1997-12-20 18:40:43 +00:00
|
|
|
/*
|
|
|
|
* Copryight 1997 Sean Eric Fagan
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer.
|
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
|
|
|
* 3. All advertising materials mentioning features or use of this software
|
|
|
|
* must display the following acknowledgement:
|
|
|
|
* This product includes software developed by Sean Eric Fagan
|
|
|
|
* 4. Neither the name of the author may be used to endorse or promote
|
|
|
|
* products derived from this software without specific prior written
|
|
|
|
* permission.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
|
|
|
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
|
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
|
|
|
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
|
|
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
|
|
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
|
|
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
|
|
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
|
|
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
|
|
* SUCH DAMAGE.
|
|
|
|
*/
|
|
|
|
|
2003-09-07 15:50:43 +00:00
|
|
|
#include <sys/cdefs.h>
|
|
|
|
__FBSDID("$FreeBSD$");
|
1998-01-05 07:30:26 +00:00
|
|
|
|
1997-12-06 05:23:12 +00:00
|
|
|
/*
|
|
|
|
* Various setup functions for truss. Not the cleanest-written code,
|
|
|
|
* I'm afraid.
|
|
|
|
*/
|
|
|
|
|
2001-10-22 02:02:00 +00:00
|
|
|
#include <sys/param.h>
|
2007-04-10 04:03:34 +00:00
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/ptrace.h>
|
2001-10-22 02:02:00 +00:00
|
|
|
#include <sys/wait.h>
|
|
|
|
|
1998-01-05 07:30:26 +00:00
|
|
|
#include <err.h>
|
2007-04-10 04:03:34 +00:00
|
|
|
#include <errno.h>
|
1998-01-05 07:30:26 +00:00
|
|
|
#include <fcntl.h>
|
|
|
|
#include <signal.h>
|
1997-12-06 05:23:12 +00:00
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
#include <string.h>
|
2002-08-06 12:46:14 +00:00
|
|
|
#include <time.h>
|
1997-12-06 05:23:12 +00:00
|
|
|
#include <unistd.h>
|
|
|
|
|
2007-04-10 04:03:34 +00:00
|
|
|
#include <machine/reg.h>
|
|
|
|
|
2002-08-04 00:46:48 +00:00
|
|
|
#include "truss.h"
|
2001-12-11 23:34:02 +00:00
|
|
|
#include "extern.h"
|
|
|
|
|
2007-04-10 04:03:34 +00:00
|
|
|
static int child_pid;
|
1997-12-06 05:23:12 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* setup_and_wait() is called to start a process. All it really does
|
1998-10-13 14:52:33 +00:00
|
|
|
* is fork(), set itself up to stop on exec or exit, and then exec
|
1997-12-06 05:23:12 +00:00
|
|
|
* the given command. At that point, the child process stops, and
|
|
|
|
* the parent can wake up and deal with it.
|
|
|
|
*/
|
|
|
|
|
|
|
|
int
|
2005-03-27 12:47:04 +00:00
|
|
|
setup_and_wait(char *command[])
|
|
|
|
{
|
|
|
|
int pid;
|
2007-04-10 04:03:34 +00:00
|
|
|
int waitval;
|
2005-03-27 12:47:04 +00:00
|
|
|
|
2007-04-10 04:03:34 +00:00
|
|
|
pid = vfork();
|
2005-03-27 12:47:04 +00:00
|
|
|
if (pid == -1) {
|
|
|
|
err(1, "fork failed");
|
|
|
|
}
|
|
|
|
if (pid == 0) { /* Child */
|
2007-04-10 04:03:34 +00:00
|
|
|
ptrace(PT_TRACE_ME, 0, 0, 0);
|
|
|
|
setpgid (0, 0);
|
2005-03-27 12:47:04 +00:00
|
|
|
execvp(command[0], command);
|
2007-04-10 04:03:34 +00:00
|
|
|
err(1, "execvp %s", command[0]);
|
2005-03-27 12:47:04 +00:00
|
|
|
}
|
2007-04-10 04:03:34 +00:00
|
|
|
|
2005-03-27 12:47:04 +00:00
|
|
|
/* Only in the parent here */
|
2007-04-10 04:03:34 +00:00
|
|
|
if (waitpid(pid, &waitval, 0) < -1) {
|
|
|
|
err(1, "unexpect stop in waitpid");
|
|
|
|
return 0;
|
2005-03-27 12:47:04 +00:00
|
|
|
}
|
|
|
|
|
2007-04-10 04:03:34 +00:00
|
|
|
child_pid = pid;
|
|
|
|
|
2005-03-27 12:47:04 +00:00
|
|
|
return (pid);
|
1997-12-06 05:23:12 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* start_tracing picks up where setup_and_wait() dropped off -- namely,
|
|
|
|
* it sets the event mask for the given process id. Called for both
|
|
|
|
* monitoring an existing process and when we create our own.
|
|
|
|
*/
|
|
|
|
|
|
|
|
int
|
2007-04-10 04:03:34 +00:00
|
|
|
start_tracing(int pid)
|
2005-03-27 12:47:04 +00:00
|
|
|
{
|
2007-04-10 04:03:34 +00:00
|
|
|
int waitval;
|
|
|
|
int ret;
|
|
|
|
int retry = 10;
|
|
|
|
|
|
|
|
do {
|
|
|
|
ret = ptrace(PT_ATTACH, pid, NULL, 0);
|
|
|
|
usleep(200);
|
|
|
|
} while(ret && retry-- > 0);
|
|
|
|
if (ret)
|
|
|
|
err(1, "can not attach to target process");
|
|
|
|
|
|
|
|
child_pid = pid;
|
|
|
|
if (waitpid(pid, &waitval, 0) < -1)
|
|
|
|
err(1, "Unexpect stop in waitpid");
|
|
|
|
|
|
|
|
return (0);
|
1997-12-06 05:23:12 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Restore a process back to it's pre-truss state.
|
|
|
|
* Called for SIGINT, SIGTERM, SIGQUIT. This only
|
|
|
|
* applies if truss was told to monitor an already-existing
|
|
|
|
* process.
|
|
|
|
*/
|
|
|
|
void
|
2007-04-10 04:03:34 +00:00
|
|
|
restore_proc(int signo __unused)
|
|
|
|
{
|
|
|
|
int waitval;
|
1997-12-06 05:23:12 +00:00
|
|
|
|
2007-04-10 04:03:34 +00:00
|
|
|
/* stop the child so that we can detach */
|
|
|
|
kill(child_pid, SIGSTOP);
|
|
|
|
if (waitpid(child_pid, &waitval, 0) < -1)
|
|
|
|
err(1, "Unexpected stop in waitpid");
|
|
|
|
|
|
|
|
if (ptrace(PT_DETACH, child_pid, (caddr_t)1, 0) < 0)
|
|
|
|
err(1, "Can not detach the process");
|
|
|
|
|
|
|
|
kill(child_pid, SIGCONT);
|
2005-03-27 12:47:04 +00:00
|
|
|
exit(0);
|
1997-12-06 05:23:12 +00:00
|
|
|
}
|
2007-04-10 04:03:34 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Change curthread member based on lwpid.
|
|
|
|
* If it is a new thread, create a threadinfo structure
|
|
|
|
*/
|
|
|
|
static void
|
|
|
|
find_thread(struct trussinfo *info, lwpid_t lwpid)
|
|
|
|
{
|
|
|
|
info->curthread = NULL;
|
|
|
|
struct threadinfo *np;
|
|
|
|
SLIST_FOREACH(np, &info->threadlist, entries) {
|
|
|
|
if (np->tid == lwpid) {
|
|
|
|
info->curthread = np;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
np = (struct threadinfo *)malloc(sizeof(struct threadinfo));
|
|
|
|
if (np == NULL)
|
|
|
|
errx(1, "malloc() failed");
|
|
|
|
np->tid = lwpid;
|
|
|
|
np->in_fork = 0;
|
|
|
|
np->in_syscall = 0;
|
|
|
|
SLIST_INSERT_HEAD(&info->threadlist, np, entries);
|
|
|
|
info->curthread = np;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Start the traced process and wait until it stoped.
|
|
|
|
* Fill trussinfo structure.
|
|
|
|
* When this even returns, the traced process is in stop state.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
waitevent(struct trussinfo *info)
|
|
|
|
{
|
|
|
|
int waitval;
|
|
|
|
static int pending_signal = 0;
|
|
|
|
|
|
|
|
ptrace(PT_SYSCALL, info->pid, (caddr_t)1, pending_signal);
|
|
|
|
pending_signal = 0;
|
|
|
|
|
|
|
|
if (waitpid(info->pid, &waitval, 0) < -1) {
|
|
|
|
err(1, "Unexpected stop in waitpid");
|
|
|
|
}
|
|
|
|
|
|
|
|
if (WIFCONTINUED(waitval)) {
|
|
|
|
info->pr_why = S_NONE;
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
if (WIFEXITED(waitval)) {
|
|
|
|
info->pr_why = S_EXIT;
|
|
|
|
info->pr_data = WEXITSTATUS(waitval);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
if (WIFSTOPPED(waitval) || (WIFSIGNALED(waitval))) {
|
|
|
|
struct ptrace_lwpinfo lwpinfo;
|
|
|
|
ptrace(PT_LWPINFO, info->pid, (caddr_t)&lwpinfo, sizeof(lwpinfo));
|
|
|
|
find_thread(info, lwpinfo.pl_lwpid);
|
|
|
|
switch(WSTOPSIG(waitval)) {
|
|
|
|
case SIGTRAP:
|
|
|
|
info->pr_why = info->curthread->in_syscall?S_SCX:S_SCE;
|
|
|
|
info->curthread->in_syscall = 1 - info->curthread->in_syscall;
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
info->pr_why = S_SIG;
|
|
|
|
info->pr_data = WSTOPSIG(waitval);
|
|
|
|
pending_signal = info->pr_data;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|