan Bukin #elif defined(__arm__) 55*27e54fb5SRuslan Bukin #define BREAKPOINT_INSTR 0xe7ffffff /* bkpt */ 56*27e54fb5SRuslan Bukin #define BREAKPOINT_INSTR_SZ 4 57f2242861SOleksandr Tymoshenko #elif defined(__mips__) 58f2242861SOleksandr Tymoshenko #define BREAKPOINT_INSTR 0xd /* break */ 59f2242861SOleksandr Tymoshenko #define BREAKPOINT_INSTR_SZ 4 60c7570492SJustin Hibbits #elif defined(__powerpc__) 61c7570492SJustin Hibbits #define BREAKPOINT_INSTR 0x7fe00008 /* trap */ 62c7570492SJustin Hibbits #define BREAKPOINT_INSTR_SZ 4 638eb20f36SRui Paulo #else 648eb20f36SRui Paulo #error "Add support for your architecture" 658eb20f36SRui Paulo #endif 668eb20f36SRui Paulo 67813b2694SMark Johnston static int 68813b2694SMark Johnston proc_stop(struct proc_handle *phdl) 69813b2694SMark Johnston { 70813b2694SMark Johnston int status; 71813b2694SMark Johnston 72813b2694SMark Johnston if (kill(proc_getpid(phdl), SIGSTOP) == -1) { 73813b2694SMark Johnston DPRINTF("kill %d", proc_getpid(phdl)); 74813b2694SMark Johnston return (-1); 75813b2694SMark Johnston } else if (waitpid(proc_getpid(phdl), &status, WSTOPPED) == -1) { 76813b2694SMark Johnston DPRINTF("waitpid %d", proc_getpid(phdl)); 77813b2694SMark Johnston return (-1); 78813b2694SMark Johnston } else if (!WIFSTOPPED(status)) { 79813b2694SMark Johnston DPRINTFX("waitpid: unexpected status 0x%x", status); 80813b2694SMark Johnston return (-1); 81813b2694SMark Johnston } 82813b2694SMark Johnston 83813b2694SMark Johnston return (0); 84813b2694SMark Johnston } 85813b2694SMark Johnston 868eb20f36SRui Paulo int 878eb20f36SRui Paulo proc_bkptset(struct proc_handle *phdl, uintptr_t address, 888eb20f36SRui Paulo unsigned long *saved) 898eb20f36SRui Paulo { 908eb20f36SRui Paulo struct ptrace_io_desc piod; 918eb20f36SRui Paulo unsigned long paddr, caddr; 9292f92525SMark Johnston int ret = 0, stopped; 938eb20f36SRui Paulo 948eb20f36SRui Paulo *saved = 0; 958eb20f36SRui Paulo if (phdl->status == PS_DEAD || phdl->status == PS_UNDEAD || 968eb20f36SRui Paulo phdl->status == PS_IDLE) { 978eb20f36SRui Paulo errno = ENOENT; 988eb20f36SRui Paulo return (-1); 998eb20f36SRui Paulo } 1008eb20f36SRui Paulo 101813b2694SMark Johnston DPRINTFX("adding breakpoint at 0x%lx", address); 102813b2694SMark Johnston 10392f92525SMark Johnston stopped = 0; 10492f92525SMark Johnston if (phdl->status != PS_STOP) { 105813b2694SMark Johnston if (proc_stop(phdl) != 0) 106813b2694SMark Johnston return (-1); 10792f92525SMark Johnston stopped = 1; 10892f92525SMark Johnston } 109813b2694SMark Johnston 1108eb20f36SRui Paulo /* 1118eb20f36SRui Paulo * Read the original instruction. 1128eb20f36SRui Paulo */ 1138eb20f36SRui Paulo caddr = address; 1148eb20f36SRui Paulo paddr = 0; 1158eb20f36SRui Paulo piod.piod_op = PIOD_READ_I; 1168eb20f36SRui Paulo piod.piod_offs = (void *)caddr; 1178eb20f36SRui Paulo piod.piod_addr = &paddr; 1188eb20f36SRui Paulo piod.piod_len = BREAKPOINT_INSTR_SZ; 1198eb20f36SRui Paulo if (ptrace(PT_IO, proc_getpid(phdl), (caddr_t)&piod, 0) < 0) { 12030e81f7eSMark Johnston DPRINTF("ERROR: couldn't read instruction at address 0x%" 12130e81f7eSMark Johnston PRIuPTR, address); 122813b2694SMark Johnston ret = -1; 123813b2694SMark Johnston goto done; 1248eb20f36SRui Paulo } 1258eb20f36SRui Paulo *saved = paddr; 1268eb20f36SRui Paulo /* 1278eb20f36SRui Paulo * Write a breakpoint instruction to that address. 1288eb20f36SRui Paulo */ 1298eb20f36SRui Paulo caddr = address; 1308eb20f36SRui Paulo paddr = BREAKPOINT_INSTR; 1318eb20f36SRui Paulo piod.piod_op = PIOD_WRITE_I; 1328eb20f36SRui Paulo piod.piod_offs = (void *)caddr; 1338eb20f36SRui Paulo piod.piod_addr = &paddr; 1348eb20f36SRui Paulo piod.piod_len = BREAKPOINT_INSTR_SZ; 1358eb20f36SRui Paulo if (ptrace(PT_IO, proc_getpid(phdl), (caddr_t)&piod, 0) < 0) { 13630e81f7eSMark Johnston DPRINTF("ERROR: couldn't write instruction at address 0x%" 13730e81f7eSMark Johnston PRIuPTR, address); 138813b2694SMark Johnston ret = -1; 139813b2694SMark Johnston goto done; 1408eb20f36SRui Paulo } 1418eb20f36SRui Paulo 142813b2694SMark Johnston done: 14392f92525SMark Johnston if (stopped) 144813b2694SMark Johnston /* Restart the process if we had to stop it. */ 14592f92525SMark Johnston proc_continue(phdl); 146813b2694SMark Johnston 147813b2694SMark Johnston return (ret); 1488eb20f36SRui Paulo } 1498eb20f36SRui Paulo 1508eb20f36SRui Paulo int 1518eb20f36SRui Paulo proc_bkptdel(struct proc_handle *phdl, uintptr_t address, 1528eb20f36SRui Paulo unsigned long saved) 1538eb20f36SRui Paulo { 1548eb20f36SRui Paulo struct ptrace_io_desc piod; 1558eb20f36SRui Paulo unsigned long paddr, caddr; 15692f92525SMark Johnston int ret = 0, stopped; 1578eb20f36SRui Paulo 1588eb20f36SRui Paulo if (phdl->status == PS_DEAD || phdl->status == PS_UNDEAD || 1598eb20f36SRui Paulo phdl->status == PS_IDLE) { 1608eb20f36SRui Paulo errno = ENOENT; 1618eb20f36SRui Paulo return (-1); 1628eb20f36SRui Paulo } 163813b2694SMark Johnston 164813b2694SMark Johnston DPRINTFX("removing breakpoint at 0x%lx", address); 165813b2694SMark Johnston 16692f92525SMark Johnston stopped = 0; 16792f92525SMark Johnston if (phdl->status != PS_STOP) { 168813b2694SMark Johnston if (proc_stop(phdl) != 0) 169813b2694SMark Johnston return (-1); 17092f92525SMark Johnston stopped = 1; 17192f92525SMark Johnston } 172813b2694SMark Johnston 1738eb20f36SRui Paulo /* 1748eb20f36SRui Paulo * Overwrite the breakpoint instruction that we setup previously. 1758eb20f36SRui Paulo */ 1768eb20f36SRui Paulo caddr = address; 1778eb20f36SRui Paulo paddr = saved; 1788eb20f36SRui Paulo piod.piod_op = PIOD_WRITE_I; 1798eb20f36SRui Paulo piod.piod_offs = (void *)caddr; 1808eb20f36SRui Paulo piod.piod_addr = &paddr; 1818eb20f36SRui Paulo piod.piod_len = BREAKPOINT_INSTR_SZ; 1828eb20f36SRui Paulo if (ptrace(PT_IO, proc_getpid(phdl), (caddr_t)&piod, 0) < 0) { 18330e81f7eSMark Johnston DPRINTF("ERROR: couldn't write instruction at address 0x%" 18430e81f7eSMark Johnston PRIuPTR, address); 185813b2694SMark Johnston ret = -1; 1868eb20f36SRui Paulo } 1878eb20f36SRui Paulo 18892f92525SMark Johnston if (stopped) 189813b2694SMark Johnston /* Restart the process if we had to stop it. */ 19092f92525SMark Johnston proc_continue(phdl); 191813b2694SMark Johnston 192813b2694SMark Johnston return (ret); 1938eb20f36SRui Paulo } 1948eb20f36SRui Paulo 1958eb20f36SRui Paulo /* 1968eb20f36SRui Paulo * Decrement pc so that we delete the breakpoint at the correct 1978eb20f36SRui Paulo * address, i.e. at the BREAKPOINT_INSTR address. 1988eb20f36SRui Paulo */ 1998eb20f36SRui Paulo void 2008eb20f36SRui Paulo proc_bkptregadj(unsigned long *pc) 2018eb20f36SRui Paulo { 2028eb20f36SRui Paulo *pc = *pc - BREAKPOINT_INSTR_SZ; 2038eb20f36SRui Paulo } 2048eb20f36SRui Paulo 2058eb20f36SRui Paulo /* 2068eb20f36SRui Paulo * Step over the breakpoint. 2078eb20f36SRui Paulo */ 2088eb20f36SRui Paulo int 2098eb20f36SRui Paulo proc_bkptexec(struct proc_handle *phdl, unsigned long saved) 2108eb20f36SRui Paulo { 2118eb20f36SRui Paulo unsigned long pc; 2128eb20f36SRui Paulo unsigned long samesaved; 2138eb20f36SRui Paulo int status; 2148eb20f36SRui Paulo 2158eb20f36SRui Paulo if (proc_regget(phdl, REG_PC, &pc) < 0) { 21630e81f7eSMark Johnston DPRINTFX("ERROR: couldn't get PC register"); 2178eb20f36SRui Paulo return (-1); 2188eb20f36SRui Paulo } 2198eb20f36SRui Paulo proc_bkptregadj(&pc); 2208eb20f36SRui Paulo if (proc_bkptdel(phdl, pc, saved) < 0) { 22130e81f7eSMark Johnston DPRINTFX("ERROR: couldn't delete breakpoint"); 2228eb20f36SRui Paulo return (-1); 2238eb20f36SRui Paulo } 2248eb20f36SRui Paulo /* 2258eb20f36SRui Paulo * Go back in time and step over the new instruction just 2268eb20f36SRui Paulo * set up by proc_bkptdel(). 2278eb20f36SRui Paulo */ 2288eb20f36SRui Paulo proc_regset(phdl, REG_PC, pc); 2298eb20f36SRui Paulo if (ptrace(PT_STEP, proc_getpid(phdl), (caddr_t)1, 0) < 0) { 23030e81f7eSMark Johnston DPRINTFX("ERROR: ptrace step failed"); 2318eb20f36SRui Paulo return (-1); 2328eb20f36SRui Paulo } 2334c74b245SRui Paulo proc_wstatus(phdl); 2344c74b245SRui Paulo status = proc_getwstat(phdl); 2358eb20f36SRui Paulo if (!WIFSTOPPED(status)) { 23630e81f7eSMark Johnston DPRINTFX("ERROR: don't know why process stopped"); 2378eb20f36SRui Paulo return (-1); 2388eb20f36SRui Paulo } 2398eb20f36SRui Paulo /* 2408eb20f36SRui Paulo * Restore the breakpoint. The saved instruction should be 2418eb20f36SRui Paulo * the same as the one that we were passed in. 2428eb20f36SRui Paulo */ 2438eb20f36SRui Paulo if (proc_bkptset(phdl, pc, &samesaved) < 0) { 24430e81f7eSMark Johnston DPRINTFX("ERROR: couldn't restore breakpoint"); 2458eb20f36SRui Paulo return (-1); 2468eb20f36SRui Paulo } 2478eb20f36SRui Paulo assert(samesaved == saved); 2488eb20f36SRui Paulo 2498eb20f36SRui Paulo return (0); 2508eb20f36SRui Paulo } 251