ptrace.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415
  1. /* ptrace.c */
  2. /* By Ross Biro 1/23/92 */
  3. /* edited by Linus Torvalds */
  4. /* mangled further by Bob Manson (manson@santafe.edu) */
  5. /* more mutilation by David Mosberger (davidm@azstarnet.com) */
  6. #include <linux/kernel.h>
  7. #include <linux/sched.h>
  8. #include <linux/mm.h>
  9. #include <linux/smp.h>
  10. #include <linux/smp_lock.h>
  11. #include <linux/errno.h>
  12. #include <linux/ptrace.h>
  13. #include <linux/user.h>
  14. #include <linux/slab.h>
  15. #include <linux/security.h>
  16. #include <asm/uaccess.h>
  17. #include <asm/pgtable.h>
  18. #include <asm/system.h>
  19. #include <asm/fpu.h>
  20. #include "proto.h"
  21. #define DEBUG DBG_MEM
  22. #undef DEBUG
  23. #ifdef DEBUG
  24. enum {
  25. DBG_MEM = (1<<0),
  26. DBG_BPT = (1<<1),
  27. DBG_MEM_ALL = (1<<2)
  28. };
  29. #define DBG(fac,args) {if ((fac) & DEBUG) printk args;}
  30. #else
  31. #define DBG(fac,args)
  32. #endif
  33. #define BREAKINST 0x00000080 /* call_pal bpt */
  34. /*
  35. * does not yet catch signals sent when the child dies.
  36. * in exit.c or in signal.c.
  37. */
  38. /*
  39. * Processes always block with the following stack-layout:
  40. *
  41. * +================================+ <---- task + 2*PAGE_SIZE
  42. * | PALcode saved frame (ps, pc, | ^
  43. * | gp, a0, a1, a2) | |
  44. * +================================+ | struct pt_regs
  45. * | | |
  46. * | frame generated by SAVE_ALL | |
  47. * | | v
  48. * +================================+
  49. * | | ^
  50. * | frame saved by do_switch_stack | | struct switch_stack
  51. * | | v
  52. * +================================+
  53. */
  54. /*
  55. * The following table maps a register index into the stack offset at
  56. * which the register is saved. Register indices are 0-31 for integer
  57. * regs, 32-63 for fp regs, and 64 for the pc. Notice that sp and
  58. * zero have no stack-slot and need to be treated specially (see
  59. * get_reg/put_reg below).
  60. */
  61. enum {
  62. REG_R0 = 0, REG_F0 = 32, REG_FPCR = 63, REG_PC = 64
  63. };
  64. static int regoff[] = {
  65. PT_REG( r0), PT_REG( r1), PT_REG( r2), PT_REG( r3),
  66. PT_REG( r4), PT_REG( r5), PT_REG( r6), PT_REG( r7),
  67. PT_REG( r8), SW_REG( r9), SW_REG( r10), SW_REG( r11),
  68. SW_REG( r12), SW_REG( r13), SW_REG( r14), SW_REG( r15),
  69. PT_REG( r16), PT_REG( r17), PT_REG( r18), PT_REG( r19),
  70. PT_REG( r20), PT_REG( r21), PT_REG( r22), PT_REG( r23),
  71. PT_REG( r24), PT_REG( r25), PT_REG( r26), PT_REG( r27),
  72. PT_REG( r28), PT_REG( gp), -1, -1,
  73. SW_REG(fp[ 0]), SW_REG(fp[ 1]), SW_REG(fp[ 2]), SW_REG(fp[ 3]),
  74. SW_REG(fp[ 4]), SW_REG(fp[ 5]), SW_REG(fp[ 6]), SW_REG(fp[ 7]),
  75. SW_REG(fp[ 8]), SW_REG(fp[ 9]), SW_REG(fp[10]), SW_REG(fp[11]),
  76. SW_REG(fp[12]), SW_REG(fp[13]), SW_REG(fp[14]), SW_REG(fp[15]),
  77. SW_REG(fp[16]), SW_REG(fp[17]), SW_REG(fp[18]), SW_REG(fp[19]),
  78. SW_REG(fp[20]), SW_REG(fp[21]), SW_REG(fp[22]), SW_REG(fp[23]),
  79. SW_REG(fp[24]), SW_REG(fp[25]), SW_REG(fp[26]), SW_REG(fp[27]),
  80. SW_REG(fp[28]), SW_REG(fp[29]), SW_REG(fp[30]), SW_REG(fp[31]),
  81. PT_REG( pc)
  82. };
  83. static unsigned long zero;
  84. /*
  85. * Get address of register REGNO in task TASK.
  86. */
  87. static unsigned long *
  88. get_reg_addr(struct task_struct * task, unsigned long regno)
  89. {
  90. unsigned long *addr;
  91. if (regno == 30) {
  92. addr = &task->thread_info->pcb.usp;
  93. } else if (regno == 65) {
  94. addr = &task->thread_info->pcb.unique;
  95. } else if (regno == 31 || regno > 65) {
  96. zero = 0;
  97. addr = &zero;
  98. } else {
  99. addr = (void *)task->thread_info + regoff[regno];
  100. }
  101. return addr;
  102. }
  103. /*
  104. * Get contents of register REGNO in task TASK.
  105. */
  106. static unsigned long
  107. get_reg(struct task_struct * task, unsigned long regno)
  108. {
  109. /* Special hack for fpcr -- combine hardware and software bits. */
  110. if (regno == 63) {
  111. unsigned long fpcr = *get_reg_addr(task, regno);
  112. unsigned long swcr
  113. = task->thread_info->ieee_state & IEEE_SW_MASK;
  114. swcr = swcr_update_status(swcr, fpcr);
  115. return fpcr | swcr;
  116. }
  117. return *get_reg_addr(task, regno);
  118. }
  119. /*
  120. * Write contents of register REGNO in task TASK.
  121. */
  122. static int
  123. put_reg(struct task_struct *task, unsigned long regno, unsigned long data)
  124. {
  125. if (regno == 63) {
  126. task->thread_info->ieee_state
  127. = ((task->thread_info->ieee_state & ~IEEE_SW_MASK)
  128. | (data & IEEE_SW_MASK));
  129. data = (data & FPCR_DYN_MASK) | ieee_swcr_to_fpcr(data);
  130. }
  131. *get_reg_addr(task, regno) = data;
  132. return 0;
  133. }
  134. static inline int
  135. read_int(struct task_struct *task, unsigned long addr, int * data)
  136. {
  137. int copied = access_process_vm(task, addr, data, sizeof(int), 0);
  138. return (copied == sizeof(int)) ? 0 : -EIO;
  139. }
  140. static inline int
  141. write_int(struct task_struct *task, unsigned long addr, int data)
  142. {
  143. int copied = access_process_vm(task, addr, &data, sizeof(int), 1);
  144. return (copied == sizeof(int)) ? 0 : -EIO;
  145. }
  146. /*
  147. * Set breakpoint.
  148. */
  149. int
  150. ptrace_set_bpt(struct task_struct * child)
  151. {
  152. int displ, i, res, reg_b, nsaved = 0;
  153. unsigned int insn, op_code;
  154. unsigned long pc;
  155. pc = get_reg(child, REG_PC);
  156. res = read_int(child, pc, (int *) &insn);
  157. if (res < 0)
  158. return res;
  159. op_code = insn >> 26;
  160. if (op_code >= 0x30) {
  161. /*
  162. * It's a branch: instead of trying to figure out
  163. * whether the branch will be taken or not, we'll put
  164. * a breakpoint at either location. This is simpler,
  165. * more reliable, and probably not a whole lot slower
  166. * than the alternative approach of emulating the
  167. * branch (emulation can be tricky for fp branches).
  168. */
  169. displ = ((s32)(insn << 11)) >> 9;
  170. child->thread_info->bpt_addr[nsaved++] = pc + 4;
  171. if (displ) /* guard against unoptimized code */
  172. child->thread_info->bpt_addr[nsaved++]
  173. = pc + 4 + displ;
  174. DBG(DBG_BPT, ("execing branch\n"));
  175. } else if (op_code == 0x1a) {
  176. reg_b = (insn >> 16) & 0x1f;
  177. child->thread_info->bpt_addr[nsaved++] = get_reg(child, reg_b);
  178. DBG(DBG_BPT, ("execing jump\n"));
  179. } else {
  180. child->thread_info->bpt_addr[nsaved++] = pc + 4;
  181. DBG(DBG_BPT, ("execing normal insn\n"));
  182. }
  183. /* install breakpoints: */
  184. for (i = 0; i < nsaved; ++i) {
  185. res = read_int(child, child->thread_info->bpt_addr[i],
  186. (int *) &insn);
  187. if (res < 0)
  188. return res;
  189. child->thread_info->bpt_insn[i] = insn;
  190. DBG(DBG_BPT, (" -> next_pc=%lx\n",
  191. child->thread_info->bpt_addr[i]));
  192. res = write_int(child, child->thread_info->bpt_addr[i],
  193. BREAKINST);
  194. if (res < 0)
  195. return res;
  196. }
  197. child->thread_info->bpt_nsaved = nsaved;
  198. return 0;
  199. }
  200. /*
  201. * Ensure no single-step breakpoint is pending. Returns non-zero
  202. * value if child was being single-stepped.
  203. */
  204. int
  205. ptrace_cancel_bpt(struct task_struct * child)
  206. {
  207. int i, nsaved = child->thread_info->bpt_nsaved;
  208. child->thread_info->bpt_nsaved = 0;
  209. if (nsaved > 2) {
  210. printk("ptrace_cancel_bpt: bogus nsaved: %d!\n", nsaved);
  211. nsaved = 2;
  212. }
  213. for (i = 0; i < nsaved; ++i) {
  214. write_int(child, child->thread_info->bpt_addr[i],
  215. child->thread_info->bpt_insn[i]);
  216. }
  217. return (nsaved != 0);
  218. }
  219. /*
  220. * Called by kernel/ptrace.c when detaching..
  221. *
  222. * Make sure the single step bit is not set.
  223. */
  224. void ptrace_disable(struct task_struct *child)
  225. {
  226. ptrace_cancel_bpt(child);
  227. }
  228. asmlinkage long
  229. do_sys_ptrace(long request, long pid, long addr, long data,
  230. struct pt_regs *regs)
  231. {
  232. struct task_struct *child;
  233. unsigned long tmp;
  234. size_t copied;
  235. long ret;
  236. lock_kernel();
  237. DBG(DBG_MEM, ("request=%ld pid=%ld addr=0x%lx data=0x%lx\n",
  238. request, pid, addr, data));
  239. ret = -EPERM;
  240. if (request == PTRACE_TRACEME) {
  241. /* are we already being traced? */
  242. if (current->ptrace & PT_PTRACED)
  243. goto out_notsk;
  244. ret = security_ptrace(current->parent, current);
  245. if (ret)
  246. goto out_notsk;
  247. /* set the ptrace bit in the process ptrace flags. */
  248. current->ptrace |= PT_PTRACED;
  249. ret = 0;
  250. goto out_notsk;
  251. }
  252. if (pid == 1) /* you may not mess with init */
  253. goto out_notsk;
  254. ret = -ESRCH;
  255. read_lock(&tasklist_lock);
  256. child = find_task_by_pid(pid);
  257. if (child)
  258. get_task_struct(child);
  259. read_unlock(&tasklist_lock);
  260. if (!child)
  261. goto out_notsk;
  262. if (request == PTRACE_ATTACH) {
  263. ret = ptrace_attach(child);
  264. goto out;
  265. }
  266. ret = ptrace_check_attach(child, request == PTRACE_KILL);
  267. if (ret < 0)
  268. goto out;
  269. switch (request) {
  270. /* When I and D space are separate, these will need to be fixed. */
  271. case PTRACE_PEEKTEXT: /* read word at location addr. */
  272. case PTRACE_PEEKDATA:
  273. copied = access_process_vm(child, addr, &tmp, sizeof(tmp), 0);
  274. ret = -EIO;
  275. if (copied != sizeof(tmp))
  276. break;
  277. regs->r0 = 0; /* special return: no errors */
  278. ret = tmp;
  279. break;
  280. /* Read register number ADDR. */
  281. case PTRACE_PEEKUSR:
  282. regs->r0 = 0; /* special return: no errors */
  283. ret = get_reg(child, addr);
  284. DBG(DBG_MEM, ("peek $%ld->%#lx\n", addr, ret));
  285. break;
  286. /* When I and D space are separate, this will have to be fixed. */
  287. case PTRACE_POKETEXT: /* write the word at location addr. */
  288. case PTRACE_POKEDATA:
  289. tmp = data;
  290. copied = access_process_vm(child, addr, &tmp, sizeof(tmp), 1);
  291. ret = (copied == sizeof(tmp)) ? 0 : -EIO;
  292. break;
  293. case PTRACE_POKEUSR: /* write the specified register */
  294. DBG(DBG_MEM, ("poke $%ld<-%#lx\n", addr, data));
  295. ret = put_reg(child, addr, data);
  296. break;
  297. case PTRACE_SYSCALL:
  298. /* continue and stop at next (return from) syscall */
  299. case PTRACE_CONT: /* restart after signal. */
  300. ret = -EIO;
  301. if ((unsigned long) data > _NSIG)
  302. break;
  303. if (request == PTRACE_SYSCALL)
  304. set_tsk_thread_flag(child, TIF_SYSCALL_TRACE);
  305. else
  306. clear_tsk_thread_flag(child, TIF_SYSCALL_TRACE);
  307. child->exit_code = data;
  308. /* make sure single-step breakpoint is gone. */
  309. ptrace_cancel_bpt(child);
  310. wake_up_process(child);
  311. ret = 0;
  312. break;
  313. /*
  314. * Make the child exit. Best I can do is send it a sigkill.
  315. * perhaps it should be put in the status that it wants to
  316. * exit.
  317. */
  318. case PTRACE_KILL:
  319. ret = 0;
  320. if (child->exit_state == EXIT_ZOMBIE)
  321. break;
  322. child->exit_code = SIGKILL;
  323. /* make sure single-step breakpoint is gone. */
  324. ptrace_cancel_bpt(child);
  325. wake_up_process(child);
  326. goto out;
  327. case PTRACE_SINGLESTEP: /* execute single instruction. */
  328. ret = -EIO;
  329. if ((unsigned long) data > _NSIG)
  330. break;
  331. /* Mark single stepping. */
  332. child->thread_info->bpt_nsaved = -1;
  333. clear_tsk_thread_flag(child, TIF_SYSCALL_TRACE);
  334. child->exit_code = data;
  335. wake_up_process(child);
  336. /* give it a chance to run. */
  337. ret = 0;
  338. goto out;
  339. case PTRACE_DETACH: /* detach a process that was attached. */
  340. ret = ptrace_detach(child, data);
  341. goto out;
  342. default:
  343. ret = ptrace_request(child, request, addr, data);
  344. goto out;
  345. }
  346. out:
  347. put_task_struct(child);
  348. out_notsk:
  349. unlock_kernel();
  350. return ret;
  351. }
  352. asmlinkage void
  353. syscall_trace(void)
  354. {
  355. if (!test_thread_flag(TIF_SYSCALL_TRACE))
  356. return;
  357. if (!(current->ptrace & PT_PTRACED))
  358. return;
  359. /* The 0x80 provides a way for the tracing parent to distinguish
  360. between a syscall stop and SIGTRAP delivery */
  361. ptrace_notify(SIGTRAP | ((current->ptrace & PT_TRACESYSGOOD)
  362. ? 0x80 : 0));
  363. /*
  364. * This isn't the same as continuing with a signal, but it will do
  365. * for normal use. strace only continues with a signal if the
  366. * stopping signal is not SIGTRAP. -brl
  367. */
  368. if (current->exit_code) {
  369. send_sig(current->exit_code, current, 1);
  370. current->exit_code = 0;
  371. }
  372. }