14e68ceabSDavid Greenman /* 24e68ceabSDavid Greenman * Copyright (c) 1994, Sean Eric Fagan 34e68ceabSDavid Greenman * All rights reserved. 4df8bae1dSRodney W. Grimes * 5df8bae1dSRodney W. Grimes * Redistribution and use in source and binary forms, with or without 6df8bae1dSRodney W. Grimes * modification, are permitted provided that the following conditions 7df8bae1dSRodney W. Grimes * are met: 8df8bae1dSRodney W. Grimes * 1. Redistributions of source code must retain the above copyright 9df8bae1dSRodney W. Grimes * notice, this list of conditions and the following disclaimer. 10df8bae1dSRodney W. Grimes * 2. Redistributions in binary form must reproduce the above copyright 11df8bae1dSRodney W. Grimes * notice, this list of conditions and the following disclaimer in the 12df8bae1dSRodney W. Grimes * documentation and/or other materials provided with the distribution. 13df8bae1dSRodney W. Grimes * 3. All advertising materials mentioning features or use of this software 14df8bae1dSRodney W. Grimes * must display the following acknowledgement: 154e68ceabSDavid Greenman * This product includes software developed by Sean Eric Fagan. 164e68ceabSDavid Greenman * 4. The name of the author may not be used to endorse or promote products 174e68ceabSDavid Greenman * derived from this software without specific prior written permission. 18df8bae1dSRodney W. Grimes * 194e68ceabSDavid Greenman * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 20df8bae1dSRodney W. Grimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21df8bae1dSRodney W. Grimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 224e68ceabSDavid Greenman * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 23df8bae1dSRodney W. Grimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24df8bae1dSRodney W. Grimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25df8bae1dSRodney W. Grimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26df8bae1dSRodney W. Grimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27df8bae1dSRodney W. Grimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28df8bae1dSRodney W. Grimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29df8bae1dSRodney W. Grimes * SUCH DAMAGE. 30df8bae1dSRodney W. Grimes */ 31df8bae1dSRodney W. Grimes 32677b542eSDavid E. O'Brien #include <sys/cdefs.h> 33677b542eSDavid E. O'Brien __FBSDID("$FreeBSD$"); 34677b542eSDavid E. O'Brien 35df8bae1dSRodney W. Grimes #include <sys/param.h> 36f23b4c91SGarrett Wollman #include <sys/systm.h> 37fb919e4dSMark Murray #include <sys/lock.h> 38fb919e4dSMark Murray #include <sys/mutex.h> 39012e544fSIan Dowse #include <sys/syscallsubr.h> 40d2d3e875SBruce Evans #include <sys/sysproto.h> 41df8bae1dSRodney W. Grimes #include <sys/proc.h> 424e68ceabSDavid Greenman #include <sys/vnode.h> 434e68ceabSDavid Greenman #include <sys/ptrace.h> 441005a129SJohn Baldwin #include <sys/sx.h> 45fb919e4dSMark Murray #include <sys/user.h> 46df8bae1dSRodney W. Grimes 474e68ceabSDavid Greenman #include <machine/reg.h> 48fb919e4dSMark Murray 494e68ceabSDavid Greenman #include <vm/vm.h> 50efeaf95aSDavid Greenman #include <vm/pmap.h> 513da32491SDag-Erling Smørgrav #include <vm/vm_extern.h> 52efeaf95aSDavid Greenman #include <vm/vm_map.h> 533da32491SDag-Erling Smørgrav #include <vm/vm_kern.h> 543da32491SDag-Erling Smørgrav #include <vm/vm_object.h> 554e68ceabSDavid Greenman #include <vm/vm_page.h> 564e68ceabSDavid Greenman 574b1aa58bSBruce Evans /* 584b1aa58bSBruce Evans * Functions implemented using PROC_ACTION(): 594b1aa58bSBruce Evans * 604b1aa58bSBruce Evans * proc_read_regs(proc, regs) 614b1aa58bSBruce Evans * Get the current user-visible register set from the process 624b1aa58bSBruce Evans * and copy it into the regs structure (<machine/reg.h>). 634b1aa58bSBruce Evans * The process is stopped at the time read_regs is called. 644b1aa58bSBruce Evans * 654b1aa58bSBruce Evans * proc_write_regs(proc, regs) 664b1aa58bSBruce Evans * Update the current register set from the passed in regs 674b1aa58bSBruce Evans * structure. Take care to avoid clobbering special CPU 684b1aa58bSBruce Evans * registers or privileged bits in the PSL. 694b1aa58bSBruce Evans * Depending on the architecture this may have fix-up work to do, 704b1aa58bSBruce Evans * especially if the IAR or PCW are modified. 714b1aa58bSBruce Evans * The process is stopped at the time write_regs is called. 724b1aa58bSBruce Evans * 734b1aa58bSBruce Evans * proc_read_fpregs, proc_write_fpregs 744b1aa58bSBruce Evans * deal with the floating point register set, otherwise as above. 754b1aa58bSBruce Evans * 764b1aa58bSBruce Evans * proc_read_dbregs, proc_write_dbregs 774b1aa58bSBruce Evans * deal with the processor debug register set, otherwise as above. 784b1aa58bSBruce Evans * 794b1aa58bSBruce Evans * proc_sstep(proc) 804b1aa58bSBruce Evans * Arrange for the process to trap after executing a single instruction. 814b1aa58bSBruce Evans */ 824b1aa58bSBruce Evans 834b1aa58bSBruce Evans #define PROC_ACTION(action) do { \ 847c629906SDag-Erling Smørgrav int error; \ 857c629906SDag-Erling Smørgrav \ 86eeec6babSJohn Baldwin PROC_LOCK_ASSERT(td->td_proc, MA_OWNED); \ 874b1aa58bSBruce Evans if ((td->td_proc->p_sflag & PS_INMEM) == 0) \ 884b1aa58bSBruce Evans error = EIO; \ 894b1aa58bSBruce Evans else \ 904b1aa58bSBruce Evans error = (action); \ 917c629906SDag-Erling Smørgrav return (error); \ 924b1aa58bSBruce Evans } while(0) 934b1aa58bSBruce Evans 944b1aa58bSBruce Evans int 954b1aa58bSBruce Evans proc_read_regs(struct thread *td, struct reg *regs) 964b1aa58bSBruce Evans { 974b1aa58bSBruce Evans 984b1aa58bSBruce Evans PROC_ACTION(fill_regs(td, regs)); 997c629906SDag-Erling Smørgrav } 1007c629906SDag-Erling Smørgrav 1014b1aa58bSBruce Evans int 1024b1aa58bSBruce Evans proc_write_regs(struct thread *td, struct reg *regs) 1034b1aa58bSBruce Evans { 1044b1aa58bSBruce Evans 1054b1aa58bSBruce Evans PROC_ACTION(set_regs(td, regs)); 1064b1aa58bSBruce Evans } 1074b1aa58bSBruce Evans 1084b1aa58bSBruce Evans int 1094b1aa58bSBruce Evans proc_read_dbregs(struct thread *td, struct dbreg *dbregs) 1104b1aa58bSBruce Evans { 1114b1aa58bSBruce Evans 1124b1aa58bSBruce Evans PROC_ACTION(fill_dbregs(td, dbregs)); 1134b1aa58bSBruce Evans } 1144b1aa58bSBruce Evans 1154b1aa58bSBruce Evans int 1164b1aa58bSBruce Evans proc_write_dbregs(struct thread *td, struct dbreg *dbregs) 1174b1aa58bSBruce Evans { 1184b1aa58bSBruce Evans 1194b1aa58bSBruce Evans PROC_ACTION(set_dbregs(td, dbregs)); 1204b1aa58bSBruce Evans } 1214b1aa58bSBruce Evans 1224b1aa58bSBruce Evans /* 1234b1aa58bSBruce Evans * Ptrace doesn't support fpregs at all, and there are no security holes 1244b1aa58bSBruce Evans * or translations for fpregs, so we can just copy them. 1254b1aa58bSBruce Evans */ 1264b1aa58bSBruce Evans int 1274b1aa58bSBruce Evans proc_read_fpregs(struct thread *td, struct fpreg *fpregs) 1284b1aa58bSBruce Evans { 1294b1aa58bSBruce Evans 1304b1aa58bSBruce Evans PROC_ACTION(fill_fpregs(td, fpregs)); 1314b1aa58bSBruce Evans } 1324b1aa58bSBruce Evans 1334b1aa58bSBruce Evans int 1344b1aa58bSBruce Evans proc_write_fpregs(struct thread *td, struct fpreg *fpregs) 1354b1aa58bSBruce Evans { 1364b1aa58bSBruce Evans 1374b1aa58bSBruce Evans PROC_ACTION(set_fpregs(td, fpregs)); 1384b1aa58bSBruce Evans } 1397c629906SDag-Erling Smørgrav 1407c629906SDag-Erling Smørgrav int 1417c629906SDag-Erling Smørgrav proc_sstep(struct thread *td) 1427c629906SDag-Erling Smørgrav { 1437c629906SDag-Erling Smørgrav 1444b1aa58bSBruce Evans PROC_ACTION(ptrace_single_step(td)); 1457c629906SDag-Erling Smørgrav } 1467c629906SDag-Erling Smørgrav 1473da32491SDag-Erling Smørgrav int 1483da32491SDag-Erling Smørgrav proc_rwmem(struct proc *p, struct uio *uio) 14950f74e92SDag-Erling Smørgrav { 1503da32491SDag-Erling Smørgrav struct vmspace *vm; 1513da32491SDag-Erling Smørgrav vm_map_t map; 152c40f7377SAlan Cox vm_object_t backing_object, object = NULL; 1533da32491SDag-Erling Smørgrav vm_offset_t pageno = 0; /* page number */ 1543da32491SDag-Erling Smørgrav vm_prot_t reqprot; 1553da32491SDag-Erling Smørgrav vm_offset_t kva; 15619610b66SBruce Evans int error, writing; 1574e68ceabSDavid Greenman 1583da32491SDag-Erling Smørgrav GIANT_REQUIRED; 1594e68ceabSDavid Greenman 1604e68ceabSDavid Greenman /* 1613da32491SDag-Erling Smørgrav * if the vmspace is in the midst of being deallocated or the 1623da32491SDag-Erling Smørgrav * process is exiting, don't try to grab anything. The page table 1633da32491SDag-Erling Smørgrav * usage in that process can be messed up. 1644e68ceabSDavid Greenman */ 1653da32491SDag-Erling Smørgrav vm = p->p_vmspace; 1663da32491SDag-Erling Smørgrav if ((p->p_flag & P_WEXIT)) 167c5799337SDag-Erling Smørgrav return (EFAULT); 1683da32491SDag-Erling Smørgrav if (vm->vm_refcnt < 1) 1693da32491SDag-Erling Smørgrav return (EFAULT); 1703da32491SDag-Erling Smørgrav ++vm->vm_refcnt; 1713da32491SDag-Erling Smørgrav /* 1723da32491SDag-Erling Smørgrav * The map we want... 1733da32491SDag-Erling Smørgrav */ 1743da32491SDag-Erling Smørgrav map = &vm->vm_map; 1754e68ceabSDavid Greenman 1763da32491SDag-Erling Smørgrav writing = uio->uio_rw == UIO_WRITE; 1773da32491SDag-Erling Smørgrav reqprot = writing ? (VM_PROT_WRITE | VM_PROT_OVERRIDE_WRITE) : 1783da32491SDag-Erling Smørgrav VM_PROT_READ; 1793da32491SDag-Erling Smørgrav 180884962aeSAlan Cox kva = kmem_alloc_nofault(kernel_map, PAGE_SIZE); 1813da32491SDag-Erling Smørgrav 1823da32491SDag-Erling Smørgrav /* 1833da32491SDag-Erling Smørgrav * Only map in one page at a time. We don't have to, but it 1843da32491SDag-Erling Smørgrav * makes things easier. This way is trivial - right? 1853da32491SDag-Erling Smørgrav */ 1863da32491SDag-Erling Smørgrav do { 1873da32491SDag-Erling Smørgrav vm_map_t tmap; 1883da32491SDag-Erling Smørgrav vm_offset_t uva; 1893da32491SDag-Erling Smørgrav int page_offset; /* offset into page */ 1903da32491SDag-Erling Smørgrav vm_map_entry_t out_entry; 1913da32491SDag-Erling Smørgrav vm_prot_t out_prot; 1923da32491SDag-Erling Smørgrav boolean_t wired; 1933da32491SDag-Erling Smørgrav vm_pindex_t pindex; 1943da32491SDag-Erling Smørgrav u_int len; 1953da32491SDag-Erling Smørgrav vm_page_t m; 1963da32491SDag-Erling Smørgrav 1973da32491SDag-Erling Smørgrav object = NULL; 1983da32491SDag-Erling Smørgrav 1993da32491SDag-Erling Smørgrav uva = (vm_offset_t)uio->uio_offset; 2003da32491SDag-Erling Smørgrav 2013da32491SDag-Erling Smørgrav /* 2023da32491SDag-Erling Smørgrav * Get the page number of this segment. 2033da32491SDag-Erling Smørgrav */ 2043da32491SDag-Erling Smørgrav pageno = trunc_page(uva); 2053da32491SDag-Erling Smørgrav page_offset = uva - pageno; 2063da32491SDag-Erling Smørgrav 2073da32491SDag-Erling Smørgrav /* 2083da32491SDag-Erling Smørgrav * How many bytes to copy 2093da32491SDag-Erling Smørgrav */ 2103da32491SDag-Erling Smørgrav len = min(PAGE_SIZE - page_offset, uio->uio_resid); 2113da32491SDag-Erling Smørgrav 2123da32491SDag-Erling Smørgrav /* 2133da32491SDag-Erling Smørgrav * Fault the page on behalf of the process 2143da32491SDag-Erling Smørgrav */ 2153da32491SDag-Erling Smørgrav error = vm_fault(map, pageno, reqprot, VM_FAULT_NORMAL); 2163da32491SDag-Erling Smørgrav if (error) { 2173da32491SDag-Erling Smørgrav error = EFAULT; 2183da32491SDag-Erling Smørgrav break; 2193da32491SDag-Erling Smørgrav } 2203da32491SDag-Erling Smørgrav 2213da32491SDag-Erling Smørgrav /* 2223da32491SDag-Erling Smørgrav * Now we need to get the page. out_entry, out_prot, wired, 2233da32491SDag-Erling Smørgrav * and single_use aren't used. One would think the vm code 2243da32491SDag-Erling Smørgrav * would be a *bit* nicer... We use tmap because 2253da32491SDag-Erling Smørgrav * vm_map_lookup() can change the map argument. 2263da32491SDag-Erling Smørgrav */ 2273da32491SDag-Erling Smørgrav tmap = map; 2283da32491SDag-Erling Smørgrav error = vm_map_lookup(&tmap, pageno, reqprot, &out_entry, 2293da32491SDag-Erling Smørgrav &object, &pindex, &out_prot, &wired); 2303da32491SDag-Erling Smørgrav if (error) { 2313da32491SDag-Erling Smørgrav error = EFAULT; 2323da32491SDag-Erling Smørgrav break; 2333da32491SDag-Erling Smørgrav } 234c40f7377SAlan Cox VM_OBJECT_LOCK(object); 235c40f7377SAlan Cox while ((m = vm_page_lookup(object, pindex)) == NULL && 236c40f7377SAlan Cox !writing && 237c40f7377SAlan Cox (backing_object = object->backing_object) != NULL) { 238c40f7377SAlan Cox /* 239c40f7377SAlan Cox * Allow fallback to backing objects if we are reading. 240c40f7377SAlan Cox */ 241c40f7377SAlan Cox VM_OBJECT_LOCK(backing_object); 2423da32491SDag-Erling Smørgrav pindex += OFF_TO_IDX(object->backing_object_offset); 243c40f7377SAlan Cox VM_OBJECT_UNLOCK(object); 244c40f7377SAlan Cox object = backing_object; 2453da32491SDag-Erling Smørgrav } 246c40f7377SAlan Cox VM_OBJECT_UNLOCK(object); 2473da32491SDag-Erling Smørgrav if (m == NULL) { 2483da32491SDag-Erling Smørgrav vm_map_lookup_done(tmap, out_entry); 249c6eb850aSAlan Cox error = EFAULT; 2503da32491SDag-Erling Smørgrav break; 2513da32491SDag-Erling Smørgrav } 2523da32491SDag-Erling Smørgrav 2533da32491SDag-Erling Smørgrav /* 254c6eb850aSAlan Cox * Hold the page in memory. 2553da32491SDag-Erling Smørgrav */ 256a4e80b6bSAlan Cox vm_page_lock_queues(); 257c6eb850aSAlan Cox vm_page_hold(m); 258a4e80b6bSAlan Cox vm_page_unlock_queues(); 2593da32491SDag-Erling Smørgrav 2603da32491SDag-Erling Smørgrav /* 2613da32491SDag-Erling Smørgrav * We're done with tmap now. 2623da32491SDag-Erling Smørgrav */ 2633da32491SDag-Erling Smørgrav vm_map_lookup_done(tmap, out_entry); 2644e68ceabSDavid Greenman 265ac59490bSJake Burkholder pmap_qenter(kva, &m, 1); 2664e68ceabSDavid Greenman 2673da32491SDag-Erling Smørgrav /* 2683da32491SDag-Erling Smørgrav * Now do the i/o move. 2693da32491SDag-Erling Smørgrav */ 2703da32491SDag-Erling Smørgrav error = uiomove((caddr_t)(kva + page_offset), len, uio); 2713da32491SDag-Erling Smørgrav 272ac59490bSJake Burkholder pmap_qremove(kva, 1); 2733da32491SDag-Erling Smørgrav 2743da32491SDag-Erling Smørgrav /* 275c6eb850aSAlan Cox * Release the page. 2763da32491SDag-Erling Smørgrav */ 277a4e80b6bSAlan Cox vm_page_lock_queues(); 278c6eb850aSAlan Cox vm_page_unhold(m); 279a4e80b6bSAlan Cox vm_page_unlock_queues(); 2803da32491SDag-Erling Smørgrav 2813da32491SDag-Erling Smørgrav } while (error == 0 && uio->uio_resid > 0); 2823da32491SDag-Erling Smørgrav 2833da32491SDag-Erling Smørgrav kmem_free(kernel_map, kva, PAGE_SIZE); 2843da32491SDag-Erling Smørgrav vmspace_free(vm); 2853da32491SDag-Erling Smørgrav return (error); 2864e68ceabSDavid Greenman } 2874e68ceabSDavid Greenman 288df8bae1dSRodney W. Grimes /* 289df8bae1dSRodney W. Grimes * Process debugging system call. 290df8bae1dSRodney W. Grimes */ 291d2d3e875SBruce Evans #ifndef _SYS_SYSPROTO_H_ 292df8bae1dSRodney W. Grimes struct ptrace_args { 293df8bae1dSRodney W. Grimes int req; 294df8bae1dSRodney W. Grimes pid_t pid; 295df8bae1dSRodney W. Grimes caddr_t addr; 296df8bae1dSRodney W. Grimes int data; 297df8bae1dSRodney W. Grimes }; 298d2d3e875SBruce Evans #endif 299df8bae1dSRodney W. Grimes 30017b8a8a7SJohn Baldwin /* 30117b8a8a7SJohn Baldwin * MPSAFE 30217b8a8a7SJohn Baldwin */ 3034e68ceabSDavid Greenman int 3043da32491SDag-Erling Smørgrav ptrace(struct thread *td, struct ptrace_args *uap) 3054e68ceabSDavid Greenman { 30619610b66SBruce Evans /* 30719610b66SBruce Evans * XXX this obfuscation is to reduce stack usage, but the register 30819610b66SBruce Evans * structs may be too large to put on the stack anyway. 30919610b66SBruce Evans */ 3103da32491SDag-Erling Smørgrav union { 3118bc814e6SDag-Erling Smørgrav struct ptrace_io_desc piod; 3123da32491SDag-Erling Smørgrav struct dbreg dbreg; 3133da32491SDag-Erling Smørgrav struct fpreg fpreg; 31419610b66SBruce Evans struct reg reg; 3153da32491SDag-Erling Smørgrav } r; 316012e544fSIan Dowse void *addr; 317012e544fSIan Dowse int error = 0; 318012e544fSIan Dowse 319012e544fSIan Dowse addr = &r; 320012e544fSIan Dowse switch (uap->req) { 321012e544fSIan Dowse case PT_GETREGS: 322012e544fSIan Dowse case PT_GETFPREGS: 323012e544fSIan Dowse case PT_GETDBREGS: 324012e544fSIan Dowse break; 325012e544fSIan Dowse case PT_SETREGS: 326012e544fSIan Dowse error = copyin(uap->addr, &r.reg, sizeof r.reg); 327012e544fSIan Dowse break; 328012e544fSIan Dowse case PT_SETFPREGS: 329012e544fSIan Dowse error = copyin(uap->addr, &r.fpreg, sizeof r.fpreg); 330012e544fSIan Dowse break; 331012e544fSIan Dowse case PT_SETDBREGS: 332012e544fSIan Dowse error = copyin(uap->addr, &r.dbreg, sizeof r.dbreg); 333012e544fSIan Dowse break; 334012e544fSIan Dowse case PT_IO: 335012e544fSIan Dowse error = copyin(uap->addr, &r.piod, sizeof r.piod); 336012e544fSIan Dowse break; 337012e544fSIan Dowse default: 338012e544fSIan Dowse addr = uap->addr; 3391c843354SMarcel Moolenaar break; 340012e544fSIan Dowse } 341012e544fSIan Dowse if (error) 342012e544fSIan Dowse return (error); 343012e544fSIan Dowse 344012e544fSIan Dowse error = kern_ptrace(td, uap->req, uap->pid, addr, uap->data); 345012e544fSIan Dowse if (error) 346012e544fSIan Dowse return (error); 347012e544fSIan Dowse 348012e544fSIan Dowse switch (uap->req) { 349012e544fSIan Dowse case PT_IO: 350012e544fSIan Dowse (void)copyout(&r.piod, uap->addr, sizeof r.piod); 351012e544fSIan Dowse break; 352012e544fSIan Dowse case PT_GETREGS: 353012e544fSIan Dowse error = copyout(&r.reg, uap->addr, sizeof r.reg); 354012e544fSIan Dowse break; 355012e544fSIan Dowse case PT_GETFPREGS: 356012e544fSIan Dowse error = copyout(&r.fpreg, uap->addr, sizeof r.fpreg); 357012e544fSIan Dowse break; 358012e544fSIan Dowse case PT_GETDBREGS: 359012e544fSIan Dowse error = copyout(&r.dbreg, uap->addr, sizeof r.dbreg); 360012e544fSIan Dowse break; 361012e544fSIan Dowse } 362012e544fSIan Dowse 363012e544fSIan Dowse return (error); 364012e544fSIan Dowse } 365012e544fSIan Dowse 366012e544fSIan Dowse int 367012e544fSIan Dowse kern_ptrace(struct thread *td, int req, pid_t pid, void *addr, int data) 368012e544fSIan Dowse { 369012e544fSIan Dowse struct iovec iov; 370012e544fSIan Dowse struct uio uio; 37146e12b42SAlfred Perlstein struct proc *curp, *p, *pp; 37219610b66SBruce Evans struct thread *td2; 373012e544fSIan Dowse struct ptrace_io_desc *piod; 3745c859660SThomas Moestl int error, write, tmp; 3756871a6c8SJohn Baldwin int proctree_locked = 0; 3764e68ceabSDavid Greenman 37746e12b42SAlfred Perlstein curp = td->td_proc; 37846e12b42SAlfred Perlstein 379012e544fSIan Dowse /* Lock proctree before locking the process. */ 380012e544fSIan Dowse switch (req) { 3816871a6c8SJohn Baldwin case PT_TRACE_ME: 3826871a6c8SJohn Baldwin case PT_ATTACH: 3836871a6c8SJohn Baldwin case PT_STEP: 3846871a6c8SJohn Baldwin case PT_CONTINUE: 385ea924c4cSRobert Drehmel case PT_TO_SCE: 386ea924c4cSRobert Drehmel case PT_TO_SCX: 3876871a6c8SJohn Baldwin case PT_DETACH: 3886871a6c8SJohn Baldwin sx_xlock(&proctree_lock); 3896871a6c8SJohn Baldwin proctree_locked = 1; 3906871a6c8SJohn Baldwin break; 3916871a6c8SJohn Baldwin default: 3929daa5b14SMarcel Moolenaar break; 3936871a6c8SJohn Baldwin } 3946871a6c8SJohn Baldwin 3957a0dde68SPeter Wemm write = 0; 396012e544fSIan Dowse if (req == PT_TRACE_ME) { 3976871a6c8SJohn Baldwin p = td->td_proc; 39833a9ed9dSJohn Baldwin PROC_LOCK(p); 39933a9ed9dSJohn Baldwin } else { 400012e544fSIan Dowse if ((p = pfind(pid)) == NULL) { 4016871a6c8SJohn Baldwin if (proctree_locked) 4026871a6c8SJohn Baldwin sx_xunlock(&proctree_lock); 403c5799337SDag-Erling Smørgrav return (ESRCH); 4044e68ceabSDavid Greenman } 40533a9ed9dSJohn Baldwin } 4064f18efe2SRobert Watson if ((error = p_cansee(td, p)) != 0) 4076871a6c8SJohn Baldwin goto fail; 4083da32491SDag-Erling Smørgrav 409f44d9e24SJohn Baldwin if ((error = p_candebug(td, p)) != 0) 4106871a6c8SJohn Baldwin goto fail; 4116871a6c8SJohn Baldwin 4123da32491SDag-Erling Smørgrav /* 41319610b66SBruce Evans * System processes can't be debugged. 4143da32491SDag-Erling Smørgrav */ 4153da32491SDag-Erling Smørgrav if ((p->p_flag & P_SYSTEM) != 0) { 4166871a6c8SJohn Baldwin error = EINVAL; 4176871a6c8SJohn Baldwin goto fail; 4183da32491SDag-Erling Smørgrav } 4193da32491SDag-Erling Smørgrav 420b0281cefSPeter Wemm /* 421b0281cefSPeter Wemm * Permissions check 422b0281cefSPeter Wemm */ 423012e544fSIan Dowse switch (req) { 424b0281cefSPeter Wemm case PT_TRACE_ME: 425b0281cefSPeter Wemm /* Always legal. */ 426b0281cefSPeter Wemm break; 4274e68ceabSDavid Greenman 428b0281cefSPeter Wemm case PT_ATTACH: 429b0281cefSPeter Wemm /* Self */ 4306871a6c8SJohn Baldwin if (p->p_pid == td->td_proc->p_pid) { 4316871a6c8SJohn Baldwin error = EINVAL; 4326871a6c8SJohn Baldwin goto fail; 43333a9ed9dSJohn Baldwin } 434b0281cefSPeter Wemm 435b0281cefSPeter Wemm /* Already traced */ 436731a1aeaSJohn Baldwin if (p->p_flag & P_TRACED) { 4376871a6c8SJohn Baldwin error = EBUSY; 4386871a6c8SJohn Baldwin goto fail; 439731a1aeaSJohn Baldwin } 440b0281cefSPeter Wemm 44146e12b42SAlfred Perlstein /* Can't trace an ancestor if you're being traced. */ 44246e12b42SAlfred Perlstein if (curp->p_flag & P_TRACED) { 44346e12b42SAlfred Perlstein for (pp = curp->p_pptr; pp != NULL; pp = pp->p_pptr) { 44446e12b42SAlfred Perlstein if (pp == p) { 44546e12b42SAlfred Perlstein error = EINVAL; 44646e12b42SAlfred Perlstein goto fail; 44746e12b42SAlfred Perlstein } 44846e12b42SAlfred Perlstein } 44946e12b42SAlfred Perlstein } 45046e12b42SAlfred Perlstein 45146e12b42SAlfred Perlstein 452b0281cefSPeter Wemm /* OK */ 453b0281cefSPeter Wemm break; 454b0281cefSPeter Wemm 4551c843354SMarcel Moolenaar default: 456b0281cefSPeter Wemm /* not being traced... */ 457731a1aeaSJohn Baldwin if ((p->p_flag & P_TRACED) == 0) { 4586871a6c8SJohn Baldwin error = EPERM; 4596871a6c8SJohn Baldwin goto fail; 460731a1aeaSJohn Baldwin } 461b0281cefSPeter Wemm 462b0281cefSPeter Wemm /* not being traced by YOU */ 4636871a6c8SJohn Baldwin if (p->p_pptr != td->td_proc) { 4646871a6c8SJohn Baldwin error = EBUSY; 4656871a6c8SJohn Baldwin goto fail; 46698f03f90SJake Burkholder } 467b0281cefSPeter Wemm 468b0281cefSPeter Wemm /* not currently stopped */ 469e602ba25SJulian Elischer if (!P_SHOULDSTOP(p) || (p->p_flag & P_WAITED) == 0) { 4706871a6c8SJohn Baldwin error = EBUSY; 4716871a6c8SJohn Baldwin goto fail; 4720ebabc93SJohn Baldwin } 473b0281cefSPeter Wemm 474b0281cefSPeter Wemm /* OK */ 475b0281cefSPeter Wemm break; 4764e68ceabSDavid Greenman } 477b0281cefSPeter Wemm 478fe0d0493SPeter Wemm td2 = FIRST_THREAD_IN_PROC(p); 479b0281cefSPeter Wemm #ifdef FIX_SSTEP 480df8bae1dSRodney W. Grimes /* 481b0281cefSPeter Wemm * Single step fixup ala procfs 482b0281cefSPeter Wemm */ 483fe0d0493SPeter Wemm FIX_SSTEP(td2); /* XXXKSE */ 484b0281cefSPeter Wemm #endif 485b0281cefSPeter Wemm 486b0281cefSPeter Wemm /* 487b0281cefSPeter Wemm * Actually do the requests 488df8bae1dSRodney W. Grimes */ 4894e68ceabSDavid Greenman 490b40ce416SJulian Elischer td->td_retval[0] = 0; 4914e68ceabSDavid Greenman 492012e544fSIan Dowse switch (req) { 493b0281cefSPeter Wemm case PT_TRACE_ME: 494b0281cefSPeter Wemm /* set my trace flag and "owner" so it can read/write me */ 4954e68ceabSDavid Greenman p->p_flag |= P_TRACED; 496b0281cefSPeter Wemm p->p_oppid = p->p_pptr->p_pid; 497731a1aeaSJohn Baldwin PROC_UNLOCK(p); 4981005a129SJohn Baldwin sx_xunlock(&proctree_lock); 499c5799337SDag-Erling Smørgrav return (0); 5004e68ceabSDavid Greenman 501b0281cefSPeter Wemm case PT_ATTACH: 502b0281cefSPeter Wemm /* security check done above */ 503731a1aeaSJohn Baldwin p->p_flag |= P_TRACED; 504b0281cefSPeter Wemm p->p_oppid = p->p_pptr->p_pid; 5056871a6c8SJohn Baldwin if (p->p_pptr != td->td_proc) 5066871a6c8SJohn Baldwin proc_reparent(p, td->td_proc); 507012e544fSIan Dowse data = SIGSTOP; 508b0281cefSPeter Wemm goto sendsig; /* in PT_CONTINUE below */ 509b0281cefSPeter Wemm 510b0281cefSPeter Wemm case PT_STEP: 511b0281cefSPeter Wemm case PT_CONTINUE: 512ea924c4cSRobert Drehmel case PT_TO_SCE: 513ea924c4cSRobert Drehmel case PT_TO_SCX: 5144e68ceabSDavid Greenman case PT_DETACH: 515007e25d9SJacques Vidrine /* Zero means do not send any signal */ 516007e25d9SJacques Vidrine if (data < 0 || data > _SIG_MAXSIG) { 5176871a6c8SJohn Baldwin error = EINVAL; 5186871a6c8SJohn Baldwin goto fail; 5196871a6c8SJohn Baldwin } 520b0281cefSPeter Wemm 5216871a6c8SJohn Baldwin _PHOLD(p); 522b0281cefSPeter Wemm 523ea924c4cSRobert Drehmel switch (req) { 524ea924c4cSRobert Drehmel case PT_STEP: 5258ac61436SJohn Baldwin PROC_UNLOCK(p); 526fe0d0493SPeter Wemm error = ptrace_single_step(td2); 5272d008b44SPeter Wemm if (error) { 5288ac61436SJohn Baldwin PRELE(p); 5298ac61436SJohn Baldwin goto fail_noproc; 530b0281cefSPeter Wemm } 5318ac61436SJohn Baldwin PROC_LOCK(p); 532ea924c4cSRobert Drehmel break; 533ea924c4cSRobert Drehmel case PT_TO_SCE: 534ea924c4cSRobert Drehmel p->p_stops |= S_PT_SCE; 535ea924c4cSRobert Drehmel break; 536ea924c4cSRobert Drehmel case PT_TO_SCX: 537ea924c4cSRobert Drehmel p->p_stops |= S_PT_SCX; 538ea924c4cSRobert Drehmel break; 539ea924c4cSRobert Drehmel case PT_SYSCALL: 540ea924c4cSRobert Drehmel p->p_stops |= S_PT_SCE | S_PT_SCX; 541ea924c4cSRobert Drehmel break; 542b0281cefSPeter Wemm } 543b0281cefSPeter Wemm 544012e544fSIan Dowse if (addr != (void *)1) { 5458ac61436SJohn Baldwin PROC_UNLOCK(p); 546012e544fSIan Dowse error = ptrace_set_pc(td2, (u_long)(uintfptr_t)addr); 5472d008b44SPeter Wemm if (error) { 5488ac61436SJohn Baldwin PRELE(p); 5498ac61436SJohn Baldwin goto fail_noproc; 550b0281cefSPeter Wemm } 5518ac61436SJohn Baldwin PROC_LOCK(p); 552b0281cefSPeter Wemm } 5536871a6c8SJohn Baldwin _PRELE(p); 554b0281cefSPeter Wemm 555012e544fSIan Dowse if (req == PT_DETACH) { 556b0281cefSPeter Wemm /* reset process parent */ 557b0281cefSPeter Wemm if (p->p_oppid != p->p_pptr->p_pid) { 558b0281cefSPeter Wemm struct proc *pp; 559b0281cefSPeter Wemm 5606871a6c8SJohn Baldwin PROC_UNLOCK(p); 561b0281cefSPeter Wemm pp = pfind(p->p_oppid); 562f591779bSSeigo Tanimura if (pp == NULL) 5636c49a8e2SJohn Baldwin pp = initproc; 564f591779bSSeigo Tanimura else 565f591779bSSeigo Tanimura PROC_UNLOCK(pp); 5666c49a8e2SJohn Baldwin PROC_LOCK(p); 5676c49a8e2SJohn Baldwin proc_reparent(p, pp); 568cf93aa16SDon Lewis if (pp == initproc) 56955b5f2a2SDon Lewis p->p_sigparent = SIGCHLD; 5706871a6c8SJohn Baldwin } 571b0281cefSPeter Wemm p->p_flag &= ~(P_TRACED | P_WAITED); 572b0281cefSPeter Wemm p->p_oppid = 0; 573731a1aeaSJohn Baldwin 574b0281cefSPeter Wemm /* should we send SIGCHLD? */ 575b0281cefSPeter Wemm } 576b0281cefSPeter Wemm 577b0281cefSPeter Wemm sendsig: 5786871a6c8SJohn Baldwin if (proctree_locked) 5796871a6c8SJohn Baldwin sx_xunlock(&proctree_lock); 580b0281cefSPeter Wemm /* deliver or queue signal */ 581e602ba25SJulian Elischer if (P_SHOULDSTOP(p)) { 582012e544fSIan Dowse p->p_xstat = data; 5831279572aSDavid Xu p->p_flag &= ~(P_STOPPED_TRACE|P_STOPPED_SIG); 584b68e0849SJohn Baldwin mtx_lock_spin(&sched_lock); 58571fad9fdSJulian Elischer thread_unsuspend(p); 586fe0d0493SPeter Wemm setrunnable(td2); /* XXXKSE */ 587e602ba25SJulian Elischer /* Need foreach kse in proc, ... make_kse_queued(). */ 5889ed346baSBosko Milekic mtx_unlock_spin(&sched_lock); 589012e544fSIan Dowse } else if (data) 590012e544fSIan Dowse psignal(p, data); 591731a1aeaSJohn Baldwin PROC_UNLOCK(p); 5926871a6c8SJohn Baldwin 593c5799337SDag-Erling Smørgrav return (0); 5944e68ceabSDavid Greenman 5954e68ceabSDavid Greenman case PT_WRITE_I: 5964e68ceabSDavid Greenman case PT_WRITE_D: 597b0281cefSPeter Wemm write = 1; 59893b0017fSPhilippe Charnier /* FALLTHROUGH */ 599b0281cefSPeter Wemm case PT_READ_I: 600b0281cefSPeter Wemm case PT_READ_D: 6016871a6c8SJohn Baldwin PROC_UNLOCK(p); 6025c859660SThomas Moestl tmp = 0; 603b0281cefSPeter Wemm /* write = 0 set above */ 604012e544fSIan Dowse iov.iov_base = write ? (caddr_t)&data : (caddr_t)&tmp; 605b0281cefSPeter Wemm iov.iov_len = sizeof(int); 606b0281cefSPeter Wemm uio.uio_iov = &iov; 607b0281cefSPeter Wemm uio.uio_iovcnt = 1; 608012e544fSIan Dowse uio.uio_offset = (off_t)(uintptr_t)addr; 609b0281cefSPeter Wemm uio.uio_resid = sizeof(int); 61019610b66SBruce Evans uio.uio_segflg = UIO_SYSSPACE; /* i.e.: the uap */ 611b0281cefSPeter Wemm uio.uio_rw = write ? UIO_WRITE : UIO_READ; 612b40ce416SJulian Elischer uio.uio_td = td; 61317b8a8a7SJohn Baldwin mtx_lock(&Giant); 6143da32491SDag-Erling Smørgrav error = proc_rwmem(p, &uio); 61517b8a8a7SJohn Baldwin mtx_unlock(&Giant); 6162eb80d36SPeter Wemm if (uio.uio_resid != 0) { 6172eb80d36SPeter Wemm /* 6183da32491SDag-Erling Smørgrav * XXX proc_rwmem() doesn't currently return ENOSPC, 6192eb80d36SPeter Wemm * so I think write() can bogusly return 0. 6202eb80d36SPeter Wemm * XXX what happens for short writes? We don't want 6212eb80d36SPeter Wemm * to write partial data. 6223da32491SDag-Erling Smørgrav * XXX proc_rwmem() returns EPERM for other invalid 6232eb80d36SPeter Wemm * addresses. Convert this to EINVAL. Does this 6242eb80d36SPeter Wemm * clobber returns of EPERM for other reasons? 6252eb80d36SPeter Wemm */ 6262eb80d36SPeter Wemm if (error == 0 || error == ENOSPC || error == EPERM) 6272eb80d36SPeter Wemm error = EINVAL; /* EOF */ 6282eb80d36SPeter Wemm } 6295c859660SThomas Moestl if (!write) 6305c859660SThomas Moestl td->td_retval[0] = tmp; 6312eb80d36SPeter Wemm return (error); 6324e68ceabSDavid Greenman 6338bc814e6SDag-Erling Smørgrav case PT_IO: 6345c0cc63cSJohn Baldwin PROC_UNLOCK(p); 635012e544fSIan Dowse piod = addr; 636012e544fSIan Dowse iov.iov_base = piod->piod_addr; 637012e544fSIan Dowse iov.iov_len = piod->piod_len; 6388bc814e6SDag-Erling Smørgrav uio.uio_iov = &iov; 6398bc814e6SDag-Erling Smørgrav uio.uio_iovcnt = 1; 640012e544fSIan Dowse uio.uio_offset = (off_t)(uintptr_t)piod->piod_offs; 641012e544fSIan Dowse uio.uio_resid = piod->piod_len; 6428bc814e6SDag-Erling Smørgrav uio.uio_segflg = UIO_USERSPACE; 6438bc814e6SDag-Erling Smørgrav uio.uio_td = td; 644012e544fSIan Dowse switch (piod->piod_op) { 6458bc814e6SDag-Erling Smørgrav case PIOD_READ_D: 6468bc814e6SDag-Erling Smørgrav case PIOD_READ_I: 6478bc814e6SDag-Erling Smørgrav uio.uio_rw = UIO_READ; 6488bc814e6SDag-Erling Smørgrav break; 6498bc814e6SDag-Erling Smørgrav case PIOD_WRITE_D: 6508bc814e6SDag-Erling Smørgrav case PIOD_WRITE_I: 6518bc814e6SDag-Erling Smørgrav uio.uio_rw = UIO_WRITE; 6528bc814e6SDag-Erling Smørgrav break; 6538bc814e6SDag-Erling Smørgrav default: 6548bc814e6SDag-Erling Smørgrav return (EINVAL); 6558bc814e6SDag-Erling Smørgrav } 65617b8a8a7SJohn Baldwin mtx_lock(&Giant); 6578bc814e6SDag-Erling Smørgrav error = proc_rwmem(p, &uio); 65817b8a8a7SJohn Baldwin mtx_unlock(&Giant); 659012e544fSIan Dowse piod->piod_len -= uio.uio_resid; 6608bc814e6SDag-Erling Smørgrav return (error); 6618bc814e6SDag-Erling Smørgrav 6624e68ceabSDavid Greenman case PT_KILL: 663012e544fSIan Dowse data = SIGKILL; 664b0281cefSPeter Wemm goto sendsig; /* in PT_CONTINUE above */ 665b0281cefSPeter Wemm 666b0281cefSPeter Wemm case PT_SETREGS: 6676871a6c8SJohn Baldwin _PHOLD(p); 668012e544fSIan Dowse error = proc_write_regs(td2, addr); 6696871a6c8SJohn Baldwin _PRELE(p); 6706871a6c8SJohn Baldwin PROC_UNLOCK(p); 6713da32491SDag-Erling Smørgrav return (error); 6723da32491SDag-Erling Smørgrav 6734e68ceabSDavid Greenman case PT_GETREGS: 6746871a6c8SJohn Baldwin _PHOLD(p); 675012e544fSIan Dowse error = proc_read_regs(td2, addr); 6766871a6c8SJohn Baldwin _PRELE(p); 6776871a6c8SJohn Baldwin PROC_UNLOCK(p); 6783da32491SDag-Erling Smørgrav return (error); 679b0281cefSPeter Wemm 680b0281cefSPeter Wemm case PT_SETFPREGS: 6816871a6c8SJohn Baldwin _PHOLD(p); 682012e544fSIan Dowse error = proc_write_fpregs(td2, addr); 6836871a6c8SJohn Baldwin _PRELE(p); 6846871a6c8SJohn Baldwin PROC_UNLOCK(p); 6853da32491SDag-Erling Smørgrav return (error); 6863da32491SDag-Erling Smørgrav 687b0281cefSPeter Wemm case PT_GETFPREGS: 6886871a6c8SJohn Baldwin _PHOLD(p); 689012e544fSIan Dowse error = proc_read_fpregs(td2, addr); 6906871a6c8SJohn Baldwin _PRELE(p); 6916871a6c8SJohn Baldwin PROC_UNLOCK(p); 6923da32491SDag-Erling Smørgrav return (error); 693b0281cefSPeter Wemm 694ab001a72SJonathan Lemon case PT_SETDBREGS: 6956871a6c8SJohn Baldwin _PHOLD(p); 696012e544fSIan Dowse error = proc_write_dbregs(td2, addr); 6976871a6c8SJohn Baldwin _PRELE(p); 6986871a6c8SJohn Baldwin PROC_UNLOCK(p); 6993da32491SDag-Erling Smørgrav return (error); 7003da32491SDag-Erling Smørgrav 701ab001a72SJonathan Lemon case PT_GETDBREGS: 7026871a6c8SJohn Baldwin _PHOLD(p); 703012e544fSIan Dowse error = proc_read_dbregs(td2, addr); 7046871a6c8SJohn Baldwin _PRELE(p); 7056871a6c8SJohn Baldwin PROC_UNLOCK(p); 7063da32491SDag-Erling Smørgrav return (error); 707ab001a72SJonathan Lemon 7084e68ceabSDavid Greenman default: 7091c843354SMarcel Moolenaar #ifdef __HAVE_PTRACE_MACHDEP 7101c843354SMarcel Moolenaar if (req >= PT_FIRSTMACH) { 7111c843354SMarcel Moolenaar _PHOLD(p); 7121c843354SMarcel Moolenaar PROC_UNLOCK(p); 7138ac61436SJohn Baldwin error = cpu_ptrace(td2, req, addr, data); 7148ac61436SJohn Baldwin PRELE(p); 7151c843354SMarcel Moolenaar return (error); 7161c843354SMarcel Moolenaar } 7171c843354SMarcel Moolenaar #endif 7184e68ceabSDavid Greenman break; 7194e68ceabSDavid Greenman } 7204e68ceabSDavid Greenman 7211c843354SMarcel Moolenaar /* Unknown request. */ 7221c843354SMarcel Moolenaar error = EINVAL; 7236871a6c8SJohn Baldwin 7246871a6c8SJohn Baldwin fail: 7256871a6c8SJohn Baldwin PROC_UNLOCK(p); 7268ac61436SJohn Baldwin fail_noproc: 7276871a6c8SJohn Baldwin if (proctree_locked) 7286871a6c8SJohn Baldwin sx_xunlock(&proctree_lock); 7296871a6c8SJohn Baldwin return (error); 730df8bae1dSRodney W. Grimes } 731df8bae1dSRodney W. Grimes 7322a024a2bSSean Eric Fagan /* 7333da32491SDag-Erling Smørgrav * Stop a process because of a debugging event; 7342a024a2bSSean Eric Fagan * stay stopped until p->p_step is cleared 7352a024a2bSSean Eric Fagan * (cleared by PIOCCONT in procfs). 7362a024a2bSSean Eric Fagan */ 7372a024a2bSSean Eric Fagan void 7383da32491SDag-Erling Smørgrav stopevent(struct proc *p, unsigned int event, unsigned int val) 7393897ca7cSJohn Baldwin { 7403897ca7cSJohn Baldwin 741b68e0849SJohn Baldwin PROC_LOCK_ASSERT(p, MA_OWNED); 7422a024a2bSSean Eric Fagan p->p_step = 1; 7432a024a2bSSean Eric Fagan do { 7442a024a2bSSean Eric Fagan p->p_xstat = val; 7452a024a2bSSean Eric Fagan p->p_stype = event; /* Which event caused the stop? */ 7462a024a2bSSean Eric Fagan wakeup(&p->p_stype); /* Wake up any PIOCWAIT'ing procs */ 7473897ca7cSJohn Baldwin msleep(&p->p_step, &p->p_mtx, PWAIT, "stopevent", 0); 7482a024a2bSSean Eric Fagan } while (p->p_step); 7492a024a2bSSean Eric Fagan } 750