]> git.saurik.com Git - apple/xnu.git/blob - tools/lldbmacros/userspace.py
xnu-3789.51.2.tar.gz
[apple/xnu.git] / tools / lldbmacros / userspace.py
1 from xnu import *
2 from utils import *
3 from process import *
4 from pmap import *
5 import struct
6
7 def GetBinaryNameForPC(pc_val, user_lib_info = None):
8 """ find the binary in user_lib_info that the passed pc_val falls in range of.
9 params:
10 pc_val : int - integer form of the pc address
11 user_lib_info: [] of [] which hold start, end, binary name
12 returns:
13 str - Name of binary or "unknown" if not found.
14 """
15 retval = "unknown"
16 if not user_lib_info:
17 return retval
18 matches = []
19 for info in user_lib_info:
20 if pc_val >= info[0] and pc_val <= info[1]:
21 matches.append((pc_val - info[0], info[2]))
22 matches.sort()
23 if matches:
24 retval = matches[0][1]
25 return retval
26
27 def ShowX86UserStack(thread, user_lib_info = None):
28 """ Display user space stack frame and pc addresses.
29 params:
30 thread: obj referencing thread value
31 returns:
32 Nothing
33 """
34 iss = Cast(thread.machine.iss, 'x86_saved_state_t *')
35 abi = int(iss.flavor)
36 user_ip = 0
37 user_frame = 0
38 user_abi_ret_offset = 0
39 if abi == 0xf:
40 debuglog("User process is 64 bit")
41 user_ip = iss.uss.ss_64.isf.rip
42 user_frame = iss.uss.ss_64.rbp
43 user_abi_ret_offset = 8
44 user_abi_type = "uint64_t"
45 else:
46 debuglog("user process is 32 bit")
47 user_ip = iss.uss.ss_32.eip
48 user_frame = iss.uss.ss_32.ebp
49 user_abi_ret_offset = 4
50 user_abi_type = "uint32_t"
51
52 if user_ip == 0:
53 print "This activation does not appear to have a valid user context."
54 return False
55
56 cur_ip = user_ip
57 cur_frame = user_frame
58 debuglog("ip= 0x%x , fr = 0x%x " % (cur_ip, cur_frame))
59
60 frameformat = "{0:d} FP: 0x{1:x} PC: 0x{2:x}"
61 if user_lib_info is not None:
62 frameformat = "{0:d} {3: <30s} 0x{2:x}"
63 print frameformat.format(0, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))
64
65 print kern.Symbolicate(cur_ip)
66
67 frameno = 0
68 while True:
69 frameno = frameno + 1
70 frame = GetUserDataAsString(thread.task, unsigned(cur_frame), user_abi_ret_offset*2)
71 cur_ip = _ExtractDataFromString(frame, user_abi_ret_offset, user_abi_type)
72 cur_frame = _ExtractDataFromString(frame, 0, user_abi_type)
73 if not cur_frame or cur_frame == 0x0000000800000008:
74 break
75 print frameformat.format(frameno, cur_frame, cur_ip, GetBinaryNameForPC(cur_ip, user_lib_info))
76 print kern.Symbolicate(cur_ip)
77 return
78
79 def _PrintARMUserStack(task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=None):
80 if cur_pc == 0:
81 "No valid user context for this activation."
82 return
83 frameno = 0
84 print frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))
85 while True:
86 frameno = frameno + 1
87 frame = GetUserDataAsString(task, cur_fp, framesize)
88 cur_fp = _ExtractDataFromString(frame, 0, frametype)
89 cur_pc = _ExtractDataFromString(frame, (framesize / 2), frametype)
90 if not cur_fp:
91 break
92 print frameformat.format(frameno, cur_fp, cur_pc, GetBinaryNameForPC(cur_pc, user_lib_info))
93
94 def ShowARMUserStack(thread, user_lib_info = None):
95 cur_pc = unsigned(thread.machine.PcbData.pc)
96 cur_fp = unsigned(thread.machine.PcbData.r[7])
97 frameformat = "{0:>2d} FP: 0x{1:x} PC: 0x{2:x}"
98 if user_lib_info is not None:
99 frameformat = "{0:>2d} {3: <30s} 0x{2:0>8x}"
100 framesize = 8
101 frametype = "uint32_t"
102 _PrintARMUserStack(thread.task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=user_lib_info)
103
104 def ShowARM64UserStack(thread, user_lib_info = None):
105 SAVED_STATE_FLAVOR_ARM=20
106 SAVED_STATE_FLAVOR_ARM64=21
107 upcb = thread.machine.upcb
108 flavor = upcb.ash.flavor
109 frameformat = "{0:>2d} FP: 0x{1:x} PC: 0x{2:x}"
110 if flavor == SAVED_STATE_FLAVOR_ARM64:
111 cur_pc = unsigned(upcb.uss.ss_64.pc)
112 cur_fp = unsigned(upcb.uss.ss_64.fp)
113 if user_lib_info is not None:
114 frameformat = "{0:>2d} {3: <30s} 0x{2:x}"
115 framesize = 16
116 frametype = "uint64_t"
117 elif flavor == SAVED_STATE_FLAVOR_ARM:
118 cur_pc = unsigned(upcb.uss.ss_32.pc)
119 cur_fp = unsigned(upcb.uss.ss_32.r[7])
120 if user_lib_info is not None:
121 frameformat = "{0:>2d}: {3: <30s} 0x{2:x}"
122 framesize = 8
123 frametype = "uint32_t"
124 else:
125 raise RuntimeError("Thread {0} has an invalid flavor {1}".format(unsigned(thread), flavor))
126
127 _PrintARMUserStack(thread.task, cur_pc, cur_fp, framesize, frametype, frameformat, user_lib_info=user_lib_info)
128
129
130 @lldb_command('showthreaduserstack')
131 def ShowThreadUserStack(cmd_args=None):
132 """ Show user stack for a given thread.
133 Syntax: (lldb) showthreaduserstack <thread_ptr>
134 """
135 if not cmd_args:
136 raise ArgumentError("Insufficient arguments")
137
138 thread = kern.GetValueFromAddress(ArgumentStringToInt(cmd_args[0]), 'thread *')
139 if kern.arch == "x86_64":
140 ShowX86UserStack(thread)
141 elif kern.arch == "arm":
142 ShowARMUserStack(thread)
143 elif kern.arch == "arm64":
144 ShowARM64UserStack(thread)
145 return True
146
147 @lldb_command('printuserdata','XO:')
148 def PrintUserspaceData(cmd_args=None, cmd_options={}):
149 """ Read userspace data for given task and print based on format provided.
150 Syntax: (lldb) printuserdata <task_t> <uspace_address> <format_specifier>
151 params:
152 <task_t> : pointer to task
153 <uspace_address> : address to user space memory
154 <format_specifier> : String representation for processing the data and printing it.
155 e.g Q -> unsigned long long, q -> long long, I -> unsigned int, i -> int
156 10i -> 10 ints, 20s -> 20 character string, s -> null terminated string
157 See: https://docs.python.org/2/library/struct.html#format-characters
158 options:
159 -X : print all values in hex.
160 -O <file path>: Save data to file
161 """
162
163 if not cmd_args or len(cmd_args) < 3:
164 raise ArgumentError("Insufficient arguments")
165 task = kern.GetValueFromAddress(cmd_args[0], 'task *')
166 uspace_addr = ArgumentStringToInt(cmd_args[1])
167 format_specifier_str = cmd_args[2]
168 user_data_len = 0
169 if format_specifier_str == "s":
170 print "0x%x: " % uspace_addr + GetUserspaceString(task, uspace_addr)
171 return True
172
173 try:
174 user_data_len = struct.calcsize(format_specifier_str)
175 except Exception, e:
176 raise ArgumentError("Invalid format specifier provided.")
177
178 user_data_string = GetUserDataAsString(task, uspace_addr, user_data_len)
179 if not user_data_string:
180 print "Could not read any data from userspace address."
181 return False
182 if "-O" in cmd_options:
183 fh = open(cmd_options["-O"],"w")
184 fh.write(user_data_string)
185 fh.close()
186 print "Written %d bytes to %s." % (user_data_len, cmd_options['-O'])
187 return True
188 upacked_data = struct.unpack(format_specifier_str, user_data_string)
189 element_size = user_data_len / len(upacked_data)
190 for i in range(len(upacked_data)):
191 if "-X" in cmd_options:
192 print "0x%x: " % (uspace_addr + i*element_size) + hex(upacked_data[i])
193 else:
194 print "0x%x: " % (uspace_addr + i*element_size) + str(upacked_data[i])
195
196 return True
197
198
199 @lldb_command('showtaskuserargs')
200 def ShowTaskUserArgs(cmd_args=None, cmd_options={}):
201 """ Read the process argv, env, and apple strings from the user stack
202 Syntax: (lldb) showtaskuserargs <task_t>
203 params:
204 <task_t> : pointer to task
205 """
206 if not cmd_args or len(cmd_args) != 1:
207 raise ArgumentError("Insufficient arguments")
208
209 task = kern.GetValueFromAddress(cmd_args[0], 'task *')
210 proc = Cast(task.bsd_info, 'proc *')
211
212 format_string = "Q" if kern.ptrsize == 8 else "I"
213
214 string_area_size = proc.p_argslen
215 string_area_addr = proc.user_stack - string_area_size
216
217 string_area = GetUserDataAsString(task, string_area_addr, string_area_size)
218 if not string_area:
219 print "Could not read any data from userspace address."
220 return False
221
222 i = 0
223 pos = string_area_addr - kern.ptrsize
224
225 for name in ["apple", "env", "argv"] :
226 while True:
227 if name == "argv" :
228 if i == proc.p_argc:
229 break
230 i += 1
231
232 pos -= kern.ptrsize
233
234 user_data_string = GetUserDataAsString(task, pos, kern.ptrsize)
235 ptr = struct.unpack(format_string, user_data_string)[0]
236
237 if ptr == 0:
238 break
239
240 if string_area_addr <= ptr and ptr < string_area_addr+string_area_size :
241 string_offset = ptr - string_area_addr
242 string = string_area[string_offset:];
243 else:
244 string = GetUserspaceString(task, ptr)
245
246 print name + "[]: " + string
247
248 return True
249
250 def ShowTaskUserStacks(task):
251 #print GetTaskSummary.header + " " + GetProcSummary.header
252 pval = Cast(task.bsd_info, 'proc *')
253 #print GetTaskSummary(task) + " " + GetProcSummary(pval) + "\n \n"
254 crash_report_format_string = """\
255 Process: {pname:s} [{pid:d}]
256 Path: {path: <50s}
257 Identifier: {pname: <30s}
258 Version: ??? (???)
259 Code Type: {parch: <20s}
260 Parent Process: {ppname:s} [{ppid:d}]
261
262 Date/Time: {timest:s}.000 -0800
263 OS Version: {osversion: <20s}
264 Report Version: 8
265
266 Exception Type: n/a
267 Exception Codes: n/a
268 Crashed Thread: 0
269
270 Application Specific Information:
271 Synthetic crash log generated from Kernel userstacks
272
273 """
274 user_lib_rex = re.compile("([0-9a-fx]+)\s-\s([0-9a-fx]+)\s+(.*?)\s", re.IGNORECASE|re.MULTILINE)
275 from datetime import datetime
276 ts = datetime.fromtimestamp(int(pval.p_start.tv_sec))
277 date_string = ts.strftime('%Y-%m-%d %H:%M:%S')
278 is_64 = False
279 if pval.p_flag & 0x4 :
280 is_64 = True
281
282 parch_s = ""
283 if kern.arch == "x86_64" or kern.arch == "i386":
284 osversion = "Mac OS X 10.8"
285 parch_s = "I386 (32 bit)"
286 if is_64:
287 parch_s = "X86-64 (Native)"
288 else:
289 parch_s = kern.arch
290 osversion = "iOS"
291 osversion += " ({:s})".format(kern.globals.osversion)
292 print crash_report_format_string.format(pid = pval.p_pid,
293 pname = pval.p_comm,
294 path = pval.p_comm,
295 ppid = pval.p_ppid,
296 ppname = GetProcNameForPid(pval.p_ppid),
297 timest = date_string,
298 parch = parch_s,
299 osversion = osversion
300
301 )
302 print "Binary Images:"
303 ShowTaskUserLibraries([hex(task)])
304 usertask_lib_info = [] # will host [startaddr, endaddr, lib_name] entries
305 for entry in ShowTaskUserLibraries.found_images:
306 #print "processing line %s" % line
307 arr = user_lib_rex.findall(entry[3])
308 #print "%r" % arr
309 if len(arr) == 0 :
310 continue
311 usertask_lib_info.append([int(arr[0][0],16), int(arr[0][1],16), str(arr[0][2]).strip()])
312
313 printthread_user_stack_ptr = ShowX86UserStack
314 if kern.arch == "arm":
315 printthread_user_stack_ptr = ShowARMUserStack
316 elif kern.arch =="arm64":
317 printthread_user_stack_ptr = ShowARM64UserStack
318
319 counter = 0
320 for thval in IterateQueue(task.threads, 'thread *', 'task_threads'):
321 print "\nThread {0:d} name:0x{1:x}\nThread {0:d}:".format(counter, thval)
322 counter += 1
323 try:
324 printthread_user_stack_ptr(thval, usertask_lib_info)
325 except Exception as exc_err:
326 print "Failed to show user stack for thread 0x{0:x}".format(thval)
327 if config['debug']:
328 raise exc_err
329 else:
330 print "Enable debugging ('(lldb) xnudebug debug') to see detailed trace."
331 return
332
333 @lldb_command('showtaskuserstacks', "P:F:")
334 def ShowTaskUserStacksCmdHelper(cmd_args=None, cmd_options={}):
335 """ Print out the user stack for each thread in a task, followed by the user libraries.
336 Syntax: (lldb) showtaskuserstacks <task_t>
337 or: (lldb) showtaskuserstacks -P <pid>
338 or: (lldb) showtaskuserstacks -F <task_name>
339 The format is compatible with CrashTracer. You can also use the speedtracer plugin as follows
340 (lldb) showtaskuserstacks <task_t> -p speedtracer
341
342 Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures
343 and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate
344 """
345 task_list = []
346 if "-F" in cmd_options:
347 task_list = FindTasksByName(cmd_options["-F"])
348 elif "-P" in cmd_options:
349 pidval = ArgumentStringToInt(cmd_options["-P"])
350 for t in kern.tasks:
351 pval = Cast(t.bsd_info, 'proc *')
352 if pval and pval.p_pid == pidval:
353 task_list.append(t)
354 break
355 elif cmd_args:
356 t = kern.GetValueFromAddress(cmd_args[0], 'task *')
357 task_list.append(t)
358 else:
359 raise ArgumentError("Insufficient arguments")
360
361 for task in task_list:
362 ShowTaskUserStacks(task)
363
364 def GetUserDataAsString(task, addr, size):
365 """ Get data from task's address space as a string of bytes
366 params:
367 task: task object from which to extract information
368 addr: int - start address to get data from.
369 size: int - no of bytes to read.
370 returns:
371 str - a stream of bytes. Empty string if read fails.
372 """
373 err = lldb.SBError()
374 if GetConnectionProtocol() == "kdp":
375 kdp_pmap_addr = unsigned(addressof(kern.globals.kdp_pmap))
376 if not WriteInt64ToMemoryAddress(unsigned(task.map.pmap), kdp_pmap_addr):
377 debuglog("Failed to write in kdp_pmap from GetUserDataAsString.")
378 return ""
379 content = LazyTarget.GetProcess().ReadMemory(addr, size, err)
380 if not err.Success():
381 debuglog("Failed to read process memory. Error: " + err.description)
382 return ""
383 if not WriteInt64ToMemoryAddress(0, kdp_pmap_addr):
384 debuglog("Failed to reset in kdp_pmap from GetUserDataAsString.")
385 return ""
386 elif kern.arch in ['arm', 'arm64', 'x86_64'] and long(size) < (2 * kern.globals.page_size):
387 # Without the benefit of a KDP stub on the target, try to
388 # find the user task's physical mapping and memcpy the data.
389 # If it straddles a page boundary, copy in two passes
390 range1_addr = long(addr)
391 range1_size = long(size)
392 if kern.StraddlesPage(range1_addr, range1_size):
393 range2_addr = long(kern.TruncPage(range1_addr + range1_size))
394 range2_size = long(range1_addr + range1_size - range2_addr)
395 range1_size = long(range2_addr - range1_addr)
396 else:
397 range2_addr = 0
398 range2_size = 0
399 range2_in_kva = 0
400
401 paddr_range1 = PmapWalk(task.map.pmap, range1_addr, vSILENT)
402 if not paddr_range1:
403 debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr))
404 return ""
405
406 range1_in_kva = kern.PhysToKernelVirt(paddr_range1)
407 content = LazyTarget.GetProcess().ReadMemory(range1_in_kva, range1_size, err)
408 if not err.Success():
409 raise RuntimeError("Failed to read process memory. Error: " + err.description)
410
411 if range2_addr:
412 paddr_range2 = PmapWalk(task.map.pmap, range2_addr, vSILENT)
413 if not paddr_range2:
414 debuglog("Not mapped task 0x{:x} address 0x{:x}".format(task, addr))
415 return ""
416 range2_in_kva = kern.PhysToKernelVirt(paddr_range2)
417 content += LazyTarget.GetProcess().ReadMemory(range2_in_kva, range2_size, err)
418 if not err.Success():
419 raise RuntimeError("Failed to read process memory. Error: " + err.description)
420 else:
421 raise NotImplementedError("GetUserDataAsString does not support this configuration")
422
423 return content
424
425 def _ExtractDataFromString(strdata, offset, data_type, length=0):
426 """ Extract specific data from string buffer
427 params:
428 strdata: str - string data give from GetUserDataAsString
429 offset: int - 0 based offset into the data.
430 data_type: str - defines what type to be read as. Supported values are:
431 'uint64_t', 'uint32_t', 'string'
432 length: int - used when data_type=='string'
433 returns
434 None - if extraction failed.
435 obj - based on what is requested in data_type
436 """
437 unpack_str = "s"
438 if data_type == 'uint64_t':
439 length = 8
440 unpack_str = "Q"
441 elif data_type == "uint32_t":
442 length = 4
443 unpack_str = "I"
444 else:
445 unpack_str= "%ds" % length
446
447 data_len = len(strdata)
448 if offset > data_len or (offset + length) > data_len or offset < 0:
449 debuglog("Invalid arguments to _ExtractDataFromString.")
450 return 0
451 return struct.unpack(unpack_str, strdata[offset:(offset + length)])[0]
452
453 def GetUserspaceString(task, string_address):
454 """ Maps 32 bytes at a time and packs as string
455 params:
456 task: obj - referencing task to read data from
457 string_address: int - address where the image path is stored
458 returns:
459 str - string path of the file. "" if failed to read.
460 """
461 done = False
462 retval = ""
463
464 if string_address == 0:
465 done = True
466
467 while not done:
468 str_data = GetUserDataAsString(task, string_address, 32)
469 if len(str_data) == 0:
470 break
471 i = 0
472 while i < 32:
473 if ord(str_data[i]):
474 retval += str_data[i]
475 else:
476 break
477 i += 1
478 if i < 32:
479 done = True
480 else:
481 string_address += 32
482 return retval
483
484 def GetImageInfo(task, mh_image_address, mh_path_address, approx_end_address=None):
485 """ Print user library informaiton.
486 params:
487 task : obj referencing the task for which Image info printed
488 mh_image_address : int - address which has image info
489 mh_path_address : int - address which holds path name string
490 approx_end_address: int - address which lldbmacros think is end address.
491 returns:
492 str - string representing image info. "" if failure to read data.
493 """
494 if approx_end_address:
495 image_end_load_address = int(approx_end_address) -1
496 else:
497 image_end_load_address = int(mh_image_address) + 0xffffffff
498
499 print_format = "0x{0:x} - 0x{1:x} {2: <50s} (??? - ???) <{3: <36s}> {4: <50s}"
500 # 32 bytes enough for mach_header/mach_header_64
501 mh_data = GetUserDataAsString(task, mh_image_address, 32)
502 if len(mh_data) == 0:
503 debuglog("unable to get userdata for task 0x{:x} img_addr 0x{:x} path_address 0x{:x}".format(
504 task, mh_image_address, mh_path_address))
505 return ""
506 mh_magic = _ExtractDataFromString(mh_data, (4 * 0), "uint32_t")
507 mh_cputype = _ExtractDataFromString(mh_data,(4 * 1), "uint32_t")
508 mh_cpusubtype = _ExtractDataFromString(mh_data,(4 * 2), "uint32_t")
509 mh_filetype = _ExtractDataFromString(mh_data,(4 * 3), "uint32_t")
510 mh_ncmds = _ExtractDataFromString(mh_data,(4 * 4), "uint32_t")
511 mh_sizeofcmds = _ExtractDataFromString(mh_data,(4 * 5), "uint32_t")
512 mh_flags = _ExtractDataFromString(mh_data,(4 * 6), "uint32_t")
513
514 if mh_magic == 0xfeedfacf:
515 mh_64 = True
516 lc_address = mh_image_address + 32
517 else:
518 mh_64 = False
519 lc_address = mh_image_address + 28
520
521 lc_idx = 0
522 uuid_data = 0
523 found_uuid_data = False
524 retval = None
525 while lc_idx < mh_ncmds:
526 # 24 bytes is the size of uuid_command
527 lcmd_data = GetUserDataAsString(task, lc_address, 24)
528 lc_cmd = _ExtractDataFromString(lcmd_data, 4 * 0, "uint32_t")
529 lc_cmd_size = _ExtractDataFromString(lcmd_data, 4 * 1, "uint32_t")
530 lc_data = _ExtractDataFromString(lcmd_data, 4*2, "string", 16)
531
532 uuid_out_string = ""
533 path_out_string = ""
534
535 if lc_cmd == 0x1b:
536 # need to print the uuid now.
537 uuid_data = [ord(x) for x in lc_data]
538 found_uuid_data = True
539 uuid_out_string = "{a[0]:02X}{a[1]:02X}{a[2]:02X}{a[3]:02X}-{a[4]:02X}{a[5]:02X}-{a[6]:02X}{a[7]:02X}-{a[8]:02X}{a[9]:02X}-{a[10]:02X}{a[11]:02X}{a[12]:02X}{a[13]:02X}{a[14]:02X}{a[15]:02X}".format(a=uuid_data)
540 #also print image path
541 path_out_string = GetUserspaceString(task, mh_path_address)
542 path_base_name = path_out_string.split("/")[-1]
543 retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string)
544 elif lc_cmd == 0xe:
545 ShowTaskUserLibraries.exec_load_path = lc_address + _ExtractDataFromString(lcmd_data, 4*2, "uint32_t")
546 debuglog("Found load command to be 0xe for address %s" % hex(ShowTaskUserLibraries.exec_load_path))
547 lc_address = lc_address + lc_cmd_size
548 lc_idx += 1
549
550 if not found_uuid_data:
551 path_out_string = GetUserspaceString(task, mh_path_address)
552 path_base_name = path_out_string.split("/")[-1]
553 uuid_out_string = ""
554
555 retval = print_format.format(mh_image_address, image_end_load_address, path_base_name, uuid_out_string, path_out_string)
556 return retval
557
558 @static_var("found_images", []) # holds entries of format (startaddr, endaddr, image_path_addr, infostring)
559 @static_var("exec_load_path", 0)
560 @lldb_command("showtaskuserlibraries")
561 def ShowTaskUserLibraries(cmd_args=None):
562 """ Show binary images known by dyld in target task
563 For a given user task, inspect the dyld shared library state and print information about all Mach-O images.
564 Syntax: (lldb)showtaskuserlibraries <task_t>
565 Note: the address ranges are approximations. Also the list may not be completely accurate. This command expects memory read failures
566 and hence will skip a library if unable to read information. Please use your good judgement and not take the output as accurate
567 """
568 if not cmd_args:
569 raise ArgumentError("Insufficient arguments")
570
571 #reset the found_images array
572 ShowTaskUserLibraries.found_images = []
573
574 task = kern.GetValueFromAddress(cmd_args[0], 'task_t')
575 is_task_64 = int(task.t_flags) & 0x1
576 dyld_all_image_infos_address = unsigned(task.all_image_info_addr)
577 debuglog("dyld_all_image_infos_address = %s" % hex(dyld_all_image_infos_address))
578
579 cur_data_offset = 0
580 if dyld_all_image_infos_address == 0:
581 print "No dyld shared library information available for task"
582 return False
583
584 debuglog("Extracting version information.")
585 vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112)
586 version = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t")
587 cur_data_offset += 4
588 if version > 14:
589 print "Unknown dyld all_image_infos version number %d" % version
590 image_info_count = _ExtractDataFromString(vers_info_data, cur_data_offset, "uint32_t")
591 debuglog("version = %d count = %d is_task_64 = %s" % (version, image_info_count, repr(is_task_64)))
592
593 ShowTaskUserLibraries.exec_load_path = 0
594 if is_task_64:
595 image_info_size = 24
596 image_info_array_address = _ExtractDataFromString(vers_info_data, 8, "uint64_t")
597 dyld_load_address = _ExtractDataFromString(vers_info_data, 8*4, "uint64_t")
598 dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 8*13, "uint64_t")
599 else:
600 image_info_size = 12
601 image_info_array_address = _ExtractDataFromString(vers_info_data, 4*2, "uint32_t")
602 dyld_load_address = _ExtractDataFromString(vers_info_data, 4*5, "uint32_t")
603 dyld_all_image_infos_address_from_struct = _ExtractDataFromString(vers_info_data, 4*14, "uint32_t")
604 # Account for ASLR slide before dyld can fix the structure
605 dyld_load_address = dyld_load_address + (dyld_all_image_infos_address - dyld_all_image_infos_address_from_struct)
606
607 i = 0
608 image_info_list = []
609 while i < image_info_count:
610 image_info_address = image_info_array_address + i * image_info_size
611 debuglog("i = %d, image_info_address = %s, image_info_size = %d" % (i, hex(image_info_address), image_info_size))
612 n_im_info_addr = None
613 img_data = ""
614 try:
615 img_data = GetUserDataAsString(task, image_info_address, image_info_size)
616 except Exception, e:
617 debuglog("Failed to read user data for task 0x{:x} addr 0x{:x}, exception {:s}".format(task, image_info_address, str(e)))
618 pass
619
620 if is_task_64:
621 image_info_addr = _ExtractDataFromString(img_data, 0, "uint64_t")
622 image_info_path = _ExtractDataFromString(img_data, 8, "uint64_t")
623 else:
624 image_info_addr = _ExtractDataFromString(img_data, 0, "uint32_t")
625 image_info_path = _ExtractDataFromString(img_data, 4, "uint32_t")
626
627 if image_info_addr :
628 debuglog("Found image: image_info_addr = %s, image_info_path= %s" % (hex(image_info_addr), hex(image_info_path)))
629 image_info_list.append((image_info_addr, image_info_path))
630 i += 1
631
632 image_info_list.sort()
633 num_images_found = len(image_info_list)
634
635 for ii in range(num_images_found):
636 n_im_info_addr = dyld_load_address
637 if ii + 1 < num_images_found:
638 n_im_info_addr = image_info_list[ii+1][0]
639
640 image_info_addr = image_info_list[ii][0]
641 image_info_path = image_info_list[ii][1]
642 try:
643 image_print_s = GetImageInfo(task, image_info_addr, image_info_path, approx_end_address=n_im_info_addr)
644 if len(image_print_s) > 0:
645 print image_print_s
646 ShowTaskUserLibraries.found_images.append((image_info_addr, n_im_info_addr, image_info_path, image_print_s))
647 else:
648 debuglog("Failed to print image info for task 0x{:x} image_info 0x{:x}".format(task, image_info_addr))
649 except Exception,e:
650 if config['debug']:
651 raise e
652
653 # load_path might get set when the main executable is processed.
654 if ShowTaskUserLibraries.exec_load_path != 0:
655 debuglog("main executable load_path is set.")
656 image_print_s = GetImageInfo(task, dyld_load_address, ShowTaskUserLibraries.exec_load_path)
657 if len(image_print_s) > 0:
658 print image_print_s
659 ShowTaskUserLibraries.found_images.append((dyld_load_address, dyld_load_address + 0xffffffff,
660 ShowTaskUserLibraries.exec_load_path, image_print_s))
661 else:
662 debuglog("Failed to print image for main executable for task 0x{:x} dyld_load_addr 0x{:x}".format(task, dyld_load_address))
663 else:
664 debuglog("Falling back to vm entry method for finding executable load address")
665 print "# NOTE: Failed to find executable using all_image_infos. Using fuzzy match to find best possible load address for executable."
666 ShowTaskLoadInfo([cmd_args[0]])
667 return
668
669 @lldb_command("showtaskuserdyldinfo")
670 def ShowTaskUserDyldInfo(cmd_args=None):
671 """ Inspect the dyld global info for the given user task & print out all fields including error messages
672 Syntax: (lldb)showtaskuserdyldinfo <task_t>
673 """
674 if cmd_args == None or len(cmd_args) < 1:
675 print "No arguments passed"
676 print ShowTaskUserDyldInfo.__doc__.strip()
677 return
678
679 out_str = ""
680 task = kern.GetValueFromAddress(cmd_args[0], 'task_t')
681 is_task_64 = int(task.t_flags) & 0x1
682 dyld_all_image_infos_address = unsigned(task.all_image_info_addr)
683 if dyld_all_image_infos_address == 0:
684 print "No dyld shared library information available for task"
685 return False
686 vers_info_data = GetUserDataAsString(task, dyld_all_image_infos_address, 112)
687 dyld_all_image_infos_version = _ExtractDataFromString(vers_info_data, 0, "uint32_t")
688 if dyld_all_image_infos_version > 14:
689 out_str += "Unknown dyld all_image_infos version number %d" % dyld_all_image_infos_version
690
691 # Find fields by byte offset. We assume at least version 9 is supported
692 if is_task_64:
693 dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t")
694 dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint64_t")
695 dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 16, "uint64_t")
696 dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 24, "string")
697 dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 25, "string")
698 dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 32, "uint64_t")
699 dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 40, "uint64_t")
700 dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 48, "uint64_t")
701 dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 56, "uint64_t")
702 dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 64, "uint64_t")
703 dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 72, "uint64_t")
704 dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 80, "uint64_t")
705 dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 88, "uint64_t")
706 dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 96, "uint64_t")
707 dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 104, "uint64_t")
708 else:
709 dyld_all_image_infos_infoArrayCount = _ExtractDataFromString(vers_info_data, 4, "uint32_t")
710 dyld_all_image_infos_infoArray = _ExtractDataFromString(vers_info_data, 8, "uint32_t")
711 dyld_all_image_infos_notification = _ExtractDataFromString(vers_info_data, 12, "uint32_t")
712 dyld_all_image_infos_processDetachedFromSharedRegion = _ExtractDataFromString(vers_info_data, 16, "string")
713 dyld_all_image_infos_libSystemInitialized = _ExtractDataFromString(vers_info_data, 17, "string")
714 dyld_all_image_infos_dyldImageLoadAddress = _ExtractDataFromString(vers_info_data, 20, "uint32_t")
715 dyld_all_image_infos_jitInfo = _ExtractDataFromString(vers_info_data, 24, "uint32_t")
716 dyld_all_image_infos_dyldVersion = _ExtractDataFromString(vers_info_data, 28, "uint32_t")
717 dyld_all_image_infos_errorMessage = _ExtractDataFromString(vers_info_data, 32, "uint32_t")
718 dyld_all_image_infos_terminationFlags = _ExtractDataFromString(vers_info_data, 36, "uint32_t")
719 dyld_all_image_infos_coreSymbolicationShmPage = _ExtractDataFromString(vers_info_data, 40, "uint32_t")
720 dyld_all_image_infos_systemOrderFlag = _ExtractDataFromString(vers_info_data, 44, "uint32_t")
721 dyld_all_image_infos_uuidArrayCount = _ExtractDataFromString(vers_info_data, 48, "uint32_t")
722 dyld_all_image_infos_uuidArray = _ExtractDataFromString(vers_info_data, 52, "uint32_t")
723 dyld_all_image_infos_dyldAllImageInfosAddress = _ExtractDataFromString(vers_info_data, 56, "uint32_t")
724
725 dyld_all_imfo_infos_slide = (dyld_all_image_infos_address - dyld_all_image_infos_dyldAllImageInfosAddress)
726 dyld_all_image_infos_dyldVersion_postslide = (dyld_all_image_infos_dyldVersion + dyld_all_imfo_infos_slide)
727
728 path_out = GetUserspaceString(task, dyld_all_image_infos_dyldVersion_postslide)
729 out_str += "[dyld-{:s}]\n".format(path_out)
730 out_str += "version \t\t\t\t: {:d}\n".format(dyld_all_image_infos_version)
731 out_str += "infoArrayCount \t\t\t\t: {:d}\n".format(dyld_all_image_infos_infoArrayCount)
732 out_str += "infoArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_infoArray)
733 out_str += "notification \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_notification)
734
735 out_str += "processDetachedFromSharedRegion \t: "
736 if dyld_all_image_infos_processDetachedFromSharedRegion != "":
737 out_str += "TRUE\n".format(dyld_all_image_infos_processDetachedFromSharedRegion)
738 else:
739 out_str += "FALSE\n"
740
741 out_str += "libSystemInitialized \t\t\t: "
742 if dyld_all_image_infos_libSystemInitialized != "":
743 out_str += "TRUE\n".format(dyld_all_image_infos_libSystemInitialized)
744 else:
745 out_str += "FALSE\n"
746
747 out_str += "dyldImageLoadAddress \t\t\t: {:#x}\n".format(dyld_all_image_infos_dyldImageLoadAddress)
748 out_str += "jitInfo \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_jitInfo)
749 out_str += "\ndyldVersion \t\t\t\t: {:#x}".format(dyld_all_image_infos_dyldVersion)
750 if (dyld_all_imfo_infos_slide != 0):
751 out_str += " (currently {:#x})\n".format(dyld_all_image_infos_dyldVersion_postslide)
752 else:
753 out_str += "\n"
754
755 out_str += "errorMessage \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorMessage)
756 if dyld_all_image_infos_errorMessage != 0:
757 out_str += GetUserspaceString(task, dyld_all_image_infos_errorMessage)
758
759 out_str += "terminationFlags \t\t\t: {:#x}\n".format(dyld_all_image_infos_terminationFlags)
760 out_str += "coreSymbolicationShmPage \t\t: {:#x}\n".format(dyld_all_image_infos_coreSymbolicationShmPage)
761 out_str += "systemOrderFlag \t\t\t: {:#x}\n".format(dyld_all_image_infos_systemOrderFlag)
762 out_str += "uuidArrayCount \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArrayCount)
763 out_str += "uuidArray \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_uuidArray)
764 out_str += "dyldAllImageInfosAddress \t\t: {:#x}".format(dyld_all_image_infos_dyldAllImageInfosAddress)
765 if (dyld_all_imfo_infos_slide != 0):
766 out_str += " (currently {:#x})\n".format(dyld_all_image_infos_address)
767 else:
768 out_str += "\n"
769
770 if is_task_64:
771 dyld_all_image_infos_address = dyld_all_image_infos_address + 112
772 dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 64)
773 dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 112-112, "uint64_t")
774 dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 120-112, "uint64_t")
775 dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 128-112, "uint64_t")
776 dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 136-112, "uint64_t")
777 dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 144-112, "uint64_t")
778 dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 152-112, "uint64_t")
779 dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 160-112, "string")
780 else:
781 dyld_all_image_infos_address = dyld_all_image_infos_address + 60
782 dyld_all_image_infos_v10 = GetUserDataAsString(task, dyld_all_image_infos_address, 40)
783 dyld_all_image_infos_initialImageCount = _ExtractDataFromString(dyld_all_image_infos_v10, 60-60, "uint32_t")
784 dyld_all_image_infos_errorKind = _ExtractDataFromString(dyld_all_image_infos_v10, 64-60, "uint32_t")
785 dyld_all_image_infos_errorClientOfDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 68-60, "uint32_t")
786 dyld_all_image_infos_errorTargetDylibPath = _ExtractDataFromString(dyld_all_image_infos_v10, 72-60, "uint32_t")
787 dyld_all_image_infos_errorSymbol = _ExtractDataFromString(dyld_all_image_infos_v10, 76-60, "uint32_t")
788 dyld_all_image_infos_sharedCacheSlide = _ExtractDataFromString(dyld_all_image_infos_v10, 80-60, "uint32_t")
789 dyld_all_image_infos_sharedCacheUUID = _ExtractDataFromString(dyld_all_image_infos_v10, 84-60, "string")
790
791 if dyld_all_image_infos_version >= 10:
792 out_str += "\ninitialImageCount \t\t\t: {:#x}\n".format(dyld_all_image_infos_initialImageCount)
793
794 if dyld_all_image_infos_version >= 11:
795 out_str += "errorKind \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorKind)
796 out_str += "errorClientOfDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorClientOfDylibPath)
797 if dyld_all_image_infos_errorClientOfDylibPath != 0:
798 out_str += "\t\t\t\t"
799 out_str += GetUserspaceString(task, dyld_all_image_infos_errorClientOfDylibPath)
800 out_str += "\n"
801 out_str += "errorTargetDylibPath \t\t\t: {:#x}\n".format(dyld_all_image_infos_errorTargetDylibPath)
802 if dyld_all_image_infos_errorTargetDylibPath != 0:
803 out_str += "\t\t\t\t"
804 out_str += GetUserspaceString(task, dyld_all_image_infos_errorTargetDylibPath)
805 out_str += "\n"
806 out_str += "errorSymbol \t\t\t\t: {:#x}\n".format(dyld_all_image_infos_errorSymbol)
807 if dyld_all_image_infos_errorSymbol != 0:
808 out_str += "\t\t\t\t"
809 out_str += GetUserspaceString(task, dyld_all_image_infos_errorSymbol)
810 out_str += "\n"
811
812 if dyld_all_image_infos_version >= 12:
813 out_str += "sharedCacheSlide \t\t\t: {:#x}\n".format(dyld_all_image_infos_sharedCacheSlide)
814 if dyld_all_image_infos_version >= 13 and dyld_all_image_infos_sharedCacheUUID != "":
815 out_str += "sharedCacheUUID \t\t\t: {:s}\n".format(dyld_all_image_infos_sharedCacheUUID)
816 else:
817 out_str += "No dyld information available for task\n"
818 print out_str
819
820 # Macro: showosmalloc
821 @lldb_type_summary(['OSMallocTag'])
822 @header("{0: <20s} {1: >5s} {2: ^16s} {3: <5s} {4: <40s}".format("TAG", "COUNT", "STATE", "ATTR", "NAME"))
823 def GetOSMallocTagSummary(malloc_tag):
824 """ Summarize the given OSMalloc tag.
825 params:
826 malloc_tag : value - value representing a _OSMallocTag_ * in kernel
827 returns:
828 out_str - string summary of the OSMalloc tag.
829 """
830 if not malloc_tag:
831 return "Invalid malloc tag value: 0x0"
832
833 out_str = "{: <#20x} {: >5d} {: ^#16x} {: <5d} {: <40s}\n".format(malloc_tag,
834 malloc_tag.OSMT_refcnt, malloc_tag.OSMT_state, malloc_tag.OSMT_attr, malloc_tag.OSMT_name)
835 return out_str
836
837 @lldb_command('showosmalloc')
838 def ShowOSMalloc(cmd_args=None):
839 """ Print the outstanding allocation count of OSMalloc tags
840 Usage: showosmalloc
841 """
842 summary_str = ""
843 tag_headp = Cast(addressof(kern.globals.OSMalloc_tag_list), 'struct _OSMallocTag_ *')
844 tagp = Cast(tag_headp.OSMT_link.next, 'struct _OSMallocTag_ *')
845 summary_str += GetOSMallocTagSummary.header + "\n"
846 while tagp != tag_headp:
847 summary_str += GetOSMallocTagSummary(tagp)
848 tagp = Cast(tagp.OSMT_link.next, 'struct _OSMallocTag_ *')
849
850 print summary_str
851
852 # EndMacro: showosmalloc
853
854
855 @lldb_command('savekcdata', 'T:O:')
856 def SaveKCDataToFile(cmd_args=None, cmd_options={}):
857 """ Save the data referred by the kcdata_descriptor structure.
858 options:
859 -T: <task_t> pointer to task if memory referenced is in userstask.
860 -O: <output file path> path to file to save data. default: /tmp/kcdata.<timestamp>.bin
861 Usage: (lldb) savekcdata <kcdata_descriptor_t> -T <task_t> -O /path/to/outputfile.bin
862 """
863 if not cmd_args:
864 raise ArgumentError('Please provide the kcdata descriptor.')
865
866 kcdata = kern.GetValueFromAddress(cmd_args[0], 'kcdata_descriptor_t')
867
868 outputfile = '/tmp/kcdata.{:s}.bin'.format(str(time.time()))
869 task = None
870 if '-O' in cmd_options:
871 outputfile = cmd_options['-O']
872 if '-T' in cmd_options:
873 task = kern.GetValueFromAddress(cmd_options['-T'], 'task_t')
874
875 memory_begin_address = unsigned(kcdata.kcd_addr_begin)
876 memory_size = 16 + unsigned(kcdata.kcd_addr_end) - memory_begin_address
877 flags_copyout = unsigned(kcdata.kcd_flags)
878 if flags_copyout:
879 if not task:
880 raise ArgumentError('Invalid task pointer provided.')
881 memory_data = GetUserDataAsString(task, memory_begin_address, memory_size)
882 else:
883 data_ptr = kern.GetValueFromAddress(memory_begin_address, 'uint8_t *')
884 memory_data = []
885 for i in range(memory_size):
886 memory_data.append(chr(data_ptr[i]))
887 if i % 50000 == 0:
888 print "%d of %d \r" % (i, memory_size),
889 memory_data = ''.join(memory_data)
890
891 if len(memory_data) != memory_size:
892 print "Failed to read {:d} bytes from address {: <#020x}".format(memory_size, memory_begin_address)
893 return False
894
895 fh = open(outputfile, 'w')
896 fh.write(memory_data)
897 fh.close()
898 print "Saved {:d} bytes to file {:s}".format(memory_size, outputfile)
899 return True
900
901
902