2 # class for use inside gdb which is debugging the donor process
4 from __future__ import print_function
12 def _string_bytearray(s):
13 # gets us bytes in py2 and py3
14 if not isinstance(s, bytes):
15 s = s.encode('utf-8') # sigh, python 2/3 compat
18 def _string_escape_for_c(s):
20 for c in _string_bytearray(s):
21 if c == ord('\\') or c == ord('"') or c < 32 or c > 126:
32 def _lit_aggregate_uncasted(val_lit_strs):
33 return '{' + ', '.join(['(%s)' % v for v in val_lit_strs]) + ' }'
35 def _lit_string_uncasted(s):
36 b = _string_bytearray(s)
37 return _lit_aggregate_uncasted([_lit_integer(x) for x in b] + [ '0' ])
39 def _lit_array(elemtype, val_lit_strs):
42 (elemtype, len(val_lit_strs), _lit_aggregate_uncasted(val_lit_strs))
45 def _lit_addressof(v):
46 return '&(char[])(%s)' % v
49 if isinstance(v, int):
50 return _lit_integer(v)
52 return v # should already be an integer
55 sys.stderr.write("## EVAL %s\n" % repr(expr))
56 x = gdb.parse_and_eval(expr)
57 sys.stderr.write('## => %s\n' % x)
61 class DonorStructLayout():
62 def __init__(l, typename):
63 x = gdb.lookup_type(typename)
64 l._typename = typename
68 l._posns[f.name] = len(l._template)
69 try: f.type.fields(); blank = '{ }'
70 except TypeError: blank = '0'
71 except AttributeError: blank = '0'
72 l._template.append(blank)
73 sys.stderr.write('## STRUCT %s template %s fields %s\n'
74 % (typename, l._template, l._posns))
76 def substitute(l, values):
77 build = copy.deepcopy(l._template)
78 for (k,v) in values.items():
79 build[ l._posns[k] ] = _make_lit(v)
80 return '((%s)%s)' % (l._typename, _lit_aggregate_uncasted(build))
82 class DonorImplementation():
85 di._saved_errno = None
86 di._result_stream = os.fdopen(3, 'w')
87 di._errno_workaround = None
90 # sigh, we have to record the order of the arguments!
91 def _find_fields(di, typename):
93 fields = di._structs[typename]
95 fields = DonorStructLayout(typename)
96 di._structs[typename] = fields
99 def _make(di, typename, values):
100 fields = di._find_fields(typename)
101 return fields.substitute(values)
105 def _parse_eval_errno(di, expr_pat):
106 # evaluates expr_pat % 'errno'
107 if di._errno_workaround is not True:
109 x = parse_eval(expr_pat % 'errno')
110 di._errno_workaround = False
112 except gdb.error as e:
113 if di._errno_workaround is False:
115 di._errno_workaround = True
116 # Incomprehensibly, gdb.parse_and_eval('errno') can sometimes
118 # gdb.error: Cannot find thread-local variables on this target
119 # even though plain gdb `print errno' works while `print errno = 25'
120 # doesn't. OMG. This may be related to:
121 # https://github.com/cloudburst/libheap/issues/24
122 # although I can't find it in the gdb bug db (which is half-broken
123 # in my browser). Also the error is very nonspecific :-/.
124 # This seems to happen on jessie, and is fixed in stretch.
126 return parse_eval(expr_pat % '(*((int (*)(void))__errno_location)())')
128 # calling functions (need to cast the function name to the right
129 # type in case maybe gdb doesn't know the type)
131 def _func(di, functype, funcname, realargs):
132 expr = '((%s) %s) %s' % (functype, funcname, realargs)
133 return parse_eval(expr)
135 def _must_func(di, functype, funcname, realargs):
136 retval = di._func(functype, funcname, realargs)
138 errnoval = di._parse_eval_errno('%s')
139 raise RuntimeError("%s gave errno=%d `%s'" %
140 (funcname, errnoval, os.strerror(errnoval)))
143 # wrappers for the syscalls that do what we want
145 def _sendmsg(di, carrier, control_msg):
146 iov_base = _lit_array('char', [1])
147 iov = di._make('struct iovec', {
148 'iov_base': iov_base,
152 msg = di._make('struct msghdr', {
153 'msg_iov' : _lit_addressof(iov),
155 'msg_control' : _lit_array('char', control_msg),
156 'msg_controllen': len(control_msg),
160 'ssize_t (*)(int, const struct msghdr*, int)',
162 '(%s, %s, 0)' % (carrier, _lit_addressof(msg))
166 return di._must_func(
167 'int (*)(int, int, int)',
169 '(%d, %d, 0)' % (socket.AF_UNIX, socket.SOCK_STREAM)
172 def _connect(di, fd, path):
173 addr = di._make('struct sockaddr_un', {
174 'sun_family' : _lit_integer(socket.AF_UNIX),
175 'sun_path' : _lit_string_uncasted(path),
179 'int (*)(int, const struct sockaddr*, socklen_t)',
181 '(%d, (const struct sockaddr*)%s, sizeof(struct sockaddr_un))'
182 % (fd, _lit_addressof(addr))
186 di._must_func('int (*)(int)', 'close', '(%d)' % fd)
188 def _mkdir(di, path, mode):
190 'int (*)(const char*, mode_t)',
192 '("%s", %d)' % (_string_escape_for_c(path), mode)
195 errnoval = di._parse_eval_errno('%s')
196 if errnoval != os.errno.EEXIST:
197 raise RuntimeError("mkdir %s failed: `%s'" %
198 (repr(path), os.strerror(errnoval)))
203 di._saved_errno = di._parse_eval_errno('%s')
205 def _errno_restore(di):
206 to_restore = di._saved_errno
207 di._saved_errno = None
208 if to_restore is not None:
209 di._parse_eval_errno('%%s = %d' % to_restore)
211 def _result(di, output):
212 sys.stderr.write("#> %s" % output)
213 di._result_stream.write(output)
214 di._result_stream.flush()
218 def donate(di, path, control_msg):
219 # control_msg is an array of integers being the ancillary data
220 # array ("control") for sendmsg, and hence specifies which fds
226 carrier = di._socket()
227 di._connect(carrier, path)
228 di._sendmsg(carrier, control_msg)
232 if carrier is not None:
233 try: di._close(carrier)
234 except Exception: pass
242 val = di._must_func('uid_t (*)(void)', 'geteuid', '()')
246 di._result('%d\n' % val)
251 val = di._mkdir(path, int('0700', 8))
255 di._result('%d\n' % val)
257 def _protocol_read(di):
258 input = sys.stdin.readline()
259 if input == '': return None
260 input = input.rstrip('\n')
261 sys.stderr.write("#< %s\n" % input)
265 if not gdb.selected_inferior().was_attached:
266 print('gdb inferior not attached', file=sys.stderr)
270 cmd = di._protocol_read()
271 if cmd is None: break