ptrace.c 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597
  1. /*
  2. * Copyright (C) 2000-2003, Axis Communications AB.
  3. */
  4. #include <linux/kernel.h>
  5. #include <linux/sched.h>
  6. #include <linux/mm.h>
  7. #include <linux/smp.h>
  8. #include <linux/smp_lock.h>
  9. #include <linux/errno.h>
  10. #include <linux/ptrace.h>
  11. #include <linux/user.h>
  12. #include <linux/signal.h>
  13. #include <linux/security.h>
  14. #include <asm/uaccess.h>
  15. #include <asm/page.h>
  16. #include <asm/pgtable.h>
  17. #include <asm/system.h>
  18. #include <asm/processor.h>
  19. #include <asm/arch/hwregs/supp_reg.h>
  20. /*
  21. * Determines which bits in CCS the user has access to.
  22. * 1 = access, 0 = no access.
  23. */
  24. #define CCS_MASK 0x00087c00 /* SXNZVC */
  25. #define SBIT_USER (1 << (S_CCS_BITNR + CCS_SHIFT))
  26. static int put_debugreg(long pid, unsigned int regno, long data);
  27. static long get_debugreg(long pid, unsigned int regno);
  28. static unsigned long get_pseudo_pc(struct task_struct *child);
  29. void deconfigure_bp(long pid);
  30. extern unsigned long cris_signal_return_page;
  31. /*
  32. * Get contents of register REGNO in task TASK.
  33. */
  34. long get_reg(struct task_struct *task, unsigned int regno)
  35. {
  36. /* USP is a special case, it's not in the pt_regs struct but
  37. * in the tasks thread struct
  38. */
  39. unsigned long ret;
  40. if (regno <= PT_EDA)
  41. ret = ((unsigned long *)user_regs(task->thread_info))[regno];
  42. else if (regno == PT_USP)
  43. ret = task->thread.usp;
  44. else if (regno == PT_PPC)
  45. ret = get_pseudo_pc(task);
  46. else if (regno <= PT_MAX)
  47. ret = get_debugreg(task->pid, regno);
  48. else
  49. ret = 0;
  50. return ret;
  51. }
  52. /*
  53. * Write contents of register REGNO in task TASK.
  54. */
  55. int put_reg(struct task_struct *task, unsigned int regno, unsigned long data)
  56. {
  57. if (regno <= PT_EDA)
  58. ((unsigned long *)user_regs(task->thread_info))[regno] = data;
  59. else if (regno == PT_USP)
  60. task->thread.usp = data;
  61. else if (regno == PT_PPC) {
  62. /* Write pseudo-PC to ERP only if changed. */
  63. if (data != get_pseudo_pc(task))
  64. ((unsigned long *)user_regs(task->thread_info))[PT_ERP] = data;
  65. } else if (regno <= PT_MAX)
  66. return put_debugreg(task->pid, regno, data);
  67. else
  68. return -1;
  69. return 0;
  70. }
  71. /*
  72. * Called by kernel/ptrace.c when detaching.
  73. *
  74. * Make sure the single step bit is not set.
  75. */
  76. void
  77. ptrace_disable(struct task_struct *child)
  78. {
  79. unsigned long tmp;
  80. /* Deconfigure SPC and S-bit. */
  81. tmp = get_reg(child, PT_CCS) & ~SBIT_USER;
  82. put_reg(child, PT_CCS, tmp);
  83. put_reg(child, PT_SPC, 0);
  84. /* Deconfigure any watchpoints associated with the child. */
  85. deconfigure_bp(child->pid);
  86. }
  87. asmlinkage int
  88. sys_ptrace(long request, long pid, long addr, long data)
  89. {
  90. struct task_struct *child;
  91. int ret;
  92. unsigned long __user *datap = (unsigned long __user *)data;
  93. lock_kernel();
  94. ret = -EPERM;
  95. if (request == PTRACE_TRACEME) {
  96. /* are we already being traced? */
  97. if (current->ptrace & PT_PTRACED)
  98. goto out;
  99. ret = security_ptrace(current->parent, current);
  100. if (ret)
  101. goto out;
  102. /* set the ptrace bit in the process flags. */
  103. current->ptrace |= PT_PTRACED;
  104. ret = 0;
  105. goto out;
  106. }
  107. ret = -ESRCH;
  108. read_lock(&tasklist_lock);
  109. child = find_task_by_pid(pid);
  110. if (child)
  111. get_task_struct(child);
  112. read_unlock(&tasklist_lock);
  113. if (!child)
  114. goto out;
  115. ret = -EPERM;
  116. if (pid == 1) /* Leave the init process alone! */
  117. goto out_tsk;
  118. if (request == PTRACE_ATTACH) {
  119. ret = ptrace_attach(child);
  120. goto out_tsk;
  121. }
  122. ret = ptrace_check_attach(child, request == PTRACE_KILL);
  123. if (ret < 0)
  124. goto out_tsk;
  125. switch (request) {
  126. /* Read word at location address. */
  127. case PTRACE_PEEKTEXT:
  128. case PTRACE_PEEKDATA: {
  129. unsigned long tmp;
  130. int copied;
  131. ret = -EIO;
  132. /* The signal trampoline page is outside the normal user-addressable
  133. * space but still accessible. This is hack to make it possible to
  134. * access the signal handler code in GDB.
  135. */
  136. if ((addr & PAGE_MASK) == cris_signal_return_page) {
  137. /* The trampoline page is globally mapped, no page table to traverse.*/
  138. tmp = *(unsigned long*)addr;
  139. } else {
  140. copied = access_process_vm(child, addr, &tmp, sizeof(tmp), 0);
  141. if (copied != sizeof(tmp))
  142. break;
  143. }
  144. ret = put_user(tmp,datap);
  145. break;
  146. }
  147. /* Read the word at location address in the USER area. */
  148. case PTRACE_PEEKUSR: {
  149. unsigned long tmp;
  150. ret = -EIO;
  151. if ((addr & 3) || addr < 0 || addr > PT_MAX << 2)
  152. break;
  153. tmp = get_reg(child, addr >> 2);
  154. ret = put_user(tmp, datap);
  155. break;
  156. }
  157. /* Write the word at location address. */
  158. case PTRACE_POKETEXT:
  159. case PTRACE_POKEDATA:
  160. ret = 0;
  161. if (access_process_vm(child, addr, &data, sizeof(data), 1) == sizeof(data))
  162. break;
  163. ret = -EIO;
  164. break;
  165. /* Write the word at location address in the USER area. */
  166. case PTRACE_POKEUSR:
  167. ret = -EIO;
  168. if ((addr & 3) || addr < 0 || addr > PT_MAX << 2)
  169. break;
  170. addr >>= 2;
  171. if (addr == PT_CCS) {
  172. /* don't allow the tracing process to change stuff like
  173. * interrupt enable, kernel/user bit, dma enables etc.
  174. */
  175. data &= CCS_MASK;
  176. data |= get_reg(child, PT_CCS) & ~CCS_MASK;
  177. }
  178. if (put_reg(child, addr, data))
  179. break;
  180. ret = 0;
  181. break;
  182. case PTRACE_SYSCALL:
  183. case PTRACE_CONT:
  184. ret = -EIO;
  185. if (!valid_signal(data))
  186. break;
  187. /* Continue means no single-step. */
  188. put_reg(child, PT_SPC, 0);
  189. if (!get_debugreg(child->pid, PT_BP_CTRL)) {
  190. unsigned long tmp;
  191. /* If no h/w bp configured, disable S bit. */
  192. tmp = get_reg(child, PT_CCS) & ~SBIT_USER;
  193. put_reg(child, PT_CCS, tmp);
  194. }
  195. if (request == PTRACE_SYSCALL) {
  196. set_tsk_thread_flag(child, TIF_SYSCALL_TRACE);
  197. }
  198. else {
  199. clear_tsk_thread_flag(child, TIF_SYSCALL_TRACE);
  200. }
  201. child->exit_code = data;
  202. /* TODO: make sure any pending breakpoint is killed */
  203. wake_up_process(child);
  204. ret = 0;
  205. break;
  206. /* Make the child exit by sending it a sigkill. */
  207. case PTRACE_KILL:
  208. ret = 0;
  209. if (child->exit_state == EXIT_ZOMBIE)
  210. break;
  211. child->exit_code = SIGKILL;
  212. /* Deconfigure single-step and h/w bp. */
  213. ptrace_disable(child);
  214. /* TODO: make sure any pending breakpoint is killed */
  215. wake_up_process(child);
  216. break;
  217. /* Set the trap flag. */
  218. case PTRACE_SINGLESTEP: {
  219. unsigned long tmp;
  220. ret = -EIO;
  221. /* Set up SPC if not set already (in which case we have
  222. no other choice but to trust it). */
  223. if (!get_reg(child, PT_SPC)) {
  224. /* In case we're stopped in a delay slot. */
  225. tmp = get_reg(child, PT_ERP) & ~1;
  226. put_reg(child, PT_SPC, tmp);
  227. }
  228. tmp = get_reg(child, PT_CCS) | SBIT_USER;
  229. put_reg(child, PT_CCS, tmp);
  230. if (!valid_signal(data))
  231. break;
  232. clear_tsk_thread_flag(child, TIF_SYSCALL_TRACE);
  233. /* TODO: set some clever breakpoint mechanism... */
  234. child->exit_code = data;
  235. wake_up_process(child);
  236. ret = 0;
  237. break;
  238. }
  239. case PTRACE_DETACH:
  240. ret = ptrace_detach(child, data);
  241. break;
  242. /* Get all GP registers from the child. */
  243. case PTRACE_GETREGS: {
  244. int i;
  245. unsigned long tmp;
  246. for (i = 0; i <= PT_MAX; i++) {
  247. tmp = get_reg(child, i);
  248. if (put_user(tmp, datap)) {
  249. ret = -EFAULT;
  250. goto out_tsk;
  251. }
  252. datap++;
  253. }
  254. ret = 0;
  255. break;
  256. }
  257. /* Set all GP registers in the child. */
  258. case PTRACE_SETREGS: {
  259. int i;
  260. unsigned long tmp;
  261. for (i = 0; i <= PT_MAX; i++) {
  262. if (get_user(tmp, datap)) {
  263. ret = -EFAULT;
  264. goto out_tsk;
  265. }
  266. if (i == PT_CCS) {
  267. tmp &= CCS_MASK;
  268. tmp |= get_reg(child, PT_CCS) & ~CCS_MASK;
  269. }
  270. put_reg(child, i, tmp);
  271. datap++;
  272. }
  273. ret = 0;
  274. break;
  275. }
  276. default:
  277. ret = ptrace_request(child, request, addr, data);
  278. break;
  279. }
  280. out_tsk:
  281. put_task_struct(child);
  282. out:
  283. unlock_kernel();
  284. return ret;
  285. }
  286. void do_syscall_trace(void)
  287. {
  288. if (!test_thread_flag(TIF_SYSCALL_TRACE))
  289. return;
  290. if (!(current->ptrace & PT_PTRACED))
  291. return;
  292. /* the 0x80 provides a way for the tracing parent to distinguish
  293. between a syscall stop and SIGTRAP delivery */
  294. ptrace_notify(SIGTRAP | ((current->ptrace & PT_TRACESYSGOOD)
  295. ? 0x80 : 0));
  296. /*
  297. * This isn't the same as continuing with a signal, but it will do for
  298. * normal use.
  299. */
  300. if (current->exit_code) {
  301. send_sig(current->exit_code, current, 1);
  302. current->exit_code = 0;
  303. }
  304. }
  305. /* Returns the size of an instruction that has a delay slot. */
  306. static int insn_size(struct task_struct *child, unsigned long pc)
  307. {
  308. unsigned long opcode;
  309. int copied;
  310. int opsize = 0;
  311. /* Read the opcode at pc (do what PTRACE_PEEKTEXT would do). */
  312. copied = access_process_vm(child, pc, &opcode, sizeof(opcode), 0);
  313. if (copied != sizeof(opcode))
  314. return 0;
  315. switch ((opcode & 0x0f00) >> 8) {
  316. case 0x0:
  317. case 0x9:
  318. case 0xb:
  319. opsize = 2;
  320. break;
  321. case 0xe:
  322. case 0xf:
  323. opsize = 6;
  324. break;
  325. case 0xd:
  326. /* Could be 4 or 6; check more bits. */
  327. if ((opcode & 0xff) == 0xff)
  328. opsize = 4;
  329. else
  330. opsize = 6;
  331. break;
  332. default:
  333. panic("ERROR: Couldn't find size of opcode 0x%lx at 0x%lx\n",
  334. opcode, pc);
  335. }
  336. return opsize;
  337. }
  338. static unsigned long get_pseudo_pc(struct task_struct *child)
  339. {
  340. /* Default value for PC is ERP. */
  341. unsigned long pc = get_reg(child, PT_ERP);
  342. if (pc & 0x1) {
  343. unsigned long spc = get_reg(child, PT_SPC);
  344. /* Delay slot bit set. Report as stopped on proper
  345. instruction. */
  346. if (spc) {
  347. /* Rely on SPC if set. FIXME: We might want to check
  348. that EXS indicates we stopped due to a single-step
  349. exception. */
  350. pc = spc;
  351. } else {
  352. /* Calculate the PC from the size of the instruction
  353. that the delay slot we're in belongs to. */
  354. pc += insn_size(child, pc & ~1) - 1;
  355. }
  356. }
  357. return pc;
  358. }
  359. static long bp_owner = 0;
  360. /* Reachable from exit_thread in signal.c, so not static. */
  361. void deconfigure_bp(long pid)
  362. {
  363. int bp;
  364. /* Only deconfigure if the pid is the owner. */
  365. if (bp_owner != pid)
  366. return;
  367. for (bp = 0; bp < 6; bp++) {
  368. unsigned long tmp;
  369. /* Deconfigure start and end address (also gets rid of ownership). */
  370. put_debugreg(pid, PT_BP + 3 + (bp * 2), 0);
  371. put_debugreg(pid, PT_BP + 4 + (bp * 2), 0);
  372. /* Deconfigure relevant bits in control register. */
  373. tmp = get_debugreg(pid, PT_BP_CTRL) & ~(3 << (2 + (bp * 4)));
  374. put_debugreg(pid, PT_BP_CTRL, tmp);
  375. }
  376. /* No owner now. */
  377. bp_owner = 0;
  378. }
  379. static int put_debugreg(long pid, unsigned int regno, long data)
  380. {
  381. int ret = 0;
  382. register int old_srs;
  383. #ifdef CONFIG_ETRAX_KGDB
  384. /* Ignore write, but pretend it was ok if value is 0
  385. (we don't want POKEUSR/SETREGS failing unnessecarily). */
  386. return (data == 0) ? ret : -1;
  387. #endif
  388. /* Simple owner management. */
  389. if (!bp_owner)
  390. bp_owner = pid;
  391. else if (bp_owner != pid) {
  392. /* Ignore write, but pretend it was ok if value is 0
  393. (we don't want POKEUSR/SETREGS failing unnessecarily). */
  394. return (data == 0) ? ret : -1;
  395. }
  396. /* Remember old SRS. */
  397. SPEC_REG_RD(SPEC_REG_SRS, old_srs);
  398. /* Switch to BP bank. */
  399. SUPP_BANK_SEL(BANK_BP);
  400. switch (regno - PT_BP) {
  401. case 0:
  402. SUPP_REG_WR(0, data); break;
  403. case 1:
  404. case 2:
  405. if (data)
  406. ret = -1;
  407. break;
  408. case 3:
  409. SUPP_REG_WR(3, data); break;
  410. case 4:
  411. SUPP_REG_WR(4, data); break;
  412. case 5:
  413. SUPP_REG_WR(5, data); break;
  414. case 6:
  415. SUPP_REG_WR(6, data); break;
  416. case 7:
  417. SUPP_REG_WR(7, data); break;
  418. case 8:
  419. SUPP_REG_WR(8, data); break;
  420. case 9:
  421. SUPP_REG_WR(9, data); break;
  422. case 10:
  423. SUPP_REG_WR(10, data); break;
  424. case 11:
  425. SUPP_REG_WR(11, data); break;
  426. case 12:
  427. SUPP_REG_WR(12, data); break;
  428. case 13:
  429. SUPP_REG_WR(13, data); break;
  430. case 14:
  431. SUPP_REG_WR(14, data); break;
  432. default:
  433. ret = -1;
  434. break;
  435. }
  436. /* Restore SRS. */
  437. SPEC_REG_WR(SPEC_REG_SRS, old_srs);
  438. /* Just for show. */
  439. NOP();
  440. NOP();
  441. NOP();
  442. return ret;
  443. }
  444. static long get_debugreg(long pid, unsigned int regno)
  445. {
  446. register int old_srs;
  447. register long data;
  448. if (pid != bp_owner) {
  449. return 0;
  450. }
  451. /* Remember old SRS. */
  452. SPEC_REG_RD(SPEC_REG_SRS, old_srs);
  453. /* Switch to BP bank. */
  454. SUPP_BANK_SEL(BANK_BP);
  455. switch (regno - PT_BP) {
  456. case 0:
  457. SUPP_REG_RD(0, data); break;
  458. case 1:
  459. case 2:
  460. /* error return value? */
  461. data = 0;
  462. break;
  463. case 3:
  464. SUPP_REG_RD(3, data); break;
  465. case 4:
  466. SUPP_REG_RD(4, data); break;
  467. case 5:
  468. SUPP_REG_RD(5, data); break;
  469. case 6:
  470. SUPP_REG_RD(6, data); break;
  471. case 7:
  472. SUPP_REG_RD(7, data); break;
  473. case 8:
  474. SUPP_REG_RD(8, data); break;
  475. case 9:
  476. SUPP_REG_RD(9, data); break;
  477. case 10:
  478. SUPP_REG_RD(10, data); break;
  479. case 11:
  480. SUPP_REG_RD(11, data); break;
  481. case 12:
  482. SUPP_REG_RD(12, data); break;
  483. case 13:
  484. SUPP_REG_RD(13, data); break;
  485. case 14:
  486. SUPP_REG_RD(14, data); break;
  487. default:
  488. /* error return value? */
  489. data = 0;
  490. }
  491. /* Restore SRS. */
  492. SPEC_REG_WR(SPEC_REG_SRS, old_srs);
  493. /* Just for show. */
  494. NOP();
  495. NOP();
  496. NOP();
  497. return data;
  498. }