1 /* 2 * Copryight 1997 Sean Eric Fagan 3 * 4 * Redistribution and use in source and binary forms, with or without 5 * modification, are permitted provided that the following conditions 6 * are met: 7 * 1. Redistributions of source code must retain the above copyright 8 * notice, this list of conditions and the following disclaimer. 9 * 2. Redistributions in binary form must reproduce the above copyright 10 * notice, this list of conditions and the following disclaimer in the 11 * documentation and/or other materials provided with the distribution. 12 * 3. All advertising materials mentioning features or use of this software 13 * must display the following acknowledgement: 14 * This product includes software developed by Sean Eric Fagan 15 * 4. Neither the name of the author may be used to endorse or promote 16 * products derived from this software without specific prior written 17 * permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32 #ifndef lint 33 static const char rcsid[] = 34 "$FreeBSD$"; 35 #endif /* not lint */ 36 37 /* 38 * Various setup functions for truss. Not the cleanest-written code, 39 * I'm afraid. 40 */ 41 42 #include <sys/param.h> 43 #include <sys/ioctl.h> 44 #include <sys/pioctl.h> 45 #include <sys/wait.h> 46 47 #include <err.h> 48 #include <errno.h> 49 #include <fcntl.h> 50 #include <signal.h> 51 #include <stdio.h> 52 #include <stdlib.h> 53 #include <string.h> 54 #include <time.h> 55 #include <unistd.h> 56 57 #include "truss.h" 58 #include "extern.h" 59 60 static int evflags = 0; 61 62 /* 63 * setup_and_wait() is called to start a process. All it really does 64 * is fork(), set itself up to stop on exec or exit, and then exec 65 * the given command. At that point, the child process stops, and 66 * the parent can wake up and deal with it. 67 */ 68 69 int 70 setup_and_wait(char *command[]) { 71 struct procfs_status pfs; 72 char buf[32]; 73 int fd; 74 int pid; 75 int flags; 76 77 pid = fork(); 78 if (pid == -1) { 79 err(1, "fork failed"); 80 } 81 if (pid == 0) { /* Child */ 82 int mask = S_EXEC | S_EXIT; 83 fd = open("/proc/curproc/mem", O_WRONLY); 84 if (fd == -1) 85 err(2, "cannot open /proc/curproc/mem"); 86 fcntl(fd, F_SETFD, 1); 87 if (ioctl(fd, PIOCBIS, mask) == -1) 88 err(3, "PIOCBIS"); 89 flags = PF_LINGER; 90 /* 91 * The PF_LINGER flag tells procfs not to wake up the 92 * process on last close; normally, this is the behaviour 93 * we want. 94 */ 95 if (ioctl(fd, PIOCSFL, flags) == -1) 96 warn("cannot set PF_LINGER"); 97 execvp(command[0], command); 98 mask = ~0; 99 ioctl(fd, PIOCBIC, ~0); 100 err(4, "execvp %s", command[0]); 101 } 102 /* Only in the parent here */ 103 104 if (waitpid(pid, NULL, WNOHANG) != 0) { 105 /* 106 * Process exited before it got to us -- meaning the exec failed 107 * miserably -- so we just quietly exit. 108 */ 109 exit(1); 110 } 111 112 sprintf(buf, "/proc/%d/mem", pid); 113 if ((fd = open(buf, O_RDWR)) == -1) 114 err(5, "cannot open %s", buf); 115 if (ioctl(fd, PIOCWAIT, &pfs) == -1) 116 err(6, "PIOCWAIT"); 117 if (pfs.why == S_EXIT) { 118 fprintf(stderr, "process exited before exec'ing\n"); 119 ioctl(fd, PIOCCONT, 0); 120 wait(0); 121 exit(7); 122 } 123 close(fd); 124 return pid; 125 } 126 127 /* 128 * start_tracing picks up where setup_and_wait() dropped off -- namely, 129 * it sets the event mask for the given process id. Called for both 130 * monitoring an existing process and when we create our own. 131 */ 132 133 int 134 start_tracing(int pid, int eventflags, int flags) { 135 int fd; 136 char buf[32]; 137 struct procfs_status tmp; 138 sprintf(buf, "/proc/%d/mem", pid); 139 140 fd = open(buf, O_RDWR); 141 if (fd == -1) { 142 /* 143 * The process may have run away before we could start -- this 144 * happens with SUGID programs. So we need to see if it still 145 * exists before we complain bitterly. 146 */ 147 if (kill(pid, 0) == -1) 148 return -1; 149 err(8, "cannot open %s", buf); 150 } 151 152 if (ioctl(fd, PIOCSTATUS, &tmp) == -1) { 153 err(10, "cannot get procfs status struct"); 154 } 155 evflags = tmp.events; 156 157 if (ioctl(fd, PIOCBIS, eventflags) == -1) 158 err(9, "cannot set procfs event bit mask"); 159 160 /* 161 * This clears the PF_LINGER set above in setup_and_wait(); 162 * if truss happens to die before this, then the process 163 * needs to be woken up via procctl. 164 */ 165 166 if (ioctl(fd, PIOCSFL, flags) == -1) 167 warn("cannot clear PF_LINGER"); 168 169 return fd; 170 } 171 172 /* 173 * Restore a process back to it's pre-truss state. 174 * Called for SIGINT, SIGTERM, SIGQUIT. This only 175 * applies if truss was told to monitor an already-existing 176 * process. 177 */ 178 void 179 restore_proc(int signo __unused) { 180 extern int Procfd; 181 182 ioctl(Procfd, PIOCBIC, ~0); 183 if (evflags) 184 ioctl(Procfd, PIOCBIS, evflags); 185 exit(0); 186 } 187