gdbstub.c 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323
  1. /*
  2. * Kernel Debug Core
  3. *
  4. * Maintainer: Jason Wessel <jason.wessel@windriver.com>
  5. *
  6. * Copyright (C) 2000-2001 VERITAS Software Corporation.
  7. * Copyright (C) 2002-2004 Timesys Corporation
  8. * Copyright (C) 2003-2004 Amit S. Kale <amitkale@linsyssoft.com>
  9. * Copyright (C) 2004 Pavel Machek <pavel@ucw.cz>
  10. * Copyright (C) 2004-2006 Tom Rini <trini@kernel.crashing.org>
  11. * Copyright (C) 2004-2006 LinSysSoft Technologies Pvt. Ltd.
  12. * Copyright (C) 2005-2009 Wind River Systems, Inc.
  13. * Copyright (C) 2007 MontaVista Software, Inc.
  14. * Copyright (C) 2008 Red Hat, Inc., Ingo Molnar <mingo@redhat.com>
  15. *
  16. * Contributors at various stages not listed above:
  17. * Jason Wessel ( jason.wessel@windriver.com )
  18. * George Anzinger <george@mvista.com>
  19. * Anurekh Saxena (anurekh.saxena@timesys.com)
  20. * Lake Stevens Instrument Division (Glenn Engel)
  21. * Jim Kingdon, Cygnus Support.
  22. *
  23. * Original KGDB stub: David Grothe <dave@gcom.com>,
  24. * Tigran Aivazian <tigran@sco.com>
  25. *
  26. * This file is licensed under the terms of the GNU General Public License
  27. * version 2. This program is licensed "as is" without any warranty of any
  28. * kind, whether express or implied.
  29. */
  30. #include <u.h>
  31. #include <libc.h>
  32. #include <ureg.h>
  33. #include <ctype.h>
  34. #include <bio.h>
  35. #include <mach.h>
  36. #include "debug_core.h"
  37. #include "gdb.h"
  38. #define MAX_THREAD_QUERY 17
  39. #define BUFMAX 1024
  40. #define BUF_THREAD_ID_SIZE 8
  41. // Everything always does EINVAL.
  42. #define EINVAL 22
  43. /* Our I/O buffers. */
  44. char remcom_in_buffer[BUFMAX];
  45. char remcom_out_buffer[BUFMAX];
  46. static int gdbstub_use_prev_in_buf;
  47. static int gdbstub_prev_in_buf_pos;
  48. int remotefd;
  49. int notefid;
  50. int debug = 0;
  51. int attached_to_existing_pid = 0;
  52. Map* cormap;
  53. static struct state ks;
  54. /* support crap */
  55. /*
  56. * GDB remote protocol parser:
  57. */
  58. static char *hex_asc = "0123456789abcdef";
  59. char* regstrs[] = {
  60. [GDB_AX] = "AX",
  61. [GDB_BX] = "BX",
  62. [GDB_CX] = "CX",
  63. [GDB_DX] = "DX",
  64. [GDB_SI] = "SI",
  65. [GDB_DI] = "DI",
  66. [GDB_BP] = "BP",
  67. [GDB_SP] = "SP",
  68. [GDB_R8] = "R8",
  69. [GDB_R9] = "R9",
  70. [GDB_R10] = "R10",
  71. [GDB_R11] = "R11",
  72. [GDB_R12] = "R12",
  73. [GDB_R13] = "R13",
  74. [GDB_R14] = "R14",
  75. [GDB_R15] = "R15",
  76. [GDB_PC] = "PC",
  77. [GDB_PS] = "PS",
  78. [GDB_CS] = "CS",
  79. [GDB_SS] = "SS",
  80. [GDB_DS] = "DS",
  81. [GDB_ES] = "ES",
  82. [GDB_FS] = "FS",
  83. [GDB_GS] = "GS",
  84. };
  85. // not reentrant, bla bla bla
  86. char *
  87. errstring(char *prefix)
  88. {
  89. static char error[ERRMAX];
  90. snprint(error, sizeof(error), "%s%r", prefix);
  91. return error;
  92. }
  93. static uint8_t
  94. hex_asc_lo(int x)
  95. {
  96. return hex_asc[x & 0xf];
  97. }
  98. static uint8_t
  99. hex_asc_hi(int x)
  100. {
  101. return hex_asc_lo(x >> 4);
  102. }
  103. static void *
  104. hex_byte_pack(char *dest, int val)
  105. {
  106. *dest++ = hex_asc_hi(val);
  107. *dest++ = hex_asc_lo(val);
  108. return dest;
  109. }
  110. static int
  111. hex_to_bin(int c)
  112. {
  113. if ((c >= '0') && (c <= '9'))
  114. return c - '0';
  115. if ((c >= 'a') && (c <= 'f'))
  116. return c + 10 - 'a';
  117. if ((c >= 'A') && (c <= 'F'))
  118. return c + 10 - 'A';
  119. return -1;
  120. }
  121. char *
  122. p8(char *dest, int c)
  123. {
  124. *dest++ = hex_to_bin(c);
  125. *dest++ = hex_to_bin(c >> 4);
  126. return dest;
  127. }
  128. char *
  129. p16(char *dest, int c)
  130. {
  131. dest = p8(dest, c);
  132. dest = p8(dest, c >> 4);
  133. return dest;
  134. }
  135. char *
  136. p32(char *dest, uint32_t c)
  137. {
  138. dest = p16(dest, c);
  139. dest = p16(dest, c >> 16);
  140. return dest;
  141. }
  142. char *
  143. p64(char *dest, uint64_t c)
  144. {
  145. dest = p32(dest, c);
  146. dest = p32(dest, c >> 32);
  147. return dest;
  148. }
  149. void
  150. attach_to_process(int pid)
  151. {
  152. char buf[100];
  153. sprint(buf, "/proc/%d/text", pid);
  154. int textfid = open(buf, OREAD);
  155. if (textfid < 0){
  156. syslog(0, "gdbserver", "couldn't open %s: %r", buf);
  157. return;
  158. }
  159. Fhdr fhdr;
  160. if (!crackhdr(textfid, &fhdr)) {
  161. syslog(0, "gdbserver", "couldn't decode file header: %r");
  162. return;
  163. }
  164. // machdata will be valid after this
  165. machbytype(fhdr.type);
  166. Map* symmap = loadmap(0, textfid, &fhdr);
  167. if (symmap == nil) {
  168. syslog(0, "gdbserver", "loadmap failed: %r");
  169. return;
  170. }
  171. snprint(buf, sizeof(buf), "/proc/%d/mem", pid);
  172. int memfid = open(buf, ORDWR);
  173. if (memfid < 0) {
  174. syslog(0, "gdbserver", "couldn't open %s: %r", buf);
  175. return;
  176. }
  177. cormap = attachproc(pid, 0, memfid, &fhdr);
  178. if (cormap == 0) {
  179. syslog(0, "gdbserver", "couldn't attachproc: %r");
  180. return;
  181. }
  182. int i = findseg(cormap, "text");
  183. if (i > 0) {
  184. cormap->seg[i].name = "*text";
  185. }
  186. i = findseg(cormap, "data");
  187. if (i > 0) {
  188. cormap->seg[i].name = "*data";
  189. }
  190. snprint(buf, sizeof(buf), "/proc/%d/note", pid);
  191. notefid = open(buf, OREAD);
  192. if (notefid < 0) {
  193. syslog(0, "gdbserver", "couldn't open %s: %r", buf);
  194. return;
  195. }
  196. syslog(0, "gdbserver", "attach_to_process completed");
  197. }
  198. void
  199. sendctl(int pid, char* message)
  200. {
  201. char buf[100];
  202. int ctlfd;
  203. sprint(buf, "/proc/%d/ctl", pid);
  204. ctlfd = open(buf, OWRITE);
  205. if (ctlfd >= 0) {
  206. write(ctlfd, message, strlen(message));
  207. close(ctlfd);
  208. syslog(0, "gdbserver", "sent '%s' to %s", message, buf);
  209. }
  210. }
  211. static char *
  212. getstatus(int pid)
  213. {
  214. int fd, n;
  215. char *argv[16], buf[64];
  216. static char status[128];
  217. snprint(buf, sizeof(buf), "/proc/%d/status", pid);
  218. fd = open(buf, OREAD);
  219. if(fd < 0) {
  220. syslog(0, "gdbserver", "Failed to open %s: %r", buf);
  221. return nil;
  222. }
  223. n = read(fd, status, sizeof(status)-1);
  224. close(fd);
  225. if(n <= 0) {
  226. syslog(0, "gdbserver", "Failed to read %s: %r", buf);
  227. return nil;
  228. }
  229. status[n] = '\0';
  230. if(tokenize(status, argv, nelem(argv)-1) < 3) {
  231. syslog(0, "gdbserver", "Failed to tokenize %s: %r", buf);
  232. return nil;
  233. }
  234. return argv[2];
  235. }
  236. // Remove any pending breakpoint notes
  237. static void
  238. remove_note(void)
  239. {
  240. char buf[ERRMAX];
  241. switch (read(notefid, buf, sizeof buf)) {
  242. case -1:
  243. syslog(0, "gdbserver", "Error reading note: %r");
  244. return;
  245. case 0:
  246. syslog(0, "gdbserver", "No note to remove");
  247. return;
  248. }
  249. buf[ERRMAX-1] = '\0';
  250. if(strncmp(buf, "sys: breakpoint", 15) == 0)
  251. syslog(0, "gdbserver", "Removed breakpoint note");
  252. else
  253. syslog(0, "gdbserver", "Found unexpected note: %s", buf);
  254. }
  255. static void
  256. write_char(uint8_t c)
  257. {
  258. write(remotefd, &c, 1);
  259. }
  260. static int
  261. read_char()
  262. {
  263. uint8_t c;
  264. if (read(remotefd, &c, 1) < 0)
  265. return -1;
  266. return c;
  267. }
  268. static int
  269. gdbstub_read_wait(void)
  270. {
  271. int ret;
  272. ret = read_char();
  273. if (ret < 0) {
  274. print("Session ended\n");
  275. exits("die");
  276. }
  277. return ret;
  278. }
  279. /* scan for the sequence $<data>#<checksum> */
  280. static void
  281. get_packet(char *buffer)
  282. {
  283. unsigned char checksum;
  284. unsigned char xmitcsum;
  285. int count;
  286. char ch;
  287. do {
  288. /*
  289. * Spin and wait around for the start character, ignore all
  290. * other characters:
  291. */
  292. while ((ch = (gdbstub_read_wait())) != '$')
  293. /* nothing */ ;
  294. checksum = 0;
  295. xmitcsum = -1;
  296. count = 0;
  297. /*
  298. * now, read until a # or end of buffer is found:
  299. */
  300. while (count < (BUFMAX - 1)) {
  301. ch = gdbstub_read_wait();
  302. if (ch == '#')
  303. break;
  304. checksum = checksum + ch;
  305. buffer[count] = ch;
  306. count = count + 1;
  307. }
  308. if (ch == '#') {
  309. xmitcsum = hex_to_bin(gdbstub_read_wait()) << 4;
  310. xmitcsum += hex_to_bin(gdbstub_read_wait());
  311. if (checksum != xmitcsum) syslog(0, "gdbserver", "BAD CSUM Computed 0x%x want 0x%x", xmitcsum, checksum);
  312. if (checksum != xmitcsum)
  313. /* failed checksum */
  314. write_char('-');
  315. else
  316. /* successful transfer */
  317. write_char('+');
  318. }
  319. buffer[count] = 0;
  320. } while (checksum != xmitcsum);
  321. if (debug)
  322. print("<-%s\n", buffer);
  323. }
  324. /*
  325. * Send the packet in buffer.
  326. * Check for gdb connection if asked for.
  327. */
  328. static void
  329. put_packet(char *buffer)
  330. {
  331. unsigned char checksum;
  332. int count;
  333. char ch;
  334. /*
  335. * $<packet info>#<checksum>.
  336. */
  337. if (debug)
  338. print("->%s\n", buffer);
  339. while (1) {
  340. write_char('$');
  341. checksum = 0;
  342. count = 0;
  343. while ((ch = buffer[count])) {
  344. write_char(ch);
  345. checksum += ch;
  346. count++;
  347. }
  348. write_char('#');
  349. write_char(hex_asc_hi(checksum));
  350. write_char(hex_asc_lo(checksum));
  351. /* Now see what we get in reply. */
  352. ch = gdbstub_read_wait();
  353. if (ch == 3)
  354. ch = gdbstub_read_wait();
  355. /* If we get an ACK, we are done. */
  356. if (ch == '+')
  357. return;
  358. /*
  359. * If we get the start of another packet, this means
  360. * that GDB is attempting to reconnect. We will NAK
  361. * the packet being sent, and stop trying to send this
  362. * packet.
  363. */
  364. if (ch == '$') {
  365. write_char('-');
  366. return;
  367. }
  368. }
  369. }
  370. static char gdbmsgbuf[BUFMAX + 1];
  371. void
  372. gdbstub_msg_write(const char *s, int len)
  373. {
  374. char *bufptr;
  375. int wcount;
  376. int i;
  377. if (len == 0)
  378. len = strlen(s);
  379. /* 'O'utput */
  380. gdbmsgbuf[0] = 'O';
  381. /* Fill and send buffers... */
  382. while (len > 0) {
  383. bufptr = gdbmsgbuf + 1;
  384. /* Calculate how many this time */
  385. if ((len << 1) > (BUFMAX - 2))
  386. wcount = (BUFMAX - 2) >> 1;
  387. else
  388. wcount = len;
  389. /* Pack in hex chars */
  390. for (i = 0; i < wcount; i++)
  391. bufptr = hex_byte_pack(bufptr, s[i]);
  392. *bufptr = '\0';
  393. /* Move up */
  394. s += wcount;
  395. len -= wcount;
  396. /* Write packet */
  397. put_packet(gdbmsgbuf);
  398. }
  399. }
  400. /*
  401. * Convert the memory pointed to by mem into hex, placing result in
  402. * buf. Return a pointer to the last char put in buf (null). May
  403. * return an error.
  404. */
  405. char *
  406. mem2hex(unsigned char *mem, char *buf, int count)
  407. {
  408. char *tmp;
  409. for(tmp = buf; count; tmp += 2, count--, mem++){
  410. sprint(tmp, "%02x", *mem);
  411. }
  412. *tmp = 0;
  413. return tmp;
  414. }
  415. /*
  416. * Convert the hex array pointed to by buf into binary to be placed in
  417. * mem. Return a pointer to the character AFTER the last byte
  418. * written. May return an error.
  419. */
  420. char *
  421. hex2mem(char *buf, unsigned char *mem, int count)
  422. {
  423. char *tmp_raw;
  424. char *tmp_hex;
  425. /*
  426. * We use the upper half of buf as an intermediate buffer for the
  427. * raw memory that is converted from hex.
  428. */
  429. tmp_raw = buf + count * 2;
  430. tmp_hex = tmp_raw - 1;
  431. while (tmp_hex >= buf) {
  432. tmp_raw--;
  433. *tmp_raw = hex_to_bin(*tmp_hex--);
  434. *tmp_raw |= hex_to_bin(*tmp_hex--) << 4;
  435. }
  436. return nil; // Check for valid stuff some day?
  437. }
  438. /*
  439. * While we find nice hex chars, build a long_val.
  440. * Return number of chars processed.
  441. */
  442. int
  443. hex2long(char **ptr, unsigned long *long_val)
  444. {
  445. int hex_val;
  446. int num = 0;
  447. int negate = 0;
  448. *long_val = 0;
  449. if (**ptr == '-') {
  450. negate = 1;
  451. (*ptr)++;
  452. }
  453. while (**ptr) {
  454. hex_val = hex_to_bin(**ptr);
  455. if (hex_val < 0)
  456. break;
  457. *long_val = (*long_val << 4) | hex_val;
  458. num++;
  459. (*ptr)++;
  460. }
  461. if (negate)
  462. *long_val = -*long_val;
  463. return num;
  464. }
  465. /*
  466. * Copy the binary array pointed to by src into dest. Fix $, #, and
  467. * 0x7d escaped with 0x7d.
  468. */
  469. static void
  470. ebin2mem(unsigned char *src, unsigned char *dest, int count)
  471. {
  472. int size = 0;
  473. unsigned char *c = dest;
  474. while (count-- > 0) {
  475. c[size] = *src++;
  476. if (c[size] == 0x7d)
  477. c[size] = *src++ ^ 0x20;
  478. size++;
  479. }
  480. }
  481. /* Write memory due to an 'M' or 'X' packet. */
  482. static char *
  483. write_mem_msg(struct state *ks, int binary)
  484. {
  485. char *cp = (char *)&remcom_in_buffer[1];
  486. unsigned long addr;
  487. unsigned long length;
  488. char *err;
  489. if (hex2long(&cp, &addr) > 0 && *(cp++) == ',' &&
  490. hex2long(&cp, &length) > 0 && *(cp++) == ':') {
  491. // When gdb wants to set a variable, we seem to get a zero length write
  492. // packet immediately before the real write packet. Not sure why,
  493. // but let's not try to write it at least.
  494. if (length == 0) {
  495. return nil;
  496. }
  497. unsigned char *data = malloc(length);
  498. if (binary)
  499. ebin2mem((unsigned char *)cp, data, length);
  500. else
  501. hex2mem(cp, data, length);
  502. err = wmem(addr, ks->threadid, data, length);
  503. free(data);
  504. return err;
  505. }
  506. return Einval;
  507. }
  508. // Yep, the protocol really is this shitty: errors are numbers. Assholes.
  509. void
  510. error_packet(char *pkt, char *error)
  511. {
  512. pkt[0] = 'E';
  513. pkt[1] = error[0];
  514. pkt[2] = error[1];
  515. pkt[3] = '\0';
  516. }
  517. static char *
  518. pack_threadid(char *pkt, unsigned char *id)
  519. {
  520. unsigned char *limit;
  521. int lzero = 1;
  522. limit = id + (BUF_THREAD_ID_SIZE / 2);
  523. while (id < limit) {
  524. if (!lzero || *id != 0) {
  525. pkt = hex_byte_pack(pkt, *id);
  526. lzero = 0;
  527. }
  528. id++;
  529. }
  530. if (lzero)
  531. pkt = hex_byte_pack(pkt, 0);
  532. return pkt;
  533. }
  534. static void
  535. int_to_threadref(unsigned char *id, int value)
  536. {
  537. print("%s: panic\n", __func__);
  538. exits("fuck");
  539. // put_unaligned_be32(value, id);
  540. }
  541. uint64_t
  542. get_reg(Map *map, char *reg)
  543. {
  544. (void)map;
  545. int reg_idx = -1;
  546. for (int i = 0; i < DBG_MAX_REG_NUM; i++) {
  547. if (!strcmp(reg, regstrs[i])) {
  548. reg_idx = i;
  549. break;
  550. }
  551. }
  552. if (reg_idx == -1) {
  553. syslog(0, "gdbserver", "get_reg: Unrecognised register %s.", reg);
  554. return 0;
  555. }
  556. uint64_t value = arch_get_reg(&ks, reg_idx);
  557. return value;
  558. }
  559. /*
  560. * All the functions that start with gdb_cmd are the various
  561. * operations to implement the handlers for the gdbserial protocol
  562. * where KGDB is communicating with an external debugger
  563. */
  564. /* Handle the '?' status packets */
  565. static void
  566. gdb_cmd_status(struct state *ks)
  567. {
  568. /*
  569. * We know that this packet is only sent
  570. * during initial connect. So to be safe,
  571. * we clear out our breakpoints now in case
  572. * GDB is reconnecting.
  573. */
  574. dbg_remove_all_break(ks);
  575. remcom_out_buffer[0] = 'S';
  576. hex_byte_pack((char *)&remcom_out_buffer[1], ks->signo);
  577. }
  578. /* Handle the 'g' get registers request */
  579. static void
  580. gdb_cmd_getregs(struct state *ks)
  581. {
  582. if (ks->threadid <= 0) {
  583. syslog(0, "gdbserver", "%s: id <= 0, fuck it, make it 1", __func__);
  584. }
  585. gpr(ks, ks->threadid);
  586. mem2hex(ks->gdbregs, (char *)remcom_out_buffer, NUMREGBYTES);
  587. }
  588. /* Handle the 'G' set registers request */
  589. static void
  590. gdb_cmd_setregs(struct state *ks)
  591. {
  592. hex2mem((char *)&remcom_in_buffer[1], ks->gdbregs, NUMREGBYTES);
  593. error_packet(remcom_out_buffer, Einval);
  594. //gdb_regs_to_pt_regs(gdb_regs, ks->linux_regs);
  595. // strcpy(remcom_out_buffer, "OK");
  596. }
  597. /* Handle the 'm' memory read bytes */
  598. static void
  599. gdb_cmd_memread(struct state *ks)
  600. {
  601. char *ptr = (char *)&remcom_in_buffer[1];
  602. unsigned long length;
  603. unsigned long addr;
  604. char *err;
  605. if (hex2long(&ptr, &addr) > 0 && *ptr++ == ',' &&
  606. hex2long(&ptr, &length) > 0) {
  607. char *data = malloc(length);
  608. if ((err = rmem(data, ks->threadid, addr, length)) != 0) {
  609. if (debug)
  610. print("%s: %r", __func__);
  611. syslog(0, "gdbserver", "%s: %r", __func__);
  612. error_packet(remcom_out_buffer, err);
  613. free(data);
  614. return;
  615. }
  616. mem2hex((unsigned char *)data, (char *)remcom_out_buffer, length);
  617. free(data);
  618. } else {
  619. syslog(0, "gdbserver", "%s failed: %s : no good", __func__, remcom_in_buffer);
  620. error_packet(remcom_out_buffer, Einval);
  621. }
  622. }
  623. /* Handle the 'M' memory write bytes */
  624. static void
  625. gdb_cmd_memwrite(struct state *ks)
  626. {
  627. char *err = write_mem_msg(ks, 0);
  628. if (err)
  629. error_packet(remcom_out_buffer, err);
  630. else
  631. strcpy((char *)remcom_out_buffer, "OK");
  632. }
  633. /* Handle the 'X' memory binary write bytes */
  634. static void
  635. gdb_cmd_binwrite(struct state *ks)
  636. {
  637. char *err = write_mem_msg(ks, 1);
  638. if (err)
  639. error_packet(remcom_out_buffer, err);
  640. else
  641. strcpy((char *)remcom_out_buffer, "OK");
  642. }
  643. /* Handle the 'D', detach packet */
  644. static void
  645. gdb_cmd_detach(struct state *ks)
  646. {
  647. char *error;
  648. error = dbg_remove_all_break(ks);
  649. if (error < 0) {
  650. error_packet(remcom_out_buffer, error);
  651. } else {
  652. strcpy((char *)remcom_out_buffer, "OK");
  653. connected = 0;
  654. sendctl(ks->threadid, "start");
  655. }
  656. put_packet(remcom_out_buffer);
  657. }
  658. /* Handle the 'k' kill packet */
  659. static void
  660. gdb_cmd_kill(struct state *ks)
  661. {
  662. sendctl(ks->threadid, "kill");
  663. connected = 0;
  664. print("Process %d killed by gdb\n", ks->threadid);
  665. }
  666. /* Handle the 'R' reboot packets */
  667. static int
  668. gdb_cmd_reboot(struct state *ks)
  669. {
  670. /* For now, only honor R0 */
  671. if (strcmp((char *)remcom_in_buffer, "R0") == 0) {
  672. print(" NOT Executing emergency reboot\n");
  673. strcpy((char *)remcom_out_buffer, "OK");
  674. put_packet(remcom_out_buffer);
  675. /*
  676. * Execution should not return from
  677. * machine_emergency_restart()
  678. */
  679. connected = 0;
  680. return 1;
  681. }
  682. return 0;
  683. }
  684. /* Handle the 'q' query packets */
  685. static void
  686. gdb_cmd_query(struct state *ks)
  687. {
  688. if (strcmp(&remcom_in_buffer[1], "Symbol::") == 0) {
  689. strcpy((char *)remcom_out_buffer, "OK");
  690. return;
  691. }
  692. switch (remcom_in_buffer[1]) {
  693. case 'S':
  694. if (memcmp(remcom_in_buffer + 2, "upported", 8))
  695. break;
  696. // this code sucks.
  697. // We don't really have procs and threads for now. Just use the
  698. // thread id as the pid. i.e. no multiprocess.
  699. strcpy((char *)remcom_out_buffer, ""); // "multiprocess+");
  700. break;
  701. case 'f':
  702. if (memcmp(remcom_in_buffer + 2, "ThreadInfo", 10))
  703. break;
  704. // Just pass the main pid for now
  705. remcom_out_buffer[0] = 'm';
  706. pack_threadid((char *)remcom_out_buffer + 1, (uint8_t *)&ks->threadid);
  707. break;
  708. case 'C':
  709. /* Current thread id */
  710. strcpy((char *)remcom_out_buffer, "QC");
  711. pack_threadid((char *)remcom_out_buffer + 2, (uint8_t *) & ks->threadid);
  712. break;
  713. case 'T':
  714. if (memcmp(remcom_in_buffer+2, "Status", 6) == 0) {
  715. // TODO: proper status
  716. strcpy(remcom_out_buffer, "Tnotrun:0");
  717. break;
  718. }
  719. strcpy((char *)remcom_out_buffer, "");
  720. break;
  721. case 'A':
  722. if (memcmp(remcom_in_buffer + 2, "ttached", 7))
  723. break;
  724. strcpy((char *)remcom_out_buffer, attached_to_existing_pid ? "1" : "0");
  725. break;
  726. }
  727. }
  728. /* Handle the 'H' task query packets */
  729. static void
  730. gdb_cmd_task(struct state *ks)
  731. {
  732. char *ptr;
  733. char *err;
  734. unsigned long id;
  735. switch (remcom_in_buffer[1]) {
  736. case 'g':
  737. ptr = (char *)&remcom_in_buffer[2];
  738. //hex2long(&ptr, &ks->threadid);
  739. if (ks->threadid <= 0) {
  740. syslog(0, "gdbserver", "Warning: using 1 instead of 0");
  741. }
  742. err = gpr(ks, ks->threadid);
  743. syslog(0, "gdbserver", "Try to use thread %d: %s", ks->threadid, err);
  744. if (err){
  745. error_packet(remcom_out_buffer, err);
  746. } else {
  747. strcpy((char *)remcom_out_buffer, "OK");
  748. }
  749. break;
  750. case 'c':
  751. ptr = (char *)&remcom_in_buffer[2];
  752. hex2long(&ptr, &id);
  753. strcpy((char *)remcom_out_buffer, "OK");
  754. break;
  755. }
  756. }
  757. /* Handle the 'T' thread query packets */
  758. static void
  759. gdb_cmd_thread(struct state *ks)
  760. {
  761. //char *ptr = (char *)&remcom_in_buffer[1];
  762. char *err;
  763. //hex2long(&ptr, &ks->threadid);
  764. if (ks->threadid <= 0) {
  765. syslog(0, "gdbserver", "%s: id <= 0, fuck it, make it 1", __func__);
  766. }
  767. err = gpr(ks, ks->threadid);
  768. if (!err)
  769. strcpy((char *)remcom_out_buffer, "OK");
  770. else
  771. error_packet(remcom_out_buffer, Einval);
  772. }
  773. /* Handle the 'z' or 'Z' breakpoint remove or set packets */
  774. static void
  775. gdb_cmd_break(struct state *ks)
  776. {
  777. /*
  778. * Since GDB-5.3, it's been drafted that '0' is a software
  779. * breakpoint, '1' is a hardware breakpoint, so let's do that.
  780. */
  781. char *bpt_type = (char *)&remcom_in_buffer[1];
  782. char *ptr = (char *)&remcom_in_buffer[2];
  783. unsigned long addr;
  784. unsigned long length;
  785. char *error = nil;
  786. // We only support software breakpoints
  787. if (*bpt_type >= '1') {
  788. return;
  789. }
  790. if (*(ptr++) != ',') {
  791. error_packet(remcom_out_buffer, Einval);
  792. return;
  793. }
  794. if (!hex2long(&ptr, &addr)) {
  795. error_packet(remcom_out_buffer, Einval);
  796. return;
  797. }
  798. if (*(ptr++) != ',' || !hex2long(&ptr, &length)) {
  799. error_packet(remcom_out_buffer, Einval);
  800. return;
  801. }
  802. if (remcom_in_buffer[0] == 'Z' && *bpt_type == '0')
  803. error = dbg_set_sw_break(ks, addr);
  804. else if (remcom_in_buffer[0] == 'z' && *bpt_type == '0')
  805. error = dbg_remove_sw_break(ks, addr);
  806. if (error == 0) {
  807. strcpy((char *)remcom_out_buffer, "OK");
  808. } else {
  809. syslog(0, "gdbserver", "gdb_cmd_break: error: %s", error);
  810. error_packet(remcom_out_buffer, Einval);
  811. }
  812. }
  813. /* Handle the 'C' signal / exception passing packets */
  814. static int
  815. gdb_cmd_exception_pass(struct state *ks)
  816. {
  817. /* C09 == pass exception
  818. * C15 == detach kgdb, pass exception
  819. */
  820. if (remcom_in_buffer[1] == '0' && remcom_in_buffer[2] == '9') {
  821. ks->pass_exception = 1;
  822. remcom_in_buffer[0] = 'c';
  823. } else if (remcom_in_buffer[1] == '1' && remcom_in_buffer[2] == '5') {
  824. ks->pass_exception = 1;
  825. remcom_in_buffer[0] = 'D';
  826. dbg_remove_all_break(ks);
  827. connected = 0;
  828. return 1;
  829. } else {
  830. gdbstub_msg_write("KGDB only knows signal 9 (pass)"
  831. " and 15 (pass and disconnect)\n"
  832. "Executing a continue without signal passing\n", 0);
  833. remcom_in_buffer[0] = 'c';
  834. }
  835. /* Indicate fall through */
  836. return -1;
  837. }
  838. static void
  839. gdb_cmd_continue(struct state *ks)
  840. {
  841. if (strcmp("Stopped", getstatus(ks->threadid)) != 0) {
  842. syslog(0, "gdbserver", "Process not stopped - can't activate breakpoints");
  843. // Not really sure what to reply with here
  844. return;
  845. }
  846. syslog(0, "gdbserver", "activating breakpoints");
  847. dbg_activate_sw_breakpoints(ks);
  848. // Block for the process to stop or receive a note
  849. sendctl(ks->threadid, "startstop");
  850. // Remove the breakpoint note so the process
  851. // doesn't suicide
  852. remove_note();
  853. // Send code indicating we've hit a breakpoint
  854. strcpy((char *)remcom_out_buffer, "S05");
  855. }
  856. static void
  857. gdb_cmd_single_step(struct state *ks)
  858. {
  859. if (machdata == nil) {
  860. syslog(0, "gdbserver", "machdata not set");
  861. return;
  862. }
  863. if (machdata->foll == nil) {
  864. syslog(0, "gdbserver", "machdata->foll not set");
  865. return;
  866. }
  867. uint64_t foll[] = {0, 0, 0};
  868. uint64_t pc = arch_get_pc(ks);
  869. int nfoll = machdata->foll(cormap, pc, get_reg, foll);
  870. if (nfoll < 0)
  871. syslog(0, "gdbserver", "machdata->foll failed: %r");
  872. else
  873. syslog(0, "gdbserver", "machdata->foll succeeded, nfoll: %d", nfoll);
  874. for (int i = 0; i < nfoll; i++) {
  875. syslog(0, "gdbserver", "Setting single-step breakpoint at: %p", foll[i]);
  876. dbg_set_sw_break(ks, foll[i]);
  877. }
  878. gdb_cmd_continue(ks);
  879. for (int i = 0; i < nfoll; i++) {
  880. syslog(0, "gdbserver", "Removing single-step breakpoint at: %p", foll[i]);
  881. dbg_remove_sw_break(ks, foll[i]);
  882. }
  883. }
  884. /*
  885. * This function performs all gdbserial command procesing
  886. */
  887. int
  888. gdb_serial_stub(struct state *ks, int port)
  889. {
  890. int error = 0;
  891. int tmp;
  892. char adir[40], ldir[40], buff[256];
  893. int acfd, lcfd;
  894. sprint(buff, "tcp!*!%d", port);
  895. acfd = announce(buff, adir);
  896. if (acfd < 0) {
  897. fprint(2, "Unable to connect %r\n");
  898. exits("announce");
  899. }
  900. lcfd = listen(adir, ldir);
  901. if (lcfd < 0) {
  902. fprint(2, "listen failed %r\n");
  903. exits("listen");
  904. }
  905. print("Waiting for connection on %d...\n", port);
  906. remotefd = accept(lcfd, ldir);
  907. if (remotefd < 0) {
  908. fprint(2, "Accept failed %r\n");
  909. exits("accept");
  910. }
  911. print("Connected\n");
  912. /* Initialize comm buffer and globals. */
  913. memset(remcom_out_buffer, 0, sizeof(remcom_out_buffer));
  914. if (connected) {
  915. unsigned char thref[BUF_THREAD_ID_SIZE];
  916. char *ptr;
  917. /* Reply to host that an exception has occurred */
  918. ptr = (char *)remcom_out_buffer;
  919. *ptr++ = 'T';
  920. ptr = hex_byte_pack(ptr, ks->signo);
  921. ptr += strlen(strcpy(ptr, "thread:"));
  922. int_to_threadref(thref, 1);
  923. ptr = pack_threadid(ptr, thref);
  924. *ptr++ = ';';
  925. put_packet(remcom_out_buffer);
  926. }
  927. while (1) {
  928. error = 0;
  929. /* Clear the out buffer. */
  930. memset(remcom_out_buffer, 0, sizeof(remcom_out_buffer));
  931. get_packet(remcom_in_buffer);
  932. syslog(0, "gdbserver", "packet :%s:", remcom_in_buffer);
  933. switch (remcom_in_buffer[0]) {
  934. case '?': /* gdbserial status */
  935. gdb_cmd_status(ks);
  936. break;
  937. case 'g': /* return the value of the CPU registers */
  938. gdb_cmd_getregs(ks);
  939. break;
  940. case 'G': /* set the value of the CPU registers - return OK */
  941. gdb_cmd_setregs(ks);
  942. break;
  943. case 'm': /* mAA..AA,LLLL Read LLLL bytes at address AA..AA */
  944. gdb_cmd_memread(ks);
  945. break;
  946. case 'M': /* MAA..AA,LLLL: Write LLLL bytes at address AA..AA */
  947. gdb_cmd_memwrite(ks);
  948. break;
  949. case 'p': /* pXX Return gdb register XX (in hex) */
  950. gdb_cmd_reg_get(ks);
  951. break;
  952. case 'P': /* PXX=aaaa Set gdb register XX to aaaa (in hex) */
  953. gdb_cmd_reg_set(ks);
  954. break;
  955. case 'X': /* XAA..AA,LLLL: Write LLLL bytes at address AA..AA */
  956. gdb_cmd_binwrite(ks);
  957. break;
  958. /* kill or detach. KGDB should treat this like a
  959. * continue.
  960. */
  961. case 'D': /* Debugger detach */
  962. gdb_cmd_detach(ks);
  963. break;
  964. case 'k': /* Debugger detach via kill */
  965. gdb_cmd_kill(ks);
  966. goto exit;
  967. case 'R': /* Reboot */
  968. if (gdb_cmd_reboot(ks))
  969. goto default_handle;
  970. break;
  971. case 'q': /* query command */
  972. gdb_cmd_query(ks);
  973. break;
  974. case 'H': /* task related */
  975. gdb_cmd_task(ks);
  976. break;
  977. case 'T': /* Query thread status */
  978. gdb_cmd_thread(ks);
  979. break;
  980. case 'z': /* Break point remove */
  981. case 'Z': /* Break point set */
  982. gdb_cmd_break(ks);
  983. break;
  984. case 'C': /* Exception passing */
  985. tmp = gdb_cmd_exception_pass(ks);
  986. if (tmp > 0)
  987. goto default_handle;
  988. if (tmp == 0)
  989. break;
  990. /* Fall through on tmp < 0 */
  991. case 'c': /* Continue packet */
  992. gdb_cmd_continue(ks);
  993. break;
  994. case 's': /* Single step packet */
  995. gdb_cmd_single_step(ks);
  996. break;
  997. default:
  998. default_handle:
  999. if (remcom_in_buffer[0] == 'v') {
  1000. // Specifically indicate we don't handle
  1001. // v packets.
  1002. strcpy((char *)remcom_out_buffer, "");
  1003. }
  1004. else if (error > 0 || remcom_in_buffer[0] == 'D' ||
  1005. remcom_in_buffer[0] == 'k') {
  1006. /*
  1007. * I have no idea what to do.
  1008. * Leave cmd processing on error, detach,
  1009. * kill, continue, or single step.
  1010. */
  1011. error = 0;
  1012. goto exit;
  1013. }
  1014. }
  1015. syslog(0, "gdbserver", "RETURN :%s:", remcom_out_buffer);
  1016. /* reply to the request */
  1017. put_packet(remcom_out_buffer);
  1018. }
  1019. exit:
  1020. if (ks->pass_exception)
  1021. error = 1;
  1022. return error;
  1023. }
  1024. char *
  1025. gdbstub_state(struct state *ks, char *cmd)
  1026. {
  1027. char *error;
  1028. switch (cmd[0]) {
  1029. case 'e':
  1030. error = Einval;
  1031. #if 0
  1032. error = arch_handle_exception(ks->ex_vector,
  1033. ks->signo,
  1034. ks->err_code,
  1035. remcom_in_buffer,
  1036. remcom_out_buffer, ks->linux_regs);
  1037. #endif
  1038. return error;
  1039. case 's':
  1040. case 'c':
  1041. strcpy(remcom_in_buffer, cmd);
  1042. return nil;
  1043. case '$':
  1044. strcpy(remcom_in_buffer, cmd);
  1045. gdbstub_use_prev_in_buf = strlen(remcom_in_buffer);
  1046. gdbstub_prev_in_buf_pos = 0;
  1047. return nil;
  1048. }
  1049. write_char('+');
  1050. put_packet(remcom_out_buffer);
  1051. return nil;
  1052. }
  1053. /**
  1054. * gdbstub_exit - Send an exit message to GDB
  1055. * @status: The exit code to report.
  1056. */
  1057. void
  1058. gdbstub_exit(int status)
  1059. {
  1060. unsigned char checksum, ch, buffer[3];
  1061. int loop;
  1062. if (!connected)
  1063. return;
  1064. connected = 0;
  1065. buffer[0] = 'W';
  1066. buffer[1] = hex_asc_hi(status);
  1067. buffer[2] = hex_asc_lo(status);
  1068. write_char('$');
  1069. checksum = 0;
  1070. for (loop = 0; loop < 3; loop++) {
  1071. ch = buffer[loop];
  1072. checksum += ch;
  1073. write_char(ch);
  1074. }
  1075. write_char('#');
  1076. write_char(hex_asc_hi(checksum));
  1077. write_char(hex_asc_lo(checksum));
  1078. }
  1079. char *
  1080. rmem(void *dest, int pid, uint64_t addr, int size)
  1081. {
  1082. syslog(0, "gdbserver", "rmem(%p, %d, %p, %d)", dest, pid, addr, size);
  1083. if (get1(cormap, addr, dest, size) < 0) {
  1084. syslog(0, "gdbserver", "get1 failed: %r");
  1085. return errstring(Eio);
  1086. }
  1087. syslog(0, "gdbserver", "rmem read %d bytes", size);
  1088. return nil;
  1089. }
  1090. char *
  1091. wmem(uint64_t dest, int pid, void *addr, int size)
  1092. {
  1093. syslog(0, "gdbserver", "wmem(%p, %d, %p, %d)", dest, pid, addr, size);
  1094. if (put1(cormap, dest, addr, size) < 0) {
  1095. syslog(0, "gdbserver", "put1 failed: %r");
  1096. return errstring(Eio);
  1097. }
  1098. syslog(0, "gdbserver", "wmem wrote %d bytes", size);
  1099. return nil;
  1100. }
  1101. void
  1102. main(int argc, char **argv)
  1103. {
  1104. char* pid = nil;
  1105. char* port = "1666";
  1106. ARGBEGIN {
  1107. case 'l':
  1108. port = ARGF();
  1109. if (port == nil) {
  1110. fprint(2, "Please specify a listening port\n");
  1111. exits("listen");
  1112. }
  1113. break;
  1114. case 'p':
  1115. pid = ARGF();
  1116. if (pid == nil) {
  1117. fprint(2, "Please specify a pid\n");
  1118. exits("pid");
  1119. }
  1120. break;
  1121. case 'd':
  1122. debug = 1;
  1123. break;
  1124. default:
  1125. fprint(2, " badflag('%c')", ARGC());
  1126. } ARGEND
  1127. if (pid == nil) {
  1128. fprint(2, "Please specify a pid\n");
  1129. exits("pid");
  1130. }
  1131. ks.threadid = atoi(pid);
  1132. // Set to 0 if we eventually support creating a new process
  1133. attached_to_existing_pid = 1;
  1134. print("Stopping process...\n", ks.threadid);
  1135. sendctl(ks.threadid, "stop");
  1136. print("Process stopped. Waiting for remote gdb connection...\n");
  1137. attach_to_process(ks.threadid);
  1138. gdb_serial_stub(&ks, atoi(port));
  1139. }