CoreDump.cpp 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270
  1. /*
  2. * Copyright (c) 2019-2020, Jesse Buhagiar <jooster669@gmail.com>
  3. * Copyright (c) 2020, Itamar S. <itamar8910@gmail.com>
  4. * All rights reserved.
  5. *
  6. * Redistribution and use in source and binary forms, with or without
  7. * modification, are permitted provided that the following conditions are met:
  8. *
  9. * 1. Redistributions of source code must retain the above copyright notice, this
  10. * list of conditions and the following disclaimer.
  11. *
  12. * 2. Redistributions in binary form must reproduce the above copyright notice,
  13. * this list of conditions and the following disclaimer in the documentation
  14. * and/or other materials provided with the distribution.
  15. *
  16. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
  17. * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  18. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  19. * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE
  20. * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
  21. * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
  22. * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
  23. * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
  24. * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
  25. * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  26. */
  27. #include <AK/ByteBuffer.h>
  28. #include <Kernel/CoreDump.h>
  29. #include <Kernel/FileSystem/Custody.h>
  30. #include <Kernel/FileSystem/FileDescription.h>
  31. #include <Kernel/FileSystem/VirtualFileSystem.h>
  32. #include <Kernel/Process.h>
  33. #include <Kernel/Ptrace.h>
  34. #include <Kernel/RTC.h>
  35. #include <Kernel/SpinLock.h>
  36. #include <Kernel/VM/ProcessPagingScope.h>
  37. #include <LibELF/CoreDump.h>
  38. #include <LibELF/exec_elf.h>
  39. namespace Kernel {
  40. OwnPtr<CoreDump> CoreDump::create(Process& process)
  41. {
  42. auto fd = create_target_file(process);
  43. if (!fd)
  44. return nullptr;
  45. return make<CoreDump>(process, fd.release_nonnull());
  46. }
  47. CoreDump::CoreDump(Process& process, NonnullRefPtr<FileDescription>&& fd)
  48. : m_process(process)
  49. , m_fd(move(fd))
  50. , m_num_program_headers(process.m_regions.size() + 1) // +1 for NOTE segment
  51. {
  52. }
  53. CoreDump::~CoreDump()
  54. {
  55. }
  56. RefPtr<FileDescription> CoreDump::create_target_file(const Process& process)
  57. {
  58. static constexpr const char* coredumps_directory = "/tmp/coredump";
  59. if (VFS::the().open_directory(coredumps_directory, VFS::the().root_custody()).is_error()) {
  60. auto res = VFS::the().mkdir(coredumps_directory, 0777, VFS::the().root_custody());
  61. if (res.is_error())
  62. return nullptr;
  63. }
  64. auto tmp_dir = VFS::the().open_directory(coredumps_directory, VFS::the().root_custody());
  65. if (tmp_dir.is_error())
  66. return nullptr;
  67. auto fd_or_error = VFS::the().open(
  68. String::format("%s_%u.core", process.name().characters(), RTC::now()),
  69. O_CREAT | O_WRONLY | O_EXCL,
  70. 0, // We will enable reading from userspace when we finish generating the coredump file
  71. *tmp_dir.value(),
  72. UidAndGid { process.uid(), process.gid() });
  73. if (fd_or_error.is_error())
  74. return nullptr;
  75. return fd_or_error.value();
  76. }
  77. void CoreDump::write_elf_header()
  78. {
  79. Elf32_Ehdr elf_file_header;
  80. elf_file_header.e_ident[EI_MAG0] = 0x7f;
  81. elf_file_header.e_ident[EI_MAG1] = 'E';
  82. elf_file_header.e_ident[EI_MAG2] = 'L';
  83. elf_file_header.e_ident[EI_MAG3] = 'F';
  84. elf_file_header.e_ident[EI_CLASS] = ELFCLASS32;
  85. elf_file_header.e_ident[EI_DATA] = ELFDATA2LSB;
  86. elf_file_header.e_ident[EI_VERSION] = EV_CURRENT;
  87. elf_file_header.e_ident[EI_OSABI] = 0; // ELFOSABI_NONE
  88. elf_file_header.e_ident[EI_ABIVERSION] = 0;
  89. elf_file_header.e_ident[EI_PAD + 1] = 0;
  90. elf_file_header.e_ident[EI_PAD + 2] = 0;
  91. elf_file_header.e_ident[EI_PAD + 3] = 0;
  92. elf_file_header.e_ident[EI_PAD + 4] = 0;
  93. elf_file_header.e_ident[EI_PAD + 5] = 0;
  94. elf_file_header.e_ident[EI_PAD + 6] = 0;
  95. elf_file_header.e_ident[EI_NIDENT] = 16;
  96. elf_file_header.e_type = ET_CORE;
  97. elf_file_header.e_machine = EM_386;
  98. elf_file_header.e_version = 1;
  99. elf_file_header.e_entry = 0;
  100. elf_file_header.e_phoff = sizeof(Elf32_Ehdr);
  101. elf_file_header.e_shoff = 0;
  102. elf_file_header.e_flags = 0;
  103. elf_file_header.e_ehsize = sizeof(Elf32_Ehdr);
  104. elf_file_header.e_shentsize = sizeof(Elf32_Shdr);
  105. elf_file_header.e_phentsize = sizeof(Elf32_Phdr);
  106. elf_file_header.e_phnum = m_num_program_headers;
  107. elf_file_header.e_shnum = 0;
  108. elf_file_header.e_shstrndx = SHN_UNDEF;
  109. (void)m_fd->write(UserOrKernelBuffer::for_kernel_buffer(reinterpret_cast<uint8_t*>(&elf_file_header)), sizeof(Elf32_Ehdr));
  110. }
  111. void CoreDump::write_program_headers(size_t notes_size)
  112. {
  113. size_t offset = sizeof(Elf32_Ehdr) + m_num_program_headers * sizeof(Elf32_Phdr);
  114. for (auto& region : m_process.m_regions) {
  115. Elf32_Phdr phdr {};
  116. phdr.p_type = PT_LOAD;
  117. phdr.p_offset = offset;
  118. phdr.p_vaddr = reinterpret_cast<uint32_t>(region.vaddr().as_ptr());
  119. phdr.p_paddr = 0;
  120. phdr.p_filesz = region.page_count() * PAGE_SIZE;
  121. phdr.p_memsz = region.page_count() * PAGE_SIZE;
  122. phdr.p_align = 0;
  123. phdr.p_flags = region.is_readable() ? PF_R : 0;
  124. if (region.is_writable())
  125. phdr.p_flags |= PF_W;
  126. if (region.is_executable())
  127. phdr.p_flags |= PF_X;
  128. offset += phdr.p_filesz;
  129. (void)m_fd->write(UserOrKernelBuffer::for_kernel_buffer(reinterpret_cast<uint8_t*>(&phdr)), sizeof(Elf32_Phdr));
  130. }
  131. Elf32_Phdr notes_pheader {};
  132. notes_pheader.p_type = PT_NOTE;
  133. notes_pheader.p_offset = offset;
  134. notes_pheader.p_vaddr = 0;
  135. notes_pheader.p_paddr = 0;
  136. notes_pheader.p_filesz = notes_size;
  137. notes_pheader.p_memsz = 0;
  138. notes_pheader.p_align = 0;
  139. notes_pheader.p_flags = 0;
  140. (void)m_fd->write(UserOrKernelBuffer::for_kernel_buffer(reinterpret_cast<uint8_t*>(&notes_pheader)), sizeof(Elf32_Phdr));
  141. }
  142. void CoreDump::write_regions()
  143. {
  144. for (auto& region : m_process.m_regions) {
  145. if (region.is_kernel())
  146. continue;
  147. region.set_readable(true);
  148. region.remap();
  149. auto& vmobj = region.vmobject();
  150. for (size_t i = 0; i < region.page_count(); i++) {
  151. PhysicalPage* page = vmobj.physical_pages()[region.first_page_index() + i];
  152. uint8_t zero_buffer[PAGE_SIZE] = {};
  153. Optional<UserOrKernelBuffer> src_buffer;
  154. if (page) {
  155. src_buffer = UserOrKernelBuffer::for_user_buffer(reinterpret_cast<uint8_t*>((region.vaddr().as_ptr() + (i * PAGE_SIZE))), PAGE_SIZE);
  156. } else {
  157. // If the current page is not backed by a physical page, we zero it in the coredump file.
  158. // TODO: Do we want to include the contents of pages that have not been faulted-in in the coredump?
  159. // (A page may not be backed by a physical page because it has never been faulted in when the process ran).
  160. src_buffer = UserOrKernelBuffer::for_kernel_buffer(zero_buffer);
  161. }
  162. (void)m_fd->write(src_buffer.value(), PAGE_SIZE);
  163. }
  164. }
  165. }
  166. void CoreDump::write_notes_segment(ByteBuffer& notes_segment)
  167. {
  168. (void)m_fd->write(UserOrKernelBuffer::for_kernel_buffer(notes_segment.data()), notes_segment.size());
  169. }
  170. ByteBuffer CoreDump::create_notes_threads_data() const
  171. {
  172. ByteBuffer threads_data;
  173. m_process.for_each_thread([&](Thread& thread) {
  174. ByteBuffer entry_buff;
  175. ELF::Core::ThreadInfo info {};
  176. info.header.type = ELF::Core::NotesEntryHeader::Type::ThreadInfo;
  177. info.tid = thread.tid().value();
  178. Ptrace::copy_kernel_registers_into_ptrace_registers(info.regs, thread.get_register_dump_from_stack());
  179. entry_buff.append((void*)&info, sizeof(info));
  180. threads_data += entry_buff;
  181. return IterationDecision::Continue;
  182. });
  183. return threads_data;
  184. }
  185. ByteBuffer CoreDump::create_notes_regions_data() const
  186. {
  187. ByteBuffer regions_data;
  188. for (size_t region_index = 0; region_index < m_process.m_regions.size(); ++region_index) {
  189. ByteBuffer memory_region_info_buffer;
  190. ELF::Core::MemoryRegionInfo info {};
  191. info.header.type = ELF::Core::NotesEntryHeader::Type::MemoryRegionInfo;
  192. auto& region = m_process.m_regions[region_index];
  193. info.region_start = reinterpret_cast<uint32_t>(region.vaddr().as_ptr());
  194. info.region_end = reinterpret_cast<uint32_t>(region.vaddr().as_ptr() + region.size());
  195. info.program_header_index = region_index;
  196. memory_region_info_buffer.append((void*)&info, sizeof(info));
  197. auto name = region.name();
  198. if (name.is_null())
  199. name = String::empty();
  200. memory_region_info_buffer.append(name.characters(), name.length() + 1);
  201. regions_data += memory_region_info_buffer;
  202. }
  203. return regions_data;
  204. }
  205. ByteBuffer CoreDump::create_notes_segment_data() const
  206. {
  207. ByteBuffer notes_buffer;
  208. notes_buffer += create_notes_threads_data();
  209. notes_buffer += create_notes_regions_data();
  210. ELF::Core::NotesEntryHeader null_entry {};
  211. null_entry.type = ELF::Core::NotesEntryHeader::Type::Null;
  212. notes_buffer.append(&null_entry, sizeof(null_entry));
  213. return notes_buffer;
  214. }
  215. void CoreDump::write()
  216. {
  217. ProcessPagingScope scope(m_process);
  218. ByteBuffer notes_segment = create_notes_segment_data();
  219. write_elf_header();
  220. write_program_headers(notes_segment.size());
  221. write_regions();
  222. write_notes_segment(notes_segment);
  223. (void)m_fd->chmod(0400); // Make coredump file readable
  224. }
  225. }