14e68ceabSDavid Greenman /* 24e68ceabSDavid Greenman * Copyright (c) 1994, Sean Eric Fagan 34e68ceabSDavid Greenman * All rights reserved. 4df8bae1dSRodney W. Grimes * 5df8bae1dSRodney W. Grimes * Redistribution and use in source and binary forms, with or without 6df8bae1dSRodney W. Grimes * modification, are permitted provided that the following conditions 7df8bae1dSRodney W. Grimes * are met: 8df8bae1dSRodney W. Grimes * 1. Redistributions of source code must retain the above copyright 9df8bae1dSRodney W. Grimes * notice, this list of conditions and the following disclaimer. 10df8bae1dSRodney W. Grimes * 2. Redistributions in binary form must reproduce the above copyright 11df8bae1dSRodney W. Grimes * notice, this list of conditions and the following disclaimer in the 12df8bae1dSRodney W. Grimes * documentation and/or other materials provided with the distribution. 13df8bae1dSRodney W. Grimes * 3. All advertising materials mentioning features or use of this software 14df8bae1dSRodney W. Grimes * must display the following acknowledgement: 154e68ceabSDavid Greenman * This product includes software developed by Sean Eric Fagan. 164e68ceabSDavid Greenman * 4. The name of the author may not be used to endorse or promote products 174e68ceabSDavid Greenman * derived from this software without specific prior written permission. 18df8bae1dSRodney W. Grimes * 194e68ceabSDavid Greenman * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 20df8bae1dSRodney W. Grimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21df8bae1dSRodney W. Grimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 224e68ceabSDavid Greenman * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 23df8bae1dSRodney W. Grimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24df8bae1dSRodney W. Grimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25df8bae1dSRodney W. Grimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26df8bae1dSRodney W. Grimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27df8bae1dSRodney W. Grimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28df8bae1dSRodney W. Grimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29df8bae1dSRodney W. Grimes * SUCH DAMAGE. 30df8bae1dSRodney W. Grimes * 31c3aac50fSPeter Wemm * $FreeBSD$ 32df8bae1dSRodney W. Grimes */ 33df8bae1dSRodney W. Grimes 34df8bae1dSRodney W. Grimes #include <sys/param.h> 35f23b4c91SGarrett Wollman #include <sys/systm.h> 36fb919e4dSMark Murray #include <sys/lock.h> 37fb919e4dSMark Murray #include <sys/mutex.h> 38d2d3e875SBruce Evans #include <sys/sysproto.h> 39df8bae1dSRodney W. Grimes #include <sys/proc.h> 404e68ceabSDavid Greenman #include <sys/vnode.h> 414e68ceabSDavid Greenman #include <sys/ptrace.h> 421005a129SJohn Baldwin #include <sys/sx.h> 43fb919e4dSMark Murray #include <sys/user.h> 44df8bae1dSRodney W. Grimes 454e68ceabSDavid Greenman #include <machine/reg.h> 46fb919e4dSMark Murray 474e68ceabSDavid Greenman #include <vm/vm.h> 48efeaf95aSDavid Greenman #include <vm/pmap.h> 493da32491SDag-Erling Smørgrav #include <vm/vm_extern.h> 50efeaf95aSDavid Greenman #include <vm/vm_map.h> 513da32491SDag-Erling Smørgrav #include <vm/vm_kern.h> 523da32491SDag-Erling Smørgrav #include <vm/vm_object.h> 534e68ceabSDavid Greenman #include <vm/vm_page.h> 544e68ceabSDavid Greenman 554b1aa58bSBruce Evans /* 564b1aa58bSBruce Evans * Functions implemented using PROC_ACTION(): 574b1aa58bSBruce Evans * 584b1aa58bSBruce Evans * proc_read_regs(proc, regs) 594b1aa58bSBruce Evans * Get the current user-visible register set from the process 604b1aa58bSBruce Evans * and copy it into the regs structure (<machine/reg.h>). 614b1aa58bSBruce Evans * The process is stopped at the time read_regs is called. 624b1aa58bSBruce Evans * 634b1aa58bSBruce Evans * proc_write_regs(proc, regs) 644b1aa58bSBruce Evans * Update the current register set from the passed in regs 654b1aa58bSBruce Evans * structure. Take care to avoid clobbering special CPU 664b1aa58bSBruce Evans * registers or privileged bits in the PSL. 674b1aa58bSBruce Evans * Depending on the architecture this may have fix-up work to do, 684b1aa58bSBruce Evans * especially if the IAR or PCW are modified. 694b1aa58bSBruce Evans * The process is stopped at the time write_regs is called. 704b1aa58bSBruce Evans * 714b1aa58bSBruce Evans * proc_read_fpregs, proc_write_fpregs 724b1aa58bSBruce Evans * deal with the floating point register set, otherwise as above. 734b1aa58bSBruce Evans * 744b1aa58bSBruce Evans * proc_read_dbregs, proc_write_dbregs 754b1aa58bSBruce Evans * deal with the processor debug register set, otherwise as above. 764b1aa58bSBruce Evans * 774b1aa58bSBruce Evans * proc_sstep(proc) 784b1aa58bSBruce Evans * Arrange for the process to trap after executing a single instruction. 794b1aa58bSBruce Evans */ 804b1aa58bSBruce Evans 814b1aa58bSBruce Evans #define PROC_ACTION(action) do { \ 827c629906SDag-Erling Smørgrav int error; \ 837c629906SDag-Erling Smørgrav \ 847c629906SDag-Erling Smørgrav mtx_lock_spin(&sched_lock); \ 854b1aa58bSBruce Evans if ((td->td_proc->p_sflag & PS_INMEM) == 0) \ 864b1aa58bSBruce Evans error = EIO; \ 874b1aa58bSBruce Evans else \ 884b1aa58bSBruce Evans error = (action); \ 897c629906SDag-Erling Smørgrav mtx_unlock_spin(&sched_lock); \ 907c629906SDag-Erling Smørgrav return (error); \ 914b1aa58bSBruce Evans } while(0) 924b1aa58bSBruce Evans 934b1aa58bSBruce Evans int 944b1aa58bSBruce Evans proc_read_regs(struct thread *td, struct reg *regs) 954b1aa58bSBruce Evans { 964b1aa58bSBruce Evans 974b1aa58bSBruce Evans PROC_ACTION(fill_regs(td, regs)); 987c629906SDag-Erling Smørgrav } 997c629906SDag-Erling Smørgrav 1004b1aa58bSBruce Evans int 1014b1aa58bSBruce Evans proc_write_regs(struct thread *td, struct reg *regs) 1024b1aa58bSBruce Evans { 1034b1aa58bSBruce Evans 1044b1aa58bSBruce Evans PROC_ACTION(set_regs(td, regs)); 1054b1aa58bSBruce Evans } 1064b1aa58bSBruce Evans 1074b1aa58bSBruce Evans int 1084b1aa58bSBruce Evans proc_read_dbregs(struct thread *td, struct dbreg *dbregs) 1094b1aa58bSBruce Evans { 1104b1aa58bSBruce Evans 1114b1aa58bSBruce Evans PROC_ACTION(fill_dbregs(td, dbregs)); 1124b1aa58bSBruce Evans } 1134b1aa58bSBruce Evans 1144b1aa58bSBruce Evans int 1154b1aa58bSBruce Evans proc_write_dbregs(struct thread *td, struct dbreg *dbregs) 1164b1aa58bSBruce Evans { 1174b1aa58bSBruce Evans 1184b1aa58bSBruce Evans PROC_ACTION(set_dbregs(td, dbregs)); 1194b1aa58bSBruce Evans } 1204b1aa58bSBruce Evans 1214b1aa58bSBruce Evans /* 1224b1aa58bSBruce Evans * Ptrace doesn't support fpregs at all, and there are no security holes 1234b1aa58bSBruce Evans * or translations for fpregs, so we can just copy them. 1244b1aa58bSBruce Evans */ 1254b1aa58bSBruce Evans int 1264b1aa58bSBruce Evans proc_read_fpregs(struct thread *td, struct fpreg *fpregs) 1274b1aa58bSBruce Evans { 1284b1aa58bSBruce Evans 1294b1aa58bSBruce Evans PROC_ACTION(fill_fpregs(td, fpregs)); 1304b1aa58bSBruce Evans } 1314b1aa58bSBruce Evans 1324b1aa58bSBruce Evans int 1334b1aa58bSBruce Evans proc_write_fpregs(struct thread *td, struct fpreg *fpregs) 1344b1aa58bSBruce Evans { 1354b1aa58bSBruce Evans 1364b1aa58bSBruce Evans PROC_ACTION(set_fpregs(td, fpregs)); 1374b1aa58bSBruce Evans } 1387c629906SDag-Erling Smørgrav 1397c629906SDag-Erling Smørgrav int 1407c629906SDag-Erling Smørgrav proc_sstep(struct thread *td) 1417c629906SDag-Erling Smørgrav { 1427c629906SDag-Erling Smørgrav 1434b1aa58bSBruce Evans PROC_ACTION(ptrace_single_step(td)); 1447c629906SDag-Erling Smørgrav } 1457c629906SDag-Erling Smørgrav 1463da32491SDag-Erling Smørgrav int 1473da32491SDag-Erling Smørgrav proc_rwmem(struct proc *p, struct uio *uio) 14850f74e92SDag-Erling Smørgrav { 1493da32491SDag-Erling Smørgrav struct vmspace *vm; 1503da32491SDag-Erling Smørgrav vm_map_t map; 1513da32491SDag-Erling Smørgrav vm_object_t object = NULL; 1523da32491SDag-Erling Smørgrav vm_offset_t pageno = 0; /* page number */ 1533da32491SDag-Erling Smørgrav vm_prot_t reqprot; 1543da32491SDag-Erling Smørgrav vm_offset_t kva; 15519610b66SBruce Evans int error, writing; 1564e68ceabSDavid Greenman 1573da32491SDag-Erling Smørgrav GIANT_REQUIRED; 1584e68ceabSDavid Greenman 1594e68ceabSDavid Greenman /* 1603da32491SDag-Erling Smørgrav * if the vmspace is in the midst of being deallocated or the 1613da32491SDag-Erling Smørgrav * process is exiting, don't try to grab anything. The page table 1623da32491SDag-Erling Smørgrav * usage in that process can be messed up. 1634e68ceabSDavid Greenman */ 1643da32491SDag-Erling Smørgrav vm = p->p_vmspace; 1653da32491SDag-Erling Smørgrav if ((p->p_flag & P_WEXIT)) 166c5799337SDag-Erling Smørgrav return (EFAULT); 1673da32491SDag-Erling Smørgrav if (vm->vm_refcnt < 1) 1683da32491SDag-Erling Smørgrav return (EFAULT); 1693da32491SDag-Erling Smørgrav ++vm->vm_refcnt; 1703da32491SDag-Erling Smørgrav /* 1713da32491SDag-Erling Smørgrav * The map we want... 1723da32491SDag-Erling Smørgrav */ 1733da32491SDag-Erling Smørgrav map = &vm->vm_map; 1744e68ceabSDavid Greenman 1753da32491SDag-Erling Smørgrav writing = uio->uio_rw == UIO_WRITE; 1763da32491SDag-Erling Smørgrav reqprot = writing ? (VM_PROT_WRITE | VM_PROT_OVERRIDE_WRITE) : 1773da32491SDag-Erling Smørgrav VM_PROT_READ; 1783da32491SDag-Erling Smørgrav 1793da32491SDag-Erling Smørgrav kva = kmem_alloc_pageable(kernel_map, PAGE_SIZE); 1803da32491SDag-Erling Smørgrav 1813da32491SDag-Erling Smørgrav /* 1823da32491SDag-Erling Smørgrav * Only map in one page at a time. We don't have to, but it 1833da32491SDag-Erling Smørgrav * makes things easier. This way is trivial - right? 1843da32491SDag-Erling Smørgrav */ 1853da32491SDag-Erling Smørgrav do { 1863da32491SDag-Erling Smørgrav vm_map_t tmap; 1873da32491SDag-Erling Smørgrav vm_offset_t uva; 1883da32491SDag-Erling Smørgrav int page_offset; /* offset into page */ 1893da32491SDag-Erling Smørgrav vm_map_entry_t out_entry; 1903da32491SDag-Erling Smørgrav vm_prot_t out_prot; 1913da32491SDag-Erling Smørgrav boolean_t wired; 1923da32491SDag-Erling Smørgrav vm_pindex_t pindex; 1933da32491SDag-Erling Smørgrav u_int len; 1943da32491SDag-Erling Smørgrav vm_page_t m; 1953da32491SDag-Erling Smørgrav 1963da32491SDag-Erling Smørgrav object = NULL; 1973da32491SDag-Erling Smørgrav 1983da32491SDag-Erling Smørgrav uva = (vm_offset_t)uio->uio_offset; 1993da32491SDag-Erling Smørgrav 2003da32491SDag-Erling Smørgrav /* 2013da32491SDag-Erling Smørgrav * Get the page number of this segment. 2023da32491SDag-Erling Smørgrav */ 2033da32491SDag-Erling Smørgrav pageno = trunc_page(uva); 2043da32491SDag-Erling Smørgrav page_offset = uva - pageno; 2053da32491SDag-Erling Smørgrav 2063da32491SDag-Erling Smørgrav /* 2073da32491SDag-Erling Smørgrav * How many bytes to copy 2083da32491SDag-Erling Smørgrav */ 2093da32491SDag-Erling Smørgrav len = min(PAGE_SIZE - page_offset, uio->uio_resid); 2103da32491SDag-Erling Smørgrav 2113da32491SDag-Erling Smørgrav /* 2123da32491SDag-Erling Smørgrav * Fault the page on behalf of the process 2133da32491SDag-Erling Smørgrav */ 2143da32491SDag-Erling Smørgrav error = vm_fault(map, pageno, reqprot, VM_FAULT_NORMAL); 2153da32491SDag-Erling Smørgrav if (error) { 2163da32491SDag-Erling Smørgrav error = EFAULT; 2173da32491SDag-Erling Smørgrav break; 2183da32491SDag-Erling Smørgrav } 2193da32491SDag-Erling Smørgrav 2203da32491SDag-Erling Smørgrav /* 2213da32491SDag-Erling Smørgrav * Now we need to get the page. out_entry, out_prot, wired, 2223da32491SDag-Erling Smørgrav * and single_use aren't used. One would think the vm code 2233da32491SDag-Erling Smørgrav * would be a *bit* nicer... We use tmap because 2243da32491SDag-Erling Smørgrav * vm_map_lookup() can change the map argument. 2253da32491SDag-Erling Smørgrav */ 2263da32491SDag-Erling Smørgrav tmap = map; 2273da32491SDag-Erling Smørgrav error = vm_map_lookup(&tmap, pageno, reqprot, &out_entry, 2283da32491SDag-Erling Smørgrav &object, &pindex, &out_prot, &wired); 2293da32491SDag-Erling Smørgrav 2303da32491SDag-Erling Smørgrav if (error) { 2313da32491SDag-Erling Smørgrav error = EFAULT; 2323da32491SDag-Erling Smørgrav 2333da32491SDag-Erling Smørgrav /* 2343da32491SDag-Erling Smørgrav * Make sure that there is no residue in 'object' from 2353da32491SDag-Erling Smørgrav * an error return on vm_map_lookup. 2363da32491SDag-Erling Smørgrav */ 2373da32491SDag-Erling Smørgrav object = NULL; 2383da32491SDag-Erling Smørgrav 2393da32491SDag-Erling Smørgrav break; 2403da32491SDag-Erling Smørgrav } 2413da32491SDag-Erling Smørgrav 2423da32491SDag-Erling Smørgrav m = vm_page_lookup(object, pindex); 2433da32491SDag-Erling Smørgrav 2443da32491SDag-Erling Smørgrav /* Allow fallback to backing objects if we are reading */ 2453da32491SDag-Erling Smørgrav 2463da32491SDag-Erling Smørgrav while (m == NULL && !writing && object->backing_object) { 2473da32491SDag-Erling Smørgrav 2483da32491SDag-Erling Smørgrav pindex += OFF_TO_IDX(object->backing_object_offset); 2493da32491SDag-Erling Smørgrav object = object->backing_object; 2503da32491SDag-Erling Smørgrav 2513da32491SDag-Erling Smørgrav m = vm_page_lookup(object, pindex); 2523da32491SDag-Erling Smørgrav } 2533da32491SDag-Erling Smørgrav 2543da32491SDag-Erling Smørgrav if (m == NULL) { 2553da32491SDag-Erling Smørgrav error = EFAULT; 2563da32491SDag-Erling Smørgrav 2573da32491SDag-Erling Smørgrav /* 2583da32491SDag-Erling Smørgrav * Make sure that there is no residue in 'object' from 2593da32491SDag-Erling Smørgrav * an error return on vm_map_lookup. 2603da32491SDag-Erling Smørgrav */ 2613da32491SDag-Erling Smørgrav object = NULL; 2623da32491SDag-Erling Smørgrav 2633da32491SDag-Erling Smørgrav vm_map_lookup_done(tmap, out_entry); 2643da32491SDag-Erling Smørgrav 2653da32491SDag-Erling Smørgrav break; 2663da32491SDag-Erling Smørgrav } 2673da32491SDag-Erling Smørgrav 2683da32491SDag-Erling Smørgrav /* 2693da32491SDag-Erling Smørgrav * Wire the page into memory 2703da32491SDag-Erling Smørgrav */ 2713da32491SDag-Erling Smørgrav vm_page_wire(m); 2723da32491SDag-Erling Smørgrav 2733da32491SDag-Erling Smørgrav /* 2743da32491SDag-Erling Smørgrav * We're done with tmap now. 2753da32491SDag-Erling Smørgrav * But reference the object first, so that we won't loose 2763da32491SDag-Erling Smørgrav * it. 2773da32491SDag-Erling Smørgrav */ 2784e68ceabSDavid Greenman vm_object_reference(object); 2793da32491SDag-Erling Smørgrav vm_map_lookup_done(tmap, out_entry); 2804e68ceabSDavid Greenman 281ac59490bSJake Burkholder pmap_qenter(kva, &m, 1); 2824e68ceabSDavid Greenman 2833da32491SDag-Erling Smørgrav /* 2843da32491SDag-Erling Smørgrav * Now do the i/o move. 2853da32491SDag-Erling Smørgrav */ 2863da32491SDag-Erling Smørgrav error = uiomove((caddr_t)(kva + page_offset), len, uio); 2873da32491SDag-Erling Smørgrav 288ac59490bSJake Burkholder pmap_qremove(kva, 1); 2893da32491SDag-Erling Smørgrav 2903da32491SDag-Erling Smørgrav /* 2913da32491SDag-Erling Smørgrav * release the page and the object 2923da32491SDag-Erling Smørgrav */ 2933da32491SDag-Erling Smørgrav vm_page_unwire(m, 1); 2943da32491SDag-Erling Smørgrav vm_object_deallocate(object); 2953da32491SDag-Erling Smørgrav 2963da32491SDag-Erling Smørgrav object = NULL; 2973da32491SDag-Erling Smørgrav 2983da32491SDag-Erling Smørgrav } while (error == 0 && uio->uio_resid > 0); 2993da32491SDag-Erling Smørgrav 3003da32491SDag-Erling Smørgrav if (object) 3013da32491SDag-Erling Smørgrav vm_object_deallocate(object); 3023da32491SDag-Erling Smørgrav 3033da32491SDag-Erling Smørgrav kmem_free(kernel_map, kva, PAGE_SIZE); 3043da32491SDag-Erling Smørgrav vmspace_free(vm); 3053da32491SDag-Erling Smørgrav return (error); 3064e68ceabSDavid Greenman } 3074e68ceabSDavid Greenman 308df8bae1dSRodney W. Grimes /* 309df8bae1dSRodney W. Grimes * Process debugging system call. 310df8bae1dSRodney W. Grimes */ 311d2d3e875SBruce Evans #ifndef _SYS_SYSPROTO_H_ 312df8bae1dSRodney W. Grimes struct ptrace_args { 313df8bae1dSRodney W. Grimes int req; 314df8bae1dSRodney W. Grimes pid_t pid; 315df8bae1dSRodney W. Grimes caddr_t addr; 316df8bae1dSRodney W. Grimes int data; 317df8bae1dSRodney W. Grimes }; 318d2d3e875SBruce Evans #endif 319df8bae1dSRodney W. Grimes 3204e68ceabSDavid Greenman int 3213da32491SDag-Erling Smørgrav ptrace(struct thread *td, struct ptrace_args *uap) 3224e68ceabSDavid Greenman { 323b0281cefSPeter Wemm struct iovec iov; 324b0281cefSPeter Wemm struct uio uio; 32519610b66SBruce Evans /* 32619610b66SBruce Evans * XXX this obfuscation is to reduce stack usage, but the register 32719610b66SBruce Evans * structs may be too large to put on the stack anyway. 32819610b66SBruce Evans */ 3293da32491SDag-Erling Smørgrav union { 3308bc814e6SDag-Erling Smørgrav struct ptrace_io_desc piod; 3313da32491SDag-Erling Smørgrav struct dbreg dbreg; 3323da32491SDag-Erling Smørgrav struct fpreg fpreg; 33319610b66SBruce Evans struct reg reg; 3343da32491SDag-Erling Smørgrav } r; 3356871a6c8SJohn Baldwin struct proc *p; 33619610b66SBruce Evans struct thread *td2; 33719610b66SBruce Evans int error, write; 3386871a6c8SJohn Baldwin int proctree_locked = 0; 3394e68ceabSDavid Greenman 3406871a6c8SJohn Baldwin /* 3416871a6c8SJohn Baldwin * Do copyin() early before getting locks and lock proctree before 3426871a6c8SJohn Baldwin * locking the process. 3436871a6c8SJohn Baldwin */ 3446871a6c8SJohn Baldwin switch (uap->req) { 3456871a6c8SJohn Baldwin case PT_TRACE_ME: 3466871a6c8SJohn Baldwin case PT_ATTACH: 3476871a6c8SJohn Baldwin case PT_STEP: 3486871a6c8SJohn Baldwin case PT_CONTINUE: 3496871a6c8SJohn Baldwin case PT_DETACH: 3506871a6c8SJohn Baldwin sx_xlock(&proctree_lock); 3516871a6c8SJohn Baldwin proctree_locked = 1; 3526871a6c8SJohn Baldwin break; 3536871a6c8SJohn Baldwin #ifdef PT_SETREGS 3546871a6c8SJohn Baldwin case PT_SETREGS: 3556871a6c8SJohn Baldwin error = copyin(uap->addr, &r.reg, sizeof r.reg); 3566871a6c8SJohn Baldwin if (error) 3576871a6c8SJohn Baldwin return (error); 3586871a6c8SJohn Baldwin break; 3596871a6c8SJohn Baldwin #endif /* PT_SETREGS */ 3606871a6c8SJohn Baldwin #ifdef PT_SETFPREGS 3616871a6c8SJohn Baldwin case PT_SETFPREGS: 3626871a6c8SJohn Baldwin error = copyin(uap->addr, &r.fpreg, sizeof r.fpreg); 3636871a6c8SJohn Baldwin if (error) 3646871a6c8SJohn Baldwin return (error); 3656871a6c8SJohn Baldwin break; 3666871a6c8SJohn Baldwin #endif /* PT_SETFPREGS */ 3676871a6c8SJohn Baldwin #ifdef PT_SETDBREGS 3686871a6c8SJohn Baldwin case PT_SETDBREGS: 3696871a6c8SJohn Baldwin error = copyin(uap->addr, &r.dbreg, sizeof r.dbreg); 3706871a6c8SJohn Baldwin if (error) 3716871a6c8SJohn Baldwin return (error); 3726871a6c8SJohn Baldwin break; 3736871a6c8SJohn Baldwin #endif /* PT_SETDBREGS */ 3746871a6c8SJohn Baldwin default: 3756871a6c8SJohn Baldwin } 3766871a6c8SJohn Baldwin 3777a0dde68SPeter Wemm write = 0; 37833a9ed9dSJohn Baldwin if (uap->req == PT_TRACE_ME) { 3796871a6c8SJohn Baldwin p = td->td_proc; 38033a9ed9dSJohn Baldwin PROC_LOCK(p); 38133a9ed9dSJohn Baldwin } else { 3826871a6c8SJohn Baldwin if ((p = pfind(uap->pid)) == NULL) { 3836871a6c8SJohn Baldwin if (proctree_locked) 3846871a6c8SJohn Baldwin sx_xunlock(&proctree_lock); 385c5799337SDag-Erling Smørgrav return (ESRCH); 3864e68ceabSDavid Greenman } 38733a9ed9dSJohn Baldwin } 3886871a6c8SJohn Baldwin if (p_cansee(td->td_proc, p)) { 3896871a6c8SJohn Baldwin error = ESRCH; 3906871a6c8SJohn Baldwin goto fail; 3913da32491SDag-Erling Smørgrav } 3923da32491SDag-Erling Smørgrav 3936871a6c8SJohn Baldwin if ((error = p_candebug(td->td_proc, p)) != 0) 3946871a6c8SJohn Baldwin goto fail; 3956871a6c8SJohn Baldwin 3963da32491SDag-Erling Smørgrav /* 39719610b66SBruce Evans * System processes can't be debugged. 3983da32491SDag-Erling Smørgrav */ 3993da32491SDag-Erling Smørgrav if ((p->p_flag & P_SYSTEM) != 0) { 4006871a6c8SJohn Baldwin error = EINVAL; 4016871a6c8SJohn Baldwin goto fail; 4023da32491SDag-Erling Smørgrav } 4033da32491SDag-Erling Smørgrav 404b0281cefSPeter Wemm /* 405b0281cefSPeter Wemm * Permissions check 406b0281cefSPeter Wemm */ 407b0281cefSPeter Wemm switch (uap->req) { 408b0281cefSPeter Wemm case PT_TRACE_ME: 409b0281cefSPeter Wemm /* Always legal. */ 410b0281cefSPeter Wemm break; 4114e68ceabSDavid Greenman 412b0281cefSPeter Wemm case PT_ATTACH: 413b0281cefSPeter Wemm /* Self */ 4146871a6c8SJohn Baldwin if (p->p_pid == td->td_proc->p_pid) { 4156871a6c8SJohn Baldwin error = EINVAL; 4166871a6c8SJohn Baldwin goto fail; 41733a9ed9dSJohn Baldwin } 418b0281cefSPeter Wemm 419b0281cefSPeter Wemm /* Already traced */ 420731a1aeaSJohn Baldwin if (p->p_flag & P_TRACED) { 4216871a6c8SJohn Baldwin error = EBUSY; 4226871a6c8SJohn Baldwin goto fail; 423731a1aeaSJohn Baldwin } 424b0281cefSPeter Wemm 425b0281cefSPeter Wemm /* OK */ 426b0281cefSPeter Wemm break; 427b0281cefSPeter Wemm 428b0281cefSPeter Wemm case PT_READ_I: 429b0281cefSPeter Wemm case PT_READ_D: 430b0281cefSPeter Wemm case PT_WRITE_I: 431b0281cefSPeter Wemm case PT_WRITE_D: 4328bc814e6SDag-Erling Smørgrav case PT_IO: 433b0281cefSPeter Wemm case PT_CONTINUE: 434b0281cefSPeter Wemm case PT_KILL: 435b0281cefSPeter Wemm case PT_STEP: 436b0281cefSPeter Wemm case PT_DETACH: 437b0281cefSPeter Wemm case PT_GETREGS: 438b0281cefSPeter Wemm case PT_SETREGS: 439b0281cefSPeter Wemm case PT_GETFPREGS: 440b0281cefSPeter Wemm case PT_SETFPREGS: 441ab001a72SJonathan Lemon case PT_GETDBREGS: 442ab001a72SJonathan Lemon case PT_SETDBREGS: 443b0281cefSPeter Wemm /* not being traced... */ 444731a1aeaSJohn Baldwin if ((p->p_flag & P_TRACED) == 0) { 4456871a6c8SJohn Baldwin error = EPERM; 4466871a6c8SJohn Baldwin goto fail; 447731a1aeaSJohn Baldwin } 448b0281cefSPeter Wemm 449b0281cefSPeter Wemm /* not being traced by YOU */ 4506871a6c8SJohn Baldwin if (p->p_pptr != td->td_proc) { 4516871a6c8SJohn Baldwin error = EBUSY; 4526871a6c8SJohn Baldwin goto fail; 45398f03f90SJake Burkholder } 454b0281cefSPeter Wemm 455b0281cefSPeter Wemm /* not currently stopped */ 4560ebabc93SJohn Baldwin if (p->p_stat != SSTOP || (p->p_flag & P_WAITED) == 0) { 4576871a6c8SJohn Baldwin error = EBUSY; 4586871a6c8SJohn Baldwin goto fail; 4590ebabc93SJohn Baldwin } 460b0281cefSPeter Wemm 461b0281cefSPeter Wemm /* OK */ 462b0281cefSPeter Wemm break; 463b0281cefSPeter Wemm 464b0281cefSPeter Wemm default: 4656871a6c8SJohn Baldwin error = EINVAL; 4666871a6c8SJohn Baldwin goto fail; 4674e68ceabSDavid Greenman } 468b0281cefSPeter Wemm 469fe0d0493SPeter Wemm td2 = FIRST_THREAD_IN_PROC(p); 470b0281cefSPeter Wemm #ifdef FIX_SSTEP 471df8bae1dSRodney W. Grimes /* 472b0281cefSPeter Wemm * Single step fixup ala procfs 473b0281cefSPeter Wemm */ 474fe0d0493SPeter Wemm FIX_SSTEP(td2); /* XXXKSE */ 475b0281cefSPeter Wemm #endif 476b0281cefSPeter Wemm 477b0281cefSPeter Wemm /* 478b0281cefSPeter Wemm * Actually do the requests 479df8bae1dSRodney W. Grimes */ 4804e68ceabSDavid Greenman 481b40ce416SJulian Elischer td->td_retval[0] = 0; 4824e68ceabSDavid Greenman 483b0281cefSPeter Wemm switch (uap->req) { 484b0281cefSPeter Wemm case PT_TRACE_ME: 485b0281cefSPeter Wemm /* set my trace flag and "owner" so it can read/write me */ 4864e68ceabSDavid Greenman p->p_flag |= P_TRACED; 487b0281cefSPeter Wemm p->p_oppid = p->p_pptr->p_pid; 488731a1aeaSJohn Baldwin PROC_UNLOCK(p); 4891005a129SJohn Baldwin sx_xunlock(&proctree_lock); 490c5799337SDag-Erling Smørgrav return (0); 4914e68ceabSDavid Greenman 492b0281cefSPeter Wemm case PT_ATTACH: 493b0281cefSPeter Wemm /* security check done above */ 494731a1aeaSJohn Baldwin p->p_flag |= P_TRACED; 495b0281cefSPeter Wemm p->p_oppid = p->p_pptr->p_pid; 4966871a6c8SJohn Baldwin if (p->p_pptr != td->td_proc) 4976871a6c8SJohn Baldwin proc_reparent(p, td->td_proc); 498b0281cefSPeter Wemm uap->data = SIGSTOP; 499b0281cefSPeter Wemm goto sendsig; /* in PT_CONTINUE below */ 500b0281cefSPeter Wemm 501b0281cefSPeter Wemm case PT_STEP: 502b0281cefSPeter Wemm case PT_CONTINUE: 5034e68ceabSDavid Greenman case PT_DETACH: 50419610b66SBruce Evans /* XXX uap->data is used even in the PT_STEP case. */ 5056871a6c8SJohn Baldwin if ((uap->req != PT_STEP) && ((unsigned)uap->data >= NSIG)) { 5066871a6c8SJohn Baldwin error = EINVAL; 5076871a6c8SJohn Baldwin goto fail; 5086871a6c8SJohn Baldwin } 509b0281cefSPeter Wemm 5106871a6c8SJohn Baldwin _PHOLD(p); 511b0281cefSPeter Wemm 512b0281cefSPeter Wemm if (uap->req == PT_STEP) { 513fe0d0493SPeter Wemm error = ptrace_single_step(td2); 5142d008b44SPeter Wemm if (error) { 5156871a6c8SJohn Baldwin _PRELE(p); 5166871a6c8SJohn Baldwin goto fail; 517b0281cefSPeter Wemm } 518b0281cefSPeter Wemm } 519b0281cefSPeter Wemm 520b0281cefSPeter Wemm if (uap->addr != (caddr_t)1) { 521b40ce416SJulian Elischer fill_kinfo_proc(p, &p->p_uarea->u_kproc); 522fe0d0493SPeter Wemm error = ptrace_set_pc(td2, 5232d008b44SPeter Wemm (u_long)(uintfptr_t)uap->addr); 5242d008b44SPeter Wemm if (error) { 5256871a6c8SJohn Baldwin _PRELE(p); 5266871a6c8SJohn Baldwin goto fail; 527b0281cefSPeter Wemm } 528b0281cefSPeter Wemm } 5296871a6c8SJohn Baldwin _PRELE(p); 530b0281cefSPeter Wemm 531b0281cefSPeter Wemm if (uap->req == PT_DETACH) { 532b0281cefSPeter Wemm /* reset process parent */ 533b0281cefSPeter Wemm if (p->p_oppid != p->p_pptr->p_pid) { 534b0281cefSPeter Wemm struct proc *pp; 535b0281cefSPeter Wemm 5366871a6c8SJohn Baldwin PROC_UNLOCK(p); 537b0281cefSPeter Wemm pp = pfind(p->p_oppid); 538f591779bSSeigo Tanimura if (pp == NULL) 5396c49a8e2SJohn Baldwin pp = initproc; 540f591779bSSeigo Tanimura else 541f591779bSSeigo Tanimura PROC_UNLOCK(pp); 5426c49a8e2SJohn Baldwin PROC_LOCK(p); 5436c49a8e2SJohn Baldwin proc_reparent(p, pp); 5446871a6c8SJohn Baldwin } 545b0281cefSPeter Wemm p->p_flag &= ~(P_TRACED | P_WAITED); 546b0281cefSPeter Wemm p->p_oppid = 0; 547731a1aeaSJohn Baldwin 548b0281cefSPeter Wemm /* should we send SIGCHLD? */ 549b0281cefSPeter Wemm } 550b0281cefSPeter Wemm 551b0281cefSPeter Wemm sendsig: 5526871a6c8SJohn Baldwin if (proctree_locked) 5536871a6c8SJohn Baldwin sx_xunlock(&proctree_lock); 554b0281cefSPeter Wemm /* deliver or queue signal */ 5554e68ceabSDavid Greenman if (p->p_stat == SSTOP) { 5564e68ceabSDavid Greenman p->p_xstat = uap->data; 5576871a6c8SJohn Baldwin mtx_lock_spin(&sched_lock); 558fe0d0493SPeter Wemm setrunnable(td2); /* XXXKSE */ 5599ed346baSBosko Milekic mtx_unlock_spin(&sched_lock); 5606871a6c8SJohn Baldwin } else if (uap->data) 5614e68ceabSDavid Greenman psignal(p, uap->data); 562731a1aeaSJohn Baldwin PROC_UNLOCK(p); 5636871a6c8SJohn Baldwin 564c5799337SDag-Erling Smørgrav return (0); 5654e68ceabSDavid Greenman 5664e68ceabSDavid Greenman case PT_WRITE_I: 5674e68ceabSDavid Greenman case PT_WRITE_D: 568b0281cefSPeter Wemm write = 1; 5694e68ceabSDavid Greenman /* fallthrough */ 570b0281cefSPeter Wemm case PT_READ_I: 571b0281cefSPeter Wemm case PT_READ_D: 5726871a6c8SJohn Baldwin PROC_UNLOCK(p); 573b0281cefSPeter Wemm /* write = 0 set above */ 57450f74e92SDag-Erling Smørgrav iov.iov_base = write ? (caddr_t)&uap->data : 57550f74e92SDag-Erling Smørgrav (caddr_t)td->td_retval; 576b0281cefSPeter Wemm iov.iov_len = sizeof(int); 577b0281cefSPeter Wemm uio.uio_iov = &iov; 578b0281cefSPeter Wemm uio.uio_iovcnt = 1; 5796a206dd9SBruce Evans uio.uio_offset = (off_t)(uintptr_t)uap->addr; 580b0281cefSPeter Wemm uio.uio_resid = sizeof(int); 58119610b66SBruce Evans uio.uio_segflg = UIO_SYSSPACE; /* i.e.: the uap */ 582b0281cefSPeter Wemm uio.uio_rw = write ? UIO_WRITE : UIO_READ; 583b40ce416SJulian Elischer uio.uio_td = td; 5843da32491SDag-Erling Smørgrav error = proc_rwmem(p, &uio); 5852eb80d36SPeter Wemm if (uio.uio_resid != 0) { 5862eb80d36SPeter Wemm /* 5873da32491SDag-Erling Smørgrav * XXX proc_rwmem() doesn't currently return ENOSPC, 5882eb80d36SPeter Wemm * so I think write() can bogusly return 0. 5892eb80d36SPeter Wemm * XXX what happens for short writes? We don't want 5902eb80d36SPeter Wemm * to write partial data. 5913da32491SDag-Erling Smørgrav * XXX proc_rwmem() returns EPERM for other invalid 5922eb80d36SPeter Wemm * addresses. Convert this to EINVAL. Does this 5932eb80d36SPeter Wemm * clobber returns of EPERM for other reasons? 5942eb80d36SPeter Wemm */ 5952eb80d36SPeter Wemm if (error == 0 || error == ENOSPC || error == EPERM) 5962eb80d36SPeter Wemm error = EINVAL; /* EOF */ 5972eb80d36SPeter Wemm } 5982eb80d36SPeter Wemm return (error); 5994e68ceabSDavid Greenman 6008bc814e6SDag-Erling Smørgrav case PT_IO: 6018bc814e6SDag-Erling Smørgrav error = copyin(uap->addr, &r.piod, sizeof r.piod); 6028bc814e6SDag-Erling Smørgrav if (error) 6038bc814e6SDag-Erling Smørgrav return (error); 6048bc814e6SDag-Erling Smørgrav iov.iov_base = r.piod.piod_addr; 6058bc814e6SDag-Erling Smørgrav iov.iov_len = r.piod.piod_len; 6068bc814e6SDag-Erling Smørgrav uio.uio_iov = &iov; 6078bc814e6SDag-Erling Smørgrav uio.uio_iovcnt = 1; 6088bc814e6SDag-Erling Smørgrav uio.uio_offset = (off_t)(uintptr_t)r.piod.piod_offs; 6098bc814e6SDag-Erling Smørgrav uio.uio_resid = r.piod.piod_len; 6108bc814e6SDag-Erling Smørgrav uio.uio_segflg = UIO_USERSPACE; 6118bc814e6SDag-Erling Smørgrav uio.uio_td = td; 6128bc814e6SDag-Erling Smørgrav switch (r.piod.piod_op) { 6138bc814e6SDag-Erling Smørgrav case PIOD_READ_D: 6148bc814e6SDag-Erling Smørgrav case PIOD_READ_I: 6158bc814e6SDag-Erling Smørgrav uio.uio_rw = UIO_READ; 6168bc814e6SDag-Erling Smørgrav break; 6178bc814e6SDag-Erling Smørgrav case PIOD_WRITE_D: 6188bc814e6SDag-Erling Smørgrav case PIOD_WRITE_I: 6198bc814e6SDag-Erling Smørgrav uio.uio_rw = UIO_WRITE; 6208bc814e6SDag-Erling Smørgrav break; 6218bc814e6SDag-Erling Smørgrav default: 6228bc814e6SDag-Erling Smørgrav return (EINVAL); 6238bc814e6SDag-Erling Smørgrav } 6248bc814e6SDag-Erling Smørgrav error = proc_rwmem(p, &uio); 6258bc814e6SDag-Erling Smørgrav r.piod.piod_len -= uio.uio_resid; 6268bc814e6SDag-Erling Smørgrav (void)copyout(&r.piod, uap->addr, sizeof r.piod); 6278bc814e6SDag-Erling Smørgrav return (error); 6288bc814e6SDag-Erling Smørgrav 6294e68ceabSDavid Greenman case PT_KILL: 630b0281cefSPeter Wemm uap->data = SIGKILL; 631b0281cefSPeter Wemm goto sendsig; /* in PT_CONTINUE above */ 632b0281cefSPeter Wemm 633b0281cefSPeter Wemm case PT_SETREGS: 6346871a6c8SJohn Baldwin _PHOLD(p); 635fe0d0493SPeter Wemm error = proc_write_regs(td2, &r.reg); 6366871a6c8SJohn Baldwin _PRELE(p); 6376871a6c8SJohn Baldwin PROC_UNLOCK(p); 6383da32491SDag-Erling Smørgrav return (error); 6393da32491SDag-Erling Smørgrav 6404e68ceabSDavid Greenman case PT_GETREGS: 6416871a6c8SJohn Baldwin _PHOLD(p); 642fe0d0493SPeter Wemm error = proc_read_regs(td2, &r.reg); 6436871a6c8SJohn Baldwin _PRELE(p); 6446871a6c8SJohn Baldwin PROC_UNLOCK(p); 6453da32491SDag-Erling Smørgrav if (error == 0) 6463da32491SDag-Erling Smørgrav error = copyout(&r.reg, uap->addr, sizeof r.reg); 6473da32491SDag-Erling Smørgrav return (error); 648b0281cefSPeter Wemm 649b0281cefSPeter Wemm case PT_SETFPREGS: 6506871a6c8SJohn Baldwin _PHOLD(p); 651fe0d0493SPeter Wemm error = proc_write_fpregs(td2, &r.fpreg); 6526871a6c8SJohn Baldwin _PRELE(p); 6536871a6c8SJohn Baldwin PROC_UNLOCK(p); 6543da32491SDag-Erling Smørgrav return (error); 6553da32491SDag-Erling Smørgrav 656b0281cefSPeter Wemm case PT_GETFPREGS: 6576871a6c8SJohn Baldwin _PHOLD(p); 658fe0d0493SPeter Wemm error = proc_read_fpregs(td2, &r.fpreg); 6596871a6c8SJohn Baldwin _PRELE(p); 6606871a6c8SJohn Baldwin PROC_UNLOCK(p); 6613da32491SDag-Erling Smørgrav if (error == 0) 6623da32491SDag-Erling Smørgrav error = copyout(&r.fpreg, uap->addr, sizeof r.fpreg); 6633da32491SDag-Erling Smørgrav return (error); 664b0281cefSPeter Wemm 665ab001a72SJonathan Lemon case PT_SETDBREGS: 6666871a6c8SJohn Baldwin _PHOLD(p); 667fe0d0493SPeter Wemm error = proc_write_dbregs(td2, &r.dbreg); 6686871a6c8SJohn Baldwin _PRELE(p); 6696871a6c8SJohn Baldwin PROC_UNLOCK(p); 6703da32491SDag-Erling Smørgrav return (error); 6713da32491SDag-Erling Smørgrav 672ab001a72SJonathan Lemon case PT_GETDBREGS: 6736871a6c8SJohn Baldwin _PHOLD(p); 674fe0d0493SPeter Wemm error = proc_read_dbregs(td2, &r.dbreg); 6756871a6c8SJohn Baldwin _PRELE(p); 6766871a6c8SJohn Baldwin PROC_UNLOCK(p); 6773da32491SDag-Erling Smørgrav if (error == 0) 6783da32491SDag-Erling Smørgrav error = copyout(&r.dbreg, uap->addr, sizeof r.dbreg); 6793da32491SDag-Erling Smørgrav return (error); 680ab001a72SJonathan Lemon 6814e68ceabSDavid Greenman default: 6823da32491SDag-Erling Smørgrav KASSERT(0, ("unreachable code\n")); 6834e68ceabSDavid Greenman break; 6844e68ceabSDavid Greenman } 6854e68ceabSDavid Greenman 6863da32491SDag-Erling Smørgrav KASSERT(0, ("unreachable code\n")); 687c5799337SDag-Erling Smørgrav return (0); 6886871a6c8SJohn Baldwin 6896871a6c8SJohn Baldwin fail: 6906871a6c8SJohn Baldwin PROC_UNLOCK(p); 6916871a6c8SJohn Baldwin if (proctree_locked) 6926871a6c8SJohn Baldwin sx_xunlock(&proctree_lock); 6936871a6c8SJohn Baldwin return (error); 694df8bae1dSRodney W. Grimes } 695df8bae1dSRodney W. Grimes 69626f9a767SRodney W. Grimes int 6973da32491SDag-Erling Smørgrav trace_req(struct proc *p) 698df8bae1dSRodney W. Grimes { 69919610b66SBruce Evans 700c5799337SDag-Erling Smørgrav return (1); 701df8bae1dSRodney W. Grimes } 7022a024a2bSSean Eric Fagan 7032a024a2bSSean Eric Fagan /* 7043da32491SDag-Erling Smørgrav * Stop a process because of a debugging event; 7052a024a2bSSean Eric Fagan * stay stopped until p->p_step is cleared 7062a024a2bSSean Eric Fagan * (cleared by PIOCCONT in procfs). 7072a024a2bSSean Eric Fagan */ 7082a024a2bSSean Eric Fagan void 7093da32491SDag-Erling Smørgrav stopevent(struct proc *p, unsigned int event, unsigned int val) 7103897ca7cSJohn Baldwin { 7113897ca7cSJohn Baldwin 712731a1aeaSJohn Baldwin PROC_LOCK_ASSERT(p, MA_OWNED | MA_NOTRECURSED); 7132a024a2bSSean Eric Fagan p->p_step = 1; 7142a024a2bSSean Eric Fagan 7152a024a2bSSean Eric Fagan do { 7162a024a2bSSean Eric Fagan p->p_xstat = val; 7172a024a2bSSean Eric Fagan p->p_stype = event; /* Which event caused the stop? */ 7182a024a2bSSean Eric Fagan wakeup(&p->p_stype); /* Wake up any PIOCWAIT'ing procs */ 7193897ca7cSJohn Baldwin msleep(&p->p_step, &p->p_mtx, PWAIT, "stopevent", 0); 7202a024a2bSSean Eric Fagan } while (p->p_step); 7212a024a2bSSean Eric Fagan } 722