CoreDump.cpp 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345
  1. /*
  2. * Copyright (c) 2019-2020, Jesse Buhagiar <jooster669@gmail.com>
  3. * Copyright (c) 2020, Itamar S. <itamar8910@gmail.com>
  4. * Copyright (c) 2020-2021, Linus Groh <linusg@serenityos.org>
  5. * Copyright (c) 2021, Andreas Kling <klingi@serenityos.org>
  6. *
  7. * SPDX-License-Identifier: BSD-2-Clause
  8. */
  9. #include <AK/ByteBuffer.h>
  10. #include <AK/JsonObjectSerializer.h>
  11. #include <Kernel/CoreDump.h>
  12. #include <Kernel/FileSystem/Custody.h>
  13. #include <Kernel/FileSystem/FileDescription.h>
  14. #include <Kernel/FileSystem/VirtualFileSystem.h>
  15. #include <Kernel/KLexicalPath.h>
  16. #include <Kernel/Locking/Spinlock.h>
  17. #include <Kernel/Memory/ProcessPagingScope.h>
  18. #include <Kernel/Process.h>
  19. #include <Kernel/RTC.h>
  20. #include <LibC/elf.h>
  21. #include <LibELF/CoreDump.h>
  22. namespace Kernel {
  23. OwnPtr<CoreDump> CoreDump::create(NonnullRefPtr<Process> process, const String& output_path)
  24. {
  25. if (!process->is_dumpable()) {
  26. dbgln("Refusing to generate CoreDump for non-dumpable process {}", process->pid().value());
  27. return {};
  28. }
  29. auto fd = create_target_file(process, output_path);
  30. if (!fd)
  31. return {};
  32. return adopt_own_if_nonnull(new (nothrow) CoreDump(move(process), fd.release_nonnull()));
  33. }
  34. CoreDump::CoreDump(NonnullRefPtr<Process> process, NonnullRefPtr<FileDescription>&& fd)
  35. : m_process(move(process))
  36. , m_fd(move(fd))
  37. , m_num_program_headers(m_process->address_space().region_count() + 1) // +1 for NOTE segment
  38. {
  39. }
  40. RefPtr<FileDescription> CoreDump::create_target_file(const Process& process, const String& output_path)
  41. {
  42. auto output_directory = KLexicalPath::dirname(output_path);
  43. auto dump_directory = VirtualFileSystem::the().open_directory(output_directory, VirtualFileSystem::the().root_custody());
  44. if (dump_directory.is_error()) {
  45. dbgln("Can't find directory '{}' for core dump", output_directory);
  46. return nullptr;
  47. }
  48. auto dump_directory_metadata = dump_directory.value()->inode().metadata();
  49. if (dump_directory_metadata.uid != 0 || dump_directory_metadata.gid != 0 || dump_directory_metadata.mode != 040777) {
  50. dbgln("Refusing to put core dump in sketchy directory '{}'", output_directory);
  51. return nullptr;
  52. }
  53. auto fd_or_error = VirtualFileSystem::the().open(
  54. KLexicalPath::basename(output_path),
  55. O_CREAT | O_WRONLY | O_EXCL,
  56. S_IFREG, // We will enable reading from userspace when we finish generating the coredump file
  57. *dump_directory.value(),
  58. UidAndGid { process.uid(), process.gid() });
  59. if (fd_or_error.is_error()) {
  60. dbgln("Failed to open core dump '{}' for writing", output_path);
  61. return nullptr;
  62. }
  63. return fd_or_error.value();
  64. }
  65. KResult CoreDump::write_elf_header()
  66. {
  67. ElfW(Ehdr) elf_file_header;
  68. elf_file_header.e_ident[EI_MAG0] = 0x7f;
  69. elf_file_header.e_ident[EI_MAG1] = 'E';
  70. elf_file_header.e_ident[EI_MAG2] = 'L';
  71. elf_file_header.e_ident[EI_MAG3] = 'F';
  72. #if ARCH(I386)
  73. elf_file_header.e_ident[EI_CLASS] = ELFCLASS32;
  74. #else
  75. elf_file_header.e_ident[EI_CLASS] = ELFCLASS64;
  76. #endif
  77. elf_file_header.e_ident[EI_DATA] = ELFDATA2LSB;
  78. elf_file_header.e_ident[EI_VERSION] = EV_CURRENT;
  79. elf_file_header.e_ident[EI_OSABI] = 0; // ELFOSABI_NONE
  80. elf_file_header.e_ident[EI_ABIVERSION] = 0;
  81. elf_file_header.e_ident[EI_PAD + 1] = 0;
  82. elf_file_header.e_ident[EI_PAD + 2] = 0;
  83. elf_file_header.e_ident[EI_PAD + 3] = 0;
  84. elf_file_header.e_ident[EI_PAD + 4] = 0;
  85. elf_file_header.e_ident[EI_PAD + 5] = 0;
  86. elf_file_header.e_ident[EI_PAD + 6] = 0;
  87. elf_file_header.e_type = ET_CORE;
  88. #if ARCH(I386)
  89. elf_file_header.e_machine = EM_386;
  90. #else
  91. elf_file_header.e_machine = EM_X86_64;
  92. #endif
  93. elf_file_header.e_version = 1;
  94. elf_file_header.e_entry = 0;
  95. elf_file_header.e_phoff = sizeof(ElfW(Ehdr));
  96. elf_file_header.e_shoff = 0;
  97. elf_file_header.e_flags = 0;
  98. elf_file_header.e_ehsize = sizeof(ElfW(Ehdr));
  99. elf_file_header.e_shentsize = sizeof(ElfW(Shdr));
  100. elf_file_header.e_phentsize = sizeof(ElfW(Phdr));
  101. elf_file_header.e_phnum = m_num_program_headers;
  102. elf_file_header.e_shnum = 0;
  103. elf_file_header.e_shstrndx = SHN_UNDEF;
  104. auto result = m_fd->write(UserOrKernelBuffer::for_kernel_buffer(reinterpret_cast<uint8_t*>(&elf_file_header)), sizeof(ElfW(Ehdr)));
  105. if (result.is_error())
  106. return result.error();
  107. return KSuccess;
  108. }
  109. KResult CoreDump::write_program_headers(size_t notes_size)
  110. {
  111. size_t offset = sizeof(ElfW(Ehdr)) + m_num_program_headers * sizeof(ElfW(Phdr));
  112. for (auto& region : m_process->address_space().regions()) {
  113. ElfW(Phdr) phdr {};
  114. phdr.p_type = PT_LOAD;
  115. phdr.p_offset = offset;
  116. phdr.p_vaddr = region->vaddr().get();
  117. phdr.p_paddr = 0;
  118. phdr.p_filesz = region->page_count() * PAGE_SIZE;
  119. phdr.p_memsz = region->page_count() * PAGE_SIZE;
  120. phdr.p_align = 0;
  121. phdr.p_flags = region->is_readable() ? PF_R : 0;
  122. if (region->is_writable())
  123. phdr.p_flags |= PF_W;
  124. if (region->is_executable())
  125. phdr.p_flags |= PF_X;
  126. offset += phdr.p_filesz;
  127. [[maybe_unused]] auto rc = m_fd->write(UserOrKernelBuffer::for_kernel_buffer(reinterpret_cast<uint8_t*>(&phdr)), sizeof(ElfW(Phdr)));
  128. }
  129. ElfW(Phdr) notes_pheader {};
  130. notes_pheader.p_type = PT_NOTE;
  131. notes_pheader.p_offset = offset;
  132. notes_pheader.p_vaddr = 0;
  133. notes_pheader.p_paddr = 0;
  134. notes_pheader.p_filesz = notes_size;
  135. notes_pheader.p_memsz = notes_size;
  136. notes_pheader.p_align = 0;
  137. notes_pheader.p_flags = 0;
  138. auto result = m_fd->write(UserOrKernelBuffer::for_kernel_buffer(reinterpret_cast<uint8_t*>(&notes_pheader)), sizeof(ElfW(Phdr)));
  139. if (result.is_error())
  140. return result.error();
  141. return KSuccess;
  142. }
  143. KResult CoreDump::write_regions()
  144. {
  145. for (auto& region : m_process->address_space().regions()) {
  146. if (region->is_kernel())
  147. continue;
  148. region->set_readable(true);
  149. region->remap();
  150. for (size_t i = 0; i < region->page_count(); i++) {
  151. auto* page = region->physical_page(i);
  152. uint8_t zero_buffer[PAGE_SIZE] = {};
  153. Optional<UserOrKernelBuffer> src_buffer;
  154. if (page) {
  155. src_buffer = UserOrKernelBuffer::for_user_buffer(reinterpret_cast<uint8_t*>((region->vaddr().as_ptr() + (i * PAGE_SIZE))), PAGE_SIZE);
  156. } else {
  157. // If the current page is not backed by a physical page, we zero it in the coredump file.
  158. // TODO: Do we want to include the contents of pages that have not been faulted-in in the coredump?
  159. // (A page may not be backed by a physical page because it has never been faulted in when the process ran).
  160. src_buffer = UserOrKernelBuffer::for_kernel_buffer(zero_buffer);
  161. }
  162. auto result = m_fd->write(src_buffer.value(), PAGE_SIZE);
  163. if (result.is_error())
  164. return result.error();
  165. }
  166. }
  167. return KSuccess;
  168. }
  169. KResult CoreDump::write_notes_segment(ByteBuffer& notes_segment)
  170. {
  171. auto result = m_fd->write(UserOrKernelBuffer::for_kernel_buffer(notes_segment.data()), notes_segment.size());
  172. if (result.is_error())
  173. return result.error();
  174. return KSuccess;
  175. }
  176. ByteBuffer CoreDump::create_notes_process_data() const
  177. {
  178. ByteBuffer process_data;
  179. ELF::Core::ProcessInfo info {};
  180. info.header.type = ELF::Core::NotesEntryHeader::Type::ProcessInfo;
  181. process_data.append((void*)&info, sizeof(info));
  182. StringBuilder builder;
  183. {
  184. JsonObjectSerializer process_obj { builder };
  185. process_obj.add("pid"sv, m_process->pid().value());
  186. process_obj.add("termination_signal"sv, m_process->termination_signal());
  187. process_obj.add("executable_path"sv, m_process->executable() ? m_process->executable()->absolute_path() : String::empty());
  188. {
  189. auto arguments_array = process_obj.add_array("arguments"sv);
  190. for (auto& argument : m_process->arguments())
  191. arguments_array.add(argument);
  192. }
  193. {
  194. auto environment_array = process_obj.add_array("environment"sv);
  195. for (auto& variable : m_process->environment())
  196. environment_array.add(variable);
  197. }
  198. }
  199. builder.append(0);
  200. process_data.append(builder.string_view().characters_without_null_termination(), builder.length());
  201. return process_data;
  202. }
  203. ByteBuffer CoreDump::create_notes_threads_data() const
  204. {
  205. ByteBuffer threads_data;
  206. for (auto& thread : m_process->threads_for_coredump({})) {
  207. ByteBuffer entry_buff;
  208. ELF::Core::ThreadInfo info {};
  209. info.header.type = ELF::Core::NotesEntryHeader::Type::ThreadInfo;
  210. info.tid = thread.tid().value();
  211. if (thread.current_trap())
  212. copy_kernel_registers_into_ptrace_registers(info.regs, thread.get_register_dump_from_stack());
  213. entry_buff.append((void*)&info, sizeof(info));
  214. threads_data += entry_buff;
  215. }
  216. return threads_data;
  217. }
  218. ByteBuffer CoreDump::create_notes_regions_data() const
  219. {
  220. ByteBuffer regions_data;
  221. size_t region_index = 0;
  222. for (auto& region : m_process->address_space().regions()) {
  223. ByteBuffer memory_region_info_buffer;
  224. ELF::Core::MemoryRegionInfo info {};
  225. info.header.type = ELF::Core::NotesEntryHeader::Type::MemoryRegionInfo;
  226. info.region_start = region->vaddr().get();
  227. info.region_end = region->vaddr().offset(region->size()).get();
  228. info.program_header_index = region_index++;
  229. memory_region_info_buffer.append((void*)&info, sizeof(info));
  230. // NOTE: The region name *is* null-terminated, so the following is ok:
  231. auto name = region->name();
  232. if (name.is_empty()) {
  233. char null_terminator = '\0';
  234. memory_region_info_buffer.append(&null_terminator, 1);
  235. } else {
  236. memory_region_info_buffer.append(name.characters_without_null_termination(), name.length() + 1);
  237. }
  238. regions_data += memory_region_info_buffer;
  239. }
  240. return regions_data;
  241. }
  242. ByteBuffer CoreDump::create_notes_metadata_data() const
  243. {
  244. ByteBuffer metadata_data;
  245. ELF::Core::Metadata metadata {};
  246. metadata.header.type = ELF::Core::NotesEntryHeader::Type::Metadata;
  247. metadata_data.append((void*)&metadata, sizeof(metadata));
  248. StringBuilder builder;
  249. {
  250. JsonObjectSerializer metadata_obj { builder };
  251. m_process->for_each_coredump_property([&](auto& key, auto& value) {
  252. metadata_obj.add(key.view(), value.view());
  253. });
  254. }
  255. builder.append(0);
  256. metadata_data.append(builder.string_view().characters_without_null_termination(), builder.length());
  257. return metadata_data;
  258. }
  259. ByteBuffer CoreDump::create_notes_segment_data() const
  260. {
  261. ByteBuffer notes_buffer;
  262. notes_buffer += create_notes_process_data();
  263. notes_buffer += create_notes_threads_data();
  264. notes_buffer += create_notes_regions_data();
  265. notes_buffer += create_notes_metadata_data();
  266. ELF::Core::NotesEntryHeader null_entry {};
  267. null_entry.type = ELF::Core::NotesEntryHeader::Type::Null;
  268. notes_buffer.append(&null_entry, sizeof(null_entry));
  269. return notes_buffer;
  270. }
  271. KResult CoreDump::write()
  272. {
  273. SpinlockLocker lock(m_process->address_space().get_lock());
  274. ProcessPagingScope scope(m_process);
  275. ByteBuffer notes_segment = create_notes_segment_data();
  276. auto result = write_elf_header();
  277. if (result.is_error())
  278. return result;
  279. result = write_program_headers(notes_segment.size());
  280. if (result.is_error())
  281. return result;
  282. result = write_regions();
  283. if (result.is_error())
  284. return result;
  285. result = write_notes_segment(notes_segment);
  286. if (result.is_error())
  287. return result;
  288. return m_fd->chmod(0600); // Make coredump file read/writable
  289. }
  290. }