2020-05-09 13:00:55 +01:00
|
|
|
/*
|
|
|
|
* Copyright (c) 2020, Itamar S. <itamar8910@gmail.com>
|
|
|
|
* All rights reserved.
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions are met:
|
|
|
|
*
|
|
|
|
* 1. Redistributions of source code must retain the above copyright notice, this
|
|
|
|
* list of conditions and the following disclaimer.
|
|
|
|
*
|
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright notice,
|
|
|
|
* this list of conditions and the following disclaimer in the documentation
|
|
|
|
* and/or other materials provided with the distribution.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
|
|
|
* AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
|
|
|
|
* DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
|
|
|
|
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
|
|
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
|
|
|
|
* SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
|
|
|
|
* CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
|
|
|
|
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
|
|
|
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
*/
|
|
|
|
|
2020-04-07 18:23:37 +03:00
|
|
|
#include <Kernel/Process.h>
|
|
|
|
#include <Kernel/Ptrace.h>
|
|
|
|
#include <Kernel/Thread.h>
|
|
|
|
#include <Kernel/ThreadTracer.h>
|
|
|
|
#include <Kernel/VM/MemoryManager.h>
|
|
|
|
#include <Kernel/VM/ProcessPagingScope.h>
|
|
|
|
|
|
|
|
namespace Ptrace {
|
|
|
|
|
|
|
|
KResultOr<u32> handle_syscall(const Kernel::Syscall::SC_ptrace_params& params, Process& caller)
|
|
|
|
{
|
|
|
|
if (params.request == PT_TRACE_ME) {
|
2020-06-28 15:34:31 -06:00
|
|
|
if (Thread::current()->tracer())
|
2020-04-07 18:23:37 +03:00
|
|
|
return KResult(-EBUSY);
|
|
|
|
|
|
|
|
caller.set_wait_for_tracer_at_next_execve(true);
|
|
|
|
return KSuccess;
|
|
|
|
}
|
|
|
|
|
2020-08-09 01:08:24 +02:00
|
|
|
// FIXME: PID/TID BUG
|
|
|
|
// This bug allows to request PT_ATTACH (or anything else) the same process, as
|
|
|
|
// long it is not the main thread. Alternatively, if this is desired, then the
|
|
|
|
// bug is that this prevents PT_ATTACH to the main thread from another thread.
|
|
|
|
if (params.tid == caller.pid().value())
|
2020-04-07 18:23:37 +03:00
|
|
|
return KResult(-EINVAL);
|
|
|
|
|
|
|
|
Thread* peer = nullptr;
|
|
|
|
{
|
|
|
|
InterruptDisabler disabler;
|
2020-08-09 01:08:24 +02:00
|
|
|
peer = Thread::from_tid(params.tid);
|
2020-04-07 18:23:37 +03:00
|
|
|
}
|
|
|
|
if (!peer)
|
|
|
|
return KResult(-ESRCH);
|
|
|
|
|
|
|
|
if ((peer->process().uid() != caller.euid())
|
|
|
|
|| (peer->process().uid() != peer->process().euid())) // Disallow tracing setuid processes
|
|
|
|
return KResult(-EACCES);
|
|
|
|
|
|
|
|
if (params.request == PT_ATTACH) {
|
|
|
|
if (peer->tracer()) {
|
|
|
|
return KResult(-EBUSY);
|
|
|
|
}
|
|
|
|
peer->start_tracing_from(caller.pid());
|
2020-08-02 16:59:01 -06:00
|
|
|
if (peer->state() != Thread::State::Stopped) {
|
|
|
|
ScopedSpinLock lock(peer->get_lock());
|
|
|
|
if (!(peer->has_blocker() && peer->blocker().is_reason_signal()))
|
|
|
|
peer->send_signal(SIGSTOP, &caller);
|
|
|
|
}
|
2020-04-07 18:23:37 +03:00
|
|
|
return KSuccess;
|
|
|
|
}
|
|
|
|
|
|
|
|
auto* tracer = peer->tracer();
|
|
|
|
|
|
|
|
if (!tracer)
|
|
|
|
return KResult(-EPERM);
|
|
|
|
|
|
|
|
if (tracer->tracer_pid() != caller.pid())
|
|
|
|
return KResult(-EBUSY);
|
|
|
|
|
|
|
|
if (peer->state() == Thread::State::Running)
|
|
|
|
return KResult(-EBUSY);
|
|
|
|
|
|
|
|
switch (params.request) {
|
|
|
|
case PT_CONTINUE:
|
|
|
|
peer->send_signal(SIGCONT, &caller);
|
|
|
|
break;
|
|
|
|
|
|
|
|
case PT_DETACH:
|
|
|
|
peer->stop_tracing();
|
|
|
|
peer->send_signal(SIGCONT, &caller);
|
|
|
|
break;
|
|
|
|
|
|
|
|
case PT_SYSCALL:
|
|
|
|
tracer->set_trace_syscalls(true);
|
|
|
|
peer->send_signal(SIGCONT, &caller);
|
|
|
|
break;
|
|
|
|
|
|
|
|
case PT_GETREGS: {
|
|
|
|
if (!tracer->has_regs())
|
|
|
|
return KResult(-EINVAL);
|
|
|
|
|
2020-09-11 21:11:07 -06:00
|
|
|
auto* regs = reinterpret_cast<PtraceRegisters*>(params.addr);
|
|
|
|
if (!copy_to_user(regs, &tracer->regs()))
|
2020-04-07 18:23:37 +03:00
|
|
|
return KResult(-EFAULT);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
case PT_SETREGS: {
|
|
|
|
if (!tracer->has_regs())
|
|
|
|
return KResult(-EINVAL);
|
|
|
|
|
2020-04-14 09:50:14 +02:00
|
|
|
PtraceRegisters regs;
|
2020-09-11 21:11:07 -06:00
|
|
|
if (!copy_from_user(®s, (const PtraceRegisters*)params.addr))
|
2020-04-07 18:23:37 +03:00
|
|
|
return KResult(-EFAULT);
|
|
|
|
|
|
|
|
auto& peer_saved_registers = peer->get_register_dump_from_stack();
|
|
|
|
// Verify that the saved registers are in usermode context
|
2020-04-14 09:50:14 +02:00
|
|
|
if ((peer_saved_registers.cs & 0x03) != 3)
|
|
|
|
return KResult(-EFAULT);
|
2020-04-10 17:34:31 +03:00
|
|
|
|
2020-04-14 09:50:14 +02:00
|
|
|
tracer->set_regs(regs);
|
|
|
|
copy_ptrace_registers_into_kernel_registers(peer_saved_registers, regs);
|
|
|
|
break;
|
2020-04-07 18:23:37 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
case PT_PEEK: {
|
2020-04-10 17:34:31 +03:00
|
|
|
Kernel::Syscall::SC_ptrace_peek_params peek_params;
|
2020-09-11 21:11:07 -06:00
|
|
|
if (!copy_from_user(&peek_params, reinterpret_cast<Kernel::Syscall::SC_ptrace_peek_params*>(params.addr)))
|
2020-04-10 17:34:31 +03:00
|
|
|
return -EFAULT;
|
2020-08-01 15:25:19 -07:00
|
|
|
|
2020-04-10 17:34:31 +03:00
|
|
|
// read validation is done inside 'peek_user_data'
|
2020-09-11 21:11:07 -06:00
|
|
|
auto result = peer->process().peek_user_data((FlatPtr)peek_params.address);
|
2020-04-10 17:34:31 +03:00
|
|
|
if (result.is_error())
|
|
|
|
return -EFAULT;
|
2020-09-11 21:11:07 -06:00
|
|
|
if (!copy_to_user(peek_params.out_data, &result.value()))
|
2020-04-13 22:40:38 +02:00
|
|
|
return -EFAULT;
|
2020-04-10 17:34:31 +03:00
|
|
|
break;
|
2020-04-07 18:23:37 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
case PT_POKE: {
|
2020-09-11 21:11:07 -06:00
|
|
|
Userspace<u32*> addr = reinterpret_cast<FlatPtr>(params.addr);
|
2020-04-10 17:34:31 +03:00
|
|
|
// write validation is done inside 'poke_user_data'
|
2020-04-07 18:23:37 +03:00
|
|
|
return peer->process().poke_user_data(addr, params.data);
|
|
|
|
}
|
|
|
|
|
|
|
|
default:
|
|
|
|
return -EINVAL;
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
void copy_kernel_registers_into_ptrace_registers(PtraceRegisters& ptrace_regs, const RegisterState& kernel_regs)
|
|
|
|
{
|
|
|
|
ptrace_regs.eax = kernel_regs.eax,
|
|
|
|
ptrace_regs.ecx = kernel_regs.ecx,
|
|
|
|
ptrace_regs.edx = kernel_regs.edx,
|
|
|
|
ptrace_regs.ebx = kernel_regs.ebx,
|
|
|
|
ptrace_regs.esp = kernel_regs.userspace_esp,
|
|
|
|
ptrace_regs.ebp = kernel_regs.ebp,
|
|
|
|
ptrace_regs.esi = kernel_regs.esi,
|
|
|
|
ptrace_regs.edi = kernel_regs.edi,
|
|
|
|
ptrace_regs.eip = kernel_regs.eip,
|
|
|
|
ptrace_regs.eflags = kernel_regs.eflags,
|
|
|
|
ptrace_regs.cs = 0;
|
|
|
|
ptrace_regs.ss = 0;
|
|
|
|
ptrace_regs.ds = 0;
|
|
|
|
ptrace_regs.es = 0;
|
|
|
|
ptrace_regs.fs = 0;
|
|
|
|
ptrace_regs.gs = 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
void copy_ptrace_registers_into_kernel_registers(RegisterState& kernel_regs, const PtraceRegisters& ptrace_regs)
|
|
|
|
{
|
|
|
|
kernel_regs.eax = ptrace_regs.eax;
|
|
|
|
kernel_regs.ecx = ptrace_regs.ecx;
|
|
|
|
kernel_regs.edx = ptrace_regs.edx;
|
|
|
|
kernel_regs.ebx = ptrace_regs.ebx;
|
|
|
|
kernel_regs.esp = ptrace_regs.esp;
|
|
|
|
kernel_regs.ebp = ptrace_regs.ebp;
|
|
|
|
kernel_regs.esi = ptrace_regs.esi;
|
|
|
|
kernel_regs.edi = ptrace_regs.edi;
|
|
|
|
kernel_regs.eip = ptrace_regs.eip;
|
|
|
|
kernel_regs.eflags = ptrace_regs.eflags;
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|