]> git.saurik.com Git - apple/xnu.git/blob - tools/lldbmacros/userspace.py
4b4dd7ae5b7f324d9d05b9eeebc2a8581404a806
[apple/xnu.git] / tools / lldbmacros / userspace.py
1 from xnu import *
2 from utils import *
3 from process import *
4 from pmap import *
5 import struct
6
7 def GetBinaryNameForPC(pc_val, user_lib_info = None):
8 """ find the binary in user_lib_info that the passed pc_val falls in range of.
9 params:
10 pc_val : int - integer form of the pc address
11 user_lib_info: [] of [] which hold start, end, binary name
12 returns:
13 str - Name of binary or "unknown" if not found.
14 """
15 retval = "unknown"
16 if not user_lib_info:
17 return retval
18 matches = []
19 for info in user_lib_info:
20 if pc_val >= info[0] and pc_val <= info[1]:
21 matches.append((pc_val - info[0], info[2]))
22 matches.sort()
23 if matches:
24 retval = matches[0][1]
25 return retval
26
27 def ShowX86UserStack(thread, user_lib_info = None):
28 """ Display user space stack frame and pc addresses.
29 params:
30 thread: obj referencing thread value
31 returns:
32 Nothing
33 """
34 iss = Cast(thread.machine.iss, 'x86_saved_state_t *')
35 abi = int(iss.flavor)
36 user_ip = 0
37 user_frame = 0
38 user_abi_ret_offset = 0
39 if abi == 0xf:
40 debuglog("User process is 64 bit")
41 user_ip = iss.uss.ss_64.isf.rip
42 user_frame = iss.uss.ss_64.rbp
43 user_abi_ret_offset = 8
44 user_abi_type = "uint64_t"
45 else:
46 debuglog("user process is 32 bit")
47 user_ip = iss.uss.ss_32.eip
48 user_frame = iss.uss.ss_32.ebp
49 user_abi_ret_offset = 4
50 user_abi_type = "uint32_t"
51
52 if user_ip == 0:
53 print "This activation does not appear to have a valid user context."
54 return False
55
56 cur_ip = user_ip
57 cur_frame = user_frame
58 debuglog("ip= 0x%x , fr = 0x%x " % (cur_ip, cur_frame))
59
60 frameformat = "{0:d} FP: 0x{1:x} PC: 0x{2:x}"
61 if user_lib_info is not None:
62 frameformat = "{0:d} {3: <30s} 0x{2:x}"
63 print frameformat.format(0, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))
64
65 print kern.Symbolicate(cur_ip)
66
67 frameno = 0
68 while True:
69 frameno = frameno + 1
70 frame = GetUserDataAsString(thread.task, unsigned(cur_frame), user_abi_ret_offset*2)
71 cur_ip = _ExtractDataFromString(frame, user_abi_ret_offset, user_abi_type)
72 cur_frame = _ExtractDataFromString(frame, 0, user_abi_type)
73 if not cur_frame or cur_frame == 0x0000000800000008:
74 break
75 print frameformat.format(frameno, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))
76 print kern.Symbolicate(cur_ip)
77 return
78
79 def _PrintARMUserStack(task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=None):
80 if cur_pc == 0:
81 "No valid user context for this activation."
82 return
83 frameno = 0
84 print frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))
85 while True:
86 frameno = frameno + 1
87 frame = GetUserDataAsString(task, cur_fp, framesize)
88 cur_fp = _ExtractDataFromString(frame, 0, frametype)
89 cur_pc = _ExtractDataFromString(frame, (framesize / 2), frametype)
90 if not cur_fp:
91 break
92 print frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))
93
94 def ShowARMUserStack(thread, user_lib_info = None):
95 cur_pc = unsigned(thread.machine.PcbData.pc)
96 cur_fp = unsigned(thread.machine.PcbData.r[7])
97 frameformat = "{0:>2d} FP: 0x{1:x} PC: 0x{2:x}"
98 if user_lib_info is not None:
99 frameformat = "{0:>2d} {3: <30s} 0x{2:0>8x}"
100 framesize = 8
101 frametype = "uint32_t"
102 _PrintARMUserStack(thread.task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=user_lib_info)
103
104 def ShowARM64UserStack(thread, user_lib_info = None):
105 SAVED_STATE_FLAVOR_ARM=20
106 SAVED_STATE_FLAVOR_ARM64=21
107 upcb = thread.machine.upcb
108 flavor = upcb.ash.flavor
109 frameformat = "{0:>2d} FP: 0x{1:x} PC: 0x{2:x}"
110 if flavor == SAVED_STATE_FLAVOR_ARM64:
111 cur_pc = unsigned(upcb.uss.ss_64.pc)
112 cur_fp = unsigned(upcb.uss.ss_64.fp)
113 if user_lib_info is not None:
114 frameformat = "{0:>2d} {3: <30s} 0x{2:x}"
115 framesize = 16
116 frametype = "uint64_t"
117 elif flavor == SAVED_STATE_FLAVOR_ARM:
118 cur_pc = unsigned(upcb.uss.ss_32.pc)
119 cur_fp = unsigned(upcb.uss.ss_32.r[7])
120 if user_lib_info is not None:
121 frameformat = "{0:>2d}: {3: <30s} 0x{2:x}"
122 framesize = 8
123 frametype = "uint32_t"
124 else:
125 raise RuntimeError("Thread {0} has an invalid flavor {1}".format(unsigned(thread), flavor))
126
127 _PrintARMUserStack(thread.task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=user_lib_info)
128
129
130 @lldb_command('showthreaduserstack')
131 def ShowThreadUserStack(cmd_args=None):
132 """ Show user stack for a given thread.
133 Syntax: (lldb) showthreaduserstack <thread_ptr>
134 """
135 if not cmd_args:
136 raise ArgumentError("Insufficient arguments")
137
138 thread = kern.GetValueFromAddress(ArgumentStringToInt(cmd_args[0]), 'thread *')
139 if kern.arch == "x86_64":
140 ShowX86UserStack(thread)
141 elif kern.arch == "arm":
142 ShowARMUserStack(thread)
143 elif kern.arch == "arm64":
144 ShowARM64UserStack(thread)
145 return True
146
147 @lldb_command('printuserdata','XO:')
148 def PrintUserspaceData(cmd_args=None, cmd_options={}):
149 """ Read userspace data for given task and print based on format provided.
150 Syntax: (lldb) printuserdata <task_t> <uspace_address> <format_specifier>
151 params:
152 <task_t> : pointer to task
153 <uspace_address> : address to user space memory
154 <format_specifier> : String representation for processing the data and printing it.
155 e.g Q -> unsigned long long, q -> long long, I -> unsigned int, i -> int
156 10i -> 10 ints, 20s -> 20 character string, s -> null terminated string
157 See: https://docs.python.org/2/library/struct.html#format-characters
158 options:
159 -X : print all values in hex.
160 -O <file path>: Save data to file
161 """
162
163 if not cmd_args or len(cmd_args) < 3:
164 raise ArgumentError("Insufficient arguments")
165 task = kern.GetValueFromAddress(cmd_args[0], 'task *')
166 uspace_addr = ArgumentStringToInt(cmd_args[1])
167 format_specifier_str = cmd_args[2]
168 user_data_len = 0
169 if format_specifier_str == "s":
170 print "0x%x: " % uspace_addr + GetUserspaceString(task, uspace_addr)
171 return True
172
173 try:
174 user_data_len = struct.calcsize(format_specifier_str)
175 except Exception, e:
176 raise ArgumentError("Invalid format specifier provided.")
177
178 user_data_string = GetUserDataAsString(task, uspace_addr, user_data_len)
179 if not user_data_string:
180 print "Could not read any data from userspace address."
181 return False
182 if "-O" in cmd_options:
183 fh = open(cmd_options["-O"],"w")
184 fh.write(user_data_string)
185 fh.close()
186 print "Written %d bytes to %s." % (user_data_len, cmd_options['-O'])
187 return True
188 upacked_data = struct.unpack(format_specifier_str, user_data_string)
189 element_size = user_data_len / len(upacked_data)
190 for i in range(len(upacked_data)):
191 if "-X" in cmd_options:
192 print "0x%x: " % (uspace_addr + i*element_size) + hex(upacked_data[i])
193 else:
194 print "0x%x: " % (uspace_addr + i*element_size) + str(upacked_data[i])
195
196 return True
197
198
199 @lldb_command('showtaskuserargs')
200 def ShowTaskUserArgs(cmd_args=None, cmd_options={}):
201 """ Read the process argv, env, and apple strings from the user stack
202 Syntax: (lldb) showtaskuserargs <task_t>
203 params:
204 <task_t> : pointer to task
205 """
206 if not cmd_args or len(cmd_args) != 1:
207 raise ArgumentError("Insufficient arguments")
208
209 task = kern.GetValueFromAddress(cmd_args[0], 'task *')
210 proc = Cast(task.bsd_info, 'proc *')
211
212 format_string = "Q" if kern.ptrsize == 8 else "I"
213
214 string_area_size = proc.p_argslen
215 string_area_addr = proc.user_stack - string_area_size
216
217 string_area = GetUserDataAsString(task, string_area_addr, string_area_size)
218 if not string_area:
219 print "Could not read any data from userspace address."
220 return False
221
222 i = 0
223 pos = string_area_addr - kern.ptrsize
224
225 for name in ["apple", "env", "argv"] :
226 while True:
227 if name == "argv" :
228 if i == proc.p_argc:
229 break
230 i += 1
231
232 pos -= kern.ptrsize
233
234 user_data_string = GetUserDataAsString(task, pos, kern.ptrsize)
235 ptr = struct.unpack(format_string, user_data_string)[0]
236
237 if ptr == 0:
238 break
239
240 if string_area_addr <= ptr and ptr < string_area_addr+string_area_size :
241 string_offset = ptr - string_area_addr
242 string = string_area[string_offset:];
243 else:
244 string = GetUserspaceString(task, ptr)
245
246 print name + "[]: " + string
247
248 return True
249
250
251 @lldb_command('showtaskuserstacks')
252 def ShowTaskUserStacks(cmd_args=None):
253 """ Print out the user stack for each thread in a task, followed by the user libraries.
254 Syntax: (lldb) showtaskuserstacks <task_t>
255 The format is compatible with CrashTracer. You can also use the speedtracer plugin as follows
256 (lldb) showtaskuserstacks <task_t> -p speedtracer
257
258 Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures
259 and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate
260 """
261 if not cmd_args:
262 raise ArgumentError("Insufficient arguments")
263
264 task = kern.GetValueFromAddress(cmd_args[0], 'task *')
265 #print GetTaskSummary.header + " " + GetProcSummary.header
266 pval = Cast(task.bsd_info, 'proc *')
267 #print GetTaskSummary(task) + " " + GetProcSummary(pval) + "\n \n"
268 crash_report_format_string = """\
269 Process: {pid: <10d}
270 Path: {path: <50s}
271 Identifier: {pname: <30s}
272 Version: ??? (???)
273 Code Type: {parch: <20s}
274 Parent Process: {ppname: >20s}[{ppid:d}]
275
276 Date/Time: {timest:s}.000 -0800
277 OS Version: {osversion: <20s}
278 Report Version: 8
279
280 Exception Type: n/a
281 Exception Codes: n/a
282 Crashed Thread: 0
283
284 Application Specific Information:
285 Synthetic crash log generated from Kernel userstacks
286
287 """
288 user_lib_rex = re.compile("([0-9a-fx]+)\s-\s([0-9a-fx]+)\s+(.*?)\s", re.IGNORECASE|re.MULTILINE)
289 from datetime import datetime
290 ts = datetime.fromtimestamp(int(pval.p_start.tv_sec))
291 date_string = ts.strftime('%Y-%m-%d %H:%M:%S')
292 is_64 = False
293 if pval.p_flag & 0x4 :
294 is_64 = True
295
296 parch_s = ""
297 if kern.arch == "x86_64" or kern.arch == "i386":
298 osversion = "Mac OS X 10.8"
299 parch_s = "I386 (32 bit)"
300 if is_64:
301 parch_s = "X86-64 (Native)"
302 else:
303 parch_s = kern.arch
304 osversion = "iOS"
305 osversion += " ({:s})".format(kern.globals.osversion)
306 print crash_report_format_string.format(pid = pval.p_pid,
307 pname = pval.p_comm,
308 path = pval.p_comm,
309 ppid = pval.p_ppid,
310 ppname = GetProcNameForPid(pval.p_ppid),
311 timest = date_string,
312 parch = parch_s,
313 osversion = osversion
314
315 )
316 print "Binary Images:"
317 ShowTaskUserLibraries([hex(task)])
318 usertask_lib_info = [] # will host [startaddr, endaddr, lib_name] entries
319 for entry in ShowTaskUserLibraries.found_images:
320 #print "processing line %s" % line
321 arr = user_lib_rex.findall(entry[3])
322 #print "%r" % arr
323 if len(arr) == 0 :
324 continue
325 usertask_lib_info.append([int(arr[0][0],16), int(arr[0][1],16), str(arr[0][2]).strip()])
326
327 printthread_user_stack_ptr = ShowX86UserStack
328 if kern.arch == "arm":
329 printthread_user_stack_ptr = ShowARMUserStack
330 elif kern.arch =="arm64":
331 printthread_user_stack_ptr = ShowARM64UserStack
332
333 counter = 0
334 for thval in IterateQueue(task.threads, 'thread *', 'task_threads'):
335 print "\nThread {0:d} name:0x{1:x}\nThread {0:d}:".format(counter, thval)
336 counter += 1
337 try:
338 printthread_user_stack_ptr(thval, usertask_lib_info)
339 except Exception as exc_err:
340 print "Failed to show user stack for thread 0x{0:x}".format(thval)
341 if config['debug']:
342 raise exc_err
343 else:
344 print "Enable debugging ('(lldb) xnudebug debug') to see detailed trace."
345 return
346
347
348 def GetUserDataAsString(task, addr, size):
349 """ Get data from task's address space as a string of bytes
350 params:
351 task: task object from which to extract information
352 addr: int - start address to get data from.
353 size: int - no of bytes to read.
354 returns:
355 str - a stream of bytes. Empty string if read fails.
356 """
357 err = lldb.SBError()
358 if GetConnectionProtocol() == "kdp":
359 kdp_pmap_addr = unsigned(addressof(kern.globals.kdp_pmap))
360 if not WriteInt64ToMemoryAddress(unsigned(task.map.pmap), kdp_pmap_addr):
361 debuglog("Failed to write in kdp_pmap from GetUserDataAsString.")
362 return ""
363 content = LazyTarget.GetProcess().ReadMemory(addr, size, err)
364 if not err.Success():
365 debuglog("Failed to read process memory. Error: " + err.description)
366 return ""
367 if not WriteInt64ToMemoryAddress(0, kdp_pmap_addr):
368 debuglog("Failed to reset in kdp_pmap from GetUserDataAsString.")
369 return ""
370 elif kern.arch in ['arm', 'arm64', 'x86_64'] and long(size) < (2 * kern.globals.page_size):
371 # Without the benefit of a KDP stub on the target, try to
372 # find the user task's physical mapping and memcpy the data.
373 # If it straddles a page boundary, copy in two passes
374 range1_addr = long(addr)
375 range1_size = long(size)
376 if kern.StraddlesPage(range1_addr, range1_size):
377 range2_addr = long(kern.TruncPage(range1_addr + range1_size))
378 range2_size = long(range1_addr + range1_size - range2_addr)
379 range1_size = long(range2_addr - range1_addr)
380 else:
381 range2_addr = 0
382 range2_size = 0
383 range2_in_kva = 0
384
385 paddr_range1 = PmapWalk(task.map.pmap, range1_addr, vSILENT)
386 if not paddr_range1:
387 debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr))
388 return ""
389
390 range1_in_kva = kern.PhysToKernelVirt(paddr_range1)
391 content = LazyTarget.GetProcess().ReadMemory(range1_in_kva, range1_size, err)
392 if not err.Success():
393 raise RuntimeError("Failed to read process memory. Error: " + err.description)
394
395 if range2_addr:
396 paddr_range2 = PmapWalk(task.map.pmap, range2_addr, vSILENT)
397 if not paddr_range2:
398 debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr))
399 return ""
400 range2_in_kva = kern.PhysToKernelVirt(paddr_range2)
401 content += LazyTarget.GetProcess().ReadMemory(range2_in_kva, range2_size, err)
402 if not err.Success():
403 raise RuntimeError("Failed to read process memory. Error: " + err.description)
404 else:
405 raise NotImplementedError("GetUserDataAsString does not support this configuration")
406
407 return content
408
409 def _ExtractDataFromString(strdata, offset, data_type, length=0):
410 """ Extract specific data from string buffer
411 params:
412 strdata: str - string data give from GetUserDataAsString
413 offset: int - 0 based offset into the data.
414 data_type: str - defines what type to be read as. Supported values are:
415 'uint64_t', 'uint32_t', 'string'
416 length: int - used when data_type=='string'
417 returns
418 None - if extraction failed.
419 obj - based on what is requested in data_type
420 """
421 unpack_str = "s"
422 if data_type == 'uint64_t':
423 length = 8
424 unpack_str = "Q"
425 elif data_type == "uint32_t":
426 length = 4
427 unpack_str = "I"
428 else:
429 unpack_str= "%ds" % length
430
431 data_len = len(strdata)
432 if offset > data_len or (offset + length) > data_len or offset < 0:
433 debuglog("Invalid arguments to _ExtractDataFromString.")
434 return 0
435 return struct.unpack(unpack_str, strdata[offset:(offset + length)])[0]
436
437 def GetUserspaceString(task, string_address):
438 """ Maps 32 bytes at a time and packs as string
439 params:
440 task: obj - referencing task to read data from
441 string_address: int - address where the image path is stored
442 returns:
443 str - string path of the file. "" if failed to read.
444 """
445 done = False
446 retval = ""
447
448 if string_address == 0:
449 done = True
450
451 while not done:
452 str_data = GetUserDataAsString(task, string_address, 32)
453 if len(str_data) == 0:
454 break
455 i = 0
456 while i < 32:
457 if ord(str_data[i]):
458 retval += str_data[i]
459 else:
460 break
461 i += 1
462 if i < 32:
463 done = True
464 else:
465 string_address += 32
466 return retval
467
468 def GetImageInfo(task, mh_image_address, mh_path_address, approx_end_address=None):
469 """ Print user library informaiton.
470 params:
471 task : obj referencing the task for which Image info printed
472 mh_image_address : int - address which has image info
473 mh_path_address : int - address which holds path name string
474 approx_end_address: int - address which lldbmacros think is end address.
475 returns:
476 str - string representing image info. "" if failure to read data.
477 """
478 if approx_end_address:
479 image_end_load_address = int(approx_end_address) -1
480 else:
481 image_end_load_address = int(mh_image_address) + 0xffffffff
482
483 print_format = "0x{0:x} - 0x{1:x} {2: <50s} (??? - ???) <{3: <36s}> {4: <50s}"
484 # 32 bytes enough for mach_header/mach_header_64
485 mh_data = GetUserDataAsString(task, mh_image_address, 32)
486 if len(mh_data) == 0:
487 debuglog("unable to get userdata for task 0x{:x} img_addr 0x{:x} path_address 0x{:x}".format(
488 task, mh_image_address, mh_path_address))
489 return ""
490 mh_magic = _ExtractDataFromString(mh_data, (4 * 0), "uint32_t")
491 mh_cputype = _ExtractDataFromString(mh_data,(4 * 1), "uint32_t")
492 mh_cpusubtype = _ExtractDataFromString(mh_data,(4 * 2), "uint32_t")
493 mh_filetype = _ExtractDataFromString(mh_data,(4 * 3), "uint32_t")
494 mh_ncmds = _ExtractDataFromString(mh_data,(4 * 4), "uint32_t")
495 mh_sizeofcmds = _ExtractDataFromString(mh_data,(4 * 5), "uint32_t")
496 mh_flags = _ExtractDataFromString(mh_data,(4 * 6), "uint32_t")
497
498 if mh_magic == 0xfeedfacf:
499 mh_64 = True
500 lc_address = mh_image_address + 32
501 else:
502 mh_64 = False
503 lc_address = mh_image_address + 28
504
505 lc_idx = 0
506 uuid_data = 0
507 found_uuid_data = False
508 retval = None
509 while lc_idx < mh_ncmds:
510 # 24 bytes is the size of uuid_command
511 lcmd_data = GetUserDataAsString(task, lc_address, 24)
512 lc_cmd = _ExtractDataFromString(lcmd_data, 4 * 0, "uint32_t")
513 lc_cmd_size = _ExtractDataFromString(lcmd_data, 4 * 1, "uint32_t")
514 lc_data = _ExtractDataFromString(lcmd_data, 4*2, "string", 16)
515
516 uuid_out_string = ""
517 path_out_string = ""
518
519 if lc_cmd == 0x1b:
520 # need to print the uuid now.
521 uuid_data = [ord(x) for x in lc_data]
522 found_uuid_data = True
523 uuid_out_string = "{a[0]:02X}{a[1]:02X}{a[2]:02X}{a[3]:02X}-{a[4]:02X}{a[5]:02X}-{a[6]:02X}{a[7]:02X}-{a[8]:02X}{a[9]:02X}-{a[10]:02X}{a[11]:02X}{a[12]:02X}{a[13]:02X}{a[14]:02X}{a[15]:02X}".format(a=uuid_data)
524 #also print image path
525 path_out_string = GetUserspaceString(task, mh_path_address)
526 path_base_name = path_out_string.split("/")[-1]
527 retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string)
528 elif lc_cmd == 0xe:
529 ShowTaskUserLibraries.exec_load_path = lc_address + _ExtractDataFromString(lcmd_data, 4*2, "uint32_t")
530 debuglog("Found load command to be 0xe for address %s" % hex(ShowTaskUserLibraries.exec_load_path))
531 lc_address = lc_address + lc_cmd_size
532 lc_idx += 1
533
534 if not found_uuid_data:
535 path_out_string = GetUserspaceString(task, mh_path_address)
536 path_base_name = path_out_string.split("/")[-1]
537 uuid_out_string = ""
538
539 retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string)
540 return retval
541
542 @static_var("found_images", []) # holds entries of format (startaddr, endaddr, image_path_addr, infostring)
543 @static_var("exec_load_path", 0)
544 @lldb_command("showtaskuserlibraries")
545 def ShowTaskUserLibraries(cmd_args=None):
546 """ Show binary images known by dyld in target task
547 For a given user task, inspect the dyld shared library state and print information about all Mach-O images.
548 Syntax: (lldb)showtaskuserlibraries <task_t>
549 Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures
550 and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate
551 """
552 if not cmd_args:
553 raise ArgumentError("Insufficient arguments")
554
555 #reset the found_images array
556 ShowTaskUserLibraries.found_images = []
557
558 task = kern.GetValueFromAddress(cmd_args[0], 'task_t')
559 is_task_64 = int(task.t_flags) & 0x1
560 dyld_all_image_infos_address = unsigned(task.all_image_info_addr)
561 debuglog("dyld_all_image_infos_address = %s" % hex(dyld_all_image_infos_address))
562
563 cur_data_offset = 0
564 if dyld_all_image_infos_address == 0:
565 print "No dyld shared library information available for task"
566 return False
567
568 debuglog("Extracting version information.")
569 vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112)
570 version = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t")
571 cur_data_offset += 4
572 if version > 14:
573 print "Unknown dyld all_image_infos version number %d" % version
574 image_info_count = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t")
575 debuglog("version = %d count = %d is_task_64 = %s" % (version, image_info_count, repr(is_task_64)))
576
577 ShowTaskUserLibraries.exec_load_path = 0
578 if is_task_64:
579 image_info_size = 24
580 image_info_array_address = _ExtractDataFromString(vers_info_data, 8, "uint64_t")
581 dyld_load_address = _ExtractDataFromString(vers_info_data, 8*4, "uint64_t")
582 dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 8*13, "uint64_t")
583 else:
584 image_info_size = 12
585 image_info_array_address = _ExtractDataFromString(vers_info_data, 4*2, "uint32_t")
586 dyld_load_address = _ExtractDataFromString(vers_info_data, 4*5, "uint32_t")
587 dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 4*14, "uint32_t")
588 # Account for ASLR slide before dyld can fix the structure
589 dyld_load_address = dyld_load_address + (dyld_all_image_infos_address - dyld_all_image_infos_address_from_struct)
590
591 i = 0
592 image_info_list = []
593 while i < image_info_count:
594 image_info_address = image_info_array_address + i * image_info_size
595 debuglog("i = %d, image_info_address = %s, image_info_size = %d" % (i, hex(image_info_address), image_info_size))
596 n_im_info_addr = None
597 img_data = ""
598 try:
599 img_data = GetUserDataAsString(task, image_info_address, image_info_size)
600 except Exception, e:
601 debuglog("Failed to read user data for task 0x{:x} addr 0x{:x}, exception {:s}".format(task, image_info_address, str(e)))
602 pass
603
604 if is_task_64:
605 image_info_addr = _ExtractDataFromString(img_data, 0, "uint64_t")
606 image_info_path = _ExtractDataFromString(img_data, 8, "uint64_t")
607 else:
608 image_info_addr = _ExtractDataFromString(img_data, 0, "uint32_t")
609 image_info_path = _ExtractDataFromString(img_data, 4, "uint32_t")
610
611 if image_info_addr :
612 debuglog("Found image: image_info_addr = %s, image_info_path= %s" % (hex(image_info_addr), hex(image_info_path)))
613 image_info_list.append((image_info_addr, image_info_path))
614 i += 1
615
616 image_info_list.sort()
617 num_images_found = len(image_info_list)
618
619 for ii in range(num_images_found):
620 n_im_info_addr = dyld_load_address
621 if ii + 1 < num_images_found:
622 n_im_info_addr = image_info_list[ii+1][0]
623
624 image_info_addr = image_info_list[ii][0]
625 image_info_path = image_info_list[ii][1]
626 try:
627 image_print_s = GetImageInfo(task, image_info_addr, image_info_path, approx_end_address=n_im_info_addr)
628 if len(image_print_s) > 0:
629 print image_print_s
630 ShowTaskUserLibraries.found_images.append((image_info_addr, n_im_info_addr, image_info_path, image_print_s))
631 else:
632 debuglog("Failed to print image info for task 0x{:x} image_info 0x{:x}".format(task, image_info_addr))
633 except Exception,e:
634 if config['debug']:
635 raise e
636
637 # load_path might get set when the main executable is processed.
638 if ShowTaskUserLibraries.exec_load_path != 0:
639 debuglog("main executable load_path is set.")
640 image_print_s = GetImageInfo(task, dyld_load_address, ShowTaskUserLibraries.exec_load_path)
641 if len(image_print_s) > 0:
642 print image_print_s
643 ShowTaskUserLibraries.found_images.append((dyld_load_address, dyld_load_address + 0xffffffff,
644 ShowTaskUserLibraries.exec_load_path, image_print_s))
645 else:
646 debuglog("Failed to print image for main executable for task 0x{:x} dyld_load_addr 0x{:x}".format(task, dyld_load_address))
647 else:
648 debuglog("Falling back to vm entry method for finding executable load address")
649 print "# NOTE: Failed to find executable using all_image_infos. Using fuzzy match to find best possible load address for executable."
650 ShowTaskLoadInfo([cmd_args[0]])
651 return
652
653 @lldb_command("showtaskuserdyldinfo")
654 def ShowTaskUserDyldInfo(cmd_args=None):
655 """ Inspect the dyld global info for the given user task & print out all fields including error messages
656 Syntax: (lldb)showtaskuserdyldinfo <task_t>
657 """
658 if cmd_args == None or len(cmd_args) < 1:
659 print "No arguments passed"
660 print ShowTaskUserDyldInfo.__doc__.strip()
661 return
662
663 out_str = ""
664 task = kern.GetValueFromAddress(cmd_args[0], 'task_t')
665 is_task_64 = int(task.t_flags) & 0x1
666 dyld_all_image_infos_address = unsigned(task.all_image_info_addr)
667 if dyld_all_image_infos_address == 0:
668 print "No dyld shared library information available for task"
669 return False
670 vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112)
671 dyld_all_image_infos_version = _ExtractDataFromString(vers_info_data, 0, "uint32_t")
672 if dyld_all_image_infos_version > 14:
673 out_str += "Unknown dyld all_image_infos version number %d" % dyld_all_image_infos_version
674
675 # Find fields by byte offset. We assume at least version 9 is supported
676 if is_task_64:
677 dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t")
678 dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint64_t")
679 dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 16, "uint64_t")
680 dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 24, "string")
681 dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 25, "string")
682 dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 32, "uint64_t")
683 dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 40, "uint64_t")
684 dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 48, "uint64_t")
685 dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 56, "uint64_t")
686 dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 64, "uint64_t")
687 dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 72, "uint64_t")
688 dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 80, "uint64_t")
689 dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 88, "uint64_t")
690 dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 96, "uint64_t")
691 dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 104, "uint64_t")
692 else:
693 dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t")
694 dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint32_t")
695 dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 12, "uint32_t")
696 dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 16, "string")
697 dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 17, "string")
698 dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 20, "uint32_t")
699 dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 24, "uint32_t")
700 dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 28, "uint32_t")
701 dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 32, "uint32_t")
702 dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 36, "uint32_t")
703 dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 40, "uint32_t")
704 dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 44, "uint32_t")
705 dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 48, "uint32_t")
706 dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 52, "uint32_t")
707 dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 56, "uint32_t")
708
709 dyld_all_imfo_infos_slide = (dyld_all_image_infos_address - dyld_all_image_infos_dyldAllImageInfosAddress)
710 dyld_all_image_infos_dyldVersion_postslide = (dyld_all_image_infos_dyldVersion + dyld_all_imfo_infos_slide)
711
712 path_out = GetUserspaceString(task, dyld_all_image_infos_dyldVersion_postslide)
713 out_str += "[dyld-{:s}]\n".format(path_out)
714 out_str += "version \t\t\t\t: {:d}\n".format(dyld_all_image_infos_version)
715 out_str += "infoArrayCount \t\t\t\t: {:d}\n".format(dyld_all_image_infos_infoArrayCount)
716 out_str += "infoArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_infoArray)
717 out_str += "notification \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_notification)
718
719 out_str += "processDetachedFromSharedRegion \t: "
720 if dyld_all_image_infos_processDetachedFromSharedRegion != "":
721 out_str += "TRUE\n".format(dyld_all_image_infos_processDetachedFromSharedRegion)
722 else:
723 out_str += "FALSE\n"
724
725 out_str += "libSystemInitialized \t\t\t: "
726 if dyld_all_image_infos_libSystemInitialized != "":
727 out_str += "TRUE\n".format(dyld_all_image_infos_libSystemInitialized)
728 else:
729 out_str += "FALSE\n"
730
731 out_str += "dyldImageLoadAddress \t\t\t: {:#x}\n".format(dyld_all_image_infos_dyldImageLoadAddress)
732 out_str += "jitInfo \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_jitInfo)
733 out_str += "\ndyldVersion \t\t\t\t: {:#x}".format(dyld_all_image_infos_dyldVersion)
734 if (dyld_all_imfo_infos_slide != 0):
735 out_str += " (currently {:#x})\n".format(dyld_all_image_infos_dyldVersion_postslide)
736 else:
737 out_str += "\n"
738
739 out_str += "errorMessage \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorMessage)
740 if dyld_all_image_infos_errorMessage != 0:
741 out_str += GetUserspaceString(task, dyld_all_image_infos_errorMessage)
742
743 out_str += "terminationFlags \t\t\t: {:#x}\n".format(dyld_all_image_infos_terminationFlags)
744 out_str += "coreSymbolicationShmPage \t\t: {:#x}\n".format(dyld_all_image_infos_coreSymbolicationShmPage)
745 out_str += "systemOrderFlag \t\t\t: {:#x}\n".format(dyld_all_image_infos_systemOrderFlag)
746 out_str += "uuidArrayCount \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArrayCount)
747 out_str += "uuidArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArray)
748 out_str += "dyldAllImageInfosAddress \t\t: {:#x}".format(dyld_all_image_infos_dyldAllImageInfosAddress)
749 if (dyld_all_imfo_infos_slide != 0):
750 out_str += " (currently {:#x})\n".format(dyld_all_image_infos_address)
751 else:
752 out_str += "\n"
753
754 if is_task_64:
755 dyld_all_image_infos_address = dyld_all_image_infos_address + 112
756 dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 64)
757 dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 112-112, "uint64_t")
758 dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 120-112, "uint64_t")
759 dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 128-112, "uint64_t")
760 dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 136-112, "uint64_t")
761 dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 144-112, "uint64_t")
762 dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 152-112, "uint64_t")
763 dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 160-112, "string")
764 else:
765 dyld_all_image_infos_address = dyld_all_image_infos_address + 60
766 dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 40)
767 dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 60-60, "uint32_t")
768 dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 64-60, "uint32_t")
769 dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 68-60, "uint32_t")
770 dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 72-60, "uint32_t")
771 dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 76-60, "uint32_t")
772 dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 80-60, "uint32_t")
773 dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 84-60, "string")
774
775 if dyld_all_image_infos_version >= 10:
776 out_str += "\ninitialImageCount \t\t\t: {:#x}\n".format(dyld_all_image_infos_initialImageCount)
777
778 if dyld_all_image_infos_version >= 11:
779 out_str += "errorKind \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorKind)
780 out_str += "errorClientOfDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorClientOfDylibPath)
781 if dyld_all_image_infos_errorClientOfDylibPath != 0:
782 out_str += "\t\t\t\t"
783 out_str += GetUserspaceString(task, dyld_all_image_infos_errorClientOfDylibPath)
784 out_str += "\n"
785 out_str += "errorTargetDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorTargetDylibPath)
786 if dyld_all_image_infos_errorTargetDylibPath != 0:
787 out_str += "\t\t\t\t"
788 out_str += GetUserspaceString(task, dyld_all_image_infos_errorTargetDylibPath)
789 out_str += "\n"
790 out_str += "errorSymbol \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorSymbol)
791 if dyld_all_image_infos_errorSymbol != 0:
792 out_str += "\t\t\t\t"
793 out_str += GetUserspaceString(task, dyld_all_image_infos_errorSymbol)
794 out_str += "\n"
795
796 if dyld_all_image_infos_version >= 12:
797 out_str += "sharedCacheSlide \t\t\t: {:#x}\n".format(dyld_all_image_infos_sharedCacheSlide)
798 if dyld_all_image_infos_version >= 13 and dyld_all_image_infos_sharedCacheUUID != "":
799 out_str += "sharedCacheUUID \t\t\t: {:s}\n".format(dyld_all_image_infos_sharedCacheUUID)
800 else:
801 out_str += "No dyld information available for task\n"
802 print out_str
803
804 # Macro: showosmalloc
805 @lldb_type_summary(['OSMallocTag'])
806 @header("{0: <20s} {1: >5s} {2: ^16s} {3: <5s} {4: <40s}".format("TAG", "COUNT", "STATE", "ATTR", "NAME"))
807 def GetOSMallocTagSummary(malloc_tag):
808 """ Summarize the given OSMalloc tag.
809 params:
810 malloc_tag : value - value representing a _OSMallocTag_ * in kernel
811 returns:
812 out_str - string summary of the OSMalloc tag.
813 """
814 if not malloc_tag:
815 return "Invalid malloc tag value: 0x0"
816
817 out_str = "{: <#20x} {: >5d} {: ^#16x} {: <5d} {: <40s}\n".format(malloc_tag,
818 malloc_tag.OSMT_refcnt, malloc_tag.OSMT_state, malloc_tag.OSMT_attr, malloc_tag.OSMT_name)
819 return out_str
820
821 @lldb_command('showosmalloc')
822 def ShowOSMalloc(cmd_args=None):
823 """ Print the outstanding allocation count of OSMalloc tags
824 Usage: showosmalloc
825 """
826 summary_str = ""
827 tag_headp = Cast(addressof(kern.globals.OSMalloc_tag_list), 'struct _OSMallocTag_ *')
828 tagp = Cast(tag_headp.OSMT_link.next, 'struct _OSMallocTag_ *')
829 summary_str += GetOSMallocTagSummary.header + "\n"
830 while tagp != tag_headp:
831 summary_str += GetOSMallocTagSummary(tagp)
832 tagp = Cast(tagp.OSMT_link.next, 'struct _OSMallocTag_ *')
833
834 print summary_str
835
836 # EndMacro: showosmalloc
837
838
839 @lldb_command('savekcdata', 'T:O:')
840 def SaveKCDataToFile(cmd_args=None, cmd_options={}):
841 """ Save the data referred by the kcdata_descriptor structure.
842 options:
843 -T: <task_t> pointer to task if memory referenced is in userstask.
844 -O: <output file path> path to file to save data. default: /tmp/kcdata.<timestamp>.bin
845 Usage: (lldb) savekcdata <kcdata_descriptor_t> -T <task_t> -O /path/to/outputfile.bin
846 """
847 if not cmd_args:
848 raise ArgumentError('Please provide the kcdata descriptor.')
849
850 kcdata = kern.GetValueFromAddress(cmd_args[0], 'kcdata_descriptor_t')
851
852 outputfile = '/tmp/kcdata.{:s}.bin'.format(str(time.time()))
853 task = None
854 if '-O' in cmd_options:
855 outputfile = cmd_options['-O']
856 if '-T' in cmd_options:
857 task = kern.GetValueFromAddress(cmd_options['-T'], 'task_t')
858
859 memory_begin_address = unsigned(kcdata.kcd_addr_begin)
860 memory_size = 16 + unsigned(kcdata.kcd_addr_end) - memory_begin_address
861 flags_copyout = unsigned(kcdata.kcd_flags)
862 if flags_copyout:
863 if not task:
864 raise ArgumentError('Invalid task pointer provided.')
865 memory_data = GetUserDataAsString(task, memory_begin_address, memory_size)
866 else:
867 data_ptr = kern.GetValueFromAddress(memory_begin_address, 'uint8_t *')
868 memory_data = []
869 for i in range(memory_size):
870 memory_data.append(chr(data_ptr[i]))
871 if i % 50000 == 0:
872 print "%d of %d \r" % (i, memory_size),
873 memory_data = ''.join(memory_data)
874
875 if len(memory_data) != memory_size:
876 print "Failed to read {:d} bytes from address {: <#020x}".format(memory_size, memory_begin_address)
877 return False
878
879 fh = open(outputfile, 'w')
880 fh.write(memory_data)
881 fh.close()
882 print "Saved {:d} bytes to file {:s}".format(memory_size, outputfile)
883 return True
884
885
886